CPS 230 has commencedSix chapters · sourced

APRA CPS 230 Operational Risk Management for Australian financial services

A plain-English guide to APRA Prudential Standard CPS 230 Operational Risk Management. Covers critical operations, tolerance levels, business continuity testing, and the material service provider register. Drawn from APRA's published response paper, the April 2026 targeted amendments and current industry practice.

For boards, executive teams and operations leaders of ADIs, insurers and superannuation trustees, plus the technology providers sitting on the register.

In force across all entities

Commenced 1 Jul 2025, smaller entities from 1 Jul 2026

Replaces five standards

CPS 231, CPS 232, SPS 231, SPS 232, HPS 231

Material service provider register

Substitution plans expected

Editorially reviewed
Last reviewed31 Aug 2026
Sources verified31 Aug 2026
01

Why CPS 230 exists

One standard replaces five. Operational risk is now a board-level obligation.

Every APRA-regulated entity is in scope.

CPS 230 Operational Risk Management is the Australian Prudential Regulation Authority's cross-industry standard for operational resilience. It commenced on 1 July 2025 for larger entities and consolidates five previous prudential standards covering operational risk, business continuity, and outsourcing. Smaller entities had a 12-month transition, which closed on 1 July 2026, so the standard now applies across the regulated population. The 30 April 2026 targeted amendments clarified the third-party register obligations.

01

Replaces five standards

CPS 230 replaces CPS 231 Outsourcing, CPS 232 Business Continuity Management, SPS 231 Outsourcing, SPS 232 Business Continuity Management, and HPS 231 Outsourcing. One standard for operational risk, business continuity, and third-party arrangements.

Source · APRA CPS 230 response paper
02

1 July 2025 commencement

CPS 230 commenced on 1 July 2025 for most APRA-regulated entities. Smaller superannuation entities and non-significant financial institutions had until 1 July 2026, a date that has now passed. Existing material service provider contracts may transition over a longer window.

Source · APRA Operational Risk Management page
03

April 2026 targeted amendments

On 30 April 2026, APRA finalised targeted amendments to CPS 230, clarifying the material service provider register obligation and tightening expectations around fourth-party concentration risk.

Source · APRA finalises targeted amendments to CPS 230
04

Sits alongside CPS 234

CPS 234 Information Security remains in force as the cyber-specific standard. CPS 230 is broader: it covers operational risk, business continuity, and the third-party arrangements that often carry cyber risk. Boards should expect to evidence both in tandem.

Source · CPS 234 Information Security
02

Who is in scope

Every APRA-regulated entity. From the majors to single-trustee super funds.

Authorised deposit-taking institutions, insurers, and superannuation trustees.

CPS 230 applies to all APRA-regulated entities. That includes the four major banks, every other authorised deposit-taking institution (ADI), general insurers, life insurers, private health insurers, and registrable superannuation entities. The proportionality principle applies, so smaller entities can meet the standard with less elaborate arrangements, but the substantive obligations are the same.

01

ADIs (banks, credit unions, building societies)

All authorised deposit-taking institutions, regardless of size. The major banks and the smallest mutuals are both in scope, with proportionality applied to the depth of evidence required.

02

General, life, and private health insurers

All insurers regulated by APRA. Includes friendly societies and reinsurance arrangements.

03

Superannuation trustees

All RSE licensees, including small APRA funds. Trustees should expect APRA to look closely at administrator and investment manager arrangements as material service providers.

04

Boards are accountable, not just management

CPS 230 makes the board ultimately accountable for the operational risk management framework. The board must approve the framework, review it at least annually, and ensure tolerance levels are set for critical operations.

03

The four core obligations

Identify critical operations. Set tolerances. Test continuity. Manage providers.

Substance, not just policy. The standard is operational.

CPS 230 has four substantive limbs. Each is enforceable on its own, but in practice they reinforce one another. The standard does not prescribe specific controls, but it does prescribe specific board-level processes that must be in place and capable of being evidenced.

01

Identify critical operations

Every entity must identify its critical operations: the processes that, if disrupted, would materially affect financial or operational viability, or the entity's role in the financial system. Examples for an ADI typically include payments, deposit-taking, lending, customer authentication, and core banking platform availability.

02

Set tolerance levels for disruption

For each critical operation, the board must approve maximum tolerance levels for disruption. Tolerances typically cover duration of disruption, data loss, and service degradation, and are tested under severe but plausible scenarios.

03

Test business continuity

Business continuity plans must be tested at least annually for each critical operation. Testing must include scenarios that involve the loss of a material service provider, a cyber incident, and a wider operational failure. Findings must be reported to the board.

04

Manage material service providers

Entities must maintain a register of all material service providers, perform due diligence at engagement and on an ongoing basis, and have exit and substitution plans. This obligation is the one most often missed by entities transitioning from CPS 231 outsourcing arrangements.

Source · APRA CPS 230 response paper
04

The material service provider register

If a provider could disrupt a critical operation, they are on the register.

