HomeBlogFinancial Services
Financial Services

APRA CPS 230 vs CPS 234: which one you need, and how they fit together

Sep 2026 · 8 min read

Isometric illustration of a padlocked server rack with a monitoring screen on one tile and a bank building with a stopwatch and linked supplier nodes on another, joined to a central shield hub

Two prudential standards, one regulator, and a question we hear from almost every APRA-regulated client: do we need CPS 230 or CPS 234? They are separate legislative instruments with separate subject matter — CPS 234 is information security, CPS 230 is operational resilience — and every APRA-regulated entity is bound by both. This article sets out what each one requires, from the instruments rather than the commentary, and then the places where they meet.

What CPS 234 requires

Prudential Standard CPS 234 Information Security has been in force since 1 July 2019 and has never been amended. It makes the Board ultimately responsible for information security and sets 24 obligations, in paragraphs 13 to 36, across nine headings: roles and responsibilities, information security capability, the policy framework, classification of information assets, implementation of controls, incident management, testing of control effectiveness, internal audit and notification to APRA.

Five of those paragraphs reach into third parties. An entity must assess the information security capability of any related or third party that manages its information assets, evaluate the design of that party's controls, judge whether it can rely on that party's testing, and have internal audit assess the party's assurance before relying on it. None of that is limited to formal outsourcing arrangements.

Two clocks apply. An information security incident that materially affects the entity or its customers — or that has been notified to any other regulator, in Australia or elsewhere — must be notified to APRA within 72 hours. A material control weakness the entity does not expect to remediate in a timely manner must be notified within 10 business days. Neither the standard nor its practice guide defines 'material', which is why APRA's independent reviews in 2023 found so many entities without written criteria.

What CPS 230 requires

Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025, replacing the outsourcing and business continuity standards, and was revoked and re-made with effect from 1 July 2026 to add an exemption for arrangements with non-traditional service providers such as central banks, exchanges, clearing and settlement facilities and payment schemes. The same date closed the transition for pre-existing contracts and for smaller entities' business continuity requirements, so since July 2026 every obligation applies to every APRA-regulated entity.

It has three pillars. Operational risk management: a comprehensive risk profile, controls that are tested, incidents and near misses recorded, and a 72-hour notification to APRA of a material operational risk incident. Business continuity: a register of critical operations — payments, deposits, custody and settlements for banks; claims for insurers; investment management and fund administration for superannuation trustees; customer enquiries and supporting systems for everyone — with Board-approved tolerance levels for the maximum disruption, maximum data loss and minimum service level, a business continuity plan tested annually against severe but plausible scenarios, and a 24-hour notification when a critical operation is disrupted beyond tolerance. Service providers: a policy, a register of material service providers submitted to APRA every year, a mandatory clause set for every material agreement, monitoring, exit planning, and notification within 20 business days of signing or changing an agreement that supports a critical operation, or before offshoring.

Where they meet

CPS 230 paragraph 24 requires an entity to meet CPS 234 as part of managing its technology risk, so a CPS 234 gap is automatically a CPS 230 gap. Footnote 11 of CPS 230 says an information security incident notified under CPS 234 does not have to be notified again under CPS 230 — but an incident that also takes a critical operation outside tolerance still starts the 24-hour clock. And the suppliers are the same: the third parties whose information security CPS 234 asks the entity to assess are, for the most part, the material service providers CPS 230 asks it to register, contract and monitor.

The differences are just as important. CPS 234 sits with the CISO and is assessed on control effectiveness; CPS 230 sits with the chief operating officer, operational risk and procurement and is assessed on whether critical operations can be kept within tolerance. CPS 234 applies identically to every entity class; CPS 230's deemed lists differ by whether you are a bank, an insurer or a superannuation trustee. A single combined score would hide the state most entities are in — strong on a standard that has been in force for seven years, still working on one that has been in force for one.

What an assessment should look like

Two catalogues, one profile. Assess CPS 234 paragraph by paragraph, with the entity's own materiality criteria, the third-party register and the testing programme as evidence. Assess CPS 230 by pillar, with the critical operations register and tolerance schedule, the Board approvals, the BCP test reports, the material service provider register in APRA's template and the contract clause checklist as evidence. Track the five APRA clocks — 72 hours twice, 24 hours, 10 business days, 20 business days — as indicators rather than as lines in a policy, and let one supplier record feed both standards.

GRCLens carries CPS 234 and CPS 230 as separate catalogues under its Australia folder, transcribed from the legislative instruments with the 2026 paragraph numbering, sharing one sector profile and one evidence base, with the notification duties, the register and the tolerance levels as key risk indicators on the Board dashboard.

Primary sources

Prudential Standard CPS 234 Information Security, F2018L01745, commenced 1 July 2019. Prudential Standard CPS 230 Operational Risk Management, F2026L00475, in force 1 July 2026 (first commenced 1 July 2025 as F2023L01242). CPG 234 Information Security, June 2019. CPG 230 Operational Risk Management, June 2024, updated April 2026. APRA, Cyber security stocktake exposes gaps, 5 July 2023. APRA, APRA finalises targeted amendments to CPS 230, 30 April 2026.

This article is general information, not legal advice. Confirm current requirements with APRA before relying on them.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles