A frank briefing on what APRA expects from regulated entities β based on experience supporting financial institutions through supervisory reviews, enforcement inquiries and directed remediations. Not what the standard says. What regulators actually scrutinise.
CPS 234 came into effect in July 2019 and applies to all APRA-regulated entities β banks, insurers, superannuation funds and other financial institutions. It establishes mandatory information security requirements across three core areas. Understanding these areas in the way a regulator reads them is the starting point for a compliant programme.
Boards must maintain active oversight of information security. The board must ensure the entity has sufficient information security capability, must approve the information security policy, and must receive timely reporting on security posture and incidents.
Entities must maintain information security capability commensurate with the size and nature of their operations and the extent of threats. This includes a documented and tested information security policy, systematic identification and classification of information assets, and controls aligned to asset criticality.
Entities must have a robust incident response plan and must notify APRA within 72 hours of becoming aware of a material information security incident. Third-party incidents affecting the entity's data or systems trigger the same notification obligation.
CPS 234's third-party provisions are the most frequently misunderstood aspect of the standard. The requirement is not limited to direct suppliers. It extends to any party that manages information assets on behalf of the APRA-regulated entity β including cloud providers, managed security service providers, payment processors and technology vendors with access to customer data.
APRA-regulated entities must assess the information security posture of their material service providers and ensure those providers maintain controls commensurate with the entity's own requirements. A data breach at a cloud provider is not a defence against a CPS 234 supervisory finding β the obligation sits with the regulated entity, not the provider. This means your vendor assessment programme, your contract security schedules and your ongoing third-party monitoring are all within APRA's supervisory scope.
CPS 234 requires boards to attest annually that the entity's information security capability is commensurate with threats. This is not a compliance checkbox. It is a board-level commitment that APRA can β and does β reference in supervisory actions where subsequent security failures reveal the attestation was not supportable. Boards that attest without evidence of a robust, tested programme are creating personal and institutional risk.
The attestation should be supported by documented evidence of the security programme's scope, effectiveness testing results, incident history and third-party assessments β material that can be produced to APRA on request and that genuinely supports the claim being made.
APRA does not distinguish between entities that had a weak programme and entities that had a strong programme and were unlucky. It distinguishes between entities that can demonstrate their programme was appropriate and those that cannot.
APRA's supervisory approach to CPS 234 has become significantly more active since 2022. Understanding what regulators prioritise in practice β not just what the standard requires β is the difference between a programme that satisfies a compliance audit and one that satisfies an APRA review.
APRA assesses whether boards receive meaningful, actionable security reporting β not polished slide decks that obscure material risks behind green RAG ratings. They look for evidence that boards ask informed questions, challenge management positions and make documented risk decisions.
Boards that receive monthly security reports but cannot demonstrate engagement with material findings β late patching windows, unresolved third-party gaps, notification delays β are a supervisory concern regardless of the quality of the underlying programme.
APRA's supervisory experience has identified third-party management as the most consistently underdeveloped area across regulated entities. Reviewers look for a register of material information asset custodians, evidence of pre-engagement security assessments, contractual security requirements and ongoing monitoring β not just annual questionnaires.
Cloud migration in particular has created significant third-party exposure that entities are still working to bring within their CPS 234 frameworks. APRA has been explicit that cloud adoption does not transfer compliance obligations to the provider.
CPS 234 requires that information security controls be tested by suitably skilled independent parties. APRA looks for evidence of actual penetration testing, vulnerability assessments, incident response exercises and control effectiveness testing β with findings documented and remediated. Testing that does not produce findings raises a supervisory concern: either controls are genuinely exceptional, or the testing methodology is insufficient.
The 72-hour notification obligation is meaningless without a detection and escalation capability that can identify a material incident within hours of occurrence. APRA has found in multiple supervisory reviews that entities either detected incidents too late to meet the notification window or escalated them to the wrong level β neither is acceptable.
