13 catalogued controls across 13 areas, assessed deterministically against your uploaded and connector-collected evidence — honest coverage against the full catalogue, consultant-grade reporting from one run.
Book a demo on Third-Party Risk Management (NIST 800-161 / CPS 230) → Open the sample-evidence demoApplies to: Banks & APRA-regulated · Insurers & APRA-regulated · Superannuation & RSE licensees · Small & medium business · GRC consultants & practices · Healthcare · Critical infrastructure — SOCI · Third-party & supplier risk · Schools & education · Early childhood education & care · APRA CPS 230 & CPS 234
Generated from the live catalogue at build time — control identifiers and CyberSentien's own labels; no standard text is reproduced.
Verdicts against the FULL catalogue — controls without evidence read “manual assessment required”, never a fabricated pass.
Every report carries a run id and SHA-256 integrity anchor; sections trace to the controls and evidence they rest on.
The same run renders the Third-Party Risk Management (NIST 800-161 / CPS 230) report, executive brief and board pack — no drift between audiences.
Run it against synthetic sample documents now, or bring your own evidence in a gated demo week.
One that assesses real vendor evidence against CPS 230/234 rather than relying on self-attested questionnaires (SIG Lite/Core). CyberSentien grades evidence and flags gaps, feeding the material service provider register.
CPS 230 makes material service providers a board obligation. A TPRM program identifies material providers, evidences the mandatory contract terms and fourth-party risk, and populates the register APRA can request.
Yes — CyberSentien is AU-sovereign with AI that runs inside the client boundary, so vendor and evidence data does not leave your control, unlike US-hosted alternatives.
Questionnaires capture assertions; CPS 230 expects defensible evidence. CyberSentien assesses the underlying evidence so a vendor's claims are verified, never assumed.