Banking Act 1959 - Prudential Standard APS 310 - Audit & Related Arrangements for Prudential Reporting (08/09/2000)

Administered by Department of the Treasury

Legislation au F2006B01693 Not in force Legislative Instrument

Legislation content

I, Graeme John Thompson, a delegate of the Australian Prudential Regulation Authority (“APRA”), under subsection 11AF(1) of the Banking Act 1959 (the “Act”), DETERMINE the standards that are set out in the Schedule in relation to prudential matters to be complied with by ADIs.

 

 

Dated   8 September 2000

 

 

 [Signed]

……………………...

Graeme Thompson

Chief Executive Officer

 

 

[Note 1:  This standard comes into force on 1 October 2000.

Note 2:  In this instrument, “ADI” and “prudential matters” have the meanings given in section 5 of the Act.

Note 3:  An ADI that does not comply with a standard may be issued with directions by APRA under paragraph 11CA(1)(a) of the Act.  Non-compliance with a direction is an offence attracting a penalty of up to $27,500 for each day that the offence continues.  Officers of the ADI may also be criminally liable (see section 11CG).]

 

 

Prudential Standard

APS 310 - Audit & Related Arrangements

for Prudential Reporting

Objective

This standard aims to ensure the high quality of information provided by ADIs to APRA.  It also specifies requirements for a management attestation by ADIs in respect of the effectiveness and adequacy of their risk management processes.

 

Principles

Overview

  1. APRA’s supervisory process depends on prudential information[1] provided by ADIs[2].  APRA needs to be assured of the accuracy and integrity of the information provided to be confident that its judgements about the ADI’s management practices and compliance with prudential requirements are well-informed and soundly based.  Arrangements with an ADI’s external auditors operate to enhance the credibility of the information provided.
  2. Liaison with an ADI’s external auditor will normally be conducted under tripartite arrangements involving APRA, the ADI and its external auditor.  In the normal course, regular tripartite meeting will be held to discuss the external auditor’s reports and any matters arising from the external auditor’s review.  However, any one of the three parties can initiate meetings or discussions at any time should it consider necessary.  Notwithstanding the tripartite relationship, an ADI’s external auditor and APRA may, in exceptional circumstances as required under the Banking Act 1959, engage with each other on a bilateral basis.
  3. An ADI should keep its external auditor fully informed of APRA’s prudential requirements for the ADI.  This includes passing to the external auditor any relevant information from its communications with APRA, as well as other relevant information provided by APRA to the ADI from time to time (such as the release of new Prudential Standards or subsequent changes to any existing Prudential Standards).

 

Risk Management Systems

4.             It is the responsibility of an ADI’s board and management to ensure that the ADI meets prudential and statutory requirements and has management practices to limit risks to prudent levels.  The risk management practices must be detailed in risk management systems descriptions which should be regularly reviewed and updated (at least annually) to take account of changing circumstances.

5.             An ADI is required to provide APRA with high level descriptions of its key risk management systems covering all major areas of risks and keep APRA informed of all material changes to their risk management systems descriptions as they are made.

6.             Within 3 months[3] of its annual balance date, an ADI should provide APRA with a “declaration” from the chief executive, endorsed by the board or in the case of a foreign ADI, by a senior officer from outside Australia with responsibility for overseeing the Australian operations.

7.             The “declaration” should attest that, for the financial year past,:

(a)          the board and management have identified the key risks facing the ADI;

(b)         the board and management have established systems to monitor and manage those risks including, where appropriate, by setting and requiring adherence to a series of prudent limits, and by adequate and timely reporting processes;

(c)          these risk management systems are operating effectively and are adequate having regard to the risks they are designed to control; and 

(d)         the risk management systems descriptions provided to APRA are accurate and current.

8.             If an ADI feels it needs to qualify the declaration prescribed in paragraph 7, it would need to explain the reasons for the qualifications, as well as provide plans for corrective action.

 

Role of Internal Audit

11.       The scope of the internal audit should include a review of the processes and controls put in place by management to ensure compliance with APRA’s prudential requirements.

