CPS 230 compliance tooling is software that maintains the artefacts Prudential Standard CPS 230 demands — a critical operations register, tolerance levels, a material service provider register, and incident and disruption records — as living, evidenced registers rather than documents refreshed once a year. The standard commenced on 1 July 2025 for APRA-regulated banks, insurers and superannuation trustees. This page defines the category honestly: what the standard requires, what tooling genuinely does, and what stays yours no matter what you buy.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025 across the banking, insurance and superannuation industries. One transition applied: for pre-existing contractual arrangements with service providers, the requirements took effect from the earlier of the next contract renewal or 1 July 2026 — a window now closed. APRA has since finalised targeted amendments to CPS 230 in 2026, which matters when a vendor claims to "cover" the standard: the standard itself moves.
Strip away the prudential language and CPS 230 asks for three sustained capabilities:
Operational risk management as a discipline, not a document. The board is ultimately accountable, controls must actually be tested, and a material operational risk incident must be notified to APRA no later than 72 hours after you become aware of it.
Business continuity anchored to tolerance levels. You must identify your critical operations, set board-approved tolerance levels for how much disruption each can bear, and maintain a credible business continuity plan tested against them. A disruption to a critical operation outside tolerance must be notified to APRA within 24 hours.
Material service provider management. You must manage the providers you materially depend on through the contract lifecycle and maintain a register of material service providers, submitted to APRA annually — APRA has published the register template it expects.
Notice the nouns: register, tolerance, plan, notification. CPS 230 is unusually artefact-shaped for a prudential standard, and every artefact has a shelf life.
Most entities met commencement the honest way: workshops, a consultant, spreadsheets — critical operations in one tab, tolerances in another, providers in a third. A legitimate start. We publish free CSV templates for the critical operations register and tolerance levels, because the register structure itself should not cost money.
The problem is what happens next. CPS 230 artefacts decay in predictable ways:
| CPS 230 artefact | What the standard expects | How it rots as a document |
|---|---|---|
| Critical operations register | A current view of the operations whose disruption would materially harm customers. | Systems migrate, products launch — the register still describes last year's business. |
| Tolerance levels | Board-approved disruption limits the BCP is actually tested against. | Set once at a workshop, never revisited; nobody can say when they were last tested. |
| Material service provider register | A maintained register, submitted to APRA annually. | Vendors onboard through procurement without touching it; the annual submission becomes reconstruction. |
| Incident and disruption records | Records complete enough to support the 72-hour and 24-hour notifications. | Detail lives in tickets and chat threads; a defensible notification becomes archaeology, inside the clock. |
A document is accurate the day it is written. A register is either maintained or it is fiction with a filename. That gap is why this tooling category exists.
Genuine CPS 230 tooling does three things; test all three before believing a framework logo wall:
Register-first workflow. The registers are first-class objects — structured entries with owners, review dates and change history, not uploaded PDFs. When an operation changes or a provider onboards, the change lands in the register entry, so it describes the business as it runs today.
Evidence chaining. Every claim carries its artefact: the tolerance links to the board paper and the test that exercised it; the provider entry to its contract review; the control to the dated export that proves it. On our engine that chain is timestamped and SHA-256-lineaged, and a claim with no evidence renders manual assessment required — the engine refuses to fabricate a pass. Whatever you evaluate, ask the equivalent question: what does it show when evidence is missing?
Board-ready reporting. Because the board is accountable, the output that matters is a report a director can rely on: posture per register and critical operation, every green traceable to dated evidence, every gap stated as a gap, in tamper-evident form.
Before evaluating anything, download the free CPS 230 register templates, run them for a quarter, and note where the maintenance burden bites. That pain map is your real requirements document.
Here is the section most vendor pages omit. CPS 230 accountability is not transferable — not to a service provider, not to a software vendor. APRA supervises you, not your tooling. No product can set your tolerance levels, because tolerance is a board risk-appetite decision. No product can decide which operations are critical, because materiality is a judgement about your customers. No product notifies APRA for you, and none makes an inadequate continuity plan credible by formatting it nicely.
