APRA may set, in writing, prudential standards binding on general insurers, on authorised NOHCs, and on their subsidiaries, a specified class of them, or named entities, and a standard may impose different requirements on different classes, situations or activities, including requiring a group to collectively satisfy requirements, or addressing auditor appointment and audit conduct (s 32). Once bound by a prudential standard, the insurer, NOHC or subsidiary concerned follows it (s 35). The specific content of a given standard (for example CPS 220 risk management, CPS 230 operational risk management, CPS 234 information security) sits in the standard itself, not in the Act; this leaf is the Act's duty to comply, mapped to the relevant prudential standards in a later near-miss pass, not this run.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.