The date for compliance with the Australian Prudential Regulation Authority’s (APRA) Prudential Standard CPS 230 Operational Risk Management (CPS 230) for APRA‑regulated entities and their material service providers is rapidly approaching. If your organisation is a material service provider to an APRA‑regulated entity, your deadline to engage with those entities and finalise amendments to contracts for material arrangements is 1 July 2026.
Material service providers that fail to engage meaningfully with APRA-regulated entities and APRA-regulated entities that fail to meaningfully engage with these reforms risk being left behind and losing business to competitors who do.
This article discusses the key CPS 230 requirements relevant to material service providers and the actions required by both them and APRA‑regulated entities to ensure they remain compliant.
Recap: What is CPS 230?
CPS 230 requires APRA‑regulated entities to identify, assess and manage operational risks so they can continue to serve customers even during periods of severe disruption. It follows on from the introduction of other similar reforms around the globe in recent times, with its main objectives being to:
- strengthen operational risk management and ensure weaknesses in controls are identified and addressed;
- improve business continuity to support service continuation during severe disruption;
- ensure material arrangements with material service providers are appropriately managed; and
- enhance board governance and accountability.
Since 1 July 2025, APRA-regulated entities have been required to bring material arrangements with material service providers into line with CPS 230 requirements by the earlier of the next renewal of the relevant material arrangement or 1 July 2026. In some instances, this has forced a complete rethink of commercial terms, risk allocation, audit and access rights, business continuity obligations and subcontracting controls, and even exit planning where negotiations fall short of the requirements and how those exits impact the business.
Who does CPS 230 target?
CPS 230 directly targets APRA-regulated entities and requires them to adopt an operational risk management approach appropriate to its size, business mix and complexity, to help ensure the resilience and continuity of their critical operations.1 As part of this, it requires APRA-regulated entities to manage (and submit and maintain a register to APRA of) their material service providers. By doing so it draws certain in-scope third parties (i.e. these material service providers) into the remit of the CPS 230 regulatory ecosystem through flow-down obligations imposed on them in their material arrangements by the APRA-regulated entity.
Importantly:
- “material service providers” are those third parties, related entities, or connected entities, that an APRA‑regulated entity relies on to perform a critical operation or that exposes it to material operational risk; and
- “material arrangements” are those arrangements that an APRA-regulated entity relies on to undertake a critical operation or that exposes it to material operational risk.
As such, service providers across areas such as technology, business process outsourcing, data and analytics, infrastructure, professional services, and other operational support functions may be considered a “material service provider” if their failure could affect an APRA-regulated entity’s ability to deliver its own services or materially increases its own operational risk.
CPS 230 also requires APRA-regulated entities to have a service provider management policy that addresses their approach to managing risk associated with fourth parties in its supply chain (a fourth party being a party that a material service provider relies on to deliver a critical operation to the APRA-regulated entity).
The upshot of all these requirements is that a wide range of providers (not just the APRA-regulated entities) may be impacted (whether directly or indirectly) by CPS 230.
What is a ‘critical operation’?
Critical operations are those processes undertaken by an APRA-regulated entity or its service providers which, if disrupted beyond certain tolerance levels determined by the APRA-regulated entity, would have a material adverse impact on its customers or other beneficiaries, or its role in the broader financial system.
The APRA-regulated entity must establish tolerance levels for each critical operation that define the maximum period of time a disruption to the critical operation would be tolerated, the maximum extent of data loss that would be acceptable because of a disruption, and the minimum service levels that must be maintained while operating under alternative arrangements during a disruption.
Although this exercise gives APRA-regulated entities flexibility in determining what constitutes a critical operation, CPS 230 mandates certain processes as critical operations and also empowers APRA to require that APRA-regulated entities classify certain business operations as critical operations.
Key contractual requirements for material arrangements
APRA-regulated entities must conduct due diligence on their service providers to assess the financial and non-financial risks associated with placing reliance on that service provider, before entering or materially modifying material arrangements (per paragraph 53 of CPS 230). Material service providers need to be aware that for any new material arrangements or modifications to existing material arrangements, APRA-regulated entities must (at a minimum):
- Contractual Requirements: Maintain a legally binding agreement with the material service provider which addresses the services and associated service levels, the parties’ rights and responsibilities, requires notification of use of other material service providers, requires that the service provider is liable for any failure by a subcontractor, ensures the ability of the APRA-regulated entity to meet its legal and compliance obligations, includes a force majeure provision, and includes termination provisions (paragraph 54).
- Regulatory Access: Ensure that the material arrangement allows APRA access to information and onsite visits and that the material service provider does not obstruct APRA in fulfilling its regulatory duties (paragraph 55).
- Risk Management and Exit Planning: Identify and manage risks for each material arrangement and ensure they maintain the ability to execute business continuity plans and exit arrangements effectively (paragraph 56).
