Homeβ€Ί Insightsβ€Ί APRA CPS 234 in Practice
🏦 APRA-Regulated Entities · Financial Services · Superannuation · Insurance

APRA CPS 234 in Practice:
What Regulators Are Actually Looking For

A frank briefing on what APRA expects from regulated entities β€” based on experience supporting financial institutions through supervisory reviews, enforcement inquiries and directed remediations. Not what the standard says. What regulators actually scrutinise.

2019CPS 234 effective date
3Core obligations under CPS 234
72 hrsNotification obligation for material incidents
AnnualBoard attestation requirement

What CPS 234 actually requires

CPS 234 came into effect in July 2019 and applies to all APRA-regulated entities β€” banks, insurers, superannuation funds and other financial institutions. It establishes mandatory information security requirements across three core areas. Understanding these areas in the way a regulator reads them is the starting point for a compliant programme.

1
Roles & Responsibilities

Boards must maintain active oversight of information security. The board must ensure the entity has sufficient information security capability, must approve the information security policy, and must receive timely reporting on security posture and incidents.

2
Information Security Capability

Entities must maintain information security capability commensurate with the size and nature of their operations and the extent of threats. This includes a documented and tested information security policy, systematic identification and classification of information assets, and controls aligned to asset criticality.

3
Incident Response & Notification

Entities must have a robust incident response plan and must notify APRA within 72 hours of becoming aware of a material information security incident. Third-party incidents affecting the entity's data or systems trigger the same notification obligation.

The third-party obligation β€” the clause most entities underestimate

CPS 234's third-party provisions are the most frequently misunderstood aspect of the standard. The requirement is not limited to direct suppliers. It extends to any party that manages information assets on behalf of the APRA-regulated entity β€” including cloud providers, managed security service providers, payment processors and technology vendors with access to customer data.

⚠️
What the third-party obligation actually means in practice

APRA-regulated entities must assess the information security posture of their material service providers and ensure those providers maintain controls commensurate with the entity's own requirements. A data breach at a cloud provider is not a defence against a CPS 234 supervisory finding β€” the obligation sits with the regulated entity, not the provider. This means your vendor assessment programme, your contract security schedules and your ongoing third-party monitoring are all within APRA's supervisory scope.

Board attestation β€” what it actually commits to

CPS 234 requires boards to attest annually that the entity's information security capability is commensurate with threats. This is not a compliance checkbox. It is a board-level commitment that APRA can β€” and does β€” reference in supervisory actions where subsequent security failures reveal the attestation was not supportable. Boards that attest without evidence of a robust, tested programme are creating personal and institutional risk.

The attestation should be supported by documented evidence of the security programme's scope, effectiveness testing results, incident history and third-party assessments β€” material that can be produced to APRA on request and that genuinely supports the claim being made.

APRA does not distinguish between entities that had a weak programme and entities that had a strong programme and were unlucky. It distinguishes between entities that can demonstrate their programme was appropriate and those that cannot.

What APRA actually focuses on β€” the supervisory lens

APRA's supervisory approach to CPS 234 has become significantly more active since 2022. Understanding what regulators prioritise in practice β€” not just what the standard requires β€” is the difference between a programme that satisfies a compliance audit and one that satisfies an APRA review.

πŸ›οΈ
Board-level security literacy and active oversight

APRA assesses whether boards receive meaningful, actionable security reporting β€” not polished slide decks that obscure material risks behind green RAG ratings. They look for evidence that boards ask informed questions, challenge management positions and make documented risk decisions.

Boards that receive monthly security reports but cannot demonstrate engagement with material findings β€” late patching windows, unresolved third-party gaps, notification delays β€” are a supervisory concern regardless of the quality of the underlying programme.

πŸ”—
Third-party management β€” depth and rigour

APRA's supervisory experience has identified third-party management as the most consistently underdeveloped area across regulated entities. Reviewers look for a register of material information asset custodians, evidence of pre-engagement security assessments, contractual security requirements and ongoing monitoring β€” not just annual questionnaires.

Cloud migration in particular has created significant third-party exposure that entities are still working to bring within their CPS 234 frameworks. APRA has been explicit that cloud adoption does not transfer compliance obligations to the provider.

πŸ§ͺ
Testing β€” demonstrated, not asserted

CPS 234 requires that information security controls be tested by suitably skilled independent parties. APRA looks for evidence of actual penetration testing, vulnerability assessments, incident response exercises and control effectiveness testing β€” with findings documented and remediated. Testing that does not produce findings raises a supervisory concern: either controls are genuinely exceptional, or the testing methodology is insufficient.

🚨
Incident detection and notification timeliness

The 72-hour notification obligation is meaningless without a detection and escalation capability that can identify a material incident within hours of occurrence. APRA has found in multiple supervisory reviews that entities either detected incidents too late to meet the notification window or escalated them to the wrong level β€” neither is acceptable.

APRA also reviews the quality of notifications received: were they complete? Did they accurately characterise the incident's scope and impact? Post-notification, did the entity's response demonstrate competent incident management?

πŸ“Š
Capability commensurate with size and risk profile

CPS 234 does not set a fixed control standard β€” it requires capability commensurate with the entity's size, nature of operations and the threats it faces. A small superannuation fund is held to a different standard than a major bank β€” but both must demonstrate that their programme is proportionate and that the proportionality is supported by documented risk assessment, not assumed.

