APRA CPS 220 Risk Management
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assurance
The institution must ensure that compliance with and the effectiveness of the risk management framework is reviewed by internal or external audit at least annually, with results reported to the Board Audit Committee, the senior officer outside Australia or the Compliance Committee as relevant.
- Annual audit review reports on the framework
- Reporting records to the relevant committee
- Audit scope covering both compliance and effectiveness
- Review covers compliance only and not effectiveness
- Results not reported to the required committee
Attestation
The Board must make an annual risk management declaration to APRA satisfying the requirements of Attachment A, signed by the chairperson of the Board and the chairperson of the Board Risk Committee, or for a Category C insurer, foreign ADI or EFLIC by the senior officer outside Australia or two members of the Compliance Committee as relevant.
- Signed risk management declarations
- Evidence supporting each Attachment A assertion
- Signatory authority records
- Declaration signed without underlying assurance evidence
- Wrong signatories for the entity type
The Board must qualify the risk management declaration where there has been any significant breach of or material deviation from the risk management framework or the requirements of Attachment A, and any qualification must describe the cause and circumstances and the steps taken or proposed to remedy the problem.
- Qualified declarations where applicable
- Cause and circumstance descriptions with remediation steps
- Evidence the qualification decision was considered against the breach register
- Declaration signed unqualified despite an open significant breach
- Qualification given without describing cause or remedy
Unless APRA approves otherwise the institution must submit its risk management declaration to APRA within four months of its annual balance date if it is an ADI or authorised banking non operating holding company that is not a disclosing entity under the Corporations Act, within four months if it is a Level 3 Head, and within three months of its annual balance date for all other APRA regulated institutions.
- Submission records with balance date and submission date
- Determination of the applicable deadline for the entity type
- Any APRA approval of an alternative timeframe
- Three month deadline applied where four months was assumed or the reverse
- Deadline tracked from financial statement signing rather than balance date
Board Oversight
The Board is ultimately responsible for the risk management framework and for overseeing its operation by management, and must ensure it sets risk appetite and approves the risk appetite statement and risk management strategy, forms a view of risk culture and drives any changes needed, has senior management monitor and manage all material risks consistently with approved strategy, appetite and policies, has an operational structure that supports effective risk management, has risk taking policies and processes consistent with the strategy and appetite, dedicates sufficient resources to risk management, and recognises the uncertainties, limitations and assumptions in measuring each material risk.
- Board charter and terms of reference
- Board approvals of the risk appetite statement and risk management strategy
- Board records forming a view on risk culture and any resulting actions
- Resourcing decisions for risk management
- Risk culture never formally considered by the Board
- Measurement limitations and assumptions not surfaced to the Board
CRO
The institution must designate a person as Chief Risk Officer responsible for the risk management function, who must be involved in and have authority to effectively challenge activities and decisions that could materially affect the institution risk profile.
- CRO appointment records and position description
- Evidence of CRO involvement in material decisions
- Records of challenge exercised at committee or Board level
- CRO informed of decisions rather than involved in them
- No record of challenge ever being exercised
The Chief Risk Officer must be independent of business lines, other revenue generating responsibilities and the finance function, and must not be the Chief Executive Officer, Chief Financial Officer, Appointed Actuary or Head of Internal Audit.
- CRO position description and reporting lines
- Declarations confirming none of the barred roles are held
- Remuneration structure evidencing independence from revenue generation
- CRO carrying a revenue or finance responsibility
- Combined CRO and Head of Internal Audit role
The Chief Risk Officer must report directly to the Chief Executive Officer and must have regular and unfettered access to the Board and the Board Risk Committee.
- Organisation chart showing the direct reporting line to the Chief Executive Officer
- Records of CRO attendance at Board and Board Risk Committee meetings
- Evidence of access without management filtering
- CRO reporting through the Chief Financial Officer or Chief Operating Officer
- Board access only by invitation
Change
Where a material change to the size, business mix and complexity of operations is identified outside the triennial comprehensive review, the institution must assess at that time whether the framework needs amendment or review to take account of it.
