APRA SPS 220 Risk Management (Superannuation)
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assurance
The RSE licensee must ensure the appropriateness, effectiveness and adequacy of its risk management framework is comprehensively reviewed at least every three years by operationally independent, appropriately trained and competent persons.
- Comprehensive review reports at least every three years
- Reviewer independence, training and competence evidence
- Findings and management responses
- Review conducted by the risk function itself
- Reviewer competence not evidenced
For each year in which a comprehensive review does not take place the RSE licensee must undertake a review of the appropriateness, effectiveness and adequacy of the risk management framework.
- Annual review records for the intervening years
- Scope covering appropriateness, effectiveness and adequacy
- Findings and management responses
- No review performed in the two years between comprehensive reviews
- Intervening review narrower than the three required dimensions
The scope of the comprehensive review must have regard to the size, business mix and complexity of business operations, the extent of any change to those operations or to risk appetite and any changes in the external environment, and the review must at a minimum cover whether the framework remains appropriate for business operations, the specific resources used to undertake the required risk management activities and whether those activities are adequately resourced, the risk appetite statement, the risk management strategy and whether it accurately documents the framework and the strategy for managing risk, all risk management policies and procedures, and all risk management and internal control systems.
- Documented review scope with scoping rationale
- Review reports addressing each of the six required coverage areas
- Resource adequacy assessment
- Review omits internal control systems
- Resource adequacy never assessed
Where institutional, operational or other developments that materially affect the size, business mix and complexity of business operations are identified outside the triennial comprehensive review, the RSE licensee must assess whether the framework needs amendment or review to take account of them.
- Trigger criteria for material developments
- Assessments performed at the time of each material development
- Resulting framework amendments
- Waiting for the next scheduled review after a successor fund transfer or merger
- No defined trigger for material development
Audit
The RSE licensee must implement satisfactory internal audit procedures and external audit arrangements to ensure compliance with the risk management framework and to allow it to attest that its risk management and internal control systems are operating effectively and are adequate.
- Internal audit plan and reports covering the framework
- External audit arrangements and reports
- Evidence supporting the attestation on control system effectiveness and adequacy
- Audit tests compliance but not adequacy of the control systems
- Attestation made without underlying audit support
Board and Senior Management
The RSE licensee must have a designated risk management function that assists the Board, board committees and senior management to develop and maintain the framework, is proportionate to the size, business mix and complexity of business operations and operationally independent of the business units, is staffed by people with clearly defined roles and appropriate experience and qualifications, has access to every part of business operations capable of generating material risk including information technology systems and systems development resources, has the authority and reporting structure to act effectively and independently, and is required to notify the Board of any material deviation from or material breach of the framework.
- Risk function mandate and reporting structure
- Staffing, experience and qualification records
- Evidence of access to IT systems and development resources
- Records of deviation and breach notifications to the Board
- Function not operationally independent of business units
- Access to technology development activity not granted
Governance
The Board of the RSE licensee is ultimately responsible for the risk management framework.
- Board charter assigning responsibility for the framework
- Board minutes evidencing oversight
- Board approval records for framework components
- Responsibility delegated to an executive committee with no Board accountability
- No Board record of framework oversight
The Board is ultimately responsible for maintaining the solvency of the RSE licensee and for ensuring its business operations have adequate resources to undertake the activities for which it holds an RSE licence.
- Solvency monitoring and reporting to the Board
- Resource adequacy assessments against licensed activities
- Board minutes evidencing consideration of both
- Resource adequacy assumed rather than assessed
- Solvency monitored by management with no Board visibility
Where the RSE licensee is part of a corporate group and uses group policies or functions, the Board must approve that use and must ensure those policies and functions give appropriate regard to the licensee own business operations and specific requirements.
