Australia · Australian Prudential Regulation Authority (APRA) · CPS 230

APRA Prudential Standard CPS 230

APRA's operational-risk-management standard, including business continuity and service-provider management obligations.

What it is

CPS 230 consolidates and strengthens APRA's expectations on operational risk, covering resilience of critical operations, management of service provider arrangements, and scenario testing of recovery against severe-but-plausible disruption. Cyber incidents sit inside operational risk under this standard: "critical operations" must be identified and their disruption tolerances documented, measured and tested. Boards approve tolerances; internal audit provides independent assurance.

Who it applies to

All APRA-regulated entities - ADIs, insurers, superannuation trustees and RSE licensees. Non-significant financial institutions had an additional 12-month transition window.

Requirements

Critical operations

Identify operations whose disruption would have a material adverse impact on beneficiaries, members, policyholders or the financial system.

Tolerance for disruption

Establish, and have the Board approve, tolerance levels for each critical operation (maximum period and extent of disruption).

Scenario testing

Regularly test the ability to operate within tolerance through severe-but-plausible scenarios.

Service provider management

Maintain a register, undertake due diligence, manage service-provider risk and notify APRA of material arrangements.

Business continuity plan

Maintain a Board-approved plan aligned to critical operations and tolerances.

Operational risk incidents

Notify APRA of operational-risk incidents likely to have a material impact and maintain an incident register.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.