APRA CPS 220 Risk Management
Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees.
APRA CPS 220 Risk Management is a compliance framework from Australia with 17 domains and 40 controls that map to 27 other frameworks. The largest domains are Group (5 controls), Regulator (5 controls), RMF (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Assurance
| Code | Title |
|---|---|
| CPS220-11 | Annual Audit Review of the Framework |
Attestation
| Code | Title |
|---|---|
| CPS220-20 | Annual Board Risk Management Declaration |
| CPS220-P50 | Qualification of the Risk Management Declaration |
| CPS220-P51 | Submission Deadline for the Risk Management Declaration |
Board Oversight
| Code | Title |
|---|---|
| CPS220-02 | Board Responsibility for the Risk Management Framework |
CRO
| Code | Title |
|---|---|
| CPS220-09 | Designation of a Chief Risk Officer |
| CPS220-P39 | Independence of the Chief Risk Officer |
| CPS220-P40 | Chief Risk Officer Reporting Lines and Board Access |
Change
| Code | Title |
|---|---|
| CPS220-P48 | Assessment Following Material Change Outside the Review Cycle |
Documentation
| Code | Title |
|---|---|
| CPS220-P35 | Required Content of Risk Management Policies and Procedures |
| CPS220-P36 | Monitoring of Policy Review Dates and Ownership |
Group
| Code | Title |
|---|---|
| CPS220-17 | Group Framework Coverage of Non Regulated Group Entities |
| CPS220-P12 | Identification of Group Derived Framework Elements |
| CPS220-P14 | Head of Group Coordination of Material Risks |
| CPS220-P15 | Restriction on the Group Chief Risk Officer Role |
| CPS220-P17 | Group Liquidity Management Policy |
Operating Model
| Code | Title |
|---|---|
| CPS220-P43 | Designated Compliance Function |
RMF
| Code | Title |
|---|---|
| CPS220-04 | Maintenance of a Risk Management Framework |
| CPS220-P21 | Consistency of the Framework with the Business Plan |
| CPS220-P22 | Framework Structure for Managing Each Material Risk |
| CPS220-P23 | Minimum Contents of the Risk Management Framework |
Regulator
| Code | Title |
|---|---|
| CPS220-19 | APRA Notification of Framework Breach within 10 Business Days |
| CPS220-P16 | Head of Group Notification Duties |
| CPS220-P52 | Submission of Appetite Statement, Business Plan and Strategy to APRA |
| CPS220-P54 | APRA Notification of Material Changes to the Institution |
| CPS220-P55 | APRA Notification of Overseas Business Rights |
Reporting
| Code | Title |
|---|---|
| CPS220-16 | Management Information System and Data Framework |
Review
| Code | Title |
|---|---|
| CPS220-18 | Triennial Comprehensive Review of the Framework |
| CPS220-P46 | Scope of the Comprehensive Review |
| CPS220-P47 | Minimum Assessment Required by the Framework Review |
Risk Appetite
| Code | Title |
|---|---|
| CPS220-06 | Risk Appetite Statement |
| CPS220-P28 | Minimum Contents of the Risk Appetite Statement |
Risk Function
| Code | Title |
|---|---|
| CPS220-10 | Designated Risk Management Function |
Risk Identification
| Code | Title |
|---|---|
| CPS220-07 | Material Risk Categories the Framework Must Address |
| CPS220-P33 | Risks Arising from Strategic Objectives and the Business Plan |
Strategy
| Code | Title |
|---|---|
| CPS220-05 | Risk Management Strategy |
| CPS220-P30 | Minimum Contents of the Risk Management Strategy |
| CPS220-P31 | Maintenance of a Business Plan |
| CPS220-P32 | Business Plan Duration, Review and Approval |
Stress Testing
| Code | Title |
|---|---|
| CPS220-14 | Scenario Analysis and Stress Testing Programs |
Your Compliance Coverage
If you comply with APRA CPS 220 Risk Management, you already cover:
NIST Cybersecurity Framework 2.0
90%
36 controls mapped
Compare →NIST SP 800-53 Rev 5
73%
29 controls mapped
Compare →SOC 2
68%
27 controls mapped
Compare →+ 24 more: Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (57%), NIST SP 800-161 Rev 1 (48%)
See all 27 mapped frameworks ↓Maps to 27 other frameworks
What is APRA CPS 220 Risk Management and who does it apply to?
APRA CPS 220 Risk Management is a compliance framework from Australia with 17 domains and 40 controls. Australian Prudential Regulation Authority Prudential Standard CPS 220 sets out requirements for APRA-regulated entities to have an effective risk management framework, including the Board's responsibility for risk oversight, a Chief Risk Officer, and the 'three lines of defence' model. Applies to ADIs, insurers, and RSE licensees. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does APRA CPS 220 Risk Management actually require?
APRA CPS 220 Risk Management has 40 controls organised across 17 domains. The largest domains are Group (5 controls), Regulator (5 controls), RMF (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of APRA CPS 220 Risk Management do I already cover?
APRA CPS 220 Risk Management maps to 27 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (90% coverage), NIST SP 800-53 Rev 5 (73% coverage), SOC 2 (68% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement APRA CPS 220 Risk Management?
Start your APRA CPS 220 Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 220 Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required