- Trigger criteria for material change
- Assessments performed at the time of each material change
- Resulting framework amendments
- Waiting for the next scheduled review after a major acquisition
- No defined trigger for what counts as material change
Documentation
The policies and procedures the risk management strategy is required to list must include the process for identifying and assessing material risks and controls, for validating, approving and using risk measurement models, for establishing, implementing and testing mitigation strategies and control mechanisms, for monitoring, communicating and reporting risk issues including escalation of material events and incidents, for identifying, monitoring and managing potential and actual conflicts of interest, the mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements, the process for ensuring consistency across the framework components, the process for establishing and maintaining contingency arrangements including robust and credible recovery plans where warranted for operating the framework in stressed conditions, and the process for reviewing the framework.
- Policy and procedure set mapped against each of the nine required processes
- Model validation and approval records
- Conflicts of interest and prudential compliance monitoring procedures
- Model validation process absent
- Contingency arrangements for framework operation under stress not documented
The institution must monitor the date each policy or procedure was last revised, the date it next falls due for review, and who is responsible for that review.
- Policy register recording last revision date, next review date and review owner
- Overdue review reporting
- Evidence the register covers the full policy set
- Register incomplete or unowned
- Overdue reviews not escalated
Group
Where an institution within the group that is not an APRA regulated institution engages in business activities that may pose a material risk to the group, the Head of the group must ensure the risk management framework addresses the risks that entity poses to the group and to depositors, policyholders or RSE beneficiaries.
- Inventory of non regulated group entities and their activities
- Materiality assessments of the risk they pose
- Framework coverage evidence for those entities
- Framework scope limited to regulated entities
- Contagion from non regulated activities unassessed
Where the institution is part of a group and any element of its risk management framework is controlled or influenced by another group entity, the framework must specifically take account of risks arising from the group framework and must clearly identify whether it is wholly or partly derived from group frameworks, policies, procedures or functions, the linkages and significant differences between the institution and group frameworks, how those linkages and differences change the institution risk profile, and the process for monitoring by or reporting to the group on risk management including key procedures, reporting frequency and the approach to reviews.
- Documented mapping of group derived framework elements
- Gap and difference analysis between institution and group frameworks
- Group reporting and review protocols
- Group policies adopted wholesale with no difference analysis
- Effect of group linkages on the institution risk profile not assessed
As part of the group risk management framework the Head of a group must maintain processes coordinating the identification, measurement, evaluation, monitoring, reporting and control or mitigation of all material risks across the group in normal times and in periods of stress, and must ensure its Board has a comprehensive group wide view of all material risks including the roles and relationships of subsidiaries to one another and to the Head.
- Group risk coordination processes
- Group wide risk reporting to the Head Board
- Subsidiary role and relationship mapping
- Aggregation works in normal conditions but not under stress
- Intra group relationships not documented for the Board
The group risk management function need not sit with the Head of a group and may be located elsewhere in the group, but the group Chief Risk Officer must not hold any of the roles that a Chief Risk Officer is barred from holding for any institution within the group.
- Group CRO appointment and role records
- Conflict checks against the barred roles across group institutions
- Location and reporting lines of the group risk function
- Group CRO also acting as a subsidiary Chief Financial Officer or Head of Internal Audit
- Role conflicts checked at appointment only
The Head of a group must maintain a Board approved liquidity management policy for the group that adequately and consistently identifies, measures, monitors and manages material liquidity risks, includes a strategy ensuring the group has enough liquidity to meet obligations as they fall due including in stressed conditions, and outlines processes for identifying existing and potential constraints on transferring funds within the group, and must submit a copy to APRA as soon as practicable and no more than 10 business days after Board approval.
- Board approved group liquidity management policy
- Analysis of constraints on intra group fund transfers
- Submission records to APRA within 10 business days of approval
- Fund transfer constraints such as ring fencing not identified
- Policy approved but submission to APRA missed or late
Operating Model
The institution must have a designated compliance function assisting senior management to effectively manage compliance risks, adequately staffed by appropriately trained and competent people with sufficient authority to perform their role and with a reporting line independent of business lines.
- Compliance function mandate and reporting lines
- Staffing, training and competence records
- Evidence of authority to act
- Compliance embedded in and reporting to a business line
- Function under resourced relative to the compliance risk profile
RMF
The institution must maintain a risk management framework that lets it develop and implement strategies, policies, procedures and controls for the different types of material risk and that gives the Board a comprehensive institution wide view of material risks.
- Risk management framework documentation
- Board reporting evidencing an institution wide view
- Approval and version history
- Framework described only at policy level with no operating detail
- Board view assembled per business line and never consolidated
The risk management framework must be consistent with the business plan the institution is required to maintain.