Cloud, managed IT, payments, custody, administration, and core platforms.

The material service provider register is the operational core of CPS 230 for technology and operations teams. APRA has clarified that a material service provider is any third party whose failure or disruption could materially impair the entity's critical operations. The register must include the provider, the service, the criticality assessment, and the substitution plan if the provider failed.

01

What counts as a material service provider

Hyperscale cloud providers, core banking platforms, payments rails, custodians, administrators, managed IT and security providers, identity providers, and key SaaS platforms typically qualify. Branch hardware, generic office IT, and most professional services usually do not.

02

Fourth-party risk is in scope

The April 2026 amendments clarified that entities are expected to understand fourth-party arrangements where they introduce concentration risk. A managed IT provider running on a hyperscale cloud creates fourth-party visibility obligations even though the entity does not contract directly with the cloud provider.

03

Substitution plans must be credible

For each material service provider, the register must record a substitution plan. The expectation is that the plan is operationally credible: identified alternative provider, expected transition timeframe, key dependencies, and any contractual exit assistance terms.

04

What APRA expects from the contract

Material service provider contracts are expected to include audit and information rights for APRA and the entity, service performance and continuity obligations, sub-contracting controls, exit assistance, and notification of significant incidents.

05

How CPS 230 maps to CPS 234

CPS 234 is the cyber standard. CPS 230 is the resilience standard.

Cyber risk shows up under both. The reporting cadence is shared.

Many of the same controls satisfy both CPS 230 and CPS 234. The difference is framing. CPS 234 asks how information security capability is maintained, with explicit obligations on roles, capability, controls, testing, and APRA notification. CPS 230 asks how the entity stays operational when something goes wrong. A cyber incident affecting a critical operation is reportable under CPS 234 and is a continuity event under CPS 230.

01

Incident reporting overlap

A material information security incident is reportable to APRA under CPS 234 within 72 hours of detection. The same incident, if it affects a critical operation, is also a CPS 230 continuity event. Boards should expect one combined post-incident review.

02

Third-party assurance overlap

Material service provider due diligence under CPS 230 must include cyber security assurance. A SOC 2 Type II report, ISO 27001 certification, or independent CPS 234 attestation from the provider is the typical evidence base.

03

Board reporting cadence

Boards typically receive CPS 234 reporting quarterly and CPS 230 reporting at least annually. In practice, a combined operational resilience board paper covering both standards is the cleaner approach.

Source · Board reporting for IT
04

Tested business continuity now includes cyber scenarios

APRA has clarified that business continuity testing must include cyber-driven scenarios. Loss of identity provider, ransomware affecting the core platform, and material data integrity loss are common test scenarios for ADIs and trustees in 2026.

06

Practical readiness pathway

Most entities have the building blocks. The work is integration and evidence.

Align critical operations, register, and testing cadence.

For entities that already had CPS 231 outsourcing arrangements and CPS 234 information security programs in place, CPS 230 is largely a re-framing exercise. The substantive work is identifying critical operations, building the material service provider register with substitution plans, and lifting business continuity testing into an annual cadence with board reporting. Smaller entities that are still consolidating after the 1 July 2026 deadline can sequence the work in four phases.

01

Phase 1 : Critical operations identification

Workshop the executive team. Identify the operations that, if disrupted, materially affect customers, the entity, or the financial system. Document the dependencies of each critical operation on people, processes, technology, and third parties.

02

Phase 2 : Tolerance levels

For each critical operation, propose tolerance levels for disruption duration, data loss, and service degradation under a severe but plausible scenario. Walk through with the board risk committee. Approve at full board.

03

Phase 3 : Material service provider register

Build the register from your existing third-party inventory, with cyber assurance evidence and a substitution plan for each entry. Engage your managed IT and security partners; many providers now produce a CPS 230 evidence pack on request.

04

Phase 4 : Annual continuity testing

Run a tabletop exercise covering at least one material service provider failure, one cyber scenario, and one wider operational failure. Document findings, remediation, and board reporting. Lock the test into the board calendar.

05

Where Real Bytes fits

If we are your managed IT or security provider, we will sit on your material service provider register and produce the assurance evidence required: SOC reports, control attestations, sub-contracting maps, incident notification commitments, and exit assistance terms. For entities running on multiple managed providers, we can also help build the register and the substitution plans.

Common questions

Questions APRA-regulated entities ask us first.

Yes, but proportionately. CPS 230 applies to every APRA-regulated entity. Smaller entities are expected to meet the standard in a way that is proportionate to size and complexity. The core obligations are the same; the depth of documentation and testing is calibrated. Smaller entities had until 1 July 2026 to comply.

If you are an APRA-regulated entity

We sit on the register. We help you build it.

As your managed IT or managed security provider, we provide the CPS 230 evidence pack on request. For entities building the material service provider register for the first time, or running multiple providers, we can help you build the register, write the substitution plans, and rehearse the continuity testing your board will sign off.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.