Back to Frameworks

APRA CPS 220 Risk Management

Australia
v2023
17 domains
40 controls

Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees.

Verified

APRA CPS 220 Risk Management is a compliance framework from Australia with 17 domains and 40 controls that map to 27 other frameworks. The largest domains are Group (5 controls), Regulator (5 controls), RMF (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

Assurance

1 controls
Controls in the Assurance domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-11Annual Audit Review of the Framework

Attestation

3 controls
Controls in the Attestation domain of APRA CPS 220 Risk Management3 controls
CodeTitle
CPS220-20Annual Board Risk Management Declaration
CPS220-P50Qualification of the Risk Management Declaration
CPS220-P51Submission Deadline for the Risk Management Declaration

Board Oversight

1 controls
Controls in the Board Oversight domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-02Board Responsibility for the Risk Management Framework

CRO

3 controls
Controls in the CRO domain of APRA CPS 220 Risk Management3 controls
CodeTitle
CPS220-09Designation of a Chief Risk Officer
CPS220-P39Independence of the Chief Risk Officer
CPS220-P40Chief Risk Officer Reporting Lines and Board Access

Change

1 controls
Controls in the Change domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-P48Assessment Following Material Change Outside the Review Cycle

Documentation

2 controls
Controls in the Documentation domain of APRA CPS 220 Risk Management2 controls
CodeTitle
CPS220-P35Required Content of Risk Management Policies and Procedures
CPS220-P36Monitoring of Policy Review Dates and Ownership

Group

5 controls
Controls in the Group domain of APRA CPS 220 Risk Management5 controls
CodeTitle
CPS220-17Group Framework Coverage of Non Regulated Group Entities
CPS220-P12Identification of Group Derived Framework Elements
CPS220-P14Head of Group Coordination of Material Risks
CPS220-P15Restriction on the Group Chief Risk Officer Role
CPS220-P17Group Liquidity Management Policy

Operating Model

1 controls
Controls in the Operating Model domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-P43Designated Compliance Function

RMF

4 controls
Controls in the RMF domain of APRA CPS 220 Risk Management4 controls
CodeTitle
CPS220-04Maintenance of a Risk Management Framework
CPS220-P21Consistency of the Framework with the Business Plan
CPS220-P22Framework Structure for Managing Each Material Risk
CPS220-P23Minimum Contents of the Risk Management Framework

Regulator

5 controls
Controls in the Regulator domain of APRA CPS 220 Risk Management5 controls
CodeTitle
CPS220-19APRA Notification of Framework Breach within 10 Business Days
CPS220-P16Head of Group Notification Duties
CPS220-P52Submission of Appetite Statement, Business Plan and Strategy to APRA
CPS220-P54APRA Notification of Material Changes to the Institution
CPS220-P55APRA Notification of Overseas Business Rights

Reporting

1 controls
Controls in the Reporting domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-16Management Information System and Data Framework

Review

3 controls
Controls in the Review domain of APRA CPS 220 Risk Management3 controls
CodeTitle
CPS220-18Triennial Comprehensive Review of the Framework
CPS220-P46Scope of the Comprehensive Review
CPS220-P47Minimum Assessment Required by the Framework Review

Risk Appetite

2 controls
Controls in the Risk Appetite domain of APRA CPS 220 Risk Management2 controls
CodeTitle
CPS220-06Risk Appetite Statement
CPS220-P28Minimum Contents of the Risk Appetite Statement

Risk Function

1 controls
Controls in the Risk Function domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-10Designated Risk Management Function

Risk Identification

2 controls
Controls in the Risk Identification domain of APRA CPS 220 Risk Management2 controls
CodeTitle
CPS220-07Material Risk Categories the Framework Must Address
CPS220-P33Risks Arising from Strategic Objectives and the Business Plan

Strategy

4 controls
Controls in the Strategy domain of APRA CPS 220 Risk Management4 controls
CodeTitle
CPS220-05Risk Management Strategy
CPS220-P30Minimum Contents of the Risk Management Strategy
CPS220-P31Maintenance of a Business Plan
CPS220-P32Business Plan Duration, Review and Approval

Stress Testing

1 controls
Controls in the Stress Testing domain of APRA CPS 220 Risk Management1 controls
CodeTitle
CPS220-14Scenario Analysis and Stress Testing Programs

Your Compliance Coverage

If you comply with APRA CPS 220 Risk Management, you already cover:

Maps to 27 other frameworks

40 total controls
NIST Cybersecurity Framework 2.0
36 source controls mapped|29 target controls covered
90%
NIST SP 800-53 Rev 5
29 source controls mapped|19 target controls covered
73%
SOC 2
27 source controls mapped|16 target controls covered
68%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
23 source controls mapped|20 target controls covered
57%
NIST SP 800-161 Rev 1
19 source controls mapped|16 target controls covered
48%
HIPAA Security Rule
14 source controls mapped|11 target controls covered
35%
NIST SP 800-66 Rev 2
13 source controls mapped|9 target controls covered
33%
C5 (Germany)
13 source controls mapped|10 target controls covered
33%
FedRAMP High
11 source controls mapped|14 target controls covered
28%
FedRAMP Moderate
11 source controls mapped|14 target controls covered
28%
NIST SP 800-53 Revision 5.1 HIGH
11 source controls mapped|14 target controls covered
28%
NIST SP 800-53 Rev 5 MODERATE
11 source controls mapped|14 target controls covered
28%
NIST SP 800-53 Rev 5 LOW
10 source controls mapped|12 target controls covered
25%
APRA SPS 220 Risk Management (Superannuation)
10 source controls mapped|12 target controls covered
25%
CMMC 2.0
9 source controls mapped|5 target controls covered
23%
ISO 45001:2018
1 source controls mapped|2 target controls covered
3%
ISO 22301:2019
1 source controls mapped|1 target controls covered
3%
ISO 22000:2018
1 source controls mapped|1 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%
ISO 37301:2021
1 source controls mapped|2 target controls covered
3%
ISO 37001:2016
1 source controls mapped|1 target controls covered
3%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|1 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%
ISO 14001:2015
1 source controls mapped|2 target controls covered
3%
ISO 13485:2016
1 source controls mapped|1 target controls covered
3%
ISO 9001:2015
1 source controls mapped|1 target controls covered
3%
ISO 14004:2016
1 source controls mapped|1 target controls covered
3%

What is APRA CPS 220 Risk Management and who does it apply to?

APRA CPS 220 Risk Management is a compliance framework from Australia with 17 domains and 40 controls. Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does APRA CPS 220 Risk Management actually require?

APRA CPS 220 Risk Management has 40 controls organised across 17 domains. The largest domains are Group (5 controls), Regulator (5 controls), RMF (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of APRA CPS 220 Risk Management do I already cover?

APRA CPS 220 Risk Management maps to 27 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (90% coverage), NIST SP 800-53 Rev 5 (73% coverage), SOC 2 (68% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement APRA CPS 220 Risk Management?

Start your APRA CPS 220 Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 220 Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required