APRA Prudential Standard CPS 230 Operational Risk Management took effect on 1 July 2025 and represents the most significant change to operational risk regulation for Australian financial entities in years. It consolidates and replaces several older standards, and it reframes cyber not as a standalone IT concern but as one of the most material sources of operational disruption a regulated entity faces.
For chief information security officers, technology leaders and boards at banks, insurers and superannuation funds, CPS 230 raises the bar. This guide explains what the standard requires, how it connects to your existing CPS 234 information security controls, and the practical steps to be ready.
What CPS 230 sets out to achieve
CPS 230’s objective is to ensure regulated entities are resilient to operational risks and disruptions. It requires entities to manage operational risk effectively, maintain critical operations within defined tolerance levels through disruptions, and manage the risks arising from service providers. It consolidates and replaces the previous outsourcing standard CPS 231 and the business continuity standard CPS 232, bringing these obligations together under one framework.
The standard rests on three pillars that every cyber programme should understand.
- Operational risk management – maintain a framework to identify, assess and manage operational risks, with effective internal controls and regular monitoring. Cyber and technology risk sit squarely within this.
- Business continuity – identify critical operations, set tolerance levels for disruption, and maintain a credible, tested business continuity plan.
- Service provider management – identify material service providers, maintain a register, manage their risks and ensure they support the entity’s ability to meet its obligations.
Why CPS 230 is fundamentally a cyber standard
Although CPS 230 is framed around operational risk generally, cyber events are among the most likely and most severe causes of operational disruption. Ransomware that encrypts core systems, a cloud provider outage, or a data-destruction attack are precisely the severe but plausible scenarios CPS 230 expects entities to plan for. A robust information security posture under APRA CPS 234 is therefore a prerequisite for meeting CPS 230, not a separate track of work.
The connection runs both ways. CPS 234 tells you to detect and respond to incidents; CPS 230 tells you to keep your critical operations running within tolerance while you do. An incident response plan that recovers a system but cannot demonstrate the business stayed within its disruption tolerance no longer meets the regulatory bar.
Critical operations and tolerance levels
The headline new concept in CPS 230 is the critical operation. These are the processes whose disruption would materially harm depositors, policyholders, beneficiaries or financial system stability – typically payments, settlements, claims, member transactions and the systems underpinning them. Entities must identify their critical operations, map the people, technology, information and service providers each depends on, and set tolerance levels: the maximum disruption the entity is willing to tolerate, expressed in measurable terms such as acceptable downtime or data loss.
The cyber implication is direct. Once you have set, say, a maximum tolerable downtime for payments processing, you must be able to show through testing that a ransomware event will not breach it. That forces conversations about recovery time objectives, immutable and tested backups, segmentation, and the ability to fail over or operate degraded. The ASD Essential Eight – particularly its backup, patching and application control mitigations – maps directly to keeping critical operations within tolerance during a cyber disruption.
Scenario testing that includes cyber
CPS 230 requires entities to test their ability to maintain critical operations within tolerance under severe but plausible scenarios, and to do so regularly. For cyber teams, this means moving beyond a tabletop walk-through of a single incident toward integrated exercises that test the full chain: detection, response, business continuity invocation, communications and recovery, all measured against tolerance levels.
Practical, high-value scenarios include a ransomware event that renders a core platform unavailable, a prolonged outage at a critical cloud or processing provider, and a destructive attack that compromises both primary systems and recent backups. A well-designed exercise produces evidence APRA values: where tolerances held, where they were breached, and what remediation followed. Our guidance on building an incident response plan shows how to align incident response with these continuity and tolerance requirements so the two operate as one playbook.
Material service providers: a wider net than CPS 234
CPS 230 significantly expands provider-management obligations. Entities must identify their material service providers – those they rely on for critical operations or that expose them to material operational risk – maintain a register of them, and notify APRA of certain arrangements. They must have policies for managing these providers, assess and manage the risks, and ensure providers can support the entity’s continuity and compliance obligations.
This goes beyond CPS 234’s focus on providers managing information assets. Under CPS 230, a provider may be material because of its role in a critical operation even if it does not directly handle sensitive data. The two standards should be served by a single, integrated provider-management framework rather than parallel processes. We explore the information security dimension in detail in our article on CPS 234 and third-party service providers, including the contractual incident-notification and audit rights that both standards effectively demand. APRA provided transitional arrangements for some pre-existing contracts, but new and renewed arrangements should be brought into line now.
Governance and board accountability
Like CPS 234, CPS 230 places clear accountability on the board. The board is responsible for the operational risk management framework and must ensure senior management establishes and maintains it. Boards should expect reporting on critical operations and their tolerances, scenario-testing results, material operational risk incidents and the status of material service providers. For entities also subject to APRA’s accountability regimes, individual accountabilities for operational resilience should be clearly assigned.
Where in-house capability is stretched – and operational resilience spans technology, cyber, risk and continuity – a virtual CISO can provide the cross-disciplinary leadership to connect cyber controls to operational-risk outcomes and produce board-grade reporting that satisfies the standard.
A practical CPS 230 readiness checklist
- Identify your critical operations and map their dependencies on technology, data and providers.
- Set measurable tolerance levels for disruption to each critical operation.
- Confirm your cyber controls – especially backups, recovery and segmentation – can keep operations within tolerance during a cyber event.
- Run severe-but-plausible scenario tests, including ransomware and provider-outage scenarios, and document results.
- Build a single material-service-provider register and management framework serving both CPS 230 and CPS 234.
- Establish board reporting that links operational resilience, cyber posture and provider risk.
CPS 230 makes cyber resilience a board-level operational imperative, measured by your ability to keep the lights on through a severe disruption. CISO Advisory Australia helps banks, insurers and superannuation funds align their CPS 234 and CPS 230 programmes into one coherent, defensible whole. For a confidential discussion, get in touch or call 07 2112 8502.
Frequently asked questions
When did CPS 230 take effect?
APRA Prudential Standard CPS 230 Operational Risk Management took effect on 1 July 2025. APRA provided transitional arrangements for certain pre-existing service provider contracts, but the core operational risk management, business continuity and service provider obligations apply from that date for in-scope regulated entities.
How is CPS 230 different from CPS 234?
CPS 234 governs information security specifically. CPS 230 is broader: it covers all operational risk, including cyber, technology, people, process and external events. CPS 230 also introduces explicit business continuity, tolerance-level and critical-operations requirements, and a strengthened framework for managing material service providers across the whole operation.
What are critical operations under CPS 230?
Critical operations are processes that, if disrupted, would have a material adverse impact on depositors, policyholders, beneficiaries or the financial system. Examples include payments, settlements, claims processing and member transactions. Entities must identify these, set tolerance levels for disruption, and demonstrate they can maintain them within tolerance during severe but plausible scenarios.
What is a disruption tolerance level?
A tolerance level is the maximum level of disruption an entity is willing to accept for a critical operation, expressed in measurable terms such as maximum downtime or data loss. CPS 230 requires entities to set these, then test through severe but plausible scenarios, including cyber scenarios such as ransomware, that they can stay within tolerance.
Does CPS 230 replace CPS 231 and CPS 232?
Yes. CPS 230 consolidates and replaces the previous outsourcing standard (CPS 231) and business continuity management standard (CPS 232), along with related standards, into a single operational risk framework. This means service provider and continuity obligations now sit together under one prudential standard.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.