Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
FAQ: What APRA CPS 230 Actually RequiresRegulatory Obligations Management
5 min readFor Compliance Officers

FAQ: What APRA CPS 230 Actually Requires

These questions come from compliance teams preparing for APRA CPS 230 implementation. They're the practical questions that arise in planning meetings after you've read the standard multiple times and still need clarity on translating policy language into actionable steps.

Do we really need to replace our spreadsheets, or is that just vendor talk?

You don't need to replace them because a platform vendor said so. You need to replace them because CPS 230 creates dependencies between operational risk data, control testing records, incident timelines, and third-party assessments that spreadsheets can't maintain at scale.

Here's what breaks: your critical operations register lives in one workbook, your material service provider assessments live in another, and your incident log lives in a third. When an incident occurs involving a material service provider supporting a critical operation, you're manually cross-referencing three sources to understand impact tolerance thresholds and control adequacy. That manual process introduces lag and error when you need speed and accuracy.

CPS 230 expects you to demonstrate oversight of how these elements connect. If your control testing shows a deficiency, can you immediately identify which critical operations are affected and which service providers are involved? If not, you're maintaining compliance theater, not operational resilience.

What's the actual difference between a critical operation and a material business activity?

A critical operation under CPS 230 is a process or service whose disruption would have a material impact on your business operations, customers, or financial position. The standard requires you to identify these operations, set impact tolerances for each one, and maintain controls to operate within those tolerances.

Material business activities are a broader category that includes critical operations but also encompasses other significant processes. Think of critical operations as the subset that absolutely cannot fail without causing material harm.

In practice, start by mapping your material business activities, then apply impact analysis to identify which ones meet the threshold for critical operations. Your impact tolerance for a critical operation should specify the maximum tolerable level of disruption before you breach regulatory obligations or cause material customer harm.

How granular do our impact tolerances need to be?

Granular enough to drive operational decisions. A tolerance that says "payment processing must be restored within 24 hours" isn't useful if your actual customer commitment is four-hour settlement windows. Your tolerance should reflect the point at which disruption becomes material, not a comfortable buffer.

For each critical operation, define tolerances for both duration and severity. How long can the operation be fully unavailable? How long can it run in degraded mode? At what service level does degradation become material?

These tolerances then inform your control design, testing frequency, and incident response thresholds. If you can't use your stated tolerance to make a decision during an incident, it's not specific enough.

We already do Resilience Testing Programme and vendor reviews. Isn't that enough?

Resilience Testing Programme proves you can execute a recovery plan. CPS 230 requires you to prove your controls prevent disruption in the first place, detect it when it occurs, and maintain operations within impact tolerance during recovery.

Your vendor reviews might assess financial stability and security posture. CPS 230 requires you to identify which vendors are material service providers, understand their role in supporting critical operations, and maintain oversight proportional to the risk they introduce. That includes knowing their sub-service providers if those relationships could affect your critical operations.

The integration matters. When you test a recovery plan, you're also testing whether your material service providers can meet their obligations during disruption. When you review a vendor, you're evaluating their controls against the impact tolerance of the critical operations they support.

What does "ongoing monitoring" of service providers actually mean?

It means you don't rely on annual assessments to understand current risk. For material service providers, you need mechanisms to detect changes in their risk profile between formal reviews.

Practical approaches include automated monitoring of security ratings, financial health indicators, and publicly disclosed incidents. You should also define triggers that require immediate reassessment: a material breach at the provider, a significant change in their sub-service provider relationships, or a merger that changes their operational model.

The frequency and depth of ongoing monitoring should scale with the provider's materiality. If a provider supports a critical operation with tight impact tolerance, you need near-real-time visibility into their operational status.

How do we prove we're meeting CPS 230 to APRA?

APRA expects evidence that you've implemented the requirements, not just documented policies. That means showing your critical operations inventory, the analysis that determined impact tolerances, control test results, incident response records, and service provider oversight activities.

The evidence needs to demonstrate continuity and integration. Can you show that when a control test failed, you updated the risk assessment, adjusted the treatment plan, and verified the remediation? Can you trace an incident back to the affected critical operation and forward to the lessons learned that improved your controls?

Most organizations struggle here because their evidence lives in disconnected systems. You end up manually compiling reports that show point-in-time snapshots rather than demonstrating continuous oversight.

Where should we start if we're behind?

Start with critical operations identification and impact tolerance definition. You can't prioritize control improvements, vendor oversight, or testing programs until you know which operations are critical and what level of disruption is tolerable.

Run a structured workshop with business unit leaders to identify operations that meet the materiality threshold. For each operation, define impact tolerances based on regulatory obligations, customer commitments, and financial materiality. Document the dependencies: which systems, processes, people, and third parties does each critical operation rely on?

Once you have that foundation, you can map existing controls to critical operations, identify gaps against impact tolerances, and prioritize remediation based on actual risk.

Where can we find more detailed implementation guidance?

APRA's CPS 230 Prudential Standard and accompanying Prudential Practice Guide CPG 230 provide the authoritative requirements and implementation expectations. The practice guide includes examples of how to apply the standard across different operational contexts.

For control frameworks, ISO 22301 (business continuity management) and NIST SP 800-34 (contingency planning) offer structured approaches to resilience that align with CPS 230's objectives. If you're also subject to other operational resilience requirements, look for overlaps with DORA's ICT risk management provisions or the UK's operational resilience framework to avoid duplicating work.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like