APRA CPS 230
Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.
2026 determination (effective 2026-07-01) · Australian Prudential Regulation Authority · published 2026-04-30
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
APRA CPS 230 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
APRA publishes the in-force prudential standard and implementation guidance. Pin the 2026 clean determination before normalization.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Operational risk management · Critical operations and tolerance levels · Business continuity · Material service providers · Board oversight and reporting
- Applies to
- banking · insurance · superannuation · financial services · AU
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2023 determination (effective 2025-07-01) | Superseded | 2023-07-17 |
| 2026 determination (effective 2026-07-01) | Current edition · supersedes 2023 determination (effective 2025-07-01) | 2026-04-30 |
05Change history
06Related frameworks
- FFIEC IT Examination HandbookCurrent booklets (living collection)
Also applies to banking · The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.
- NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)
Also applies to financial services · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
- Shared Assessments SIG2026 annual release
Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.