What Is APRA CPS 230? What to Know About this Australia’s Operational Resilience Standard

Published On: August 18th, 2025Categories: Business Resilience, Governance, Risk & Compliance: GRC1.5 min read

APRA CPS 230 is a regulatory standard introduced by the Australian Prudential Regulation Authority. Its goal is to improve operational resilience in the financial sector. It applies to a wide range of institutions—banks, insurers, super funds, and others that provide essential financial services in Australia.

At the heart of CPS 230? A key focus on protecting critical services. These are the functions that, if disrupted, could significantly impact customers or the financial system. To safeguard them, organizations are expected to strengthen their internal controls, assess and manage operational risks, and prepare thoroughly for potential disruptions.

One of the key areas APRA CPS 230 addresses is third-party oversight. Here, financial institutions must identify and maintain a current register of material service providers, conduct ongoing risk assessments, and put formal agreements in place that outline expectations, responsibilities, and exit strategies. This level of visibility is essential for understanding interdependencies and minimizing the impact of potential failures.

The standard also reinforces the importance of business continuity planning. Organizations need actionable plans to respond to operational disruptions, from cyber incidents to system outages. These plans should be regularly tested and ready to activate at a moment’s notice.

CPS 230 brings a sense of much-needed structure to how organizations manage operational risk. Ultimately, it encourages a more intentional and informed approach across people, systems, and third-party relationships. It also highlights the role of senior leaders and boards in staying accountable and engaged in resilience planning.

Preparing for CPS 230 compliance is an opportunity. One that can create a more stable, adaptive business. By investing in strong risk frameworks and improving visibility into critical operations, organizations can stay resilient and ready in a constantly shifting environment.

Let’s Start a Conversation

Schedule a virtual coffee with a team member: Click here to demo our GRC solutions.

What Is APRA CPS 230

Find out more about SAI360 Solutions

Request Demo