Back to Frameworks

APRA CPS 220 Risk Management

Australia
v2023
22 domains
23 controls

Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (22)

Assurance

1 controls
Controls in the Assurance domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-11Internal Audit

Attestation

1 controls
Controls in the Attestation domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-20Declaration to APRA

Board Oversight

2 controls
Controls in the Board Oversight domain of APRA CPS 220 Risk Management2 controls
CodeTitle
CPS220-02Board Responsibility
CPS220-03Board Risk Committee

CRO

1 controls
Controls in the CRO domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-09Chief Risk Officer

Capital

1 controls
Controls in the Capital domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-15ICAAP Linkage

Change

1 controls
Controls in the Change domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-13New and Material Changes

Culture

1 controls
Controls in the Culture domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-12Risk Culture

Documentation

1 controls
Controls in the Documentation domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-23Documentation and Records

Governance

1 controls
Controls in the Governance domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-01Application and Scope

Group

1 controls
Controls in the Group domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-17Group Risk Management

Operating Model

1 controls
Controls in the Operating Model domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-08Three Lines of Accountability

Operational Risk

1 controls
Controls in the Operational Risk domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-22Operational and Non-Financial Risk

RMF

1 controls
Controls in the RMF domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-04Risk Management Framework

Regulator

1 controls
Controls in the Regulator domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-19Notification to APRA

Reporting

1 controls
Controls in the Reporting domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-16Risk Reporting

Review

1 controls
Controls in the Review domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-18Comprehensive Review

Risk Appetite

1 controls
Controls in the Risk Appetite domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-06Risk Appetite Statement

Risk Function

1 controls
Controls in the Risk Function domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-10Risk Management Function

Risk Identification

1 controls
Controls in the Risk Identification domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-07Material Risks Coverage

Strategy

1 controls
Controls in the Strategy domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-05Risk Management Strategy

Stress Testing

1 controls
Controls in the Stress Testing domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-14Stress Testing

Third Party

1 controls
Controls in the Third Party domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-21Outsourcing and Service Provider Risk

Maps to 3 other frameworks

23 total controls
APRA SPS 220 Risk Management (Superannuation)
15 source controls mapped|17 target controls covered
65%
NIST SP 800-53 Rev 5
5 source controls mapped|4 target controls covered
22%
NIST Cybersecurity Framework 2.0
2 source controls mapped|2 target controls covered
9%

Frequently Asked Questions

What is APRA CPS 220 Risk Management?

APRA CPS 220 Risk Management is a compliance framework from Australia with 22 domains and 23 controls. Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does APRA CPS 220 Risk Management have?

APRA CPS 220 Risk Management has 23 controls organised across 22 domains. The largest domains are Board Oversight (2 controls), Assurance (1 controls), Attestation (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does APRA CPS 220 Risk Management map to?

APRA CPS 220 Risk Management maps to 3 other compliance frameworks. The top mapping partners are APRA SPS 220 Risk Management (Superannuation) (65% coverage), NIST SP 800-53 Rev 5 (22% coverage), NIST Cybersecurity Framework 2.0 (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with APRA CPS 220 Risk Management compliance?

Start your APRA CPS 220 Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 220 Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required