APRA Prudential Standard CPS 234 Information Security compliance software
APRA's information security standard for every regulated bank, insurer and superannuation trustee — 32 obligations across nine sections, with the 72-hour incident and 10-business-day control-weakness notifications tracked as indicators.
- RegulatorAPRA — Australian Prudential Regulation Authority
- InstrumentF2018L01745, in force 1 July 2019; unamended
- Structure9 sections, paragraphs 13–36; 32 assessable controls
- Notifications72 hours (incidents) · 10 business days (control weaknesses)
What AU APRA CPS 234 requires
Who it applies to
- Authorised deposit-taking institutions, including foreign ADIs and banking NOHCs
- General insurers, life companies and friendly societies, and private health insurers
- RSE licensees (superannuation trustees) across their business operations
- Heads of groups, on a group basis, including non-APRA-regulated group entities
Prudential Standard CPS 234 Information Security is the legislative instrument (F2018L01745) through which the Australian Prudential Regulation Authority holds its regulated entities to account for information security. In force since 1 July 2019 and never amended, it binds authorised deposit-taking institutions, general insurers, life companies, private health insurers and RSE licensees, and where an entity is the Head of a group it applies across the group including entities APRA does not regulate.
The standard is short and principles-based: 24 numbered obligations in paragraphs 13 to 36 under nine headings — roles and responsibilities, information security capability, policy framework, asset identification and classification, implementation of controls, incident management, testing control effectiveness, internal audit and APRA notification. Five of them expressly reach information assets managed by related and third parties, whatever the outsourcing arrangement. GRCLens carries 32 assessable controls, splitting the lettered items APRA itself separated, with guidance drawn from CPG 234 and the weaknesses APRA published from its tripartite independent reviews in 2023.
Two clocks matter most. An incident that materially affects the entity or its customers, or that has been notified to any other regulator, must be notified to APRA within 72 hours; a material control weakness the entity cannot remediate in a timely manner within 10 business days. Neither the standard nor CPG 234 defines 'material', so the entity's own criteria are part of the evidence.
How GRCLens supports AU APRA CPS 234
AU APRA CPS 234 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Paragraph-level assessment
Every obligation in paragraphs 13–36 is a control with APRA's wording, CPG 234 guidance and the evidence APRA's reviews expect — not a mapped ISO 27001 subset.
Notification clocks as indicators
The 72-hour and 10-business-day duties, the third-party assurance paragraphs and the testing programme are watched as key risk indicators with thresholds, so a gap is a number on the Board's dashboard.
Third parties in scope
Paragraphs 16, 22, 28 and 34 are assessed against every related and third party holding information assets, with the supplier register feeding them — the gap APRA found most often.
Beside CPS 230 and ISO 27001
Runs under the same Australia folder as CPS 230, PSPF, IRAP and the Essential Eight, sharing evidence with ISO/IEC 27001 where the controls overlap.
AU APRA CPS 234 frequently asked questions
Has CPS 234 changed since 2019?
No. The instrument has never been amended. What has changed is supervision: APRA's tripartite independent reviews (2021–2024), letters on backups, cyber hygiene and, in April 2026, AI risk — all of which sharpen how the same paragraphs are assessed.
How does CPS 234 relate to CPS 230?
CPS 230 paragraph 24 requires an entity to meet CPS 234 as part of managing technology risk, and an incident notified under CPS 234 does not have to be notified again under CPS 230. They remain separate standards with separate owners; GRCLens carries both and cross-references them.
Does GRCLens define 'material' for the 72-hour notification?
No regulator does, and neither do we. The catalogue asks for the entity's documented materiality criteria and the log of incidents assessed against them, which is what APRA looks for.
One platform, many obligations

Talk to us about AU APRA CPS 234
Security Solution Consultants provides APRA cyber and prudential advisory alongside the platform, so you can combine tooling with hands-on expertise.