THIRD PARTYCURRENT
Regulation & Standards · Regulatory Analysis

CPS 230 puts service-provider resilience into force in Australia

APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.

Third Party Current editorial graphic. Source material: Australian Prudential Regulation Authority; analysis and presentation by Third Party Current.

Service providers sit inside resilience

CPS 230 is not simply a vendor-assessment rule. APRA frames service-provider risk inside the entity's ability to maintain critical operations through severe disruption. That changes the unit of analysis: a supplier can look acceptable in isolation while still creating an operational weakness through concentration, subcontracting, geographic dependency, recovery assumptions, or an impractical exit path.

Regulated entities therefore need a relationship record that connects the provider, services, critical operations, agreements, accountable owners, tolerance levels, continuity arrangements, monitoring evidence, incidents, and remediation. A questionnaire or external score may contribute evidence, but neither creates that operating model on its own.

What a system must preserve

A useful platform should make materiality and dependency reviewable. Buyers should ask how it represents one provider delivering several services, multiple providers supporting one critical operation, subcontractors, internal group arrangements, exempt contractual situations, and changes that alter a service's materiality. Flat vendor rows are unlikely to express the full relationship context.

The demonstration should follow a material service from classification through agreement, monitoring, disruption, remediation, and exit planning. The output should be more than a dashboard: it should preserve who decided, which evidence supported the decision, what exception was accepted, when the record changed, and which downstream reports were affected.

The market implication

CPS 230 raises the importance of operational-resilience, contract, service, and dependency data in TPRM selection. Workflow products, GRC platforms, procurement suites, resilience tools, and intelligence providers may each cover part of the job. Buyers should resist assuming that one broad product label establishes end-to-end support.

Third Party Current will map the standard to provider capabilities only as a research pathway. A vendor's assertion that it supports CPS 230 does not establish customer compliance, and an unlisted mapping does not prove the capability is absent. Legal and regulatory scope remains an organizational determination.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: Australian Prudential Regulation Authority · Australian prudential regulator.

Source boundary: This article is independent editorial analysis of APRA's published standard and is not legal or regulatory advice.

Editorial record: Published July 1, 2026; last reviewed July 19, 2026. Corrections policy.