APRA CPS 220 Risk Management CPS220-P33: Risks Arising from Strategic Objectives and the Business Plan
The institution must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects its risk profile.
What else in your programme already covers this
This control maps to 11 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PM-11 Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and