Board assurance: APRA feedback on Cyber Resilience and CPS 234
Client AlertOn Tuesday 23 November 2021, APRA released commentary following the conclusion of its pilot initiatives – the tri-partite audit and technology resilience data collection.
Expert-led tax essentials delivering practical insights and strategic foresight. Learn more.
Reflecting on the history of the mutual sector, Lonsdale highlighted APRA’s recent review of mutuals exiting the industry and their performance 12 months prior to their exit. It brought to the fore several issues that could lead to potential future mutual exits, such as poor performance on cost management, lending growth and profitability.
APRA also considers good governance to be preconditioned to sustainable success, regardless of industry sector. Outdated practices employed mean that there are a number of areas where mutuals should continually evolve and be vigilant, particularly in relation to board tenure, composition and a mutual ADI’s Bond. Consistent with CPS 510, good governance practice would include:
APRA further highlighted three core priorities to “support a strong, stable mutual sector”, being:
To increase regulated entities preparedness for cyber-attacks, APRA is conducting CPS 234 independent reviews. COBA members are the first to undertake these reviews, which are likely to conclude for this group by the end of 2022.
Prior to this week’s speech from APRA Deputy Chair John Lonsdale, APRA has emphasised the importance of board assurance and data recovery in relation to potential cyber attacks and the CPS 234 reviews.
APRA’s recent survey highlighted mutuals lagging behind other banks in their cohort when it comes to the effectiveness of risk management policies, and appropriate frameworks in place to mitigate risk.
Referring back to a recent article we published on auditing risk culture there are six key steps to effectively measure and audit risk culture:
Further to an ADI’s risk management framework, APRA has conveyed the necessity for a contingency plan when facing financial stress.
Read APRA Deputy Chair John Lonsdale’s full speech here.
On Tuesday 23 November 2021, APRA released commentary following the conclusion of its pilot initiatives – the tri-partite audit and technology resilience data collection.