- Consistency assessment between the framework and the business plan
- Records of framework changes following business plan revision
- Board consideration of alignment
- Business plan revised without revisiting the framework
- Alignment asserted with no assessment
The risk management framework must provide a structure for identifying and managing each material risk so the institution is prudently and soundly managed, having regard to the size, business mix and complexity of its operations.
- Framework structure documentation showing treatment of each material risk
- Proportionality rationale referencing size, business mix and complexity
- Evidence each identified material risk has an owner and a treatment path
- Material risks identified but with no defined management structure
- Proportionality claimed without analysis
The risk management framework must include at least a risk appetite statement, a risk management strategy, a business plan, policies and procedures supporting clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout the institution, a designated risk management function meeting the required criteria, an Internal Capital Adequacy Assessment Process, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process confirming the framework is effective.
- Framework inventory evidencing each of the eight required components
- ICAAP documentation and its linkage to the framework
- Reporting structure and role documentation
- ICAAP maintained separately with no linkage to the framework
- No defined review process inside the framework
Regulator
The institution must notify APRA as soon as practicable and no more than 10 business days after becoming aware of a significant breach of or material deviation from its risk management framework, or that the framework did not adequately address a material risk.
- Notification records with awareness and submission dates
- Breach and deviation register with significance assessments
- Escalation path from the risk function to the notification decision
- Clock started at investigation close rather than awareness
- No definition of what makes a breach significant
The Head of a group must meet the notification duties of this standard in respect of the group risk management framework, except where an APRA regulated institution within the group has already notified APRA of that information.
- Group level notification records
- Evidence of coordination to avoid or rely on subsidiary notifications
- Register of what was notified by whom
- Each entity assuming another has notified
- No group level view of notification obligations
On adoption and after any material revision the institution must submit to APRA a copy of its risk appetite statement, business plan and risk management strategy as soon as practicable and no more than 10 business days after Board approval.
- Submission records for each of the three documents with Board approval and submission dates
- Definition of what constitutes a material revision
- Version control linking each submission to an approved version
- Material revisions treated as minor so never submitted
- Documents submitted late against the 10 business day deadline
The institution must notify APRA as soon as practicable and no more than 10 business days after becoming aware of any material or prospective material change to its size, business mix or complexity.
- Notification records with awareness and submission dates
- Criteria for identifying material and prospective material change
- Linkage from strategic and corporate development activity to the notification process
- Prospective changes not notified because they had not completed
- No defined threshold for materiality of change
Where the institution conducts business in a jurisdiction outside Australia it must notify APRA as soon as practicable and no more than 10 business days after becoming aware that its right to conduct business there has been materially affected by that jurisdiction law or has ceased.
- Register of jurisdictions in which business is conducted
- Monitoring of foreign licensing and legal status
- Notification records with awareness and submission dates
- No monitoring of foreign licence status
- Branch or subsidiary status changes not routed to the notification process
Reporting
The management information system must give the Board, board committees and senior management regular, accurate and timely information on the institution risk profile, and must rest on a robust data framework enabling aggregation of exposures and risk measures across business lines, prompt reporting of limit breaches and forward looking scenario analysis and stress testing, with data quality adequate for timely and accurate measurement, assessment and reporting and sound enough to base decisions on.
- Risk reporting suite and distribution records
- Data framework and aggregation architecture documentation
- Data quality controls and limit breach reporting evidence
- Manual aggregation preventing prompt reporting
- Data quality not assessed against decision making needs
Review
In addition to the annual audit review the institution must ensure the appropriateness, effectiveness and adequacy of its risk management framework is comprehensively reviewed at least every three years by operationally independent, appropriately trained and competent persons who may include external consultants, with results reported to the Board Risk Committee, the senior officer outside Australia or the Compliance Committee as relevant.
- Comprehensive review reports at least triennial
- Reviewer independence and competence evidence
- Reporting records to the relevant committee
- Comprehensive review merged into the annual audit review
- Reviewer independence not evidenced
The scope of the comprehensive review must have regard to the size, business mix and complexity of the institution, the extent of any change to its operations or risk appetite, and any changes in the external environment in which it operates.
- Documented review scope with the scoping rationale
- Analysis of operational, appetite and external environment change
- Approval of the scope before the review begins
- Identical scope reused each cycle
- External environment change not considered in scoping
The review of the risk management framework must at least assess whether the framework is implemented and effective, whether it remains appropriate given the current business plan, whether it remains consistent with the Board risk appetite, whether it is supported by adequate resources, and whether the risk management strategy accurately documents the key elements of the framework that give effect to the strategy for managing risk.
