Quick answer: CPS 230 is APRA's Prudential Standard on Operational Risk Management, in force since 1 July 2025. It replaced CPS 231 (outsourcing) and CPS 232 (business continuity) and requires banks, insurers and superannuation trustees to identify critical operations, set Board-approved tolerance levels for disruption, manage material service providers and notify APRA of incidents within 72 hours. Any AI model that sits inside a critical operation inherits every one of those obligations.
APRA has been consistent on one point: it is not writing an AI-specific prudential standard. Instead, it expects regulated entities to run AI through the risk frameworks they already have, and since mid-2025 the most important of those is CPS 230. That changes the conversation inside Australian banks and insurers. The question is no longer "do we have an AI policy?" but "can we show APRA where AI sits in our critical operations, what happens when it fails, and who we depend on to run it?"
This guide is written for the people who have to answer that question in 2026-2027: CROs, heads of operational risk, CIOs, heads of data and AI, and the model risk and third-party teams in between. It covers what CPS 230 requires, where AI in banking and insurance actually lives today, how each CPS 230 obligation maps onto an AI system, and what else (ASIC, the Privacy Act, the Voluntary AI Safety Standard) you need to line up alongside it.
What is CPS 230 and what did it replace?
Prudential Standard CPS 230 Operational Risk Management applies to all APRA-regulated entities: authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees. It consolidated and replaced CPS 231 Outsourcing, CPS 232 Business Continuity Management and their superannuation and health equivalents (SPS 231, SPS 232, HPS 231), with CPG 230 providing the accompanying practice guide.
The standard has four pillars:
- Operational risk management. Maintain a comprehensive operational risk profile, controls and a control-testing programme, and remediate material weaknesses.
- Business continuity. Identify critical operations, set tolerance levels for disruption, maintain and test a credible business continuity plan, and run scenario analysis.
- Service provider management. Keep a register of material service providers, perform due diligence, include minimum contractual terms, and manage fourth-party (sub-contracting) risk.
- Notification. Tell APRA within 72 hours of an operational risk incident likely to have a material financial impact or a material impact on critical operations, within 24 hours of a disruption that breaches a tolerance level, and within 20 business days of entering or materially changing a material service provider arrangement.
Key dates: the standard commenced on 1 July 2025. Entities that were not significant financial institutions had until 1 July 2026 to meet the business continuity and scenario analysis requirements, and pre-existing service provider contracts had to comply from the earlier of their next renewal or 1 July 2026. By the time you read this, the transition is over.
Does CPS 230 apply to AI?
Yes, by design. CPS 230 is technology-neutral and operations-centred. It does not mention machine learning once, but it asks four questions that any AI system in a bank must be able to answer:
- Is this system part of a critical operation? APRA presumes payments, deposit-taking and account management, custody, settlements and clearing, claims processing, investment management and fund administration are critical, along with the systems and infrastructure that support them.
- What is our tolerance for it failing, running degraded, or producing wrong outputs?
- Who provides it, and are they a material service provider?
- Would its failure be a notifiable incident?
APRA's broader messaging through 2024-2026 reinforced this: AI is treated as an operational risk and a technology risk under CPS 220 (risk management), CPS 230 and CPS 234 (information security), with the Board ultimately accountable. If you are looking for a single Australian "AI rule" for banks, CPS 230 is the closest thing you have.
Where AI in banking and insurance actually lives today
The use cases are no longer experimental. Across the Australian majors, regionals, mutuals and insurers the pattern in 2026 looks like this:
- Real-time fraud and scam detection on payments — Typical business owner: Financial crime · Presumptively critical operation?: Yes (payments) · CPS 230 hook: Tolerance levels, 72-hour notification, vendor model as material service provider
- AML transaction monitoring and alert triage — Typical business owner: Financial crime / compliance · Presumptively critical operation?: Yes (regulatory reporting dependency) · CPS 230 hook: Control testing, change management, AUSTRAC interplay
- Credit decisioning and pricing models — Typical business owner: Retail / business lending · Presumptively critical operation?: Often (account origination) · CPS 230 hook: Model risk, scenario analysis, data lineage
- Claims triage and straight-through processing — Typical business owner: Insurance operations · Presumptively critical operation?: Yes (claims processing) · CPS 230 hook: Tolerance levels for claims turnaround, BCP
- Contact-centre copilots and conversational assistants — Typical business owner: Customer / digital · Presumptively critical operation?: Sometimes (customer servicing) · CPS 230 hook: Third-party LLM providers, data handling, degradation plans
- Document and KYC extraction — Typical business owner: Operations / onboarding · Presumptively critical operation?: Sometimes · CPS 230 hook: Service provider register, accuracy tolerances
- Software engineering assistants — Typical business owner: Technology · Presumptively critical operation?: No (indirect) · CPS 230 hook: Change risk, secure development under CPS 234
- Underwriting and pricing in general insurance — Typical business owner: Underwriting · Presumptively critical operation?: Sometimes · CPS 230 hook: Model governance, fairness, pricing-practice scrutiny
The important column is the third one. If the answer is "yes" or "sometimes", the model is not just a data science asset; it is a component of a critical operation with a Board-approved tolerance level attached. For the fraud and AML rows, see our deep dives on AI fraud detection systems, scams and mule accounts and AML/CTF reforms, transaction monitoring and perpetual KYC.
