Compliance standards for Finance Sector

Pertains to banking, insurance, and financial services, focusing on regulatory compliance, risk management, and financial integrity. Updated continuously, with mapped controls and expert guidance from 6clicks.

56 items

All Finance Sector content · 56 items

GRCStandard

APS 222 — Prudential Standard APS 222: Associations with Related Entities

APS 222 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) aimed at ensuring that authorised deposit-taking institutions (ADIs) identify, monitor, and control risks related to their associations and dealings with related entities. It mandates policies and limits on exposures to mitigate contagion and step-in risks.

Australian Prudential Regulation Authority (APRA) • Australia • vJanuary 2015

View details
GRCRegulation

APS 220 — Prudential Standard APS 220 Credit Risk Management

APS 220 sets requirements for authorised deposit-taking institutions (ADIs) to establish a comprehensive credit risk management framework. The standard includes strategies, policies, and procedures for identifying, assessing, and mitigating credit risks.

Australian Prudential Regulation Authority (APRA) • Australia • vSeptember 2020

View details
GRCRegulation

APS 210 — Prudential Standard APS 210 Liquidity

APS 210 Liquidity is a prudential standard issued by APRA requiring authorised deposit-taking institutions (ADIs) to adopt prudent practices in managing liquidity risks. It mandates maintaining adequate liquidity to meet obligations under various operating scenarios, including severe stress situations.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCRegulation

3PS 310 — Banking, Insurance and Life Insurance (Prudential Standard) Determination No. 4 of 2016 - Prudential Standard 3PS 310 Audit and Related Matters

This prudential standard sets out auditing and related responsibilities for entities operating within the banking, insurance, and life insurance sectors in Australia. It is part of the regulatory framework administered by the Department of Treasury under the Banking Act, Insurance Act, and Life Insurance Act.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCRegulation

Prudential Standard 3PS 222 — Banking, Insurance and Life Insurance (Prudential Standard) Determination No. 3 of 2016 - Prudential Standard 3PS 222 Intra-group Transactions and Exposures

Prudential Standard 3PS 222 establishes requirements for managing intra-group transactions and exposures within banking, insurance, and life insurance entities in Australia. It aims to ensure financial stability and risk management in group entities regulated under relevant Australian financial laws.

Department of the Treasury • Australia • v14 September 2016

View details
GRCRegulation

Prudential Standard APS 221 Large Exposures — Banking (prudential standard) determination No. 4 of 2019

This is a prudential regulatory instrument issued under the Banking Act 1959 in Australia, focusing on controlling large exposures and risk concentrations within the banking sector. It includes provisions for boards, measurement, limits, and notification requirements related to large exposures.

Australian Prudential Regulation Authority (APRA) • Australia • vF2019L01599

View details
GRCRegulation

Prudential Standard 3PS 221- Aggregate Risk Exposures — Banking, Insurance and Life Insurance (prudential standard) determination No. 2 of 2016 - Prudential Standard 3PS 221 Aggregate Risk Exposures

This legislative determination establishes prudential requirements for managing and reporting aggregate risk exposures within banking, insurance, and life insurance sectors. It aims to ensure robust risk management practices across these industries.

Australian Prudential Regulation Authority (APRA) • Australia • vF2016L01429

View details
GRCGuideline

APG 223 — Prudential Practice Guide APG 223 Residential Mortgage Lending

APG 223 is a detailed guidance document issued by the Australian Prudential Regulation Authority (APRA) to assist authorized deposit-taking institutions (ADIs) in managing risks associated with residential mortgage lending. It provides recommendations on best practices for loan serviceability assessments and setting buffer and floor rates.

Australian Prudential Regulation Authority (APRA) • Australia

View details
CybersecurityStandard

PPG 511 — Prudential Practice Guide 511 - Remuneration

Prudential Practice Guide (PPG) 511 - Remuneration is APRA guidance that helps regulated institutions design and manage remuneration arrangements that support prudent risk management, strong governance, and sustainable organisational performance.

