The CPS 230 that binds an APRA-regulated entity today was made on 23 April 2026 and commenced on 1 July 2026. It revoked the earlier version and moved the paragraph numbers. Of the seven pages ranking for the term in September 2026, five could be read, and every one of them is out of date on the version that binds. The critical operations register is paragraph 33 and was 34. Tolerance levels are 37 and were 38. The processes and resources requirement is 26 and was 27. A citation copied out of a 2025 explainer now points at the paragraph next door.
APRA is the Australian Prudential Regulation Authority, the regulator for banks, insurers and superannuation funds. Prudential Standard CPS 230 Operational Risk Management is how it asks one question of every entity it supervises: when something breaks, does the business keep running, and can you show the number it was meant to keep running to? The standard states its own aim as ensuring that an APRA-regulated entity is resilient to operational risks and disruptions, and it sets three key requirements. Identify, assess and manage operational risk, with effective internal controls, monitoring and remediation. Continue to deliver critical operations within tolerance levels through severe disruptions, with a credible business continuity plan. Manage the risks associated with service providers, through a policy, formal agreements and monitoring.
Every paragraph number below is from the current standard.
Why CPS 230 matters
CPS 230 reaches further than most standards an Australian risk team has read. Paragraph 2 applies it to authorised deposit-taking institutions, the regulatory term for banks, building societies and credit unions, including foreign ones; to general insurers; to life companies including friendly societies; to private health insurers; and to registrable superannuation entity licensees, the trustees of superannuation funds, in respect of their business operations. Paragraph 3 narrows the obligations to Australian branch operations for a foreign bank, a Category C insurer and an eligible foreign life insurance company. Paragraph 4 pushes them outwards again: an entity that heads a group has to comply in its own capacity, by applying the requirements appropriately throughout the group including to entities APRA does not regulate, and on a group basis.
Then it reaches past the group entirely. Paragraph 34 defines a critical operation as a process undertaken by the entity or its service provider which, if disrupted beyond tolerance levels, would have a material adverse impact on customers or on the entity's role in the financial system. A process you outsourced is still your critical operation. That phrase is why a supplier to a mid-sized insurer now receives contract variations quoting paragraphs 53 and 54, and why paragraph 54 is the clause that stalls negotiations: the agreement has to let APRA access documentation, data and other information about the service, allow APRA an on-site visit to the provider, and have the provider agree not to impede APRA.
What changed in kind is easier to see than what changed in wording. CPS 230 replaced five standards, and APRA named them when it opened consultation on 28 July 2022: CPS 231 and CPS 232, the outsourcing and business continuity management standards for banks and insurers, the corresponding superannuation standards SPS 231 and SPS 232, and the private health insurance standard HPS 231. Two subjects, three industries, five documents about arrangements and plans. What replaced them carries both subjects for every regulated entity, and puts a third requirement group in front of them.
The five standards replaced
One standard, three requirement groups
Outsourcing
Banks and insurers, superannuation, and private health insurance each had their own outsourcing standard.
Business continuity management
Banks, insurers and superannuation had a continuity standard. APRA's list of five names none for private health insurance.
Paragraphs 12 to 32
Operational risk management
Manage operational risk, test the controls, record incidents and near misses, notify APRA.
Paragraphs 33 to 45
Business continuity
A register of critical operations, tolerance levels for each, a credible plan and a testing program.
Paragraphs 46 to 61
Service provider management
A policy, a register that goes to APRA each year, contract minimums, and monitoring that reaches fourth parties.
The five standards replaced
Outsourcing
Banks and insurers, superannuation, and private health insurance each had their own outsourcing standard.
Business continuity management
Banks, insurers and superannuation had a continuity standard. APRA's list of five names none for private health insurance.
Paragraphs 12 to 32
Operational risk management
Manage operational risk, test the controls, record incidents and near misses, notify APRA.
Paragraphs 33 to 45
Business continuity
A register of critical operations, tolerance levels for each, a credible plan and a testing program.
Paragraphs 46 to 61
Service provider management
A policy, a register that goes to APRA each year, contract minimums, and monitoring that reaches fourth parties.
