Frameworks / APRA SPS 220 Risk Management (Superannuation) / SPS220-22 APRA SPS 220 Risk Management (Superannuation)
Risk Management Strategy
APRA SPS 220 Risk Management (Superannuation) SPS220-22: Framework Enabling Strategies, Policies, Procedures and Controls The risk management framework must enable the RSE licensee to develop and implement strategies, policies, procedures and controls that appropriately manage the different types of material risk.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 123 controls across 61 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO23894-6.3 AI Risk Assessment ISO23894-6.3.1 AI Risk Identification ISO23894-6.3.3 AI Risk Evaluation 6.4.2 Risk identification BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use RMI-DD-2 Supply Chain Information Collection RMI-SEG-2 Environmental Standards RMI-SEG-3 OHS and Governance SSAE18-CC3.1 CC3.1 - COSO Principle 6: Risk Identification SSAE18-CC3.2 CC3.2 - COSO Principle 7: Risk Analysis SSAE18-SOC1-02 Risk Assessment API1164-07 Remote Access API1164-24 Vulnerability assessment for critical systems IS.D.OR.205 Information Security Risk Assessment IS.I.OR.205 Information Security Risk Assessment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain IEC62443-07 Personnel risk assessment IEC62443-24 Vulnerability assessment for critical systems ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.2 Information security risk assessment ISO27019-07 Personnel risk assessment ISO27019-24 Vulnerability assessment for critical systems 27557-4.3 Individual impact consideration 27557-6.3 Privacy risk assessment 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan ISMSP-MS-02 Risk Management ISMSP-SYS-04 Vulnerability Management CH-FADP-21 Data protection impact assessments FADP-7 Data Protection Impact Assessment (Articles 9-10) CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment UNESCO-AI-PA1 Ethical Impact Assessment UNESCOAI-1 Principles 1-3: Proportionality, Safety, Fairness AMLCTF-PartA-RiskAssess ML/TF Risk Assessment CPS220-07 Material Risk Categories the Framework Must Address CPS230-11 Identification, Assessment and Management of Operational Risk 4.3.1 Risk Assessment and Impact Analysis P1-S1 Advance Electronic Information BB-DPA-20 Sections 50-60 - Registration and Responsibilities RA-1 Policy and Procedures RA-1 Policy and Procedures UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) ISO-22313-8.2 Business impact analysis and risk assessment ISO-26262-3-7 Hazard analysis and risk assessment (HARA) ISO27799-06 Security management process and risk analysis 6.4.2 Risk identification 27031-7.2 Resource Requirements 29147-5.11 Researcher Safe Harbour and Legal Posture NFPA1600-5.1 Risk Assessment PICERL-P2 Risk Assessment SOC-CY-DC5 Risk Assessment Process SA-PDPL-21 Data protection impact assessments SOCI-S30CU Vulnerability assessments SCA-S10 Annual Risk Assessment IM8-SEC.4 Vulnerability Management TAIWAN-3 Data Subject Rights TEXASTDPSA-3 Sensitive Data, Children, Sale Notice UKAI-1 Risk-Based Approach and Pro-Innovation Principles Standard 2 Data Protection Impact Assessments UKOPRES-3 Self-Assessment and Board Engagement UKGDPRREG-3 Controller and Processor (Articles 24-43) s.54(5) Statement Content Requirements SEMD-SP-2 Risk Identification and Assessment CPSC-RA.3 Lifecycle Risk Assessment URUGUAY-5 Database Registration with AGESIC URCDP VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Risk Management Strategy Query this from an agent The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.