Financial services

CPS 230 and AI in banking: how to govern AI under APRA's operational risk standard

Clutch Events Editorial
Editorial team, Clutch Events
October 5, 2026
CPS 230 and AI in banking: how to govern AI under APRA's operational risk standard

Quick answer: CPS 230 is APRA's Prudential Standard on Operational Risk Management, in force since 1 July 2025. It replaced CPS 231 (outsourcing) and CPS 232 (business continuity) and requires banks, insurers and superannuation trustees to identify critical operations, set Board-approved tolerance levels for disruption, manage material service providers and notify APRA of incidents within 72 hours. Any AI model that sits inside a critical operation inherits every one of those obligations.

APRA has been consistent on one point: it is not writing an AI-specific prudential standard. Instead, it expects regulated entities to run AI through the risk frameworks they already have, and since mid-2025 the most important of those is CPS 230. That changes the conversation inside Australian banks and insurers. The question is no longer "do we have an AI policy?" but "can we show APRA where AI sits in our critical operations, what happens when it fails, and who we depend on to run it?"

This guide is written for the people who have to answer that question in 2026-2027: CROs, heads of operational risk, CIOs, heads of data and AI, and the model risk and third-party teams in between. It covers what CPS 230 requires, where AI in banking and insurance actually lives today, how each CPS 230 obligation maps onto an AI system, and what else (ASIC, the Privacy Act, the Voluntary AI Safety Standard) you need to line up alongside it.

What is CPS 230 and what did it replace?

Prudential Standard CPS 230 Operational Risk Management applies to all APRA-regulated entities: authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees. It consolidated and replaced CPS 231 Outsourcing, CPS 232 Business Continuity Management and their superannuation and health equivalents (SPS 231, SPS 232, HPS 231), with CPG 230 providing the accompanying practice guide.

The standard has four pillars:

  1. Operational risk management. Maintain a comprehensive operational risk profile, controls and a control-testing programme, and remediate material weaknesses.
  2. Business continuity. Identify critical operations, set tolerance levels for disruption, maintain and test a credible business continuity plan, and run scenario analysis.
  3. Service provider management. Keep a register of material service providers, perform due diligence, include minimum contractual terms, and manage fourth-party (sub-contracting) risk.
  4. Notification. Tell APRA within 72 hours of an operational risk incident likely to have a material financial impact or a material impact on critical operations, within 24 hours of a disruption that breaches a tolerance level, and within 20 business days of entering or materially changing a material service provider arrangement.

Key dates: the standard commenced on 1 July 2025. Entities that were not significant financial institutions had until 1 July 2026 to meet the business continuity and scenario analysis requirements, and pre-existing service provider contracts had to comply from the earlier of their next renewal or 1 July 2026. By the time you read this, the transition is over.

Does CPS 230 apply to AI?

Yes, by design. CPS 230 is technology-neutral and operations-centred. It does not mention machine learning once, but it asks four questions that any AI system in a bank must be able to answer:

  • Is this system part of a critical operation? APRA presumes payments, deposit-taking and account management, custody, settlements and clearing, claims processing, investment management and fund administration are critical, along with the systems and infrastructure that support them.
  • What is our tolerance for it failing, running degraded, or producing wrong outputs?
  • Who provides it, and are they a material service provider?
  • Would its failure be a notifiable incident?

APRA's broader messaging through 2024-2026 reinforced this: AI is treated as an operational risk and a technology risk under CPS 220 (risk management), CPS 230 and CPS 234 (information security), with the Board ultimately accountable. If you are looking for a single Australian "AI rule" for banks, CPS 230 is the closest thing you have.

Where AI in banking and insurance actually lives today

The use cases are no longer experimental. Across the Australian majors, regionals, mutuals and insurers the pattern in 2026 looks like this:

  • Real-time fraud and scam detection on payments — Typical business owner: Financial crime · Presumptively critical operation?: Yes (payments) · CPS 230 hook: Tolerance levels, 72-hour notification, vendor model as material service provider
  • AML transaction monitoring and alert triage — Typical business owner: Financial crime / compliance · Presumptively critical operation?: Yes (regulatory reporting dependency) · CPS 230 hook: Control testing, change management, AUSTRAC interplay
  • Credit decisioning and pricing models — Typical business owner: Retail / business lending · Presumptively critical operation?: Often (account origination) · CPS 230 hook: Model risk, scenario analysis, data lineage
  • Claims triage and straight-through processing — Typical business owner: Insurance operations · Presumptively critical operation?: Yes (claims processing) · CPS 230 hook: Tolerance levels for claims turnaround, BCP
  • Contact-centre copilots and conversational assistants — Typical business owner: Customer / digital · Presumptively critical operation?: Sometimes (customer servicing) · CPS 230 hook: Third-party LLM providers, data handling, degradation plans
  • Document and KYC extraction — Typical business owner: Operations / onboarding · Presumptively critical operation?: Sometimes · CPS 230 hook: Service provider register, accuracy tolerances
  • Software engineering assistants — Typical business owner: Technology · Presumptively critical operation?: No (indirect) · CPS 230 hook: Change risk, secure development under CPS 234
  • Underwriting and pricing in general insurance — Typical business owner: Underwriting · Presumptively critical operation?: Sometimes · CPS 230 hook: Model governance, fairness, pricing-practice scrutiny

The important column is the third one. If the answer is "yes" or "sometimes", the model is not just a data science asset; it is a component of a critical operation with a Board-approved tolerance level attached. For the fraud and AML rows, see our deep dives on AI fraud detection systems, scams and mule accounts and AML/CTF reforms, transaction monitoring and perpetual KYC.

