APRA CPS 230 Operational Risk Management
Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Business Continuity
Requirements for business continuity planning (Paragraphs 25-36)
| Code | Title |
|---|---|
| CPS230-25 | Business Continuity Policy |
| CPS230-26 | Business Continuity Plans |
| CPS230-27 | BCP Scope |
| CPS230-28 | Recovery Objectives |
| CPS230-29 | Communication Plans |
| CPS230-30 | Alternative Arrangements |
| CPS230-31 | Escalation Procedures |
| CPS230-32 | Dependencies Identification |
| CPS230-33 | BCP Testing |
| CPS230-34 | Tailored Testing Programs |
| CPS230-35 | Annual BCP Updates |
| CPS230-36 | BCP Internal Audit |
Critical Operations
Requirements for identifying and managing critical operations (Paragraphs 17-24)
| Code | Title |
|---|---|
| CPS230-17 | Critical Operations Identification |
| CPS230-18 | Critical Operations Register |
| CPS230-19 | Critical Operation Tolerance Levels |
| CPS230-20 | Capability to Remain Within Tolerance |
| CPS230-21 | Scenario Analysis |
| CPS230-22 | Vulnerability and Gap Identification |
| CPS230-23 | Regular Testing |
| CPS230-24 | APRA Critical Operation Notification |
Operational Risk Management Framework
Requirements for establishing and maintaining an operational risk management framework (Paragraphs 7-16)
| Code | Title |
|---|---|
| CPS230-10 | Operational Risk Management Policy |
| CPS230-11 | Risk Identification and Assessment |
| CPS230-12 | Internal Controls and Systems |
| CPS230-13 | Incident Management |
| CPS230-14 | APRA Notification |
| CPS230-15 | Monitoring and Reporting |
| CPS230-16 | Internal Audit Review |
| CPS230-7 | Board Responsibility |
| CPS230-8 | Board Tolerance Levels |
| CPS230-9 | Senior Management Accountability |
Service Provider Management
Requirements for managing material service providers (Paragraphs 37-49)
| Code | Title |
|---|---|
| CPS230-37 | Service Provider Management Policy |
| CPS230-38 | Policy Coverage |
| CPS230-39 | Material Service Provider Identification |
| CPS230-40 | Material Classification |
| CPS230-41 | Annual Register Submission |
| CPS230-42 | APRA Classification Power |
| CPS230-43 | Due Diligence |
| CPS230-44 | Formal Agreements |
| CPS230-45 | APRA Access Provisions |
| CPS230-46 | Ongoing Risk Management |
| CPS230-47 | Monitoring and Reporting |
| CPS230-48 | APRA Notification of Arrangements |
| CPS230-49 | Internal Audit of Service Providers |
Maps to 534 other frameworks
Frequently Asked Questions
What is APRA CPS 230 Operational Risk Management?
APRA CPS 230 Operational Risk Management is a compliance framework from Australia with 4 domains and 43 controls. Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does APRA CPS 230 Operational Risk Management have?
APRA CPS 230 Operational Risk Management has 43 controls organised across 4 domains. The largest domains are Service Provider Management (13 controls), Business Continuity (12 controls), Operational Risk Management Framework (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does APRA CPS 230 Operational Risk Management map to?
APRA CPS 230 Operational Risk Management maps to 534 other compliance frameworks. The top mapping partners are NIS2 Directive Implementing Acts (26% coverage), Defence Security Principles Framework (DSPF) (26% coverage), Protective Security Policy Framework (PSPF) Release 2024 (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with APRA CPS 230 Operational Risk Management compliance?
Start your APRA CPS 230 Operational Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 230 Operational Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required