Operational risk management. No predecessor among the five
Business continuity. Carries CPS 232 and SPS 232
Service provider management. Carries CPS 231, SPS 231 and HPS 231
The service provider requirements at paragraphs 46 to 61 carry the three outsourcing standards. The business continuity requirements at paragraphs 33 to 45 carry the two continuity standards, and APRA's list of five names no private health insurance continuity standard. Paragraphs 12 to 32, the operational risk management group, have no predecessor among the five. That group is where the standard defines operational risk as risk arising from inadequate or failed internal processes or systems, from the actions or inactions of people, or from external drivers and events, and calls it inherent in all products, activities, processes and systems (paragraph 12). It is where controls have to be embedded in line with risk appetite (paragraph 28), tested for design and operating effectiveness at a frequency matched to what they control (paragraph 29), and where a control gap stays in the operational risk profile until it is remediated (paragraph 30). It is also where incidents and near misses have to be identified, escalated, recorded and addressed, and fed back into the assessment of the risk profile (paragraph 31).
None of that stands alone. Paragraph 15 places the whole of it inside the risk management framework CPS 220 Risk Management and SPS 220 already require, and lists what that framework covers for operational risk: governance, a risk profile with an appetite supported by indicators and limits, controls that operate effectively, monitoring and escalation, continuity plans tested against severe but plausible scenarios, and processes for service provider arrangements. Paragraph 17 adds that business continuity planning must not undermine the recovery and exit planning an entity does under CPS 190.
The part to put in front of a board is short. Paragraph 19 makes the Board ultimately accountable for oversight of the entity's operational risk management, including business continuity and service provider management. Paragraph 21(b) requires the Board to approve the business continuity plan and the tolerance levels for disruptions to critical operations, review testing results and oversee the execution of findings. Paragraph 21(c) adds the service provider management policy and the risk and performance reporting on material service providers. Those approvals sit with the Board itself. Paragraph 40 then requires the entity to monitor compliance with its tolerance levels and to report any failure to meet them, with a remediation plan, to the same Board.
Where APRA considers that an entity's operational risk management has material weaknesses, paragraph 18 lets it require an independent review, a remediation program, additional capital where relevant, or conditions on the entity's licence.
How CPS 230 works, step by step
The standard hangs almost everything on one thing. Name a critical operation and four more requirements attach to it, each in its own paragraph.
- The operation itself
- What delivers it
- What the entity sets
- Outside the entity
What the standard names
A critical operation
A process the entity or its service provider undertakes which, disrupted beyond tolerance levels, would materially harm customers or the entity's role in the financial system.
Paragraph 34
Delivered by
Processes and resources
People, technology, information, facilities and service providers, and the interdependencies across them.
Paragraph 26(b)
Measured against
Three tolerance levels
The maximum disruption it would tolerate, the maximum data loss it would accept, and the minimum service level it would maintain.
Paragraph 37
Relies on
Material service providers
The providers the entity relies on to undertake it, each one on a register that goes to APRA every year.
Paragraphs 48 and 50
Rely in turn on
Fourth parties
The parties a material service provider relies on to deliver the operation, covered by the entity's own policy.
Paragraph 47(c)
Held inside tolerance by
A business continuity plan
The triggers that activate it, the actions that hold the operation inside tolerance, the execution risks and a communications strategy.
Paragraph 39
Tolerance levels and the continuity plan are what the entity sets. The resources and the providers are what it has to find and write down, including the fourth parties its providers rely on. Miss one of the four and the operation sits on the register without being managed. Putting all four there runs in ten moves, each leaving an artefact a supervisor can ask for.
- 01
Identify and register your critical operations
Start from the minimum list APRA prescribes for your industry in paragraph 35 and add what your own customers depend on. Paragraph 36 lets APRA require you to treat a further business operation as critical.
Output: A register of critical operations, paragraph 33(a)
- 02
Map what delivers each one
Paragraph 26(b) asks for the processes and resources needed to deliver critical operations, including people, technology, information, facilities and service providers, the interdependencies across them, and the associated risks, obligations, key data and controls.
Output: A dated dependency map, paragraph 26(b)
- 03
Set three tolerance levels for each operation
Paragraph 37 asks for the maximum period of disruption you would tolerate, the maximum data loss you would accept, and the minimum service levels you would maintain under alternative arrangements. One number per question, not one number per operation.
Output: Three numbers per critical operation, paragraph 37
- 04
Take the plan and the numbers to the Board
Paragraph 21(b) puts the approval of the business continuity plan and the tolerance levels with the Board, which means the business has to own the numbers before the meeting.
Output: A recorded Board approval, paragraph 21(b)
- 05
Write the plan so it contains the five things asked for
Paragraph 39 wants the register and its tolerance levels, the triggers that identify a disruption and prompt activation with the arrangements to direct resources, the actions that hold the operation inside tolerance, an assessment of execution risks, resources and preparatory measures including key internal and external dependencies, and a communications strategy.
Output: A business continuity plan, paragraph 39
- 06
Run scenario analysis on the severe events
Paragraph 26(c) requires scenario analysis to identify and assess the impact of severe operational risk events, test operational resilience and identify the need for new or amended controls.
Output: Scenario results and a control change list, paragraph 26(c)
- 07
Test the plan on a program, not on a date
Paragraph 42 asks for a systematic testing program covering all critical operations, including an annual business continuity exercise across a range of severe but plausible scenarios. Paragraph 43 adds disruptions to material service providers and scenarios needing contingency arrangements, and lets APRA require a scenario of its own.
Output: Exercise results against each tolerance level, paragraph 42
- 08
Identify your material service providers and register them
Paragraph 48 covers providers you rely on to undertake a critical operation or that expose you to material operational risk, paragraph 49 sets the industry minimum list, and paragraph 50 sends the register to APRA each year.
Output: A register of material service providers, paragraphs 48 and 50
- 09
Put the contract terms and the arrangement management in place
Paragraph 52 requires due diligence before entering or materially modifying an arrangement, paragraph 53 sets seven minimum terms for the agreement, paragraph 54 adds APRA's access and on-site visit rights, and paragraph 55 requires step-in and contagion risk, plan execution and an orderly exit to be managed per arrangement.
Output: A signed agreement and a per-arrangement risk position, paragraphs 52 to 55
- 10
Monitor, notify and have it reviewed
Paragraph 59 sets ongoing monitoring of service levels, control effectiveness and both parties' compliance. Paragraphs 32, 41 and 60 set the notification clocks. Paragraph 44 asks for the plan to be updated annually as necessary, paragraph 45 puts internal audit over the plan and its testing, and paragraph 61 puts internal audit over any proposal to outsource a critical operation.
Output: Notifications, an updated plan and an internal audit report, paragraphs 32 to 61
What an agreement with a material service provider carries
Take one organisation, the insurer this guide's worked example follows and the figures draw: a general insurer of about 1,400 people writing home and motor cover, with six critical operations on its register. Two of its material arrangements sit at opposite ends of the same requirement. It negotiates freely with Meridian Claims Services, the offshore provider that assesses a share of its claims, and it negotiates nothing at all with the operator of the payment scheme its claim payments travel over, which offers every participant the same terms. Paragraphs 57 and 58 are new, they separate those two arrangements, and reading them as broad relief is an easy mistake.
- The obligation applies
- Lifted by paragraph 57
- A provider on negotiated terms
- The arrangement the exemption reaches
- 47
In the service provider management policy, fourth parties too
Meridian · appliesScheme operator · applies - 48
On the register of material service providers
Meridian · appliesScheme operator · applies - 52
Due diligence before entering or materially modifying it
Meridian · appliesScheme operator · applies - 53
A formal, legally binding agreement with seven minimum terms
Meridian · appliesScheme operator · lifted - 54
APRA access to documentation and data, and an on-site visit
Meridian · appliesScheme operator · lifted - 55(a) to (c)
Delivery, step-in and contagion risk, plan execution
Meridian · appliesScheme operator · applies - 55(d)
An orderly exit
Meridian · appliesScheme operator · lifted - 59(a)
Performance against agreed service levels assessed
Meridian · appliesScheme operator · lifted - 59(b)
The controls managing the provider's risks assessed
Meridian · appliesScheme operator · applies - 59(c)
Both parties' compliance with the agreement assessed
Meridian · appliesScheme operator · lifted - 60(a)
APRA notified within 20 business days of a change
Meridian · appliesScheme operator · applies
Both conditions have to hold · paragraph 57
The provider sits in one of the seven categories listed in the Attachment, and the arrangement uses standardised terms the entity has no, or substantially no, ability to negotiate, or is not documented in a formal agreement. Where an arrangement satisfies neither condition, paragraph 58 lets APRA exempt it from the same five provisions by written notice, so that relief is a decision APRA takes.