Australian Prudential Regulation Authority (APRA) • Australia • v30 November 2009

View details
CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
GRCLaw

ASIC Act — Australian Securities and Investments Commission Act 2001

This Act establishes the legal framework for the operation of the Australian Securities and Investments Commission (ASIC), which is responsible for regulating company, financial services, and consumer protection laws in Australia. It outlines ASIC's powers, functions, and responsibilities while detailing provisions for consumer protection and fair competition in financial services industries.

Australian Government • Australia • vNo. 91, 1 July 2023

View details
GRCGuideline

RG 78 — Regulatory Guide 78: Breach Reporting by AFS Licensees and Credit Licensees

This guide provides Australian Financial Services (AFS) licensees and credit licensees with instructions on reporting certain legal breaches to ASIC, as required under the Corporations Act 2001 and the National Consumer Credit Protection Act 2009.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 205 — Regulatory Guide 205: Credit Licensing: General Conduct Obligations

RG 205 is a regulatory guide issued by ASIC detailing the general conduct obligations for credit licensees, license applicants, and unlicensed carried-over instrument lenders. It helps entities comply with the National Credit Act and outlines specific areas of focus during compliance assessments.

Australian Securities & Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 207 — Regulatory Guide 207: Credit licensing: Financial requirements

RG 207 outlines the minimum expectations for Australian credit licensees to comply with the financial resource requirements under the National Consumer Credit Protection Act 2009. It provides guidance on how licensees should demonstrate adequate financial resources to ASIC during license application and annual compliance certification.

Australian Securities & Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 206 — Regulatory Guide 206: Credit licensing: Competence and training

Regulatory Guide 206 outlines the minimum expectations for credit licensees in demonstrating organisational competence as required by the National Credit Act. It covers compliance obligations related to qualifications, experience, training, and competence for individuals involved in credit activities.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 273 — Regulatory Guide 273: Mortgage brokers: Best interests duty

RG 273 is a regulatory guide issued by ASIC that provides guidance for mortgage brokers and Australian credit licensees on complying with best interests obligations outlined in Part 3-5A of the National Consumer Credit Protection Act 2009. It includes steps to minimize the risk of non-compliance.

Australian Securities & Investments Commission (ASIC) • Australia • v2020

View details
GRCGuideline

RG 210 — Regulatory Guide 210: Compensation and Insurance Arrangements for Credit Licensees

ASIC Regulatory Guide 210 outlines the compensation and insurance arrangements required for credit licensees in Australia. It primarily mandates professional indemnity insurance to ensure financial resources are available for consumer compensation claims.

Australian Securities and Investments Commission (ASIC) • Australia • vMarch 2010

View details
GRCGuideline

RG 209 — Regulatory Guide 209 Credit licensing: Responsible lending conduct

RG 209 is a regulatory guide issued by the Australian Securities & Investments Commission (ASIC). It outlines responsible lending obligations for credit licensees and applicants under Chapter 3 of the National Consumer Credit Protection Act 2009, providing steps to ensure compliance and reduce risks.

Australian Securities & Investments Commission (ASIC) • Australia • v2019

View details
PrivacyRegulation

CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)

The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.

Australian Government • Australia • v2.1

View details
GRCRegulation

NCCP Regulations — National Consumer Credit Protection Regulations 2010

This regulation provides detailed requirements under the National Consumer Credit Protection Act 2009 to govern the licensing, responsible lending, credit contracts, and compliance monitoring for entities providing credit services in Australia. It aims to ensure transparency and protection for consumers in financial and credit transactions.

Australian Government • Australia • v2021-12

View details
GRCLaw

SIS Act — Superannuation Industry (Supervision) Act 1993

The Superannuation Industry (Supervision) Act 1993 establishes the regulatory framework for superannuation funds in Australia. It defines compliance standards for trustees, funds, and associated entities, aiming to ensure proper administration and protection of member benefits.

