CPS 230 Postcard #5 Flashcards
What is the title of CPS 230?
Operational Risk Management
Which regulator set the regulatory requirement known as CPS 230?
APRA
What are the general goals of CPS 230?
Strengthening operational resilience & reducing disruption to customer, company & country
What are the three main expected outcomes of CPS 230?
- Effectively managing risks.
- Maintaining COs within tolerance levels through severe but plausible disruptions.
- Effectively managing the risks associated with the use of service providers.
What are the 3 key dates for NAB regarding CPS 230?
- 31 Dec 24: Internal readiness target
- 1 July 25: Effective date
- 1 July 26: Material Service Provider contracts udpated
What 2 key things must we do to fundamentally shift how we manage Critical Operations?
- Maintain/Strengthen COs, which often span across Divisions, while recognising FAR accountabilities.
- Effectively connect, manage, and strengthen the ecosystem of each CO, comprising the service providers, technology assets, office locations, and enabling teams that support them.
How many Critical Operations does NAB have?
17
Regarding Critical Operations, what are some workstream highlights completed in April?
- Reduced COs from 19 to 17
- Progressed BIAs for COs
- L4 Processes validated by CO Owners.
- Updated NFI/FI tables to support Risk Profiles.
- ‘Critical Process’ measure for prioritising PACE delivery at NAB has been retired.
Why are we mobilising Critical Operations? (6 steps)
- COs defined (based on L4 processes)
- Dependencies mapped (based on BIAs)
- Impact Tolerance Levels defined and tested
- Risk Profiles approved
- Gaps & exposures identified
- Remediation plans approved (for elements negatively impacting the resilience of COs)
What activities will CO owners be completing in April?
- Validate L4 processes by 30 April
- Triage sessions to identify FY25 funding requirements
What activities will CO owners be completing in May?
- L4 processes for all COs documented in PH by end of May
What activities will CO owners be completing in June?
- CO Owners define tolerance levels
- CO Risk Profiles commence
What activities will CO owners be completing in August?
- Gaps in L4 processes certified
- Commence drafting Customer Playbooks
What activities will CO owners be completing in September?
- BIAs approved by CO Owners
What activities will CO owners be completing in October?
- Risk profiles approved by CO Owners
- MSP register confirmed
- Findings raised in GRACE