- Monitoring and Performance: Monitor material arrangements on an ongoing basis including performance, the effectiveness of risk management controls, and contractual compliance (paragraph 58).
- Internal Audit: Ensure there is an internal audit function to review any proposed material arrangement involving the outsourcing of a critical operation, and regularly report to the Board or Board Audit Committee on compliance with its service provider management policy (paragraph 60).
The impact of CPS 230 and what it means in practice
CPS 230 represents a structural shift in APRA’s approach to shoring up the operational resilience of the financial services sector. It replaces and consolidates a wide suite of previous standards and guidance.2 Unlike previous prudential standards which were fragmented and treated outsourcing rules and business continuity management as largely separate compliance exercises, CPS 230 recognises that modern financial services rely on deep, complex webs of third-party service providers to function. It forces each APRA-regulated entity to consider whether its third-party arrangements provide sufficient resiliency for it to be able to maintain critical operations within defined disruption tolerances.
By way of updated contractual arrangements, material service providers working with APRA‑regulated entities will be required to uplift operational capabilities to ensure they do not create vulnerability in the APRA-regulated entity’s ability to maintain its critical operations through disruption. A material service provider to an APRA-regulated entity may also be required to flow CPS 230‑aligned obligations into arrangements with its service provider supply chain (being fourth parties to the APRA-regulated entity) so that critical operations can be maintained within the tolerance levels established by the APRA‑regulated entity.
The consequences of a breach of CPS 230 are serious for the APRA-regulated entity and can give rise to criminal or civil consequences, as well as administrative action including licence conditions, enforceable undertakings, or removal of a license. If an APRA-regulated entity operates on the Australian Securities Exchange (ASX), non‑compliance can result in warnings, additional capital requirements, independent reviews, and in serious cases, fines, suspension or termination of participation rights, or referral to the Australian Securities and Investment Commission (ASIC). Separately, there is the reputational damage an APRA-regulated entity may suffer because of operational disruption that may have otherwise been preventable had an appropriate risk management and business continuity framework been in place.
Practically, CPS 230 compliance brings a significant volume of work for APRA-regulated entities in identifying and staying on top of all material service providers, with ongoing monitoring needed to ensure material arrangements are progressing in line with APRA’s expectations. This requires strong leadership, clear ownership, and coordination by those driving the APRA-regulated entity’s contract uplifts. In addition, CPS 230 is prompting closer scrutiny of intra‑group service structures, with clients recognising that internal arrangements with material service providers must now be negotiated with the same level of rigour as material arrangements with external providers. CPS 230 is therefore having (and will continue to have) a material impact on the Australian market and is driving industry‑wide contract uplift programs initiated by APRA-regulated entities, with material service providers taking subsequent responsibility for corresponding improvements in their own operations to ensure ongoing contractual compliance.
What is next
APRA’s 2025-26 Corporate Plan (Plan) announced that two key strategic objectives for the coming years are (1) maintaining financial and operational resilience and (2) responding to significant and emerging risks. The Plan confirms that APRA-regulated entities can expect a strong supervisory focus on CPS 230, with early engagement directed at significant financial institutions. There is also a strong focus towards strengthening and uplifting cyber resilience within APRA-regulated entities.
For APRA-regulated entities, it will be important over the coming months to continue progressing their CPS 230 uplift programs, including strengthening cyber controls, to close any remaining gaps and ensure they fully meet APRA and their client’s expectations. From a material service provider perspective, it will be important to actively engage with APRA‑regulated clients to negotiate and agree necessary amendments to material arrangements ahead of 1 July 2026.
If you are an APRA-regulated entity or providing services to an APRA-regulated entity and want to discuss how to comply with CPS 230 and understand what the regulatory landscape means for your business, please get in touch with our experts, Alex Hutchens, Nikhil Ullal and Tom Marshall.
- There is a targeted exemption from certain contractual and notification requirements under CPS 230 for material arrangements with specified categories of non‑traditional service providers (NTSPs) and where the arrangement uses standardised, non‑negotiable terms or is not documented in a formal agreement. However, all other CPS 230 obligations continue to apply to those APRA-regulated entities. APRA may also, by written notice, exempt a material arrangement with a service provider from specified CPS 230 contractual and notification requirements, even where the arrangement falls outside the NTSP exempt categories. ↩︎
- The standards and guidance that were consolidated and have been replaced include CPS 231 (Outsourcing); CPS 232 (Business Continuity Management); SPS 231 (Outsourcing); SPS 232 (Business Continuity Management); HPS 231 (Outsourcing); GPG 230 (Operational Risk); LPG 230 (Operational Risk); CPG 231 (Outsourcing); SPG 231 (Outsourcing); and SPG 232 (Business Continuity Management). ↩︎