How each CPS 230 obligation maps to an AI system

Critical operations and the AI inventory

You cannot map AI to critical operations without an inventory. Most institutions now maintain one, but many were built for ethics or privacy purposes and record "use cases" rather than "systems in a process". Re-cut the inventory so each entry names the critical operation it supports, the upstream data it depends on, the provider (internal team, cloud platform, model vendor, foundation-model API) and the fallback if it is switched off.

Tolerance levels: the AI-specific twist

CPS 230 asks for three tolerance measures per critical operation: the maximum period of disruption, the maximum extent of data loss, and the minimum service level during disruption. For conventional systems the hard case is downtime. For AI the hard case is silent degradation: the model stays up but drifts, is fed poisoned or stale data, or produces outputs outside its validated range. Treat a model that is operating outside its performance guardrails as a disruption to the critical operation, define what "minimum service level" looks like (for example, reverting to rules-based decisioning with manual review), and make sure monitoring would actually detect the breach within the tolerance window.

Material service providers: are LLM vendors in scope?

A material service provider is one on which the entity relies to undertake a critical operation, or that exposes it to material operational risk. A cloud platform hosting your fraud model is clearly in. A foundation-model API embedded in a customer-facing assistant that handles complaints or hardship conversations is very likely in. Expect to need: due diligence on the provider's own resilience, contractual terms on data use, incident notification, audit and access rights, exit and step-in plans, and visibility of the provider's own sub-contractors (the fourth-party chain). The register goes to APRA annually, so decide now rather than when the submission is due.

Business continuity and scenario analysis

Add AI-specific scenarios to your programme: the provider withdraws or deprecates the model version you depend on; a regulator or court orders a model to be switched off; a data-pipeline failure feeds the model with the wrong population; a prompt-injection or model-manipulation attack targets a customer-facing assistant. Each scenario should end with a tested fallback, not a slide.

Incident notification

Build the decision tree before you need it. A fraud model outage that lets a wave of scam payments through is a 72-hour notification. A claims-triage model that stops processing for longer than the tolerance level is a 24-hour notification. A model producing biased credit outcomes may also trigger obligations to ASIC and the OAIC. Make sure your operational risk incident process knows what a "model incident" is.

What else governs AI in financial services in Australia?

CPS 230 is the operational spine, but it is not the whole skeleton.

  • ASIC. ASIC's October 2024 review of AI governance across a sample of AFS and credit licensees (Report 798) found adoption running ahead of governance, with some licensees lacking policies or risk assessments specific to AI. ASIC's position is that existing licensee obligations (efficiently, honestly and fairly; adequate risk management; design and distribution obligations; responsible lending) already apply to AI-driven decisions.
  • Privacy Act reforms. The Privacy and Other Legislation Amendment Act 2024 introduced a requirement to disclose substantially automated decision-making in privacy policies, commencing in December 2026. Credit, pricing and claims models are the obvious candidates.
  • Voluntary AI Safety Standard. The Commonwealth's ten guardrails (accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply-chain transparency, record-keeping, stakeholder engagement) are a sensible internal baseline and map neatly onto CPS 230 artefacts.
  • CPS 234. Models, training data and prompts are information assets; see our CPS 234 information security and third-party risk guide.
  • Global frameworks that Australian institutions borrow from: the EU AI Act (credit scoring and life/health insurance pricing are high-risk uses), the NIST AI Risk Management Framework, ISO/IEC 42001 for AI management systems, and MAS's FEAT principles in Singapore.

A practical operating model for AI under CPS 230

  1. One inventory, three views. Every AI system recorded once, viewable by critical operation (CPS 230), by information asset (CPS 234) and by customer impact (ASIC, Privacy Act).
  2. Tier by consequence, not by technology. A GenAI summariser for internal policy documents and a GenAI assistant that talks to customers in hardship are not the same tier.
  3. Model risk management that includes vendors. Validation, performance thresholds, drift monitoring, change control and periodic revalidation, applied equally to models you build and models you buy.
  4. Third-party due diligence that asks AI questions. Training-data provenance, model versioning and deprecation policy, data residency, sub-processors, incident notification, and the right to test.
  5. Human oversight that is real. Define who can override, pause or switch off each tier-one model, and test that they actually can.
  6. Evidence by default. Decision logs, monitoring dashboards and incident records designed so that an APRA or ASIC request can be met in days, not months.

