CPS 230 gap assessment on real evidence, not questionnaires

A CPS 230 gap assessment measures how far your operational risk management sits from APRA’s Prudential Standard CPS 230 — and the honest way to run one is against real evidence, not a self-scored questionnaire. That means grading each requirement (critical operations, tolerance levels, the material service provider register, incident notification clocks) against artefacts you can actually produce: policies, registers, test results and board papers. Where evidence is missing, the finding reads “manual assessment required” rather than a green tick. The output is a defensible, board-ready coverage picture your assurance provider and APRA can trust.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

Why questionnaire-based CPS 230 assessments mislead boards

Most CPS 230 “readiness” work still runs as a spreadsheet of yes/no questions answered by the same team that owns the controls. That produces a comfortable score and a fragile position. When an independent reviewer or APRA asks “show me,” a self-rated green with no artefact behind it collapses — and the gap you thought you’d closed reopens under scrutiny. CPS 230 commenced 1 July 2025, with full effect and the material service provider contract transition due by 1 July 2026, so the window for optimistic self-assessment has effectively closed.

An evidence-led CPS 230 gap analysis inverts the default. Instead of asking a person to rate maturity, it asks a document to prove a requirement. A tolerance level is only “met” if a board-approved artefact states it in measurable terms. A material service provider is only “registered” if the register entry exists with the required attributes. Everything else is surfaced as a genuine gap. This is the meaning of “never a false green” — a control without corroborating evidence is reported as unassessed, not as passing.

What a complete CPS 230 gap assessment must cover

CPS 230 consolidated and replaced the old CPS 231 (outsourcing) and CPS 232 (business continuity), so a credible gap assessment has to span the whole operational-risk lifecycle rather than a single silo. The standard’s obligations cluster into four practical evidence domains:

Critical operations

Have you identified your critical operations end-to-end, mapped their dependencies (people, technology, data, third parties), and can you evidence the mapping? A gap here undermines everything downstream.

Tolerance levels

Board-approved tolerance levels for disruption to each critical operation — expressed as measurable limits (time, extent, service level), not aspirations. The evidence is the board-approved artefact, dated and current.

Material service providers

A maintained register of material service providers with the required attributes, plus contracts that meet CPS 230 terms. The 1 July 2026 contract transition makes register completeness the highest-pressure gap for most entities.

Incident & scenario testing

Operational risk incident management with defined notification clocks, plus scenario testing and business continuity exercises that are actually run and documented — APRA expects evidence of testing, not just a plan on file.

Read the source obligations directly at apra.gov.au, and see how CyberSentien structures each clause on our APRA CPS 230 framework page.

The notification clocks a gap assessment should test

Notification timing is a common weak point because it depends on process readiness, not just documentation. Your gap assessment should confirm that runbooks, on-call rosters and escalation paths can actually meet APRA’s expectations under pressure. The headline clocks entities should be able to evidence:

TriggerStandardExpectation (verify against current text)
Material operational risk incidentCPS 230Notify APRA as soon as possible and within 72 hours
Material information security incidentCPS 234Notify APRA within 72 hours
Material information security control weaknessCPS 234Notify APRA within 10 business days

Because CPS 230 and CPS 234 interlock in practice, a mature assessment reviews both together — an incident often touches operational resilience and information security at once. Always reconcile clock specifics against the current standard text on legislation.gov.au and APRA’s published guidance, as prudential requirements are periodically updated.

How CyberSentien runs an evidence-led CPS 230 gap assessment

CyberSentien performs readiness and evidence assessment — it does not certify you and it is not your independent assurance provider. What it does is grade the artefacts you already hold against the full CPS 230 clause set, then present coverage honestly:

The result is a CPS 230 self-assessment you can defend — a clear list of what is evidenced, what is missing, and what to remediate before your independent review. Start from our CPS 230 readiness checklist to see the clauses in plain language.

Try it on sample docs

Turning gaps into a remediation plan before 1 July 2026

A gap assessment only earns its keep if it drives a plan. Once coverage is graded, sequence remediation by regulatory exposure: the material service provider register and contract transition first, since that deadline is fixed; then board-approved tolerance levels, since they gate meaningful resilience testing; then the incident and scenario-testing evidence that demonstrates the controls actually work.

Practical starting points: pull your critical-operations mapping and confirm each has a current, board-approved tolerance statement; reconcile your service provider inventory against the CPS 230 materiality criteria; and dry-run a notification to confirm you can meet the clocks. Our CPS 230 templates give you the register and tolerance structures to populate, and banking-specific context sits on our APRA-regulated banking solution page. For the authoritative requirements, always work from the primary sources at apra.gov.au. The tripartite assurance itself — where an independent practitioner provides an ASAE 3150-style opinion — is performed by that independent party; CyberSentien’s role is to get your evidence ready so that review goes smoothly rather than surfacing surprises.

Frequently asked

What is a CPS 230 gap assessment?

A CPS 230 gap assessment maps your critical operations, tolerance levels, business continuity and material service provider controls against the standard to show exactly where evidence exists and where it is missing before 1 July 2026.

How do you do a CPS 230 gap assessment?

Scope your critical operations, gather evidence for each CPS 230 obligation, assess it control by control, and record residual gaps with a remediation plan. CyberSentien automates the evidence grading and outputs a hash-sealed report.

What is the most common CPS 230 gap?

Incomplete critical operations mapping and material service provider registers, plus tolerance levels that are asserted rather than evidenced and tested.

Is the output audit-ready?

CyberSentien produces a tamper-evident, SHA-256-lineage readiness report and board pack. It supports your evidence base but does not replace an APRA-appointed independent review.