APRA CPS 234
Definition
APRA CPS 234
APRA CPS 234 is the Australian prudential standard on information security, requiring regulated entities to maintain defences proportionate to the threats they face. It reaches assets held by third parties, which makes a provider’s controls your own board’s problem.
The standard was Australia’s first prudential rule aimed squarely at cyber resilience.
Unlike its outsourcing counterpart, it survived the 2025 consolidation and remains in force in its own right.
Its most commercially significant feature is the third party clause — the obligations do not stop at the boundary of systems you operate.
Key takeaways
- The standard commenced on 1 July 2019 and remains current.
- It covers information assets managed by related parties and third parties.
- Entities must assess and evaluate a third party’s information security controls.
- Material incidents must be notified within seventy-two hours.
How it works
Commencement is stated in the standard itself. This Prudential Standard commences on 1 July 2019, and it requires an information security capability commensurate with the vulnerabilities and threats an entity faces.
The third party reach is explicit. A key objective is minimising the likelihood and impact of incidents on information assets, including information assets managed by related parties or third parties.
Two duties attach where somebody else holds your assets. The entity must assess the information security capability of that party commensurate with the potential consequences, and evaluate the design of that party’s controls.
| Requirement | What it means when a provider is involved |
|---|---|
| Capability assessment | You assess the provider, proportionate to what could go wrong |
| Control design evaluation | You form a view on the design, not just the certificate |
| Testing frequency | You judge whether their testing matches the risk |
| Incident notification | Seventy-two hours from becoming aware, whoever discovered it |
| Control weakness notification | Ten business days where a material weakness cannot be remediated promptly |
| Board accountability | The board remains ultimately responsible for information security |
Notification timing is the part providers most often break — the clock runs from when the entity becomes aware, which means a provider that sits on a discovery for a day has spent a third of the window.
Control weaknesses carry their own deadline — where a material weakness cannot be remediated in a timely manner, the regulator must be told no later than ten business days.
Examples
Australian financial institutions run large offshore technology estates, and the standard follows every one of them. Every case here involves an obligation the buyer kept and the provider performed.
A bank hosts core systems with a global cloud provider. The bank still evaluates the design of that provider’s controls rather than accepting a certification summary as the assessment.
An insurer outsources claims document storage to an offshore vendor. Because the vendor manages information assets, the insurer’s testing judgement has to cover the vendor’s environment.
A superannuation fund’s provider detects an incident on a Friday evening. The seventy-two hour clock is the fund’s, so the contract requires immediate escalation rather than next business day reporting.
A wealth manager identifies a material control weakness it cannot fix quickly. The ten business day notification applies, and a remediation plan is not a substitute for telling the regulator.
Related terms
Information security obligations arrive from prudential, contractual and certification directions all at the same time. Each of these covers ground this entry does not, and the gaps matter.
- ISO 27001 outsourcing: the certification providers offer as evidence of capability.
- Cybersecurity outsourcing: buying the security function itself rather than regulating it.
- Security operations outsourcing: the monitoring capability that detects the incidents you must report.
- Information security analyst: the role that performs assessment work in practice.
- Regulated outsourcing: supervised sector outsourcing, which this standard governs security for.
- Banking outsourcing: one of the regulated populations covered.
- Insurance outsourcing: the other major population inside scope.
FAQ
Did the 2025 consolidation replace this standard?
No. The consolidation absorbed the outsourcing and business continuity standards. The information security standard remains in force separately.
Does it apply to our provider directly?
It applies to the regulated entity. The entity’s obligations then shape what it must require of and verify about the provider.
Is a certification enough evidence?
Not on its own. The standard requires evaluating the design of the party’s controls, which is an assessment rather than a document check.
When does the notification clock start?
From when the entity becomes aware of a material incident, which is why contracts require immediate provider escalation.
What is the ten business day rule?
It applies to material control weaknesses that cannot be remediated in a timely manner, which must be notified within that window.
Who is ultimately accountable?
The board of the regulated entity, regardless of who operates the systems.
Compare source partners in the Outsource Accelerator hubs directory and shortlist providers whose security posture you can independently test.







Independent




