CPS 230 vs CPS 234 vs CPS 220 — how the APRA standards fit together

CPS 230 and CPS 234 are separate but overlapping APRA prudential standards: CPS 230 (Operational Risk Management) governs operational resilience — critical operations, tolerance levels and material service providers — while CPS 234 (Information Security) governs the security of information assets. CPS 220 (Risk Management) sits above both as the entity-wide risk framework they plug into. They share evidence but answer different questions, so an APRA-regulated entity typically needs all three assessed against one control base rather than in isolation.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

The three standards at a glance

APRA’s Cross-industry Prudential Standards (CPS) form a stack. CPS 220 sets the overarching risk management framework; CPS 230 addresses operational risk and resilience; CPS 234 addresses information security. Each has its own scope and notification obligations, and it is common for a single incident — a ransomware event, say — to trigger clocks under both CPS 230 and CPS 234 at once. Understanding where the boundaries fall is what keeps an assessment defensible.

CPS 220 — Risk Management

The entity-wide risk management framework: risk appetite, roles and responsibilities, and board oversight of material risks across the business. It is the umbrella CPS 230 and CPS 234 report up into.

CPS 230 — Operational Risk

Commenced 1 July 2025. Covers critical operations, board-approved tolerance levels, the material service provider register, and operational-risk incident notification. It replaced CPS 231 (outsourcing) and CPS 232 (business continuity).

CPS 234 — Information Security

Requires identification and classification of information assets, control implementation and testing, clear board accountability, and specific breach and control-weakness notifications to APRA.

The difference between CPS 230 and CPS 234

The cleanest way to hold the distinction is by the question each standard forces you to answer. CPS 234 asks: are your information assets secure, and can you prove the controls work? CPS 230 asks a broader operational question: can your critical operations keep running within tolerance when something breaks — including, but not limited to, a cyber event? A denial-of-service that takes payments offline is a CPS 230 resilience matter and a CPS 234 security matter simultaneously; the same evidence supports both, but the assessment lenses differ.

DimensionCPS 230 Operational RiskCPS 234 Information Security
Primary focusOperational resilience & continuity of critical operationsSecurity of information assets
Core artefactsCritical operations list, tolerance levels, material service provider registerAsset inventory & classification, control testing evidence
Board roleApproves tolerance levels; ultimately accountable for operational riskUltimately accountable for information security
Incident clockNotify as soon as possible / within 72 hours of a material operational-risk incidentNotify within 72 hours of a material incident; within 10 business days of a material control weakness
ReplacesCPS 231 (outsourcing) & CPS 232 (business continuity)N/A — standalone since 2019

You can read the standards in full on the federal register: CPS 230 and CPS 234 are published via legislation.gov.au and APRA’s own guidance sits on apra.gov.au. Our framework breakdowns for CPS 230 and CPS 234 map each obligation to the evidence that satisfies it.

Where CPS 220 fits

CPS 220 is easy to overlook because it does not carry the same headline incident clocks, but it is the connective tissue. Both CPS 230 and CPS 234 assume a functioning enterprise risk management framework: a documented risk appetite, defined three-lines-of-defence roles, and a board risk committee that receives and challenges reporting. When an assessor finds CPS 230 tolerance levels that are not traceable to any board-approved appetite statement, that is a CPS 220 gap surfacing through a CPS 230 lens. Assessing CPS 220, CPS 230 and CPS 234 together — rather than as three unrelated projects — is what stops the same weakness being reported three different ways. Our CPS 220 framework page sets out the risk-management obligations in detail.

The 2026 transition and why timing matters

CPS 230 commenced on 1 July 2025, with full effect and the transition of material service provider contracts to compliant terms expected by 1 July 2026. That second date is the one most entities are still working toward: existing outsourcing arrangements that were governed under the retired CPS 231 need to be re-papered against CPS 230’s material service provider requirements, and the register that underpins them has to be current, accurate and board-visible. Because CPS 230 absorbed both outsourcing (CPS 231) and business continuity (CPS 232), the evidence you built for those older standards does not disappear — it is re-purposed and extended, particularly around tolerance levels and scenario testing, which CPS 231 and CPS 232 did not demand in the same form.

Running a combined CPS 230 / CPS 234 gap assessment

The practical case for a combined gap assessment is that the three standards draw on one evidence base. A material service provider contract is CPS 230 evidence; the security clauses inside it are CPS 234 evidence; the risk-acceptance decision behind engaging that provider is CPS 220 evidence. Assessing them on a shared control base means each document is ingested once and mapped to every obligation it touches.

This is where CyberSentien fits. CyberSentien performs readiness and evidence assessment — it is not an accredited body and does not certify compliance. It reads your documents, maps them across CPS 220, CPS 230 and CPS 234, and reports what the evidence actually supports. Critically, a control that has no supporting evidence is never marked green: it reads “manual assessment required” so nothing is overstated to a board or, eventually, to APRA. Where an obligation genuinely needs an independent assurance practitioner — for example formal assurance engagements — CyberSentien prepares the readiness pack; it does not stand in for the practitioner.

Try it on sample docs

If you are an APRA-regulated bank, insurer or superannuation entity, our APRA solutions page walks through how the combined assessment runs end to end against ASD’s security expectations on cyber.gov.au and the prudential standards on apra.gov.au.

Common mistakes to avoid

Treating them as one project

CPS 230 resilience and CPS 234 security are related but not interchangeable. A single control test rarely satisfies both without mapping the intent of each obligation.

Forgetting CPS 220 traceability

Tolerance levels and control decisions that do not trace back to a board-approved risk appetite typically read as gaps under scrutiny.

Assuming CPS 231/232 evidence still stands alone

Those standards are retired. Their artefacts feed CPS 230 but must be extended with tolerance levels and scenario testing.

Frequently asked

What is the difference between CPS 230 and CPS 234?

CPS 234 governs information security (asset classification, control testing, 72-hour incident notification). CPS 230 governs broader operational risk and resilience — critical operations, tolerance levels and material service providers. They overlap on third-party and incident obligations.

How does CPS 230 relate to CPS 220?

CPS 220 sets the overarching risk management framework; CPS 230 operationalises resilience within it. CPS 230 replaces the older CPS 231 outsourcing and CPS 232 business continuity standards.

Can I assess CPS 230 and CPS 234 together?

Yes. CyberSentien assesses CPS 220, CPS 230 and CPS 234 from one evidence base — an advantage over single-standard tools — so shared controls are evidenced once.

Which should I prioritise first?

If you already meet CPS 234, focus the remaining runway on CPS 230's 1 July 2026 obligations — critical operations, tolerance levels and material service provider contracts.