APRA CPS 230 Operational Risk Management
Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assurance
As part of the risk management framework reviews required under CPS 220 and SPS 220 the entity must review its operational risk management, covering each of the operational risk elements the framework is required to contain.
- Review reports covering operational risk management
- Scope evidence covering every required framework element
- Reviewer independence and competence records
- Framework review skips the operational risk elements
- Scope narrower than the elements required by paragraph 16
Business Continuity
The entity must define, identify and maintain a register of its critical operations, take reasonable steps to minimise the likelihood and impact of disruption to them, maintain a credible business continuity plan setting out how it would hold critical operations within tolerance levels through disruption including disaster recovery planning for critical information assets, activate that plan when needed and return to normal operations promptly.
- Register of critical operations
- Approved business continuity plan including disaster recovery planning for critical information assets
- Activation records and post disruption return to normal evidence
- BCP exists but omits disaster recovery for critical information assets
- No evidence the plan has ever been activated or rehearsed for activation
Operational risk incidents and near misses must be identified, escalated, recorded and addressed promptly, and must feed promptly into the assessment of the operational risk profile and of control effectiveness.
- Incident and near miss register
- Escalation records with timestamps
- Evidence incidents updated the risk profile and control assessments
- Near misses not captured
- Incidents recorded but never reflected in the risk profile
The entity must run a systematic testing program for its business continuity plan that covers all critical operations and includes an annual business continuity exercise, testing the effectiveness of the plan and the ability to meet tolerance levels across a range of severe but plausible scenarios.
- Testing program and schedule covering all critical operations
- Annual business continuity exercise reports
- Results measured against tolerance levels
- Testing covers selected operations only
- Exercises run but tolerance levels not measured
The testing program must be tailored to the material risks of the entity and include a range of severe but plausible scenarios, among them disruptions to services provided by material service providers and scenarios requiring contingency arrangements.
- Scenario library with rationale linking scenarios to material risks
- Evidence of service provider disruption scenarios
- Contingency arrangement scenarios and results
- Same scenarios repeated each year
- Material service provider failure never exercised
The business continuity plan must contain the register of critical operations and their tolerance levels, triggers for identifying a disruption and prompting activation together with arrangements for directing resources on activation, the actions the entity would take to hold critical operations within tolerance, an assessment of execution risks, required resources and preparatory measures including key internal and external dependencies, and a communications strategy supporting execution.
- BCP document mapped against each required content element
- Activation triggers and resource direction arrangements
- Execution risk assessment and dependency analysis
- Communications strategy
- Plan lists actions but omits execution risk and dependency analysis
- Activation triggers undefined
The entity must maintain the capabilities needed to execute the business continuity plan including access to people, resources and technology, must monitor compliance with its tolerance levels, and must report any failure to meet a tolerance level to the Board together with a remediation plan.
- Capability inventory supporting BCP execution including third party held capability
- Tolerance level monitoring records
- Board reports of tolerance breaches with remediation plans
- Capability assumed available and never verified
- Tolerance breaches handled operationally without Board reporting
The entity must update its business continuity plan as necessary on an annual basis to reflect changes in legal or organisational structure, business mix, strategy or risk profile and to close shortcomings found through review and testing.
- Annual BCP update records with change log
- Traceability from test and review findings to plan changes
- Approval of each updated version
- Plan reviewed annually but never changed despite test failures
- Organisational change not reflected in the plan
Controls
The entity must regularly monitor, review and test controls for design and operating effectiveness at a frequency proportionate to the materiality of the risks controlled, report results to senior management, and rectify any gaps or deficiencies in the control environment promptly.
- Control testing schedule with frequency rationale by risk materiality
- Test results reported to senior management
- Rectification tracker with closure evidence
- Uniform testing frequency regardless of risk materiality
- Deficiencies recorded but left open
The entity must remediate material weaknesses in its operational risk management including control gaps, weaknesses and failures, supported by clear accountabilities and assurance, addressing root causes promptly, and must keep identified gaps, weaknesses and failures in its operational risk profile until they are remediated.
- Remediation plans with named accountable owners
- Root cause analyses
- Evidence open items remain in the operational risk profile until closed
- Symptoms fixed without root cause analysis
- Items removed from the risk profile before remediation completed
Critical Operations
Unless it can justify otherwise the entity must classify as critical operations at least payments, deposit taking and management, custody, settlements and clearing for an ADI, claims processing for an insurer, investment management and fund administration for an RSE licensee, and for all entities customer enquiries together with the systems and infrastructure supporting critical operations.
