Live · updated from trending searches

The Risk Glossary

300+ curated definitions across ERM, cyber, privacy, AML/CTF, ESG and emerging risk — tuned to Australian regulatory vocabulary.

12 TERMS

Operational

CPS 230 Tolerance Level

The board-approved maximum acceptable disruption to a critical operation — time, data loss and minimum service — required under APRA CPS 230.

Privacy

Notifiable Data Breach

An eligible data breach under the Privacy Act 1988 likely to result in serious harm, triggering notification to the OAIC and affected individuals.

Cyber

Essential Eight Maturity Level

A 0–3 rating of how completely an organisation has implemented the ACSC's eight mitigation strategies against escalating tradecraft.

Third Party

Material Service Provider

A provider on which an APRA-regulated entity relies for a critical operation, or that exposes it to material operational risk — registrable under CPS 230.

Critical Infra

System of National Significance

A critical infrastructure asset declared under the SOCI Act attracting enhanced cyber obligations including incident response planning and vulnerability reports.

Governance

FAR Accountable Person

A senior executive registered under the Financial Accountability Regime with prescribed responsibilities and deferred-remuneration consequences.

ESG

Scope 3 Emissions

Indirect value-chain emissions — 15 categories — disclosable from year two of an entity's AASB S2 reporting.

AML/CTF

Suspicious Matter Report

A report to AUSTRAC where a reporting entity suspects on reasonable grounds a link to crime — 24 hours for terrorism financing, 3 business days otherwise.

Audit

Three Lines Model

Governance model separating management controls, risk & compliance oversight, and independent internal audit assurance.

AI

Shadow AI

Unauthorised or undisclosed use of AI tools by employees outside formal governance — an emerging APRA and OAIC supervisory theme.

ERM

Risk Appetite Statement

A board-approved articulation of the risk the entity is willing to take — mandated for APRA entities under CPS 220.

Cyber

IRAP Assessment

An Infosec Registered Assessors Program review against the ISM, commonly required for cloud services handling Australian government data.