Skip to the main content.

9 min read

Understand the relationship between APRA CPS 230 and CPS 234

Understand the relationship between APRA CPS 230 and CPS 234
Understand the relationship between APRA CPS 230 and CPS 234
28:18

APRA CPS 230 and CPS 234. What's the difference?

The Australian Prudential Regulation Authority (APRA) is instrumental in maintaining the financial stability and security of institutions across Australia. Two pivotal prudential standards, CPS 230 and CPS 234, focus on essential elements of operational resilience and information security. Grasping the connection between these standards is crucial for financial entities aiming to stay compliant and boost their operational effectiveness.

Important update: CPS 230 came into effect on 1 July 2025. If your organisation is APRA-regulated, compliance obligations are now active. Non-significant financial institutions (non-SFIs) have an extension on certain requirements until 1 July 2026. Read on for a full breakdown of what has changed, what is still to come, and what Insicon Cyber recommends you do now.

Overview of APRA CPS 230 and CPS 234

APRA CPS 230 focuses on the operational resilience of financial institutions, highlighting the importance of withstanding, responding to, and recovering from disruptive events. This encompasses business continuity, risk management frameworks, and testing resilience strategies across various scenarios. The standard not only prepares organisations for anticipated disruptions but also encourages the development of adaptive strategies for unforeseen circumstances. This proactive approach ensures that financial institutions can maintain critical operations, thereby safeguarding customer trust and the overall stability of the financial system.

On the other hand, CPS 234 focuses on information security management. This standard establishes a comprehensive framework for identifying and mitigating risks associated with information assets, fostering a culture of security, and ensuring that entities maintain robust defences against cyber threats. Emphasising a security-first mindset is essential in today's digital landscape, where cyberattacks are increasingly sophisticated and frequent. Organisations are encouraged to implement continuous monitoring and improvement processes, ensuring that their security measures evolve in tandem with emerging threats.

Both standards stem from APRA's commitment to fostering a resilient financial system.

An institution's ability to operate effectively during disruptions and its capability to protect sensitive information are interlinked.

Furthermore, these standards promote a holistic view of risk management, urging institutions to integrate operational resilience and information security into their overall governance frameworks. By doing so, organisations can create a more cohesive strategy that not only addresses compliance but also enhances their competitive advantage in a rapidly changing environment.

What does CPS 230 replace?

CPS 230 consolidates and replaces five existing prudential standards that many Australian financial institutions will be familiar with: CPS 231 (Outsourcing), CPS 232 (Business Continuity Management), SPS 232 (Business Continuity Management for superannuation), CPG 233 (Operational Risk), and CPG 231 (Outsourcing). This unification is significant. Rather than managing separate frameworks for outsourcing and business continuity, entities now operate under a single, unified operational risk standard. If your organisation has historically managed CPS 231 or CPS 232 compliance in silos, CPS 230 requires you to bring those workstreams together.

Don't forget about 'Colin from Accounts'

In addition to compliance, APRA CPS 230 and CPS 234 encourage financial institutions to engage in regular training and awareness programs for their staff.

The investment in human capital is essential, as employees play a critical role in both operational resilience and information security.

By fostering a culture of awareness and preparedness, organisations can empower their workforce to recognise potential threats and respond effectively, thereby minimising the impact of disruptive events.

Additionally, collaboration with third-party vendors and partners is highlighted, given that many financial institutions depend on external services that may pose vulnerabilities. Building robust relationships and maintaining clear communication channels can greatly improve an institution's overall resilience and security stance.

Key Objectives of APRA CPS 230

The main goal of CPS 230 is to ensure that entities are equipped to manage operational disruptions while sustaining essential services. This entails outlining key resilience measures, such as detailed incident response plans and continuity management systems. By implementing these frameworks, organisations can more effectively address unforeseen challenges, including cyberattacks, natural disasters, or technological failures, which might otherwise cause significant service interruptions.

