# APRA CPS 234: Prudential Standard CPS 234 Information Security

Source: https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234
Last updated: Oct 5, 2026

CPS 234 Information Security is APRA's binding prudential standard requiring banks and other APRA-regulated entities to maintain an information security capability commensurate with the size and extent of threats to their information assets. It was determined on 30 November 2018 and has applied since 1 July 2019, with third-party-managed assets brought in by the earlier of contract renewal or 1 July 2020. The Board is ultimately responsible; entities must classify assets by criticality and sensitivity, implement controls, test them through a systematic program, and notify APRA within 72 hours of a material information security incident. The standard does not mention AI, but its definition of an information asset covers software, hardware and data, so AI models, training data and AI platforms are in scope. APRA's April 2026 AI letter treats AI-specific attack paths as part of the information security uplift it expects.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) |
| Type | Regulation |
| Status | In force |
| Published | Nov 30, 2018 |
| Effective | Jul 1, 2019 |
| Applies to | All APRA-regulated entities: ADIs (including foreign ADIs, for Australian branch operations) and authorised banking non-operating holding companies, general insurers, life companies, private health insurers and RSE licensees. Banks are directly bound. Requirements for information assets managed by a third party applied from the earlier of the contract's next renewal or 1 July 2020 |
| Official text | https://www.apra.gov.au/standards/cps-234 |

## Key points

- Paragraph 13: the Board is ultimately responsible for information security, commensurate with the size and extent of threats to the entity's information assets; paragraph 14 requires clearly defined security roles for the Board, senior management and individuals.
- Paragraphs 15 to 17: maintain an information security capability commensurate with the threat environment, and actively maintain it as vulnerabilities and threats change, including from changes to information assets or the business environment.
- Paragraph 12(d) defines an information asset as 'information and information technology, including software, hardware and data'; the standard does not name AI, so AI systems are covered as information assets.
- Paragraphs 16, 20 to 22: assess the information security capability of related and third parties that manage the entity's information assets, classify those assets by criticality and sensitivity, and evaluate the design of third-party controls; footnotes make this apply to all third-party-managed assets, not only outsourced material business activities.
- Paragraphs 23 to 26: robust detection and response, response plans for plausible incidents covering detection to post-incident review, and annual review and testing of those plans.
- Paragraphs 27 to 31: a systematic control-testing program proportionate to the rate of change of threats, criticality and sensitivity, and frequency of change to assets; testing by skilled, functionally independent specialists; sufficiency reviewed at least annually.
- Paragraphs 32 to 34: internal audit must review the design and operating effectiveness of information security controls, including those maintained by related and third parties.
- Paragraphs 35 and 36: notify APRA no later than 72 hours after becoming aware of a material information security incident (or one notified to other regulators), and within 10 business days of a material control weakness that cannot be remediated in a timely manner.

## What changed for banks

CPS 234 made information security a binding prudential requirement, with a 72-hour incident notification duty and an obligation to assess the controls of third parties that hold the entity's information. For AI it matters because it reaches any AI system, data pipeline or vendor-hosted model as an information asset, and APRA's 2026 AI letter and joint APRA-ASIC frontier AI statement tie today's AI-driven cyber threats back to this standard and to CPS 230.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [AI-generated code & coding agents](https://www.bankingnewsai.com/ai-regulation/by-use-case#ai-generated-code)

## What does APRA CPS 234 require of banks, and how does it apply to AI?

APRA CPS 234 requires a bank's Board to be ultimately responsible for information security and the bank to maintain an information security capability commensurate with the size and extent of threats to its information assets. The bank must classify information assets (including those managed by related or third parties) by criticality and sensitivity, implement controls proportionate to threats and the asset's life-cycle stage, run a systematic and independent testing program, maintain tested incident response plans, have internal audit review control design and effectiveness, and notify APRA within 72 hours of a material incident. The text does not name AI, but because an information asset includes software, hardware and data, AI models, training data and vendor-hosted AI platforms must be classified, protected, tested and covered by third-party assessments. In force since 1 July 2019.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Paragraphs 13 and 14 — Board responsibility and roles | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | The Board is ultimately responsible for information security; roles and responsibilities of the Board, senior management and individuals must be clearly defined. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 15 to 17 — Information security capability | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Maintain a capability commensurate with the size and extent of threats and keep it current as threats and information assets change. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 18 and 19 — Policy framework | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Maintain an information security policy framework commensurate with exposure to vulnerabilities and threats, setting responsibilities for all parties with a security obligation. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 16 and 22 — Third-party information assets | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Assess the information security capability of related and third parties managing the entity's information assets and evaluate the design of their controls. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraph 20 — Asset classification | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Classify information assets, including those managed by third parties, by criticality and sensitivity. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraph 21 — Implementation of controls | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Implement controls in a timely manner, commensurate with vulnerabilities and threats, criticality and sensitivity, life-cycle stage and potential consequences of an incident. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 23 to 26 — Incident management | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Detect and respond to incidents in a timely manner, maintain response plans covering all stages from detection to post-incident review, and review and test them annually. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 27 to 31 — Testing control effectiveness | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Run a systematic testing program proportionate to the rate of change of threats and the materiality and frequency of change to information assets, using skilled and functionally independent testers. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 32 to 34 — Internal audit | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Include review of the design and operating effectiveness of information security controls, including those of related and third parties, with appropriately skilled personnel. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |
| Paragraphs 35 and 36 — APRA notification | [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Notify APRA within 72 hours of a material information security incident and within 10 business days of a material control weakness that cannot be remediated in a timely manner. | In force since 1 July 2019 | [APRA CPS 234](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234) |

