Regulation guide

APRA CPG 230

Operationalize the APRA CPG 230 requirements—from regulatory obligations and evidence collection to vendor assessments, continuous monitoring, governance, and remediation workflows.

Overview

APRA CPG 230 is guidance supporting CPS 230. It helps entities understand better-practice approaches for operational risk management, critical operations, material service providers, business continuity, testing, and evidence.

CPG 230 helps regulated entities interpret and implement CPS 230. The guide should be read as practice guidance rather than the prudential standard itself.

Rather than prescribing identical controls for every relationship, the regulation emphasizes a continuous approach, requiring organizations to apply governance, oversight, controls, monitoring, and due diligence according to the criticality and risk of each relationship.

This implementation guide explains what the regulation requires, how those requirements translate into operational controls and evidence, and how Halbarad helps organizations operationalize compliance through assessments, continuous monitoring, governance workflows, and supply chain risk intelligence.

Official Sources

Intent of the Guide

CPG 230 helps regulated entities interpret and implement CPS 230. The guide should be read as practice guidance rather than the prudential standard itself. It is valuable because it helps teams translate requirements into operating records and evidence.

Operationalization Requirements

  • Use CPS 230 as the binding standard and CPG 230 as implementation guidance.
  • Map critical operations, tolerance levels, material service providers, and dependencies.
  • Maintain continuity plans, scenario tests, provider evidence, issues, and remediation.
  • Report operational risk and resilience posture to management and the board.

Evidence Requirements

  • CPS 230 / CPG 230 mapping.
  • Critical operations, dependency maps, and material service provider records.
  • Scenario testing, continuity, remediation, and reporting evidence.

Common Gaps

  • CPG 230 is treated as optional reading rather than implementation guidance.
  • Service provider records are not connected to critical operations.
  • Testing results are not linked to remediation.

How Halbarad Helps

Halbarad helps connect critical operations, material service providers, dependency maps, incidents, test evidence, issues, and remediation.

Disclaimer

This guide is for general information only and is not legal advice. Review the official regulation, guidance, and supervisory materials, and consult qualified counsel or compliance advisors for your organization's specific obligations.