APRA CPS 220 Risk Management
Reporting

APRA CPS 220 Risk Management CPS220-16: Management Information System and Data Framework

The management information system must give the Board, board committees and senior management regular, accurate and timely information on the institution risk profile, and must rest on a robust data framework enabling aggregation of exposures and risk measures across business lines, prompt reporting of limit breaches and forward looking scenario analysis and stress testing, with data quality adequate for timely and accurate measurement, assessment and reporting and sound enough to base decisions on.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • 22 Para 22 Senior management informs the Board on impacts to critical operations
  • 26 Para 26 Maintain a comprehensive operational risk profile assessment
  • SPS220-42 Minimum Contents of the Risk Management Framework

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.