Skip to content
Go to homepageDrova logo
Storm over water, symbolising operational disruption

APRA CPS 230: what operational resilience requires

APRA's operational risk standard, in plain English.

What CPS 230 asks of regulated entities, the three pillars, who it applies to, and what it means now the standard is in force.

What is CPS 230?

CPS 230 is APRA's Prudential Standard for Operational Risk Management. It requires regulated entities to manage operational risk, be able to keep critical operations running through disruption within set tolerances, and manage the risks from the third parties those operations depend on. It came into force on 1 July 2025, replacing the older outsourcing and business continuity standards (CPS 231, CPS 232 and their equivalents).

Looking for the standard itself? Read CPS 230 on APRA's website. This page explains what it means and how to meet it.

Why operational resilience matters

Disruption is a matter of when, not if. Cyber incidents, supplier failures, system outages and extreme weather all interrupt the services entities provide, and Australia's financial system is more interconnected and more dependent on third parties than ever. Operational resilience is the discipline of knowing which operations are critical, how much disruption you can absorb, and being able to keep going when something breaks.

APRA introduced CPS 230 so regulated entities manage this deliberately, to reduce the impact of disruptions on customers and the financial system.

Operational resilience under pressure

ASD, 2024-25

6 min

how often a cybercrime is reported in Australia, on average

ASD, 2024-25

$81k

average cost of cybercrime to a business, up 50% on the year

ASD, 2024-25

1,200

serious cyber incidents ASD responded to in 2024-25, up 11%

Cyber and third-party risk are rising across Australia's financial system, which is exactly what CPS 230 sets out to manage.

Who does CPS 230 apply to?

CPS 230 applies across APRA-regulated industries:

  • Authorised deposit-taking institutions (banks, building societies and credit unions)
  • General insurers, life insurers and private health insurers
  • Superannuation (RSE) licensees

Its aim is to improve operational risk management through stronger Board and senior-management focus, and to minimise the impact of disruptions on customers and the financial system.

The three pillars of CPS 230

CPS 230 brings operational resilience together under three pillars:

  1. Operational risk management — identify critical operations, set tolerances, test, and report.
  2. Business continuity planning — keep critical operations running through disruption.
  3. Service provider management — manage the risks from material service providers.

Pillar 1: Operational risk management

Identify your critical operations and the processes, people, technology, data and third parties they depend on. For each, set Board-approved impact tolerances: the maximum time you would tolerate a disruption, the maximum data loss, and the minimum service levels you would maintain on alternative arrangements. Then scenario-test against severe but plausible disruption, and report operational risk and incidents to the Board.

With RunReady:

  • Build a central register of critical operations, with owners, priority and criticality
  • Set tolerance levels and measure impact over time with an impact-over-time view
  • Run guided scenario tests and see the results against your tolerances
  • Keep an audit trail of tests, results and remediation
Simple feature background

See where you stand against CPS 230

Drova RunReady

Map critical operations, set tolerances, test scenarios and manage service providers in one workspace.

Pillar 2: Business continuity planning

Maintain a business continuity plan that sets out how you identify, manage and respond to disruption within your tolerances. It must include disaster-recovery planning for critical information assets, be regularly tested against severe but plausible scenarios, and be backed by the people, resources and technology needed to execute it. The Board oversees the BCP as part of overall risk management.

With RunReady:

  • Map critical processes and contingencies for integrated BCP testing
  • Identify the people, information, assets and suppliers each plan depends on
  • Run a systematic, risk-based testing programme with clear roles and responsibilities

Pillar 3: Service provider management

Maintain a register of your material service providers and manage the risks from them: monitor arrangements, assess performance, and keep compliance with the service agreement. The register of material service providers is submitted to APRA annually, and APRA must be notified within 20 business days of entering into or materially changing an agreement for a service on which a critical operation relies.

With RunReady:

  • Track the third parties, assets and facilities behind your critical operations
  • Maintain the material service provider register and manage contracts in one place
  • Run attestations and due diligence, and link providers to your risk and compliance records
  • Test service-provider-managed resources through integrated scenario testing

See the detail: CPS 230 material service provider requirements.

Take the guide with you

The full CPS 230 operating guide

All three pillars, in a format you can share with your board or risk committee.

Simple feature visual

CPS 230: where entities are now

In force since 1 July 2025. CPS 230 replaced the older outsourcing and business continuity standards and now applies across APRA-regulated industries.

Service providers, from 1 July 2026. APRA gave a further year for pre-existing material service provider contracts. That transitional period has now ended, so the service-provider requirements apply in full.

Now. Operational resilience is business as usual. APRA is engaging with entities on their new obligations and running targeted reviews, starting with the largest institutions. Entities are expected to keep their critical-operations register, tolerances, testing and service-provider register current.

Operational resilience goes beyond CPS 230

CPS 230 is a strong foundation, but operational resilience is wider than any single standard. It spans cyber threats, third and fourth-party resilience, and climate resilience, and it connects to how an entity manages risk, controls, events, contracts and regulatory change.

RunReady is the operational resilience module of Drova's RunGood platform, so the critical operations, tolerances, testing and service-provider records you build for CPS 230 sit alongside the rest of your risk and compliance work rather than in a silo.

CPS 230, answered

When did CPS 230 come into effect?

CPS 230 came into force on 1 July 2025. A further one-year transition for pre-existing material service provider contracts ended on 1 July 2026, so the standard now applies in full.

Who does CPS 230 apply to?

APRA-regulated entities: authorised deposit-taking institutions (banks, building societies, credit unions), general, life and private health insurers, and superannuation (RSE) licensees.

What are the three pillars of CPS 230?

Operational risk management, business continuity planning, and service provider management.

What is a critical operation?

An operation that, if disrupted, would have a material adverse effect on the entity's members, policyholders, depositors or other customers, or on financial system stability. CPS 230 requires you to identify these and set impact tolerances for each.

What is an impact tolerance under CPS 230?

Board-approved limits for each critical operation: the maximum time you would tolerate a disruption, the maximum data loss you would accept, and the minimum service levels you would maintain on alternative arrangements.

When must APRA be notified about a service provider?

Within 20 business days of entering into, or materially changing, an agreement for a service on which a critical operation relies. The register of material service providers is also submitted to APRA annually.

How is CPS 230 different from the FCA's PS21/3?

Both are operational resilience regimes built on critical or important services and tolerances. CPS 230 is the Australian APRA regime; PS21/3 is the UK FCA regime.

RunReady keeps your critical operations, tolerances, testing and service-provider register in one place.

Prove CPS 230 without rebuilding it in spreadsheets