CPS230 General Notes Flashcards
What is the primary objective of CPS230?
To enhance operational resilience and security by setting standards for managing operational risk.
Which entities must comply with CPS230?
APRA-regulated banks, insurance companies, and superannuation funds.
What must the risk management framework include?
Policies, procedures, and controls for managing operational risks.
What is required for governance under CPS230?
Oversight by the board and senior management.
What should be in place for incident management under CPS230?
Processes for identifying, reporting, and managing operational incidents.
What does CPS230 require for business continuity?
Effective plans for continuity and disaster recovery.
How should third-party risks be managed?
Ensure third-party providers meet operational risk standards.
How should CPS230 be integrated?
Incorporate it into existing risk management and governance frameworks.
What are the bank’s compliance obligations for CPS230?
Regular reviews and audits; reporting to APRA on compliance and incidents.