Skip to content

Evidence request lists

APRA CPS 220 Risk Management

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assurance

CPS220-11
Annual Audit Review of the Framework

The institution must ensure that compliance with and the effectiveness of the risk management framework is reviewed by internal or external audit at least annually, with results reported to the Board Audit Committee, the senior officer outside Australia or the Compliance Committee as relevant.

Artefacts an auditor will ask for
  • Annual audit review reports on the framework
  • Reporting records to the relevant committee
  • Audit scope covering both compliance and effectiveness
Where this commonly fails
  • Review covers compliance only and not effectiveness
  • Results not reported to the required committee

Attestation

CPS220-20
Annual Board Risk Management Declaration

The Board must make an annual risk management declaration to APRA satisfying the requirements of Attachment A, signed by the chairperson of the Board and the chairperson of the Board Risk Committee, or for a Category C insurer, foreign ADI or EFLIC by the senior officer outside Australia or two members of the Compliance Committee as relevant.

Artefacts an auditor will ask for
  • Signed risk management declarations
  • Evidence supporting each Attachment A assertion
  • Signatory authority records
Where this commonly fails
  • Declaration signed without underlying assurance evidence
  • Wrong signatories for the entity type
CPS220-P50
Qualification of the Risk Management Declaration

The Board must qualify the risk management declaration where there has been any significant breach of or material deviation from the risk management framework or the requirements of Attachment A, and any qualification must describe the cause and circumstances and the steps taken or proposed to remedy the problem.

Artefacts an auditor will ask for
  • Qualified declarations where applicable
  • Cause and circumstance descriptions with remediation steps
  • Evidence the qualification decision was considered against the breach register
Where this commonly fails
  • Declaration signed unqualified despite an open significant breach
  • Qualification given without describing cause or remedy
CPS220-P51
Submission Deadline for the Risk Management Declaration

Unless APRA approves otherwise the institution must submit its risk management declaration to APRA within four months of its annual balance date if it is an ADI or authorised banking non operating holding company that is not a disclosing entity under the Corporations Act, within four months if it is a Level 3 Head, and within three months of its annual balance date for all other APRA regulated institutions.

Artefacts an auditor will ask for
  • Submission records with balance date and submission date
  • Determination of the applicable deadline for the entity type
  • Any APRA approval of an alternative timeframe
Where this commonly fails
  • Three month deadline applied where four months was assumed or the reverse
  • Deadline tracked from financial statement signing rather than balance date

Board Oversight

CPS220-02
Board Responsibility for the Risk Management Framework

The Board is ultimately responsible for the risk management framework and for overseeing its operation by management, and must ensure it sets risk appetite and approves the risk appetite statement and risk management strategy, forms a view of risk culture and drives any changes needed, has senior management monitor and manage all material risks consistently with approved strategy, appetite and policies, has an operational structure that supports effective risk management, has risk taking policies and processes consistent with the strategy and appetite, dedicates sufficient resources to risk management, and recognises the uncertainties, limitations and assumptions in measuring each material risk.

Artefacts an auditor will ask for
  • Board charter and terms of reference
  • Board approvals of the risk appetite statement and risk management strategy
  • Board records forming a view on risk culture and any resulting actions
  • Resourcing decisions for risk management
Where this commonly fails
  • Risk culture never formally considered by the Board
  • Measurement limitations and assumptions not surfaced to the Board

CRO

CPS220-09
Designation of a Chief Risk Officer

The institution must designate a person as Chief Risk Officer responsible for the risk management function, who must be involved in and have authority to effectively challenge activities and decisions that could materially affect the institution risk profile.

Artefacts an auditor will ask for
  • CRO appointment records and position description
  • Evidence of CRO involvement in material decisions
  • Records of challenge exercised at committee or Board level
Where this commonly fails
  • CRO informed of decisions rather than involved in them
  • No record of challenge ever being exercised
CPS220-P39
Independence of the Chief Risk Officer

The Chief Risk Officer must be independent of business lines, other revenue generating responsibilities and the finance function, and must not be the Chief Executive Officer, Chief Financial Officer, Appointed Actuary or Head of Internal Audit.

Artefacts an auditor will ask for
  • CRO position description and reporting lines
  • Declarations confirming none of the barred roles are held
  • Remuneration structure evidencing independence from revenue generation
Where this commonly fails
  • CRO carrying a revenue or finance responsibility
  • Combined CRO and Head of Internal Audit role
CPS220-P40
Chief Risk Officer Reporting Lines and Board Access

The Chief Risk Officer must report directly to the Chief Executive Officer and must have regular and unfettered access to the Board and the Board Risk Committee.

