Draft Prudential Practice Guide: CPG 220 - Risk Management
Draft Prudential Practice Guide: CPG 220 - Risk Management
www.apra.gov.au
Australian Prudential Regulation Authority
Disclaimer and copyright
This prudential practice guide is not legal advice and
users are encouraged to obtain professional advice
about the application of any legislation or prudential
standard relevant to their particular circumstances and
to exercise their own skill and care in relation to any
material contained in this guide.
APRA disclaims any liability for any loss or damage
arising out of any use of this prudential practice guide.
© Australian Prudential Regulation Authority (APRA)
This work is licensed under the Creative Commons
Attribution 3.0 Australia Licence (CCBY 3.0).
This licence allows you to copy,
distribute and adapt this work, provided you attribute
the work and do not suggest that APRA endorses you
or your work. To view a full copy of the terms of this
licence, visit www.creativecommons.org/licenses/
by/3.0/au/.
Introduction 5
Risk governance 5
Material risks 9
Compliance function 13
Outsourcing 13
3 Refer to CPS 510 and Prudential Practice Guide PPG 511 Remuneration on
the design of remuneration policies.
85. CPS 220 allows an APRA-regulated institution’s (a) events such as proposals relating to major
risk management declaration to be encompassed modifications to, or the re-organisation of,
in the risk management declaration the functions of the institution;
documentation of a Level 2 and/or Level 3 group, (b) proposed acquisitions;
where applicable. Where a Level 1 institution’s
declaration is encompassed within the group (c) changes to business lines and products;
declaration, the Level 1 institution’s Board (d) changes in organisational structure; and
remains responsible for any qualifications in the
(e) deviations from the risk management strategy.
declaration that relate to that institution. Where a
risk management declaration is made on a Level 2
and/or Level 3 group basis, CPS 220 requires any
BOARD
• Establishes a governance structure (board sub- • Sets the institution’s risk appetite and ensure
committees, executive responsibilities and risk that it is clearly communicated.
management and assurance functions.)
• Oversees the institution’s risk profile.
• Oversees the effectiveness of the risk
• Establishes a sound risk management culture.
management framework.
Oversight of Management of
Responsibilities
implementation implementation
Email
[email protected]
Website
PPG_CPG220_012014
www.apra.gov.au
Mail
GPO Box 9836
in all capital cities
(except Hobart and Darwin)