APRA CPS 230 operational resilience framework

Additionally, CPS 230 encourages institutions to regularly assess their operational risks and review their resilience strategies. This ongoing evaluation aids in the proactive identification of vulnerabilities that could jeopardise essential operations during crises. Institutions are urged to adopt a culture of continuous improvement, where lessons learned from past incidents inform future preparedness efforts.

Ultimately, the intent is to safeguard not only the institution but also the stakeholders who depend on its services, thus contributing to a stable financial sector. By prioritising resilience, organisations can instil confidence among clients and investors, reassuring them that their interests are protected even in the face of adversity.

Moreover, the implementation of CPS 230 requires entities to invest in training and awareness programs for their employees.

By equipping staff with the knowledge and skills necessary to respond effectively to operational disruptions, organisations can ensure a swift and coordinated response.

This human element is crucial, as the effectiveness of incident response plans often hinges on the preparedness and agility of the personnel involved. Regular drills and simulations can help reinforce these skills, creating a workforce that is not only aware of potential risks but also adept at executing the strategies laid out in their continuity management systems.

The Material Service Provider Register

One of the most operationally significant obligations introduced by CPS 230 is the requirement for APRA-regulated entities to maintain and submit a Material Service Provider (MSP) register. A material service provider is any provider your organisation relies upon to deliver a critical operation, or whose arrangement exposes you to material operational risk.

APRA released its MSP register template in October 2024, and the first completed registers were required to be submitted to APRA by 1 October 2025. This register must be submitted annually going forward. In June 2025, APRA also released electronic notification forms for entities to use when reporting material events and tolerance breaches under CPS 230.

From a supervisory standpoint, APRA has made clear that it will use MSP register data actively. Entities that appear to be outliers in terms of their service provider arrangements can expect heightened scrutiny. If your organisation has not yet submitted its first register, or is unsure whether your register accurately reflects your critical operations, Insicon Cyber's Managed Compliance Services can help you get across the line.

Source: APRA Operational Risk Management page

Non-Traditional Service Providers: A Live Amendment

In December 2025, APRA released a consultation letter proposing targeted amendments to CPS 230 to address a practical challenge that many Australian banks, superannuation funds, and insurers have raised since the standard went live. The issue relates to non-traditional service providers (NTSPs), which are market-mandated providers such as stock exchanges, payment schemes, and clearing and settlement facilities.

Because these providers typically do not offer negotiable contracts, applying CPS 230's contractual and service level obligations to them has been difficult in practice. The consultation closed on 30 January 2026, and APRA has committed to finalising the amendments before the 1 July 2026 compliance deadline for service provider contracts.

Source: APRA Targeted Amendments to CPS 230

Where do you actually stand?

Australian and New Zealand regulators are now asking for evidence, not assurances.

APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.

Key Objectives of APRA CPS 234

CPS 234 aims to protect the integrity and confidentiality of information through robust security measures. Its objectives include establishing a comprehensive information security framework that encompasses policy development, risk assessment, and proactive threat management.

APRA CPS 234 information security framework

The standard requires financial institutions to identify information security incidents promptly and to implement effective responses without delay. Regular training and awareness programs are also mandated to cultivate a culture of security within the organisation.

In essence, CPS 234 seeks to ensure that all financial entities can respond to cyber security threats and vulnerabilities, thus protecting consumer and institutional data alike.

APRA's 2025 Action Letter to Superannuation Trustees

In June 2025, APRA issued a notably direct letter to the board chairs of all registrable superannuation entity (RSE) licensees, reminding them of their binding obligations under CPS 234. The trigger was a pattern of credential stuffing incidents across the superannuation sector, which exposed persistent weaknesses in authentication controls.

