Introduction to APRA Prudential Standards
APRA (Australian Prudential Regulation Authority) sets standards to ensure the stability of Australia's financial system. CPS 220, 230, and 234 form a critical triad that financial institutions must implement to manage risk effectively. While they overlap and interconnect, each standard has distinct objectives and requirements.
What CPS 220 Requires
CPS 220 Risk Management is the foundation standard. It does not tell an entity which controls to run. It tells the Board that it owns the risk of the whole business, and it prescribes the structure through which that ownership has to be exercised. Everything APRA later asks about operational resilience (CPS 230) or information security (CPS 234) is measured against the framework and the appetite this standard requires.
The framework
An entity must maintain a risk management framework that covers every material risk it faces, on a group basis where it is the head of a group. The framework has to fit the size, business mix and complexity of the entity, and it has to be written down. At its core sit four things the Board approves:
- A risk appetite statement, setting the degree of risk the Board is prepared to accept for each material risk, and the limits and tolerances that follow from it.
- A risk management strategy, describing how each material risk is identified, measured, monitored and managed, and how the risk function is organised.
- A business plan, covering at least three years, consistent with the appetite and the strategy.
- Policies, procedures and controls for each material risk, with the management information the Board needs to see whether the entity is staying inside its appetite.
The people
- The Board is ultimately responsible for the framework and for the entity's risk culture. It cannot delegate that responsibility to a committee or to management.
- A Board Risk Committee, made up of non-executive directors, oversees the framework on the Board's behalf.
- A Chief Risk Officer, independent of business lines and of revenue-generating responsibilities, with unfettered access to the Board and its Risk Committee. The CRO cannot also be the CEO, CFO, head of internal audit or the appointed actuary.
- A risk management function, operationally independent of the business, with the standing and resources to challenge it. This is the second of the three lines of defence; the business is the first, internal audit the third.
The obligations that recur
- An annual risk management declaration to APRA, signed by the Board, attesting that the framework is appropriate and operating effectively.
- A comprehensive review of the framework at least every three years, by people who are operationally independent of it and competent to judge it.
- Notifying APRA of significant breaches of, or material deviations from, the framework, and of material changes to it.
Where cyber risk sits
CPS 220 never uses the words "cyber" or "information security". It does not need to. Information security is a material risk for any regulated entity, so the framework has to cover it, the risk appetite statement has to say how much of it the Board will tolerate, and the CRO has to be able to see whether the entity is inside that tolerance. CPS 234 then specifies the controls and the incident reporting, and CPS 230 the resilience of the operations those controls protect. A security program that cannot show the line from a CPS 234 control back to a CPS 220 appetite is the gap APRA's supervisors look for first.
Comparison of the Three Standards
Enterprise-wide risk management governance and framework. Establishes the overall risk management structure and accountability.
To ensure APRA-regulated entities have a sound risk management framework appropriate to their size, business mix, and complexity.
- Board accountability for risk management
- Risk Management Framework (RMF)
- Risk Appetite Statement (RAS)
- Clear roles (Three Lines of Defence)
- Chief Risk Officer (CRO) appointment
- Risk culture assessment and monitoring
Board of Directors, CRO, Senior Management, Risk Committee
Operational risk and resilience - ensuring critical operations can continue during severe disruptions.
To strengthen operational risk management and ensure entities can continue to deliver critical operations through disruptions.
- Identify critical operations
- Set impact tolerances
- Test operational resilience
- Manage third-party risks
- Business continuity planning
- Incident management framework
Chief Operations Officer, Business Continuity Team, Third-Party Managers, IT Operations
Information security as a subset of operational risk - specifically protecting information assets.
To ensure information security is maintained to protect information assets and support sound risk management.
- Information security capability
- Information asset identification
- Security controls implementation
- Incident response planning
- Third-party information security
- 72-hour incident notification to APRA
Chief Information Security Officer (CISO), IT Security Team, Data Protection Officer
How the Standards Connect and Interact
These standards don't operate in isolation. They form a hierarchical and interconnected framework:
Establishes the overall risk management framework, governance, and culture. Provides the "umbrella" under which CPS 230 and 234 operate.
Example: The Board's risk appetite (CPS 220) determines how much operational risk (CPS 230) and cyber risk (CPS 234) the entity can tolerate.
Applies the risk management framework to operational risks. Focuses on ensuring critical operations continue during disruptions.
Example: A cyber attack is a "severe but plausible disruption" that CPS 230 requires testing for. The controls to prevent it come from CPS 234.
Provides specific controls for information security risks (a subset of operational risks). Implements the technical safeguards needed for resilience.
Example: Multi-factor authentication and Data Loss Prevention (DLP) controls (CPS 234) help achieve operational resilience goals (CPS 230) within the risk appetite (CPS 220).