- Review reports addressing each of the five required assessments
- Findings and management responses
- Evidence of resource adequacy assessment
- Review reports on implementation but not on effectiveness
- Resource adequacy never assessed
Risk Appetite
The institution must maintain an appropriate, clear and concise risk appetite statement addressing its material risks, with the Board responsible for setting risk appetite and required to approve the statement.
- Approved risk appetite statement
- Board approval records
- Coverage mapping against the material risk categories
- Statement covers financial risks only
- Approved once and never refreshed
The risk appetite statement must convey at least the degree of risk the institution will accept in pursuit of its strategic objectives and business plan having regard to the interests of depositors or policyholders, for each material risk the maximum level it is willing to operate within expressed as a risk limit based on appetite, profile and capital strength, the process for setting risk tolerances at an appropriate level based on estimated breach impact and likelihood, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.
- Risk appetite statement mapped against each of the five required elements
- Quantified risk limits per material risk
- Breach monitoring and escalation records
- Qualitative appetite with no expressed limits
- No defined action on tolerance breach
Risk Function
The institution must have a designated risk management function that assists the Board, board committees and senior management to maintain the framework, is proportionate to size, business mix and complexity, is operationally independent, has the authority and reporting lines to act effectively and independently, is staffed with people of appropriate experience and qualifications holding clearly defined roles, has access to every part of the institution capable of generating material risk including information technology systems and systems development resources, and is required to notify the Board of any significant breach of or material deviation from the framework.
- Risk function mandate and reporting lines
- Staffing, experience and qualification records
- Evidence of access to IT systems and development resources
- Records of breach notifications made to the Board
- Function lacks access to technology development activity
- Independence compromised by dual business responsibilities
Risk Identification
The risk management framework must at a minimum address credit risk, market and investment risk, liquidity risk, insurance risk, operational risk, risks arising from the strategic objectives and business plans, and any other risk that alone or in combination may have a material impact on the institution.
- Risk taxonomy mapped to each required category
- Justification where a category is not applicable
- Assessment of combined risk effects
- Strategic and business plan risk omitted
- Risks assessed only in isolation and never in combination
The institution must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects its risk profile.
- Strategic risk assessments tied to the business plan
- Evidence those risks are managed through the framework
- Reassessment records following plan changes
- Strategic risks listed but not managed through the framework
- Plan changes made without reassessing the risk profile
Strategy
The institution must maintain a risk management strategy addressing each of the material risk categories the framework is required to cover, approved by the Board.
- Approved risk management strategy document
- Board approval records
- Coverage mapping against each material risk category
- Strategy silent on one or more required risk categories
- Document not kept current with the framework
The risk management strategy must at least describe each material risk identified and the approach to managing it, list the policies and procedures dealing with risk management matters, summarise the role and responsibilities of the risk management function, describe the risk governance relationship between the Board, board committees and senior management with respect to the framework, and outline the approach to ensuring all persons in the institution are aware of the framework and to instilling an appropriate risk culture.
- Risk management strategy mapped against each required element
- Policy and procedure inventory referenced by the strategy
- Risk awareness and culture approach with supporting activity records
- Strategy omits the risk culture and awareness approach
- Policy list stale relative to the actual policy set
The institution must maintain a written plan setting out its approach to implementing its strategic objectives.
- Current written business plan
- Evidence it sets out the approach to implementing strategic objectives
- Approval records
- Strategy deck held in place of a written business plan
- Plan not maintained between planning cycles
The business plan must be a rolling plan of at least three years reviewed at least annually with results of the review reported to the Board, must cover the entirety of the institution and must be approved by the Board.
- Business plan showing a rolling horizon of at least three years
- Annual review records and Board reporting
- Board approval evidence and whole of institution coverage
- Plan covers a single year
- Divisions or subsidiaries excluded from coverage
Stress Testing
The risk management framework must include forward looking scenario analysis and stress testing programs proportionate to the size, business mix and complexity of the institution and built on severe but plausible assumptions.
- Stress testing and scenario analysis program documentation
- Assumption sets with severity justification
- Results and management actions arising
- Scenarios not severe enough to be informative
- Results produced but never acted on
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA CPS 220 Risk Management framework page.