{{item.title}}
{{item.text}}
{{item.title}}
{{item.text}}
APRA released the final Prudential Standard CPS 230 Operational Risk Management (CPS 230) in July 2023. CPS 230 will take effect from 1 July 2025, with transition agreements for existing service provider arrangements until 1 July 2026.
The objective of CPS 230 is to strengthen the management of operational risk in the banking, insurance, and superannuation industries, improve operational resilience and minimise the impact of disruption to members and the financial system, through:
CPS 230 will replace five existing APRA Standards: Prudential Standard CPS 231 Outsourcing, Prudential Standard CPS 232 Business Continuity Management and the equivalent superannuation and health insurance Standards (SPS and HPS).
There are three key focus areas in the Standard:
1. Operational Risk Management:
The Board is ultimately accountable for an organisation’s operational risk management and must oversee senior management’s implementation and maintenance of CPS 230. CPS 230 requires regulated entities to consider operational risk from a critical operations lens, therefore, all risk management practices, including the overall risk profile, will need to be revised and align to the new critical operations view.
2. Business Continuity Management:
To support a comprehensive operational risk profile and business continuity plan (BCP), CPS 230 requires entities to:
3. Service Provider Management:
Requirements have been enhanced to cover all material service providers that APRA-regulated entities rely upon for critical operations, or that expose them to material operational risk. Entities are required to understand and manage the risks associated with the use of these material service providers, along with their downstream providers (i.e. fourth or nth parties), with a comprehensive outsourcing management policy, formal agreements, and robust governance / monitoring.
Entities must manage their full range of operational risks by maintaining a comprehensive operational risk profile. Internal controls to mitigate these risks within appetite should be embedded and regularly tested. Entities must also maintain strong data and IT infrastructure to meet business requirements and support critical operations.
To effectively manage business continuity, entities must ensure that they define criticality criteria and identify critical operations taking into consideration those identified by APRA’s CPS 230, unless justified otherwise. Once identified, entities must understand and manage risk associated with its critical operations to continue to deliver critical operations within tolerance levels through severe disruptions.
Entities must set clear tolerances for the maximum level of disruption they are willing to accept, including tolerances on maximum time to be disrupted, data loss, and minimum service levels. Tolerance levels need to be customer and outcomes focused. Entities are expected to maintain critical operations within tolerance levels and conduct regular scenario testing to calibrate tolerances.
Entities must understand and manage the risks associated with the use of service providers that support their critical operations, or expose them to material operational risk, including downstream providers (fourth or nth parties). A register of MSPs and associated risks must be reported to APRA annually, as well as changes to MSP agreements.
Whilst CPS 230 will take effect 1 July 2025, APRA expects demonstration of proactive preparation and progress from organisations throughout 2024 and 2025.
The below timeline outlines key milestones and recommended approaches for the Prudential Standard’s commencement:
At PwC, we have service offerings built to help you set up and run a fit for purpose and digitally enabled operational resilience capability, which will also enable you to meet your CPS 230 obligations. With our global connectivity and experience, we will provide you with the confidence that we are the right people. Our propositions are designed to encompass each of the Prepare, Respond and Sustain phases of your journey. Whilst there are three distinct components in the CPS 230 Standard, they are not mutually exclusive, and we will support you in responding to this in a holistic manner.
Susanna Chan
Partner, Cybersecurity & Digital Trust, PwC Australia
Tel: +61 414 544 066