Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Australian regulation

    APRA CPS 230

    CPS 230 is the APRA prudential standard on operational risk management. It requires regulated entities to identify critical operations, set tolerance levels for disruption, maintain and test business continuity plans, and manage material service provider arrangements including a register and formal oversight.

    What APRA CPS 230 means in practice

    CPS 230 shifted the regulatory conversation from technology controls to business outcomes. Rather than asking whether a system is secure, it asks whether the entity can keep delivering its critical operations through a disruption, and how long it can be down before the harm becomes unacceptable.

    Three obligations do most of the work. First, identifying critical operations — the processes that, if disrupted, would have a material adverse impact on depositors, policyholders, members or financial system stability — and setting explicit tolerance levels for maximum disruption, data loss and minimum service. Second, maintaining a business continuity plan that shows how those tolerances are met, and testing it regularly against severe but plausible scenarios rather than optimistic ones. Third, managing material service providers with a register, due diligence, contractual requirements and ongoing monitoring, including fourth-party dependencies.

    Technology providers feel this standard as a documentation burden passed down the chain. Regulated clients need to evidence oversight of their providers, which means concrete answers about resilience, subcontractors, data location, incident notification timelines and exit arrangements.

    The technical work that follows is usually about proving recovery rather than building new systems. Tolerance levels expressed as recovery time and recovery point objectives have to be tested against real restore exercises, not vendor capability statements. Dependencies have to be mapped, because a critical operation often relies on an application, an identity platform, a network path and a third party that were each assessed separately and never together.

    The standard rewards honesty. An entity that documents a four-hour tolerance it cannot meet has created a finding; one that documents the real position with a remediation plan has demonstrated the risk management the standard is asking for.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.