ASD, 2024-25
6 min
how often a cybercrime is reported in Australia, on average
APRA's operational risk standard, in plain English.
What CPS 230 asks of regulated entities, the three pillars, who it applies to, and what it means now the standard is in force.
CPS 230 is APRA's Prudential Standard for Operational Risk Management. It requires regulated entities to manage operational risk, be able to keep critical operations running through disruption within set tolerances, and manage the risks from the third parties those operations depend on. It came into force on 1 July 2025, replacing the older outsourcing and business continuity standards (CPS 231, CPS 232 and their equivalents).
Looking for the standard itself? Read CPS 230 on APRA's website. This page explains what it means and how to meet it.
Disruption is a matter of when, not if. Cyber incidents, supplier failures, system outages and extreme weather all interrupt the services entities provide, and Australia's financial system is more interconnected and more dependent on third parties than ever. Operational resilience is the discipline of knowing which operations are critical, how much disruption you can absorb, and being able to keep going when something breaks.
APRA introduced CPS 230 so regulated entities manage this deliberately, to reduce the impact of disruptions on customers and the financial system.
ASD, 2024-25
6 min
how often a cybercrime is reported in Australia, on average
ASD, 2024-25
$81k
average cost of cybercrime to a business, up 50% on the year
ASD, 2024-25
1,200
serious cyber incidents ASD responded to in 2024-25, up 11%
Cyber and third-party risk are rising across Australia's financial system, which is exactly what CPS 230 sets out to manage.
CPS 230 applies across APRA-regulated industries:
Its aim is to improve operational risk management through stronger Board and senior-management focus, and to minimise the impact of disruptions on customers and the financial system.
CPS 230 brings operational resilience together under three pillars:
Identify your critical operations and the processes, people, technology, data and third parties they depend on. For each, set Board-approved impact tolerances: the maximum time you would tolerate a disruption, the maximum data loss, and the minimum service levels you would maintain on alternative arrangements. Then scenario-test against severe but plausible disruption, and report operational risk and incidents to the Board.
With RunReady:
Drova RunReady
Map critical operations, set tolerances, test scenarios and manage service providers in one workspace.
Maintain a business continuity plan that sets out how you identify, manage and respond to disruption within your tolerances. It must include disaster-recovery planning for critical information assets, be regularly tested against severe but plausible scenarios, and be backed by the people, resources and technology needed to execute it. The Board oversees the BCP as part of overall risk management.
With RunReady:
Maintain a register of your material service providers and manage the risks from them: monitor arrangements, assess performance, and keep compliance with the service agreement. The register of material service providers is submitted to APRA annually, and APRA must be notified within 20 business days of entering into or materially changing an agreement for a service on which a critical operation relies.
With RunReady:
See the detail: CPS 230 material service provider requirements.
The full CPS 230 operating guide
All three pillars, in a format you can share with your board or risk committee.
In force since 1 July 2025. CPS 230 replaced the older outsourcing and business continuity standards and now applies across APRA-regulated industries.
Service providers, from 1 July 2026. APRA gave a further year for pre-existing material service provider contracts. That transitional period has now ended, so the service-provider requirements apply in full.
Now. Operational resilience is business as usual. APRA is engaging with entities on their new obligations and running targeted reviews, starting with the largest institutions. Entities are expected to keep their critical-operations register, tolerances, testing and service-provider register current.
CPS 230 is a strong foundation, but operational resilience is wider than any single standard. It spans cyber threats, third and fourth-party resilience, and climate resilience, and it connects to how an entity manages risk, controls, events, contracts and regulatory change.
RunReady is the operational resilience module of Drova's RunGood platform, so the critical operations, tolerances, testing and service-provider records you build for CPS 230 sit alongside the rest of your risk and compliance work rather than in a silo.
CPS 230 came into force on 1 July 2025. A further one-year transition for pre-existing material service provider contracts ended on 1 July 2026, so the standard now applies in full.
APRA-regulated entities: authorised deposit-taking institutions (banks, building societies, credit unions), general, life and private health insurers, and superannuation (RSE) licensees.
Operational risk management, business continuity planning, and service provider management.
An operation that, if disrupted, would have a material adverse effect on the entity's members, policyholders, depositors or other customers, or on financial system stability. CPS 230 requires you to identify these and set impact tolerances for each.
Board-approved limits for each critical operation: the maximum time you would tolerate a disruption, the maximum data loss you would accept, and the minimum service levels you would maintain on alternative arrangements.
Within 20 business days of entering into, or materially changing, an agreement for a service on which a critical operation relies. The register of material service providers is also submitted to APRA annually.
Both are operational resilience regimes built on critical or important services and tolerances. CPS 230 is the Australian APRA regime; PS21/3 is the UK FCA regime.
RunReady keeps your critical operations, tolerances, testing and service-provider register in one place.