Battleground-Beware-the-first-220-declaration-after-CPS230-Article-

5 minute read

If your financial year has just closed and APRA is a regulator, you are probably having conversations about this year’s Risk Management Declaration (RMD).

Technically the year ended before CPS230 came into force, but will the regulator see it that way? APRA has committed to a series of CPS230 prudential reviews, stating that its tolerance “has never been lower”, and all reviews reference the latest RMD for evidence of self-awareness.

Before those reviews land it may be instructive to learn from the recent past. Two themes stand out when looking at APRA’s public enforcement actions since the Royal Commission: 1) it’s dominated by superannuation, 2) failures of non-financial risk (NFR) controls and governance, despite predating CPS230.

Common threads

Across the 14 public actions, APRA repeatedly references “inadequate risk management frameworks,” “weak controls,” and “governance failures.” The common threads? NFR issues stemming from:

  • insufficient line 2 risk resourcing and capability
  • a history of outsourced internal audit
  • poor oversight of service providers
  • deficient NFR data undermining information sent to decision-makers
  • and a culture that has prioritised growth over diligence, excused by industry consolidation.

These themes weren’t limited to the 14 super firms receiving public enforcement actions. During my time in APRA, I saw them repeat across other funds, trustees, and industries, though not quite egregious enough to warrant public enforcement. But it was rare to see a qualified RMD.

And it’s not just APRA. ASIC’s report on death benefits is more about NFRs than insurance risk (“the maturity of governance and controls in superannuation remains variable, with many trustees falling short of best practice”). Or even ASIC fining Star Casino’s executive for providing incomplete risk reporting to its board. ASIC’s focus on governance and risk management systems foreshadows how it will likely supervise FAR, cementing governance and accountability in the regulator’s NFR expectations.

NFR maturity in super remains stubbornly low. Trustee systems were not designed to capture, escalate, or act on non-financial risks. Data is fragmented, controls are untested, and boards rely on lagging, incomplete reports. Combined, these common threads make risk management frameworks a business hinderance rather than enabler. Filling this gap are overworked operations teams and their Chief Operating Officers that feel the need to be in every incident forum, service provider meeting or breach assessment. Despite all this, qualified RMDs remain rare.

Call to action

From my conversations with CROs it is clear the decision whether to qualify an RMD is often borderline. How that decision plays out now CPS230 is in force needs careful attention. So what are funds to do before signing the first RMD to consider CPS230 compliance?

CPS230 checklist

Start with APRA’s day one checklist and consider the strength of each tick. Assuming all the new ‘hardware’ requirements are in place (Critical Operations and Material Service Providers ready for submission 1 Oct), move onto the ‘software’ of the updated requirements, particularly requirements that overlap with SPS220 (Board Governance & Oversight and Risk Profiles & Reporting). Enforcement action shows governance fails when risk data doesn’t reach decision-makers. NFR data must be connected, distilled into information, and flowing to the right audience at the right time

Resourcing

Assess how much capacity line 2 risk has once the CPS230 project winds up. Do they possess appropriate NFR experience and qualifications now the consultants have gone? Consider how the CRO is maintaining external awareness of what good risk management looks like.

Consider a qualified RMD

Submitting a qualified RMD may not be immediately appealing but it shows awareness of self and of better practice. With CPS230 in force it provides a unique clean slate to have no-blame conversations between the CRO and chairs of RiskCo and the board. Are your board and executive overestimating their own risk abilities? Is a lack of self-awareness preventing an accurate assessment against requirements and peers? Nothing accelerates enforcement action like the Dunning-Kruger effect in action. You need to know where you’re at, what good looks like, and you need a plan on how to get from here to there.

In contrast, doing the same as last year loses the CRO leverage to shine a light on risk management deficiencies, and the impetus to fix it properly.

Choose wisely

The regulators’ growing appetite for enforcement shows that mature NFR capabilities are the table stakes to operate. And CPS230 has increased the big and little blinds making a clean RMD harder to justify. The choice is to invest in these capabilities proactively, understand where you are and where you should be, or wait for a regulator to do it for you under the glare of public enforcement, at immense cost to your reputation and members.

If you’re looking to strengthen your organisation’s approach to non-financial risk or want tailored advice on qualifying RMDs, our experts are here to help.

We have walked the walk as both management and regulators in qualifying RMD’s and related remediation. We know what it takes to call out the issues, develop the plans to address them and ensure that improvement sticks. 

Ask us below and we’ll get back to you with ideas and insights.

Our team can provide tailored advice on your Risk Management Declaration (RMD), help assess your current risk management frameworks, and guide you on the path to meeting regulator expectations with confidence.

To find out why you’re better with Battleground, book an appointment with our CPS 230 experts to discuss your organisation’s needs. 

Share this article with your network