How APRA CPS 230 Applies to AI in Financial Services
APRA's Prudential Standard CPS 230 — Operational Risk Management imposes explicit obligations on material service arrangements and technology risk. Here is what that means for AI systems deployed inside APRA-regulated entities.
APRA's Prudential Standard CPS 230 — Operational Risk Management — became effective on 1 July 2025. Its scope is broad: it applies to all APRA-regulated entities, including authorised deposit-taking institutions, general insurers, life insurers, and registrable superannuation entity licensees.
Most commentary on CPS 230 has focused on its implications for operational resilience and third-party service provider management. Less attention has been paid to what CPS 230 means specifically for AI systems — which is the question that risk and technology teams at regulated entities are now navigating in practice.
Why CPS 230 Matters for AI Teams, Not Just Ops Risk
CPS 230 is classified as an operational risk standard, which has led some organisations to treat it as a concern for the operational risk function rather than the technology or AI governance function. That categorisation is understandable but incomplete.
AI systems that perform material operational functions — credit decisioning, fraud detection, claims triage, customer communications — are, under CPS 230's framework, service arrangements subject to its requirements. The fact that the service is delivered by an internal AI system rather than a third-party vendor does not exempt it from the standard's operational risk obligations.
For financial services technology and AI governance teams, CPS 230 creates a set of obligations that are directly relevant to how AI systems are registered, assessed, monitored, and documented.
What Counts as a "Material Service Arrangement"
CPS 230 §21–§24 define "material service arrangements" as those that, if disrupted, would have a material impact on the entity's operations, financial position, or reputation, or on the interests of beneficiaries or policyholders.
The standard does not enumerate a list of qualifying services. The determination is risk-based: entities are expected to assess which arrangements are material and apply the relevant obligations accordingly.
For AI systems, the assessment should consider whether the system performs a function that: (a) processes significant transaction volumes, (b) influences outcomes that directly affect customers, beneficiaries, or policyholders, (c) has no immediate manual substitute, or (d) is operationally critical to business continuity.
An AI credit decisioning system that processes thousands of applications per day, or a fraud detection model that monitors real-time transactions, will typically qualify as a material service arrangement under any reasonable reading of §21–§24.
Four CPS 230 Obligations Most Likely to Be Triggered
For AI systems that qualify as material service arrangements, four categories of obligation in CPS 230 are directly relevant.
Risk assessment. CPS 230 §9–§14 require entities to identify, assess, and manage operational risks, including risks arising from the use of technology. AI systems introduce specific risk types — model drift, data quality failures, adversarial inputs, output instability — that must be addressed within the operational risk framework, not treated as purely technical matters outside the scope of risk management.
Business continuity. CPS 230 §25–§30 require entities to maintain business continuity plans that address the failure of material service arrangements. For AI systems, this means understanding what happens when the model performs below expectations, what manual substitutes exist, and how long those substitutes can sustain operations.
Service provider oversight. §31–§35 apply specifically to third-party service providers, but the principles of oversight — documented assessments, performance monitoring, clear accountability — apply equally to internally developed AI systems when those systems perform material functions. The underlying governance requirement is the same regardless of whether the service is sourced internally or externally.
Board and senior management accountability. CPS 230 §5–§8 impose explicit accountability at board and senior management level for operational risk management, including technology risk. Board members and senior executives are expected to understand the material operational risks their entities face, which includes AI systems that perform material functions. A board that cannot articulate the governance posture of its significant AI systems is not meeting the accountability requirements of §5–§8.
The Evidence Problem
CPS 230 does not merely require that regulated entities have governance processes for AI systems. It requires that those processes be documented, monitored, and demonstrable to APRA on request.
Sections 36–40 of CPS 230 set out monitoring and reporting requirements. Entities must maintain records sufficient to demonstrate compliance, must monitor material risks on an ongoing basis, and must be able to report to APRA on their operational risk posture in a form that is both timely and accurate.
For AI systems, this creates a specific evidence challenge. Many organisations have AI governance policies. Far fewer have:
- A complete registry of AI systems, with documented risk assessments for each.
- Evidence documents — bias assessments, model cards, privacy impact assessments, data governance documentation — that are current, integrity-verified, and linked to the specific systems they cover.
- Control evaluations that have been reviewed and updated when material changes to the system occurred.
- Audit-trail records showing who made what governance decisions about an AI system, when, and on what basis.
The gap between having a governance policy and having demonstrable ongoing governance is where most regulated entities currently sit.
Connecting CPS 230 to Broader AI Governance
CPS 230 does not exist in isolation. For regulated entities with international exposure or cross-regulatory obligations, several frameworks intersect.
ISO 42001 — the international standard for AI management systems — provides an Annex A control set that maps well to CPS 230's operational risk requirements. Entities implementing ISO 42001 will find that many of its controls — particularly those covering risk assessment, monitoring, and documentation — address the same underlying governance requirements that CPS 230 imposes.
OAIC privacy impact assessment requirements, including those arising from the Privacy Act reforms taking effect in December 2026, require assessment of the privacy implications of automated decision-making. For AI systems that process personal information — which includes most credit and insurance AI systems — the OAIC requirements and CPS 230 requirements overlap significantly in their documentation and monitoring demands.
A Practical Readiness Assessment
Compliance officers reviewing AI systems under CPS 230 should be able to answer the following 8 questions for each AI system they consider material:
- Is this AI system formally registered, with a documented risk assessment?
- Has it been assessed for qualification as a material service arrangement under CPS 230 §21–§24?
- Does current documentation include a model risk assessment, data governance documentation, and a bias or fairness assessment, where relevant?
- Are those documents current — reviewed and updated following any material change to the system?
- Is there an integrity-verified evidence record for each document, so that the version presented to APRA matches the version that was in use at the relevant time?
- Is there a documented business continuity arrangement addressing the failure of this system?
- Is there a named accountable person — at an appropriate level — responsible for the ongoing governance of this system?
- Has the governance posture been reviewed in the last 12 months, and can that review be demonstrated?
An AI system for which any of these questions cannot be answered in the affirmative represents a governance gap under CPS 230.
How Governance Infrastructure Helps
The evidence challenge CPS 230 creates — maintaining current, integrity-verified, demonstrable governance documentation at the AI-system level — is not easily addressed through manual processes at scale.
A governance platform addresses this by maintaining an AI system registry, linking evidence documents to systems with SHA-256 integrity verification, running control evaluations against applicable frameworks, and generating a TrustScore™ — a deterministic composite score across governance dimensions — that provides a board-reportable confidence signal.
The TrustScore is calculated from control decisions and evidence, not from model outputs. It reflects documented current state, not historical state. When APRA requests evidence of ongoing oversight, the response is the audit trail and score history — already assembled, already verified.
Download the AI Governance Checklist to assess your organisation's CPS 230 readiness. For a deeper look at how continuous assurance infrastructure works, see Continuous Assurance vs Point-in-Time Audits. To see the platform, visit Sentrify for Financial Services.
This post is informational and does not constitute legal or regulatory advice. Regulatory obligations under CPS 230 depend on the specific facts and circumstances of each entity. APRA-regulated entities should seek advice from qualified legal and regulatory specialists in determining their obligations under CPS 230 and related standards.