How each CPS 230 obligation maps to an AI system
Critical operations and the AI inventory
You cannot map AI to critical operations without an inventory. Most institutions now maintain one, but many were built for ethics or privacy purposes and record "use cases" rather than "systems in a process". Re-cut the inventory so each entry names the critical operation it supports, the upstream data it depends on, the provider (internal team, cloud platform, model vendor, foundation-model API) and the fallback if it is switched off.
Tolerance levels: the AI-specific twist
CPS 230 asks for three tolerance measures per critical operation: the maximum period of disruption, the maximum extent of data loss, and the minimum service level during disruption. For conventional systems the hard case is downtime. For AI the hard case is silent degradation: the model stays up but drifts, is fed poisoned or stale data, or produces outputs outside its validated range. Treat a model that is operating outside its performance guardrails as a disruption to the critical operation, define what "minimum service level" looks like (for example, reverting to rules-based decisioning with manual review), and make sure monitoring would actually detect the breach within the tolerance window.
Material service providers: are LLM vendors in scope?
A material service provider is one on which the entity relies to undertake a critical operation, or that exposes it to material operational risk. A cloud platform hosting your fraud model is clearly in. A foundation-model API embedded in a customer-facing assistant that handles complaints or hardship conversations is very likely in. Expect to need: due diligence on the provider's own resilience, contractual terms on data use, incident notification, audit and access rights, exit and step-in plans, and visibility of the provider's own sub-contractors (the fourth-party chain). The register goes to APRA annually, so decide now rather than when the submission is due.
Business continuity and scenario analysis
Add AI-specific scenarios to your programme: the provider withdraws or deprecates the model version you depend on; a regulator or court orders a model to be switched off; a data-pipeline failure feeds the model with the wrong population; a prompt-injection or model-manipulation attack targets a customer-facing assistant. Each scenario should end with a tested fallback, not a slide.
Incident notification
Build the decision tree before you need it. A fraud model outage that lets a wave of scam payments through is a 72-hour notification. A claims-triage model that stops processing for longer than the tolerance level is a 24-hour notification. A model producing biased credit outcomes may also trigger obligations to ASIC and the OAIC. Make sure your operational risk incident process knows what a "model incident" is.
What else governs AI in financial services in Australia?
CPS 230 is the operational spine, but it is not the whole skeleton.
- ASIC. ASIC's October 2024 review of AI governance across a sample of AFS and credit licensees (Report 798) found adoption running ahead of governance, with some licensees lacking policies or risk assessments specific to AI. ASIC's position is that existing licensee obligations (efficiently, honestly and fairly; adequate risk management; design and distribution obligations; responsible lending) already apply to AI-driven decisions.
- Privacy Act reforms. The Privacy and Other Legislation Amendment Act 2024 introduced a requirement to disclose substantially automated decision-making in privacy policies, commencing in December 2026. Credit, pricing and claims models are the obvious candidates.
- Voluntary AI Safety Standard. The Commonwealth's ten guardrails (accountability, risk management, data governance, testing, human oversight, transparency, contestability, supply-chain transparency, record-keeping, stakeholder engagement) are a sensible internal baseline and map neatly onto CPS 230 artefacts.
- CPS 234. Models, training data and prompts are information assets; see our CPS 234 information security and third-party risk guide.
- Global frameworks that Australian institutions borrow from: the EU AI Act (credit scoring and life/health insurance pricing are high-risk uses), the NIST AI Risk Management Framework, ISO/IEC 42001 for AI management systems, and MAS's FEAT principles in Singapore.
A practical operating model for AI under CPS 230
- One inventory, three views. Every AI system recorded once, viewable by critical operation (CPS 230), by information asset (CPS 234) and by customer impact (ASIC, Privacy Act).
- Tier by consequence, not by technology. A GenAI summariser for internal policy documents and a GenAI assistant that talks to customers in hardship are not the same tier.
- Model risk management that includes vendors. Validation, performance thresholds, drift monitoring, change control and periodic revalidation, applied equally to models you build and models you buy.
- Third-party due diligence that asks AI questions. Training-data provenance, model versioning and deprecation policy, data residency, sub-processors, incident notification, and the right to test.
- Human oversight that is real. Define who can override, pause or switch off each tier-one model, and test that they actually can.
- Evidence by default. Decision logs, monitoring dashboards and incident records designed so that an APRA or ASIC request can be met in days, not months.
If you are moving from assistants to autonomous agents, the governance questions get sharper; see agentic AI use cases in banking and insurance.
Common mistakes we see
- Treating the AI inventory as an ethics artefact rather than an operational one.
- Classifying only "models" and missing the embedded AI inside vendor SaaS products.
- Setting tolerance levels for downtime only, not for degraded or incorrect output.
- Assuming a hyperscaler's shared-responsibility statement discharges your service provider due diligence.
- Letting the data science team own model risk end to end with no second-line challenge.
Key takeaways
- CPS 230 is the de facto AI operational risk standard for Australian banks and insurers; APRA is not writing a separate one.
- Classify every AI system against critical operations and tolerance levels, including silent degradation, not just outages.
- Treat model vendors and foundation-model providers as material service providers where a critical operation depends on them.
- Line CPS 230 up with CPS 234, ASIC's licensee duties, the Privacy Act's automated decision-making disclosure and the Voluntary AI Safety Standard.
- Build evidence by default: inventory, monitoring, decision logs and incident records that can answer a regulator in days.
Join your peers at the Clutch AI in FSI Summits 2027
Clutch Events runs free-to-attend, invite-curated, practitioner-led AI in FSI summits for senior technology, risk and business leaders at Australian banks, insurers and super funds:
See all upcoming Clutch events · More guides on Clutch Events Insights