Eleven obligations attach to a material arrangement, and the exemption lifts five: paragraph 53's agreement with its seven minimum terms, paragraph 54's APRA access and on-site visit, paragraph 55(d)'s orderly exit, and paragraphs 59(a) and 59(c), the regular assessment of performance against agreed service levels and of both parties' compliance with the agreement. Six stay. The provider is still covered by the service provider management policy, which under paragraph 47(c) reaches the fourth parties a material provider relies on. It is still on the register under paragraph 48 and still goes to APRA under paragraph 50. Due diligence under paragraph 52 still applies, and so do paragraphs 55(a) to 55(c): delivery risk, step-in and contagion risk, and the entity's ability to execute its continuity plan. So does paragraph 59(b), the assessment of the controls managing the provider's risks, which sits between two subsections that were lifted, and so does the 20 business day notification in paragraph 60(a).
Paragraph 57 carries both conditions, and both have to hold. The provider has to sit in one of the seven categories in the standard's Attachment: government agencies, regulators, central banks, financial market exchanges, operators of clearing and settlement facilities, operators of payment systems and schemes, and financial messaging infrastructure. And the arrangement has to use standardised terms, which the closing words of paragraph 57 define as terms prepared by the provider where the entity has no, or substantially no, ability to negotiate or amend rights and obligations, or it has to be an arrangement with no formal agreement at all. Where an arrangement satisfies neither condition, paragraph 58 lets APRA exempt it from the same five provisions by written notice, so that relief is a decision APRA takes. APRA described the change as a targeted, administratively efficient solution that preserves the core objectives of operational risk management.
Three clocks after the event, and one obligation before it
A team that came to CPS 230 from CPS 234 knows one notification clock. There are three, and a fourth obligation that runs the other way.
- Starts with a disruption or an incident
- Starts with a provider arrangement
- The shortest clock, 24 hours
- Paragraph 41
24 hours
A disruption to a critical operation outside tolerance levels
1328 days - Paragraph 32
72 hours
An operational risk incident the entity judges likely to have a material financial impact, or a material impact on maintaining critical operations
1328 days - Paragraph 60(a)
20 business days
Entering into, or materially changing, an agreement for a service the entity relies on to undertake a critical operation
1328 days - Paragraph 60(b)
Before it happens
Entering into, or significantly changing, a material offshoring arrangement
Paragraph 41. The nature of the disruption, the action taken, the likely impact and when normal operations return.
Paragraph 32. A notification already made under CPS 234 Information Security does not have to be repeated.
Paragraph 60(a). Twenty business days is four working weeks, which is where the bar ends on this axis.
Paragraph 60(b). Offshoring is decided by where the service is physically performed, not by where the provider is incorporated.
Paragraph 41 is the short one. APRA has to be told as soon as possible and no later than 24 hours after a disruption to a critical operation outside tolerance levels, with the nature of the disruption, the action taken, the likely impact and the timeframe for returning to normal operations. Paragraph 32 gives 72 hours from the moment the entity becomes aware of an operational risk incident it determines to be likely to have a material financial impact or a material impact on its ability to maintain critical operations, and its footnote says a notification already made under CPS 234 does not have to be repeated. Paragraph 60(a) gives 20 business days, four working weeks, after entering into or materially changing an agreement for a service the entity relies on to undertake a critical operation. Paragraph 60(b) runs before the event: APRA is notified before the entity enters into or significantly changes a material offshoring arrangement, and its footnote defines offshoring on where the service is physically performed, not on where the provider is incorporated.
A worked example: a general insurer's claims payment operation
The insurer has no discretion about the critical operation this guide follows. Paragraph 35 prescribes claims processing for a general, life or private health insurer unless the entity can justify otherwise, so claims payment is on the register as CO-02, defined end to end: a claim arrives and is registered, liability and the amount are decided, a payment file is built and released.
