# APRA CPS 230: Prudential Standard CPS 230 Operational Risk Management

Source: https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230
Last updated: Oct 5, 2026

CPS 230 Operational Risk Management is the Australian Prudential Regulation Authority's binding prudential standard on operational risk, business continuity and service providers. APRA finalised it on 17 July 2023 and it has applied to all APRA-regulated entities, including banks, since 1 July 2025; targeted amendments finalised on 30 April 2026 (new limited contract exemptions for certain non-traditional service providers) commence on 1 July 2026. The text does not use the words 'artificial intelligence'; it reaches AI through its technology and data risk requirements, the assessment of new technologies, critical-operations tolerance levels, and the rules for material service providers, which can include AI model and platform vendors. APRA's April 2026 AI letter says its prudential framework is 'technology and vendor agnostic' and that AI risks must be managed within it.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) |
| Type | Regulation |
| Status | In force |
| Published | Jul 17, 2023 |
| Effective | Jul 1, 2025 |
| Applies to | All APRA-regulated entities: authorised deposit-taking institutions (ADIs, including foreign ADIs for their Australian branch operations) and authorised banking non-operating holding companies, general insurers, life companies, private health insurers and registrable superannuation entity licensees. Banks are directly bound. Group heads must apply it on a group basis |
| Official text | https://www.apra.gov.au/operational-risk-management |

## Key points

- Three key requirements (paragraph 11): effectively manage operational risks, maintain critical operations within tolerance levels through severe disruptions, and manage the risks of using service providers.
- Paragraph 14: an entity must not rely on a service provider unless it can continue to meet its prudential obligations in full and effectively manage the associated risks.
- Paragraphs 23 and 24: operational risk explicitly includes technology risk, data risk and change management risk; entities must maintain sound IT capability and meet the information security requirements of CPS 234.
- Paragraph 25: business and strategic planning must assess 'the impact of new products, services, geographies and technologies on its operational risk profile and operational resilience'.
- Paragraphs 33 to 45: register of critical operations, tolerance levels for maximum disruption time, data loss and minimum service levels, a credible business continuity plan, and testing that includes disruptions to material service providers (paragraph 43).
- Paragraphs 46 to 51: a service provider management policy (including fourth parties), a register of material service providers submitted to APRA annually, and mandatory classification of providers of risk management and core technology services, among others, as material unless justified otherwise.
- Paragraphs 52 to 55: due diligence and concentration assessment before entering a material arrangement, a formal legally binding agreement with specified terms (including audit access, sub-contractor liability, termination rights and APRA access), and an orderly-exit capability.
- Notification: operational risk incidents likely to have a material financial impact or a material impact on critical operations within 72 hours (paragraph 32), disruptions to critical operations outside tolerance within 24 hours (paragraph 41), and critical-service agreements within 20 business days and material offshoring before entry (paragraph 60).

## What changed for banks

CPS 230 is a single cross-industry operational risk standard that makes the Board ultimately accountable for operational risk, business continuity and service provider management. For AI it matters because most banks buy AI capability: a model, platform or cloud provider that supports a critical operation, or exposes the bank to material operational risk, falls into the material service provider regime with its register, contract terms, concentration assessment and exit planning. The April 2026 amendments keep these obligations but exempt arrangements on standardised terms with listed categories of provider (such as central banks, regulators and clearing and settlement facilities).

## Use cases it governs

- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)

## What does APRA CPS 230 require of banks that use AI vendors?

APRA CPS 230 requires a bank's Board to oversee operational risk, business continuity and service provider management, and requires the bank to manage operational risk (including technology, data and change risk), keep critical operations within tolerance levels through severe disruptions, and manage the risks of every service provider it relies on. The text does not name AI, but an AI model or platform vendor that supports a critical operation, or exposes the bank to material operational risk, is a material service provider (paragraph 48): the bank must register it, assess concentration risk, sign a formal agreement with the paragraph 53 and 54 terms (including APRA access and sub-contractor liability), manage fourth-party risk, notify APRA within 20 business days of entering a critical-service agreement, and be able to exit in an orderly way. The standard has applied since 1 July 2025, with amendments commencing 1 July 2026.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Paragraph 14 — No reliance without control | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Do not rely on a service provider unless the entity can continue to meet its prudential obligations in full and effectively manage the associated risks. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 23 to 25 — Technology, data and new-technology risk | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Manage technology risk, data risk and change management risk; maintain sound IT capability and meet CPS 234; assess the impact of new technologies on the operational risk profile during strategic planning. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 28 to 31 — Controls and incidents | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Design, test and remediate internal controls proportionately to risk, and ensure incidents and near misses are escalated and recorded; notify APRA within 72 hours of a material operational risk incident (paragraph 32). | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 33 to 41 — Critical operations and tolerance levels | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Register critical operations, set tolerance levels for disruption time, data loss and minimum service, and notify APRA within 24 hours of a disruption outside tolerance. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 42 to 45 — BCP testing | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Test the business continuity plan annually in severe but plausible scenarios, including disruption of material service providers, with internal audit assurance. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 46 to 51 — Service provider policy and register | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Keep a service provider management policy covering fourth parties, identify material service providers (risk management and core technology services are material by default) and submit the register to APRA annually. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 52 and 53 — Due diligence and formal agreements | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Perform due diligence and a concentration assessment before entering or materially modifying a material arrangement, and hold a formal agreement with the specified minimum terms. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 54 and 55 — APRA access and exit | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Ensure the agreement gives APRA information access and on-site visit rights, and that the entity can run its BCP and exit orderly. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraphs 57 and 58 — Exemptions (amended text) | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Limited exemptions from paragraphs 53, 54, 55(d), 59(a) and 59(c) for arrangements on standardised terms with listed provider categories (for example central banks, regulators, clearing and settlement facilities). | From 1 July 2026 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |
| Paragraph 60 — Notifying APRA | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Notify APRA within 20 business days of entering or materially changing a critical-service agreement, and before entering a material offshoring arrangement. | In force since 1 July 2025 | [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) |

