APRA CPS 230 and CPS 234 Advisory and Audit

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our CPS 230 and CPS 234 advisory helps APRA-regulated banks, insurers and superannuation trustees meet APRA’s information security and operational risk standards, prove it to the board, and stay ready for supervisory review. Security Solution Consultants (SSC) provides gap assessments, maturity assessments, independent control testing and audit support for CPS 234 Information Security and CPS 230 Operational Risk Management.

Executives in a bank boardroom above a harbour city reviewing a resilience report, representing APRA CPS 230 and CPS 234 advisory
APRA holds boards accountable for both information security and operational resilience.

CPS 234 and CPS 230 in brief

CPS 234 Information SecurityCPS 230 Operational Risk Management
In force1 July 2019Commenced 1 July 2025; targeted amendments apply from 1 July 2026
FocusInformation security capability, controls, testing and incident notificationOperational risk, critical operations, business continuity and material service providers
Key requirementsBoard accountability, information asset classification, controls, systematic testing, internal audit, third-party assuranceCritical operations and tolerance levels, business continuity plans tested annually, service provider management and a register of material arrangements
APRA notifications72 hours for a material information security incident; 10 business days for a material control weakness72 hours for a material operational risk incident; 24 hours when a critical operation is disrupted beyond tolerance; 20 business days after entering or materially changing a material arrangement

The two standards overlap: a cyber incident is an operational risk event, and a service provider that holds your data is both a CPS 234 third party and a CPS 230 material service provider. We assess them together so you build one set of controls and evidence.

Our CPS 230 and CPS 234 services

  • Gap assessment against every paragraph of CPS 234 and CPS 230, with a prioritised remediation plan.
  • Maturity assessment that scores your information security and operational resilience capability, so the board can see progress year on year.
  • Independent control testing to meet CPS 234’s requirement for systematic testing of control effectiveness, by people independent of those who run the controls.
  • Audit and assurance support for internal audit reviews, including scoping, test plans and findings.
  • Critical operations and tolerance levels: identifying critical operations, setting maximum disruption, data loss and minimum service levels, and mapping the people, technology and providers they rely on.
  • Business continuity and scenario testing: plans and severe but plausible scenarios, tested at least annually.
  • Service provider risk: the material arrangements register, due diligence, contract clauses and ongoing monitoring.
  • Incident notification playbooks so the 24-hour and 72-hour clocks are met.

Material service providers and third parties

Signed service agreement beside a laptop showing a network of supplier nodes, representing material service provider management under CPS 230
Your obligations do not stop at your own systems.

CPS 230 requires a comprehensive service provider management policy, a register of material arrangements submitted to APRA, and controls over material arrangements, including those with offshore providers. CPS 234 adds that you must assess the information security capability of third parties that manage your information assets. We build the register, design a proportionate due diligence and monitoring approach, and draft the contract clauses that make it enforceable.

Independent testing under CPS 234

Security tester reviewing coloured control test results on two monitors, representing independent CPS 234 control testing
Testing shows the board that controls work, not just that they exist.

CPS 234 expects testing to be risk-based, carried out by appropriately skilled and independent people, and reported to the board with remediation tracked. We design the testing program, test key controls such as access management, privileged access, vulnerability management, backup and recovery, and third-party access, and report results in a form the board and APRA can rely on.

Why work with SSC

  • We combine information security, operational risk and audit experience, so CPS 234 and CPS 230 are handled as one program.
  • SSC is certified to ISO/IEC 27001, and many CPS 234 controls map directly to ISO 27001 Annex A.
  • Our GRCLens CPS 230 and CPS 234 modules keep controls, evidence, critical operations and the service provider register in one place.

Related: what changed in CPS 230 on 1 July 2026, business continuity management, enterprise risk management and cyber security maturity assessments.

Frequently asked questions

APRA-regulated entities, including authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees of superannuation funds.

A board-accountable information security capability, classification of information assets, controls proportionate to threats, systematic and independent testing of control effectiveness, internal audit coverage, and notification to APRA of material incidents and control weaknesses.

CPS 230 commenced on 1 July 2025, replacing APRA's earlier outsourcing and business continuity standards. APRA made targeted amendments that apply from 1 July 2026.

Critical operations are processes whose disruption would have a material adverse impact on customers or the entity. For each, the entity sets tolerance levels for the maximum period of disruption, the maximum extent of data loss and minimum service levels.

Under CPS 234, within 72 hours for a material information security incident. Under CPS 230, within 72 hours for a material operational risk incident and within 24 hours when a critical operation is disrupted beyond its tolerance.

Yes. Our consultants are independent of your operations team and can run the systematic control testing CPS 234 expects, with results reported to the board.

Talk to us about CPS 230 and CPS 234

Tell us where you are today and what you need to achieve. We will come back with a clear scope, timeline and fixed quote.