APRA’s delivery of its 2026-27 Corporate Plan is supported by effective risk management practices. These include robust internal governance and accountability mechanisms, supported by sustained focus on risk awareness to strengthen risk culture across the organisation.
APRA’s system of risk oversight, management and internal controls is designed to support compliance with section 16 of the PGPA Act and is aligned with the Commonwealth Risk Management Policy.
APRA is also subject to oversight by the National Anti-Corruption Commission, an independent Commonwealth agency responsible for detecting, investigating, and reporting on serious or systemic corruption issues in the Commonwealth public sector.
APRA’s Enterprise Risk function oversees the administration of the Enterprise Risk Management Framework (ERMF) while the Internal Audit function provides independent assurance on the effectiveness of internal controls, risk management and governance across the organisation.
Governance
APRA’s risk profile is governed through key committees:
- Executive Board: comprising APRA Members and chaired by the Accountable Authority (i.e. the Chair), it is responsible for overseeing APRA’s performance against its mandate. This committee is focused on ensuring that a sound framework of internal control, risk management and compliance is established and maintained. It also monitors APRA’s risk profile to ensure that risks are being managed within APRA’s stated risk appetite or actions are being taken to bring risks back within appetite.
- Executive Committee: comprising all APRA Members and Executive Directors, and chaired by the Accountable Authority. The Executive Committee focuses on strategy, overseeing the execution of the corporate plan and scanning of the external risk environment.
- Prudential Policy Committee: comprising APRA’s Members and relevant executives, this committee is chaired by the Accountable Authority. It oversees the implementation of APRA’s policy development function, including related strategic initiatives and risks.
- Supervision, Enforcement and Resolution Committee: comprising APRA’s Members and relevant executives, this committee is chaired by a Deputy Chair. It oversees APRA’s core supervisory function, including the use of enforcement and resolution powers, and related strategic initiatives and risks.
- Organisational Effectiveness Committee: comprising APRA’s Executive Directors and chaired by an APRA member, this committee oversees the implementation of strategic organisational initiatives and associated risks. This committee will be established in the first half of 2026-27, replacing the existing Management Committee.
- Audit and Risk Committee: consisting of three independent members, it provides an independent view to the Accountable Authority on the operation of APRA’s ERMF.
APRA’s Chief Risk Officer provides regular reports to governance committees on key risks along with any material breaches, incidents, and instances of non-compliance with or material deviation from the ERMF.
Risk management framework
The ERMF enables APRA to identify, assess, manage, monitor and report on the key risks that could affect the organisation’s ability to deliver on the initiatives set out in this Corporate Plan. It is supported by risk appetite, governance and reporting that help APRA understand whether risks are being managed within acceptable levels.
Managing risk is part of everyone’s job at APRA. This is supported through regular training and awareness activities so staff can recognise and address risks in their day-to-day work.
Key risks
The table below outlines the key risks that could affect APRA’s ability to deliver on its purpose and objectives, and the actions in place to manage those risks.
Key risk | Mitigating actions |
|---|---|
APRA is unable to deliver its Corporate Plan objectives and change agenda in an evolving operating environment. |
|
APRA’s prudential policies and supervision activities do not achieve their intended outcomes, reducing its effectiveness in protecting the financial interests of the Australian community. |
|
APRA’s operational resilience arrangements do not adequately protect its critical operations from disruption, including its cyber security and third-party dependency risks. |
|
| APRA does not effectively manage integrity risks, including conflicts of interest and regulatory capture, resulting in reputational damage and reduced confidence in APRA's decisions and actions. |
|
| APRA does not effectively identify, understand or respond to the opportunities and risks presented by emerging technologies, including artificial intelligence. |
|
| APRA’s decisions, supervision and reporting are adversely affected by incomplete, inaccurate, inaccessible or poorly governed data, or the inconsistent use of information. |
|