Skip to main content


      Strengthening your operational risk and resilience practices

      The Australian Prudential Regulation Authority (APRA) release of cross-industry Prudential Standard CPS 230 Operational Risk Management is designed to strengthen operational risk management and resilience across APRA-regulated entities.

      CPS 230 applies to entities in financial services including banking, insurance and superannuation fund organisations.

      The standard underpins CPS 220 Risk Management and replaces several existing standards including CPS/SPS 232 Business Continuity management and CPS/SPS/HPS 231 Outsourcing.

      If you need help with CPS 230 compliance, uplift, or testing, contact us.



      Final guidance for APRA's Prudential Practice Guide CPG 230

      On 30 April 2026, APRA released final targeted amendments to Prudential Practice Guide CPG 230 Operational Risk Management (CPG 230). The updated CPG 230 commenced on 1 July 2026 and provides further clarity on APRA’s expectations for operational risk resilience, service provider risk management and ongoing compliance. This guidance reinforces APRA’s focus on ensuring APRA-regulated entities can maintain critical operations through disruption while taking a proportionate, risk-based approach to implementation.

      Key areas of focus include:

      • Proportionate implementation

        The guidance reinforces that CPS 230 applies to all APRA-regulated entities, but implementation should be proportionate to the organisation’s size, complexity and risk profile. APRA’s expectations remain outcomes-focused, providing flexibility in how entities achieve resilience objectives while maintaining effective risk management practices.

      • Exempt service provider arrangements

        A significant enhancement introduced through the 2026 amendments is the introduction of limited exemptions from specific contractual requirements for material arrangements with certain categories of service providers where contractual compliance is not practicable. The updated CPG 230 provides additional guidance on APRA’s expectations for managing risks associated with these arrangements, ensuring that entities maintain appropriate oversight and risk management even where contractual requirements do not fully apply.



      CPS 230 timeline

      • April 2023

        APRA announces revised implementation table

      • June 2024

        Release of final CPS 230

      • Mid-2024

        Material service providers / critical operations identified*

      • End of 2024

        Entities positioned to set tolerance levels*

      • 1 July 2025

        CPS 230 commences*

      • 1 July 2026

        CPS 230 all requirements in effect for all entities

       

      * Proactive transition period, regulated entitites prepare for new requirements



      Key considerations for CPS 230

      With CPS 230 now fully in effect, APRA-regulated entities should be focused on demonstrating sustainable compliance and operational resilience outcomes. Since 1 July 2026, all CPS 230 requirements apply across the industry, including those that were subject to transitional arrangements for non-significant financial institutions. APRA’s focus has increasingly shifted towards evidence of effective implementation, resilience testing, governance, and ongoing management of operational risk and service provider arrangements.

      Key themes of CPS 230 to consider include:

      • Be prepared for risk events

        Entities must ensure they have an effective process to support the management and response to risk events, effectively reducing their impact.

      • Know your customer and market impacting Critical Operations

        Entities must have an end-to-end understanding of critical operations and the associated resources which are critical to the operation to ensure appropriate mitigating controls are in place to prevent disruption and manage risk within appetite.

      • Be resilient

        Entities must be able to continue to operate through the ever-increasing breadth of disruption, providing critical services to their customers and the market.

      • Protect the entity and the community

        Business Continuity Planning and exercising will be critical to ensure that the impact of disruptions is minimised to an acceptable/tolerable level.

      • Effectively manage service provider risk

        Entities must ensure they have processes in place to identify, assess, manage, and govern service providers that are critical to service delivery or pose a material risk.



      CPS 230 compliance: Areas of focus

      • Operating model

        Ensure you have a future fit target operating model with clear roles and responsibilities.

      • Critical operations identification

        Define the methodology and approach to identify your critical operations.

      • Service providers

        Enhance your frameworks, identification and risk management relating to material service providers.

      • Recovery of critical operations

        Utilise existing business continuity and IT disaster recover capabilities to support the recovery of critical operations.

      • Incident escalation

        Implement an effective incident management approach to ensure escalation and notification to APRA within timeframe.

      • Controls management

        Develop a robust controls management approach to ensure the controls mitigating your critical operations are tested frequently, weaknesses identified and plans in place to remediate.



      CPS 230 operational risk management implementation

      KPMG’s experienced risk and resilience teams support Global Financial Services clients throughout Australia, Europe, the United Kingdom and APAC to respond to evolving regulation and framework changes and implementation of operational risk management and resilience practices.

      While many organisations have achieved baseline compliance, operational resilience remains a multi-year journey. Leading organisations are continuing to mature their frameworks, strengthen end-to-end process and resource mapping, enhance resilience testing programs, improve service provider oversight, and leverage better data and reporting to support informed decision-making. These investments not only support compliance with CPS 230 but also help organisations build greater resilience, protect customers and stakeholders, and improve their ability to respond to an increasingly complex risk environment.


      Related insights

      Something went wrong

      Oops!! Something went wrong, please try again

      Prudential Standard CPS 230 FAQs

      The standard applies to all APRA-regulated entities which includes:

      • Banking – Authorised deposit-taking institutions (ADIs), including Foreign ADIs, and non-operating holding companies (NOHCs)
      • General Insurance – Including Category C insurers, NOHCs and parent entities of Level 2 insurance groups
      • Life Insurance – Including friendly societies, eligible foreign insurance companies (EFLICs) and NOHCs
      • Private Health Insurance – Registered under the PHIPS Act
      • Superannuation – Registerable superannuation entity licensees (RSE licensees)

      The standard is relevant for the Australian branch operations for foreign ADI, Category C insurer and EFLIC entities. Where the entity is the Head of a Group, it must comply with CPS 230.

      As part of APRA's plan to modernise the architecture of prudential standards and guidance for banks, insurers and superannuation funds, CPS 230 Operational Risk Management is a combination of five existing APRA standards, these being:

      • CPS 231 Outsourcing
      • CPS 232 Business Continuity Management
      • SPS 231 Outsourcing (Superannuation)
      • SPS 232 Business Continuity Management (Superannuation)
      • HPS 231 Outsourcing (Private Health Insurance)

      This standard aims to ensure banks, insurers and superannuation funds better manage operational risk, the ability to respond to business disruption and manage the risks from the use of service providers.



      Get in touch

      Gavin Rosettenstein

      Partner, Third Party Risk Management

      KPMG Australia

      Matt Tottenham

      Partner, Risk Strategy & Technology

      KPMG Australia