All insights
APRA & Financial Services June 4, 2026 6 min read

CPS 234 and Third-Party Service Providers: Managing the Risk

The most common misconception about APRA CPS 234 is that outsourcing a system or dataset transfers the cyber obligation along with it. It does not. Where a third party stores, processes or otherwise manages your information assets, CPS 234 holds the regulated entity responsible for ensuring that party’s controls are adequate – and for evidencing it.

For Australian banks, insurers and superannuation funds, this matters more every year as core processing, cloud platforms, claims systems and member portals shift to vendors. This guide sets out what CPS 234 requires of your third-party arrangements and the practical controls that satisfy APRA without grinding procurement to a halt.

What the standard actually says about third parties

CPS 234 contains explicit, repeated references to third parties. The standard requires that an entity’s information security capability is commensurate with vulnerabilities and threats, including where information assets are managed by a related party or a third party. It requires that information assets managed by third parties are classified by criticality and sensitivity. And critically, it requires the entity to evaluate the design and operating effectiveness of the information security controls maintained by any third party that manages the entity’s information assets.

In other words, the same obligations you apply internally – classification, proportionate controls, control testing, internal audit assurance – extend to your supply chain. The depth of evaluation should scale with how critical and sensitive the relevant assets are. A provider holding member tax file numbers or running your core banking platform warrants far deeper scrutiny than one hosting a brochureware website. Our overview of APRA CPS 234 obligations sets the broader context for these requirements.

Building a defensible provider risk programme

A programme that satisfies CPS 234 has a clear lifecycle: identify, assess, contract, monitor and exit. Each stage produces evidence APRA can review.

  • Identify and classify – maintain a register of providers that manage information assets, with the assets, their classification and the provider’s role. You cannot manage providers you have not catalogued.
  • Risk-tier – rank providers by the criticality and sensitivity of the assets they handle so assurance effort is proportionate.
  • Assess controls – gather evidence of control design and operating effectiveness before onboarding and periodically thereafter.
  • Contract – lock in security, audit, incident and exit obligations.
  • Monitor – review assurance reports, incidents and material changes on an ongoing basis, not just at onboarding.
  • Exit – ensure data is returned or destroyed and access revoked when the relationship ends.

Evidence that satisfies APRA

CPS 234 requires you to evaluate the design and operating effectiveness of a provider’s controls – not merely to ask whether they take security seriously. The proportionate evidence base typically includes:

  • Independent assurance reports – a SOC 2 Type II report or ISO 27001 certification with a current Statement of Applicability gives independent comfort over a provider’s control environment. A Type II report is more valuable than Type I because it covers operating effectiveness over a period, not just design at a point in time.
  • Provider control testing – penetration test summaries and vulnerability management evidence.
  • Security questionnaires – useful for lower-tier providers, but weak as standalone evidence for critical ones.
  • Right-to-audit – for your most critical providers, contractual audit rights and, where warranted, direct independent assessment.

For high-criticality relationships, do not rely on a certificate alone. Review the scope of any certification carefully – an ISO 27001 certificate that excludes the very system holding your data offers little assurance. Likewise, read the exceptions and complementary user entity controls in a SOC 2 report: those controls are your responsibility, not the provider’s, and a clean opinion can still leave material work in your court. Our guidance on cyber due diligence covers how to test these claims properly, including the assessment depth APRA expects for material providers. The ISO 27001 standard is a useful common language when comparing providers.

Fourth parties and concentration risk

Your providers have providers. The cloud platform your claims system runs on, the data centre behind your core banking vendor, the email-security service your member portal depends on – each is a fourth party whose failure or compromise can flow straight through to you. CPS 234 follows your information assets wherever they are managed, so material sub-contracting must be visible and controlled. Contracts should require providers to disclose material sub-contractors, control changes to them, and flow down equivalent security and notification obligations.

Concentration risk compounds this. When many of your critical providers ultimately rely on the same hyperscale cloud region or the same identity provider, a single outage or breach can disrupt several supposedly independent services at once. Mapping these shared dependencies across your provider register lets you see correlated failure points that a per-provider assessment would miss – and it feeds directly into the business-continuity and tolerance work that CPS 230 now demands.

