Skip to content

Evidence request lists

APRA SPS 220 Risk Management (Superannuation)

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assurance

SPS220-46
Triennial Comprehensive Review of the Framework

The RSE licensee must ensure the appropriateness, effectiveness and adequacy of its risk management framework is comprehensively reviewed at least every three years by operationally independent, appropriately trained and competent persons.

Artefacts an auditor will ask for
  • Comprehensive review reports at least every three years
  • Reviewer independence, training and competence evidence
  • Findings and management responses
Where this commonly fails
  • Review conducted by the risk function itself
  • Reviewer competence not evidenced
SPS220-P28
Annual Review in Non Comprehensive Review Years

For each year in which a comprehensive review does not take place the RSE licensee must undertake a review of the appropriateness, effectiveness and adequacy of the risk management framework.

Artefacts an auditor will ask for
  • Annual review records for the intervening years
  • Scope covering appropriateness, effectiveness and adequacy
  • Findings and management responses
Where this commonly fails
  • No review performed in the two years between comprehensive reviews
  • Intervening review narrower than the three required dimensions
SPS220-P29
Scope and Minimum Content of the Comprehensive Review

The scope of the comprehensive review must have regard to the size, business mix and complexity of business operations, the extent of any change to those operations or to risk appetite and any changes in the external environment, and the review must at a minimum cover whether the framework remains appropriate for business operations, the specific resources used to undertake the required risk management activities and whether those activities are adequately resourced, the risk appetite statement, the risk management strategy and whether it accurately documents the framework and the strategy for managing risk, all risk management policies and procedures, and all risk management and internal control systems.

Artefacts an auditor will ask for
  • Documented review scope with scoping rationale
  • Review reports addressing each of the six required coverage areas
  • Resource adequacy assessment
Where this commonly fails
  • Review omits internal control systems
  • Resource adequacy never assessed
SPS220-P31
Assessment Following Material Developments Outside the Review Cycle

Where institutional, operational or other developments that materially affect the size, business mix and complexity of business operations are identified outside the triennial comprehensive review, the RSE licensee must assess whether the framework needs amendment or review to take account of them.

Artefacts an auditor will ask for
  • Trigger criteria for material developments
  • Assessments performed at the time of each material development
  • Resulting framework amendments
Where this commonly fails
  • Waiting for the next scheduled review after a successor fund transfer or merger
  • No defined trigger for material development

Audit

SPS220-48
Internal and External Audit Arrangements

The RSE licensee must implement satisfactory internal audit procedures and external audit arrangements to ensure compliance with the risk management framework and to allow it to attest that its risk management and internal control systems are operating effectively and are adequate.

Artefacts an auditor will ask for
  • Internal audit plan and reports covering the framework
  • External audit arrangements and reports
  • Evidence supporting the attestation on control system effectiveness and adequacy
Where this commonly fails
  • Audit tests compliance but not adequacy of the control systems
  • Attestation made without underlying audit support

Board and Senior Management

SPS220-16
Designated Risk Management Function

The RSE licensee must have a designated risk management function that assists the Board, board committees and senior management to develop and maintain the framework, is proportionate to the size, business mix and complexity of business operations and operationally independent of the business units, is staffed by people with clearly defined roles and appropriate experience and qualifications, has access to every part of business operations capable of generating material risk including information technology systems and systems development resources, has the authority and reporting structure to act effectively and independently, and is required to notify the Board of any material deviation from or material breach of the framework.

Artefacts an auditor will ask for
  • Risk function mandate and reporting structure
  • Staffing, experience and qualification records
  • Evidence of access to IT systems and development resources
  • Records of deviation and breach notifications to the Board
Where this commonly fails
  • Function not operationally independent of business units
  • Access to technology development activity not granted

Governance

SPS220-13
Board Responsibility for the Risk Management Framework

The Board of the RSE licensee is ultimately responsible for the risk management framework.