Naming it is the easy part. Paragraph 26(b) then asks for the processes and resources that deliver it: people, technology, information, facilities and service providers, the interdependencies across them, and the associated risks, obligations, key data and controls. The insurer's map was dated 31 July 2026.
- The critical operation
- Its three steps
- Outside the insurer
CO-02
Claims payment
Paragraph 34
Lodgement
A claim arrives and is registered
People
Contact centre team, Adelaide
Technology
Policy administration system
Information
Claim files and evidence
Facilities
Adelaide contact centre
Service providers
Document store providerMaterial
Assessment
Liability and the amount are decided
People
Six in-house assessors on the surge roster
Technology
Claims management system
Information
Assessment notes and decisions
Facilities
Melbourne claims centre
Service providers
Meridian Claims ServicesMaterial
Fourth party · paragraph 47(c)
Meridian's cloud hosting provider, Singapore
Payment release
A payment file is built and released
People
Payments officers, Melbourne
Technology
Payment file gateway
Information
Payment instructions and the daily file
Facilities
Melbourne claims centre
Service providers
Payment scheme operator and the transactional bankMaterial
Read down a column and the operation stops looking like a department. Assessment alone runs on six in-house assessors on the surge roster, the claims management system, their notes and decisions, the Melbourne claims centre and Meridian Claims Services. All four providers across the three steps are material under paragraph 48, and one of them brings a further party into view: Meridian's cloud hosting provider in Singapore, a fourth party the policy has to cover under paragraph 47(c).
The three numbers the Board approved
On 18 June 2026, ahead of the current standard commencing, the Board approved three tolerance levels for claims payment under what is now paragraph 21(b). The maximum period of disruption it would tolerate is eight hours. The maximum data loss it would accept is fifteen minutes. The minimum service level it would maintain under alternative arrangements is sixty payments released a day, against about nine hundred on a normal day, covering emergency and hardship claims released by hand. Paragraph 38 leaves APRA a hand in them: it may require an entity to review and change a tolerance level, and may set them itself where it identifies a heightened risk or material weakness.
Paragraph 42's annual business continuity exercise then tested them. On 2 September 2026 the insurer took Meridian offline for a full day, a scenario the program has to include because paragraph 43 requires disruptions to material service providers.
- The paragraph that requires it
- The number the Board approved
- Inside tolerance
- Outside tolerance
Hours
The maximum period of time it would tolerate a disruption
Maximum allowable disruption and recovery time objective
Minutes
The maximum extent of data loss it would accept
Recovery point objective, which sets how often point-in-time backups run
Payments released a day
The minimum service levels it would maintain under alternative arrangements
Recovery level objective, the minimum people, information assets and other resources the service needs
The hatched band on each scale is the side the operation must not finish on. On the first two it lies beyond the number, because the tolerance is a ceiling. On the third it lies short of the number, because the tolerance is a floor, and the top of that axis is a reading scale rather than the capacity of the operation, which runs to about nine hundred payments on a normal day. The three numbers were approved by the Board on 18 June 2026. The second column reads CPG 230 Table 4, which is APRA's guidance on sound practice and not a requirement in itself.
Two of the three held and one did not. Data loss came in at seven minutes against a ceiling of fifteen, and manual payments ran at sixty-eight a day against a floor of sixty. Restoration took ten hours against a ceiling of eight, and the two hours are the whole finding: the surge roster of six assessors could not be stood up inside the window, because four of them were working their normal claim queues and nobody had pre-authorised the switch.
That result is a test, not a disruption, so no clock started. Had the same two-hour overrun happened in production, paragraph 41's 24 hours would have been running from the moment the insurer knew the operation was outside tolerance.
What the record holds afterwards
Finding BCX-11 records the overrun, owned by Daniel Okafor, head of claims, due 18 December 2026, and its remediation is a pre-authorised surge roster with a standing release from the assessors' line managers. The Board reviewed the exercise result and the remediation plan on 16 September 2026, which is the review and oversight paragraph 21(b) requires of it. Internal audit's periodic review of the plan and of whether the testing is adequate and satisfactorily conducted, required by paragraph 45, is scheduled for March 2027.
