APRA CPS 230 Operational Risk Management for Australian financial services
A plain-English guide to APRA Prudential Standard CPS 230 Operational Risk Management. Covers critical operations, tolerance levels, business continuity testing, and the material service provider register. Drawn from APRA's published response paper, the April 2026 targeted amendments and current industry practice.
For boards, executive teams and operations leaders of ADIs, insurers and superannuation trustees, plus the technology providers sitting on the register.
In force across all entities
Commenced 1 Jul 2025, smaller entities from 1 Jul 2026
Replaces five standards
CPS 231, CPS 232, SPS 231, SPS 232, HPS 231
Material service provider register
Substitution plans expected
Why CPS 230 exists
One standard replaces five. Operational risk is now a board-level obligation.
Every APRA-regulated entity is in scope.
CPS 230 Operational Risk Management is the Australian Prudential Regulation Authority's cross-industry standard for operational resilience. It commenced on 1 July 2025 for larger entities and consolidates five previous prudential standards covering operational risk, business continuity, and outsourcing. Smaller entities had a 12-month transition, which closed on 1 July 2026, so the standard now applies across the regulated population. The 30 April 2026 targeted amendments clarified the third-party register obligations.
Replaces five standards
CPS 230 replaces CPS 231 Outsourcing, CPS 232 Business Continuity Management, SPS 231 Outsourcing, SPS 232 Business Continuity Management, and HPS 231 Outsourcing. One standard for operational risk, business continuity, and third-party arrangements.
Source · APRA CPS 230 response paper1 July 2025 commencement
CPS 230 commenced on 1 July 2025 for most APRA-regulated entities. Smaller superannuation entities and non-significant financial institutions had until 1 July 2026, a date that has now passed. Existing material service provider contracts may transition over a longer window.
Source · APRA Operational Risk Management pageApril 2026 targeted amendments
On 30 April 2026, APRA finalised targeted amendments to CPS 230, clarifying the material service provider register obligation and tightening expectations around fourth-party concentration risk.
Source · APRA finalises targeted amendments to CPS 230Sits alongside CPS 234
CPS 234 Information Security remains in force as the cyber-specific standard. CPS 230 is broader: it covers operational risk, business continuity, and the third-party arrangements that often carry cyber risk. Boards should expect to evidence both in tandem.
Source · CPS 234 Information SecurityWho is in scope
Every APRA-regulated entity. From the majors to single-trustee super funds.
Authorised deposit-taking institutions, insurers, and superannuation trustees.
CPS 230 applies to all APRA-regulated entities. That includes the four major banks, every other authorised deposit-taking institution (ADI), general insurers, life insurers, private health insurers, and registrable superannuation entities. The proportionality principle applies, so smaller entities can meet the standard with less elaborate arrangements, but the substantive obligations are the same.
ADIs (banks, credit unions, building societies)
All authorised deposit-taking institutions, regardless of size. The major banks and the smallest mutuals are both in scope, with proportionality applied to the depth of evidence required.
General, life, and private health insurers
All insurers regulated by APRA. Includes friendly societies and reinsurance arrangements.
Superannuation trustees
All RSE licensees, including small APRA funds. Trustees should expect APRA to look closely at administrator and investment manager arrangements as material service providers.
Boards are accountable, not just management
CPS 230 makes the board ultimately accountable for the operational risk management framework. The board must approve the framework, review it at least annually, and ensure tolerance levels are set for critical operations.
The four core obligations
Identify critical operations. Set tolerances. Test continuity. Manage providers.
Substance, not just policy. The standard is operational.
CPS 230 has four substantive limbs. Each is enforceable on its own, but in practice they reinforce one another. The standard does not prescribe specific controls, but it does prescribe specific board-level processes that must be in place and capable of being evidenced.
Identify critical operations
Every entity must identify its critical operations: the processes that, if disrupted, would materially affect financial or operational viability, or the entity's role in the financial system. Examples for an ADI typically include payments, deposit-taking, lending, customer authentication, and core banking platform availability.
Set tolerance levels for disruption
For each critical operation, the board must approve maximum tolerance levels for disruption. Tolerances typically cover duration of disruption, data loss, and service degradation, and are tested under severe but plausible scenarios.
Test business continuity
Business continuity plans must be tested at least annually for each critical operation. Testing must include scenarios that involve the loss of a material service provider, a cyber incident, and a wider operational failure. Findings must be reported to the board.
Manage material service providers
Entities must maintain a register of all material service providers, perform due diligence at engagement and on an ongoing basis, and have exit and substitution plans. This obligation is the one most often missed by entities transitioning from CPS 231 outsourcing arrangements.
Source · APRA CPS 230 response paperThe material service provider register
If a provider could disrupt a critical operation, they are on the register.
Cloud, managed IT, payments, custody, administration, and core platforms.
The material service provider register is the operational core of CPS 230 for technology and operations teams. APRA has clarified that a material service provider is any third party whose failure or disruption could materially impair the entity's critical operations. The register must include the provider, the service, the criticality assessment, and the substitution plan if the provider failed.