If you are moving from assistants to autonomous agents, the governance questions get sharper; see agentic AI use cases in banking and insurance.

Common mistakes we see

  • Treating the AI inventory as an ethics artefact rather than an operational one.
  • Classifying only "models" and missing the embedded AI inside vendor SaaS products.
  • Setting tolerance levels for downtime only, not for degraded or incorrect output.
  • Assuming a hyperscaler's shared-responsibility statement discharges your service provider due diligence.
  • Letting the data science team own model risk end to end with no second-line challenge.

Key takeaways

  • CPS 230 is the de facto AI operational risk standard for Australian banks and insurers; APRA is not writing a separate one.
  • Classify every AI system against critical operations and tolerance levels, including silent degradation, not just outages.
  • Treat model vendors and foundation-model providers as material service providers where a critical operation depends on them.
  • Line CPS 230 up with CPS 234, ASIC's licensee duties, the Privacy Act's automated decision-making disclosure and the Voluntary AI Safety Standard.
  • Build evidence by default: inventory, monitoring, decision logs and incident records that can answer a regulator in days.

Join your peers at the Clutch AI in FSI Summits 2027

Clutch Events runs free-to-attend, invite-curated, practitioner-led AI in FSI summits for senior technology, risk and business leaders at Australian banks, insurers and super funds:

See all upcoming Clutch events · More guides on Clutch Events Insights

Frequently asked questions

What is CPS 230?

CPS 230 is APRA's Prudential Standard on Operational Risk Management. It requires APRA-regulated banks, insurers and superannuation trustees to manage operational risk, identify critical operations and set tolerance levels for their disruption, maintain tested business continuity plans, manage material service providers, and notify APRA of material incidents. It is supported by Prudential Practice Guide CPG 230.

When did CPS 230 come into effect?

CPS 230 commenced on 1 July 2025. Non-significant financial institutions had until 1 July 2026 for the business continuity and scenario analysis requirements, and pre-existing material service provider contracts had to comply from the earlier of their next renewal date or 1 July 2026.

What did CPS 230 replace?

It replaced CPS 231 Outsourcing and CPS 232 Business Continuity Management, together with their superannuation (SPS 231, SPS 232) and private health insurance (HPS 231) equivalents, consolidating outsourcing, business continuity and operational risk into a single standard.

Does CPS 230 apply to AI?

Yes. CPS 230 is technology-neutral. Any AI model or AI-enabled service that supports a critical operation must be covered by the entity's operational risk profile, tolerance levels, business continuity planning and, where it is externally provided, material service provider management. APRA has said it does not intend to issue a separate AI prudential standard.

Is an AI vendor a material service provider under CPS 230?

It is if the entity relies on it to undertake a critical operation or if the arrangement exposes the entity to material operational risk. A cloud platform hosting a fraud model, or a foundation-model API inside a customer-facing assistant, will usually qualify and must appear on the material service provider register, with due diligence and the required contractual terms.

What are tolerance levels under CPS 230?

Tolerance levels are Board-approved limits for each critical operation: the maximum period of disruption, the maximum extent of data loss, and the minimum service level to be maintained during disruption. For AI systems, good practice is to treat sustained operation outside validated performance guardrails as a disruption, not just downtime.

How is AI in banking regulated in Australia?

Through existing law rather than an AI Act: APRA's CPS 220, CPS 230 and CPS 234; ASIC's licensee obligations and its 2024 AI governance review; the Privacy Act, including automated decision-making transparency from December 2026; anti-discrimination law; and the Commonwealth's Voluntary AI Safety Standard as a reference baseline.

Related event

Hear this live at the Sydney AI in FSI Summit 2027

Sydney AI in FSI Summit 2027

March 10, 2027
More insights

Keep reading

Events & community
Tech conferences in Australia 2027: the IT leadership events worth attending

The IT conferences in Australia worth a senior leader's time in 2027: CIO, AI, cyber, data, DevOps and government events, with typical dates and costs.

October 5, 2026
Public sector AI
AI in government in Australia: the responsible AI rules every agency leader needs to know

AI in government in Australia: DTA responsible AI policy v2.0, impact assessments, transparency statements, NSW AI Assessment Framework and procurement.

October 5, 2026
Engineering & DevOps
AI coding assistants in enterprise engineering teams: rollout, measurement and governance

AI coding assistants for large engineering organisations: what the evidence says about productivity, and how to roll out, measure and govern them.

October 5, 2026
Engineering & DevOps
DORA metrics and developer productivity: how to measure engineering without gaming it

DORA metrics explained: the five delivery metrics, how to measure them, how SPACE and DevEx complete the picture, and how to avoid gaming them.

October 5, 2026
All insights →
CPS 230 and AI in banking: how to govern AI under APRA's operational risk standard
CPS 230 explained for AI in banking: which AI systems are critical operations, when AI vendors are material service providers, and how to govern them.
Clutch Events Editorial
Editorial team, Clutch Events
October 5, 2026
cps-230-ai-in-banking-governance
Financial services