Requirements for APRA Regulated Entities

 

Australian regulations for the financial services sector

 

If your organisation is an Authorised Deposit-Taking Institution, General Insurer, Superannuation fund, Life Insurer or Friendly Society regulated by the Australian Prudential Regulation Authority (APRA), you're subject to a number of Prudential Standards.

These standards typically:

  • Hold the Board accountable for implementation

  • Require annual review

  • Require annual testing (exercising) to validate them

Most organisations start with CPS 230, the standard most likely to affect them directly. See what CPS 230 requires.

Below is the full landscape of standards and guidance that address risk management, resilience and recovery.

 

Prudential Standards


CPS 230 — Operational Risk Management

 

The current standard for operational resilience. It requires APRA-regulated entities to manage operational risk effectively, maintain Critical Operations through disruptions, and manage risks arising from service providers. In force since 1 July 2025, with the transition period for legacy service-provider contracts having closed on 1 July 2026 — it now applies in full.

Operational Risk Management | APRA

See what CPS 230 requires


CPS 220 — Risk Management

 

Requires APRA-regulated institutions to have systems for identifying, measuring, evaluating, monitoring, reporting, and controlling or mitigating material risks that could affect their ability to meet obligations to depositors and policyholders.

Risk Management | APRA


CPS 234 — Information Security

 

Requires APRA-regulated entities to maintain an information security capability commensurate with the vulnerabilities and threats they face, including resilience against cyber-attacks. Sits alongside CPS 230 — a security incident affecting a Critical Operation will typically engage both standards.

Information Security | APRA

 

CPS 231 and CPS 232 — superseded

 

CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management) have been replaced by CPS 230 and are no longer the operative standards. If you're still working from a CPS 232-era Business Continuity Plan, it's worth checking it against CPS 230's requirements.

 

CPG 229 — Climate Change Financial Risks

 

Finalised guidance (November 2021, current) assisting APRA-regulated entities in managing climate-related risks and opportunities within their existing risk management and governance frameworks.

Consultation on draft Prudential Practice Guide on Climate Change Financial Risks | APRA

 

Background reading


APRA's paper on cloud computing services

 

A 2018 paper addressing APRA's observations on the growing use of cloud computing by regulated entities, associated risk appetite, and areas of supervisory concern. Still useful background on APRA's thinking, though CPS 230 is now the operative standard for third-party and cloud arrangements.

Information Paper - Outsourcing involving cloud computing services

 

ASX requirements


Business continuity

 

ASX Clear Operating Rules — Guidance Note 10 helps participants understand the disaster recovery arrangements needed to meet their obligations under the ASX Clear Operating Rules.

ASX Clear GN 10 - Business Continuity and Disaster Recovery


Offshoring and outsourcing

 

ASX Clear Operating Rules — Guidance Note 9 covers what participants need to address when offshoring or outsourcing activities.

ASX OR GN 9 - Offshoring and outsourcing


Recovery Time Objectives

 

Following the impact of the COVID pandemic on businesses, the ASX reviewed RTO times outlined in Key Requirement 4.6.

Guidance Note 10 – Recovery Time Objective and Notification Requirements

 

ASIC requirements


Licensed market operators

 

This guide relates to the obligations of market operators set out under 7.2 and 7.2A of the Corporations Act 2001. These obligations are relevant for all licensed or exempt market operators, as applicable. The guide also relates to the obligations of certain domestic market operators that are subject to the ASIC market integrity rules.

The Guide contains a number of requirements for domestic and overseas operators to address business continuity.

Regulatory Guide RG 172 Financial markets: Domestic and overseas operators


Cyber resilience

 

This report highlights the importance of cyber resilience to ASIC’s regulated population. It is intended to help our regulated population improve their cyber resilience by increasing their awareness of cyber risks, encouraging collaboration between industry and government, and identifying opportunities for them to improve their cyber resilience.

Report REP 429 Cyber resilience: Health check


Observations on operational approaches during the pandemic

 

ASIC Observations of operational resilience of market intermediaries during the COVID-19 pandemic.

Operational resilience of market intermediaries during the COVID-19 pandemic

 

AFS Licensees

 

Regulatory Guide 104 describes what ASIC looks for when assessing compliance with the general obligations under s912A(1) of the Corporations Act, including the requirement to have a Business Continuity Plan.

Regulatory Guide RG 104 AFS Licensing: Meeting the general obligations

 

Risk management systems

 

Regulatory Guide 259 covers how responsible entities and AFS licensees can comply with their legal obligation to maintain adequate risk management systems.

Regulatory Guide RG 259 Risk management systems of responsible entities

 

Where next?

Not sure which standards apply to you? Get in touch and we'll help you work out what's relevant to your organisation.

Get in touch