APRA SPS 220 Risk Management (Superannuation)
Australian Prudential Regulation Authority Prudential Standard SPS 220 sets out risk management requirements specifically for RSE licensees (superannuation trustees). It requires RSE licensees to maintain a Board-approved risk management framework covering material risks to the business operations and to the interests of beneficiaries.
APRA SPS 220 Risk Management (Superannuation) is a compliance framework from Australia with 10 domains and 28 controls that map to 96 other frameworks. The largest domains are Risk Management (6 controls), Assurance (4 controls), Governance (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Assurance
| Code | Title |
|---|---|
| SPS220-46 | Triennial Comprehensive Review of the Framework |
| SPS220-P28 | Annual Review in Non Comprehensive Review Years |
| SPS220-P29 | Scope and Minimum Content of the Comprehensive Review |
| SPS220-P31 | Assessment Following Material Developments Outside the Review Cycle |
Audit
| Code | Title |
|---|---|
| SPS220-48 | Internal and External Audit Arrangements |
Board and Senior Management
| Code | Title |
|---|---|
| SPS220-16 | Designated Risk Management Function |
Governance
Reporting
| Code | Title |
|---|---|
| SPS220-42 | Minimum Contents of the Risk Management Framework |
| SPS220-44 | APRA Notification of Framework Breach within 10 Business Days |
| SPS220-P36 | APRA Notification of Material Changes to Business Operations |
Review and Reporting
| Code | Title |
|---|---|
| SPS220-28 | Annual Board Risk Management Declaration |
| SPS220-P33 | Submission Deadline for the Risk Management Declaration |
| SPS220-P34 | Content of a Qualified Risk Management Declaration |
Risk Categories
| Code | Title |
|---|---|
| SPS220-P13 | Contagion Risk from Non Superannuation Business |
Risk Management
| Code | Title |
|---|---|
| SPS220-17 | Maintenance of a Risk Management Framework |
| SPS220-19 | Risk Appetite Statement |
| SPS220-23 | Risk Categories the Framework Must Cover |
| SPS220-P11 | Assessment of the Materiality of Each Risk |
| SPS220-P18 | Risks Arising from Strategic Objectives and the Business Plan |
| SPS220-P20 | Minimum Contents of the Risk Appetite Statement |
Risk Management Framework
| Code | Title |
|---|---|
| SPS220-18 | Framework Coverage of All Material Risks |
| SPS220-P15 | Reasonable Assurance of Prudent and Sound Management |
| SPS220-P17 | Identification of Group Derived Framework Elements |
Risk Management Strategy
| Code | Title |
|---|---|
| SPS220-20 | Risk Management Strategy |
| SPS220-22 | Framework Enabling Strategies, Policies, Procedures and Controls |
| SPS220-P22 | Minimum Contents of the Risk Management Strategy |
Your Compliance Coverage
If you comply with APRA SPS 220 Risk Management (Superannuation), you already cover:
NIST Cybersecurity Framework 2.0
100%
28 controls mapped
Compare →APRA CPS 220 Risk Management
43%
12 controls mapped
Compare →CMMC 2.0
25%
7 controls mapped
Compare →+ 93 more: NIST SP 800-53 Rev 5 (14%), UK AI Regulation Framework (7%)
See all 96 mapped frameworks ↓Maps to 96 other frameworks
What is APRA SPS 220 Risk Management (Superannuation) and who does it apply to?
APRA SPS 220 Risk Management (Superannuation) is a compliance framework from Australia with 10 domains and 28 controls. Australian Prudential Regulation Authority Prudential Standard SPS 220 sets out risk management requirements specifically for RSE licensees (superannuation trustees). It requires RSE licensees to maintain a Board-approved risk management framework covering material risks to the business operations and to the interests of beneficiaries. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does APRA SPS 220 Risk Management (Superannuation) actually require?
APRA SPS 220 Risk Management (Superannuation) has 28 controls organised across 10 domains. The largest domains are Risk Management (6 controls), Assurance (4 controls), Governance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of APRA SPS 220 Risk Management (Superannuation) do I already cover?
APRA SPS 220 Risk Management (Superannuation) maps to 96 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (100% coverage), APRA CPS 220 Risk Management (43% coverage), CMMC 2.0 (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement APRA SPS 220 Risk Management (Superannuation)?
Start your APRA SPS 220 Risk Management (Superannuation) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA SPS 220 Risk Management (Superannuation) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required