CPS 230 is the horizontal standard through which APRA supervises AI at banks. APRA's 30 April 2026 letter to all regulated entities says its principle-based prudential framework 'is technology and vendor agnostic', that most entities recognise existing standards apply to AI, and that few have operationalised that. The letter's supplier expectations track CPS 230's service provider rules: map the full AI supply chain including material, third-party and fourth-party dependencies, secure contractual transparency and auditability over AI services, and manage concentration, substitution and exit for critical AI providers.

The paragraph numbers above are those of the consolidated text commencing 1 July 2026 as published on APRA's CPS 230 page; APRA's June 2025 notification forms cite paragraphs 33, 42 and 59, which differ from the numbering of the 2026 consolidated text, so check which version a citation refers to. The amendments finalised on 30 April 2026 concern non-traditional service providers only; the core obligations were not changed. APRA's April 2023 timeline announcement said it intended to apply the requirements to pre-existing service provider contracts from the earlier of their next renewal or 1 July 2026.

CPS 230 sits next to CPS 234 (information security) and the Prudential Practice Guide CPG 230. Operational risk incidents reported under CPS 234 need not be separately notified under CPS 230 (footnote to paragraph 32). APRA can take stronger supervisory action under paragraph 18 and, as its AI letter says, 'where appropriate, pursue enforcement' where AI risks are not adequately identified, managed or controlled.

### What this means in practice

- Classify each AI model, platform and API provider against paragraph 48: does a critical operation depend on it, or does it create material operational risk? If yes, it goes on the material service provider register.
- Add AI-specific terms to formal agreements: notice of material model changes, sub-contractor and foundation-model disclosure, audit access, incident notification and data-handling changes, plus the APRA access terms in paragraph 54.
- Include AI provider outage and degradation in business continuity scenarios (paragraph 43) and test credible fallbacks where AI supports a critical operation.
- Record a concentration and exit view for each critical AI provider; APRA's letter says few entities had tested exit and substitution strategies.
- Report to the Board on tolerance-level breaches and material service provider performance, as paragraphs 21 and 40 require.

## FAQ

### When did APRA CPS 230 take effect?

CPS 230 was finalised on 17 July 2023 and commenced on 1 July 2025 after APRA extended the original timeline. APRA finalised targeted amendments on 30 April 2026, and the updated CPS 230 and CPG 230 commence on 1 July 2026. The amendments add limited exemptions from certain contract requirements for specified categories of service provider.

### Does CPS 230 apply to banks?

Yes. It applies to all APRA-regulated entities, including ADIs and authorised banking non-operating holding companies; for foreign ADIs the obligations apply to Australian branch operations. It also applies to insurers and superannuation trustees.

### Does CPS 230 cover AI?

The text does not mention artificial intelligence. It applies to AI because it covers technology and data risk, requires assessment of new technologies in strategic planning, and regulates material service providers on which a bank relies for a critical operation or that expose it to material operational risk. APRA's 30 April 2026 AI letter says the prudential framework is technology and vendor agnostic and expects entities to map their AI supply chain, including fourth parties, and manage concentration.

### What are the consequences of failing to comply with CPS 230?

Under paragraph 18, where APRA considers operational risk management has material weaknesses it may require an independent review, require a remediation program, require additional capital, impose licence conditions and take other supervisory action. The standard itself does not set monetary penalties.

### How does CPS 230 compare with OSFI Guideline B-10?

CPS 230 and Canada's B-10 both require a bank to stay accountable for third-party arrangements, to assess concentration and subcontracting risk and to contract for audit and exit. CPS 230 is a binding prudential standard that also covers business continuity and operational risk generally, and gives APRA specific notification rights; B-10 is supervisory guidance on third parties only.

## Related documents

- [APRA AI Letter to Industry (April 2026)](https://www.bankingnewsai.com/ai-regulation/documents/apra-letter-industry-ai-2026) — APRA Letter to Industry on Artificial Intelligence (AI) (Apr 30, 2026)
- [ASIC REP 798](https://www.bankingnewsai.com/ai-regulation/documents/asic-rep-798) — REP 798 Beware the gap: Governance arrangements in the face of AI innovation (Oct 29, 2024)
- [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) — Prudential Standard CPS 234 Information Security (Nov 30, 2018)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [FSB Chair's letter to G20 (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-chair-letter-g20-august-2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models (Aug 31, 2026)
- [Colorado AG proposed ADMT rules](https://www.bankingnewsai.com/ai-regulation/documents/co-ag-admt-proposed-rules-2026) — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) (Aug 11, 2026)
- [ESA Statement on ICT risks from frontier AI models (JC 2026 25)](https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models (Jul 31, 2026)
- [ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026) — Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutions (Jul 7, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.apra.gov.au/operational-risk-management) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