The service provider work ran over the same quarter. The register of material service providers went to APRA on 31 July 2026 under paragraph 50, carrying fourteen arrangements, four of which support claims payment. On 6 August 2026 the insurer notified APRA under paragraph 60(b), before it moved a second claims queue, motor total-loss assessment, to Meridian in Manila: a significant change to a material offshoring arrangement, and the notification has to precede it. The varied agreement with Meridian was signed on 14 August 2026 carrying paragraph 53's seven minimums, among them that Meridian notify the insurer of other material service providers it materially relies on and remain liable for any sub-contractor failure, plus paragraph 54's APRA access and on-site visit rights.
What the insurer holds at the end of the quarter is one critical operation with a named definition, three approved tolerance numbers, one dated dependency map naming four material providers and one fourth party, one exercise with a result against each tolerance level, one finding with an owner and a date, one recorded Board review and one submitted register. That is the record a supervisor asks for, and it exists because the work produced it.
Common mistakes
Eight failure modes turn up repeatedly, and each has a fix that costs less than the rework.
- Building against the July 2025 version. Check any paragraph number against the current instrument, F2026L00475, before it goes into a policy, a board pack or a contract. The numbering moved.
- Treating APRA's prescribed list as the whole list. Paragraph 35 is a floor, not a ceiling, and paragraph 36 lets APRA require a further business operation to be treated as critical. The operations your own customers would notice belong on the register whether or not APRA names them.
- Letting the technology team set the tolerance levels. Paragraph 21(b) puts the approval with the Board, so the business has to own the number before it reaches the meeting.
- Recording one tolerance number per operation. Paragraph 37 asks three different questions, and they fail in different ways: time to restore, data lost, and service delivered while the alternative arrangement is running.
- Keeping a register of critical operations that does not say which providers support each one. Paragraph 26(b) requires the interdependencies, and CPG 230 says a register in practice names a responsible person per arrangement and the critical operation it supports. Without those links the first supervisory question has no answer.
- Stopping at third parties. Paragraph 47(c) requires the policy to cover the risks of any fourth parties that material service providers rely on to deliver a critical operation. A fourth party is a party the provider relies on in delivering services to the entity.
- Missing the 24 hour clock because the 72 hour one is the familiar clock. Paragraph 32 and paragraph 41 answer different events, and only paragraph 32 shares its notification with CPS 234.
- Reading the 2026 amendment as broad relief. Paragraph 57 reaches seven named categories, only where the terms are genuinely non-negotiable, and only five provisions; everything outside it needs a written notice from APRA under paragraph 58.
Several of these land in the same place, the row on the register itself.
- What fails in it
What is named
Claims management system
Paragraph 34 names a process, not a system
Claims payment, end to end: lodgement, assessment, payment release
Paragraph 34
Tolerance levels
Recovery time objective, 8 hours
Paragraph 37 asks three questions, and they fail in different ways
8 hours of disruption · 15 minutes of data loss · 60 payments a day
Paragraph 37
What delivers it
Owned by technology
Paragraph 26(b) asks for the interdependencies, not only the owner
People, technology, information, facilities, four material providers and one fourth party
Paragraph 26(b)
Who answers for it
Not recorded
Nobody to ask when the operation stops
A named responsible person per arrangement, and the critical operation each one supports
CPG 230 · guidance
Nothing on the right is there for its own sake. Every field answers a question a supervisor asks, and each one is already required somewhere else in the standard.
CPS 230 compared with its neighbours
Two things separate CPS 230 from the documents around it: what each one governs, and whether it binds at all.
- The standard this guide is about
- Named inside CPS 230
- An obligation from outside APRA
- A model you may adopt
Binding on every APRA-regulated entity
Governs: the operation
CPS 230
In force 1 July 2026
Points at CPS 234 for information security, paragraph 24
Governs: the entity
CPS 220
Named at paragraph 15
Governs: the entity
CPS 190
Named at paragraph 17
Law, administered outside APRA
Governs: the operation
Security of Critical Infrastructure Act 2018
Administered outside APRA
Guidance or voluntary
Governs: the operation
CPG 230
APRA's own guidance
Governs: the operation
ISO 22301
Voluntary, certifiable
Three of the neighbours are named inside CPS 230 itself, which is why they cannot be run as separate programs. The list below carries the sentence that decides which one answers a given question.