Artefacts an auditor will ask for
  • Board charter assigning responsibility for the framework
  • Board minutes evidencing oversight
  • Board approval records for framework components
Where this commonly fails
  • Responsibility delegated to an executive committee with no Board accountability
  • No Board record of framework oversight
SPS220-P8
Board Responsibility for Solvency and Adequate Resources

The Board is ultimately responsible for maintaining the solvency of the RSE licensee and for ensuring its business operations have adequate resources to undertake the activities for which it holds an RSE licence.

Artefacts an auditor will ask for
  • Solvency monitoring and reporting to the Board
  • Resource adequacy assessments against licensed activities
  • Board minutes evidencing consideration of both
Where this commonly fails
  • Resource adequacy assumed rather than assessed
  • Solvency monitored by management with no Board visibility
SPS220-P9
Board Approval of Group Policies and Functions

Where the RSE licensee is part of a corporate group and uses group policies or functions, the Board must approve that use and must ensure those policies and functions give appropriate regard to the licensee own business operations and specific requirements.

Artefacts an auditor will ask for
  • Board approvals for each group policy or function relied upon
  • Assessments confirming fit to the licensee business operations
  • Register of group policies and functions in use
Where this commonly fails
  • Group policies adopted by management without Board approval
  • No assessment of fit to the licensee specific requirements

Reporting

SPS220-42
Minimum Contents of the Risk Management Framework

The risk management framework must include at least the risk appetite statement, the risk management strategy, a designated risk management function meeting the required criteria, all risk management policies, procedures and controls to identify, assess, monitor, report on, mitigate and manage each material risk, clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout business operations, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process ensuring the framework remains effective.

Artefacts an auditor will ask for
  • Framework inventory evidencing each of the seven required components
  • Management information system outputs to the Board and senior management
  • Documented roles, responsibilities and reporting structures
Where this commonly fails
  • Reporting adequate in normal conditions but untested under stress
  • No defined review process inside the framework
SPS220-44
APRA Notification of Framework Breach within 10 Business Days

The RSE licensee must notify APRA within 10 business days when it becomes aware of a significant breach of or material deviation from the risk management framework, or discovers that the framework did not adequately address a material risk.

Artefacts an auditor will ask for
  • Notification records with awareness and submission dates
  • Breach and deviation register with significance assessments
  • Escalation path from the risk function to the notification decision
Where this commonly fails
  • Clock started at investigation close rather than awareness
  • Inadequate framework coverage of a material risk not recognised as notifiable
SPS220-P36
APRA Notification of Material Changes to Business Operations

The RSE licensee must notify APRA as soon as practicable when it becomes aware of any material change to the size, business mix or complexity of its business operations.

Artefacts an auditor will ask for
  • Notification records with awareness and submission dates
  • Criteria for identifying material change to business operations
  • Linkage from corporate activity such as fund mergers to the notification process
Where this commonly fails
  • Successor fund transfers and mergers not routed to the notification process
  • No defined materiality threshold for change

Review and Reporting

SPS220-28
Annual Board Risk Management Declaration

The Board must provide APRA annually with a risk management declaration signed by two directors that satisfies the requirements of Attachment A to the standard.

Artefacts an auditor will ask for
  • Signed annual risk management declarations
  • Evidence supporting each Attachment A assertion
  • Signatory authority records for the two directors
Where this commonly fails
  • Declaration signed by one director or by management
  • Assertions made without supporting assurance evidence
SPS220-P33
Submission Deadline for the Risk Management Declaration

The RSE licensee must submit the risk management declaration to APRA on or before the day it is required to submit annual information under reporting standards made by APRA under the Financial Sector (Collection of Data) Act 2001.

Artefacts an auditor will ask for
  • Submission records with the applicable annual reporting due date
  • Reconciliation of the declaration date against the reporting standard deadline
  • Evidence of the deadline determination
Where this commonly fails
  • Declaration submitted after the annual information deadline
  • Deadline tracked from the financial year end rather than the reporting standard
SPS220-P34
Content of a Qualified Risk Management Declaration

Where the Board qualifies the risk management declaration, the qualified declaration must describe any material deviation from the risk management framework and the steps taken or proposed to remedy those deviations.

