APRA CPS 220 Risk Management
Attestation

APRA CPS 220 Risk Management CPS220-20: Annual Board Risk Management Declaration

The Board must make an annual risk management declaration to APRA satisfying the requirements of Attachment A, signed by the chairperson of the Board and the chairperson of the Board Risk Committee, or for a Category C insurer, foreign ADI or EFLIC by the senior officer outside Australia or two members of the Compliance Committee as relevant.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 10 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

SOC 2 · 3 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SPS220-28 Annual Board Risk Management Declaration

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Attestation

Query this from an agent

The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.