Operational resilience is a critical factor in the success of any organisation, both strategically and operationally. Effective leadership requires a deep understanding of your organisation’s maturity in operational risk management, including how you manage service providers and ensure business continuity.
To help organisations achieve this, APRA has proposed a new standard for operational risk management that will apply to all APRA-regulated entities. The proposed standard, CPS 230 Operational Risk Management (CPS 230), will establish minimum requirements for managing operational risk, with a particular emphasis on business continuity and service provider management. APRA is aiming to implement this standard by January 1, 2024.
The goal of this new standard is to consolidate the key elements of operational resilience into a single framework, while ensuring clear accountability for business operators in managing risks related to resilience. This means that business operators, rather than the risk function, will be responsible for owning and managing these risks.
A maturity assessment is a simple and practical tool for understanding your organisation’s level of operational resilience. It’s not just about compliance; it also helps identify your strengths and weaknesses, allowing you to focus on key risk management activities over time.
Think of a maturity assessment as a way to measure your growth and development, much like the marks on a door frame as you watch your children grow over time. To assist in your assessment against the standard, we have developed a simple and user-friendly maturity assessment tool.
By using a maturity assessment model, you can move beyond pure compliance to an engaging way to support everyone in managing their business and risks. However, ensuring compliance with CPS230 requires creating or updating frameworks, systems, and processes while embedding the activity within your front-line business.
To meet these requirements, consider the following key approaches:
- Conduct workshops with each business area to undertake a maturity assessment against the elements of CPS230.
- Ensure that the activity occurs within the business lines, rather than through a centralized team. The central team, if required, should facilitate engagement with each business area.
- Engage the board and executive team from the beginning of the initiative through completion, including organization-wide education and training sessions.
If you wish to know more and receive access to this tool for your self-assessment purposes please contact us.