Artefacts an auditor will ask for
  • Qualified declarations where applicable
  • Descriptions of each material deviation with remediation steps
  • Evidence the qualification decision was considered against the deviation register
Where this commonly fails
  • Declaration signed unqualified despite an open material deviation
  • Qualification given without describing the remedy

Risk Categories

SPS220-P13
Contagion Risk from Non Superannuation Business

Where the RSE licensee conducts business with a purpose other than superannuation, its risk management framework must cover all material contagion risks that the non superannuation business might pose to the superannuation business.

Artefacts an auditor will ask for
  • Identification of any non superannuation business conducted
  • Contagion risk assessments
  • Framework coverage evidence for those risks
Where this commonly fails
  • Non superannuation activity not identified
  • Contagion assessed for financial impact only

Risk Management

SPS220-17
Maintenance of a Risk Management Framework

The RSE licensee must at all times have a risk management framework that appropriately manages the risks to its business operations, including risks arising from outsourced functions.

Artefacts an auditor will ask for
  • Risk management framework documentation
  • Approval and version history
  • Coverage evidence including outsourced functions
Where this commonly fails
  • Framework lapsing between review cycles
  • Outsourced activity treated as outside the framework
SPS220-19
Risk Appetite Statement

The RSE licensee must maintain an up to date risk appetite statement covering its business operations and each category of material risk, approved by the Board.

Artefacts an auditor will ask for
  • Approved risk appetite statement
  • Board approval records
  • Coverage mapping against each material risk category
Where this commonly fails
  • Statement not refreshed as the risk profile changes
  • Categories of material risk missing from the statement
SPS220-23
Risk Categories the Framework Must Cover

The risk management framework must cover at least governance risk, investment governance risk, liquidity risk including the liquidity characteristics of investment options offered or proposed, operational risk, insurance risk, strategic and tactical risks arising from the strategic and business plans, and any other risk that may have a material impact on business operations.

Artefacts an auditor will ask for
  • Risk taxonomy mapped to each of the seven required categories
  • Liquidity analysis of each investment option offered or proposed
  • Justification for any category assessed as not applicable
Where this commonly fails
  • Investment option liquidity characteristics not assessed
  • Strategic and tactical risk omitted from the taxonomy
SPS220-P11
Assessment of the Materiality of Each Risk

The RSE licensee must assess the materiality of each risk by reference to its business operations as a whole, to each RSE within those operations, and to the impact of the risk on its obligations to beneficiaries.

Artefacts an auditor will ask for
  • Materiality assessment methodology
  • Assessments performed at whole of operations and per RSE level
  • Analysis of impact on obligations to beneficiaries
Where this commonly fails
  • Materiality assessed only at the aggregate level
  • Beneficiary impact not part of the materiality test
SPS220-P18
Risks Arising from Strategic Objectives and the Business Plan

The RSE licensee must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects the risk profile of business operations.

Artefacts an auditor will ask for
  • Strategic risk assessments tied to the business plan
  • Evidence those risks are managed through the framework
  • Reassessment records following plan changes
Where this commonly fails
  • Strategic risks listed but not managed through the framework
  • Plan changes made without reassessing the risk profile
SPS220-P20
Minimum Contents of the Risk Appetite Statement

The risk appetite statement must articulate at least the degree of risk the RSE licensee will accept in pursuit of its strategic objectives and business plan having regard to the interests of beneficiaries, for each material risk the maximum level it is willing to operate within expressed where possible as a measurable residual risk limit after allowing for mitigants, the process for setting risk tolerances at an appropriate level based on estimated impact on beneficiaries of a breach and the likelihood of the risk being realised, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.