12.       Internal auditors should be represented in tripartite meetings with APRA, the ADI and its external auditor.

 

Role of External Auditors

13.        External auditors should, within 3 months[4] of the annual balance date of an ADI, provide simultaneously to APRA and the Audit Committee, or in the case of foreign ADIs, the senior country managers, a report up to the latest balance date detailing the external auditor’s opinions[5] as to whether:

(a)          the ADI has observed all the prudential standard requirements which APRA has set for the ADI;

(b)         the statistical and financial data provided by the ADI to APRA are reliable;

(c)          the ADI has complied with statutory banking requirements, any conditions on the authority to carry on banking business, and any other conditions imposed by APRA in relation to the ADI’s operations; and

(d)         there are any matters which, in the auditor’s opinion, may have the potential to prejudice materially the interests of depositors of the ADI.

14.        Management Letters relating to work undertaken by the auditor which have a bearing on the auditor’s opinions as required in paragraph 13 should accompany the report.

15.        APRA may, in consultation with an ADI, request its external auditor or, where appropriate, other external auditors to undertake a specific review of a particular aspect of the ADI’s operations or risk management system.  The cost of specific reviews will be borne by the ADI.

16.        The specific reviews will be conducted along the lines of an “Engagement to Perform Agreed-Upon Procedures” (refer Auditing Standard 904).  The report of such reviews should be submitted to APRA and the ADI simultaneously, within 3 months after the review is commissioned.

17.        In addition to the requirements of this Standard, the Banking Act 1959 (“the Act”) requires an auditor of an ADI to inform APRA if the auditor has reasonable grounds for believing that:

(a)          the ADI is insolvent, or there is a significant risk that the ADI will become insolvent; or

(b)         the ADI has failed to comply with a prudential standard, a requirement under the Act or the regulations, a direction under Division 1BA of Part II or a condition of its section 9 authority; or

(c)          an existing or proposed state of affairs may materially prejudice the interests of depositors of the ADI.

18.        Under the Act, APRA may, by notice in writing, require an auditor of an ADI to provide information about the ADI if APRA considers that the provision of the information will assist APRA in performing its functions under the Act.

 

Notes to Banking Act 1959 - Prudential Standard APS 310Audit & Related Arrangements for Prudential Reporting (08/09/2000)

 

Note 1

Banking Act 1959 – Prudential standard APS 310 – Audit & Related Arrangements for Prudential Reporting (08/09/2000) (in force under section 11AF of the Banking Act 1959) as shown in this compilation comprises the principal Banking Act 1959 – Prudential standard APS 310 – Audit & Related Arrangements for Prudential Reporting (08/09/2000) (made on 8 September 2000) amended as indicated in the Tables below.

Table of Legislative Instruments

Description of instrument

Date of notification in Gazette or registration in Federal Register of Legislative Instruments

Date of
commencement

Application, saving or
transitional provisions

Banking Act 1959 – Prudential Standard APS310 (F2006B01693)

20 September 2000

1 October 2000

 

Banking (prudential standards) determination No. 2 of 2006 (F2006L01461)

10 May 2006

1 October 2006

 

  

 

Table of Amendments

ad. = added or inserted      am. = amended      rep. = repealed      rs. = repealed and substituted

Provision affected

How affected

Heading “Audit Committee”……………….

rep. No. 2 of 2006

Heading “Internal Audit”…

rs. No. 2 of 2006

Paragraph 9……………….

rep. No. 2 of 2006

Paragraph 10……………...

rep. No. 2 of 2006

Paragraph 11……………...

am. No. 2 of 2006

Paragraph 12……………...

am. No. 2 of 2006

 

1 This includes statutory and prudential returns, financial statements and risk management system descriptions.

[2] For the purpose of this Standard, reference to “an ADI” or “ADIs” includes locally incorporated ADIs and foreign ADIs (branches), unless otherwise indicated.

[3] 4 months for non-disclosing entities.

[4] See footnote 3.

[5] External auditors should consult the Auditing Guidance Statement in preparing their report to APRA.

