APRA's information security standard for regulated entities, covering asset classification, control testing, third-party assurance and incident notification.
CPS 234 is APRA's prudential standard on information security. It requires APRA-regulated entities to maintain an information security capability commensurate with the size and extent of the threats to their information assets, so those assets remain protected against attacks and other compromises.
Its core obligations are:
The third-party dimension is the part most often underestimated. Where information assets are managed by a service provider, the regulated entity remains accountable for their security — which is why the obligation reaches suppliers through contracts and assurance requests.
Banks and other authorised deposit-taking institutions, general and life insurers, and registrable superannuation entities — for whom CPS 234 is a supervised prudential obligation.
The larger commercial population. The regulated entity remains accountable for the security of information assets managed by third parties, so it must obtain assurance from you.
Where the CPS 234 assurance request is frequently the reason a deal stalls, and where holding recognised certification shortens the conversation considerably.
Most APRA-regulated entities hold both obligations. They overlap on third-party risk but are separate standards.
Clearly define the information security responsibilities of the board, senior management, governing bodies and individuals. The board holds ultimate responsibility and that cannot be delegated away.
Including those managed by third parties, by criticality and sensitivity. This is the foundation for everything after it, and third-party assets are where classification exercises most often stop short.
Sized to the criticality and sensitivity of the assets and to the threat environment, rather than to a uniform baseline.
A programme of testing, with the nature and frequency driven by the rate of change in vulnerabilities and threats, the criticality of assets, and the consequences of an incident. Testing must be more than an annual penetration test.
Internal audit must review the design and operating effectiveness of information security controls, including those maintained by third parties.
Material incidents to APRA within 72 hours; material control weaknesses that cannot be remediated in a timely manner within 10 business days. Both require a decision process that works under pressure.
For regulated entities, Soveriq builds the classification and control testing programme, which is where CPS 234 obligations are most often thin — particularly the systematic testing requirement and the coverage of information assets held by third parties.
For service providers to APRA-regulated entities — where most of our work sits — we build the security position and evidence that answers a regulated client's assurance request. ISO 27001 maps closely onto CPS 234 obligations and is usually the most efficient route.
On internal review. This matters more here than almost anywhere, because CPS 234 explicitly requires internal audit review of control design and operating effectiveness. Where Soveriq has built your control set, we do not then review it and present that as satisfying that requirement. We provide readiness validation, labelled as such, and genuine independent review is performed by someone independent of the build and disclosed to you in writing.
What we will not do. Soveriq does not speak for APRA and does not promise a supervisory outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
CPS 234 is about information security specifically — protecting information assets from compromise. CPS 230 is about operational risk and resilience more broadly, including continuity and service provider management. They overlap on third-party risk but they are separate standards with separate obligations, and holding one does not satisfy the other.
Material information security incidents must be notified to APRA within 72 hours. Material information security control weaknesses that cannot be remediated in a timely manner must be notified within 10 business days. The second is the one entities forget.
No. APRA does not mandate a particular standard. ISO 27001 maps closely onto the obligations — asset classification, control implementation, testing, internal audit — and for a service provider it is usually the most efficient way to answer a regulated client's assurance request.
The obligation to assess your security sits with the regulated entity, but it is discharged by asking you for evidence. In practice that means the requirement reaches you through the contract and through recurring assurance requests, and the entity remains accountable regardless of what you do.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope