CPS 230 Compliance Guide
What CPS 230 requires and the practical path to observable compliance.
Read more →Observed Compliance
Your compliance documents say the controls exist. Can you show a supervisor the signal proving they operated last Tuesday? Observed Compliance is RUBIX's continuous compliance monitoring offering for APRA-regulated institutions: your CPS 230, CPS 234, CPG 235, Privacy Act and SOCI obligations mapped to observable signals in your data estate, monitored continuously.
Our control library translates regulatory obligations into specific, observable data estate controls: freshness and completeness on pipelines feeding critical operations, lineage coverage, schema change detection, access anomalies, retention conformance.
Data observability, powered by our partnership with Decube, instruments those controls across your platform, whether Databricks, Microsoft Fabric or hybrid.
Signals roll up to a compliance scorecard with a full audit trail: control, obligation, signal, timestamp. Board-ready, supervisor-ready.
Mid-tier APRA-regulated institutions: mutual banks, customer-owned banks, superannuation funds and insurers that carry the same obligations as the majors without the same compliance headcount. If your risk function spends its quarter chasing screenshots and attestations, Observed Compliance replaces that with signals that were being collected anyway.
| Tier | What's included |
|---|---|
| Foundation | Control mapping, core observability on critical-operation pipelines, monthly compliance scorecard |
| Assured | Everything in Foundation plus expanded control coverage, third-party data flow monitoring, quarterly control attestation pack |
| Continuous | Full control library coverage, real-time alerting, board reporting pack, and a named RUBIX compliance engineer |
Pricing on application. Every engagement starts with a compliance observability assessment.
Since 2010 we have delivered 450+ data projects for 115+ Australian organisations, including NAB, ANZ, MUFG and AustralianSuper. Observed Compliance productises fifteen years of regulated-industry delivery into a subscription your risk committee can rely on.
Compliance demonstrated by continuous signals from operating systems rather than by point-in-time documentation. The control isn't just described; its operation is observed and logged.
APRA CPS 230 and CPS 234, CPG 235 guidance, Privacy Act obligations relating to data handling, and SOCI Act requirements where applicable.
No. The control library is platform-agnostic; we implement on Databricks, Microsoft Fabric/Azure and hybrid estates.
No. It feeds your GRC and risk reporting with live evidence from the data estate, replacing manual attestation gathering.
What CPS 230 requires and the practical path to observable compliance.
Read more →Data platforms, AI governance and APRA compliance for banks, super and insurers.
Read more →The data observability layer behind Observed Compliance.
Read more →