| Term | What it is | Reach for it when |
|---|---|---|
| CPS 230 Operational Risk Management | The prudential standard on operational risk, business continuity and service provider management. In force from 1 July 2026, binding on every APRA-regulated entity, with the Board approving the plan, the tolerance levels and the service provider policy. | The question is whether a named operation keeps running through a severe disruption, and to what number. |
| CPS 234 Information Security | The prudential standard on information security, in force since 1 July 2019. CPS 230 does not repeat it: paragraph 24 requires the entity to monitor the age and health of its information assets and to meet CPS 234's requirements. | The question is whether information is protected. Run both from one control set: CPS 230 points at CPS 234 for technology risk instead of restating it. |
| CPS 220 Risk Management | The risk management framework CPS 230 sits inside. Paragraph 15 lists what that framework has to include for operational risk, from risk appetite and indicators through to service provider processes. | You are setting the appetite, the limits and the governance the operational risk work reports into. |
| CPS 190 | The standard covering recovery and exit planning. Paragraph 17 of CPS 230 requires business continuity planning to be consistent with it and not to conflict with or undermine it. | The scenario is the viability of the entity rather than the availability of an operation. |
| CPS 231, CPS 232, SPS 231, SPS 232 and HPS 231 | The five standards CPS 230 replaced: outsourcing and business continuity management across banking and insurance, superannuation, and private health insurance. | Never, for a live obligation. They are useful only for reading why an old policy says what it says. |
| ISO 22301 | The international standard for business continuity management systems, certifiable by an accredited body and voluntary. It sets out a management system, not an Australian obligation. | You want an external certificate, or a common structure to run continuity in. It does not discharge CPS 230 by itself. |
| The Security of Critical Infrastructure Act 2018 | Australian law, administered outside APRA, whose Part 2A requires a responsible entity for certain critical infrastructure assets to have a critical infrastructure risk management program and to submit an annual report on it. | Your assets fall inside the Act. An APRA-regulated entity can hold both obligations and should evidence them from one record. |
Standards and references
Start with which document binds. The standard in force was made under Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026, signed on 23 April 2026, registered on 29 April 2026 as F2026L00475, and commenced on 1 July 2026. That determination revoked the 2023 determination and the CPS 230 made under it, as varied in 2024, the 60-paragraph version that commenced on 1 July 2025 and that most of the pages ranking for the term still quote.
The renumbering has one cause. The 2025 version carried a transitional paragraph at 7: where an entity had pre-existing contractual arrangements with a service provider, the requirements applied from the earlier of the next renewal date or 1 July 2026. That paragraph had done its work by the time the new instrument was made, so it is gone, and everything between the old paragraphs 8 and 57 moved down by one.
Superseded
The July 2025 version
- Made under determination No. 2 of 2023, as varied in 2024
- Commenced 1 July 2025
- 60 paragraphs
- Revoked by the 2026 determination
In force
The current CPS 230
- Made under determination No. 1 of 2026, signed 23 April 2026
- Registered 29 April 2026 as F2026L00475
- Commenced 1 July 2026
- 61 paragraphs plus an Attachment
2025
2026
What the paragraph covers
Removed, which is why everything after it moved
The transitional arrangement for pre-existing service provider contracts, which ran to 1 July 2026
Minus one: paragraphs 8 to 57 became 7 to 56
The processes and resources a critical operation depends on, and scenario analysis
The 72 hour notification for a material operational risk incident
The business continuity requirements, including the register of critical operations
Tolerance levels for each critical operation
What the business continuity plan has to contain
The 24 hour notification for a disruption outside tolerance
Inserted, and the reason the tail moved the other way
The exemption from five provisions for certain non-traditional service providers, and what standardised terms means
APRA's power to exempt an arrangement that satisfies neither condition in paragraph 57, by written notice
Plus one: paragraphs 58 to 60 became 59 to 61
Ongoing monitoring of a material arrangement
The 20 business day notification and the offshoring notification
Internal audit on outsourcing a critical operation
Two new paragraphs were then inserted at 57 and 58 for the non-traditional service provider exemption, which pushed the last three the other way: monitoring moved from 58 to 59, the notification obligations from 59 to 60, and internal audit on outsourcing a critical operation from 60 to 61. The six rows in the middle group are the ones most likely to be sitting in an existing policy already.