APRA's message was unambiguous: there is a gap between what the standard requires and what many trustees currently have in place, and APRA has run out of patience waiting for voluntary uplift. All RSE licensees were required to complete the following actions by 31 August 2025:

  • Perform a self-assessment of existing information security controls against CPS 234 requirements.
  • Notify APRA of any weaknesses identified in material controls.
  • Conduct a breach assessment if the entity was directly affected by a credential stuffing incident.
  • Advise APRA of the Accountable Person(s) under the Financial Accountability Regime (FAR) responsible for CPS 234 compliance.

This last point is significant. APRA's explicit connection of CPS 234 compliance to FAR accountability means that information security is no longer solely a technical or operational matter. It is a named executive accountability.

Source: APRA: For Action, Information Security Obligations and Critical Authentication Controls

Comparative Analysis of CPS 230 and CPS 234

When comparing CPS 230 and CPS 234, a few distinct differences and similarities emerge. Both standards share a foundation in risk management and resilience, yet they target slightly different arenas. CPS 230 focuses on overall operational resilience, whereas CPS 234 zeroes in on information security.

Despite the differences, there is a notable intersection: effective information security contributes to operational resilience and vice versa. For instance, an institution that has robust information security measures in place may be better equipped to maintain its operations during a cyber incident.

Therefore, while targeting different aspects, both CPS 230 and CPS 234 are integral to a bank's risk management framework, emphasising a holistic approach to resilience and security.

It is also worth noting that APRA has clarified that an information security incident reported under CPS 234 does not need to be separately reported under CPS 230. The two notification obligations do not overlap, which simplifies incident reporting for regulated entities managing both standards simultaneously.

CPS 230 Compliance: Who Must Do What and When

One of the most common questions Insicon Cyber receives from Australian and New Zealand-based financial institutions relates to which obligations apply to them and by when. The following summarises the current compliance timeline.

Date Obligation Who it applies to
1 July 2025 CPS 230 comes into full effect (all core requirements) All APRA-regulated entities
1 October 2025 First Material Service Provider register due to APRA ADIs, superannuation trustees, insurers
1 July 2026 Business continuity and scenario analysis requirements commence; service provider contract uplift deadline; non-SFI full compliance deadline; finalisation of NTSP amendments Non-SFIs; all entities with existing MSP contracts
2027 to 2028 Business-as-usual ongoing supervision; possible consultation on a formal CPS 230 reporting standard All APRA-regulated entities

Source: APRA Response to Submissions: CPG 230 Operational Risk Management

Best Practices for Aligning with Both Standards

To effectively align with both CPS 230 and CPS 234, financial institutions across Australia and New Zealand should adopt a few best practices:

  1. Conduct comprehensive risk assessments to identify vulnerabilities across both operational and information security domains.
  2. Develop a cohesive risk management framework that integrates both operational resilience and information security, treating them as complementary rather than separate programmes.
  3. Identify and document your critical operations, material service providers, and associated tolerance levels.
  4. Submit your Material Service Provider register to APRA and review it annually.
  5. Implement regular training and awareness programs to foster a culture of security. Do not underestimate the role of your people, from the board to Colin from Accounts.
  6. Establish clear incident response protocols that include communication plans for various stakeholders.
  7. Clarify your Financial Accountability Regime (FAR) accountable person(s) for both CPS 230 and CPS 234.
  8. Engage in periodic reviews and updates of resilience strategies and information security policies.

APRA's Regulatory Activity: Letters, Guidance and Enforcement

As the financial landscape evolves, so too does APRA's regulatory posture. The authority has moved from broad consultation to active supervision, and from guidance to enforcement.

APRA's 2024 letters to regulated entities

In a series of letters to all APRA regulated entities in June and August 2024, APRA called out the need for all entities to remain vigilant and proactively implement strategies to mitigate the risk and impact of potential cyber-attacks. The August 2024 letter highlighted common weaknesses across security configuration management, privileged access management, and security testing coverage.

