AST APRA Managing Operational Risk

Updated on: Jun 16, 2024

Latest Event


  • Jun. 2024 Finalized CPG 230
  • On Jun. 13, 2024, AST APRA finalized the prudential practice guide operational risk management (CPG 230), assisting the implementation of prudential standard CPS 230.
  • AST APRA published the response to submission re CPG 230; highlighted changes.
  • Changes include that AST APRA has given smaller entities more time to comply with some components; simplified the guidance to align more closely with the standard
  • In addition, provided information about what to expect from AST APRA supervision.
  • CPS 230 will still come into effect on Jul. 1 2025 for all APRA-regulated entities.
  • However, AST APRA gives non-significant financial institutions (SFIs) a 12-month extension on requirements relating to business continuity and scenario analysis.
  • Provides a day one checklist for entities to assist in their implementation of CPS 230.
  • Plus a three-year forward plan of its intended approach to supervising CPS 230.
  • On the same day, AST APRA published the finalized CPG 230 guidance under risk management section of prudential and reporting standards for general insurance.
  • In Oct. 2024, AST APRA issued material service provider register form, see #230067.

On Jul. 17, AST APRA proposed CPG 230 guidance on operational risk.

  • AST APRA released Prudential practice guide - draft CPG 230 operational risk management - integrated version to assist regulated entities with implementation of the new Prudential standard CPS 230 operational risk management (CPS 230).
  • Draft CPG 230 also addresses issues raised in submissions to consultation on CPS 230.
  • AST APRA is seeking feedback from stakeholders with respect to this draft CPG 230.
  • Finalized CPS 230
  • On the same day, AST APRA published the finalized Prudential standard CPS 230 operational risk management (CPS 230), effective on Jul. 1, 2025, see #144564.
  • Overview of Draft Guidance
  • Prefatory text states Prudential practice guides (PPGs) provide guidance on AST APRA’s view of sound practice in particular areas; PPGs frequently discuss legal requirements.
  • Specifically, from legislation, regulations or AST APRA’s prudential standards; however, it said PPGs do not in and of themselves create requirements that are enforceable.
  • This PPG guides AST APRA-regulated entities to assist in complying with CPS 230.
  • PPG states that under CPS 230, AST APRA-regulated entities are required to effectively manage operational risks, continue to deliver critical operations through disruptions as well as effectively manage the risks arising from the use of service providers.
  • In addition, this PPG includes a graphic which summarizes AST APRA’s prudential framework, as well as shows where CPS 230 fits in, within the risk management pillar.
  • Integrated version of CPG 230 maps AST APRA’s guidance to the relevant paragraphs in CPS 230; paragraphs from CPS 230, which are enforceable requirements, have been set out in blue boxes - the accompanying guidance is set out below these blue boxes.
  • Next Steps
  • AST APRA said after the end of the consult it expects to finalize guidance later in 2023.
  • Effectiveness
  • The comment period for this consultation closes on Oct. 13, 2023.
  • In Aug. 2023, AST APRA spoke about the evolution of operational risk, see #182854.
  • Oct. 2023 Editorial Update
  • On Oct. 6, 2023, Reg-Track added a sub-heading to the summary above, for the purpose of clarification with regard to the finalized prudential standard CPS 230.
  • Jun. 2024 Finalized CPG 230
  • On Jun. 13, 2024, AST APRA finalized the prudential practice guide operational risk management (CPG 230), assisting the implementation of prudential standard CPS 230.
  • AST APRA published the response to submission re CPG 230; highlighted changes.
  • Changes include that AST APRA has given smaller entities more time to comply with some components; simplified the guidance to align more closely with the standard
  • In addition, provided information about what to expect from AST APRA supervision.
  • CPS 230 will still come into effect on Jul. 1 2025 for all APRA-regulated entities.
  • However, AST APRA gives non-significant financial institutions (SFIs) a 12-month extension on requirements relating to business continuity and scenario analysis.
  • Provides a day one checklist for entities to assist in their implementation of CPS 230.
  • Plus a three-year forward plan of its intended approach to supervising CPS 230.
  • On the same day, AST APRA published the finalized CPG 230 guidance under risk management section of prudential and reporting standards for general insurance.
  • In Oct. 2024, AST APRA issued material service provider register form, see #230067.
Regulators
AST APRA
Entity Types
Bank; Ins; Pension; SIFI
Reference
Gd, PR, 6/13/2024; CP, PR 7/17/2023; Citation: CPG 230; CPS 230;
Functions
BCS; Compliance; C-Suite; Legal; Operations; Outsourcing; Risk; Technology
Countries
Australia
Category
State
N/A
Products
Banking; Insurance; Pensions; Retirement Plan
Rule Type
Final
Regions
AP
Rule Date
Jul 17, 2023
Effective Date
Jul 1, 2025
Rule ID
179326
Linked to
Reg. Last Update
Jun 13, 2024
Report Section
International