- Classification decisions against the mandatory minimum list
- Documented justification for any listed operation excluded
- Mapping of supporting systems and infrastructure
- Mandatory list not applied to the entity type
- Exclusions taken without a documented justification
For every critical operation the entity must set tolerance levels covering the maximum period of disruption it would tolerate, the maximum extent of data loss it would accept, and the minimum service levels it would maintain while operating under alternative arrangements during a disruption.
- Tolerance level register covering all three dimensions per critical operation
- Basis and rationale for each tolerance
- Board approval evidence
- Only a time based tolerance set
- Minimum service levels during alternative operation undefined
So far as practicable the entity must prevent disruption to critical operations, adapt its processes and systems to keep operating within tolerance levels during a disruption, and return to normal operations promptly once the disruption is over.
- Preventive measures mapped to critical operations
- Alternative operating arrangements and workarounds
- Post disruption return to normal records
- Focus on recovery with no preventive measures
- No defined path back to normal operations
The entity must design, implement and embed internal controls that mitigate its operational risks in line with its risk appetite and allow it to meet its compliance obligations.
- Control library mapped to operational risks and compliance obligations
- Control design documentation
- Evidence controls are embedded in business process
- Controls documented but not operating
- No linkage from controls to risk appetite
Governance
Senior management must give the Board clear and comprehensive information on the expected impacts to critical operations whenever the Board is making decisions that could affect the resilience of those operations.
- Board papers for resilience affecting decisions showing critical operation impacts
- Evidence of the impact assessment supporting each paper
- Board minutes recording consideration
- Strategic decisions taken with no critical operation impact assessment
- Impact information limited to cost and benefit
Operational Risk Management Framework
The entity must identify, assess and manage the operational risks arising from inadequate or failed internal processes and systems, from the actions or inactions of people, and from external drivers and events, recognising that operational risk is inherent in all products, activities, processes and systems.
- Operational risk taxonomy and register
- Risk and control self assessment records
- Coverage evidence across all products, activities, processes and systems
- Register covers technology risk only
- Externally driven risks omitted
The Board is ultimately accountable for oversight of the entity operational risk management, including business continuity and the management of service provider arrangements.
- Board charter assigning operational risk accountability
- Board minutes covering business continuity and service provider oversight
- Board reporting pack contents
- Accountability recorded for operational risk but not for continuity or service providers
- No Board level record of oversight
The Board must ensure the entity sets clear roles and responsibilities for senior managers covering operational risk management, business continuity and the management of service provider arrangements.
- Accountability statements or role descriptions for senior managers
- Board approval of the allocation
- Coverage of continuity and service provider duties
- Roles allocated informally without Board endorsement
- Continuity and service provider duties unassigned
As part of the risk management framework required by CPS 220 and SPS 220 the entity must develop and maintain operational risk governance, an operational risk profile assessment with a defined risk appetite supported by indicators, limits and tolerance levels, effective internal controls, monitoring, analysis, reporting and escalation, tested business continuity plans, and processes for managing service provider arrangements.
- Risk management framework documentation covering the six operational risk elements
- Risk appetite statement with operational indicators, limits and tolerance levels
- Escalation procedures for operational incidents and events
- Operational risk appetite stated without indicators or limits
- Service provider processes sitting outside the framework
Internal audit must periodically review the business continuity plan and give the Board assurance that it is a credible plan for holding critical operations within tolerance levels through severe disruption and that testing procedures are adequate and have been carried out satisfactorily.
- Internal audit reports on the BCP
- Assurance opinions provided to the Board
- Assessment of the adequacy and conduct of testing
- Audit reviews testing paperwork without opining on plan credibility
- No periodic cadence defined
The Board must oversee operational risk management and the effectiveness of key internal controls in holding the risk profile within appetite with regular updates and action where concerns arise, approve the business continuity plan and the tolerance levels for disruption to critical operations and review testing results and the execution of findings, and approve the service provider management policy and review risk and performance reporting on material service providers.
- Board approvals of the BCP, tolerance levels and service provider policy
- Regular Board updates on the operational risk profile
- Board review of testing results and material service provider reporting
- Tolerance levels set by management without Board approval
- Testing results never reaching the Board
The entity must manage its full range of operational risks including legal, regulatory, compliance, conduct, technology, data and change management risk, with senior management responsible for operational risk management across the end to end process for all business operations.
