Operational resilience in Australia: CPS 230 compliance

Are you prepared to anticipate and recover from the unexpected?

As organisations place more reliance on technology to support ongoing operations, a sound understanding of how to minimise the impact of a disruption to your external stakeholders and the broader economy is of paramount importance. APRA’s Prudential Standard CPS 230 (Operational Risk Management), aims to reinforce the importance of maintaining a clear focus on customer outcomes in firms’ management and oversight of their risk and control environments, and sets minimum operational resilience requirements that must always be maintained to ensure any disruptions minimise consumer harm.

CPS 230 implementation timeline 

  • 1 July 2026: Full commencement for non-significant financial institutions
  • 1 July 2025: CPS 230 goes into effect (revised enforcement date)

With the CPS 230 compliance deadline fast approaching, organisations are entering the final phase of implementation—prioritising the completion of outstanding requirements and actively responding to Board feedback.

CPS 230 day one checklist: Have you met all requirements? 

ThemeDay one artefacts
1. Operating model
  • Operating model – Integration of operational risk disciplines with clear accountabilities and responsibilities defined
2. Board oversight
  • Comprehensive MI reporting for Board and key committees
3. Operational risk management and framework
  • Refreshed risk management framework
  • Updated risk appetite statement metrics
4. Risk profiles & reporting
  • GRC system refreshed with controls for CPS 230, alignment to critical operations and assessment of operational risk profile
5. Critical operations (COs)
  • Board-approved critical operations, with clear ownership defined
6. Process and resource mapping
  • Critical operations mapped end-to-end, including inter-dependencies
7. Tolerance levelsBoard-approved tolerance levels
8. Material service providers (MSPs)
  • Board-approved service provider management policy
  • Material service providers identified and monitored
  • APRA MSP register ready to share
9. Incidents and notifications
  • APRA notification requirements embedded into operations, including performance of dry-runs
10. Business continuity management
  • Board-Approved business continuity planning covering all critical operations
  • Library of severe but plausible scenarios defined
  • Comprehensive testing strategy and plan in place
11. Technology resilience
  • Systems and infrastructure demonstrating resilience capabilities to remain within tolerance levels set by critical operations

 

  • Jul 2024 – APRA publishes finalised standard
  • Jan 2024 – Original enforcement date
  • Jul 2022 – APRA publishes discussion paper and draft standard

How can Protiviti Australia help with CPS 230 implementation and operational resilience optimisation? 

We help you take on the challenge to build and sustain processes required to demonstrate resilience. Our program and domain expertise across operational risk, business continuity, and service provider management will help provide your Board with confidence in ability to achieve CPS 230 compliance.

Foundational capabilitiesGovernance and oversightOperational riskInformation securityIT disaster recoveryBusiness continuityCrisis managementService provider management

 

Gap assessment and roadmap developmentTarget operating model designCritical operations framework development
Determining your CPS 230-readiness, using a requirements traceability matrix. Developing an informed and prioritised roadmap to address gaps against the requirements prior to the regulatory deadline.Working with your management team to develop a bespoke target operating model to manage CPS 230 compliance sustainably for the long term.Tailoring tried and tested methodologies to help you identify critical operations, establish tolerance levels and map end-to-end the processes, resources, risks and controls.
Program design and implementationIntegrated resilience testingProgram assurance 
Designing and implementing a CPS 230 program leveraging Protiviti’s Operational Resilience Framework, with a focus on practical and proportionate delivery and strong governance to demonstrate compliance before the regulatory deadline.Developing and delivering resilience testing; maturing capability from desktop walkthrough through to evidence-based scenarios testing, and integrating the output from other testing such as ITDR and threat-led penetration conducted across your business.Providing an independent expert review of your planned, in-flight, or completed CPS 230 activity, to identify opportunities to improve practices.

 

Why Protiviti?

  • We work closely with leading firms to offer technology enabled solutions to CPS 230 compliance and related initiatives suitable for mid-size businesses through to leading global firms
  • Tools to model processes and capture process attributes offer a range of benefits towards understanding your risk profile for CPS 230 compliance, but also wider strategic business optimisation initiatives
  • We partner with providers of GRC systems to help firms manage their risk profile sustainably and provide clarity to senior management and the board on where to focus their time and investment.
  • Our CPS 230 and operational resilience clients include global SIFI’s and other leading Australian Banks, mid-size ADI’s, large and mid-size Insurers, key suppliers of insurers and ADIs, such as technology firms
  • We have been delivering CPS 230 programs since its inception
  • We have designed CPS 230 and operational resilience target operating models to support sustainable long-term management
  • We have provided CPS 230 and operational resilience across the 3 lines of defence
  • We have a substantial history of engagements across the foundational areas of cyber, business, technology and third-party resilience.

Contact us for more information on these frequently asked questions:

Board oversight

+

What information does our board need to fulfill its oversight accountabilities?

Cross-disciplinary Integration

+

How do we sustainably integrate practices that have traditionally operated in silos – operational risk management, business continuity, service provider management and IT service continuity?

Demonstrating resilience

+

To what extent should we test our ability to remain within tolerance levels, and how do we demonstrate that our technology suite and key suppliers support recovery with defined tolerance levels?

Managing competing priorities

+

How do we meet the new requirements in the face of cost cutting initiatives? How do we manage competing local and international requirements, in particular the EU’s Digital Operational Resilience Act (DORA)

Loading...