APRA SPS 220 Risk Management (Superannuation) SPS220-44: APRA Notification of Framework Breach within 10 Business Days
The RSE licensee must notify APRA within 10 business days when it becomes aware of a significant breach of or material deviation from the risk management framework, or discovers that the framework did not adequately address a material risk.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction