What CPS 230 replaces and why
CPS 230 brings operational risk, business continuity and outsourcing into a single, modernised standard, superseding older APRA standards such as CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management). APRA's view, sharpened by high-profile outages and cyber incidents, is that operational resilience is now a prudential issue in its own right — a severe disruption can threaten an institution as surely as a credit or market shock.
The standard is principles-based but pointed. It expects entities to understand the operations their customers and the financial system depend on, and to be able to keep those running through plausible but severe scenarios — including the failure of a key technology service or supplier.
Critical operations and tolerance levels
A central CPS 230 concept is the 'critical operation' — a process whose disruption would have a material adverse impact on depositors, policyholders, beneficiaries or the financial system. Examples include payments, claims processing, settlements and member transactions. Entities must identify these and map the people, technology, data and providers each one depends on.
For every critical operation, the board must approve a tolerance level: the maximum level of disruption the entity is willing to accept, expressed in terms such as maximum tolerable downtime and acceptable data loss. The entity must then be able to demonstrate — through testing — that it can keep operations within tolerance during a severe disruption. Tolerance levels turn 'we have a continuity plan' into a measurable, board-owned commitment.
Service-provider and fourth-party risk
CPS 230 significantly raises the bar on third-party risk. Entities must maintain a register of their material service-provider arrangements, conduct due diligence, manage the arrangements under board-approved policy, and — importantly — understand concentration risk and the fourth parties (their providers' own critical suppliers) that sit behind a critical operation.
The register and the underlying contracts must support continuity: notification obligations, rights to assess and audit, and the ability to exit or substitute a provider without breaching tolerance. APRA also expects entities to notify it of certain material arrangements and incidents.
Board accountability and evidence
CPS 230 puts the board squarely on the hook. The board is ultimately accountable for operational risk management, must approve the entity's tolerance levels, and must oversee the business continuity plan and material service-provider policy. Senior management must operate the framework day to day and escalate when limits are breached.
Because the standard is outcomes-focused, APRA will look for evidence that controls actually work and that disruptions were genuinely contained within tolerance — not just that policies exist on paper. Scenario testing, incident reviews and clear lines from a control failure to its remediation are the currency of compliance.
Operationalising CPS 230
Meeting CPS 230 means connecting things that often live in silos: the operational risk register, the control library, business-continuity plans, the service-provider inventory and incident records. When a supplier degrades or an internal control fails, the entity needs to see immediately which critical operations are affected and whether any tolerance is at risk.
Entities that run operational risk, resilience and third-party management on one connected platform can answer the questions APRA actually asks — which critical operations depend on this provider, are we inside tolerance, where is the evidence — without assembling it by hand every time. That is the difference between demonstrating resilience and merely asserting it.