CPS 220 says: "You must have a robust risk governance framework."
CPS 230 says: "Within that framework, you must prove you can keep critical services running through major disruptions."
CPS 234 says: "Since many disruptions will be cyber-related, you must have strong information security controls and response plans."
Key Requirements Comparison Table
| Requirement Category | CPS 220 (Risk Management) | CPS 230 (Operational Risk) | CPS 234 (Information Security) |
|---|---|---|---|
| Governance & Accountability | Board accountable for RMF; CRO appointment | Accountability for operational resilience | Board oversees information security strategy |
| Framework & Approach | Enterprise-wide Risk Management Framework | Operational risk management; Business continuity | Information security framework; Security controls |
| Risk Assessment | Risk appetite statement; Risk identification | Identify critical operations; Set impact tolerances | Information asset identification; Security assessments |
| Testing & Validation | Risk culture assessment; Framework review | Resilience testing with severe scenarios | Security testing; Vulnerability assessments |
| Third-Party Management | Part of overall risk management | Extend operational resilience to material providers | Ensure third-party information security controls |
| Incident Management | Part of overall risk framework | Operational incident management framework | Information security incident response; 72-hour APRA notification |
| Reporting & Monitoring | Regular risk reporting to Board | Monitor critical operations; Report on resilience | Monitor security controls; Report security incidents |
CPS 220 Questions
What is APRA CPS 220?
CPS 220 Risk Management is the APRA prudential standard that requires a regulated entity to maintain a risk management framework covering every material risk it faces, with the Board ultimately accountable for it. It has applied to banks and insurers since 1 January 2015. Superannuation trustees have the equivalent standard, SPS 220.
Who has to comply with CPS 220?
Authorised deposit-taking institutions, general insurers, life insurers (including friendly societies), private health insurers, and the heads of groups that contain any of them. Registrable superannuation entity licensees are covered by SPS 220 instead.
What is the difference between CPS 220 and CPS 230?
CPS 220 sets the overall risk management framework: governance, risk appetite, the Chief Risk Officer and the Board's accountability. CPS 230 Operational Risk Management, in force since 1 July 2025, applies that framework to one class of risk. It requires an entity to identify its critical operations, set tolerance levels for disruption to them, and manage the material service providers those operations depend on.
What is the difference between CPS 220 and CPS 234?
CPS 234 Information Security, in force since 1 July 2019, is narrower again. It requires an entity to maintain an information security capability commensurate with its threats, to classify and protect its information assets, and to notify APRA of a material information security incident within 72 hours. Under CPS 220, information security is one of the material risks the framework and the risk appetite statement must cover.
What does CPS 220 mean for cyber security?
The Board's risk appetite statement under CPS 220 is where an entity decides how much cyber risk it will tolerate, and the Chief Risk Officer is the executive who challenges the business on whether it is staying inside that appetite. A CISO's controls under CPS 234 and the resilience testing under CPS 230 are the evidence that the appetite is being met, so a cyber security program that cannot be traced back to the CPS 220 risk appetite is one APRA will ask questions about.
What is the CPS 220 risk management declaration?
Each year the Board must give APRA a risk management declaration stating that, to the best of its knowledge, the entity has systems in place to ensure compliance with the prudential standards, that the risk management framework is appropriate and operating effectively, and that the Board is satisfied with the entity's risk management. The framework itself must also be comprehensively reviewed at least every three years by people who are operationally independent of it.
Practical Implications for Financial Institutions
Example: Managing SharePoint for PII Data
Action: Include SharePoint PII risks in the Risk Management Framework. The Board sets risk appetite for data breaches.
Deliverable: Risk Appetite Statement defining acceptable PII exposure levels.
Action: Classify PII data handling as a critical operation. Set impact tolerances (e.g., "PII data cannot be unavailable for more than 4 hours").
Deliverable: Business continuity plan for SharePoint PII repositories.
Action: Implement DLP, encryption, access controls for SharePoint PII data. Establish incident response plan.
Deliverable: Technical security controls; 72-hour incident notification process.
CPS 220 is the FOUNDATION: It's about governance, framework, and culture. It answers "Who is accountable?" and "What's our risk appetite?"
CPS 230 is the APPLICATION: It's about operational resilience. It answers "Can we keep running during a crisis?" and "How do we manage third-party risks?"
CPS 234 is the SPECIALIZATION: It's about cyber security controls. It answers "How do we protect our data?" and "How do we respond to security incidents?"
The Bottom Line: While CPS 220 sets the rules of the game, CPS 230 ensures you can keep playing during a storm, and CPS 234 provides the protective gear against cyber threats.