How is your operational resilience maturity

1286

Operational resilience is a critical factor in the success of any organisation, both strategically and operationally. Effective leadership requires a deep understanding of your organisation’s maturity in operational risk management, including how you manage service providers and ensure business continuity.

To help organisations achieve this, APRA has proposed a new standard for operational risk management that will apply to all APRA-regulated entities. The proposed standard, CPS 230 Operational Risk Management (CPS 230), will establish minimum requirements for managing operational risk, with a particular emphasis on business continuity and service provider management. APRA is aiming to implement this standard by January 1, 2024.

The goal of this new standard is to consolidate the key elements of operational resilience into a single framework, while ensuring clear accountability for business operators in managing risks related to resilience. This means that business operators, rather than the risk function, will be responsible for owning and managing these risks.

A maturity assessment is a simple and practical tool for understanding your organisation’s level of operational resilience. It’s not just about compliance; it also helps identify your strengths and weaknesses, allowing you to focus on key risk management activities over time.

Think of a maturity assessment as a way to measure your growth and development, much like the marks on a door frame as you watch your children grow over time. To assist in your assessment against the standard, we have developed a simple and user-friendly maturity assessment tool.

By using a maturity assessment model, you can move beyond pure compliance to an engaging way to support everyone in managing their business and risks. However, ensuring compliance with CPS230 requires creating or updating frameworks, systems, and processes while embedding the activity within your front-line business.

To meet these requirements, consider the following key approaches:

  • Conduct workshops with each business area to undertake a maturity assessment against the elements of CPS230.
  • Ensure that the activity occurs within the business lines, rather than through a centralized team. The central team, if required, should facilitate engagement with each business area.
  • Engage the board and executive team from the beginning of the initiative through completion, including organization-wide education and training sessions.

If you wish to know more and receive access to this tool for your self-assessment purposes please contact us.

Scott North has extensive executive and board experience in risk management, internal audit, operational risk and compliance, governance, risk strategy, scenario planning, technology risk, technology architecture, systems design, financial accounting, and management accounting. With Chief Risk Officers roles across financial services in Australia, Scott is an accomplished and experienced senior risk executive with extraordinary results in leading risk management teams. An innovative and process-focused leader, with an entrepreneurial style. Scott has a passion for innovation and digital. Scott is an experienced project leader across multiple disciplines including risk, finance and enterprise systems.