- Risk taxonomy evidencing each named risk category
- End to end process ownership records
- Senior management responsibility assignments
- Named categories such as conduct or data risk absent from the taxonomy
- Ownership assigned by function rather than end to end process
The entity must effectively manage its operational risks and set and maintain appropriate standards for conduct and compliance, hold its critical operations within tolerance levels through severe disruption, and manage the risks arising from its use of service providers.
- Documented conduct and compliance standards
- Evidence the three principles are reflected in the framework
- Management attestation against each principle
- Conduct and compliance standards absent
- Principles stated in policy with no operating evidence
Operational risk management must be integrated into the entity overall risk management framework and processes, and business continuity planning must be consistent with and must not conflict with or undermine the entity recovery and exit planning.
- Evidence of integration into the enterprise framework and processes
- Consistency review between the BCP and recovery and exit plans
- Records reconciling conflicting assumptions
- Operational risk run as a standalone silo
- BCP and recovery plan assumptions never reconciled
As part of business and strategic planning the entity must assess the impact of its business and strategic decisions on its operational risk profile and operational resilience, including the impact of new products, services, geographies and technologies.
- Operational risk assessments embedded in strategic planning papers
- New product, service, geography and technology assessments
- Evidence the assessments changed the risk profile record
- Strategic planning without operational risk input
- New technology adopted with no resilience assessment
The entity must maintain a comprehensive assessment of its operational risk profile, supported by information systems that monitor operational risk and enable reporting to the Board and senior management, by documentation of the processes and resources needed to deliver critical operations including people, technology, information, facilities and service providers together with their interdependencies, risks, obligations, key data and controls, and by scenario analysis of severe operational risk events that tests resilience and identifies the need for new or amended controls.
- Operational risk profile assessment and supporting systems
- End to end process and resource maps with interdependencies for each critical operation
- Scenario analysis results and resulting control changes
- Process maps stop at the department boundary
- Scenario analysis performed but no control changes traced from it
Before providing a material service to another party the entity must conduct a comprehensive risk assessment to confirm it will still be able to meet its prudential obligations after entering the arrangement.
- Risk assessments for services provided to other parties
- Prudential obligation impact conclusions
- Approval records before the arrangement commences
- Only inbound service arrangements assessed
- Assessment performed after the arrangement began
Operations
The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monitor the age and health of its information assets and meet the information security requirements of CPS 234.
- Technology capability assessment against current and projected requirements
- Asset age and health monitoring records including end of life tracking
- Evidence of CPS 234 compliance linkage
- Legacy asset age and health untracked
- Capability assessed against current needs only
Regulatory
The entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an operational risk incident it determines is likely to have a material financial impact or a material impact on its ability to maintain critical operations.
- Notification records with awareness and submission timestamps
- Materiality determination criteria and decision records
- Escalation path from the incident register to the notification decision
- Clock started at incident classification rather than awareness
- No documented materiality threshold
The entity must notify APRA as soon as possible and no later than 24 hours after suffering a disruption to a critical operation outside tolerance, covering the nature of the disruption, the action taken, the likely impact on business operations and the timeframe for returning to normal operations.
- Notification records with disruption and submission timestamps
- Evidence the notification covered all four required content elements
- Tolerance breach detection records feeding the notification
- Tolerance breach detected late so the 24 hour clock is missed
- Notification sent without impact or return timeframe
The entity must submit its register of material service providers to APRA on an annual basis.
- Submission records and dates for each annual cycle
- The register as submitted
- Reconciliation between the submitted register and the live register
- Register maintained internally but never submitted
- Submitted register out of step with the live register
The entity must notify APRA as soon as possible and no more than 20 business days after entering into or materially changing an agreement for a service it relies on to undertake a critical operation, and must notify APRA before entering into any material offshoring arrangement or when a significant change to such an arrangement is proposed, including where data or personnel relevant to the service will be located offshore.
- Notification records with execution and submission dates
- Offshoring notifications evidencing they preceded execution
- Identification of arrangements where data or personnel move offshore
- Offshoring notified after signature instead of before
- The 20 business day clock tracked from contract start rather than execution
Service Provider Management
The entity must maintain a comprehensive service provider management policy covering how it identifies material service providers and manages service provider arrangements, including managing the material risks those arrangements create.
- Approved service provider management policy
- Board approval evidence
- Identification criteria for material service providers
- Policy covers procurement only
- Criteria for materiality left to judgement with no policy basis
The entity must identify and maintain a register of its material service providers and manage the material risks of using them, material providers and arrangements being those the entity relies on to undertake a critical operation or that expose it to material operational risk.
