Compliance guide

The CPS 230 compliance guide for data teams.

CPS 230 is APRA's prudential standard for operational risk management. It came into force on 1 July 2025, transitional relief ended on 1 July 2026, and full obligations now apply to every APRA-regulated entity. This guide explains what the standard requires and, more practically, how to evidence compliance from your data estate rather than from documents alone.

TL;DR

CPS 230 requires APRA-regulated entities to manage operational risk, maintain critical operations through disruption within defined tolerance levels, and manage risks from material service providers. Every one of those obligations depends on data, so the strongest compliance position is built from observable signals in the data estate: pipeline health, freshness, lineage, access and quality, rolled up into evidence a board and a supervisor can inspect.

1 Jul 2025CPS 230 in force
1 Jul 2026Transition ended
3Core obligation areas
AllAPRA-regulated entities

Who CPS 230 applies to, and since when.

CPS 230 applies to all APRA-regulated entities: banks and other authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees (superannuation trustees). It came into force on 1 July 2025. Transitional arrangements for pre-existing contractual arrangements with material service providers ran to the earlier of the contract's next renewal or 1 July 2026, which means the transition period is now over: full obligations apply.

The standard is still moving. On 30 April 2026 APRA released targeted amendments, effective 1 July 2026, introducing limited exemptions from specific contractual requirements for certain categories of service providers where contractual compliance is not practicable, alongside updated CPG 230 guidance and a revised material service provider register template. If your register and contract uplift were built to the 2025 shape of the standard, they are worth revisiting.

Read APRA's CPS 230 operational risk management hub →

What CPS 230 requires.

At its core, CPS 230 requires regulated entities to do three things well:

  • Manage operational risk effectively. Identify, assess and manage operational risks with appropriate controls, and rectify weaknesses promptly.
  • Maintain critical operations through disruption. Define critical operations, set tolerance levels for disruption (maximum outage time, maximum data loss, minimum service levels), and maintain credible business continuity plans tested against severe but plausible scenarios.
  • Manage risks from service providers. Maintain a register of material service providers, conduct due diligence, and ensure agreements meet prescribed requirements, including for fourth parties your providers depend on.

Why CPS 230 is a data problem.

Most institutions treated CPS 230 as a policy exercise: registers, attestations, board papers. But every obligation above depends on data:

  • You cannot set or monitor a tolerance level for data loss without knowing where the data is, how fresh it is, and whether the pipelines that feed critical operations are healthy.
  • You cannot prove a control operated without a signal showing it operated.
  • Key-person and service-provider risk lives in undocumented pipelines and tribal knowledge as much as it lives in contracts.

This is the difference between asserted compliance (documents saying controls exist) and observed compliance (signals from the data estate proving controls are operating). APRA's supervisory approach increasingly asks for the latter: evidence, not assertion. We unpack the distinction in our insight, Asserted vs observed compliance.

CPS 230, CPS 234 and CPG 235: how they fit together.

InstrumentWhat it coversHow it relates
CPS 230 (operational risk)Critical operations, tolerance levels, controls, service providersThe umbrella standard
CPS 234 (information security)Security capability, control testing, 72-hour incident notificationOverlaps CPS 230 wherever a security failure would disrupt a critical operation
CPG 235 (data risk)Data quality, lineage, retention, accessGuidance, not an enforceable standard, but the lens supervisors apply to data practices under both standards

A single control framework mapped across all three, with each control tied to an observable signal, is far more defensible than three parallel document sets.

The practical path

Five steps to observable CPS 230 compliance.

01

Map

Map critical operations to data assets: the systems, pipelines and datasets each one depends on. If this map does not exist, that is finding number one.

02

Translate

Translate tolerances into data SLOs. "Maximum data loss" and "maximum outage" become measurable freshness, completeness and availability thresholds on specific pipelines.

03

Instrument

Instrument the controls. Deploy observability across the data estate so control operation produces a signal: schema changes detected, lineage captured, quality thresholds monitored, access reviewed.

04

Evidence

Build the evidence layer. Signals roll up to a control dashboard the risk function and board can consume, and an audit trail a supervisor can inspect.

05

Close the loop

Extend monitoring to data flowing to and from material service providers, and document pipeline knowledge so continuity does not depend on individuals.

RUBIX productises this path as Observed Compliance: obligations mapped to live signals from your data estate, with the dashboards and audit trail built in. It runs alongside our APRA AI compliance and data governance work.

Frequently asked questions.

Who does CPS 230 apply to?

All APRA-regulated entities: authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees (superannuation trustees). Non-SFI (non-significant financial institution) entities have some proportionality relief but core obligations still apply.

When did CPS 230 come into effect?

1 July 2025, with transitional relief for pre-existing material service provider contracts until their next renewal or 1 July 2026, whichever came first. APRA released targeted amendments on 30 April 2026, effective 1 July 2026, covering limited exemptions for certain service provider categories.

What is the difference between asserted and observed compliance?

Asserted compliance is documentation stating a control exists. Observed compliance is a continuous signal from your systems demonstrating the control is operating, with an evidence trail. Supervisors and boards are shifting expectation toward the latter.

Does CPS 230 replace CPS 234?

No. CPS 234 remains in force for information security. CPS 230 sits above it as the operational risk framework. The two share territory on incident management and third-party risk.

How does RUBIX help with CPS 230?

RUBIX maps CPS 230, CPS 234 and CPG 235 obligations to observable signals in your data estate and implements the monitoring, dashboards and evidence trail through our Observed Compliance offering.

Which consultants help Australian financial services meet CPS 230 using AI?

RUBIX is an Australian data and AI consultancy (established 2010, Melbourne and Sydney) working with APRA-regulated banks, superannuation funds and insurers. We instrument the data estate rather than add paperwork: critical operations are mapped end to end, disruption tolerances become measurable data SLOs, and AI-assisted monitoring detects freshness breaches, schema changes and access anomalies continuously, producing a timestamped evidence trail for supervisors and boards. See Observed Compliance and our financial services practice. RUBIX has delivered data and AI work for NAB, ANZ, MUFG and AustralianSuper.

Related reading.

Observed Compliance

Continuous compliance monitoring for APRA-regulated institutions. Evidence, not assertion.

Read more →

Financial Services

Data platforms, AI governance and APRA compliance for banks, super funds and insurers.

Read more →

Case study: NAB

Enterprise data delivery for one of Australia's largest banks.

Read more →

This guide summarises RUBIX's understanding of APRA's CPS 230 and related guidance for general information only, current as at August 2026. It is not legal, compliance or regulatory advice. Regulated entities should verify obligations against current APRA publications and seek appropriate advice.