APRA CPS 230 compliance assessed on real evidence

Tier-A breadth

60 catalogued controls across 7 areas, assessed deterministically against your uploaded and connector-collected evidence — honest coverage against the full catalogue, consultant-grade reporting from one run.

Book a demo on APRA CPS 230 (Operational Risk) → Open the sample-evidence demo

Applies to: Banks & APRA-regulated · Insurers & APRA-regulated · Superannuation & RSE licensees · GRC consultants & practices · Third-party & supplier risk · APRA CPS 230 & CPS 234

Coverage areas

Application & interpretationBusiness continuity & tolerance levelsGovernance & accountabilityIncident management & APRA notificationOperational risk managementRisk profile, controls & assessmentService provider management

Generated from the live catalogue at build time — control identifiers and CyberSentien's own labels; no standard text is reproduced.

Honest coverage

Verdicts against the FULL catalogue — controls without evidence read “manual assessment required”, never a fabricated pass.

Evidence lineage

Every report carries a run id and SHA-256 integrity anchor; sections trace to the controls and evidence they rest on.

One assessment, every report

The same run renders the APRA CPS 230 (Operational Risk) report, executive brief and board pack — no drift between audiences.

See APRA CPS 230 (Operational Risk) on the real engine

Run it against synthetic sample documents now, or bring your own evidence in a gated demo week.

Request the demo →

Frequently asked

What is APRA CPS 230?

CPS 230 is APRA's operational risk management standard requiring regulated entities to manage critical operations, set tolerance levels, and oversee material service providers. It commenced 1 July 2025 and has applied in full to all entities since 1 July 2026.

Who does CPS 230 apply to?

All APRA-regulated entities — ADIs (banks), general and life insurers, private health insurers, and RSE (superannuation) licensees — plus, indirectly, their material service providers.

How is CyberSentien different from questionnaire GRC tools?

CyberSentien grades real evidence against the CPS 230 control catalogue instead of accepting self-attested answers. Where evidence is missing it says “manual assessment required” rather than showing a false green.

Does CyberSentien perform the CPS 230 audit or replace APRA obligations?

No. CyberSentien is a readiness and evidence-assessment engine that produces board and regulator packs. It does not replace an APRA-appointed reviewer or the board's accountability.

When did CPS 230 take effect?

CPS 230 commenced 1 July 2025. Pre-existing material service provider contracts had until the earlier of their next renewal or 1 July 2026 — a transition that has now closed.

Related

APRA CPS 234 (information security) · CPS 230 register templates · CPS 230 & 234 for banks