- Board approvals for each group policy or function relied upon
- Assessments confirming fit to the licensee business operations
- Register of group policies and functions in use
- Group policies adopted by management without Board approval
- No assessment of fit to the licensee specific requirements
Reporting
The risk management framework must include at least the risk appetite statement, the risk management strategy, a designated risk management function meeting the required criteria, all risk management policies, procedures and controls to identify, assess, monitor, report on, mitigate and manage each material risk, clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout business operations, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process ensuring the framework remains effective.
- Framework inventory evidencing each of the seven required components
- Management information system outputs to the Board and senior management
- Documented roles, responsibilities and reporting structures
- Reporting adequate in normal conditions but untested under stress
- No defined review process inside the framework
The RSE licensee must notify APRA within 10 business days when it becomes aware of a significant breach of or material deviation from the risk management framework, or discovers that the framework did not adequately address a material risk.
- Notification records with awareness and submission dates
- Breach and deviation register with significance assessments
- Escalation path from the risk function to the notification decision
- Clock started at investigation close rather than awareness
- Inadequate framework coverage of a material risk not recognised as notifiable
The RSE licensee must notify APRA as soon as practicable when it becomes aware of any material change to the size, business mix or complexity of its business operations.
- Notification records with awareness and submission dates
- Criteria for identifying material change to business operations
- Linkage from corporate activity such as fund mergers to the notification process
- Successor fund transfers and mergers not routed to the notification process
- No defined materiality threshold for change
Review and Reporting
The Board must provide APRA annually with a risk management declaration signed by two directors that satisfies the requirements of Attachment A to the standard.
- Signed annual risk management declarations
- Evidence supporting each Attachment A assertion
- Signatory authority records for the two directors
- Declaration signed by one director or by management
- Assertions made without supporting assurance evidence
The RSE licensee must submit the risk management declaration to APRA on or before the day it is required to submit annual information under reporting standards made by APRA under the Financial Sector (Collection of Data) Act 2001.
- Submission records with the applicable annual reporting due date
- Reconciliation of the declaration date against the reporting standard deadline
- Evidence of the deadline determination
- Declaration submitted after the annual information deadline
- Deadline tracked from the financial year end rather than the reporting standard
Where the Board qualifies the risk management declaration, the qualified declaration must describe any material deviation from the risk management framework and the steps taken or proposed to remedy those deviations.
- Qualified declarations where applicable
- Descriptions of each material deviation with remediation steps
- Evidence the qualification decision was considered against the deviation register
- Declaration signed unqualified despite an open material deviation
- Qualification given without describing the remedy
Risk Categories
Where the RSE licensee conducts business with a purpose other than superannuation, its risk management framework must cover all material contagion risks that the non superannuation business might pose to the superannuation business.
- Identification of any non superannuation business conducted
- Contagion risk assessments
- Framework coverage evidence for those risks
- Non superannuation activity not identified
- Contagion assessed for financial impact only
Risk Management
The RSE licensee must at all times have a risk management framework that appropriately manages the risks to its business operations, including risks arising from outsourced functions.
- Risk management framework documentation
- Approval and version history
- Coverage evidence including outsourced functions
- Framework lapsing between review cycles
- Outsourced activity treated as outside the framework
The RSE licensee must maintain an up to date risk appetite statement covering its business operations and each category of material risk, approved by the Board.
- Approved risk appetite statement
- Board approval records
- Coverage mapping against each material risk category
- Statement not refreshed as the risk profile changes
- Categories of material risk missing from the statement
The risk management framework must cover at least governance risk, investment governance risk, liquidity risk including the liquidity characteristics of investment options offered or proposed, operational risk, insurance risk, strategic and tactical risks arising from the strategic and business plans, and any other risk that may have a material impact on business operations.
- Risk taxonomy mapped to each of the seven required categories
- Liquidity analysis of each investment option offered or proposed
- Justification for any category assessed as not applicable
- Investment option liquidity characteristics not assessed
- Strategic and tactical risk omitted from the taxonomy
The RSE licensee must assess the materiality of each risk by reference to its business operations as a whole, to each RSE within those operations, and to the impact of the risk on its obligations to beneficiaries.