Artefacts an auditor will ask for
  • Organisation chart showing the direct reporting line to the Chief Executive Officer
  • Records of CRO attendance at Board and Board Risk Committee meetings
  • Evidence of access without management filtering
Where this commonly fails
  • CRO reporting through the Chief Financial Officer or Chief Operating Officer
  • Board access only by invitation

Change

CPS220-P48
Assessment Following Material Change Outside the Review Cycle

Where a material change to the size, business mix and complexity of operations is identified outside the triennial comprehensive review, the institution must assess at that time whether the framework needs amendment or review to take account of it.

Artefacts an auditor will ask for
  • Trigger criteria for material change
  • Assessments performed at the time of each material change
  • Resulting framework amendments
Where this commonly fails
  • Waiting for the next scheduled review after a major acquisition
  • No defined trigger for what counts as material change

Documentation

CPS220-P35
Required Content of Risk Management Policies and Procedures

The policies and procedures the risk management strategy is required to list must include the process for identifying and assessing material risks and controls, for validating, approving and using risk measurement models, for establishing, implementing and testing mitigation strategies and control mechanisms, for monitoring, communicating and reporting risk issues including escalation of material events and incidents, for identifying, monitoring and managing potential and actual conflicts of interest, the mechanisms for monitoring and ensuring ongoing compliance with all prudential requirements, the process for ensuring consistency across the framework components, the process for establishing and maintaining contingency arrangements including robust and credible recovery plans where warranted for operating the framework in stressed conditions, and the process for reviewing the framework.

Artefacts an auditor will ask for
  • Policy and procedure set mapped against each of the nine required processes
  • Model validation and approval records
  • Conflicts of interest and prudential compliance monitoring procedures
Where this commonly fails
  • Model validation process absent
  • Contingency arrangements for framework operation under stress not documented
CPS220-P36
Monitoring of Policy Review Dates and Ownership

The institution must monitor the date each policy or procedure was last revised, the date it next falls due for review, and who is responsible for that review.

Artefacts an auditor will ask for
  • Policy register recording last revision date, next review date and review owner
  • Overdue review reporting
  • Evidence the register covers the full policy set
Where this commonly fails
  • Register incomplete or unowned
  • Overdue reviews not escalated

Group

CPS220-17
Group Framework Coverage of Non Regulated Group Entities

Where an institution within the group that is not an APRA regulated institution engages in business activities that may pose a material risk to the group, the Head of the group must ensure the risk management framework addresses the risks that entity poses to the group and to depositors, policyholders or RSE beneficiaries.

Artefacts an auditor will ask for
  • Inventory of non regulated group entities and their activities
  • Materiality assessments of the risk they pose
  • Framework coverage evidence for those entities
Where this commonly fails
  • Framework scope limited to regulated entities
  • Contagion from non regulated activities unassessed
CPS220-P12
Identification of Group Derived Framework Elements

Where the institution is part of a group and any element of its risk management framework is controlled or influenced by another group entity, the framework must specifically take account of risks arising from the group framework and must clearly identify whether it is wholly or partly derived from group frameworks, policies, procedures or functions, the linkages and significant differences between the institution and group frameworks, how those linkages and differences change the institution risk profile, and the process for monitoring by or reporting to the group on risk management including key procedures, reporting frequency and the approach to reviews.

Artefacts an auditor will ask for
  • Documented mapping of group derived framework elements
  • Gap and difference analysis between institution and group frameworks
  • Group reporting and review protocols
Where this commonly fails
  • Group policies adopted wholesale with no difference analysis
  • Effect of group linkages on the institution risk profile not assessed
CPS220-P14
Head of Group Coordination of Material Risks

As part of the group risk management framework the Head of a group must maintain processes coordinating the identification, measurement, evaluation, monitoring, reporting and control or mitigation of all material risks across the group in normal times and in periods of stress, and must ensure its Board has a comprehensive group wide view of all material risks including the roles and relationships of subsidiaries to one another and to the Head.

Artefacts an auditor will ask for
  • Group risk coordination processes
  • Group wide risk reporting to the Head Board
  • Subsidiary role and relationship mapping
Where this commonly fails
  • Aggregation works in normal conditions but not under stress
  • Intra group relationships not documented for the Board
CPS220-P15
Restriction on the Group Chief Risk Officer Role

The group risk management function need not sit with the Head of a group and may be located elsewhere in the group, but the group Chief Risk Officer must not hold any of the roles that a Chief Risk Officer is barred from holding for any institution within the group.

