APRA CPS 230 Operational Risk Management
Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Assurance
| Code | Title |
|---|---|
| CPS230-66 | Independent Review |
Business Continuity
| Code | Title |
|---|---|
| CPS230-25 | Business Continuity Policy |
| CPS230-26 | Business Continuity Plans |
| CPS230-27 | Incident Management |
| CPS230-28 | Recovery Objectives |
| CPS230-29 | Communication Plans |
| CPS230-30 | Risk Culture |
| CPS230-31 | Escalation Procedures |
| CPS230-32 | Dependencies Identification |
| CPS230-33 | BCP Testing |
| CPS230-34 | Tailored Testing Programs |
| CPS230-36 | Tolerance Levels for Disruption |
| CPS230-38 | Business Continuity Plan |
Business Continuity
Requirements for business continuity planning (Paragraphs 25-36)
| Code | Title |
|---|---|
| CPS230-25 | Business Continuity Policy |
| CPS230-26 | Business Continuity Plans |
| CPS230-27 | Incident Management |
| CPS230-28 | Recovery Objectives |
| CPS230-29 | Communication Plans |
| CPS230-30 | Risk Culture |
| CPS230-31 | Escalation Procedures |
| CPS230-32 | Dependencies Identification |
| CPS230-33 | BCP Testing |
| CPS230-34 | Tailored Testing Programs |
| CPS230-36 | Tolerance Levels for Disruption |
| CPS230-38 | Business Continuity Plan |
Controls
| Code | Title |
|---|---|
| CPS230-24 | Internal Controls |
Critical Operations
Requirements for identifying and managing critical operations (Paragraphs 17-24)
| Code | Title |
|---|---|
| CPS230-17 | Critical Operations Identification |
| CPS230-18 | Critical Operations Register |
| CPS230-19 | Critical Operation Tolerance Levels |
| CPS230-20 | Capability to Remain Within Tolerance |
| CPS230-22 | Vulnerability and Gap Identification |
| CPS230-23 | Regular Testing |
| CPS230-24 | Internal Controls |
Governance
| Code | Title |
|---|---|
| CPS230-13 | Board Accountability |
| CPS230-14 | Senior Management Roles |
| CPS230-30 | Risk Culture |
Operational Risk Management Framework
Requirements for establishing and maintaining an operational risk management framework (Paragraphs 7-16)
| Code | Title |
|---|---|
| CPS230-10 | Operational Risk Management Policy |
| CPS230-11 | Risk Identification and Assessment |
| CPS230-12 | Internal Controls and Systems |
| CPS230-13 | Board Accountability |
| CPS230-14 | Senior Management Roles |
| CPS230-15 | Operational Risk Framework |
| CPS230-16 | Internal Audit Review |
| CPS230-7 | Board Responsibility |
| CPS230-8 | Board Tolerance Levels |
| CPS230-9 | Senior Management Accountability |
Operations
| Code | Title |
|---|---|
| CPS230-27 | Incident Management |
| CPS230-70 | Change Management |
Regulatory
| Code | Title |
|---|---|
| CPS230-60 | APRA Notification of Provider Arrangements |
Reporting
| Code | Title |
|---|---|
| CPS230-63 | Operational Risk Reporting |
Risk Management
| Code | Title |
|---|---|
| CPS230-15 | Operational Risk Framework |
Service Provider Management
Requirements for managing material service providers (Paragraphs 37-49)
| Code | Title |
|---|---|
| CPS230-37 | Service Provider Management Policy |
| CPS230-38 | Business Continuity Plan |
| CPS230-39 | Material Service Provider Identification |
| CPS230-40 | Material Classification |
| CPS230-42 | APRA Classification Power |
| CPS230-43 | Due Diligence |
| CPS230-44 | Service Provider Risk Identification |
| CPS230-45 | APRA Access Provisions |
| CPS230-46 | Ongoing Risk Management |
| CPS230-47 | Monitoring and Reporting |
| CPS230-48 | Service Provider Due Diligence |
| CPS230-49 | Internal Audit of Service Providers |
Third Party
| Code | Title |
|---|---|
| CPS230-44 | Service Provider Risk Identification |
| CPS230-48 | Service Provider Due Diligence |
| CPS230-50 | Service Provider Contracts |
| CPS230-53 | Service Provider Monitoring |
| CPS230-57 | Concentration Risk |
Your Compliance Coverage
If you comply with APRA CPS 230 Operational Risk Management, you already cover:
NIST SP 800-53 Rev 5
55%
26 controls mapped
Compare →FedRAMP Rev 5
19%
9 controls mapped
Compare →Annex 11 to EU GMP - Computerised Systems
19%
9 controls mapped
Compare →+ 255 more: NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (17%), NIST Privacy Framework (17%)
See all 258 mapped frameworks ↓Maps to 258 other frameworks
Frequently Asked Questions
What is APRA CPS 230 Operational Risk Management?
APRA CPS 230 Operational Risk Management is a compliance framework from Australia with 13 domains and 57 controls. Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does APRA CPS 230 Operational Risk Management have?
APRA CPS 230 Operational Risk Management has 57 controls organised across 13 domains. The largest domains are Service Provider Management (12 controls), Business Continuity (11 controls), Operational Risk Management Framework (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does APRA CPS 230 Operational Risk Management map to?
APRA CPS 230 Operational Risk Management maps to 258 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (55% coverage), FedRAMP Rev 5 (19% coverage), Annex 11 to EU GMP - Computerised Systems (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with APRA CPS 230 Operational Risk Management compliance?
Start your APRA CPS 230 Operational Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 230 Operational Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required