Frameworks / APRA CPS 234

APRA CPS 234 compliance for financial services

CPS 234 requires APRA-regulated entities to maintain an information security capability commensurate with the threats they face. We help banks, insurers, super funds, and fintechs meet every requirement — from board-level governance to technical controls and incident notification.

Start CPS 234 Compliance →

CPS 234 requirements

APRA CPS 234 mandates that APRA-regulated entities clearly define information security roles and responsibilities, maintain an information security capability commensurate with the size and extent of threats, implement controls to protect information assets, test the effectiveness of those controls, and notify APRA of material information security incidents.

Our CPS 234 service

Gap Assessment

Assessment against all CPS 234 requirements and APRA's supporting guidance (CPG 234). Clear view of gaps and remediation priorities.

Information Security Capability

We help you build and demonstrate an information security capability proportionate to your threat environment — including people, processes, and technology.

Third-Party Management

Assessment of third-party and related-party information security arrangements. Vendor risk assessment framework and ongoing monitoring.

Testing & Assurance

Design and execution of your control testing program, including systematic testing per CPS 234 requirements and independent assurance activities.