APRA CPS 234 · Prudential Standard · Banking · Insurance · Superannuation
CPS 234 is not a certification. It is an obligation.
There is no certificate, no auditor to satisfy, and no completion date. There is a binding prudential standard, a Board that carries ultimate responsibility for it, and two notification clocks that start the moment you become aware.
We deliver all 24 requirements as a live register inside your Microsoft 365 tenant — cross-mapped to ISO 27001 and NIST CSF so the prudential obligation and the certification are prepared once, not twice.
- All 24 requirements (¶13–36)
- Systematic testing program
- Evidence of effectiveness, not assertion
- Data stays in your tenant
Does CPS 234 apply to us?
Directly if you are APRA-regulated. Indirectly — and increasingly in writing — if you hold their data.
Directly regulated
Authorised deposit-taking institutions, general and life insurers, private health insurers, and registrable superannuation entity licensees. CPS 234 has applied since 1 July 2019 and supports CPS 220 Risk Management.
Service providers to the sector
You are not regulated by APRA — but your customer is, and CPS 234 requires them to assess your security capability, evaluate the design of your controls, and assess whether your control testing is sufficient. Being able to evidence all three is what keeps you on the panel.
The 24 requirements, in the nine domains auditors use
CPS 234's substantive obligations run from paragraph 13 to paragraph 36. Internal audit functions and APRA assessors group them like this.
Roles and responsibilities
¶13–14The Board carries ultimate responsibility — not the CISO, not IT. Roles for the Board, senior management, governing bodies and individuals must be defined in writing.
Information security capability
¶15–17Capability commensurate with the size and extent of threats, actively maintained as threats change — and assessed for any related or third party managing your assets.
Policy framework
¶18–19A policy framework sized to your exposure, giving direction to every party with an obligation — staff, contractors, related parties and third parties alike.
Asset identification and classification
¶20Information assets classified by criticality and sensitivity, reflecting the impact on the entity and on depositors, policyholders, beneficiaries or other customers.
Implementation of controls
¶21–22Controls sized against four named factors — threat, sensitivity, life-cycle stage and consequence — plus design evaluation of any third party holding your assets.
Incident management
¶23–26Detection and response mechanisms, response plans for incidents that could plausibly occur, Board escalation, and an annual review and test of those plans.
Testing control effectiveness
¶27–31A systematic testing program — not ad hoc penetration testing — conducted by skilled and functionally independent specialists, with its own sufficiency reviewed annually.
Internal audit
¶32–34Internal audit reviews both the design and the operating effectiveness of controls, and assesses third-party assurance it intends to rely on.
APRA notification
¶35–36Two separate clocks: 72 hours for a material incident, and 10 business days for a material control weakness you cannot remediate in time.
Two notification clocks, not one
These are routinely conflated. They have different triggers and different deadlines, and the second one does not require an incident to have happened at all.
¶35 · Material incident
72 hours
From becoming aware of an incident that materially affected — or had the potential to materially affect — the entity or its depositors, policyholders, beneficiaries or other customers. Or that has been notified to any other regulator, in Australia or elsewhere. That second limb catches incidents you might not have judged material yourself.
¶36 · Material control weakness
10 business days
From becoming aware of a material control weakness you expect you will not be able to remediate in a timely manner. No incident is required. This is the obligation entities miss most often, because nothing has visibly gone wrong — you have simply found something you cannot fix in time.
"Implemented" is an assertion. CPS 234 asks for effectiveness.
Paragraph 27 requires a systematic testing program — not an annual penetration test — with nature and frequency driven by five named factors.
- The rate at which vulnerabilities and threats change
- The criticality and sensitivity of the information asset
- The consequences of an information security incident
- Risk from environments where you cannot enforce your own policies
- The materiality and frequency of change to information assets
Testing must be conducted by appropriately skilled and functionally independent specialists (¶30), unremediable deficiencies escalated to the Board or senior management (¶29), and the sufficiency of the program itself reviewed at least annually (¶31). Where you rely on a third party's testing, you must assess whether it is commensurate with the same five factors (¶28).
How we deliver it
In your tenant, cross-mapped, and evidenced continuously rather than reconstructed before a review.
Your tenant, your data
Every register — requirements, risks, actions, evidence, incidents — lives in SharePoint lists inside your own Microsoft 365 tenant. No third-party GRC platform licence, and no compliance data leaving your environment.
Cross-mapped, not duplicated
Every CPS 234 requirement is mapped to its ISO 27001 and NIST CSF equivalents. If you hold ISO 27001, most of the underlying work is already done — we evidence it against the prudential obligation rather than rebuilding it.
Evidence of effectiveness
Automated posture checks run against your tenant and rank each requirement by what actually sits behind it — continuously demonstrated, evidenced, or merely asserted. That distinction is what paragraphs 27 and 32 are asking for.
Where does your CPS 234 position actually stand?
A 30-minute call. We will walk the nine domains, identify which requirements you can evidence today and which rest on assertion, and tell you plainly whether your notification process would survive a real incident.
Book a 30-min call