Artefacts an auditor will ask for
  • Group CRO appointment and role records
  • Conflict checks against the barred roles across group institutions
  • Location and reporting lines of the group risk function
Where this commonly fails
  • Group CRO also acting as a subsidiary Chief Financial Officer or Head of Internal Audit
  • Role conflicts checked at appointment only
CPS220-P17
Group Liquidity Management Policy

The Head of a group must maintain a Board approved liquidity management policy for the group that adequately and consistently identifies, measures, monitors and manages material liquidity risks, includes a strategy ensuring the group has enough liquidity to meet obligations as they fall due including in stressed conditions, and outlines processes for identifying existing and potential constraints on transferring funds within the group, and must submit a copy to APRA as soon as practicable and no more than 10 business days after Board approval.

Artefacts an auditor will ask for
  • Board approved group liquidity management policy
  • Analysis of constraints on intra group fund transfers
  • Submission records to APRA within 10 business days of approval
Where this commonly fails
  • Fund transfer constraints such as ring fencing not identified
  • Policy approved but submission to APRA missed or late

Operating Model

CPS220-P43
Designated Compliance Function

The institution must have a designated compliance function assisting senior management to effectively manage compliance risks, adequately staffed by appropriately trained and competent people with sufficient authority to perform their role and with a reporting line independent of business lines.

Artefacts an auditor will ask for
  • Compliance function mandate and reporting lines
  • Staffing, training and competence records
  • Evidence of authority to act
Where this commonly fails
  • Compliance embedded in and reporting to a business line
  • Function under resourced relative to the compliance risk profile

RMF

CPS220-04
Maintenance of a Risk Management Framework

The institution must maintain a risk management framework that lets it develop and implement strategies, policies, procedures and controls for the different types of material risk and that gives the Board a comprehensive institution wide view of material risks.

Artefacts an auditor will ask for
  • Risk management framework documentation
  • Board reporting evidencing an institution wide view
  • Approval and version history
Where this commonly fails
  • Framework described only at policy level with no operating detail
  • Board view assembled per business line and never consolidated
CPS220-P21
Consistency of the Framework with the Business Plan

The risk management framework must be consistent with the business plan the institution is required to maintain.

Artefacts an auditor will ask for
  • Consistency assessment between the framework and the business plan
  • Records of framework changes following business plan revision
  • Board consideration of alignment
Where this commonly fails
  • Business plan revised without revisiting the framework
  • Alignment asserted with no assessment
CPS220-P22
Framework Structure for Managing Each Material Risk

The risk management framework must provide a structure for identifying and managing each material risk so the institution is prudently and soundly managed, having regard to the size, business mix and complexity of its operations.

Artefacts an auditor will ask for
  • Framework structure documentation showing treatment of each material risk
  • Proportionality rationale referencing size, business mix and complexity
  • Evidence each identified material risk has an owner and a treatment path
Where this commonly fails
  • Material risks identified but with no defined management structure
  • Proportionality claimed without analysis
CPS220-P23
Minimum Contents of the Risk Management Framework

The risk management framework must include at least a risk appetite statement, a risk management strategy, a business plan, policies and procedures supporting clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout the institution, a designated risk management function meeting the required criteria, an Internal Capital Adequacy Assessment Process, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process confirming the framework is effective.

Artefacts an auditor will ask for
  • Framework inventory evidencing each of the eight required components
  • ICAAP documentation and its linkage to the framework
  • Reporting structure and role documentation
Where this commonly fails
  • ICAAP maintained separately with no linkage to the framework
  • No defined review process inside the framework

Regulator

CPS220-19
APRA Notification of Framework Breach within 10 Business Days

The institution must notify APRA as soon as practicable and no more than 10 business days after becoming aware of a significant breach of or material deviation from its risk management framework, or that the framework did not adequately address a material risk.

Artefacts an auditor will ask for
  • Notification records with awareness and submission dates
  • Breach and deviation register with significance assessments
  • Escalation path from the risk function to the notification decision
Where this commonly fails
  • Clock started at investigation close rather than awareness
  • No definition of what makes a breach significant
CPS220-P16
Head of Group Notification Duties

The Head of a group must meet the notification duties of this standard in respect of the group risk management framework, except where an APRA regulated institution within the group has already notified APRA of that information.

Artefacts an auditor will ask for
  • Group level notification records
  • Evidence of coordination to avoid or rely on subsidiary notifications
  • Register of what was notified by whom
Where this commonly fails
  • Each entity assuming another has notified
  • No group level view of notification obligations
CPS220-P52
Submission of Appetite Statement, Business Plan and Strategy to APRA

On adoption and after any material revision the institution must submit to APRA a copy of its risk appetite statement, business plan and risk management strategy as soon as practicable and no more than 10 business days after Board approval.