The standard, F2026L00475 (made 23 April 2026, commenced 1 July 2026). The authorised text on legislation.gov.au is the version to quote. APRA also publishes the full text on its own CPS 230 page, under the status line In force, 1 July 2026.
The superseded July 2025 version (the 2023 determination as varied in 2024). Worth opening only to check a number in an old document against the current one.
CPG 230 Operational Risk Management, July 2026 edition (released 30 April 2026). APRA's practice guide, with 113 numbered paragraphs and five tables. Table 4 is the most useful page in it, because it maps the three tolerance levels onto maximum allowable disruption, the recovery time objective, the recovery point objective and the recovery level objective. Its paragraph 18 says what a supervisor will ask for when an entity decides a prescribed business operation is not a critical operation: documented reasons, approved by an Accountable person, reviewed at least annually. Its paragraph 48 describes what a register of material service providers holds in practice, and its paragraphs 32 and 33 list what a prudent entity weighs when setting tolerance levels.
APRA's media release finalising the targeted amendments (30 April 2026). The short public account of what changed at paragraphs 57 and 58, and the announcement that came with the updated register template for material service providers.
The 2022 consultation release (28 July 2022) and the 2023 response paper (11 July 2023). The consultation release is the primary source for the five standards CPS 230 replaced. The response paper is where APRA deferred commencement from the proposed 1 January 2024 to 1 July 2025 and added the transitional arrangement for existing service provider arrangements.
How Alvor helps
With Alvor, an organisation can keep the record CPS 230 asks it to produce, in the shape the standard asks for it.
The Business Continuity module holds the operational side. Business processes are registered with owners and typed dependencies on assets, vendors and named people, which is the shape paragraph 26(b) asks for. A guided business impact analysis derives the criticality tier, the maximum tolerable period of disruption and a recommended recovery time objective from the process owner's own impact ratings. Continuity plans inherit recovery time, recovery point and maximum tolerable downtime from the approved analyses of every process they cover, and the most stringent value wins, so a plan cannot quietly promise less than a process needs. Recovery time gap analysis flags any supporting asset that recovers more slowly than the process it supports. Exercises run from tabletop through to full failover, each linked to the plans and processes it tests, recording the achieved recovery time and recovery point against target and turning lessons into tracked findings. A real activation becomes a live task board assigned to named people, and the incident runs Active, Stood down, Closed in that order with debrief findings in between.
The supplier side sits in Third-Party Risk Management. A vendor is filed at intake before it exists in the system, triaged and approved by someone other than the requester, and given a tier that sets how often it is reassessed. Vendors answer in a hardened external portal with a rotating link and an emailed code, and every submission writes to the hash-chained audit log. A vendor record carries contacts, contracts, certifications, the scored assessment and the findings raised against it, and residual risk is accepted only by the person named to accept it, with conditions and an expiry. A business process can declare a vendor as a typed dependency with its own criticality, which is the link between the continuity register and the supplier record.
APRA CPS 234 installs from the framework library in the standard's own wording, and you can add any framework in Alvor, so your CPS 230 obligations go in as APRA words them and work like every other framework: control owners, evidence with freshness states, assessments, and crosswalks so evidence attached once serves more than one framework while each is still assessed on its own wording. Alvor for Australian organisations covers the rest of the Australian picture.
Alvor Advisory runs a named APRA CPS 230 operational resilience readiness engagement alongside a CPS 234 information security readiness engagement, ending in a control-by-control gap register and a board-ready assurance summary. The practice prepares you, evidences the gaps and stands beside you, and never marks its own work: compliance with a prudential standard is a matter between the entity, its board and APRA. APRA CPS 230 and CPS 234 readiness has the scope.
The AI Assistant is bring-your-own-model, so prompts go to the provider and region you choose or to a self-hosted model inside your own boundary, and it proposes while a person approves every write. Activating a plan, standing down, closing an incident and approving a plan stay human. Alvor runs as a dedicated single-tenant instance in the Sydney region, ap-southeast-2, on your own servers, or air-gapped, with every module included in each of the three.