APRA CPS 220 Risk Management
Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Assurance
| Code | Title |
|---|---|
| CPS220-11 | Internal Audit |
Attestation
| Code | Title |
|---|---|
| CPS220-20 | Declaration to APRA |
Board Oversight
| Code | Title |
|---|---|
| CPS220-02 | Board Responsibility |
| CPS220-03 | Board Risk Committee |
CRO
| Code | Title |
|---|---|
| CPS220-09 | Chief Risk Officer |
Capital
| Code | Title |
|---|---|
| CPS220-15 | ICAAP Linkage |
Change
| Code | Title |
|---|---|
| CPS220-13 | New and Material Changes |
Culture
| Code | Title |
|---|---|
| CPS220-12 | Risk Culture |
Documentation
| Code | Title |
|---|---|
| CPS220-23 | Documentation and Records |
Governance
| Code | Title |
|---|---|
| CPS220-01 | Application and Scope |
Group
| Code | Title |
|---|---|
| CPS220-17 | Group Risk Management |
Operating Model
| Code | Title |
|---|---|
| CPS220-08 | Three Lines of Accountability |
Operational Risk
| Code | Title |
|---|---|
| CPS220-22 | Operational and Non-Financial Risk |
RMF
| Code | Title |
|---|---|
| CPS220-04 | Risk Management Framework |
Regulator
| Code | Title |
|---|---|
| CPS220-19 | Notification to APRA |
Reporting
| Code | Title |
|---|---|
| CPS220-16 | Risk Reporting |
Review
| Code | Title |
|---|---|
| CPS220-18 | Comprehensive Review |
Risk Appetite
| Code | Title |
|---|---|
| CPS220-06 | Risk Appetite Statement |
Risk Assessment and Reporting
Requirements for identifying, assessing, measuring and reporting risks
| Code | Title |
|---|---|
| CPS220-RAR-1 | Material Risk Identification |
| CPS220-RAR-2 | Risk Measurement and Monitoring |
| CPS220-RAR-3 | Stress Testing |
| CPS220-RAR-4 | Risk Reporting |
Risk Function
| Code | Title |
|---|---|
| CPS220-10 | Risk Management Function |
Risk Governance and Oversight
Governance arrangements for risk management
| Code | Title |
|---|---|
| CPS220-GOV-1 | Board Risk Committee |
| CPS220-GOV-2 | Chief Risk Officer |
| CPS220-GOV-3 | Three Lines of Defence |
| CPS220-GOV-4 | Risk Management Declaration |
Risk Identification
| Code | Title |
|---|---|
| CPS220-07 | Material Risks Coverage |
Strategy
| Code | Title |
|---|---|
| CPS220-05 | Risk Management Strategy |
Stress Testing
| Code | Title |
|---|---|
| CPS220-14 | Stress Testing |
Third Party
| Code | Title |
|---|---|
| CPS220-21 | Outsourcing and Service Provider Risk |
Your Compliance Coverage
If you comply with APRA CPS 220 Risk Management, you already cover:
Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022)
13%
4 controls mapped
Compare →NIST AI Risk Management Framework (AI RMF 1.0)
13%
4 controls mapped
Compare →NIST AI 600-1 Generative AI Profile
13%
4 controls mapped
Compare →+ 407 more: C2M2 (13%), CDP (formerly Carbon Disclosure Project) (13%)
See all 410 mapped frameworks ↓Maps to 410 other frameworks
Frequently Asked Questions
What is APRA CPS 220 Risk Management?
APRA CPS 220 Risk Management is a compliance framework from Australia with 24 domains and 31 controls. Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does APRA CPS 220 Risk Management have?
APRA CPS 220 Risk Management has 31 controls organised across 24 domains. The largest domains are Risk Assessment and Reporting (4 controls), Risk Governance and Oversight (4 controls), Board Oversight (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does APRA CPS 220 Risk Management map to?
APRA CPS 220 Risk Management maps to 410 other compliance frameworks. The top mapping partners are Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) (13% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (13% coverage), NIST AI 600-1 Generative AI Profile (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with APRA CPS 220 Risk Management compliance?
Start your APRA CPS 220 Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 220 Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required