Australian Government • Australia • vNo. 78, 1993

View details
PrivacyRegulation

FCA BCOBS — Banking: Conduct of Business Sourcebook (BCOBS)

The FCA's Banking: Conduct of Business Sourcebook (BCOBS) applies to firms accepting deposits from banking customers, focusing on protecting retail customers in banking and payment services. It includes key recordkeeping requirements, such as notifications of cancellation rights.

Financial Conduct Authority (FCA) • United Kingdom • vFebruary 2026

View details
PrivacyLaw

NCCP Act 2009 — National Consumer Credit Protection Act 2009

The National Consumer Credit Protection Act 2009 is an Australian law that regulates the provision of consumer credit and financial services in the country. It outlines licensing requirements for entities engaged in credit activities and includes protections for consumers against unsuitable credit agreements.

Australian Government • Australia • vNo. 134

View details
GRCGuideline

RG 96 — Regulatory Guide 96: Debt Collection Guideline: For Collectors and Creditors

This guideline was jointly produced by the Australian Competition and Consumer Commission (ACCC) and the Australian Securities and Investments Commission (ASIC) to outline how Commonwealth consumer protection laws apply to debt collection. It applies to creditors and external agencies involved in debt collection, and provides guidance to debtors.

Australian Securities and Investments Commission (ASIC) • Australia • v13 April 2021

View details
Critical InfrastructureRegulation

DORA — Regulation (EU) 2022/2554 - Digital Operational Resilience Act

Regulation (EU) 2022/2554, known as DORA, establishes a unified framework for digital operational resilience in the European Union's financial sector. It aims to ensure financial entities can withstand, recover, and adapt to ICT-related disruptions while safeguarding the stability and integrity of the financial system.

European Parliament and Council of the European Union • European Union

View details
GRCLaw

SOX — Sarbanes-Oxley Act of 2002

The Sarbanes-Oxley Act (SOX) is a U.S. federal law enacted in 2002 to enhance corporate accountability and financial transparency in response to major corporate scandals. It applies to publicly traded companies, mandating stricter financial reporting, internal controls, and governance standards.

US Government • United States

View details
GRCLaw

AML/CTF Act — Anti-Money Laundering and Counter-Terrorism Financing Act 2006

This is an Australian law established to prevent money laundering and financing of terrorism. It imposes obligations on certain entities to implement anti-money laundering and counter-terrorism financing measures, including customer due diligence, reporting, and record-keeping.

Australian Government • Australia • vCompilation No. 60, 31 March 2026

View details
GRCLaw

AML/CTF Rules — Anti-Money Laundering and Counter-Terrorism Financing Rules 2025

The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 provide detailed obligations on reporting entities in Australia to prevent financial crimes, including money laundering and terrorism financing. Administered by the Department of Home Affairs, it supports compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.

Australian Government • Australia • vCompilation No. 1, 31 March 2026

View details
GRCLaw

CBK Law — Law No. (32) of 1968 Concerning Currency, The Central Bank of Kuwait and The Regulation of Banking

Law No. (32) of 1968 establishes the legal framework for the establishment and operation of the Central Bank of Kuwait (CBK) and governs currency issuance, banking regulations, and financial supervision within Kuwait. It includes amendments to address evolving economic and regulatory needs.

Central Bank of Kuwait • Kuwait • v2021

View details
CybersecurityGuideline

Guidelines on ICT and Security Risk Management

The EBA Guidelines establish requirements for credit institutions, investment firms, and payment service providers on mitigating and managing information and communication technology (ICT) risks. They aim to ensure a consistent and robust approach to ICT and security risk management across the EU financial sector.

European Banking Authority (EBA) • European Union • v2025 update

View details
CybersecurityStandardControl set

PCI DSS — PCI Data Security Standard (PCI DSS)

The PCI Data Security Standard (PCI DSS) is a global security standard designed to protect payment card account data. It establishes technical and operational security requirements for organizations that handle cardholder data.