Contracts: the control that ties it together

Assurance is only as strong as the contract behind it. CPS 234 does not prescribe clauses, but APRA expects arrangements that let you meet your own obligations. At a minimum, contracts with providers managing your information assets should address:

  • Specific information security obligations aligned to your classification and control expectations.
  • Audit and assurance rights, including access to independent reports and, for critical providers, a right to audit.
  • Incident notification timeframes short enough that you can meet APRA’s 72-hour deadline – the obligation to notify APRA rests with you, not the provider.
  • Controls on sub-contracting and fourth-party risk, so the provider cannot quietly shift your data to an unassessed party.
  • Data location, sovereignty and handling requirements.
  • Return or secure destruction of data and revocation of access on exit.

The incident-notification clause is the one most often missed. If your provider has 30 days to tell you about a breach, you cannot possibly meet a 72-hour regulatory deadline that starts when you become aware. Drafting that obligation tightly is one of the highest-value things you can do.

Ongoing monitoring, not a one-off tick

CPS 234 obligations are continuous. A provider assessed as low-risk at onboarding can become high-risk after a merger, a platform migration, a change of sub-contractor or a publicly disclosed breach. A credible programme refreshes assurance evidence on a risk-based cycle, tracks providers’ own incidents, and re-tiers providers when their role or your data footprint changes. Internal audit should periodically test that this monitoring is actually happening – CPS 234 extends the internal audit assurance requirement to third-party controls.

The CPS 230 overlap you cannot ignore

From 1 July 2025, CPS 230 sits alongside CPS 234 and significantly widens provider-management expectations. Where CPS 234 is concerned with information security of third-party-managed assets, CPS 230 requires entities to identify material service providers, maintain a register, manage the risks they pose to operations, and ensure they support business continuity. The two standards reinforce each other, and a single provider-management framework should satisfy both. We unpack the operational-risk dimension in our article on APRA CPS 230 operational risk.

Where to start

If your third-party programme needs strengthening, begin by building or refreshing the provider register and risk-tiering it by asset criticality. From there, close the gaps in assurance evidence for your top-tier providers, tighten incident-notification clauses in renewals, and confirm internal audit has third-party controls in its plan.

Managing supply-chain cyber risk to APRA’s standard takes both regulatory fluency and technical judgement. CISO Advisory Australia helps regulated entities and their providers build proportionate, defensible third-party risk programmes. To discuss your arrangements, contact us or call 07 2112 8502.

Frequently asked questions

Does CPS 234 apply to my third-party providers?

CPS 234 applies to the regulated entity, not directly to its providers. However, where a third party manages your information assets, you must be satisfied their information security capability is commensurate with the sensitivity of those assets and you must evaluate the design and operating effectiveness of their controls. The obligation stays with you.

What is the difference between CPS 234 and CPS 230 for providers?

CPS 234 focuses on information security of third-party-managed assets. CPS 230, effective 1 July 2025, broadens this to operational risk and requires entities to manage material service providers, maintain a register, and ensure providers support business continuity. They overlap but CPS 230 sets wider provider-management expectations.

How do I assess a provider's controls under CPS 234?

Use evidence proportionate to asset criticality: independent assurance reports such as SOC 2 Type II or ISO 27001 certification, the provider's own control testing results, right-to-audit clauses, security questionnaires, and contractual incident-notification obligations. For critical providers, supplement reports with direct review or independent assessment.

What contract clauses does CPS 234 effectively require?

While CPS 234 does not dictate wording, contracts with providers managing information assets should cover information security obligations, audit and assurance rights, incident notification timeframes that let you meet APRA's 72-hour deadline, sub-contracting controls, data location and return or destruction on exit.

Who must notify APRA if a provider suffers a breach?

The regulated entity is responsible for notifying APRA, not the provider. That is why provider contracts must require prompt incident notification to you, fast enough that you can meet your own 72-hour APRA deadline. You cannot rely on the provider to discharge an obligation that legally rests with you.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act