Operational ResilienceJanuary 29, 20268 min read

APRA CPS 230 guide: operational risk management for regulated entities

CPS 230 is APRA's prudential standard for operational risk management, business continuity and service-provider management. It applies to banks, insurers and superannuation trustees in Australia from 1 July 2025.

ABy GeneSecure
The short answer

CPS 230 is Prudential Standard CPS 230 Operational Risk Management, issued by the Australian Prudential Regulation Authority (APRA). It applies to APRA-regulated entities — banks (ADIs), general and life insurers, private health insurers and superannuation trustees — and takes effect from 1 July 2025, with provisions relating to existing material service-provider arrangements phased to 1 July 2026. CPS 230 consolidates and strengthens several older standards into one regime built on three pillars. First, entities must manage operational risk end to end: maintain a risk management framework, identify and assess operational risks and controls, and monitor them. Second, they must ensure business continuity by identifying their critical operations, setting tolerance levels for how long and how far a disruption can run before it is unacceptable, and being able to keep those operations within tolerance through severe disruptions. Third, they must manage the risks from service providers — including the fourth parties their providers rely on — with a register of material arrangements and board-approved policies. CPS 230 makes the board accountable and demands evidence, not just documents.

What CPS 230 replaces and why

CPS 230 brings operational risk, business continuity and outsourcing into a single, modernised standard, superseding older APRA standards such as CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management). APRA's view, sharpened by high-profile outages and cyber incidents, is that operational resilience is now a prudential issue in its own right — a severe disruption can threaten an institution as surely as a credit or market shock.

The standard is principles-based but pointed. It expects entities to understand the operations their customers and the financial system depend on, and to be able to keep those running through plausible but severe scenarios — including the failure of a key technology service or supplier.

Critical operations and tolerance levels

A central CPS 230 concept is the 'critical operation' — a process whose disruption would have a material adverse impact on depositors, policyholders, beneficiaries or the financial system. Examples include payments, claims processing, settlements and member transactions. Entities must identify these and map the people, technology, data and providers each one depends on.

For every critical operation, the board must approve a tolerance level: the maximum level of disruption the entity is willing to accept, expressed in terms such as maximum tolerable downtime and acceptable data loss. The entity must then be able to demonstrate — through testing — that it can keep operations within tolerance during a severe disruption. Tolerance levels turn 'we have a continuity plan' into a measurable, board-owned commitment.

Service-provider and fourth-party risk

CPS 230 significantly raises the bar on third-party risk. Entities must maintain a register of their material service-provider arrangements, conduct due diligence, manage the arrangements under board-approved policy, and — importantly — understand concentration risk and the fourth parties (their providers' own critical suppliers) that sit behind a critical operation.

The register and the underlying contracts must support continuity: notification obligations, rights to assess and audit, and the ability to exit or substitute a provider without breaching tolerance. APRA also expects entities to notify it of certain material arrangements and incidents.

Board accountability and evidence

CPS 230 puts the board squarely on the hook. The board is ultimately accountable for operational risk management, must approve the entity's tolerance levels, and must oversee the business continuity plan and material service-provider policy. Senior management must operate the framework day to day and escalate when limits are breached.

Because the standard is outcomes-focused, APRA will look for evidence that controls actually work and that disruptions were genuinely contained within tolerance — not just that policies exist on paper. Scenario testing, incident reviews and clear lines from a control failure to its remediation are the currency of compliance.

Operationalising CPS 230

Meeting CPS 230 means connecting things that often live in silos: the operational risk register, the control library, business-continuity plans, the service-provider inventory and incident records. When a supplier degrades or an internal control fails, the entity needs to see immediately which critical operations are affected and whether any tolerance is at risk.

Entities that run operational risk, resilience and third-party management on one connected platform can answer the questions APRA actually asks — which critical operations depend on this provider, are we inside tolerance, where is the evidence — without assembling it by hand every time. That is the difference between demonstrating resilience and merely asserting it.

FAQ

Common questions, answered.

What evaluation teams want to know before a demo — answered plainly.

CPS 230 applies to all APRA-regulated entities — authorised deposit-taking institutions (banks), general, life and private health insurers, and registrable superannuation entity licensees (super trustees).

CPS 230 takes effect from 1 July 2025, with a transitional arrangement allowing existing material service-provider contracts to come into compliance by 1 July 2026.

A tolerance level is the maximum level of disruption to a critical operation the board is willing to accept — for example a maximum tolerable downtime and acceptable level of data loss. Entities must be able to keep critical operations within these board-approved tolerances through severe disruptions.

Entities must maintain a register of material service-provider arrangements, perform due diligence, manage them under board-approved policy, and understand concentration and fourth-party risk — the critical suppliers their own providers depend on.

See this run on your data.

Book a 30-minute walkthrough and we'll show GeneSecure handling the exact framework you just read about — grounded in your own risk graph.

APRA CPS 230 guide: operational risk management for regulated entities | GeneSecure