← All articles
2026-09-14 · Compliance

APRA CPS 220 Compliance Requirements: A Complete Guide for Risk Managers

Master APRA CPS 220 compliance requirements with our comprehensive guide. Learn operational resilience expectations, testing frameworks, and implementation strategies for financial institutions.

Understanding APRA CPS 220 Compliance Requirements

APRA's Prudential Standard CPS 220, titled Operational Resilience, represents one of the most significant compliance frameworks introduced by the Australian Prudential Regulation Authority. This standard establishes mandatory requirements for authorised deposit-taking institutions (ADIs), general insurers, and life insurance companies to build and maintain operational resilience in their business operations.

The primary objective of CPS 220 is to ensure that regulated institutions can continue operating and serving customers during periods of significant stress, while maintaining compliance with prudential requirements. This goes beyond traditional business continuity planning—it requires institutions to actively identify, measure, and manage their vulnerabilities to operational disruptions.

Core Pillars of APRA CPS 220 Compliance

1. Business Continuity Management (BCM)

Business continuity management sits at the heart of CPS 220 compliance. Institutions must establish comprehensive BCM frameworks that identify critical business functions and the resources required to maintain them during disruptions. Risk managers need to document:

A practical example: An ADI identifies that its loan origination system is critical, with an RTO of 4 hours. The institution must maintain backup infrastructure, test recovery procedures quarterly, and document that they can genuinely restore this function within the specified timeframe.

2. Stress Testing and Scenario Analysis

CPS 220 requires institutions to conduct regular stress testing across operational and financial scenarios. This involves:

For example, a general insurer must stress-test scenarios such as major system failures affecting claims processing, loss of key office locations, or simultaneous cyber incidents across multiple systems. The stress tests should reveal whether your institution can process claims within service levels during these events.

3. Scenario Analysis Framework

Institutions must develop and document a scenario analysis framework that includes:

Risk managers should ensure that scenario analysis isn't a tick-box exercise. Each scenario must be relevant to your institution's specific operating environment, asset base, and customer base.

Key Compliance Obligations for Risk Managers

Documentation and Record-Keeping

APRA expects institutions to maintain comprehensive documentation of their CPS 220 compliance activities. This includes:

Many institutions now use integrated compliance platforms like Diogelu to centralise this documentation, enabling easy retrieval during APRA examinations and ensuring that compliance records remain current and auditable.

Regular Testing and Validation

CPS 220 requires that institutions test their operational resilience arrangements regularly—typically annually, though APRA may require more frequent testing for critical functions or high-risk areas. Testing must be:

A practical scenario: A life insurance company conducts an annual disaster recovery test of its policy administration system. During the test, they discover that while systems can be recovered within the RTO, data restoration takes longer than anticipated. This finding triggers an immediate remediation plan to upgrade backup infrastructure.

Board and Senior Management Accountability

CPS 220 places explicit accountability on Boards and senior management for operational resilience. Specifically:

Common Compliance Gaps and How to Address Them

Insufficient Scenario Relevance

Many institutions develop generic stress scenarios that don't reflect their actual risk profile. Instead, conduct a thorough operational risk assessment to identify scenarios that would genuinely impact your institution's ability to serve customers. For a mortgage lender, a critical scenario might be loss of access to property valuation systems; for an insurer, it might be inability to process claims during a major natural disaster event.

Inadequate Testing Frequency and Scope

Testing should be risk-based. High-criticality functions require more frequent testing. Additionally, testing must be end-to-end; testing individual system recovery without validating whether staff can access those systems or whether business processes can function produces a false sense of readiness.

Poor Documentation of Compliance Activities

Risk managers often conduct sound operational resilience work but fail to document it adequately for APRA scrutiny. Maintaining a central repository of all CPS 220 compliance evidence—from policy approvals to test results—is essential. Solutions like Diogelu provide compliance tracking functionality that streamlines this documentation process, reducing the time spent on compliance administration.

Implementation Best Practices

Integrate Operational Resilience with Risk Management

Operational resilience shouldn't exist in isolation. Integrate it with your existing risk management frameworks, including enterprise risk registers and incident management processes. This ensures that operational risks identified through stress testing are tracked through to resolution.

Use Data-Driven Decision-Making

Leverage quantitative data from your operations to inform stress testing assumptions. Historical incident data, system performance metrics, and staffing patterns should all feed into scenario development and impact assessment.

Establish Clear Accountability and Escalation Paths

Define who is responsible for operational resilience at each level of your organisation. Establish clear escalation procedures when stress testing reveals that your institution cannot meet its operational resilience objectives.

Engage Third Parties Early

If your institution relies on critical third-party services (cloud providers, payment processors, claims management vendors), ensure that their resilience capabilities are documented and tested. CPS 220 holds your institution accountable, even for outsourced functions.

Reporting and Continuous Improvement

CPS 220 compliance is not a one-time project. Risk managers must establish ongoing monitoring, testing, and improvement processes. Key activities include:

Documenting this continuous improvement cycle through a structured compliance management approach demonstrates to APRA that your institution takes operational resilience seriously and is actively strengthening its capabilities.

Streamline Your CPS 220 Compliance with Diogelu

Managing APRA CPS 220 compliance requirements across documentation, testing, and reporting can be resource-intensive. Diogelu simplifies this by providing an integrated platform for tracking compliance activities, maintaining audit-ready documentation, and monitoring remediation actions. With centralised risk registers, incident management, and compliance tracking, Diogelu helps risk managers and compliance officers ensure their institutions meet APRA's operational resilience expectations efficiently and sustainably. Learn more about how Diogelu supports regulatory compliance at https://diogelu.com.

Manage your risks with Diogelu

Enterprise risk register, compliance tracking, property survey, incident management and claims — all in one platform.

Start free 14-day trial →