CPS 230 readiness checklist — now the standard is fully in force

A CPS 230 readiness checklist confirms an APRA-regulated entity can identify its critical operations, has set board-approved tolerance levels, maintains a material service provider register, holds contracts carrying the required protections, and can meet the notification clocks — 24 hours for a disruption outside tolerance, 72 hours for a material operational risk incident. CPS 230 commenced 1 July 2025, and the transitional window for pre-existing service provider arrangements — which ran to the earlier of the next contract renewal or 1 July 2026 — has now closed. The standard applies in its entirety. This page walks the checklist domain by domain so you can see which items you can evidence under supervision today, and which still read “manual assessment required.”

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

What CPS 230 replaced — and why the checklist changed

CPS 230 Operational Risk Management consolidated and replaced CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management), pulling operational risk, business continuity and third-party management under one prudential standard. That means a readiness checklist built for the old standards is no longer sufficient: the emphasis has shifted from a static outsourcing policy to demonstrable control over critical operations, quantified tolerance levels, and a live material service provider register. The full standard is published on the APRA site at apra.gov.au. Treat the checklist below as five evidence domains — each item is either backed by an artefact you can produce today, or it is an open exposure under a standard that already applies in full.

The five readiness domains

A defensible CPS 230 day-one checklist groups into five domains. Each card lists the questions an independent reviewer — or your own board — will ask, and the evidence that answers them.

1. Critical operations

Have you defined and documented your critical operations (the processes that, if disrupted, would materially affect the entity or its customers)? Is there a current process map, and are dependencies — people, technology, facilities, service providers — identified for each? Evidence: a board-noted critical-operations register with mapped dependencies.

2. Tolerance levels

For each critical operation, has the board approved a tolerance level — the maximum tolerable disruption, expressed in time, volume or another measurable dimension? Are those tolerances tested against realistic severe-but-plausible scenarios? Evidence: board minutes approving tolerances plus scenario-test results.

3. Material service providers

Is there a material service provider (MSP) register identifying providers your critical operations rely on, including fourth-party concentrations where known? Evidence: the MSP register with materiality rationale and mapping back to each critical operation.

4. Service provider contracts

Do MSP contracts carry the protections CPS 230 expects? The transition window for pre-existing arrangements closed on 1 July 2026, so a clause that is still missing is a live gap, not a scheduled one. Evidence: a clause-mapping matrix per contract (see the clause table below).

5. Incident & notification readiness

Can you notify APRA as soon as possible, and no later than 72 hours, after becoming aware of a material operational risk incident? Are roles, contact paths and a drafting template pre-positioned? Evidence: an incident-response runbook with the notification clock built in.

The contract-clause checkpoints

Contract remediation is the item most entities underestimate, because it depends on counterparties, not just internal effort. It is also the item most often under-scoped: CPS 230 sets a minimum of ten matters a formal agreement for a material arrangement must address, not seven. Seven cover the substance of the arrangement, and three exist purely for the regulator — APRA access to documentation, data and any other information related to the provision of the service; APRA’s right to conduct an on-site visit at the service provider; and the service provider agreeing not to impede APRA in fulfilling its duties as prudential regulator. If your clause matrix stops at seven, check those last three explicitly rather than assuming a general audit-access clause covers them. Work through your material service provider agreements against the checkpoints below and record, per contract, whether each is present, absent, or under renegotiation. Where a clause cannot be evidenced from the contract text, it should read “manual assessment required” rather than be assumed satisfied.

CheckpointWhat the contract should evidence
Service scope & levelsClear description of the service and measurable service levels tied to your critical operations.
Entity rights & audit accessRights, responsibilities and expectations of each party, including ownership of assets, ownership and control of data, dispute resolution, audit access, liability and indemnity.
Sub-contracting & fourth partiesNotice and controls over material sub-contracting arrangements.
Legal & compliance obligationsProvisions that ensure the arrangement does not prevent you meeting your own legal and compliance obligations.
Sub-contractor liabilityLiability for failure by a sub-contractor sits with the service provider — it is not passed back to you.
Force majeureAn explicit force majeure provision. Frequently the term missing from contracts otherwise considered “done”.
Termination & exitExit plan, transition support and continuity of service on wind-down.
APRA access to informationThe agreement must allow APRA access to documentation, data and any other information related to the provision of the service.
APRA on-site visitThe agreement must allow APRA the right to conduct an on-site visit to the service provider.
No impediment to APRAThe service provider must agree not to impede APRA in fulfilling its duties as prudential regulator.

