APRA CPS 234 — Information Security

APRA's information security standard for regulated entities, covering asset classification, control testing, third-party assurance and incident notification.

Australian Prudential Regulation Authority (APRA).

What it is

CPS 234 is APRA's prudential standard on information security. It requires APRA-regulated entities to maintain an information security capability commensurate with the size and extent of the threats to their information assets, so those assets remain protected against attacks and other compromises.

Its core obligations are:

  • Clear roles and responsibilities for information security across the board, senior management, governing bodies and individuals, with the board ultimately responsible.
  • Classification of information assets by criticality and sensitivity — including assets managed by third parties.
  • Controls proportionate to that criticality and sensitivity and to the threat environment.
  • Systematic testing of control effectiveness, with the nature and frequency driven by the rate of change in vulnerabilities and threats, the criticality of assets, and the consequences of an incident.
  • Internal audit review of the design and operating effectiveness of information security controls, including those maintained by third parties.
  • Notification to APRA — material information security incidents within 72 hours, and material control weaknesses that cannot be remediated in a timely manner within 10 business days.

The third-party dimension is the part most often underestimated. Where information assets are managed by a service provider, the regulated entity remains accountable for their security — which is why the obligation reaches suppliers through contracts and assurance requests.

Who it's for

APRA-regulated entities

Banks and other authorised deposit-taking institutions, general and life insurers, and registrable superannuation entities — for whom CPS 234 is a supervised prudential obligation.

Service providers holding or managing regulated entities' information assets

The larger commercial population. The regulated entity remains accountable for the security of information assets managed by third parties, so it must obtain assurance from you.

Technology and SaaS vendors selling into financial services

Where the CPS 234 assurance request is frequently the reason a deal stalls, and where holding recognised certification shortens the conversation considerably.

Entities also subject to CPS 230

Most APRA-regulated entities hold both obligations. They overlap on third-party risk but are separate standards.

Why implement it

  • For regulated entities it is a supervised prudential obligation, with board-level accountability that cannot be delegated.
  • For suppliers it decides deals. The CPS 234 assurance request is one of the most common reasons a financial services sale stalls, and a prepared answer is a commercial advantage.
  • Systematic testing is the differentiator. The standard asks for a testing programme driven by threat and criticality, which is a materially higher bar than an annual penetration test, and it is where many entities are thinnest.
  • Third-party coverage is explicit. Information assets managed by others are in scope, so an assessment that stops at the perimeter does not meet the obligation.
  • ISO 27001 does most of it. Asset classification, proportionate controls, testing and internal audit all map closely, which is why ISO 27001 is the usual route for suppliers answering these requests.

How implementation works

1. Establish roles and accountability

Clearly define the information security responsibilities of the board, senior management, governing bodies and individuals. The board holds ultimate responsibility and that cannot be delegated away.

2. Classify information assets

Including those managed by third parties, by criticality and sensitivity. This is the foundation for everything after it, and third-party assets are where classification exercises most often stop short.

3. Implement proportionate controls

Sized to the criticality and sensitivity of the assets and to the threat environment, rather than to a uniform baseline.

4. Test control effectiveness systematically

A programme of testing, with the nature and frequency driven by the rate of change in vulnerabilities and threats, the criticality of assets, and the consequences of an incident. Testing must be more than an annual penetration test.

5. Have internal audit review

Internal audit must review the design and operating effectiveness of information security controls, including those maintained by third parties.

6. Maintain notification readiness

Material incidents to APRA within 72 hours; material control weaknesses that cannot be remediated in a timely manner within 10 business days. Both require a decision process that works under pressure.

How Soveriq helps

For regulated entities, Soveriq builds the classification and control testing programme, which is where CPS 234 obligations are most often thin — particularly the systematic testing requirement and the coverage of information assets held by third parties.

For service providers to APRA-regulated entities — where most of our work sits — we build the security position and evidence that answers a regulated client's assurance request. ISO 27001 maps closely onto CPS 234 obligations and is usually the most efficient route.

On internal review. This matters more here than almost anywhere, because CPS 234 explicitly requires internal audit review of control design and operating effectiveness. Where Soveriq has built your control set, we do not then review it and present that as satisfying that requirement. We provide readiness validation, labelled as such, and genuine independent review is performed by someone independent of the build and disclosed to you in writing.

What we will not do. Soveriq does not speak for APRA and does not promise a supervisory outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the standard, including asset classification and control testing coverage.
  • Module 02 — Build. Information security policy framework, asset classification, control implementation and the systematic testing programme.
  • Module 03 — Internal review, subject to the impartiality position above and to the standard's own requirement for internal audit review.
  • Module 04 — Representation where APRA or a regulated client engages directly.
  • Module 05 — Continuous compliance, including the testing cycle and notification readiness.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

How does CPS 234 differ from CPS 230?

CPS 234 is about information security specifically — protecting information assets from compromise. CPS 230 is about operational risk and resilience more broadly, including continuity and service provider management. They overlap on third-party risk but they are separate standards with separate obligations, and holding one does not satisfy the other.

What are the notification timeframes?

Material information security incidents must be notified to APRA within 72 hours. Material information security control weaknesses that cannot be remediated in a timely manner must be notified within 10 business days. The second is the one entities forget.

Does CPS 234 require ISO 27001?

No. APRA does not mandate a particular standard. ISO 27001 maps closely onto the obligations — asset classification, control implementation, testing, internal audit — and for a service provider it is usually the most efficient way to answer a regulated client's assurance request.

We are a third party, not regulated. What applies to us?

The obligation to assess your security sits with the regulated entity, but it is discharged by asking you for evidence. In practice that means the requirement reaches you through the contract and through recurring assurance requests, and the entity remains accountable regardless of what you do.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope