Requirements for APRA Regulated Entities
Australian regulations for the financial services sector
If your organisation is an Authorised Deposit-Taking Institution, General Insurer, Superannuation fund, Life Insurer or Friendly Society regulated by the Australian Prudential Regulation Authority (APRA), you're subject to a number of Prudential Standards.
These standards typically:
Hold the Board accountable for implementation
Require annual review
Require annual testing (exercising) to validate them
Most organisations start with CPS 230, the standard most likely to affect them directly. See what CPS 230 requires.
Below is the full landscape of standards and guidance that address risk management, resilience and recovery.
Prudential Standards
CPS 230 — Operational Risk Management
The current standard for operational resilience. It requires APRA-regulated entities to manage operational risk effectively, maintain Critical Operations through disruptions, and manage risks arising from service providers. In force since 1 July 2025, with the transition period for legacy service-provider contracts having closed on 1 July 2026 — it now applies in full.
CPS 220 — Risk Management
Requires APRA-regulated institutions to have systems for identifying, measuring, evaluating, monitoring, reporting, and controlling or mitigating material risks that could affect their ability to meet obligations to depositors and policyholders.
CPS 234 — Information Security
Requires APRA-regulated entities to maintain an information security capability commensurate with the vulnerabilities and threats they face, including resilience against cyber-attacks. Sits alongside CPS 230 — a security incident affecting a Critical Operation will typically engage both standards.
CPS 231 and CPS 232 — superseded
CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management) have been replaced by CPS 230 and are no longer the operative standards. If you're still working from a CPS 232-era Business Continuity Plan, it's worth checking it against CPS 230's requirements.
CPG 229 — Climate Change Financial Risks
Finalised guidance (November 2021, current) assisting APRA-regulated entities in managing climate-related risks and opportunities within their existing risk management and governance frameworks.
Consultation on draft Prudential Practice Guide on Climate Change Financial Risks | APRA
Background reading
APRA's paper on cloud computing services
A 2018 paper addressing APRA's observations on the growing use of cloud computing by regulated entities, associated risk appetite, and areas of supervisory concern. Still useful background on APRA's thinking, though CPS 230 is now the operative standard for third-party and cloud arrangements.
Information Paper - Outsourcing involving cloud computing services
ASX requirements
Business continuity
ASX Clear Operating Rules — Guidance Note 10 helps participants understand the disaster recovery arrangements needed to meet their obligations under the ASX Clear Operating Rules.
Offshoring and outsourcing
ASX Clear Operating Rules — Guidance Note 9 covers what participants need to address when offshoring or outsourcing activities.
Recovery Time Objectives
Following the impact of the COVID pandemic on businesses, the ASX reviewed RTO times outlined in Key Requirement 4.6.
Guidance Note 10 – Recovery Time Objective and Notification Requirements
ASIC requirements
Licensed market operators
This guide relates to the obligations of market operators set out under 7.2 and 7.2A of the Corporations Act 2001. These obligations are relevant for all licensed or exempt market operators, as applicable. The guide also relates to the obligations of certain domestic market operators that are subject to the ASIC market integrity rules.
The Guide contains a number of requirements for domestic and overseas operators to address business continuity.
Regulatory Guide RG 172 Financial markets: Domestic and overseas operators
Cyber resilience
This report highlights the importance of cyber resilience to ASIC’s regulated population. It is intended to help our regulated population improve their cyber resilience by increasing their awareness of cyber risks, encouraging collaboration between industry and government, and identifying opportunities for them to improve their cyber resilience.
Observations on operational approaches during the pandemic
ASIC Observations of operational resilience of market intermediaries during the COVID-19 pandemic.
Operational resilience of market intermediaries during the COVID-19 pandemic
AFS Licensees
Regulatory Guide 104 describes what ASIC looks for when assessing compliance with the general obligations under s912A(1) of the Corporations Act, including the requirement to have a Business Continuity Plan.
Regulatory Guide RG 104 AFS Licensing: Meeting the general obligations
Risk management systems
Regulatory Guide 259 covers how responsible entities and AFS licensees can comply with their legal obligation to maintain adequate risk management systems.
Regulatory Guide RG 259 Risk management systems of responsible entities
Where next?
Not sure which standards apply to you? Get in touch and we'll help you work out what's relevant to your organisation.
Get in touch