APRA also reviews the quality of notifications received: were they complete? Did they accurately characterise the incident's scope and impact? Post-notification, did the entity's response demonstrate competent incident management?
CPS 234 does not set a fixed control standard β it requires capability commensurate with the entity's size, nature of operations and the threats it faces. A small superannuation fund is held to a different standard than a major bank β but both must demonstrate that their programme is proportionate and that the proportionality is supported by documented risk assessment, not assumed.
APRA's supervisory toolkit has expanded significantly since 2019. Understanding the escalation path helps boards and CISOs calibrate the urgency of CPS 234 programme gaps.
Supervisory review identifies gaps. APRA issues a letter identifying material concerns and requesting a remediation plan with timeframes.
Directed review. APRA may direct the entity to engage an independent reviewer at the entity's cost to assess the adequacy of remediation.
Enforceable undertaking. The entity commits to a specific remediation programme with milestones β non-delivery has legal consequences.
Civil penalty. For serious or persistent non-compliance, APRA may seek civil penalties through the Federal Court β as demonstrated in enforcement actions against regulated entities since 2022.
"APRA does not distinguish between entities that were unlucky and entities with weak programmes. It distinguishes between those who can demonstrate their programme was appropriate and those who cannot."
APRA supervisory reviews are not announced far in advance. The entities that navigate them well are those that maintain their CPS 234 programme in a state of continuous readiness β not those that scramble to assemble evidence in the weeks before a review. The following preparation approach applies whether a review is imminent or a year away.
CPS 234 requires a documented information security policy approved by the board. Many entities have policies that were written in 2019 when the standard first came into effect and have not been substantively reviewed since. APRA will ask when the policy was last reviewed, whether the board approved the current version, and whether it reflects the entity's current operating environment including cloud services.
An information asset register that was built during the 2019 compliance exercise and not touched since is a supervisory risk. Assets must be classified by criticality and sensitivity, with controls documented against each classification. New systems, cloud services and third-party integrations added since the register was last reviewed must be included.
The notification obligation requires a capability β not just a process document. Run a tabletop exercise that simulates a material incident and tests whether the escalation path, initial assessment and notification drafting can be completed within 72 hours under realistic conditions. Document the exercise, the outcome and the gaps identified. APRA may ask for this record.
CPS 234 specifically requires testing by suitably skilled independent parties. Internal testing does not satisfy this requirement. Ensure your most recent penetration test was conducted by a credentialed external provider, that all findings were documented, and that remediation was tracked to completion with evidence. Unresolved high or critical findings from previous tests are a primary supervisory focus.
Prepare a current list of all material information asset custodians β cloud providers, managed service providers, payment processors, data custodians. For each, confirm that a security assessment has been conducted within the last 12 months, that contractual security requirements are in place, and that your monitoring approach is documented. Entities that cannot produce this list promptly in a supervisory review are significantly exposed.
Board packs should enable the board to genuinely understand the entity's security posture, the material risks being managed, the testing results, and the status of remediation against any open findings. If your board reporting is currently a one-page RAG dashboard, it does not meet the standard APRA expects for a CPS 234 board attestation.
The entities that navigate APRA supervisory reviews well are those that maintain their programme in a state of continuous readiness β not those that scramble to assemble evidence when a review is announced.
APRA CPS 234 in Practice: What Regulators Are Actually Looking For Β· GadgetAccess Advisory Β· March 2026 Β· 10 min read
What assessors test and how to prepare β from the assessor's perspective.
Webinar Summary Β· Apr 2026Practical session covering the five gaps most commonly found in assessments.
Sector AdvisoryAPRA CPS 234, ASD Essential Eight and regulatory advisory for financial institutions.
Our advisors have supported financial institutions through APRA supervisory reviews, directed remediations and enforcement inquiries. We understand what regulators look for β and how to build a programme that genuinely satisfies their scrutiny.