Common CPS 234 Findings in APRA Supervisory Reviews
  • Boards receiving security reports that do not adequately surface material risks β€” resulting in attestations not supported by the underlying evidence
  • Third-party registers that are incomplete, outdated or do not capture cloud service providers and SaaS platforms
  • Penetration testing conducted by the internal IT team rather than an independent suitably skilled party
  • Incident notification reaching APRA more than 72 hours after the entity was aware β€” often due to unclear escalation paths
  • Information asset classification registers that exist as documents but are not operationally maintained or used to drive control decisions
  • Control testing that finds no findings β€” treated as success rather than as a testing methodology concern
  • Information security policies that have not been reviewed or updated since CPS 234 first came into effect in 2019

APRA's escalation path when entities fall short

APRA's supervisory toolkit has expanded significantly since 2019. Understanding the escalation path helps boards and CISOs calibrate the urgency of CPS 234 programme gaps.

Step 1

Supervisory review identifies gaps. APRA issues a letter identifying material concerns and requesting a remediation plan with timeframes.

Step 2

Directed review. APRA may direct the entity to engage an independent reviewer at the entity's cost to assess the adequacy of remediation.

Step 3

Enforceable undertaking. The entity commits to a specific remediation programme with milestones β€” non-delivery has legal consequences.

Step 4

Civil penalty. For serious or persistent non-compliance, APRA may seek civil penalties through the Federal Court β€” as demonstrated in enforcement actions against regulated entities since 2022.

"APRA does not distinguish between entities that were unlucky and entities with weak programmes. It distinguishes between those who can demonstrate their programme was appropriate and those who cannot."

How to prepare for a CPS 234 supervisory review

APRA supervisory reviews are not announced far in advance. The entities that navigate them well are those that maintain their CPS 234 programme in a state of continuous readiness β€” not those that scramble to assemble evidence in the weeks before a review. The following preparation approach applies whether a review is imminent or a year away.

1
Maintain a current, board-approved information security policy

CPS 234 requires a documented information security policy approved by the board. Many entities have policies that were written in 2019 when the standard first came into effect and have not been substantively reviewed since. APRA will ask when the policy was last reviewed, whether the board approved the current version, and whether it reflects the entity's current operating environment including cloud services.

2
Keep your information asset register current and classified

An information asset register that was built during the 2019 compliance exercise and not touched since is a supervisory risk. Assets must be classified by criticality and sensitivity, with controls documented against each classification. New systems, cloud services and third-party integrations added since the register was last reviewed must be included.

3
Build and test your 72-hour notification capability

The notification obligation requires a capability β€” not just a process document. Run a tabletop exercise that simulates a material incident and tests whether the escalation path, initial assessment and notification drafting can be completed within 72 hours under realistic conditions. Document the exercise, the outcome and the gaps identified. APRA may ask for this record.

4
Conduct independent penetration testing with documented remediation

CPS 234 specifically requires testing by suitably skilled independent parties. Internal testing does not satisfy this requirement. Ensure your most recent penetration test was conducted by a credentialed external provider, that all findings were documented, and that remediation was tracked to completion with evidence. Unresolved high or critical findings from previous tests are a primary supervisory focus.

5
Review and update your third-party security assessments

Prepare a current list of all material information asset custodians β€” cloud providers, managed service providers, payment processors, data custodians. For each, confirm that a security assessment has been conducted within the last 12 months, that contractual security requirements are in place, and that your monitoring approach is documented. Entities that cannot produce this list promptly in a supervisory review are significantly exposed.

6
Prepare board-level security reporting that meets APRA's standards

Board packs should enable the board to genuinely understand the entity's security posture, the material risks being managed, the testing results, and the status of remediation against any open findings. If your board reporting is currently a one-page RAG dashboard, it does not meet the standard APRA expects for a CPS 234 board attestation.

What strong board security reporting looks like under CPS 234

  • Summary of the current threat landscape relevant to the entity's sector and risk profile
  • Material incidents in the reporting period β€” scope, impact, response status and notification decisions
  • Penetration testing and vulnerability assessment results β€” findings, severity distribution and remediation status
  • Third-party security assessment status β€” coverage, last assessment date and open gaps
  • Key risk indicators with trend data β€” not single-point-in-time metrics
  • Regulatory interaction update β€” any APRA correspondence, directed actions or pending obligations
  • Attestation support section β€” evidence basis for the upcoming or most recent board attestation

The entities that navigate APRA supervisory reviews well are those that maintain their programme in a state of continuous readiness β€” not those that scramble to assemble evidence when a review is announced.

Source Material
  • Australian Prudential Regulation Authority. Prudential Standard CPS 234 Information Security.
  • Australian Prudential Regulation Authority. Prudential Practice Guide CPG 234 Information Security.
  • Australian Prudential Regulation Authority. Information paper: Cyber security β€” Lessons from incidents and observations.
  • Australian Prudential Regulation Authority. Supervisory actions and enforcement outcomes (public register).
πŸ“„

Download the Full Research Brief β€” PDF

APRA CPS 234 in Practice: What Regulators Are Actually Looking For Β· GadgetAccess Advisory Β· March 2026 Β· 10 min read

⬇ Download PDF
Related Insights

Preparing for an APRA review or strengthening your CPS 234 programme?

Our advisors have supported financial institutions through APRA supervisory reviews, directed remediations and enforcement inquiries. We understand what regulators look for β€” and how to build a programme that genuinely satisfies their scrutiny.