Critical operations
Identify operations whose disruption would have a material adverse impact on beneficiaries, members, policyholders or the financial system.
APRA's operational-risk-management standard, including business continuity and service-provider management obligations.
CPS 230 consolidates and strengthens APRA's expectations on operational risk, covering resilience of critical operations, management of service provider arrangements, and scenario testing of recovery against severe-but-plausible disruption. Cyber incidents sit inside operational risk under this standard: "critical operations" must be identified and their disruption tolerances documented, measured and tested. Boards approve tolerances; internal audit provides independent assurance.
All APRA-regulated entities - ADIs, insurers, superannuation trustees and RSE licensees. Non-significant financial institutions had an additional 12-month transition window.
Identify operations whose disruption would have a material adverse impact on beneficiaries, members, policyholders or the financial system.
Establish, and have the Board approve, tolerance levels for each critical operation (maximum period and extent of disruption).
Regularly test the ability to operate within tolerance through severe-but-plausible scenarios.
Maintain a register, undertake due diligence, manage service-provider risk and notify APRA of material arrangements.
Maintain a Board-approved plan aligned to critical operations and tolerances.
Notify APRA of operational-risk incidents likely to have a material impact and maintain an incident register.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.