Who must comply with APRA CPS 220 (Risk Management)?
The applicability test for Comply with APRA CPS 220 (Risk Management) (APRA), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has APRA regulation.
What the obligation is
APRA-regulated entities must have a comprehensive risk management framework.
Prudential Standard CPS 220 Risk Management, in force since 1 July 2019, requires every ADI, general insurer, life insurer and private health insurer to maintain a risk management framework covering all material risks, consistent with its strategic objectives and business plan. The Board is ultimately responsible. It must approve a risk appetite statement setting risk tolerances for each material risk, a risk management strategy and a rolling business plan of at least three years that is reviewed annually. The institution must have a designated risk management function led by a Chief Risk Officer who is independent of business lines and finance, cannot be the CEO, CFO, Appointed Actuary or Head of Internal Audit, and has unfettered access to the Board Risk Committee. Internal or external audit must review the framework at least annually, and operationally independent persons must conduct a comprehensive review at least every three years. The Board then makes an annual risk management declaration to APRA.
The applicability test
Applies when the business has APRA regulation.
How the regulator frames it: ADIs and authorised banking NOHCs, general insurers and authorised insurance NOHCs, life companies (including friendly societies) and registered life NOHCs, and private health insurers, together with the Head of a Level 2 or Level 3 group. Superannuation trustees are covered by the separate SPS 220, not CPS 220.
What triggers it: Being an APRA-regulated institution in the banking, general insurance, life insurance or private health insurance industries, or the Head of a group of such institutions.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (3 of 35: yes; 32 of 35: no).
| Industry | Answer |
|---|---|
| Banks & ADIs | Yes |
| Superannuation trustees | Yes |
| Private health insurers | Yes |
| No | 32 other industries |
Business structure and size
Structure does not change the answer in the 3 industries it can reach: for every structure the answer is "yes".
Size does not change the answer in the 3 industries it can reach: at every size band the answer is "yes".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in banks & adis with 6–19 employees, turnover $1M–$3M: applies. ADI — APRA-regulated.
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires APRA regulation.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business is regulated by APRA: it then applies (APRA-regulated).
What you must do, and when
- When due
- Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.
- Frequency
- Annual
- Evidence to keep
- Board-approved risk appetite statement, risk management strategy and three-year business plan; CRO appointment and reporting lines; management information system reports on material risks; annual audit review report to the Board Audit Committee; triennial comprehensive review report to the Board Risk Committee; signed risk management declaration (with any qualification and remediation steps).
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: CPS 220 sets no fixed monetary penalty. It is made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995 and Private Health Insurance (Prudential Supervision) Act 2015, so a breach exposes the institution to APRA's supervisory and enforcement powers under those Acts. A Board must qualify its declaration where there has been a significant breach of the framework.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so do these 4: the engine uses the same rule for each.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
Where it sits in the corpus
Rules Mate tracks 3 published obligations tagged "apra", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is a annual obligation.
Regulator, legislation and tools
Regulated by Australian Prudential Regulation Authority.
APRA: Prudential regulator of banks (ADIs), insurers (general, life, private health), and superannuation funds. Sets and enforces CPS standards including CPS 234 (information security) and CPS 230 (operational risk).
Free tools that help with this obligation:
Questions
- Who must comply with APRA CPS 220 (Risk Management)?
- Applies when the business has APRA regulation.
- Do sole traders need to comply with APRA CPS 220 (Risk Management)?
- Yes. Looking in the 3 industries it can reach and every size band, the engine's answer for a sole trader is: yes.
- Do businesses with 1–5 employees need to comply with APRA CPS 220 (Risk Management)?
- Yes (1–5 employees, turnover $100K–$1M).
- When is "Comply with APRA CPS 220 (Risk Management)" due?
- Ongoing. Risk management declaration lodged within three months of the annual balance date (four months for an ADI or banking NOHC that is not a disclosing entity, and for a Level 3 Head). Risk appetite statement, business plan and risk management strategy sent to APRA within 10 business days of Board approval of a new or materially revised version. Annual audit review; comprehensive review every three years.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.