What counts as a material service provider
Hyperscale cloud providers, core banking platforms, payments rails, custodians, administrators, managed IT and security providers, identity providers, and key SaaS platforms typically qualify. Branch hardware, generic office IT, and most professional services usually do not.
Fourth-party risk is in scope
The April 2026 amendments clarified that entities are expected to understand fourth-party arrangements where they introduce concentration risk. A managed IT provider running on a hyperscale cloud creates fourth-party visibility obligations even though the entity does not contract directly with the cloud provider.
Substitution plans must be credible
For each material service provider, the register must record a substitution plan. The expectation is that the plan is operationally credible: identified alternative provider, expected transition timeframe, key dependencies, and any contractual exit assistance terms.
What APRA expects from the contract
Material service provider contracts are expected to include audit and information rights for APRA and the entity, service performance and continuity obligations, sub-contracting controls, exit assistance, and notification of significant incidents.
How CPS 230 maps to CPS 234
CPS 234 is the cyber standard. CPS 230 is the resilience standard.
Cyber risk shows up under both. The reporting cadence is shared.
Many of the same controls satisfy both CPS 230 and CPS 234. The difference is framing. CPS 234 asks how information security capability is maintained, with explicit obligations on roles, capability, controls, testing, and APRA notification. CPS 230 asks how the entity stays operational when something goes wrong. A cyber incident affecting a critical operation is reportable under CPS 234 and is a continuity event under CPS 230.
Incident reporting overlap
A material information security incident is reportable to APRA under CPS 234 within 72 hours of detection. The same incident, if it affects a critical operation, is also a CPS 230 continuity event. Boards should expect one combined post-incident review.
Third-party assurance overlap
Material service provider due diligence under CPS 230 must include cyber security assurance. A SOC 2 Type II report, ISO 27001 certification, or independent CPS 234 attestation from the provider is the typical evidence base.
Board reporting cadence
Boards typically receive CPS 234 reporting quarterly and CPS 230 reporting at least annually. In practice, a combined operational resilience board paper covering both standards is the cleaner approach.
Source · Board reporting for ITTested business continuity now includes cyber scenarios
APRA has clarified that business continuity testing must include cyber-driven scenarios. Loss of identity provider, ransomware affecting the core platform, and material data integrity loss are common test scenarios for ADIs and trustees in 2026.
Practical readiness pathway
Most entities have the building blocks. The work is integration and evidence.
Align critical operations, register, and testing cadence.
For entities that already had CPS 231 outsourcing arrangements and CPS 234 information security programs in place, CPS 230 is largely a re-framing exercise. The substantive work is identifying critical operations, building the material service provider register with substitution plans, and lifting business continuity testing into an annual cadence with board reporting. Smaller entities that are still consolidating after the 1 July 2026 deadline can sequence the work in four phases.
Phase 1 : Critical operations identification
Workshop the executive team. Identify the operations that, if disrupted, materially affect customers, the entity, or the financial system. Document the dependencies of each critical operation on people, processes, technology, and third parties.
Phase 2 : Tolerance levels
For each critical operation, propose tolerance levels for disruption duration, data loss, and service degradation under a severe but plausible scenario. Walk through with the board risk committee. Approve at full board.
Phase 3 : Material service provider register
Build the register from your existing third-party inventory, with cyber assurance evidence and a substitution plan for each entry. Engage your managed IT and security partners; many providers now produce a CPS 230 evidence pack on request.
Phase 4 : Annual continuity testing
Run a tabletop exercise covering at least one material service provider failure, one cyber scenario, and one wider operational failure. Document findings, remediation, and board reporting. Lock the test into the board calendar.
Where Real Bytes fits
If we are your managed IT or security provider, we will sit on your material service provider register and produce the assurance evidence required: SOC reports, control attestations, sub-contracting maps, incident notification commitments, and exit assistance terms. For entities running on multiple managed providers, we can also help build the register and the substitution plans.
Sources referenced
- 01
Prudential Standard CPS 230 Operational Risk Management
APRAwww.apra.gov.au - 02
Response paper : Operational Risk Management
APRAJul 2023www.apra.gov.au - 03
APRA finalises targeted amendments to CPS 230
Norton Rose Fulbright30 Apr 2026www.regulationtomorrow.com - 04
Prudential Standard CPS 234 Information Security
APRAwww.apra.gov.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
Common questions
Questions APRA-regulated entities ask us first.
Yes, but proportionately. CPS 230 applies to every APRA-regulated entity. Smaller entities are expected to meet the standard in a way that is proportionate to size and complexity. The core obligations are the same; the depth of documentation and testing is calibrated. Smaller entities had until 1 July 2026 to comply.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
If you are an APRA-regulated entity
We sit on the register. We help you build it.
As your managed IT or managed security provider, we provide the CPS 230 evidence pack on request. For entities building the material service provider register for the first time, or running multiple providers, we can help you build the register, write the substitution plans, and rehearse the continuity testing your board will sign off.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.
Keep exploring
Related services, locations and industries
Explore how this connects across our wider offering.

Remote Support