APRA Level 3 Conglomerate Standards: The 1 October 2026 Sunset

On 27 July 2026, the Australian Prudential Regulation Authority (APRA) confirmed that it will remake three of the APRA Level 3 conglomerate standards before they automatically lapse on 1 October 2026. The three instruments are Prudential Standard 3PS 221 Aggregate Risk Exposures, Prudential Standard 3PS 222 Intra-group Transactions and Exposures, and Prudential Standard 3PS 310 Audit and Related Matters. APRA has stated that it will carry the changes through with administrative updates only, and that they do not introduce new requirements for conglomerate groups.

For a group risk or prudential reporting team inside a diversified Australian financial group, the operative question is narrow: does anything you build, calculate, or submit change before the sunset date? On APRA’s own account, the answer is no. APRA states that the three standards will be remade without new requirements. The confirmed amendments are updated references, an interpretation paragraph and a previous-exercise-of-discretion paragraph; the replacement determinations and their citations will change once made and registered.

That makes this a maintenance cycle, and it deserves a maintenance response: confirm which standards you rely on, check that your policies and control documents point at the correct instrument, and diary the sunset date so a live requirement does not lapse in your control environment by accident.

Related reading: our guide to FICOD financial conglomerate supervision in the EU.

Key dates for the remake

The remaking runs on a short, sunset-driven calendar. These are the operative dates a reporting team should hold.

  • 1 July 2017: the current versions of 3PS 221, 3PS 222 and 3PS 310 commenced.
  • 31 March 2026: APRA opened its consultation on remaking the three Level 3 conglomerate standards.
  • 29 May 2026: the consultation closed to submissions.
  • 27 July 2026: APRA published its response to submissions and confirmed it will remake the three standards with administrative updates only.
  • 1 October 2026: the date on which the current versions would otherwise sunset. The remade instruments are intended to be in place before this date so the requirements continue without a gap.

What APRA confirmed on 27 July 2026

APRA released its response to submissions on the consultation to remake three Level 3 conglomerate prudential standards ahead of their scheduled sunset on 1 October 2026. Following that consultation, APRA said it will remake 3PS 221, 3PS 222 and 3PS 310 with administrative updates only, and that the updates do not introduce new requirements for conglomerate groups.

Two words in that statement carry the weight for reporting teams: administrative, and only. Administrative signals that the edits are of the housekeeping kind, without touching substantive policy. Only signals that APRA has closed the door on wider change through this instrument, at least for now. The consultation ran for roughly two months, from 31 March to 29 May 2026, and APRA has now moved to finalise the remake before the sunset falls.

The announcement is bounded to 3PS 221, 3PS 222 and 3PS 310. APRA deferred the Level 3 capital components in 2016 and did not finalise proposed 3PS 110, so this remake does not concern a current Level 3 capital standard. The former 3PS 001 Definitions was superseded from 1 October 2024; current Level 3 defined terms are carried in CPS 001 Defined terms.

Why standards lapse, and why APRA is remaking these three

APRA prudential standards are legislative instruments registered on the Federal Register of Legislation and generally subject to Chapter 3, Part 4 of the Legislation Act 2003 (Cth). Under the default rule, an instrument sunsets on the first 1 April or 1 October beginning on or after the tenth anniversary of its registration, unless an exception or altered date applies. The three current determinations were registered in September 2016 and commenced on 1 July 2017; APRA confirms that they are scheduled to sunset on 1 October 2026.

Sunsetting is a statutory review mechanism intended to ensure that legislative instruments remain fit for purpose. It does not by itself mean that a rule has failed or will be discontinued. APRA reviewed these standards, stated that they remain fit for purpose, and decided to remake them with administrative updates and no new requirements.

The sunset date is a hard control point. If no replacement instrument is made and registered, the existing instrument will cease to be in force on 1 October 2026, although its historical text will remain on the Federal Register. APRA’s 27 July response states that it will remake the three standards before that date; the control should remain open until the replacement determinations are registered and their commencement provisions are verified.

Where the APRA Level 3 conglomerate standards sit in the framework

The Level 3 framework applies where APRA determines institutions to form a Level 3 group. APRA may make that determination where material activities are performed across more than one prudentially regulated industry and/or in one or more non-prudentially regulated industries, so that group risks do not adversely affect the obligations of the group’s prudentially regulated institutions.

