APRA SPS 220 Risk Management (Superannuation)
Australian Prudential Regulation Authority Prudential Standard SPS 220 sets out risk management requirements specifically for RSE licensees (superannuation trustees). It requires RSE licensees to maintain a Board-approved risk management framework covering material risks to the business operations and to the interests of beneficiaries.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Assurance
| Code | Title |
|---|---|
| SPS220-46 | Comprehensive Review of RMF |
Audit
| Code | Title |
|---|---|
| SPS220-48 | Internal Audit of RMF |
Board and Senior Management
| Code | Title |
|---|---|
| SPS220-14 | Member Best Financial Interests |
| SPS220-15 | Senior Management Responsibility |
| SPS220-16 | Risk Management Function |
Business Continuity
| Code | Title |
|---|---|
| SPS220-50 | Business Continuity Management |
Capability
| Code | Title |
|---|---|
| SPS220-35 | Risk Management Function |
Governance
| Code | Title |
|---|---|
| SPS220-13 | Board Risk Responsibility |
| SPS220-14 | Member Best Financial Interests |
| SPS220-33 | Risk Culture |
| SPS220-37 | Three Lines Model |
| SPS220-52 | Conflicts Management |
| SPS220-54 | Fit and Proper |
| SPS220-56 | Whistleblower Arrangements |
Insurance
| Code | Title |
|---|---|
| SPS220-27 | Insurance Risk Management |
Investment
| Code | Title |
|---|---|
| SPS220-25 | Investment Risk Management |
Operational
| Code | Title |
|---|---|
| SPS220-29 | Operational Risk Management |
Reporting
| Code | Title |
|---|---|
| SPS220-42 | Risk Reporting to Board |
| SPS220-44 | Material Risk Event Reporting |
Review and Reporting
| Code | Title |
|---|---|
| SPS220-27 | Insurance Risk Management |
| SPS220-28 | Risk Management Declaration |
| SPS220-29 | Operational Risk Management |
Risk Categories
| Code | Title |
|---|---|
| SPS220-23 | Material Risks Identification |
| SPS220-24 | Insurance Risk |
| SPS220-25 | Investment Risk Management |
| SPS220-26 | Strategic and Concentration Risk |
Risk Management
| Code | Title |
|---|---|
| SPS220-17 | Risk Management Framework |
| SPS220-19 | Risk Appetite Statement |
| SPS220-21 | Risk Management Strategy |
| SPS220-23 | Material Risks Identification |
| SPS220-40 | Stress Testing |
Risk Management Framework
| Code | Title |
|---|---|
| SPS220-17 | Risk Management Framework |
| SPS220-18 | Scope of Framework |
| SPS220-19 | Risk Appetite Statement |
Risk Management Strategy
| Code | Title |
|---|---|
| SPS220-20 | Risk Management Strategy |
| SPS220-21 | Risk Management Strategy |
| SPS220-22 | Risk Identification and Assessment |
Third Party
| Code | Title |
|---|---|
| SPS220-31 | Outsourcing Risk Management |
Your Compliance Coverage
If you comply with APRA SPS 220 Risk Management (Superannuation), you already cover:
APRA CPS 230 Operational Risk Management
13%
4 controls mapped
Compare →COSO ERM
13%
4 controls mapped
Compare →IEEE 7000
13%
4 controls mapped
Compare →+ 407 more: NIST SP 800-39 (13%), NIST AI Risk Management Framework (AI RMF 1.0) (13%)
See all 410 mapped frameworks ↓Maps to 410 other frameworks
Frequently Asked Questions
What is APRA SPS 220 Risk Management (Superannuation)?
APRA SPS 220 Risk Management (Superannuation) is a compliance framework from Australia with 16 domains and 38 controls. Australian Prudential Regulation Authority Prudential Standard SPS 220 sets out risk management requirements specifically for RSE licensees (superannuation trustees). It requires RSE licensees to maintain a Board-approved risk management framework covering material risks to the business operations and to the interests of beneficiaries. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does APRA SPS 220 Risk Management (Superannuation) have?
APRA SPS 220 Risk Management (Superannuation) has 38 controls organised across 16 domains. The largest domains are Governance (7 controls), Risk Management (5 controls), Risk Categories (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does APRA SPS 220 Risk Management (Superannuation) map to?
APRA SPS 220 Risk Management (Superannuation) maps to 410 other compliance frameworks. The top mapping partners are APRA CPS 230 Operational Risk Management (13% coverage), COSO ERM (13% coverage), IEEE 7000 (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with APRA SPS 220 Risk Management (Superannuation) compliance?
Start your APRA SPS 220 Risk Management (Superannuation) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA SPS 220 Risk Management (Superannuation) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required