CPS 230 makes operational resilience a board-owned obligation — critical operations, tolerance levels and material service providers all need evidence, not assertions. CPS 234 tripartite reviews ask for an information-security posture you can defend line by line. Most institutions still answer with spreadsheets assembled the week before the review.
Book a demo → Try it on sample docsLicence-gated catalogues carry control IDs and CyberSentien's own labels only — the full standard text requires your licence and is never reproduced.
The APRA lane — APRA CPS 230 (Operational Risk), APRA CPS 234 (Information Security), APRA CPS 220 (Risk Management / Model Risk) — is Australian by design: that is the wedge, stated plainly. The same evidence base renders the internationally used instruments a banking group answers to beyond Australia — ISO/IEC 27001:2022, SOC 1 (ISAE 3402), SOC 2 (Trust Services Criteria), PCI DSS v4.0.1 — so one assessment run reports across jurisdictions without re-assessing.
Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.
Yes — plus CPS 220. Banks and ADIs assess operational resilience and information security from one evidence base, producing board and regulator packs with tamper-evident lineage.
No. CyberSentien is the evidence layer a bank or its reviewer works from. It does not replace an APRA-appointed independent reviewer or the board's accountability.
Yes. CyberSentien is AU-sovereign and runs AI inside the client boundary, avoiding the offshore data-residency and Cloud Act exposure of US-hosted platforms.
Evidence-led posture against CPS 230/234, critical operations and material service provider registers, tolerance levels, open gaps and remediation — defensible line by line.