THIRD PARTYCURRENT
Regulation & Standards · Regulatory Update

APRA finalizes targeted CPS 230 amendments and a revised service-provider register

The April package adds limited contractual exemptions, clarifies their management, and updates the material service-provider register ahead of the July commencement date.

Third Party Current editorial graphic. Source material: Australian Prudential Regulation Authority; analysis and presentation by Third Party Current.

An exception still needs a record

The targeted exemptions do not make exempt relationships invisible. They make decision quality more important because the organization must understand why ordinary contractual compliance is impracticable, whether the provider falls within the stated category, which requirements are affected, and how the residual risk is managed. An exception without scope, evidence, approval, and review creates ambiguity rather than proportionality.

Third-party risk systems should therefore distinguish a rule from an approved exception to that rule. Buyers should ask whether a platform can preserve the underlying authority version, exemption category, relationship facts, reviewer judgment, alternate controls, expiration or review date, and affected reports without converting the exception into a generic pass status.

The register is an operating data test

APRA's updated register template reinforces the need for consistent service-provider data. A reporting deadline is the wrong time to discover that providers, services, contracts, owners, critical operations, locations, subcontractors, and materiality decisions use incompatible identifiers across procurement, legal, resilience, security, and risk systems.

A credible implementation plan should trace every required output field back to its system of record, accountable owner, validation rule, refresh trigger, and evidence. TPRM software can coordinate that process, but it cannot repair undefined ownership or ungoverned source data merely by adding a form.

What buyers should ask vendors

Vendors should demonstrate how their data model handles one legal entity with several services and contracts, how service-level materiality changes are recorded, and how an exempt contractual arrangement remains visible to monitoring and continuity owners. Buyers should also inspect exportability and the history behind every reported value.

Third Party Current will treat the amendment package as a standards change, not as proof that any listed provider has implemented the revised template. Provider alignment claims require dated supporting documentation and remain separate from an independent finding of regulatory adequacy.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: Australian Prudential Regulation Authority · Australian prudential regulator.

Source boundary: This article is independent analysis of APRA's consultation and final-amendment materials and is not legal or regulatory advice.

Editorial record: Published April 30, 2026; last reviewed July 19, 2026. Corrections policy.