Artefacts an auditor will ask for
  • Submission records for each of the three documents with Board approval and submission dates
  • Definition of what constitutes a material revision
  • Version control linking each submission to an approved version
Where this commonly fails
  • Material revisions treated as minor so never submitted
  • Documents submitted late against the 10 business day deadline
CPS220-P54
APRA Notification of Material Changes to the Institution

The institution must notify APRA as soon as practicable and no more than 10 business days after becoming aware of any material or prospective material change to its size, business mix or complexity.

Artefacts an auditor will ask for
  • Notification records with awareness and submission dates
  • Criteria for identifying material and prospective material change
  • Linkage from strategic and corporate development activity to the notification process
Where this commonly fails
  • Prospective changes not notified because they had not completed
  • No defined threshold for materiality of change
CPS220-P55
APRA Notification of Overseas Business Rights

Where the institution conducts business in a jurisdiction outside Australia it must notify APRA as soon as practicable and no more than 10 business days after becoming aware that its right to conduct business there has been materially affected by that jurisdiction law or has ceased.

Artefacts an auditor will ask for
  • Register of jurisdictions in which business is conducted
  • Monitoring of foreign licensing and legal status
  • Notification records with awareness and submission dates
Where this commonly fails
  • No monitoring of foreign licence status
  • Branch or subsidiary status changes not routed to the notification process

Reporting

CPS220-16
Management Information System and Data Framework

The management information system must give the Board, board committees and senior management regular, accurate and timely information on the institution risk profile, and must rest on a robust data framework enabling aggregation of exposures and risk measures across business lines, prompt reporting of limit breaches and forward looking scenario analysis and stress testing, with data quality adequate for timely and accurate measurement, assessment and reporting and sound enough to base decisions on.

Artefacts an auditor will ask for
  • Risk reporting suite and distribution records
  • Data framework and aggregation architecture documentation
  • Data quality controls and limit breach reporting evidence
Where this commonly fails
  • Manual aggregation preventing prompt reporting
  • Data quality not assessed against decision making needs

Review

CPS220-18
Triennial Comprehensive Review of the Framework

In addition to the annual audit review the institution must ensure the appropriateness, effectiveness and adequacy of its risk management framework is comprehensively reviewed at least every three years by operationally independent, appropriately trained and competent persons who may include external consultants, with results reported to the Board Risk Committee, the senior officer outside Australia or the Compliance Committee as relevant.

Artefacts an auditor will ask for
  • Comprehensive review reports at least triennial
  • Reviewer independence and competence evidence
  • Reporting records to the relevant committee
Where this commonly fails
  • Comprehensive review merged into the annual audit review
  • Reviewer independence not evidenced
CPS220-P46
Scope of the Comprehensive Review

The scope of the comprehensive review must have regard to the size, business mix and complexity of the institution, the extent of any change to its operations or risk appetite, and any changes in the external environment in which it operates.

Artefacts an auditor will ask for
  • Documented review scope with the scoping rationale
  • Analysis of operational, appetite and external environment change
  • Approval of the scope before the review begins
Where this commonly fails
  • Identical scope reused each cycle
  • External environment change not considered in scoping
CPS220-P47
Minimum Assessment Required by the Framework Review

The review of the risk management framework must at least assess whether the framework is implemented and effective, whether it remains appropriate given the current business plan, whether it remains consistent with the Board risk appetite, whether it is supported by adequate resources, and whether the risk management strategy accurately documents the key elements of the framework that give effect to the strategy for managing risk.

Artefacts an auditor will ask for
  • Review reports addressing each of the five required assessments
  • Findings and management responses
  • Evidence of resource adequacy assessment
Where this commonly fails
  • Review reports on implementation but not on effectiveness
  • Resource adequacy never assessed

Risk Appetite

CPS220-06
Risk Appetite Statement

The institution must maintain an appropriate, clear and concise risk appetite statement addressing its material risks, with the Board responsible for setting risk appetite and required to approve the statement.

Artefacts an auditor will ask for
  • Approved risk appetite statement
  • Board approval records
  • Coverage mapping against the material risk categories
Where this commonly fails
  • Statement covers financial risks only
  • Approved once and never refreshed
CPS220-P28
Minimum Contents of the Risk Appetite Statement

The risk appetite statement must convey at least the degree of risk the institution will accept in pursuit of its strategic objectives and business plan having regard to the interests of depositors or policyholders, for each material risk the maximum level it is willing to operate within expressed as a risk limit based on appetite, profile and capital strength, the process for setting risk tolerances at an appropriate level based on estimated breach impact and likelihood, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.