APRA's June 2025 CPS 234 action letter to superannuation trustees

APRA's June 2025 letter to RSE licensees marked a significant shift in tone. Trustees were required to perform specific compliance actions by 31 August 2025. The letter explicitly tied CPS 234 obligations to FAR accountability, making information security a named executive responsibility.

APRA's supervision and enforcement programme: 2025 to 2028

  • 2025 to 2026: Prudential reviews of a small subset of significant financial institutions.
  • 2026 to 2027: APRA broadens supervisory coverage to additional entities.
  • 2027 to 2028: Business-as-usual ongoing supervision across the regulated population.
  • From 2028: Possible consultation on a formal CPS 230 reporting standard.

Source: MinterEllison: APRA's Final Guidance on CPS 230 | Corrs: New Insights for CPS 230 Compliance


Frequently Asked Questions: APRA CPS 230 and CPS 234

Is CPS 230 mandatory?

Yes. CPS 230 is a binding prudential standard that applies to all APRA-regulated entities. It came into effect on 1 July 2025, with non-SFIs receiving an extension on business continuity and scenario analysis requirements until 1 July 2026.

What is the difference between CPS 230 and CPS 234?

CPS 230 covers the broader management of operational risk, including business continuity, critical operations, and third-party service provider management. CPS 234 focuses specifically on information security. APRA has confirmed that an incident notified under CPS 234 does not need to be separately reported under CPS 230.

What is a material service provider under CPS 230?

A material service provider (MSP) is any provider your organisation relies upon to deliver a critical operation, or whose arrangement exposes the entity to material operational risk.

What is the CPS 230 deadline for non-SFIs?

Non-significant financial institutions must comply with all CPS 230 requirements by 1 July 2026. In the interim, non-SFIs must continue to comply with the existing CPS 232 or SPS 232 standards as applicable.

Does CPS 234 apply to superannuation funds?

Yes. CPS 234 applies to all APRA-regulated entities, including RSE licensees. APRA also expects RSE licensees to have nominated their Financial Accountability Regime (FAR) accountable person(s) for CPS 234 compliance.

How does the Financial Accountability Regime (FAR) relate to CPS 230 and CPS 234?

FAR requires APRA-regulated entities to nominate accountable persons for key responsibilities including operational resilience and information security. Boards and senior executives should ensure their FAR accountability maps clearly cover both CPS 230 and CPS 234 obligations.


How can Insicon Cyber help navigate APRA CPS 230 or CPS 234?

Insicon Cyber is your strategic partner for navigating APRA CPS 230 and CPS 234 compliance, offering tailored solutions that encompass comprehensive risk assessments, policy development, and business continuity planning. From board-level advisory to Material Service Provider register development, ongoing compliance monitoring, and CISO-as-a-Service offerings, Insicon Cyber empowers organisations to effectively manage risks and safeguard critical operations.

Partner with Insicon Cyber to transform compliance challenges into opportunities for growth and security.

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand

On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...

Read More
You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

You're Gonna Need a Bigger Boat: What the Black Hat AI Disclosures Mean for Your Business

Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...

Read More
ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

ASD Has Handed Australian and New Zealand Boards Sixteen Questions on Frontier AI. Most Directors Cannot Yet Answer Them.

The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company...

Read More
CPS 230 Compliance: 21 Days to Go and What You Need to Know

1 min read

CPS 230 Compliance: 21 Days to Go and What You Need to Know

With just 21 days until July 1, 2025, the clock is ticking on CPS 230 compliance. If you're an APRA-regulated entity, this deadline isn't negotiable...

Read More
APRA CPS 230: What You Need to Know

1 min read

APRA CPS 230: What You Need to Know

The Australian Prudential Regulation Authority (APRA) has introduced a new prudential standard, CPS 230, focusing on operational risk management....

Read More
Six best practises for cybersecurity governance in 2026

1 min read

Six best practises for cybersecurity governance in 2026

Best Practices for Cybersecurity Governance in 2026 Now more than ever, cybersecurity governance is crucial for protecting sensitive data and...

Read More