Comply with APRA CPS 220 (Risk Management)
APRA-regulated entities must have a comprehensive risk management framework.
Who must comply
ADIs and authorised banking NOHCs, general insurers and authorised insurance NOHCs, life companies (including friendly societies) and registered life NOHCs, and private health insurers, together with the Head of a Level 2 or Level 3 group. Superannuation trustees are covered by the separate SPS 220, not CPS 220.
What triggers it
Being an APRA-regulated institution in the banking, general insurance, life insurance or private health insurance industries, or the Head of a group of such institutions.
When due
Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.
Evidence required
Board-approved risk appetite statement, risk management strategy and three-year business plan; CRO appointment and reporting lines; management information system reports on material risks; annual audit review report to the Board Audit Committee; triennial comprehensive review report to the Board Risk Committee; signed risk management declaration (with any qualification and remediation steps).
Max penalty
CPS 220 sets no fixed monetary penalty. It is made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995 and Private Health Insurance (Prudential Supervision) Act 2015, so a breach exposes the institution to APRA's supervisory and enforcement powers under those Acts. A Board must qualify its declaration where there has been a significant breach of the framework
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Prudential Standard CPS 220 Risk Management, in force since 1 July 2019, requires every ADI, general insurer, life insurer and private health insurer to maintain a risk management framework covering all material risks, consistent with its strategic objectives and business plan. The Board is ultimately responsible. It must approve a risk appetite statement setting risk tolerances for each material risk, a risk management strategy and a rolling business plan of at least three years that is reviewed annually. The institution must have a designated risk management function led by a Chief Risk Officer who is independent of business lines and finance, cannot be the CEO, CFO, Appointed Actuary or Head of Internal Audit, and has unfettered access to the Board Risk Committee. Internal or external audit must review the framework at least annually, and operationally independent persons must conduct a comprehensive review at least every three years. The Board then makes an annual risk management declaration to APRA.
Enforced by
Industries
Topics
Related
- CWLTHComply with APRA CPS 230 (Operational Risk Management)APRA-regulated entities must manage operational risk including a comprehensive third-party / outsourcing register from 1 July 2025.
- CWLTHComply with APRA CPS 234 (Information Security)APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats.
- CWLTHAdopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)Covered critical infrastructure entities must adopt a CIRMP addressing cyber, physical, personnel, and supply-chain hazards.
Frequently asked questions
- Who must comply with APRA CPS 220 (Risk Management)?
- ADIs and authorised banking NOHCs, general insurers and authorised insurance NOHCs, life companies (including friendly societies) and registered life NOHCs, and private health insurers, together with the Head of a Level 2 or Level 3 group. Superannuation trustees are covered by the separate SPS 220, not CPS 220.
- What triggers APRA CPS 220 (Risk Management)?
- Being an APRA-regulated institution in the banking, general insurance, life insurance or private health insurance industries, or the Head of a group of such institutions.
- When is APRA CPS 220 (Risk Management) due?
- Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.
- What is the maximum penalty for APRA CPS 220 (Risk Management)?
- CPS 220 sets no fixed monetary penalty. It is made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995 and Private Health Insurance (Prudential Supervision) Act 2015, so a breach exposes the institution to APRA's supervisory and enforcement powers under those Acts. A Board must qualify its declaration where there has been a significant breach of the framework
- What evidence is required for APRA CPS 220 (Risk Management)?
- Board-approved risk appetite statement, risk management strategy and three-year business plan; CRO appointment and reporting lines; management information system reports on material risks; annual audit review report to the Board Audit Committee; triennial comprehensive review report to the Board Risk Committee; signed risk management declaration (with any qualification and remediation steps).
Source: https://www.apra.gov.au/standards/cps-220. Rules Mate is not a law firm. Always verify against the live regulator source before acting.