Artefacts an auditor will ask for
  • Risk appetite statement mapped against each of the five required elements
  • Quantified risk limits per material risk
  • Breach monitoring and escalation records
Where this commonly fails
  • Qualitative appetite with no expressed limits
  • No defined action on tolerance breach

Risk Function

CPS220-10
Designated Risk Management Function

The institution must have a designated risk management function that assists the Board, board committees and senior management to maintain the framework, is proportionate to size, business mix and complexity, is operationally independent, has the authority and reporting lines to act effectively and independently, is staffed with people of appropriate experience and qualifications holding clearly defined roles, has access to every part of the institution capable of generating material risk including information technology systems and systems development resources, and is required to notify the Board of any significant breach of or material deviation from the framework.

Artefacts an auditor will ask for
  • Risk function mandate and reporting lines
  • Staffing, experience and qualification records
  • Evidence of access to IT systems and development resources
  • Records of breach notifications made to the Board
Where this commonly fails
  • Function lacks access to technology development activity
  • Independence compromised by dual business responsibilities

Risk Identification

CPS220-07
Material Risk Categories the Framework Must Address

The risk management framework must at a minimum address credit risk, market and investment risk, liquidity risk, insurance risk, operational risk, risks arising from the strategic objectives and business plans, and any other risk that alone or in combination may have a material impact on the institution.

Artefacts an auditor will ask for
  • Risk taxonomy mapped to each required category
  • Justification where a category is not applicable
  • Assessment of combined risk effects
Where this commonly fails
  • Strategic and business plan risk omitted
  • Risks assessed only in isolation and never in combination
CPS220-P33
Risks Arising from Strategic Objectives and the Business Plan

The institution must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects its risk profile.

Artefacts an auditor will ask for
  • Strategic risk assessments tied to the business plan
  • Evidence those risks are managed through the framework
  • Reassessment records following plan changes
Where this commonly fails
  • Strategic risks listed but not managed through the framework
  • Plan changes made without reassessing the risk profile

Strategy

CPS220-05
Risk Management Strategy

The institution must maintain a risk management strategy addressing each of the material risk categories the framework is required to cover, approved by the Board.

Artefacts an auditor will ask for
  • Approved risk management strategy document
  • Board approval records
  • Coverage mapping against each material risk category
Where this commonly fails
  • Strategy silent on one or more required risk categories
  • Document not kept current with the framework
CPS220-P30
Minimum Contents of the Risk Management Strategy

The risk management strategy must at least describe each material risk identified and the approach to managing it, list the policies and procedures dealing with risk management matters, summarise the role and responsibilities of the risk management function, describe the risk governance relationship between the Board, board committees and senior management with respect to the framework, and outline the approach to ensuring all persons in the institution are aware of the framework and to instilling an appropriate risk culture.

Artefacts an auditor will ask for
  • Risk management strategy mapped against each required element
  • Policy and procedure inventory referenced by the strategy
  • Risk awareness and culture approach with supporting activity records
Where this commonly fails
  • Strategy omits the risk culture and awareness approach
  • Policy list stale relative to the actual policy set
CPS220-P31
Maintenance of a Business Plan

The institution must maintain a written plan setting out its approach to implementing its strategic objectives.

Artefacts an auditor will ask for
  • Current written business plan
  • Evidence it sets out the approach to implementing strategic objectives
  • Approval records
Where this commonly fails
  • Strategy deck held in place of a written business plan
  • Plan not maintained between planning cycles
CPS220-P32
Business Plan Duration, Review and Approval

The business plan must be a rolling plan of at least three years reviewed at least annually with results of the review reported to the Board, must cover the entirety of the institution and must be approved by the Board.

Artefacts an auditor will ask for
  • Business plan showing a rolling horizon of at least three years
  • Annual review records and Board reporting
  • Board approval evidence and whole of institution coverage
Where this commonly fails
  • Plan covers a single year
  • Divisions or subsidiaries excluded from coverage

Stress Testing

CPS220-14
Scenario Analysis and Stress Testing Programs

The risk management framework must include forward looking scenario analysis and stress testing programs proportionate to the size, business mix and complexity of the institution and built on severe but plausible assumptions.

Artefacts an auditor will ask for
  • Stress testing and scenario analysis program documentation
  • Assumption sets with severity justification
  • Results and management actions arising
Where this commonly fails
  • Scenarios not severe enough to be informative
  • Results produced but never acted on
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA CPS 220 Risk Management framework page.