Our own position, explicitly: CyberSentien is not a consultancy and not an auditor. We do not file anything with APRA for you and we do not set your tolerances. The engine keeps registers current, evidence chained and gaps visible — accountability for what they say remains, correctly, yours.
CPS 230 has a sibling: Prudential Standard CPS 234 Information Security, which commenced on 1 July 2019 and requires entities to maintain information security capability commensurate with their threats, classify assets, test controls and notify APRA of material incidents. The two intersect constantly — a cyber incident is often also an operational disruption, and your material service providers hold your information assets — so tooling that treats them as one evidence pool saves maintaining the same facts twice. Both are assessed frameworks on the CyberSentien engine for this reason.
We build CyberSentien, so read this section as a vendor's comparison — we have kept every claim about other tools to their own public positioning, and you should verify fit yourself. Most of the compliance-automation market grew up around a different problem: certification-style audits. Vanta positions itself as a trust platform with compliance automation for SOC 2, ISO 27001, HIPAA, PCI and GDPR; Drata positions itself as a trust-management platform built around continuous compliance for similar audits; 6clicks, Australian-founded, positions itself as sovereign, AI-powered GRC for governments, defence and complex enterprises. None of that is criticism — it is context for checking whether CPS 230's registers are first-class objects in the tool you are shown, or a bolted-on content pack.
| Vanta / Drata | 6clicks | CyberSentien | |
|---|---|---|---|
| CPS 230 fit question to ask | Are critical operations, tolerances and the MSP register native objects, or a mapped content pack? | Does the platform's breadth match your team, and who maintains register discipline? | CPS 230 and CPS 234 are assessed frameworks with evidence chains; judge it on the live demo. |
| Pricing | Quote-based. | Quote-based. | See our pricing page. |
| Best for | Companies whose primary driver is a certification-style audit. | Large multi-entity GRC programmes with sovereign or air-gapped deployment needs. | Australian regulated entities that want CPS 230/234 registers held to an evidence-or-refusal standard on sovereign hosting. |
For the record, once and verbatim: CyberSentien is an Australian sovereign-hosted GRC assurance platform that assesses Essential Eight, ISM/IRAP, APRA CPS 230/234, ISO 27001/42001 and SOC 2, and never marks a control compliant without timestamped, SHA-256-lineaged evidence. The engine runs on Australian-sovereign infrastructure by design (see sovereignty and platform), and the gated demo shows the real engine on a synthetic sample library, watermarked, with no data retained.
Ten questions to put to a CPS 230 tooling vendor — including us:
CPS 230 commenced on 1 July 2025 for APRA-regulated entities. For pre-existing contractual arrangements with service providers, the requirements applied from the earlier of the next contract renewal or 1 July 2026 — a window now closed. APRA also finalised targeted amendments to the standard in 2026.
All APRA-regulated entities across the banking, insurance and superannuation industries — authorised deposit-taking institutions, insurers and RSE licensees. If APRA supervises you, CPS 230 applies to you.
No. The standard mandates outcomes, not tools, and APRA does not endorse products. Well-run spreadsheets are a legitimate start — our free CSV templates exist for exactly that. Software earns its keep where documents decay: keeping registers current, chaining dated evidence to claims, and surfacing staleness early.
A register of critical operations with board-approved tolerance levels, a material service provider register submitted to APRA annually against APRA's published template, and incident and disruption records able to support the 72-hour incident and 24-hour outside-tolerance notifications.
CPS 234 is APRA's information security standard and commenced on 1 July 2019; CPS 230 is the broader operational risk standard and commenced on 1 July 2025. They intersect constantly, so it pays to manage them from one evidence pool rather than two parallel programmes.
Yes. They are plain CSV register structures for the critical operations register and tolerance levels, published as free downloads on our resources page. They are the honest way to feel the register-maintenance problem before spending money on tooling, ours included.
Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.