APRA CPS 230 — Operational Risk Management

CPS 230, operationalised.

Australia's operational risk management standard for APRA-regulated entities. Critical operations, material service providers, business-continuity testing — all on continuous attestation, not annual scrambles.

What is APRA CPS 230?

CPS 230 Operational Risk Management is a prudential standard issued by the Australian Prudential Regulation Authority. It applies to APRA-regulated entities — banks and other ADIs, insurers, and RSE licensees in superannuation — and it took effect on 1 July 2025, replacing and consolidating several older standards including CPS 231 on outsourcing and CPS 232 on business continuity.

It turns on three linked ideas. Critical operations are the processes whose failure would materially affect depositors, policyholders, members or financial stability — and entities must identify them and set tolerance levels for disruption to each. Material service providers are the third parties those critical operations depend on, or who handle sensitive data, and they must be recorded in a register, contracted with specified terms, and managed under a documented policy. And business continuity has to be tested, at least annually, against those tolerances rather than assumed.

The change in posture is what matters most. CPS 231 asked whether outsourcing was governed; CPS 230 asks whether the operation would survive the provider failing, holds the board accountable for that answer, and requires notification to APRA of material service provider arrangements and of operational risk incidents that hit tolerance.

The numbers your team already knows.

CPS 230 raised the bar on operational risk for the entire APRA-regulated sector. Material service provider registers, critical-operations mapping, and continuous attestation — measured by APRA, not by your audit calendar.

1 Jul 2025
CPS 230 effective date for APRA-regulated entities
Now in force
MSPs
Material service providers — annual attestation + continuous reporting
CPS 230 Section 35
Critical
Critical operations defined per-organisation, mapped to vendors
CPS 230 Section 14

TARA, VANCE, REX — your CPS 230 stack.

Three of The Agency's leads cover the full CPS 230 loop: critical-operations mapping, material service provider attestation, and the continuous monitoring that keeps APRA's bar within reach.

TARA avatar
TARA
Compliance & Remediation

Critical operations and material service providers, mapped continuously. TARA classifies vendors against your critical-operations definitions and tracks the remediation actions APRA expects you to be doing between attestations.

What you get
  • Critical-operations to vendor mapping kept live
  • Material service provider tiering and re-tiering
  • Treatment plans with deadlines and SLA tracking
VANCE avatar
VANCE
Regulatory Reporting

APRA-formatted reports composed from current evidence. VANCE generates CPS 230 attestations, material service provider registers and board-pack summaries — formatted for APRA, evidence linked.

What you get
  • CPS 230 annual attestations composed from live data
  • Material service provider register kept current
  • Tamper-evident audit trail per output
REX avatar
REX
Continuous Monitoring

Continuous attestation, not annual scrambles. REX continuously monitors the security posture of every material service provider — APRA's bar for continuous risk management has actual evidence behind it.

What you get
  • Continuous monitoring across material service providers
  • Material-change detection in hours, not at year-end
  • Concentration risk visible across the third-party portfolio

Four shifts you'll feel in your first attestation cycle.

CPS 230 stops being a binder of slides and becomes a continuous evidence stream APRA can drop in on at any time.

Material service provider register stays live

The MSP register reflects today's contracts, today's tiering and today's posture — not last attestation cycle's.

Critical operations mapped to dependencies

Every critical operation linked to the third-party arrangements that support it. Concentration risk visible at a glance.

Annual attestations composed from continuous data

You stop assembling the attestation. VANCE generates it from live evidence — your team reviews and signs, not authors.

APRA-formatted output ready on demand

When APRA asks, the report is generated against current data — not last quarter's.

CPS 230 went from a binder of slides to a continuous evidence stream. Our material service provider register is finally something I would show APRA without a quarter of prep.

TL
Head of Operational Risk
ANZ Insurer

What teams ask about CPS 230.

Who it covers, what a material service provider is, and how it differs from the standards it replaced.

Who does CPS 230 apply to, and from when?
All APRA-regulated entities — authorised deposit-taking institutions, general and life insurers, private health insurers, and RSE licensees — along with the relevant holding companies. It has applied since 1 July 2025. APRA allowed transitional relief on pre-existing service provider contracts, which are brought into line at their next renewal or by the transition date rather than being reopened immediately, but the operational requirements themselves were not deferred.
What counts as a material service provider?
A provider the entity relies on for a critical operation, or one that exposes it to material operational risk — which explicitly includes providers handling sensitive data. APRA also names service categories it expects to be treated as material, and, importantly, materiality is not limited to your direct counterparty: entities are expected to understand fourth-party dependencies where a material provider itself relies on someone else. The register has to be maintained and provided to APRA on request.
How is CPS 230 different from CPS 231 and CPS 232?
CPS 230 replaced both and raised the bar. CPS 231 governed outsourcing as a procurement discipline — approve it, document it, review it. CPS 232 covered business continuity separately. CPS 230 fuses them around critical operations and tolerance levels: rather than asking whether an arrangement is governed, it asks how long a critical operation can be disrupted before the harm is unacceptable, and requires you to test that you can stay inside it. Board accountability is explicit, and the scope of what counts as a relevant third party is wider.
How does CPS 230 relate to DORA?
They are strikingly similar in intent — both make operational resilience a board obligation, both require a register of third-party arrangements, contractual minimums and exit planning, and both demand testing rather than documentation. The differences are jurisdiction and mechanics: DORA is an EU regulation applying to financial entities with a dedicated oversight regime for critical ICT providers, while CPS 230 is an APRA prudential standard for Australian regulated entities and is not ICT-specific — it covers operational risk broadly. A group regulated under both can usually run one evidence set and two reporting formats. See our DORA page for that side.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.