Artefacts an auditor will ask for
  • Risk appetite statement mapped against each of the five required elements
  • Risk limits expressed on a residual basis where possible
  • Tolerance breach monitoring and response records
Where this commonly fails
  • Limits expressed on an inherent basis with no mitigant allowance
  • Beneficiary impact not used in setting tolerances

Risk Management Framework

SPS220-18
Framework Coverage of All Material Risks

The RSE licensee must ensure at a minimum that its risk management framework covers all material risks to its business operations, both financial and non financial, having regard to the size, business mix and complexity of those operations.

Artefacts an auditor will ask for
  • Risk register covering financial and non financial risks
  • Proportionality rationale referencing size, business mix and complexity
  • Coverage assessment against business operations
Where this commonly fails
  • Non financial risk under represented
  • Coverage limited to the RSE and excluding other licensee activities
SPS220-P15
Reasonable Assurance of Prudent and Sound Management

The risk management framework must provide reasonable assurance that each material risk to business operations is being prudently and soundly managed, having regard to the size, business mix and complexity of those operations.

Artefacts an auditor will ask for
  • Assurance mapping from each material risk to its management and monitoring
  • Proportionality rationale
  • Evidence supporting the assurance conclusion
Where this commonly fails
  • Assurance asserted with no supporting mapping
  • Risks recorded but with no demonstrated management
SPS220-P17
Identification of Group Derived Framework Elements

Where the RSE licensee is part of a corporate group and any element of its framework is controlled or influenced by, or subject to approval by, another group entity, the framework must specifically take account of risks arising from group policy objectives and strategies and must clearly identify whether it is wholly or partly derived from group policies or functions, the linkages and significant differences between the licensee framework and group policies or functions, and the process for monitoring by or reporting to the group on risk management including key procedures, reporting frequency and the approach to reviews.

Artefacts an auditor will ask for
  • Mapping of group derived framework elements
  • Gap and difference analysis against group policies and functions
  • Group reporting and review protocols
Where this commonly fails
  • Group policies adopted with no difference analysis
  • Risks arising from group objectives not assessed

Risk Management Strategy

SPS220-20
Risk Management Strategy

The RSE licensee must maintain an up to date risk management strategy for its business operations covering each material risk identified under the framework coverage requirements, approved by the Board.

Artefacts an auditor will ask for
  • Approved risk management strategy
  • Board approval records
  • Coverage mapping to each identified material risk
Where this commonly fails
  • Strategy silent on risks that the framework identifies
  • Document not maintained between Board cycles
SPS220-22
Framework Enabling Strategies, Policies, Procedures and Controls

The risk management framework must enable the RSE licensee to develop and implement strategies, policies, procedures and controls that appropriately manage the different types of material risk.

Artefacts an auditor will ask for
  • Strategies, policies, procedures and controls traceable to each material risk type
  • Evidence controls are implemented and operating
  • Framework design documentation
Where this commonly fails
  • Framework describes governance but produces no operating controls
  • Controls exist for some risk types only
SPS220-P22
Minimum Contents of the Risk Management Strategy

The risk management strategy must describe each material risk identified and the approach to managing it, the policies and procedures covering risk identification and assessment, establishing, implementing and testing mitigation strategies and control mechanisms, monitoring, communicating and reporting risk issues including escalation of material events and incidents, monitoring ongoing compliance with all prudential requirements and ensuring continued alignment between the framework and the business plan together with each policy last revision date, next review date and review owner, the role and responsibilities of the risk management function, the relationships between the Board, board committees and senior management with respect to the framework, those with managerial responsibility for the framework and their roles, the approach to risk awareness across business operations and to i

Artefacts an auditor will ask for
  • Risk management strategy mapped against each required element
  • Policy register recording last revision date, next review date and review owner
  • Risk awareness and culture approach with supporting activity records
Where this commonly fails
  • Policy revision and review dates not recorded in the strategy
  • Risk awareness and culture approach omitted
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA SPS 220 Risk Management (Superannuation) framework page.