What is APRA CPS 230?
APRA Prudential Standard CPS 230 Operational Risk Management is the Australian Prudential Regulation Authority's consolidated framework for managing operational risk across all APRA-regulated entities. Effective 1 July 2025, CPS 230 replaced the previous CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management) standards, bringing together three critical pillars of operational resilience into a single, strengthened prudential standard.
CPS 230 applies to all APRA-regulated entities: authorised deposit-taking institutions (ADIs — banks, credit unions, building societies), general insurers, life insurers, private health insurers, RSE licensees (superannuation fund trustees), and non-operating holding companies (NOHCs). Foreign bank branches operating in Australia are also subject to CPS 230.
The standard reflects APRA's assessment that operational risk — including service disruptions, third-party failures, cyber incidents, and inadequate business continuity arrangements — represents one of the most significant risks to the stability of the Australian financial system. High-profile operational incidents at major Australian financial institutions in the years preceding CPS 230 drove APRA to substantially uplift its operational risk requirements.
The three pillars of CPS 230
CPS 230 is structured around three interconnected pillars, with a governance framework and incident management overlay:
- Pillar 1 — Operational Risk Management Framework (§16–24): Board-approved ORM framework with defined risk appetite; three lines of defence model; OR oversight function; risk identification, assessment, and register
- Pillar 2 — Business Continuity Planning (§25–37): Critical operations identification; Maximum Tolerable Period of Disruption (MTPD) and Recovery Time Objective (RTO); annual BCP testing; succession planning; crisis communications
- Pillar 3 — Service Provider Management (§38–57): Material service provider (MSP) register; Board-approved MSP policy; written agreements including APRA access rights; due diligence; concentration risk management; exit strategies
Overlaid across these pillars: Incident Management (§58–67) — 72-hour APRA notification, root cause analysis; Controls Effectiveness (§68–76) — RCSA, KRIs, scenario analysis; and Governance (§77–86) — Board Risk Committee, CRO, annual APRA self-assessment.
Business Continuity Planning — the CPS 230 requirements
CPS 230 significantly strengthens business continuity requirements compared to the previous CPS 232. The key changes and requirements are:
Critical operations (§26)
Entities must define and maintain a list of critical operations — those operations whose disruption for more than a tolerable period would have a material adverse impact on: (a) the entity itself; (b) the entity's customers; or (c) the stability of the Australian financial system. This is a higher bar than previous requirements and requires entities to think beyond their own operations to systemic impact.
Factors to consider when determining critical operations include: revenue contribution, number of customers affected, regulatory obligations that depend on the operation, interconnectedness with financial market infrastructure, data sensitivity, and time-criticality for customer outcomes.
Maximum Tolerable Period of Disruption (MTPD) and Recovery Time Objective (RTO)
For each critical operation, entities must define: the MTPD — the maximum time the operation can be disrupted before material adverse impact occurs; and the RTO — the target time to restore the operation after a disruption. The RTO must be less than the MTPD to allow a margin of recovery. These figures must be documented, approved by the Board, and reviewed when circumstances change.
Annual BCP testing (§30)
CPS 230 requires BCP testing at least annually against plausible disruption scenarios. APRA expects a testing programme that goes beyond paper exercises — including live failover tests for technology systems, tabletop exercises for crisis response, and validation that recovery strategies work in practice. Test results must be documented and lessons learned actioned. APRA can request BCP test results as part of its supervisory activities.
Material service provider management
The service provider management pillar of CPS 230 is one of the most significant new requirements for many APRA-regulated entities. Under CPS 231, outsourcing requirements focused narrowly on material outsourcing arrangements. CPS 230 takes a broader view, requiring management of all material service providers — not just formal outsourcing arrangements.
Defining material service providers (§38–39)
A service provider is material if its failure or disruption would, or would be likely to, have a material adverse impact on the entity or its customers, or on the stability of the Australian financial system. Entities must establish criteria for assessing materiality and apply them across their entire service provider population. Common material service providers for Australian financial institutions include: core banking system vendors, cloud infrastructure providers (AWS, Azure, GCP), payment processing platforms, data centre operators, IT managed service providers, and software vendors for critical applications.