One narrow exemption applies. Following APRA’s targeted amendments to CPS 230, an entity need not comply with the specified contractual requirements for a material arrangement where both conditions are met: the provider falls within a category listed in the Attachment to the standard — non-traditional providers such as government agencies, regulators, central banks, financial market exchanges, operators of clearing and settlement facilities, operators of payment systems and schemes, and financial messaging infrastructures — and the arrangement uses standardised terms or is not documented in a formal agreement. “Standardised terms” means terms prepared by the provider where you have no, or substantially no, ability to negotiate them. Both limbs must hold, every other CPS 230 obligation continues to apply, and APRA has signalled it expects the scope of these exemptions to narrow rather than expand. Do not stretch this to cover an ordinary vendor who simply declined to renegotiate.

Beyond the mandatory minimum. Three further terms are not part of the ten but are standard practice in a defensible material-provider agreement, and reviewers routinely look for them: business continuity obligations on the provider aligned to your tolerance levels; incident notification fast enough that your own 24- and 72-hour clocks still start on time; and data location, handling and return or deletion on exit. Treat these as good practice, not as statutory terms — and never count them toward the ten.

Contract wording varies, so treat this as a mapping guide rather than model text. Our CPS 230 templates give you a register and clause-matrix starting point you can populate per provider.

The notification clocks you must be able to hit

Readiness is only real if the clock can actually be met under pressure. Pre-position the mechanics now.

Standards and instruments referenced here are on the Federal Register of Legislation at legislation.gov.au, and broader operational-cyber guidance is published by the ASD at cyber.gov.au.

How CyberSentien supports the checklist — honestly

CyberSentien performs readiness and evidence assessment against CPS 230; it does not certify compliance and it is not your independent assurer. The platform ingests your registers, board papers, scenario tests and contracts, then scores each checklist item against the evidence actually present. Controls with no supporting artefact are never marked green — they read “manual assessment required,” so the board sees the true state, not an optimistic one. From there you can prioritise the remaining gaps by regulatory exposure — which is what matters now the standard is in force and a supervisor can ask at any time.

For the mapped control set, see our APRA CPS 230 framework page, and to quantify where you stand today run the structured CPS 230 gap assessment.

Try it on sample docs

If items are still unevidenced: a remediation sequence

There is no runway left to plan against, so stop sequencing by calendar and sequence by regulatory exposure — what a supervisor can ask for first, and what does the most damage if it is missing when they ask.

1. Anything with a clock

Highest exposure, because an incident can happen today and the notification clock runs whether or not you are ready. Rehearse the runbook end-to-end: intake, materiality call, approver, contact path, drafting template.

2. The material service provider register

The register must be submitted to APRA on an annual basis, so it is the artefact most certain to be requested. Make sure it is current, has a materiality rationale per provider, and maps back to each critical operation.

3. Critical operations & board-approved tolerances

Everything else is derived from these, and the deferral some non-SFIs relied on for certain business continuity and scenario-analysis requirements — including tolerance levels — also ended on 1 July 2026. An unapproved tolerance is now an overdue obligation.

4. Contract gaps — overdue, not pending

Longest lead and counterparty-dependent, but the transition window has closed, so treat each missing clause as an open finding. Record the position per contract, evidence the renegotiation you have actually attempted, and check whether the narrow non-traditional-provider exemption genuinely applies before relying on it.

Where an item cannot be evidenced yet, record it as an open gap with an owner and a date rather than back-filling paperwork — a documented, in-progress remediation is a defensible position; an undocumented one is not. Because this is prudential guidance and not legal advice, confirm interpretation against the current standard and, where the tripartite assurance model applies, engage a qualified independent practitioner for the formal assurance work.

Frequently asked

What must be evidenced under CPS 230 now?

Material service provider registers, the mandatory contract terms, critical operations mapping, board-approved tolerance levels, and business continuity testing all need to be evidenced today. CPS 230 commenced on 1 July 2025 and the transitional window for pre-existing service provider arrangements closed on 1 July 2026, so these are current obligations under supervision, not upcoming ones.

What are the mandatory CPS 230 contract terms?

A formal agreement for a material arrangement must address a minimum of ten matters, not seven. Seven cover the substance of the arrangement: the services and associated service levels; the rights, responsibilities and expectations of each party, including asset and data ownership, dispute resolution, audit access, liability and indemnity; the entity’s ability to meet its legal and compliance obligations; notification of material sub-contracting; sub-contractor liability sitting with the provider; force majeure; and termination. Three more exist for the regulator: APRA access to documentation and data, APRA’s right to conduct an on-site visit at the service provider, and the provider agreeing not to impede APRA. A narrow exemption from the specified contractual requirements applies to certain non-traditional service providers listed in the Attachment to the standard where the arrangement uses standardised terms or is not documented in a formal agreement.

What is the 72-hour incident notification under CPS 230?

Entities must notify APRA within 72 hours of an operational risk incident that has, or is likely to have, a material financial or non-financial impact.

Is a checklist enough for CPS 230?

A checklist scopes the work; CPS 230 requires defensible evidence for each item. CyberSentien turns the checklist into an evidence-based assessment rather than a static tick-box.