CPS 231, APRA’s prudential standard on outsourcing, is superseded by CPS 230 Operational Risk Management. CPS 230 commenced on 1 July 2025, and on that date CPS 231 and CPS 232 (business continuity) were revoked and ceased to apply. A transition period runs to 1 July 2026 for bringing existing material service provider contracts into line with the new standard. The obligations that governed outsourcing arrangements are folded into a single, broader operational-risk regime built around critical operations, board-approved tolerance levels and a register of material service providers.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
CPS 231 treated outsourcing as a discrete activity: identify a material business activity, run due diligence, sign a compliant contract, and notify APRA of material arrangements. CPS 230 reframes the question. Instead of asking “is this activity outsourced?”, it asks “which of our operations are critical, and which providers — internal or external — do those operations depend on?” The provider register is now anchored to the resilience of end-to-end operations rather than to the legal form of an outsourcing contract. APRA has published the standard and its guidance at apra.gov.au; the operative instrument is available at legislation.gov.au.
Material business activities, outsourcing policy, due-diligence and contract requirements, notification of new or materially changed arrangements.
Business continuity management, critical business functions, recovery objectives, and BCP testing.
Consolidates both, adds critical operations, board-approved tolerance levels, a material service provider register, scenario analysis and incident notification.
The clearest way to plan a transition is to map the old obligation to where it now lives under CPS 230. The mechanics are similar in places, but the framing, the accountability chain and the notification triggers are materially different.
| Dimension | CPS 231 | CPS 230 |
|---|---|---|
| Unit of analysis | Material business activity that is outsourced | Critical operations and the services they depend on |
| Provider scope | External outsourcing providers | Material service providers, including some intra-group and fourth-party dependencies |
| Register | Records of material outsourcing arrangements | Formal register of material service providers |
| Board role | Approve outsourcing policy | Approve tolerance levels for disruption to each critical operation |
| Notification | Notify APRA of material arrangements | Notify APRA as soon as possible and within 72 hours of a material operational-risk incident |
Under CPS 231 a register of outsourcing arrangements was largely a compliance artefact. Under CPS 230 the material service provider register becomes an operational control. A provider is material where a failure or disruption would have a significant impact on a critical operation, or otherwise on the entity’s risk profile. APRA expects entities to have identified their critical operations, set board-approved tolerance levels for how long and to what extent each can be disrupted, and traced those operations down to the providers — and, in some cases, the providers’ own critical suppliers.
If your programme was built around CPS 231, the work is not thrown away — it is re-anchored. Your outsourcing inventory becomes the seed for the material service provider register, but it needs to be re-cut against critical operations rather than legal contract type. The gaps most commonly surfaced are missing tolerance levels, intra-group dependencies that were never treated as “outsourced”, and contracts that lack the resilience, notification and access clauses CPS 230 expects. APRA has signalled a supervisory focus on how boards evidence their tolerance-level decisions, not merely that a register exists. The CPS 230 framework overview walks through the full obligation set, and our CPS 230 templates give you a register and tolerance-level structure to start from.
A practical sequence: confirm your critical operations and tolerance levels; map each to its material service providers; reconcile that map against your old CPS 231 register to find what was missed; then evidence each obligation. Where a control is claimed but no evidence exists, treat it as open — a register entry with no contract on file, or a tolerance level with no board minute behind it, is a finding, not a pass.
CyberSentien performs readiness and evidence assessment against CPS 230 — it does not certify, and prudential compliance is a matter between the entity and APRA. What the platform does is take your policies, contracts, registers and board papers and test each CPS 230 obligation against the evidence actually present. Controls that have no supporting artefact are marked “manual assessment required” rather than shown as satisfied, so you never get a false green. That is deliberately different from a checklist that turns a self-attestation into a tick. For a supersession like CPS 231 to CPS 230, the value is in seeing exactly which of your existing outsourcing artefacts carry over as evidence and which obligations — tolerance levels, incident-notification runbooks, intra-group dependencies — are still unevidenced.
Read CPS 230 and its supporting guidance directly from APRA at apra.gov.au, and the legislative instrument at legislation.gov.au, before finalising any transition decision. The dates and obligation set above reflect the standard as it stands for the 1 July 2026 effective point; confirm the current text for your specific entity type and circumstances.
CPS 231 (outsourcing) and CPS 232 (business continuity) are superseded by CPS 230, which takes full effect on 1 July 2026. Buyers searching CPS 231 should plan against CPS 230.
CPS 230 broadens the scope from outsourcing arrangements to all material service providers, adds critical operations mapping, board-approved tolerance levels and stronger contract and notification requirements.
Pre-existing contracts must be brought into line with CPS 230 by 1 July 2026 or their next renewal, including the mandatory clauses and APRA access rights.