Prudential Standard SPS 220, plain-English definition from TheAICommand
← Glossary
Reference

What is APRA Prudential Standard SPS 220?

SPS 220 Risk Management is the APRA prudential standard for superannuation trustees. It requires every RSE licensee to maintain a risk management framework, a Board-approved risk appetite statement and a Board-approved risk management strategy, and to notify APRA of significant breaches.

Quick answer

SPS 220 Risk Management is the APRA prudential standard that applies to all registrable superannuation entity licensees. It requires a risk management framework appropriate to the size, business mix and complexity of the business, a Board-approved risk appetite statement, a Board-approved risk management strategy, adequate resources, and notification to APRA of significant breaches.

Verified against the current authoritative text on by the editorial team at TheAICommand.

This page is an educational summary for professionals working with AI. It is not the law and not legal advice. Always work from the current authoritative text linked below.

What does SPS 220 do?

SPS 220 establishes the risk management requirements for superannuation trustees. An RSE licensee must maintain a risk management framework appropriate to the size, business mix and complexity of its business operations, a Board-approved risk appetite statement, a Board-approved risk management strategy describing the key elements of that framework, and adequate resources to comply. It must notify APRA of a significant breach of, or material deviation from, the framework, or a discovery that the framework does not adequately address a material risk. Read the determination on the Federal Register of Legislation.

Who does it bind?

Every RSE licensee under the SIS Act 1993, in its entirety unless the standard expressly says otherwise. The Board is ultimately responsible for the framework, and for aligning it with the business plan.

What do practitioners get wrong?

Two citation errors. Reaching for CPS 220, which excludes RSE licensees in its own footnote, and quoting the 2012 determination, which determination No. 3 of 2019 revoked along with the standard made under it.

Where does AI use touch it?

At the definition of material risk. An AI system embedded in member servicing, investment decisions or administration is an internal source of inherent risk capable of materially affecting beneficiaries, so it belongs inside the framework rather than beside it. The gap-discovery notification duty then bites when the framework plainly never contemplated it. See the board risk declaration evidence chain and CPS 230.

Bottom line

SPS 220 is the trustee's risk management standard, and its Board-approved artefacts are where an AI deployment either appears or does not.

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Why does a superannuation trustee use SPS 220 rather than CPS 220?
Because CPS 220 excludes them. Footnote 1 of CPS 220 states that an RSE licensee is not treated as an APRA-regulated institution for the purposes of that standard, and directs RSE licensees to Prudential Standard SPS 220 Risk Management instead. Citing CPS 220 to a trustee names a standard that does not apply to it.
Which instrument is the current SPS 220?
Superannuation (prudential standard) determination No. 3 of 2019, registered as F2019L01578. It revoked the 2012 determination and the SPS 220 made under it, and determined the current standard, which commenced on 1 January 2020. The 2012 determination, F2012L02222, is repealed and should not be cited.
What is the risk management framework under SPS 220?
Paragraph 6 defines it as the totality of systems, structures, policies, processes and people within the RSE licensee's business operations that identify, assess, manage, mitigate and monitor all internal and external sources of inherent risk that could have a material impact on business operations or on the interests of beneficiaries.
When must a trustee notify APRA?
The key requirements include notifying APRA when the RSE licensee becomes aware of a significant breach of, or material deviation from, the risk management framework, or discovers that the risk management framework does not adequately address a material risk. The second limb is a gap-discovery trigger, not only a breach trigger.

Primary sources

← Back to the glossary

General information and education only. Not legal, compliance, financial, or professional advice. Always confirm obligations against the primary source and current regulator guidance.