Overview

The Prudential Standard APS 310 - Audit & Related Arrangements for Prudential Reporting was enacted in 2000 under the Banking Act 1959 by the Australian Prudential Regulation Authority (APRA). This standard was introduced to address the need for ensuring high quality prudential information provided by Authorised Deposit-taking Institutions (ADIs) to APRA, thereby enhancing the credibility and accuracy of the information upon which APRA bases its supervisory decisions. The policy objective is to ensure that APRA’s judgements about an ADI’s management practices and compliance with prudential requirements are well-informed and soundly based. The standard sets out requirements for management attestations, risk management processes, and the roles of both internal and external auditors in maintaining the integrity and effectiveness of prudential reporting.

Scope and Application

The Prudential Standard APS 310, set forth under the Banking Act 1959 by the Australian Prudential Regulation Authority (APRA), applies to Australian Deposit-taking Institutions (ADIs), which include both locally incorporated ADIs and foreign ADIs operating within Australia. The scope of the Act encompasses the prudential information that ADIs must provide to APRA to ensure the accuracy and integrity of the data used by APRA to assess the management practices and compliance of ADIs with prudential requirements. The Act mandates that ADIs maintain effective risk management systems and provide detailed descriptions of these systems to APRA, which must be updated annually. Additionally, ADIs are required to submit a declaration from the chief executive, endorsed by the board, attesting to the effectiveness of their risk management systems. The standard also outlines the roles of both internal and external auditors, who are expected to provide reports on the ADI's compliance with prudential standards and statutory requirements. APRA may request specific reviews from external auditors to examine particular aspects of an ADI’s operations or risk management system, with the costs borne by the ADI. Furthermore, under the Banking Act, auditors must report to APRA if they have reasonable grounds to believe that the ADI is insolvent, has failed to comply with prudential standards or statutory requirements, or if there are circumstances that may materially prejudice the interests of depositors. This standard extends its application through subordinate instruments, as evidenced by the 2006 amendment which modified certain provisions related to internal audit and audit committee roles.

Key Provisions

The main operative sections of this legislation outline the standards that ADIs (Authorised Deposit-taking Institutions) must comply with regarding prudential matters, as determined by APRA under section 11AF(1) of the Banking Act 1959 (the "Act") (section 1). The primary objective of Prudential Standard APS 310 - Audit & Related Arrangements for Prudential Reporting is to ensure that ADIs provide high-quality information to APRA, including risk management system descriptions and management attestations (section 4). ADIs are required to provide APRA with key risk management systems descriptions and keep APRA updated on any material changes (section 5). Within three months of their annual balance date, ADIs must submit a declaration from the chief executive, endorsed by the board, attesting to the effectiveness and adequacy of their risk management systems (section 6 and 7). The declaration may include qualifications if needed, along with plans for corrective action (section 8). The obligations and requirements imposed by this Act on ADIs include ensuring that their board and management are responsible for meeting prudential and statutory requirements and establishing risk management practices (section 4). ADIs must provide APRA with high-level descriptions of their key risk management systems, covering all major areas of risk, and keep APRA informed of all material changes (section 5). The internal audit scope should include a review of the processes and controls put in place by management to ensure compliance with APRA's prudential requirements (section 11). External auditors must provide a report to APRA and the Audit Committee or senior country managers within three months of the annual balance date, detailing their opinions on whether the ADI has complied with prudential standard requirements, statutory banking requirements, and any other conditions imposed by APRA (section 13). Additionally, external auditors must inform APRA if they have reasonable grounds for believing that the ADI is insolvent or has failed to comply with prudential standards, requirements, or directions (section 17). The Banking Act 1959 imposes various consequences for non-compliance with the Prudential Standard APS 310 - Audit & Related Arrangements for Prudential Reporting. An ADI that does not comply with a standard may be issued with directions by APRA under paragraph 11CA(1)(a) of the Act (Note 3). Non-compliance with a direction is an offence, attracting a penalty of up to $27,500 for each day that the offence continues (Note 3). Officers of the ADI may also be criminally liable under section 11CG (Note 3). Furthermore, APRA may require an auditor of an ADI to provide information about the ADI if APRA considers that the provision of the information will assist APRA in performing its functions under the Act (section 18).

Legal classification tags

Area of Law
Banking Law
Instrument
Legislative Instrument
Concepts
Definitions & Interpretation
Compliance Obligations
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.