How is your operational resilience maturity

Operational resilience is a critical factor in the success of any organisation, both strategically and operationally. Effective leadership requires a deep understanding of your organisation’s maturity in operational risk management, including how you manage service providers and ensure business continuity.

To help organisations achieve this, APRA has a standard for operational risk management that applies to all APRA-regulated entities. The standard, CPS 230 Operational Risk Management (CPS 230), establishs minimum requirements for managing operational risk, with a particular emphasis on business continuity and service provider management.

The goal of this standard was to consolidate the key elements of operational resilience into a single framework, while ensuring clear accountability for business operators in managing risks related to resilience.

This means that business operators, rather than the risk function, are responsible for owning and managing these risks.

A maturity self-assessment is a simple, powerful and practical tool for understanding your organisation’s level of operational resilience. It’s not just about compliance, it helps identify your strengths and weaknesses. This allows you to focus on key risk management activities over time, and make better business decisions.

The benefit of a self-assessment model, is you are in control and you don’t have to pay those excessive consultant costs. You also can perform it again and again, with no additional cost.

Think of a maturity assessment as a way to measure your growth and development, much like the marks on a door frame as you watch your children grow over time.

Operational Risk and Enterprise Risk Maturity Self-Assessments

To assist in your assessment against the standard, we have developed simple and user-friendly maturity assessment tools, available to use immediately.

By using a maturity assessment model, you can move beyond pure compliance to an engaging way to support everyone in managing their business and risks. Ensuring compliance with CPS230 requires creating or updating frameworks, systems, and processes while embedding the activity within your front-line business, it is not just a tick the box exercise.

To meet these requirements, consider the following key approaches:

  • Conduct workshops with each business area to undertake a maturity assessment against the elements of CPS230.
  • Ensure that the activity occurs within the business lines, rather than through a centralized team. The central team, if required, should facilitate engagement with each business area.
  • Engage the board and executive team from the beginning of the initiative through completion, including organization-wide education and training sessions.

If you wish to know more and receive access to this tool for your self-assessment purposes please contact us.

Scott North
Scott North has extensive executive and board experience in risk management, internal audit, operational risk and compliance, governance, risk strategy, scenario planning, technology risk, technology architecture, systems design, financial accounting, and management accounting. With Chief Risk Officers roles across financial services in Australia, Scott is an accomplished and experienced senior risk executive with extraordinary results in leading risk management teams. An innovative and process-focused leader, with an entrepreneurial style. Scott has a passion for innovation and digital. Scott is an experienced project leader across multiple disciplines including risk, finance and enterprise systems.