APRA CPS 230 Operational Risk Management
Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025.
APRA CPS 230 Operational Risk Management is a compliance framework from Australia with 11 domains and 43 controls that map to 265 other frameworks. The largest domains are Operational Risk Management Framework (12 controls), Service Provider Management (10 controls), Business Continuity (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Assurance
| Code | Title |
|---|---|
| CPS230-66 | Review of Operational Risk Management |
Business Continuity
| Code | Title |
|---|---|
| CPS230-26 | Critical Operations Register, Continuity Plan and Activation |
| CPS230-27 | Identification and Escalation of Incidents and Near Misses |
| CPS230-33 | Systematic BCP Testing Program |
| CPS230-34 | Tailoring of the Testing Program |
| CPS230-P40 | Required Content of the Business Continuity Plan |
| CPS230-P41 | BCP Execution Capability and Tolerance Breach Reporting |
| CPS230-P45 | Annual Update of the Business Continuity Plan |
Business Continuity
Requirements for business continuity planning (Paragraphs 25-36)
| Code | Title |
|---|---|
| CPS230-26 | Critical Operations Register, Continuity Plan and Activation |
| CPS230-27 | Identification and Escalation of Incidents and Near Misses |
| CPS230-33 | Systematic BCP Testing Program |
| CPS230-34 | Tailoring of the Testing Program |
| CPS230-P40 | Required Content of the Business Continuity Plan |
| CPS230-P41 | BCP Execution Capability and Tolerance Breach Reporting |
| CPS230-P45 | Annual Update of the Business Continuity Plan |
Controls
| Code | Title |
|---|---|
| CPS230-P30 | Monitoring, Review and Testing of Control Effectiveness |
| CPS230-P31 | Remediation of Material Operational Risk Weaknesses |
Critical Operations
Requirements for identifying and managing critical operations (Paragraphs 17-24)
| Code | Title |
|---|---|
| CPS230-17 | Mandatory Minimum Classification of Critical Operations |
| CPS230-19 | Tolerance Levels for Each Critical Operation |
| CPS230-20 | Prevention, Adaptation and Return to Normal Operations |
| CPS230-24 | Design and Embedding of Internal Controls |
Governance
| Code | Title |
|---|---|
| CPS230-P23 | Senior Management Information to the Board on Resilience Decisions |
Operational Risk Management Framework
Requirements for establishing and maintaining an operational risk management framework (Paragraphs 7-16)
| Code | Title |
|---|---|
| CPS230-11 | Identification, Assessment and Management of Operational Risk |
| CPS230-13 | Board Accountability for Operational Risk Management |
| CPS230-14 | Board Setting of Senior Manager Roles and Responsibilities |
| CPS230-15 | Operational Risk Elements of the Risk Management Framework |
| CPS230-16 | Internal Audit Review of the Business Continuity Plan |
| CPS230-8 | Board Oversight, Approval of the BCP, Tolerance Levels and Service Provider Policy |
| CPS230-9 | Management of the Full Range of Operational Risks |
| CPS230-P12 | Key Principles for Operational Risk, Resilience and Service Providers |
| CPS230-P18 | Integration with the Risk Management Framework and Recovery Planning |
| CPS230-P26 | Assessment of Business and Strategic Decisions on the Risk Profile |
| CPS230-P27 | Comprehensive Assessment of the Operational Risk Profile |
| CPS230-P28 | Risk Assessment Before Providing a Material Service to Another Party |
Operations
| Code | Title |
|---|---|
| CPS230-P25 | Information and Technology Capability and Asset Health |
Regulatory
| Code | Title |
|---|---|
| CPS230-P33 | APRA Notification of Operational Risk Incidents within 72 Hours |
| CPS230-P42 | APRA Notification of Disruption Outside Tolerance within 24 Hours |
| CPS230-P51 | Annual Submission of the Material Service Provider Register to APRA |
| CPS230-P59 | APRA Notification of Service Agreements and Offshoring |
Service Provider Management
Requirements for managing material service providers (Paragraphs 37-49)
| Code | Title |
|---|---|
| CPS230-37 | Service Provider Management Policy |
| CPS230-39 | Register of Material Service Providers |
| CPS230-40 | Mandatory Minimum Classification of Material Service Providers |
| CPS230-43 | Due Diligence Before Entering or Modifying a Material Arrangement |
| CPS230-45 | APRA Access Provisions in Formal Agreements |
| CPS230-46 | Ongoing Risk Management of Each Material Arrangement |
| CPS230-47 | Monitoring and Senior Management Reporting on Material Arrangements |
| CPS230-49 | Internal Audit Review of Proposed Critical Operation Outsourcing |
| CPS230-P15 | Precondition for Reliance on a Service Provider |
| CPS230-P48 | Required Content of the Service Provider Management Policy |
Third Party
| Code | Title |
|---|---|
| CPS230-50 | Formal Agreement Content for Material Arrangements |
Your Compliance Coverage
If you comply with APRA CPS 230 Operational Risk Management, you already cover:
NIST Cybersecurity Framework 2.0
100%
43 controls mapped
Compare →DORA
93%
40 controls mapped
Compare →CFTC System Safeguards (17 CFR 37, 38, 39, 49)
93%
40 controls mapped
Compare →+ 262 more: FedRAMP Moderate (93%), FedRAMP High (93%)
See all 265 mapped frameworks ↓Maps to 265 other frameworks
What is APRA CPS 230 Operational Risk Management and who does it apply to?
APRA CPS 230 Operational Risk Management is a compliance framework from Australia with 11 domains and 43 controls. Australian Prudential Regulation Authority Prudential Standard CPS 230 sets out requirements for APRA-regulated entities to effectively manage operational risks, maintain business continuity, and manage risks from service provider arrangements. Effective 1 July 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does APRA CPS 230 Operational Risk Management actually require?
APRA CPS 230 Operational Risk Management has 43 controls organised across 11 domains. The largest domains are Operational Risk Management Framework (12 controls), Service Provider Management (10 controls), Business Continuity (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of APRA CPS 230 Operational Risk Management do I already cover?
APRA CPS 230 Operational Risk Management maps to 265 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (100% coverage), DORA (93% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (93% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement APRA CPS 230 Operational Risk Management?
Start your APRA CPS 230 Operational Risk Management compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about APRA CPS 230 Operational Risk Management requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required