CPS 234 is technology-neutral and was drafted in 2018, so it never mentions AI. It reaches AI through the definitions: an information asset is information and IT including software, hardware and data, and information security means preserving confidentiality, integrity and availability. A hosted large language model, a retrieval index containing customer data or an AI coding assistant with repository access is an information asset whose threats and vulnerabilities the bank must classify and control.

APRA's April 2026 letter to industry spells out how it expects the standard to be applied to AI-era threats: security controls that address AI-specific attack paths, strong privileged access management extended to non-human actors such as AI agents, robust security testing across AI-generated code, components and libraries, and remediation (patching, configuration management) timelines aligned to an accelerated threat environment. In the letter APRA also flags that staff use of enterprise AI tools outside approved control frameworks relied too often on policy direction rather than enforceable technical restrictions. These are APRA's expectations of how existing standards apply, not new paragraphs of CPS 234.

CPS 234 is referenced by CPS 230 (paragraph 24 requires entities to meet CPS 234 when managing technology risk), and a notification made under CPS 234 need not be separately reported under CPS 230. The joint APRA-ASIC media release of 27 August 2026 on frontier AI lists cyber fundamentals, including identity and access controls, patching, tested response and recovery and third-party risk management, among the key themes from nine industry roundtables.

### What this means in practice

- Add AI models, training and retrieval data, prompts and logs, and AI agent credentials to the information asset register and classify them by criticality and sensitivity.
- Assess AI vendors' information security capability and controls under paragraphs 16 and 22, even where the arrangement is not formal outsourcing.
- Extend the systematic testing program to AI workloads: prompt injection, data leakage, insecure integrations and agent tool misuse, and security-test AI-generated code before release.
- Give AI agents unique non-human identities with least-privilege access, as APRA expects privileged access management to adapt to non-human actors.
- Update incident response plans for AI-related incidents and rehearse the 72-hour APRA notification, alongside CPS 230 notifications.

## FAQ

### When did APRA CPS 234 take effect?

CPS 234 was determined on 30 November 2018 and commenced on 1 July 2019. For information assets managed by a third party, the requirements applied from the earlier of the next renewal date of the contract with the third party or 1 July 2020.

### Does CPS 234 apply to banks?

Yes. It applies to all APRA-regulated entities, including authorised deposit-taking institutions and authorised banking non-operating holding companies, as well as insurers and RSE licensees. For a foreign ADI it applies only to Australian branch operations.

### Does CPS 234 apply to AI systems?

The text does not mention AI, but it applies to information assets, defined as information and information technology including software, hardware and data. An AI model, its training and operating data and the platform it runs on are therefore within scope, including when a third party hosts them. APRA's 30 April 2026 letter on AI describes AI-specific attack paths such as prompt injection and insecure integrations and expects security controls that address them.

### How quickly must a bank notify APRA of an information security incident under CPS 234?

Paragraph 35 requires notification as soon as possible and no later than 72 hours after becoming aware of an incident that materially affected, or had the potential to materially affect, the entity or the interests of depositors, policyholders, beneficiaries or customers, or that has been notified to other regulators. Paragraph 36 separately requires notice within 10 business days of a material control weakness that cannot be remediated in a timely manner.

### What are the penalties for breaching CPS 234?

The standard itself sets no penalties. APRA's April 2026 AI letter says that where entities fail to identify, manage or control AI risks proportionately it will take stronger supervisory action and, where appropriate, pursue enforcement.

## Related documents

- [APRA AI Letter to Industry (April 2026)](https://www.bankingnewsai.com/ai-regulation/documents/apra-letter-industry-ai-2026) — APRA Letter to Industry on Artificial Intelligence (AI) (Apr 30, 2026)
- [ASIC REP 798](https://www.bankingnewsai.com/ai-regulation/documents/asic-rep-798) — REP 798 Beware the gap: Governance arrangements in the face of AI innovation (Oct 29, 2024)
- [APRA CPS 230](https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-230) — Prudential Standard CPS 230 Operational Risk Management (Jul 17, 2023)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [FSB Chair's letter to G20 (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-chair-letter-g20-august-2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models (Aug 31, 2026)
- [ESA Statement on ICT risks from frontier AI models (JC 2026 25)](https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models (Jul 31, 2026)
- [ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026) — Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutions (Jul 7, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.apra.gov.au/standards/cps-234) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/apra-cps-234
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