- Register of material service providers and material arrangements
- Materiality determinations with supporting rationale
- Risk management records per provider
- Register limited to outsourcing contracts
- Providers exposing the entity to material operational risk omitted
Unless it can justify otherwise the entity must classify as material service providers at least those supplying credit assessment, funding and liquidity management and mortgage brokerage for an ADI, underwriting, claims management, insurance brokerage and reinsurance for an insurer, fund administration, custodial services, investment management and arrangements with promoters and financial planners for an RSE licensee, and for all entities risk management, core technology services and internal audit.
- Classification decisions against the mandatory minimum list
- Documented justification for any exclusion
- Entity type specific coverage evidence
- Internal audit or risk management providers not classified as material
- Exclusions undocumented
Before entering into or materially modifying a material arrangement the entity must undertake appropriate due diligence including a proper selection process and an assessment of the provider ability to deliver on an ongoing basis, and must assess the financial and non financial risks of relying on the provider including risks from the geographic location or concentration of the provider or of the parties it relies on.
- Due diligence files and selection records
- Financial and non financial risk assessments
- Geographic location and concentration analysis
- Due diligence performed at onboarding but not on material modification
- Concentration across providers never assessed
Formal agreements must also give APRA access to documentation, data and other information relating to the service, give APRA the right to conduct an on site visit to the provider, and secure the provider agreement not to impede APRA in performing its duties as prudential regulator.
- Contract clauses granting APRA access, on site visit rights and non impedance
- Clause coverage review across all material arrangements
- Remediation plans for legacy agreements lacking the clauses
- Legacy contracts never uplifted
- Offshore providers resisting on site visit rights
For each material arrangement the entity must identify and manage the risks that could affect the provider ability to deliver on an ongoing basis, identify and manage risks to the entity arising from the arrangement such as step in risk or contagion risk, ensure it can execute its business continuity plan if needed, and ensure it can exit the arrangement in an orderly way if needed.
- Per arrangement risk assessments covering step in and contagion risk
- Exit plans and evidence of their feasibility
- Linkage between provider arrangements and BCP execution
- Exit plans asserted but never tested for feasibility
- Step in and contagion risk not considered
The entity must monitor material arrangements and ensure senior management receive reporting proportionate to the nature and usage of the service, including regular assessment of performance against agreed service levels, the effectiveness of controls managing provider risk, and compliance by both parties with the agreement.
- Service level performance reporting
- Control effectiveness assessments for provider risks
- Two way compliance reviews against the agreement
- Monitoring covers provider performance but not the entity own compliance
- Reporting not reaching senior management
Internal audit must review any proposed material arrangement that would outsource a critical operation, and must report regularly to the Board or Board Audit Committee on whether such arrangements comply with the entity service provider management policy.
- Internal audit reviews of proposed critical operation outsourcing
- Reports to the Board or Board Audit Committee
- Compliance assessments against the service provider policy
- Audit engaged after signature rather than at proposal stage
- No regular reporting cadence to the Board
The entity must not rely on a service provider unless it can ensure that in doing so it can continue to meet its prudential obligations in full and can effectively manage the associated risks.
- Pre reliance assessments confirming prudential obligations can still be met
- Approval records for each reliance decision
- Risk manageability conclusions
- Reliance assumed rather than assessed
- No assessment of the effect on prudential obligations
The service provider management policy must set out the entity approach to entering into, monitoring, substituting and exiting agreements with material service providers, its approach to managing the risks of those providers, and its approach to managing risks from any fourth parties that material service providers rely on to deliver a critical operation.
- Policy clauses covering entry, monitoring, substitution and exit
- Fourth party risk management approach
- Evidence of fourth party identification for critical operations
- Fourth party risk not addressed
- Policy covers onboarding but not substitution or exit
Third Party
Every material arrangement must be covered by a formal legally binding agreement specifying the services and service levels, the rights, responsibilities and expectations of each party including asset ownership, data ownership and control, dispute resolution, audit access, liability and indemnity, provisions securing the entity legal and compliance obligations, notification of the provider reliance on other material service providers, provider liability for sub contractor failure, a force majeure provision, and termination rights.
- Executed agreements for every material arrangement
- Clause mapping against the required minimum content
- Sub contractor notification and liability clauses
- Verbal or intra group arrangements with no formal agreement
- Sub contracting and force majeure clauses absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA CPS 230 Operational Risk Management framework page.