Skip to main content
Rules Mate

Comply with APRA CPS 220 (Risk Management)

APRA-regulated entities must have a comprehensive risk management framework.

criticalcurrentannual

Who must comply

ADIs and authorised banking NOHCs, general insurers and authorised insurance NOHCs, life companies (including friendly societies) and registered life NOHCs, and private health insurers, together with the Head of a Level 2 or Level 3 group. Superannuation trustees are covered by the separate SPS 220, not CPS 220.

What triggers it

Being an APRA-regulated institution in the banking, general insurance, life insurance or private health insurance industries, or the Head of a group of such institutions.

When due

Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.

Evidence required

Board-approved risk appetite statement, risk management strategy and three-year business plan; CRO appointment and reporting lines; management information system reports on material risks; annual audit review report to the Board Audit Committee; triennial comprehensive review report to the Board Risk Committee; signed risk management declaration (with any qualification and remediation steps).

Max penalty

CPS 220 sets no fixed monetary penalty. It is made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995 and Private Health Insurance (Prudential Supervision) Act 2015, so a breach exposes the institution to APRA's supervisory and enforcement powers under those Acts. A Board must qualify its declaration where there has been a significant breach of the framework

Who must comply with this? The applicability test by industry, business structure and size.

Summary

Prudential Standard CPS 220 Risk Management, in force since 1 July 2019, requires every ADI, general insurer, life insurer and private health insurer to maintain a risk management framework covering all material risks, consistent with its strategic objectives and business plan. The Board is ultimately responsible. It must approve a risk appetite statement setting risk tolerances for each material risk, a risk management strategy and a rolling business plan of at least three years that is reviewed annually. The institution must have a designated risk management function led by a Chief Risk Officer who is independent of business lines and finance, cannot be the CEO, CFO, Appointed Actuary or Head of Internal Audit, and has unfettered access to the Board Risk Committee. Internal or external audit must review the framework at least annually, and operationally independent persons must conduct a comprehensive review at least every three years. The Board then makes an annual risk management declaration to APRA.

Enforced by

Industries

Topics

aprarisk-management

Related

Frequently asked questions

Who must comply with APRA CPS 220 (Risk Management)?
ADIs and authorised banking NOHCs, general insurers and authorised insurance NOHCs, life companies (including friendly societies) and registered life NOHCs, and private health insurers, together with the Head of a Level 2 or Level 3 group. Superannuation trustees are covered by the separate SPS 220, not CPS 220.
What triggers APRA CPS 220 (Risk Management)?
Being an APRA-regulated institution in the banking, general insurance, life insurance or private health insurance industries, or the Head of a group of such institutions.
When is APRA CPS 220 (Risk Management) due?
Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.
What is the maximum penalty for APRA CPS 220 (Risk Management)?
CPS 220 sets no fixed monetary penalty. It is made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995 and Private Health Insurance (Prudential Supervision) Act 2015, so a breach exposes the institution to APRA's supervisory and enforcement powers under those Acts. A Board must qualify its declaration where there has been a significant breach of the framework
What evidence is required for APRA CPS 220 (Risk Management)?
Board-approved risk appetite statement, risk management strategy and three-year business plan; CRO appointment and reporting lines; management information system reports on material risks; annual audit review report to the Board Audit Committee; triennial comprehensive review report to the Board Risk Committee; signed risk management declaration (with any qualification and remediation steps).

Source: https://www.apra.gov.au/standards/cps-220. Rules Mate is not a law firm. Always verify against the live regulator source before acting.