PCI Security Standards Council • v4.x

View details
GRCRegulation

EU 2016/1675 — Commission Delegated Regulation (EU) 2016.1675 on High Risk Third Countries

This regulation identifies high-risk third countries with strategic deficiencies in the area of anti-money laundering (AML) and countering the financing of terrorism (CFT). It supplements Directive (EU) 2015/849, providing a legal framework for such identifications.

European Commission • European Union • v14 July 2016

View details
GRCStandard

SPS 521 — Prudential Standard SPS 521 - Conflicts of Interest

Prudential Standard SPS 521 is a legislative instrument under the Superannuation Industry (Supervision) Act 1993. It sets requirements for superannuation entities in Australia to appropriately manage conflicts of interest to ensure compliance and trust in their operations.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCStandard

SPS 310 — Prudential Standard SPS 310 Audit and Related Matters

Prudential Standard SPS 310 establishes requirements for conducting audits and related matters for the superannuation industry in Australia. It ensures compliance with financial reporting and auditing practices in accordance with regulatory standards.

Australian Prudential Regulation Authority (APRA) • Australia

View details
CybersecurityFramework

FSSCP — The Financial Services Sector Cybersecurity Profile

The Financial Services Sector Cybersecurity Profile is a scalable and extensible assessment tool designed to help financial institutions manage cyber risks and demonstrate regulatory compliance. It is based on the NIST Cybersecurity Framework and offers a tailored approach to streamline cybersecurity assessments globally.

Financial Services Sector Coordinating Council (FSSCC) • Global

View details
GRCStandard

CPS 520 — Prudential Standard CPS 520 Fit and Proper

The Prudential Standard CPS 520 sets out the requirements for assessing the fitness and propriety of responsible persons in APRA-regulated institutions, including banks, insurers, and private health insurers. It ensures that key positions are held by individuals who meet high standards of integrity and competence.

Australian Prudential Regulation Authority (APRA) • Australia

View details
PrivacyRegulation

CDR Designation 2019 — Consumer Data Right (Authorised Deposit Taking Institutions) Designation 2019

This legislative instrument designates the banking sector in Australia as subject to the Consumer Data Right (CDR). It specifies which classes of information are included or excluded under the CDR framework.

Australian Government • Australia • v14 July 2023

View details
GRCGuideline

RG 175 — RG 175 AFS licensing: Financial product advisers—Conduct and disclosure

This regulatory guide outlines the conduct and disclosure obligations of financial product advisers who provide advice to retail clients in Australia. It focuses on requirements under Part 7.7 and Division 2 of Part 7.7A of the Corporations Act.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCStandard

CPS 231 — Prudential Standard CPS 231 Outsourcing

The Prudential Standard CPS 231 establishes requirements for outsourcing arrangements by financial institutions regulated by the Australian Prudential Regulation Authority (APRA). It aims to ensure that risks associated with outsourcing are effectively managed.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCGuideline

RG 1 — Regulatory Guide 1: Applying for and varying an AFS licence

This regulatory guide provides details on the process for applying for and varying an Australian Financial Services (AFS) licence. It outlines ASIC’s approach to assessing applications and the required documentation for submission.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 271 — Regulatory Guide: 271 Internal Dispute Resolution

This regulatory guide outlines enforceable standards and requirements for internal dispute resolution (IDR) systems for financial firms in Australia. It specifies the obligations these firms must meet to comply with ASIC's IDR standards.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 274 — Regulatory Guide 274: Product Design and Distribution Obligations

This guide, issued by ASIC, outlines obligations for issuers and distributors of financial products under Part 7.8A of the Corporations Act. It provides ASIC's interpretation, expectations for compliance, and approach for administering these obligations.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 181 — RG 181 AFS licensing: Managing conflicts of interest

This regulatory guide outlines the legal obligations under the Corporations Act for Australian financial services (AFS) licensees to have adequate arrangements to manage conflicts of interest. It provides specific guidance on identifying conflicts, implementing effective arrangements, and managing conflicts using appropriate tools.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 133 — RG 133 Funds Management and Custodial Services: Holding Assets

RG 133 outlines the Australian financial services (AFS) licence obligations for entities involved in managing and holding client assets. It sets minimum standards that apply to responsible entities of registered managed investment schemes, licensed custody providers, MDA providers, and IDPS operators.

