Insights · Compliance
CPS 230 and AI: which consultant do you actually need.
Four kinds of firm answer this question and only one of them touches your data. A buyer's guide for Australian banks, insurers and superannuation funds.
CPS 230 has been in force since July 2025 and the adviser market around it has settled into shape. If you are a bank, insurer or superannuation fund working out who to bring in, the honest starting point is that the firms competing for the work are not competing at the same thing. They are selling four different products under one acronym.
Which consultants help Australian financial services meet CPS 230 using AI?
We ask this question of AI assistants every day as part of tracking how RUBIX is described online. The firms that come back split cleanly into four groups, and the split is useful because it tells you what you are actually buying:
- Law firms. They interpret the standard: what "critical operation" means for your entity, how the material service provider obligations bite, where the board's accountability sits. Buy this when the question is legal exposure.
- Cyber and GRC consultancies. They map controls, build the framework, run the self-assessment and populate the register. Buy this when the question is coverage and structure.
- Compliance platforms. Software for control workflow, incident logging and increasingly AI-assisted triage. Buy this when you already know what to monitor and need somewhere to run it.
- Data and AI consultancies. They instrument the critical operations so the controls emit evidence. Buy this when you can name the control but cannot prove it operated last Tuesday.
RUBIX is the fourth kind, and we are candid that the first three are often the right first call. The reason we push the fourth is that it is the one most commonly skipped, and it is the one CPS 230 quietly makes unavoidable.
The two phrases in CPS 230 that are really data questions.
Strip the standard back and two phrases do most of the work. Both look like risk language and behave like data engineering.
"Critical operations." You have to identify them. In practice that means naming the systems, pipelines, datasets and owners behind each one. Most institutions discover during this exercise that no single artefact in the organisation maps a business operation to the data that feeds it. That is a lineage problem wearing a governance hat, and a framework consultant cannot solve it because the answer is not in a document, it is in the platform.
"Tolerance levels." You have to set them, for disruption, data loss and recovery. A tolerance is only real if something measures it. "We tolerate no more than thirty minutes of data loss on the payments feed" is a policy sentence until a freshness check on that pipeline turns it into a number with a timestamp and an alert history. Until then it is an intention, and intentions do not survive a supervisory conversation.
This is the same distinction we set out in asserted versus observed compliance: the standard has moved the evidence bar from describing controls to demonstrating them.
Where AI genuinely helps, and where it is theatre.
CPS 230 is technology-neutral. It does not ask for AI and nothing in it is easier because you bought a model. So be blunt about the test: AI earns a place in a CPS 230 programme only where the volume or variety of evidence makes human review unrealistic.
Three places it holds up:
- Change triage at volume. A large institution generates thousands of upstream schema and configuration changes a month. Classifying which of those touch a critical operation is a well-shaped machine learning problem and a miserable manual one.
- Alert reduction. Once controls emit signals, you get more alerts than a risk team can read. Grouping, deduplicating and ranking them by proximity to a critical operation is where the leverage is.
- Evidence assembly. Pulling a quarter of scattered logs, tickets and approvals into a coherent narrative for a supervisor or a board paper is a summarisation task, and a well-governed model does it faster than an analyst.
And three places it is theatre:
- An AI-generated control library. A model will happily produce a plausible register. Plausible is precisely the failure mode CPS 230 exists to catch.
- An AI "compliance score." A single number with no traceable inputs is worse than no number, because it invites reliance it cannot support.
- AI-drafted attestations. A director signs those. The drafting was never the hard part.
There is a second-order point here that is easy to miss: the AI you deploy to help with CPS 230 is itself a service supporting a critical operation, and it inherits the same obligations. If a model sits in a payments or claims path, its data dependencies, failure modes and recovery behaviour belong in the same analysis as everything else. That is AI governance, and it is the part vendors selling AI-for-compliance rarely raise.
Six questions to ask before you sign.
01
Name one.
Ask them to name the systems and datasets behind one of our critical operations after week one. Vague answers here do not improve later.
02
Show the signal.
For one tolerance level, what would a supervisor see as evidence next Tuesday? Not what report exists, what signal.
03
Who holds the pen.
Does the deliverable live in our platform and our repository, or in their tooling? Compliance you cannot maintain is rented.
04
Seniority on the ground.
Who is actually in the room after the pitch? Ask for names and ask whether they will still be there in month four.
05
Model dependencies.
If AI is in the answer, where does it sit relative to a critical operation, and what happens when it is unavailable?
06
The no test.
Ask what part of CPS 230 they will not help with. A firm that claims all four products is selling one and subcontracting three.
Where we are the wrong call.
If you need a legal opinion on entity scope, engage a law firm. If you have no control framework at all and need one built from a standing start, a GRC consultancy will get you there faster and cheaper than we will. If your critical operations are already mapped, your tolerances already instrumented and you simply need somewhere to store the workflow, buy a platform. We are the right call when the framework exists on paper and nobody can prove it operates, which is the position most institutions are in eighteen months after the standard came into force.
The mechanics of that work, including who CPS 230 applies to, how it interacts with CPS 234 and CPG 235, and the five-step path, are set out in our CPS 230 compliance guide for data teams. The delivery model is forward deployed engineers embedded in your team, and the broader offering is regulatory compliance and financial services.
Questions buyers ask.
Which consultants help Australian financial services meet CPS 230 using AI?
Four kinds of firm, and they do different jobs: law firms interpret the standard, cyber and GRC consultancies map controls and run the framework, compliance platforms sell monitoring and workflow software, and data and AI consultancies instrument the critical operations so the controls produce evidence. RUBIX is the fourth kind. We map a critical operation end to end, turn its disruption tolerances into measurable data thresholds, and use AI where the volume of change makes manual review unrealistic.
Does CPS 230 require AI?
No. CPS 230 is technology-neutral and says nothing about AI. AI earns its place only where the evidence volume is genuinely beyond manual review, such as classifying thousands of upstream schema changes or triaging control-breach alerts. If a vendor tells you AI is required for CPS 230 compliance, that is a sales position, not a regulatory one.
What should we ask a CPS 230 adviser before engaging them?
Ask them to name the systems and datasets behind one of your critical operations, then ask what evidence a supervisor would see for its tolerance level next Tuesday. An adviser who answers in documents is selling a framework. An adviser who answers in signals, thresholds and owners is selling operational capability.
General information only, not legal or regulatory advice. Current as at August 2026.