The current non-capital Level 3 standards include 3PS 221, 3PS 222 and 3PS 310, read with CPS 001 Defined terms. APRA deferred and did not finalise proposed Level 3 capital standards 3PS 110 and 3PS 111. Current cross-industry standards applying at group level include CPS 220 Risk Management, CPS 230 Operational Risk Management, CPS 510 Governance and CPS 520 Fit and Proper. CPS 231 Outsourcing and CPS 232 Business Continuity Management are superseded.

Reading the framework map matters because the remake concerns the current non-capital Level 3 standards on aggregate risk exposures, intra-group transactions and exposures, and audit. It is not a Level 3 capital event: APRA deferred and did not finalise proposed 3PS 110, so there is no current 3PS 110 group-capital requirement being left unchanged by this package.

3PS 221 Aggregate Risk Exposures: the obligations that continue

3PS 221 requires the Head of a Level 3 group to maintain an aggregate risk exposures policy that captures all material aggregate risk exposures across the group and sets limits on acceptable levels. The idea is to see concentrations that no single regulated entity would report on its own, where the same counterparty, sector, or risk driver shows up across the bank, the insurer, and the funds management arm at once. The policy has to identify, aggregate, and report those exposures, assign clear responsibility, set escalation thresholds, and consider macroeconomic effects on the exposures.

The governance and reporting mechanics are specific. The Board must approve the aggregate risk exposures policy and review it at least annually. The Level 3 Head must submit the policy to APRA as soon as practicable and no more than 10 business days after Board approval. It must notify APRA within the same outer limit after becoming aware of a breach of policy limits; a significant breach of, or material deviation from, the policy; or that the policy did not adequately address a material risk, and must advise APRA of remediation. APRA may also request reports on material aggregate risk exposures. These obligations continue under the administrative remake.

The mechanism is analogous, but not equivalent, to EU CRR large-exposure requirements. EU large-exposure reporting is performed on the applicable individual and consolidated bases and is linked to statutory exposure limits, whereas 3PS 221 applies to a mixed Level 3 group through a Board-approved group policy, policy limits and APRA supervisory powers.

3PS 222 Intra-group Transactions and Exposures: contagion control across the group

3PS 222 sets APRA’s requirements for identifying, measuring, monitoring, and controlling intra-group transactions and exposures within a Level 3 group. These are the dealings between group entities, such as internal funding lines, guarantees, service arrangements, and cross-holdings, that can move stress from one part of a conglomerate to another. The concern the standard addresses is contagion: a problem in one regulated entity reaching a sister entity through an intra-group link, or a regulated entity supporting an unregulated part of the group in a way that erodes its own strength.

As with 3PS 221, the standard works through a Board-approved policy with limits and monitoring, and it obliges the Level 3 Head to manage intra-group transactions and exposures under that policy. A reporting team should read 3PS 222 with the current CPS 001 Defined terms. CPS 001 requires APRA-regulated institutions to interpret references in relevant prudential standards to 3PS 001 as references to CPS 001.

3PS 310 covers the role of auditors and the provision of independent assurance in relation to a Level 3 group. It sets out APRA’s expectations for the group’s engagement with its auditor and for the assurance APRA receives over the group’s compliance with the Level 3 framework and the reliability of the information the group provides. For a reporting function, the practical link is that the numbers and controls behind Level 3 obligations can be subject to external assurance, so the quality of the underlying data and the documentation of the control chain matter beyond the internal audience.

The administrative remake keeps the assurance architecture as it is. What a remake of this kind can touch is the drafting around it, for example references to other standards or to APRA processes that have themselves changed since 2017. That is exactly the sort of edit to check rather than assume, which is the point of the review set out below.

Reading “administrative updates only”

The phrase administrative updates only does real work, and it pays to be precise about what it excludes. It means the remake is not adding a new data field, a new limit, a new reporting frequency, or a new class of exposure to capture. A team should not expect a fresh return, a new APRA Connect collection, or a recalibration of any threshold to fall out of this package. If your build backlog gained a line item labelled “3PS 221 changes” after the July announcement, the honest scoping is that the requirement itself did not move.

APRA identified three categories of amendment: updated references, an interpretation paragraph and a previous-exercise-of-discretion paragraph. These changes do not introduce new requirements, but they may affect citations and the treatment of earlier APRA discretions. Internal references should therefore be compared with the replacement instruments once they are registered.

