What does CPS 230 actually require?

CPS 230 requires APRA-regulated entities to identify critical operations, set tolerance levels for disruption, and maintain a business continuity plan tested at least annually.

The standard replaces CPS 231 (Outsourcing) and folds operational risk, business continuity, and third-party management into a single framework. APRA expects entities to demonstrate, not merely assert, that critical operations can continue within tolerance during a disruption.

Boards are explicitly accountable for approving tolerance levels, which moves operational risk from a technical concern to a governance one.

Who is affected by CPS 230?

All APRA-regulated entities, including banks, insurers, and superannuation trustees, are in scope, with no exemption for smaller entities.

Superannuation trustees face a particular challenge because so much of their critical operations, including administration and unit pricing, are outsourced to third parties who are not directly regulated by APRA.

Action

What to do this quarter

  1. Map your critical operationsIdentify which operations, if disrupted, would cause intolerable harm to members or customers, and document the tolerance level the board has approved for each.
  2. Audit material service provider agreementsCheck that contracts with material service providers include the audit, subcontracting, and exit provisions CPS 230 requires. Many existing agreements do not.
  3. Test your continuity planRun at least one scenario test against a critical operation this quarter and record the outcome for the board.
Martin Barnier
Principal and Consulting Director · Lumaris Consulting

Martin Barnier is Principal and Consulting Director at Lumaris, an Australian-owned, vendor-neutral advisory firm. He advises regulated enterprises on operational risk, AI governance, and critical infrastructure resilience.

View LinkedIn profile