Skip to main content
Framework library
Framework module · apra-cps-230-2026

APRA CPS 230

Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

2026 determination (effective 2026-07-01) · Australian Prudential Regulation Authority · published 2026-04-30

Standing today
Directory entry

00Answer

from the registry record
What is APRA CPS 230?
Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.
Who does APRA CPS 230 apply to?
APRA CPS 230 applies to banking, insurance, superannuation, financial services, AU, per Australian Prudential Regulation Authority.
What is the current version of APRA CPS 230?
The current edition is 2026 determination (effective 2026-07-01), issued by Australian Prudential Regulation Authority and published 2026-04-30. Source: https://www.apra.gov.au/standards/cps-230.
What does an assessment under APRA CPS 230 require?
No control catalog has been ingested for APRA CPS 230 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

APRA CPS 230 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

APRA publishes the in-force prudential standard and implementation guidance. Pin the 2026 clean determination before normalization.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Operational risk management · Critical operations and tolerance levels · Business continuity · Material service providers · Board oversight and reporting
Applies to
banking · insurance · superannuation · financial services · AU
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
2023 determination (effective 2025-07-01)Superseded2023-07-17
2026 determination (effective 2026-07-01)Current edition · supersedes 2023 determination (effective 2025-07-01)2026-04-30

05Change history

06Related frameworks

scored from registry facts
  1. FFIEC IT Examination HandbookCurrent booklets (living collection)

    Also applies to banking · The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.

  2. NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)

    Also applies to financial services · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.

  3. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

  4. Shared Assessments SIG2026 annual release

    Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

APRA CPS 230 | ControlFrame