APRA expects entities to maintain robust governance and risk management frameworks that are clearly documented, actively used, and overseen by accountable boards and senior management. This includes defined risk appetite, effective controls, and ongoing monitoring across financial and non-financial risks.
Expanded Answer
APRA’s prudential standards require entities to establish governance structures that support sound decision-making and risk oversight. This includes board accountability, independent risk and compliance functions, and clear separation of duties. Risk management frameworks must define risk appetite, identify key risks, and outline how those risks are monitored and controlled.
In practice, APRA expects these frameworks to be embedded rather than theoretical. Boards and executives should receive accurate, timely reporting and be able to challenge management decisions. Risk assessments should be updated regularly, and controls should be tested to ensure their effectiveness. There is also increasing focus on operational resilience, cyber risk, and data governance.
Risk increases where frameworks are overly complex, poorly understood, or not aligned with actual business practices. APRA is particularly concerned when non-financial risks are underdeveloped or not integrated into decision-making. For further context, see Understanding risk management: a practical guide for licensees and advice professionals and The three lines of defence: compliance miracle or mirage?.
Why it matters
APRA assesses whether governance and risk frameworks work in practice. Weak oversight or ineffective controls can lead to supervisory action, enforceable directions and increased scrutiny of senior management.
Practical guidance
- Define and communicate the organisation’s risk appetite.
- Strengthen board reporting and challenge processes around key risks.
- Test controls regularly to confirm they are effective and aligned with risk exposure.
Further reading