• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » APRA CPS 234

APRA CPS 234

Definition

APRA CPS 234

APRA CPS 234 is the Australian prudential standard on information security, requiring regulated entities to maintain defences proportionate to the threats they face. It reaches assets held by third parties, which makes a provider’s controls your own board’s problem.

The standard was Australia’s first prudential rule aimed squarely at cyber resilience.

Unlike its outsourcing counterpart, it survived the 2025 consolidation and remains in force in its own right.

Its most commercially significant feature is the third party clause — the obligations do not stop at the boundary of systems you operate.

Key takeaways

  • The standard commenced on 1 July 2019 and remains current.
  • It covers information assets managed by related parties and third parties.
  • Entities must assess and evaluate a third party’s information security controls.
  • Material incidents must be notified within seventy-two hours.

How it works

Commencement is stated in the standard itself. This Prudential Standard commences on 1 July 2019, and it requires an information security capability commensurate with the vulnerabilities and threats an entity faces.

The third party reach is explicit. A key objective is minimising the likelihood and impact of incidents on information assets, including information assets managed by related parties or third parties.

Two duties attach where somebody else holds your assets. The entity must assess the information security capability of that party commensurate with the potential consequences, and evaluate the design of that party’s controls.

RequirementWhat it means when a provider is involved
Capability assessmentYou assess the provider, proportionate to what could go wrong
Control design evaluationYou form a view on the design, not just the certificate
Testing frequencyYou judge whether their testing matches the risk
Incident notificationSeventy-two hours from becoming aware, whoever discovered it
Control weakness notificationTen business days where a material weakness cannot be remediated promptly
Board accountabilityThe board remains ultimately responsible for information security

Notification timing is the part providers most often break — the clock runs from when the entity becomes aware, which means a provider that sits on a discovery for a day has spent a third of the window.

Control weaknesses carry their own deadline — where a material weakness cannot be remediated in a timely manner, the regulator must be told no later than ten business days.

Examples

Australian financial institutions run large offshore technology estates, and the standard follows every one of them. Every case here involves an obligation the buyer kept and the provider performed.

A bank hosts core systems with a global cloud provider. The bank still evaluates the design of that provider’s controls rather than accepting a certification summary as the assessment.

An insurer outsources claims document storage to an offshore vendor. Because the vendor manages information assets, the insurer’s testing judgement has to cover the vendor’s environment.

A superannuation fund’s provider detects an incident on a Friday evening. The seventy-two hour clock is the fund’s, so the contract requires immediate escalation rather than next business day reporting.

A wealth manager identifies a material control weakness it cannot fix quickly. The ten business day notification applies, and a remediation plan is not a substitute for telling the regulator.

Related terms

Information security obligations arrive from prudential, contractual and certification directions all at the same time. Each of these covers ground this entry does not, and the gaps matter.

FAQ

Did the 2025 consolidation replace this standard?

No. The consolidation absorbed the outsourcing and business continuity standards. The information security standard remains in force separately.

Does it apply to our provider directly?

It applies to the regulated entity. The entity’s obligations then shape what it must require of and verify about the provider.

Is a certification enough evidence?

Not on its own. The standard requires evaluating the design of the party’s controls, which is an assessment rather than a document check.

When does the notification clock start?

From when the entity becomes aware of a material incident, which is why contracts require immediate provider escalation.

What is the ten business day rule?

It applies to material control weaknesses that cannot be remediated in a timely manner, which must be notified within that window.

Who is ultimately accountable?

The board of the regulated entity, regardless of who operates the systems.

Compare source partners in the Outsource Accelerator hubs directory and shortlist providers whose security posture you can independently test.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image