Written agreement requirements (§43–44)
CPS 230 requires written agreements with all MSPs that include minimum provisions: (a) scope and nature of services; (b) service level obligations; (c) the right to access information and audit the service provider; (d) APRA's right to access information about the service provider's operations and review their arrangements — this is a critical new requirement that service providers are now required to agree to as a contractual condition; (e) sub-contracting restrictions; (f) data ownership, portability, and deletion; (g) termination rights and transition obligations.
The APRA access clause is particularly significant: APRA can now require service providers to provide information directly to APRA, and entities must ensure their contracts enable this. Many existing vendor agreements will need to be renegotiated to include this provision.
Exit strategies (§50)
For each MSP supporting a critical operation, entities must document and maintain an exit strategy covering: how the entity would transition away from the service provider if required; alternative providers or insourcing options; data migration and continuity; regulatory notification requirements; and the timeframe for transition. Exit strategies must be tested periodically to confirm they are viable.
Incident management and 72-hour APRA notification
CPS 230 introduces a 72-hour notification requirement for material operational risk incidents. An entity becomes aware of a material operational risk incident when it has information that would lead a reasonable person to conclude that a material adverse impact has occurred or is likely to occur. The 72-hour clock starts from the point of awareness, not discovery of full details.
The notification to APRA must include: nature of the incident, affected operations, actual or potential impact, steps being taken to manage the incident, and estimated recovery timeline. Follow-up notifications are required as the situation evolves. After resolution, a final incident report with root cause analysis must be submitted.
This requirement means entities need: a 24/7 contact mechanism for APRA notification; a triage process to assess whether an incident is material within hours; pre-prepared notification templates; and a clearly defined decision-making chain for the notification decision.
Board and Senior Management governance
CPS 230 places strong obligations on Boards and Senior Management. The Board must: approve the ORM framework and risk appetite; approve the BCP; receive regular OR reporting; and conduct an annual CPS 230 self-assessment signed by both the CEO and CRO. The CRO (or equivalent OR oversight function) must have direct Board access and independence from the business lines being overseen.
The annual CPS 230 self-assessment (§82) is a key accountability mechanism. It requires the entity to assess its compliance with CPS 230, identify gaps, and report to APRA. APRA will use these self-assessments as a supervisory tool and may follow up with targeted reviews where gaps are identified.
How CPS 230 relates to CPS 234
APRA CPS 234 Information Security (effective 2019) covers cybersecurity specifically — information asset classification, cyber controls, incident management, and testing. CPS 230 covers broader operational risk including but not limited to cyber. The two standards are complementary and many requirements overlap: both require incident management, both address service provider risk (with CPS 234 specifically requiring information security requirements in third-party contracts), and both require Board oversight. Entities should map their compliance programmes across both standards to identify any gaps and avoid duplication.
CPS 230 transition and APRA's supervisory approach
CPS 230 became effective 1 July 2025. APRA provided transition guidance through CPG 230 (Operational Risk Management) and industry consultations. Entities that had existing robust frameworks under CPS 231 and CPS 232 were expected to focus their transition efforts on: (1) the new material service provider register and agreement uplift; (2) the critical operations framework and MTPD/RTO documentation; and (3) the governance enhancements including the annual APRA self-assessment.
APRA's enforcement approach under CPS 230 is consistent with its general enforcement policy: focused on remediation and uplift, but willing to use formal enforcement powers (directions, enforceable undertakings, court orders) against entities with persistent or material non-compliance. The self-assessment mechanism and APRA's existing supervisory relationships with regulated entities mean that early identification and remediation of gaps is strongly preferred over regulatory enforcement action.
Assess your CPS 230 compliance
The APRA CPS 230 Operational Risk Management Compliance Checker covers all 42 key obligations across six domains: ORM framework (Board approval, risk appetite, three lines of defence, risk register), business continuity planning (critical operations, MTPD/RTO, annual testing, succession planning), material service provider management (MSP register, written agreements, APRA access clause, exit strategies), incident management (72-hour notification, root cause analysis, KRI reporting), controls effectiveness (RCSA, control testing, internal audit, scenario analysis), and Board governance (CRO independence, annual self-assessment, OR culture). Mark each obligation as compliant, partial, gap, or not applicable, and generate an AI-drafted CPS 230 compliance report with a prioritised remediation roadmap.
Related tools
See also: APRA CPS 234 Cybersecurity Compliance Checker, ISO 27001 Gap Assessment, Vendor Risk Assessment, ISO 27001 Risk Assessment.