FAQ

What governance and risk management standards does APRA expect?

APRA expects entities to maintain robust governance and risk management frameworks that are clearly documented, actively used, and overseen by accountable boards and senior management. This includes defined risk appetite, effective controls, and ongoing monitoring across financial and non-financial risks.

Expanded Answer

APRA’s prudential standards require entities to establish governance structures that support sound decision-making and risk oversight. This includes board accountability, independent risk and compliance functions, and clear separation of duties. Risk management frameworks must define risk appetite, identify key risks, and outline how those risks are monitored and controlled.

In practice, APRA expects these frameworks to be embedded rather than theoretical. Boards and executives should receive accurate, timely reporting and be able to challenge management decisions. Risk assessments should be updated regularly, and controls should be tested to ensure their effectiveness. There is also increasing focus on operational resilience, cyber risk, and data governance.

Risk increases where frameworks are overly complex, poorly understood, or not aligned with actual business practices. APRA is particularly concerned when non-financial risks are underdeveloped or not integrated into decision-making. For further context, see Understanding risk management: a practical guide for licensees and advice professionals and The three lines of defence: compliance miracle or mirage?.

Why it matters

APRA assesses whether governance and risk frameworks work in practice. Weak oversight or ineffective controls can lead to supervisory action, enforceable directions and increased scrutiny of senior management.

Practical guidance

  • Define and communicate the organisation’s risk appetite.
  • Strengthen board reporting and challenge processes around key risks.
  • Test controls regularly to confirm they are effective and aligned with risk exposure.

Further reading

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?