- Materiality assessment methodology
- Assessments performed at whole of operations and per RSE level
- Analysis of impact on obligations to beneficiaries
- Materiality assessed only at the aggregate level
- Beneficiary impact not part of the materiality test
The RSE licensee must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects the risk profile of business operations.
- Strategic risk assessments tied to the business plan
- Evidence those risks are managed through the framework
- Reassessment records following plan changes
- Strategic risks listed but not managed through the framework
- Plan changes made without reassessing the risk profile
The risk appetite statement must articulate at least the degree of risk the RSE licensee will accept in pursuit of its strategic objectives and business plan having regard to the interests of beneficiaries, for each material risk the maximum level it is willing to operate within expressed where possible as a measurable residual risk limit after allowing for mitigants, the process for setting risk tolerances at an appropriate level based on estimated impact on beneficiaries of a breach and the likelihood of the risk being realised, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.
- Risk appetite statement mapped against each of the five required elements
- Risk limits expressed on a residual basis where possible
- Tolerance breach monitoring and response records
- Limits expressed on an inherent basis with no mitigant allowance
- Beneficiary impact not used in setting tolerances
Risk Management Framework
The RSE licensee must ensure at a minimum that its risk management framework covers all material risks to its business operations, both financial and non financial, having regard to the size, business mix and complexity of those operations.
- Risk register covering financial and non financial risks
- Proportionality rationale referencing size, business mix and complexity
- Coverage assessment against business operations
- Non financial risk under represented
- Coverage limited to the RSE and excluding other licensee activities
The risk management framework must provide reasonable assurance that each material risk to business operations is being prudently and soundly managed, having regard to the size, business mix and complexity of those operations.
- Assurance mapping from each material risk to its management and monitoring
- Proportionality rationale
- Evidence supporting the assurance conclusion
- Assurance asserted with no supporting mapping
- Risks recorded but with no demonstrated management
Where the RSE licensee is part of a corporate group and any element of its framework is controlled or influenced by, or subject to approval by, another group entity, the framework must specifically take account of risks arising from group policy objectives and strategies and must clearly identify whether it is wholly or partly derived from group policies or functions, the linkages and significant differences between the licensee framework and group policies or functions, and the process for monitoring by or reporting to the group on risk management including key procedures, reporting frequency and the approach to reviews.
- Mapping of group derived framework elements
- Gap and difference analysis against group policies and functions
- Group reporting and review protocols
- Group policies adopted with no difference analysis
- Risks arising from group objectives not assessed
Risk Management Strategy
The RSE licensee must maintain an up to date risk management strategy for its business operations covering each material risk identified under the framework coverage requirements, approved by the Board.
- Approved risk management strategy
- Board approval records
- Coverage mapping to each identified material risk
- Strategy silent on risks that the framework identifies
- Document not maintained between Board cycles
The risk management framework must enable the RSE licensee to develop and implement strategies, policies, procedures and controls that appropriately manage the different types of material risk.
- Strategies, policies, procedures and controls traceable to each material risk type
- Evidence controls are implemented and operating
- Framework design documentation
- Framework describes governance but produces no operating controls
- Controls exist for some risk types only
The risk management strategy must describe each material risk identified and the approach to managing it, the policies and procedures covering risk identification and assessment, establishing, implementing and testing mitigation strategies and control mechanisms, monitoring, communicating and reporting risk issues including escalation of material events and incidents, monitoring ongoing compliance with all prudential requirements and ensuring continued alignment between the framework and the business plan together with each policy last revision date, next review date and review owner, the role and responsibilities of the risk management function, the relationships between the Board, board committees and senior management with respect to the framework, those with managerial responsibility for the framework and their roles, the approach to risk awareness across business operations and to i
- Risk management strategy mapped against each required element
- Policy register recording last revision date, next review date and review owner
- Risk awareness and culture approach with supporting activity records
- Policy revision and review dates not recorded in the strategy
- Risk awareness and culture approach omitted
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA SPS 220 Risk Management (Superannuation) framework page.