APRA CPS 230 — Operational Risk Management

APRA's operational risk standard for banks, insurers and superannuation funds. In force since 1 July 2025, with the last transitional relief ended 1 July 2026.

Australian Prudential Regulation Authority (APRA).

What it is

CPS 230 is APRA's cross-industry prudential standard on operational risk management. It requires APRA-regulated entities to identify their critical operations, set tolerances for disruption, manage the risks arising from their service providers, and demonstrate they can keep operating through disruption.

The dates, stated correctly

There is a common misreading worth clearing up. CPS 230 commenced on 1 July 2025, not 2026. The substantive obligations — critical operations register, impact tolerances, business continuity capability — have applied since that date.

What happened on 1 July 2026 is that the last transitional relief expired. APRA had given entities until the earlier of the next contract renewal or 1 July 2026 to bring pre-existing material service provider arrangements into line. From that date there is no legacy category left: every material arrangement, however old the paperwork, must meet CPS 230 requirements. Non-significant financial institutions also had a 12-month extension on certain business continuity requirements, running to the same date.

APRA's final targeted amendments to CPS 230, CPG 230 and the Material Service Provider Register template, released on 30 April 2026, also commenced on 1 July 2026 — including limited contractual exemptions for certain non-traditional providers.

Four obligations frame the standard: identify critical operations; set impact tolerances for each; manage material service provider risk including fourth-party dependencies; and demonstrate business continuity capability.

Who it's for

APRA-regulated entities

Authorised deposit-taking institutions including foreign ADIs and authorised non-operating holding companies; general insurers including Category C insurers; life companies including friendly societies; and registrable superannuation entities.

Material service providers to those entities

The larger population commercially. A provider is material where the institution relies on it to undertake a critical operation, or where the arrangement exposes the institution to material operational risk. If that is you, your contract must meet CPS 230 terms and you will be asked to evidence your resilience.

AI and technology vendors inside critical operations

Worth calling out specifically. AI providers increasingly sit inside critical operations, and where an institution relies on one, that provider belongs on the MSP register with a contract that meets the standard.

Fourth parties

The standard reaches dependencies behind your suppliers, so a subcontractor to a material service provider can find the obligation arriving indirectly.

Why implement it

  • For regulated entities it is a prudential standard, supervised by APRA, applying in full with no transitional relief remaining.
  • For suppliers it is now unavoidable. Since July 2026 there is no legacy contract category, so every material arrangement is in scope regardless of when it was signed.
  • It forces an honest dependency map. Identifying critical operations and the providers behind them, including fourth parties, is work most institutions had never completed to this depth.
  • Tolerances make continuity concrete. A maximum tolerable disruption expressed in time or volume is testable in a way a business continuity plan alone is not.
  • The evidence is reusable. Suppliers answering CPS 230 assurance requests usually find that ISO 27001 plus ISO 22301 covers most of what is asked.

For the technology recovery layer beneath business continuity, ISO/IEC 27031 helps teams test whether ICT recovery capability matches the objectives they have set.

How implementation works

1. Identify critical operations

The processes whose disruption would materially affect customers, the entity, or the financial system. The final standard allows a measure of flexibility not to classify an operation as critical, provided the entity can give satisfactory justification — though APRA may override that assessment.

2. Set impact tolerances

For each critical operation, the maximum tolerable disruption in time, scale or volume. Tolerances should live with the process they govern so the two cannot drift apart.

3. Map the operations end to end

Each critical operation gets a process map, linked back to the critical operations register. This is what makes tolerance setting meaningful rather than notional.

4. Build and maintain the MSP register

Identify material service providers, including fourth-party dependencies. A provider is material if you rely on it for a critical operation or the arrangement exposes you to material operational risk. AI vendors increasingly qualify.

5. Bring contracts into line

Every material arrangement must meet CPS 230 requirements. There is no legacy category remaining.

6. Demonstrate continuity capability

Tested business continuity arrangements for critical operations, not documented intentions. ISO 22301 is a recognised way of evidencing this.

How Soveriq helps

For regulated entities, Soveriq works on the parts that are usually weakest: the honesty of the critical operations register, whether tolerances are set at a level anyone has tested, and whether the MSP register reflects who you actually depend on today rather than who mattered three years ago.

For service providers — the larger group, and the one where most of our work sits — we build the evidence a regulated client needs from you. That is usually a combination of ISO 27001 for security and ISO 22301 for tested continuity, which together answer most of what a CPS 230 assurance request asks.

On internal review. Where Soveriq has built your continuity or operational risk capability, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not speak for APRA and does not promise a supervisory outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the standard as amended, including MSP register completeness and contract status.
  • Module 02 — Build. Critical operations register, tolerance levels, process mapping, MSP register and continuity capability.
  • Module 03 — Internal review ahead of board reporting or APRA engagement, subject to the impartiality position above.
  • Module 04 — Representation where APRA or a regulated client engages directly.
  • Module 05 — Continuous compliance, including tolerance testing and register maintenance.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

For service providers, the most common engagement is proving your own resilience to a regulated client — frequently satisfied by ISO 22301 and ISO 27001 together.

Common questions

Did CPS 230 commence on 1 July 2026?

No, and this is the most common misreading. The standard commenced on 1 July 2025. What happened on 1 July 2026 is that the last transitional relief expired and the April 2026 amendments commenced. The substantive obligations have applied since 2025.

We are a supplier, not an APRA-regulated entity. Does it affect us?

Indirectly but materially. If a regulated entity relies on you for a critical operation, or your arrangement exposes it to material operational risk, you are a material service provider. Your contract must meet CPS 230 terms and you will be asked to evidence your own resilience.

Does an AI vendor go on the MSP register?

If the institution relies on that provider for a critical operation, or the arrangement creates material operational risk, yes. AI vendors increasingly sit inside critical operations, and the register has to reflect reality rather than a historic view of who the important suppliers are.

Does CPS 230 require ISO 22301?

No. APRA does not mandate any particular standard. ISO 22301 is a well-recognised way to evidence tested continuity arrangements, which is what the standard asks for, but the obligation is APRA's and the standard is a means rather than a requirement.

What belongs in the material service provider register?

An APRA-regulated entity records providers it relies on for a critical operation or whose arrangements expose it to material operational risk. The register identifies material providers and the critical operations or material operational risks for which they are used. It is maintained and submitted to APRA annually. The entity owns the register; a supplier provides the service and dependency evidence it needs.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope