CPS 230 and CPS 234 are separate but overlapping APRA prudential standards: CPS 230 (Operational Risk Management) governs operational resilience — critical operations, tolerance levels and material service providers — while CPS 234 (Information Security) governs the security of information assets. CPS 220 (Risk Management) sits above both as the entity-wide risk framework they plug into. They share evidence but answer different questions, so an APRA-regulated entity typically needs all three assessed against one control base rather than in isolation.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
APRA’s Cross-industry Prudential Standards (CPS) form a stack. CPS 220 sets the overarching risk management framework; CPS 230 addresses operational risk and resilience; CPS 234 addresses information security. Each has its own scope and notification obligations, and it is common for a single incident — a ransomware event, say — to trigger clocks under both CPS 230 and CPS 234 at once. Understanding where the boundaries fall is what keeps an assessment defensible.
The entity-wide risk management framework: risk appetite, roles and responsibilities, and board oversight of material risks across the business. It is the umbrella CPS 230 and CPS 234 report up into.
Commenced 1 July 2025. Covers critical operations, board-approved tolerance levels, the material service provider register, and operational-risk incident notification. It replaced CPS 231 (outsourcing) and CPS 232 (business continuity).
Requires identification and classification of information assets, control implementation and testing, clear board accountability, and specific breach and control-weakness notifications to APRA.
The cleanest way to hold the distinction is by the question each standard forces you to answer. CPS 234 asks: are your information assets secure, and can you prove the controls work? CPS 230 asks a broader operational question: can your critical operations keep running within tolerance when something breaks — including, but not limited to, a cyber event? A denial-of-service that takes payments offline is a CPS 230 resilience matter and a CPS 234 security matter simultaneously; the same evidence supports both, but the assessment lenses differ.
| Dimension | CPS 230 Operational Risk | CPS 234 Information Security |
|---|---|---|
| Primary focus | Operational resilience & continuity of critical operations | Security of information assets |
| Core artefacts | Critical operations list, tolerance levels, material service provider register | Asset inventory & classification, control testing evidence |
| Board role | Approves tolerance levels; ultimately accountable for operational risk | Ultimately accountable for information security |
| Incident clock | Notify as soon as possible / within 72 hours of a material operational-risk incident | Notify within 72 hours of a material incident; within 10 business days of a material control weakness |
| Replaces | CPS 231 (outsourcing) & CPS 232 (business continuity) | N/A — standalone since 2019 |
You can read the standards in full on the federal register: CPS 230 and CPS 234 are published via legislation.gov.au and APRA’s own guidance sits on apra.gov.au. Our framework breakdowns for CPS 230 and CPS 234 map each obligation to the evidence that satisfies it.
CPS 220 is easy to overlook because it does not carry the same headline incident clocks, but it is the connective tissue. Both CPS 230 and CPS 234 assume a functioning enterprise risk management framework: a documented risk appetite, defined three-lines-of-defence roles, and a board risk committee that receives and challenges reporting. When an assessor finds CPS 230 tolerance levels that are not traceable to any board-approved appetite statement, that is a CPS 220 gap surfacing through a CPS 230 lens. Assessing CPS 220, CPS 230 and CPS 234 together — rather than as three unrelated projects — is what stops the same weakness being reported three different ways. Our CPS 220 framework page sets out the risk-management obligations in detail.
CPS 230 commenced on 1 July 2025, with full effect and the transition of material service provider contracts to compliant terms expected by 1 July 2026. That second date is the one most entities are still working toward: existing outsourcing arrangements that were governed under the retired CPS 231 need to be re-papered against CPS 230’s material service provider requirements, and the register that underpins them has to be current, accurate and board-visible. Because CPS 230 absorbed both outsourcing (CPS 231) and business continuity (CPS 232), the evidence you built for those older standards does not disappear — it is re-purposed and extended, particularly around tolerance levels and scenario testing, which CPS 231 and CPS 232 did not demand in the same form.
The practical case for a combined gap assessment is that the three standards draw on one evidence base. A material service provider contract is CPS 230 evidence; the security clauses inside it are CPS 234 evidence; the risk-acceptance decision behind engaging that provider is CPS 220 evidence. Assessing them on a shared control base means each document is ingested once and mapped to every obligation it touches.
This is where CyberSentien fits. CyberSentien performs readiness and evidence assessment — it is not an accredited body and does not certify compliance. It reads your documents, maps them across CPS 220, CPS 230 and CPS 234, and reports what the evidence actually supports. Critically, a control that has no supporting evidence is never marked green: it reads “manual assessment required” so nothing is overstated to a board or, eventually, to APRA. Where an obligation genuinely needs an independent assurance practitioner — for example formal assurance engagements — CyberSentien prepares the readiness pack; it does not stand in for the practitioner.
If you are an APRA-regulated bank, insurer or superannuation entity, our APRA solutions page walks through how the combined assessment runs end to end against ASD’s security expectations on cyber.gov.au and the prudential standards on apra.gov.au.
CPS 230 resilience and CPS 234 security are related but not interchangeable. A single control test rarely satisfies both without mapping the intent of each obligation.
Tolerance levels and control decisions that do not trace back to a board-approved risk appetite typically read as gaps under scrutiny.
Those standards are retired. Their artefacts feed CPS 230 but must be extended with tolerance levels and scenario testing.
CPS 234 governs information security (asset classification, control testing, 72-hour incident notification). CPS 230 governs broader operational risk and resilience — critical operations, tolerance levels and material service providers. They overlap on third-party and incident obligations.
CPS 220 sets the overarching risk management framework; CPS 230 operationalises resilience within it. CPS 230 replaces the older CPS 231 outsourcing and CPS 232 business continuity standards.
Yes. CyberSentien assesses CPS 220, CPS 230 and CPS 234 from one evidence base — an advantage over single-standard tools — so shared controls are evidenced once.
If you already meet CPS 234, focus the remaining runway on CPS 230's 1 July 2026 obligations — critical operations, tolerance levels and material service provider contracts.