CPS 230 Compliance Guide 2025-2026: Everything Your ADI Needs to Know

Updated March 2026 | 10 min read | By GoComply

APRA Prudential Standard CPS 230 (Operational Risk Management) is the most significant prudential standard change in a decade. It consolidates three previous standards — CPS 231 (Outsourcing), CPS 232 (Business Continuity Management), and the operational risk elements of CPS 220 — into a single, integrated operational resilience framework.

Effective date: 1 July 2025 for SFIs (Significant Financial Institutions). Non-SFIs have until 1 July 2026 for BCP requirements.

Need a quick answer about CPS 230? Ask our AI compliance chatbot — it covers every paragraph of CPS 230 with clause references.

What CPS 230 Replaced and Why

CPS 230 replaced three separate standards that APRA recognised were treating interconnected risks in silos:

The key insight driving CPS 230 is that a service provider failure IS a business continuity event IS an operational risk incident. APRA wants entities to manage these as a connected system, not separate compliance exercises.

Key Requirements

1. Critical Operations and Tolerance Levels

This is the biggest change from CPS 232. Entities must:

2. Business Continuity Planning

BCPs must include:

3. Service Provider Management

CPS 230 replaces the old CPS 231 concept of "material outsourcing" with "material service provider" — a broader definition that includes intra-group arrangements. Requirements include:

4. APRA Notification Requirements

Transition Timeline

Enforcement Context

APRA has already demonstrated willingness to use capital charges as enforcement tools for operational resilience failures:

Expect similar enforcement under CPS 230 for entities that cannot demonstrate adequate operational resilience.

Practical Steps for Compliance

  1. Gap analysis — Map your current CPS 231/232 compliance against CPS 230 requirements
  2. Critical operations register — Define and document all critical operations with tolerance levels
  3. Service provider inventory — Reclassify material outsourcing arrangements as material service provider arrangements under the new definitions
  4. BCP update — Ensure BCPs include tolerance levels, scenario testing plans, and APRA notification procedures
  5. Board engagement — Brief the board on CPS 230 requirements and their oversight responsibilities
  6. Testing program — Design annual testing using severe but plausible scenarios covering service provider disruptions

Get instant CPS 230 answers

Ask any question about CPS 230 and get structured answers with clause references in seconds.

Try the AI chatbot free

Related Regulations

CPS 230 intersects with several other standards your compliance team needs to consider:

This guide is for informational purposes and does not constitute legal advice. Consult qualified compliance professionals for specific obligations. GoComply covers 37 Australian financial regulations — try the chatbot for instant clause-level answers.