Insights
Our views on governance, risk and compliance trends and practices, trending technologies and other matters affecting Australia and Global markets.
Featured Stories
Internal Audit Focus Areas for 2026
Katherina Sau (CA CIA), Jayashri Sood & Meet Vyas 26 Mar 2026
Organisations continue to face heightened regulatory oversight, rapid technological change, and growing expectations around governance, risk management, and operational resilience. Internal Audit plays a critical role in providing assurance that risk and control frameworks are effective and aligned to strategic objectives. The IIA Global Internal Audit Standards (GIAS) raise the bar on risk-based planning, technology...
Strengthening CPS 230 Resilience Through Internal Audit
Katherina Sau (CA CIA) & Branden Lee 2 Feb 2026
Since 1 July 2025, APRA’s Prudential Standard CPS 230 Operational Risk Management has been fully enforceable. The standard now shifts the focus from readiness to demonstrating resilience, requiring entities to prove that operational risk frameworks, business continuity plans and service provider arrangements operate effectively in practice. Under CPS 230, Internal Audit has two mandated responsibilities...
Six Months of CPS 230: What does the next phase of resilience look like?
Poppy Fassos & Lauren Daluz 15 Dec 2025
As APRA sharpens its focus on operational risk and organisations continuously embed regulatory requirements, the evolving business continuity landscape has exposed key areas where organisations can evolve to build true operational resilience. CPS 230 Embedment Retrospective It has now been six months since the Australian Prudential Regulatory Authority (APRA) has enforced Prudential Standard (CPS) 230...
Building Confidence in Vendor Business Continuity
Romana Bizjak & Poppy Fassos 24 Sep 2025
As organisations become more reliant on third-party providers, the risk to operational continuity grows. Validating vendor Business Continuity Management (BCM) capabilities should be standard practice, not just for regulatory compliance, but to protect operations, ensure resilience across the value chain, and maintain stakeholder trust. APRA’s CPS 230 Prudential Standard on Operational Risk Management sets a...
Submission to the Guiding Principles to Embed Zero Trust Culture
Amstelveen 25 Mar 2025
Amstelveen welcomes the opportunity to provide feedback on the proposed guiding principles to embed a Zero Trust Culture across the whole of Government.
Amstelveen is a specialist risk, technology and compliance consultancy which operates across Australia and New Zealand. Our clients include public and private sector organisations which generally have a high degree of exposure to technology and cyber-related risks, such as those in government, financial services, telecommunications and energy.
In this submission, we have responded to a subset of the questions listed in the consultation paper titled “Guiding Principles to embed Zero Trust Culture”. Our response follows the review of the Zero Trust Culture principles listed in the consultation paper, and the Protective Security Policy Framework (PSPF) release in 2024...
Areas for Internal Audit Focus in 2025
Katherina Sau (CA CIA), Nathan Manlolo & Jasmine Huang 15 Nov 2024
As organisations face evolving operational, technological, and regulatory challenges, Internal Audit functions must adapt their assurance plans to ensure that activities and insights remain of high relevance to Boards and Executives. In this article, we highlight key themes to help Internal Audit teams enhance their capabilities, align with strategic objectives, and use new technologies to...
A Proactive Approach to Manage Crises
Romana Bizjak, Luke Doran, Sri Narain, Kenneth Chu & Lauren Daluz 6 Nov 2024
Heightened focus on cyber attacks, service outages and supply chain disruptions has made crisis management more important than ever, yet increasingly more complex. With these newfound complexities in the business landscape, there are opportunities for organisations of all sizes to enhance their crisis preparedness. This document presents a lifecycle approach to uplift organisational resilience and...
Key Insights from the OAIC’s 2024 Half-Year Report
Amstelveen 31 Oct 2024
Who is the OAIC? The Office of the Australian Information Commissioner (OAIC) is an independent national regulator whose purpose is to promote and uphold individuals’ rights to privacy under the Privacy Act 1988 and information under the Freedom of Information Act 1982. What are Notifiable Data Breaches? Under the aforementioned legislation, organisations and agencies...
Cyber Security Awareness Month
Amara Tut & Roy van der Voort 24 Oct 2024
As we navigate the internet, we leave behind a trail of data with every action we take. We form our digital footprint as a record of our online activities, including the websites we visit, the emails we send, the social media posts we share, and the applications that we use. A large digital footprint holds...
IIA Global Internal Audit Standards Countdown
Amstelveen 23 Oct 2024
Are you prepared for the new IIA GLOBAL internal Audit Standards? The new Standards will take effect in January 2025, with early adoption encouraged for internal audit functions. In January 2024, the Institute of Internal Auditors (IIA) released the revised Global Internal Audit Standards to enhance the 2017 framework. The new Standards aim to promote...
Xanadu IRM Release Summary
Amstelveen 10 Oct 2024
ServiceNow‘s latest Xanadu release introduced many enhancements and fixes across its ecosystem. Particularly for the Integrated Risk Management (IRM) product, we have conveniently summarised the Xanadu release notes, giving our view on how they can practically improve risk processes in-tool. Our favourite IRM enhancements from the ServiceNow Xanadu release Smart Assessment Engine for a better...
Submission to the Mandatory Guardrails for AI in High-Risk Settings
Amstelveen 9 Oct 2024
Amstelveen welcomes the opportunity to provide feedback on the proposed Mandatory Guardrails for AI in High-risk Settings.
Amstelveen is a specialist risk and compliance consultancy which operates across Australia and New Zealand. Our clients include public and private sector organisations at the forefront of AI deployment and which generally have a high degree of exposure to technology and data-related risks, such as those in financial services, government, telecommunications and energy.
In this submission, we have responded to a subset of the questions listed in the proposals paper titled “Proposals paper for introducing mandatory guardrails for AI in high-risk settings”.
Reflections on the first Board Approved Annual Report under the SOCI Act
Louis Wellard & Brandon Nguyen 26 Sep 2024
Boards of critical infrastructure assets face heightened expectations to ensure a robust risk management framework is in place to understand and mitigate operational risks, ensuring compliance with transformative Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) reforms. As the due date for the first board-approved annual report required under the Act fast approaches; this...
A Turning Point for Superannuation Risk and Compliance
David van Gogh 30 Aug 2024
APRA’s imposition of additional licence conditions on United Super Pty Ltd and BUSS (Queensland) Pty Ltd. echo past catalysts that transformed Australia’s Financial Services governance, signaling regulatory changes ahead. Introduction Three moments have been pivotal for the uplift of risk and compliance practices in the Australian Financial Services Industry. Implications This followed widespread media coverage...