This is also where the remake connects to APRA’s wider push to reduce unnecessary regulatory burden, visible in the joint APRA and ASIC changes to the Financial Accountability Regime. A clean, administrative-only remake is the low-burden path: it keeps a working framework current without asking groups to rebuild anything.

A review checklist before 1 October 2026

Because nothing substantive changes, the work here is verification rather than construction. An auditor looking at your Level 3 control environment after the remake would expect to see that you had checked, not rebuilt. The following checks, offered as practitioner guidance for a group’s own review, cover the ground.

  • Confirm which of the three standards your group actually relies on and where each is referenced in your policy suite, control library, and board reporting.
  • Read APRA’s response to submissions and the remade instruments once registered, and note any changed cross-references, defined terms, or numbering against your current citations.
  • Update internal documents that quote 3PS 221, 3PS 222 or 3PS 310 by title or paragraph, so a post-sunset citation does not point at a repealed instrument.
  • Re-confirm the operational triggers that do not change: the annual Board review under 3PS 221 and notification to APRA as soon as practicable and no more than 10 business days after awareness of a breach of policy limits, a significant breach or material deviation, or inadequate coverage of a material risk.
  • Check that the aggregate risk exposures policy and the intra-group transactions and exposures policy are current and Board-approved, since the remake is a natural prompt for the periodic review the standards already require.
  • Diary the 1 October 2026 sunset as a control checkpoint and record that the requirement continues under the remade instrument, so your audit trail shows the lapse risk was managed.

Treat sunset dates as first-class entries in the compliance calendar. Check each APRA legislative instrument individually for its registered sunset date and for any exemption, deferral or altered date; most, but not all, legislative instruments follow the default sunsetting regime. Mapping those dates turns remakes into scheduled control events.

How this differs from EU financial conglomerate supervision

Practitioners who work across jurisdictions sometimes read APRA’s Level 3 framework as the Australian version of the EU Financial Conglomerates Directive, and the two do share a purpose: supervising risks that only appear at the level of a mixed financial group. The mechanics differ enough that the mapping should be treated as a loose analogy. The EU regime is directive-based and coordinates group-wide supervision across banking, insurance, and investment sectors through supplementary capital, risk concentration, and intra-group transaction requirements. APRA’s Level 3 framework is a set of prudential standards made under Australian law, applying to a Level 3 Head that APRA has determined, with the aggregate risk, intra-group, and audit content carried in 3PS 221, 3PS 222, and 3PS 310.

The relevant contrast for this article is the change event itself. What is happening in Australia is a sunset-driven remake of existing standards with the substance held constant. It is not the kind of policy reform that periodically reshapes conglomerate supervision in other jurisdictions. A reporting team should resist importing an EU expectation of substantive change onto an Australian instrument that APRA has explicitly described as administratively updated.

Frequently Asked Questions

Which standards is APRA remaking, and does anything I report change?

APRA is remaking three Level 3 conglomerate prudential standards: 3PS 221 Aggregate Risk Exposures, 3PS 222 Intra-group Transactions and Exposures, and 3PS 310 Audit and Related Matters. APRA has stated the changes are administrative only and do not introduce new requirements for conglomerate groups, so the substance of what you calculate, monitor, and report does not change. The item to check is whether cross-references and defined-term citations move in the remade instruments.

Why do the standards need to be remade in 2026?

The standards are legislative instruments subject to the sunsetting regime in the Legislation Act 2003. Under the default rule, an instrument sunsets on the first 1 April or 1 October beginning on or after the tenth anniversary of registration. The relevant determinations were registered in September 2016 and commenced on 1 July 2017, and APRA confirms that they are scheduled to sunset on 1 October 2026. Replacement instruments must be made and registered in time to avoid a gap.

Does the remake introduce or change a Level 3 group capital requirement?

No. The announcement is limited to 3PS 221, 3PS 222 and 3PS 310. Proposed 3PS 110 was not finalised after APRA deferred the Level 3 capital components in 2016. 3PS 001 is also no longer current; Level 3 definitions are now carried in CPS 001. This remake therefore does not introduce or change a current Level 3 capital requirement.

What still needs Board approval under 3PS 221?