Australian Securities and Investments Commission (ASIC) • Australia

View details
CybersecurityGuideline

CPG 234 — CPG 234 Information Security

This standard provides information security guidance for Australian financial institutions regulated by APRA. It aims to ensure operational resilience and protect against information security threats.

Australian Prudential Regulation Authority (APRA) • Australia • vJune 2019

View details
GRCGuideline

CPG 235 — Prudential Practice Guide CPG 235 - Managing Data Risk

The Prudential Practice Guide CPG 235 provides guidance for Australian financial institutions on how to effectively manage data risk. It focuses on identifying, assessing, and mitigating risks associated with data to ensure its integrity, availability, and confidentiality.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCStandard

CPS 220 — Prudential Standard CPS 220 Risk Management

CPS 220 is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) outlining risk management requirements for regulated entities. It establishes standards for institutions to identify, assess, and manage risks effectively to ensure financial stability and compliance.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCStandard

CPS 226 — Prudential Standard CPS 226: Margining and Risk Mitigation for Non-centrally Cleared Derivatives

This is an Australian standard issued by APRA outlining the requirements for margining and risk mitigation of non-centrally cleared derivatives. It ensures financial institutions operate with adequate practices to manage counterparty risk.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCStandard

CPS 232 — Prudential Standard CPS 232 Business Continuity Management

CPS 232 is an Australian Prudential Standard that outlines the requirements for regulated entities to maintain and manage effective business continuity plans. It ensures that entities are prepared to address and recover from disruptions to their operations.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCStandard

CPS 230 — Prudential Standard CPS 230 Operational Risk Management

CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks. It covers obligations on governance, risk frameworks, and risk controls to ensure resilience against operational disruptions.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCGuideline

RG 166 — RG 166 AFS Licensing: Financial Requirements

RG 166 provides financial requirements for holders of an Australian Financial Services (AFS) licence, which vary based on the financial products and services offered. It excludes entities regulated by the Australian Prudential Regulation Authority (APRA) that are not required to comply with specific provisions of the Corporations Act 2001.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 104 — Regulatory Guide 104: AFS Licensing: Meeting the General Obligations

This regulatory guide provides information for Australian Financial Services (AFS) licensees and applicants about compliance with general obligations under section 912A(1) of the Corporations Act. It outlines what ASIC looks for during assessments of compliance.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 105 — RG 105 AFS Licensing: Organisational Competence

This guide outlines the requirements for Australian financial services (AFS) licensees and applicants to meet the 'organisational competence obligation' under the Corporations Act. It provides clarity on compliance expectations relating to the qualifications, experience, and capability of key individuals within the licensee's organization.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCStandard

CPS 510 — Prudential Standard CPS 510 Governance

This is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) to provide requirements for governance of regulated entities. It focuses on promoting sound corporate governance practices.

Australian Prudential Regulation Authority (APRA) • Australia

View details
GRCGuideline

RG 270 — Regulatory Guide 270: Whistleblower Policies

This guide provides entities with information on establishing whistleblower policies that comply with legal obligations under the Corporations Act. It includes guidance for both entities required to have such policies and those managing whistleblowing under legal frameworks.

Australian Securities and Investments Commission (ASIC) • Australia

View details
GRCGuideline

RG 259 — Regulatory Guide 259: Risk management systems of fund operators

This regulatory guide provides specific guidance for Australian financial services (AFS) licensees that are responsible entities or corporate directors (fund operators) on how to comply with their obligation under s912A(1)(h) of the Corporations Act 2001 to maintain adequate risk management systems.

Australian Securities and Investments Commission (ASIC) • Australia

View details

Manage Finance Sector compliance with 6clicks

The 6clicks platform maps these regulations to controls, evidence and risks — automatically.