Take advantage of CPS 230

Take advantage of CPS 230

July 1st is fast approaching and for many Authorised Deposit Taking Institutions (ADIs), General Insurers, Private Health Insurers and Superannuation Providers, deadlines are closing-in on operation compliance with APRAs latest risk management standard, CPS 230. I’ve been fortunate to work with several project teams as they have been getting ready for its introduction and its been fascinating to observe the impact of a regulatory burning platform on teammates energy, enthusiasm and engagement.

Further to and superseding some of the broader risk management requirements of CPS 220, this latest obligation delves deeper into an organisations operational risk management capability. Specifically, organisations have been asked to better understand and manage their risks, controls and continuity of their critical and essential business operations. This includes better understanding and managing their 3rd party suppliers that often play a substantive role delivering critical business operation outcomes.

So, in just over month, many of Australia’s largest, and most important organisations will sit back and take another deep, compliance filled, breath. It will be familiar for many after years of risk management transformation activity resulting from the 2018 Financial Services Royal Commission and several mandatory undertakings.

And like before, as the dust settles and boards become comfortable that their organisation is remaining safe, we can expect them to start questioning what has been learned from the CPS230 readiness exercise and how can its outcomes be used to perform better?

Spending time in the trenches with these CPS230 teams, here are few ways that I believe organisations will be able to use CPS 230 outcomes to improve the performance of your organisation rapidly.

Turn your business architecture into an asset.

For all the stress and anxiety, a new prudential standard evokes, the introduction of CPS 230 has Business Architects across Australia rejoicing. For years they’ve pleaded with leadership to invest in documenting business process capabilities and use them to understand how outcome quality is controlled, technology is utilised, and human capability is developed. Thanks to CPS230 business process architecture content should now exist, even informally, for all critical and essential business activity. Architects will now be focussed on putting the asset to good use, rather than it winding up gathering ‘compliance dust’ on a shelf. Examples include:

  • Relating process information to risk and control information in a GRC, making line 1B Risk and Control self-assessments (RCSA) far more effective;
  • Using critical process information to help understand and improve business continuity plans (BCPs), particularly where 3rd parties are involved;
  • Partnering with human resource functions to test how process content can assist with creating job descriptions and optimal hierarchies;
  • Optimising operational process review cycles with major projects. Too often major projects and programs develop To-Be processes for critical business operations without first understanding the current state. They’re also generally developed without a process design discipline (e.g. BPMN2.0), or standard process documentation tooling. Working off a single source of truth and in a common language has all sort of project delivery, benefits management and risk management benefit

Make the most of your 3-lines of Accountability model, particularly Line 1(b).

Most deposit taking institutions over the past 4-5 years have augmented or increased structural cost by adding quality assurance to their front-line. Understanding key controls and how they’re being deployed in every day operations has become critical to safety. But what about efficiency?

Organisations are beginning to use Line 1B as not only a safety function, but also to continually improve. Consider a function tasked with identifying common root causes and tactical quick fixes of problems across critical business operations, whilst remaining diligent. It’s a misconception that wholesale technology change is required for such improvements also. Often, it’s just understanding the commonalities in processes that enable the best bang for solution buck.

And who better to understand than a function who needs to know that detail to keep thing safe?