3PS 221 requires the Board of the Level 3 Head to approve the aggregate risk exposures policy and to review it at least annually. Those obligations continue under an administrative remake. The remake is a reasonable prompt to bring the annual review forward if it is due, but it does not create a new approval step.

Is there a new APRA Connect collection or return to build?

APRA has not announced a new data collection as part of this remake. 3PS 221, 3PS 222, and 3PS 310 operate largely through Board-approved policies, limits, monitoring, and event-based notifications to APRA, and do not sit inside a new periodic return. Treat any internal build item as a citation and documentation review rather than a data-model change unless APRA later says otherwise.

What is the deadline a reporting team should hold?

The controlling date is 1 October 2026, when the current instruments would otherwise sunset. Between APRA’s 27 July 2026 response and that date, confirm your references, refresh policy documents that cite the three standards, and record that the requirements continue under the remade instruments. Keep the notification requirement in mind: APRA must be notified as soon as practicable and no more than 10 business days after awareness of a breach of policy limits, a significant breach or material deviation, or inadequate coverage of a material risk.

Does the remake affect entities that are not part of a Level 3 group?

3PS 221, 3PS 222 and 3PS 310 apply directly to each Level 3 Head. A Level 1 or Level 2 institution may nevertheless be a member of a Level 3 group and be affected through group-wide policies and controls applied by the Level 3 Head. Scope should therefore be determined from APRA’s Level 3 Head and group determination, not from Level 1 or Level 2 status alone.

Key Takeaways

  • On 27 July 2026, APRA confirmed it will remake 3PS 221, 3PS 222, and 3PS 310 before their 1 October 2026 sunset, with administrative updates only and no new requirements for conglomerate groups.
  • The remake is driven by the sunsetting regime in the Legislation Act 2003, under which instruments registered around a decade earlier are automatically repealed unless remade. The current standards commenced on 1 July 2017.
  • The package is bounded to 3PS 221, 3PS 222 and 3PS 310. Proposed 3PS 110 was not finalised, and the former 3PS 001 has been superseded by CPS 001 Defined terms.
  • 3PS 221 continues to require a Board-approved aggregate risk exposures policy with limits and an at-least-annual Board review. Notification is required as soon as practicable and no more than 10 business days after awareness of a breach of policy limits, a significant breach or material deviation, or inadequate coverage of a material risk.
  • APRA identifies the administrative amendments as updated references, an interpretation paragraph and a previous-exercise-of-discretion paragraph. Verify internal citations and the treatment of earlier APRA discretions against the replacement instruments once registered.
  • The practical task before 1 October 2026 is verification: confirm scope, update citations, and diary the sunset as a control checkpoint.

Sources and References

  • APRA, “APRA releases response to consultation on remaking Level 3 conglomerate standards” (media release, 27 July 2026): apra.gov.au
  • APRA, “Remaking Level 3 conglomerate standards” (consultation, opened 31 March 2026, closed 29 May 2026, response 2026): apra.gov.au consultation page
  • APRA, “Supervision of conglomerate groups (Level 3)” (framework overview and standard list): apra.gov.au
  • APRA, Prudential Standard 3PS 221 Aggregate Risk Exposures (effective 1 July 2017): apra.gov.au/standards/3ps-221
  • APRA, Prudential Standard CPS 001 Defined terms (current instrument commencing 1 July 2026; CPS 001 originally replaced 3PS 001 from 1 October 2024): apra.gov.au/standards/cps-001
  • APRA, “Operational risk management” (CPS 230, effective 1 July 2025, superseding CPS 231 and CPS 232): apra.gov.au
  • Legislation Act 2003 (Cth), Chapter 3, Part 4 (sunsetting of legislative instruments), with Federal Register of Legislation sunsetting guidance: legislation.gov.au

The remake as a maintenance cycle

The most useful frame for this announcement is the least dramatic one. APRA has confirmed that it will remake three working standards before their scheduled sunset on 1 October 2026, using administrative updates only. Until the replacement determinations are made and registered, the sunset should remain an open control point. For a conglomerate group’s reporting and compliance functions, the value is in treating it accordingly: verify the references, confirm the policies are current and Board-approved, and log the 1 October 2026 sunset as a managed control point. A remake handled as a scheduled maintenance check is a sign the framework is being kept tidy, and it is the response the announcement actually calls for.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts