APRA Corporate Plan 2026-27

Risk & Governance

APRA’s delivery of its 2026-27 Corporate Plan is supported by effective risk management practices. These include robust internal governance and accountability mechanisms, supported by sustained focus on risk awareness to strengthen risk culture across the organisation.

APRA’s system of risk oversight, management and internal controls is designed to support compliance with section 16 of the PGPA Act and is aligned with the Commonwealth Risk Management Policy. 

APRA is also subject to oversight by the National Anti-Corruption Commission, an independent Commonwealth agency responsible for detecting, investigating, and reporting on serious or systemic corruption issues in the Commonwealth public sector.

APRA’s Enterprise Risk function oversees the administration of the Enterprise Risk Management Framework (ERMF) while the Internal Audit function provides independent assurance on the effectiveness of internal controls, risk management and governance across the organisation.

Governance

APRA’s risk profile is governed through key committees:

  • Executive Board: comprising APRA Members and chaired by the Accountable Authority (i.e. the Chair), it is responsible for overseeing APRA’s performance against its mandate. This committee is focused on ensuring that a sound framework of internal control, risk management and compliance is established and maintained. It also monitors APRA’s risk profile to ensure that risks are being managed within APRA’s stated risk appetite or actions are being taken to bring risks back within appetite.
  • Executive Committee: comprising all APRA Members and Executive Directors, and chaired by the Accountable Authority. The Executive Committee focuses on strategy, overseeing the execution of the corporate plan and scanning of the external risk environment.
  • Prudential Policy Committee: comprising APRA’s Members and relevant executives, this committee is chaired by the Accountable Authority. It oversees the implementation of APRA’s policy development function, including related strategic initiatives and risks. 
  • Supervision, Enforcement and Resolution Committee: comprising APRA’s Members and relevant executives, this committee is chaired by a Deputy Chair. It oversees APRA’s core supervisory function, including the use of enforcement and resolution powers, and related strategic initiatives and risks. 
  • Organisational Effectiveness Committee: comprising APRA’s Executive Directors and chaired by an APRA member, this committee oversees the implementation of strategic organisational initiatives and associated risks. This committee will be established in the first half of 2026-27, replacing the existing Management Committee. 
  • Audit and Risk Committee: consisting of three independent members, it provides an independent view to the Accountable Authority on the operation of APRA’s ERMF.

APRA’s Chief Risk Officer provides regular reports to governance committees on key risks along with any material breaches, incidents, and instances of non-compliance with or material deviation from the ERMF.

Risk management framework

The ERMF enables APRA to identify, assess, manage, monitor and report on the key risks that could affect the organisation’s ability to deliver on the initiatives set out in this Corporate Plan. It is supported by risk appetite, governance and reporting that help APRA understand whether risks are being managed within acceptable levels. 

Managing risk is part of everyone’s job at APRA. This is supported through regular training and awareness activities so staff can recognise and address risks in their day-to-day work.

Key risks

The table below outlines the key risks that could affect APRA’s ability to deliver on its purpose and objectives, and the actions in place to manage those risks. 

Key risk

Mitigating actions

APRA is unable to deliver its Corporate Plan objectives and change agenda in an evolving operating environment.

  • Regular review of strategic priorities, delivery risks and emerging risks by the Executive Board and relevant committees.
  • Effective governance arrangements that support timely prioritisation, decision-making and resource allocation.
  • Workforce planning, succession planning and targeted capability development to support delivery of strategic priorities.

APRA’s prudential policies and supervision activities do not achieve their intended outcomes, reducing its effectiveness in protecting the financial interests of the Australian community.

  • Maintain a multi-year strategy incorporating insights from domestic and global peers.
  • Adhere to the Office of Impact Analysis requirements and robust policy development processes.
  • Use governance and oversight arrangements to maintain the quality, consistency and effectiveness of supervision.
  • Monitor emerging risks and periodic review of regulatory outcomes to inform continuous improvement.

APRA’s operational resilience arrangements do not adequately protect its critical operations from disruptionincluding its cyber security and third-party dependency risks.

  • Maintain and test business continuity, disaster recovery and incident response arrangements, including crisis simulation exercises.
  • Strengthen cyber security, information security and data protection controls to address evolving threats and vulnerabilities.
  • Promote a strong culture of security, resilience and wellbeing across APRA.
APRA does not effectively manage integrity risks, including conflicts of interest and regulatory capture, resulting in reputational damage and reduced confidence in APRA's decisions and actions. 
  • Maintain integrity compliance and accountability policies, controls and processes that promote ethical behaviour and compliance with APRA’s obligations. 
  • Provide regular training and awareness programs that reinforce APRA’s values, expected behaviours and integrity obligations.
  • Formal governance, monitoring and reporting of organisational integrity, conduct and compliance risks, supported by independent assurance activities. 
  • Promote a culture where staff feel safe to raise concerns including through effective whistleblower, speak up and escalation mechanisms.
APRA does not effectively identify, understand or respond to the opportunities and risks presented by emerging technologies, including artificial intelligence.
  • Maintain governance and oversight arrangements for the responsible adoption and use of emerging technologies, including ethical, security, privacy and operational risk considerations.
  • Apply risk management, testing and assurance processes before deploying new technologies into APRA's operations.
APRA’s decisions, supervision and reporting are adversely affected by incomplete, inaccurate, inaccessible or poorly governed data, or the inconsistent use of information.
  • Maintain enterprise data governance arrangements including clear accountability for the quality, integrity, security and appropriate use of data.
  • Strengthen data management practices, analytics capability and consistent standards for priority data assets.
  • Monitor material data risks, issues and remediation activity through relevant governance forums, supported by assurance where appropriate. 

Footnotes