APRA CPS 230 — Operational Risk Management

CPS 230, operationalised.

Australia's operational risk management standard for APRA-regulated entities. Critical operations, material service providers, business-continuity testing — all on continuous attestation, not annual scrambles.

The numbers your team already knows.

CPS 230 raised the bar on operational risk for the entire APRA-regulated sector. Material service provider registers, critical-operations mapping, and continuous attestation — measured by APRA, not by your audit calendar.

1 Jul 2025
CPS 230 effective date for APRA-regulated entities
Now in force
MSPs
Material service providers — annual attestation + continuous reporting
CPS 230 Section 35
Critical
Critical operations defined per-organisation, mapped to vendors
CPS 230 Section 14

TARA, VANCE, REX — your CPS 230 stack.

Three of The Agency's leads cover the full CPS 230 loop: critical-operations mapping, material service provider attestation, and the continuous monitoring that keeps APRA's bar within reach.

TARA avatar
TARA
Compliance & Remediation

Critical operations and material service providers, mapped continuously. TARA classifies vendors against your critical-operations definitions and tracks the remediation actions APRA expects you to be doing between attestations.

What you get
  • Critical-operations to vendor mapping kept live
  • Material service provider tiering and re-tiering
  • Treatment plans with deadlines and SLA tracking
VANCE avatar
VANCE
Regulatory Reporting

APRA-formatted reports composed from current evidence. VANCE generates CPS 230 attestations, material service provider registers and board-pack summaries — formatted for APRA, evidence linked.

What you get
  • CPS 230 annual attestations composed from live data
  • Material service provider register kept current
  • Tamper-evident audit trail per output
REX avatar
REX
Continuous Monitoring

Continuous attestation, not annual scrambles. REX continuously monitors the security posture of every material service provider — APRA's bar for continuous risk management has actual evidence behind it.

What you get
  • Continuous monitoring across material service providers
  • Material-change detection in hours, not at year-end
  • Concentration risk visible across the third-party portfolio

Four shifts you'll feel in your first attestation cycle.

CPS 230 stops being a binder of slides and becomes a continuous evidence stream APRA can drop in on at any time.

Material service provider register stays live

The MSP register reflects today's contracts, today's tiering and today's posture — not last attestation cycle's.

Critical operations mapped to dependencies

Every critical operation linked to the third-party arrangements that support it. Concentration risk visible at a glance.

Annual attestations composed from continuous data

You stop assembling the attestation. VANCE generates it from live evidence — your team reviews and signs, not authors.

APRA-formatted output ready on demand

When APRA asks, the report is generated against current data — not last quarter's.

CPS 230 went from a binder of slides to a continuous evidence stream. Our material service provider register is finally something I would show APRA without a quarter of prep.

TL
Head of Operational Risk
ANZ Insurer

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.