Learn how APRA’s CPS 220 and CPS 230 set the foundation for governance and operational resilience, supported by specific risk-profile standards like CPS 234 and CPS 229.
Looking beyond ISO: the standards that shape organisational risk management
We often talk a lot about ISO standards when it comes to risk management -frameworks like ISO 31000 or ISO 22301 that shape global best practice in governance, continuity and resilience.
But in Australia, the Australian Prudential Regulation Authority (APRA) issues its own comprehensive suite of prudential standards, practice guides and associated guidance that define how financial organisations must govern risk, manage resilience and protect financial stability.
These standards cover the entire prudential landscape – governance, risk management, financial resilience, recovery and resolution, reporting, and economic and financial statistics.
At the centre of this framework are CPS 220 Risk Management and CPS 230 Operational Risk Management. These two standards set the tone for enterprise-wide risk management and operational resilience, while a series of related standards provide detailed guidance for managing specific risk profiles such as cybersecurity, climate change, outsourcing, and data management.
CPS 220: The foundation of risk governance
Prudential Standard CPS 220 Risk Management is the cornerstone of APRA’s risk framework. It establishes how boards and senior executives must design, oversee, and continually improve an organisation’s risk management framework.
CPS 220 requires each entity to:
- Maintain a comprehensive, board-approved risk management framework (RMF) suited to its size, business mix and complexity.
- Develop a risk appetite statement that defines acceptable risk levels.
- Conduct regular independent reviews of the RMF’s design and effectiveness.
- Ensure risk management is embedded into strategic planning, culture, and decision-making.
CPS 220 is intentionally principles-based. It does not prescribe controls; instead, it creates the foundation on which other prudential standards, including CPS 230, are built.
CPS 230: Operational risk and resilience in practice
CPS 230 Operational Risk Management moves beyond frameworks to focus on real-world resilience. It requires organisations to demonstrate that they can maintain critical operations and meet their prudential obligations even during disruption.
Key requirements include:
- Operational-risk identification and control across people, process, systems, and third-party dependencies.
- Critical operations and tolerance levels – defining which functions are essential and how long they can be interrupted before causing harm.
- Business continuity and scenario testing for severe but plausible events.
- Service-provider management, including registers, performance monitoring, audit rights, and exit plans.
- Governance and accountability, with the board ultimately responsible for resilience oversight.
CPS 230 turns operational risk into a measurable and testable capability, closing the loop between risk management and business continuity.
How CPS 220 and CPS 230 work together
- CPS 220 defines how risk is governed: frameworks, appetite, oversight and culture.
- CPS 230 defines how resilience is achieved: testing, continuity and service-provider assurance.
Together, they embed operational risk into the broader enterprise-risk framework, ensuring that resilience and recovery receive the same level of scrutiny as financial performance and compliance.
Other prudential standards for specific risk profiles
While CPS 220 and CPS 230 provide the overarching governance and operational-risk structures, APRA also maintains a range of standards and practice guides that address particular categories of risk.
Prudential Standards are mandatory and enforceable, while Prudential Practice Guides are advisory but influential. Each plays a specific role within an organisation’s broader risk-management ecosystem, aligning targeted risk controls with the overarching frameworks of CPS 220 and CPS 230.
These targeted requirements extend the prudential framework to ensure consistency and depth across the full spectrum of risk exposures. They include:
CPS 234 – Information Security
Sets out mandatory expectations for protecting information assets and responding to cyber incidents. Organisations must maintain robust security controls, testing regimes, and board-level reporting on cyber resilience.
CPS 229 – Climate Change Financial Risks
Requires entities to identify, measure, and manage both physical and transition risks arising from climate change. This includes scenario analysis, governance integration, and transparent disclosure of climate-related risks.
CPS 231 – Outsourcing (being superseded by CPS 230 but still informative)
Historically focused on managing risk from outsourcing arrangements, much of its intent is now incorporated into CPS 230’s service-provider provisions.
CPS 232 – Business Continuity Management
Likewise, its key principles – ensuring continuity of critical operations and recovery capabilities – have been absorbed into CPS 230’s resilience framework.
CPS 226 – Margining and Risk Mitigation for Non-centrally Cleared Derivatives
Targets counterparty and operational risks specific to over-the-counter derivatives.
CPG 235 – Managing Data Risk
A Prudential Practice Guide, not a binding standard, CPG 235 provides best-practice guidance for managing data quality, lineage and governance. It supports CPS 230’s requirement to manage data risk as part of operational-risk management.
These standards and guides illustrate how APRA’s prudential architecture addresses risk holistically, combining broad governance standards (like CPS 220 and CPS 230) with targeted measures that strengthen resilience against specific threats.
Integrating APRA’s Prudential Framework
To comply effectively, and to get genuine value from the framework, organisations should take an integrated approach:
- Connect governance to operations: link CPS 220’s governance and culture requirements directly to CPS 230’s resilience testing and reporting.
- Map interdependencies: identify where targeted standards (e.g., CPS 234 cyber, CPS 229 climate, CPG 235 data) intersect with operational-risk processes.
- Embed board accountability: ensure directors have clear visibility of critical operations, key risks and third-party dependencies.
- Create a unified evidence base: maintain documentation, test results and assurance reporting that align across all standards.
Integration ensures a consistent line of sight from strategic governance through to operational delivery, enabling organisations to respond quickly and effectively when risks materialise.
From Compliance to Confidence
The combined effect of CPS 220 and CPS 230, supported by targeted standards like CPS 234, CPS 229 and CPG 235, represent a modern, layered approach to prudential supervision.
It’s not about checking boxes; it’s about proving organisational resilience.
Boards and executives must show that they can manage risks comprehensively, maintain continuity, and protect stakeholders, even in the face of technological failure, cyber-attack, data loss, or climate-driven disruption.
When treated as strategic tools rather than compliance exercises, APRA’s prudential standards provide a powerful foundation for trust, stability and sustainable performance in Australia’s financial system.
RTP’s Risk Management courses give you the skills to identify, assess, and mitigate risks in your organisation.
- Risk Management Fundamentals (2 days): Learn practical application of risk management frameworks in alignment with ISO 31000 and other business processes. We cover the foundations of risk and effective risk management, using current and emerging issues as case studies to reinforce real-world application.
We offer the Nationally Recognised BSBOPS504 Manage business risks unit of competency as part of our Risk Management Fundamentals course. - Introduction to Risk Management (eLearn): This self-paced 45-minute eLearn will give you an overview of risk management concepts and approaches to understand the fundamentals of identifying, assessing, and managing risks.
- Introduction to Risk-Based Auditing eLearn: This self-paced eLearning module (45–60 minutes) introduces the principles of risk-based auditing. You’ll learn how to align audit activities with organisational risk priorities, evaluate control effectiveness, and enhance audit outcomes through a risk-based approach.
- Introduction to Fraud & Corruption Control Systems: This 2.5-hour self-paced eLearn that will help you build resilience against fraud with a practical introduction to fraud and corruption control systems in line with AS 8001.
-
Anti-money Laundering Foundations eLearn: This 45-minute self-paced eLearn that provides a clear introduction to the foundations of Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF). This course helps you understand both your personal obligations and the broader compliance frameworks that protect organisations and communities from financial crime.
Strengthen your decision-making and boost your workplace resilience. Enrol now and be ready for what’s next.
Find out more about our Risk Management courses
Further reading
Understand why risk management is important for everyone
Find out why proactive risk management is a competitive advantage
Learn about harnessing GRC technology for effective ISO compliance

