AuditXYZ

Compliance Framework

APRA Prudential Standard CPS 234 Information Security (APRA CPS 234)

APRA CPS 234 requires Australian financial entities to maintain information security capability commensurate with threats. This guide covers requirements, board obligations, incident reporting, and implementation.

$50,000–$500,0004–12 monthsAudit Required2019
Issuing BodyAustralian Prudential Regulation Authority (APRA)
First Published2019-07-01
Latest Version2019
Typical Cost$50,000–$500,000
Typical Timeline4–12 months
Audit RequiredYes
Audit FrequencyAnnual internal audit review of information security controls. APRA conducts periodic supervisory reviews.
Geographyaustralia

APRA CPS 234: Australian Information Security Standard

APRA Prudential Standard CPS 234 is Australia's mandatory information security standard for APRA-regulated financial entities. Effective since July 2019, it requires entities to maintain information security capability commensurate with the size and extent of threats to their information assets, and to promptly notify APRA of material security incidents or control weaknesses. CPS 234 places accountability for information security at the board level — a structural shift that fundamentally changed how Australian financial institutions govern cyber risk.

What CPS 234 Is and Who Issues It

CPS 234 is issued by the Australian Prudential Regulation Authority (APRA), the independent statutory authority responsible for prudential supervision of the financial services industry. APRA regulates banks, insurers, and superannuation funds under a mandate to promote financial stability and protect the interests of beneficiaries and policyholders.

APRA issued CPS 234 after recognizing that information security risks were not receiving adequate board-level attention across the regulated sector. The standard was informed by international frameworks including NIST CSF and ISO 27001, but was designed for prescriptive application within the Australian prudential context. APRA has supplemented CPS 234 with guidance papers and supervisory letters providing additional expectations on specific topics including third-party risk, cloud computing, and penetration testing.

Who Must Comply

CPS 234 applies to all APRA-regulated entities, which fall into four main categories:

  • Authorized deposit-taking institutions (ADIs): Banks, building societies, credit unions, and other deposit-taking entities authorized by APRA
  • General insurers: All APRA-licensed general insurance companies
  • Life insurance companies: APRA-licensed life insurers and friendly societies
  • Registrable superannuation entity (RSE) licensees: Trustees of APRA-regulated superannuation funds

Third-party service providers — including cloud providers, technology outsourcers, and fintech partners — are indirectly captured through CPS 234's third-party risk management requirements. APRA-regulated entities must ensure their service providers maintain information security commensurate with CPS 234 standards and include appropriate contractual protections.

The managed service provider or cloud vendor to an Australian bank faces genuine compliance pressure from CPS 234 through its customers' obligations, making it practically mandatory for any technology company with significant exposure to the Australian financial sector.

Key Requirements Explained in Depth

Board Accountability

CPS 234 makes the board of an APRA-regulated entity accountable for information security. Specifically, the board must ensure that the entity maintains information security capability commensurate with the size and extent of threats to its information assets. This is not a delegatable administrative function — the board must actively engage with information security governance, receive regular reporting, and hold management accountable.

Boards must receive regular briefings on the entity's information security posture, material vulnerabilities, and significant incidents. APRA expects evidence that boards ask probing questions and take meaningful action in response to security concerns.

Defined Roles and Responsibilities

CPS 234 requires entities to clearly define information security responsibilities for the board, senior management, governing bodies, and individuals. The standard does not prescribe a specific organizational structure but expects that accountability is unambiguous and that all individuals with information security responsibilities understand their obligations.

Information Security Capability

The core obligation of CPS 234 is to maintain an information security capability commensurate with the size and extent of threats. This capability must be maintained both within the entity and across any third-party arrangements. "Commensurate with threats" means entities must actively assess the threat landscape relevant to their specific sector, geography, and business model — not simply implement a fixed set of controls.

APRA expects entities in higher-threat environments — such as large banks processing millions of transactions daily — to maintain more sophisticated security capabilities than smaller, lower-complexity entities.

Policy Framework

Entities must maintain an information security policy framework that addresses the entity's information security risks. This framework must be reviewed at least annually and whenever there are material changes to the environment. Policies must cover the full spectrum of information security domains relevant to the entity's operations.

Information Asset Classification

CPS 234 requires entities to classify their information assets by criticality and sensitivity. This classification must form the basis for decisions about which controls to apply and with what intensity. Asset classification is a prerequisite for implementing proportionate, risk-based controls.

Security Controls Implementation

Controls must be implemented to protect information assets in a manner commensurate with asset criticality and sensitivity. CPS 234 does not prescribe a specific control set but expects entities to draw on recognized frameworks. APRA supervisory guidance references ISO 27001 and the Australian Cyber Security Centre's Essential Eight as appropriate reference points.

Incident Management and APRA Notification

CPS 234 contains explicit and time-bound notification requirements:

  • Material information security incidents must be notified to APRA within 72 hours of the entity becoming aware of the incident
  • Material control weaknesses that the entity reasonably believes could affect its information security capability must be notified to APRA within 10 business days of identification

A "material information security incident" is one that has materially affected or could materially affect the entity's operational capability or financial interests, or those of its customers. This is a demanding standard that requires rapid detection, triage, and escalation capabilities.

Testing of Control Effectiveness

CPS 234 requires entities to test the effectiveness of their information security controls through a systematic testing program. Testing must include:

  • Annual review by internal audit of the information security controls
  • Penetration testing of critical systems with a frequency commensurate with their risk profile
  • Vulnerability scanning and remediation processes

APRA expects testing results to feed into the ongoing improvement of the information security program. Internal audit must have the independence and capability to assess information security controls meaningfully.

Third-Party and Related-Party Risk

Where an entity uses third parties to manage information assets, the entity remains responsible for ensuring those third parties maintain information security commensurate with CPS 234. Contracts must include appropriate information security requirements. Entities must also manage information security risks across related parties — subsidiaries, holding companies, and affiliates sharing systems or data.

Audit and Assessment Process

CPS 234 compliance is assessed through two main mechanisms:

MechanismFrequencyScope
Internal audit reviewAnnualReview of all information security controls
APRA supervisory reviewPeriodicThematic reviews and entity-specific assessments
Penetration testingRisk-based (typically annual for critical systems)Critical information assets and systems

APRA has conducted multiple industry-wide thematic reviews of CPS 234 implementation and issued public findings highlighting common deficiencies. Key themes in APRA findings have included inadequate third-party security management, insufficient board-level engagement, and gaps in penetration testing coverage.

APRA can impose enforceable undertakings, increased capital requirements, or license conditions on entities that fail to meet CPS 234 standards.

Costs and Timeline

Entity TypeTypical TimelineEstimated Cost Range
Small ADI or insurer4–6 months$50,000–$150,000
Mid-sized bank or RSE6–9 months$150,000–$300,000
Large bank or insurer9–12 months$300,000–$500,000+

Ongoing annual costs include internal audit, penetration testing, policy maintenance, and third-party risk assessments.

  • ISO 27001: Approximately 70% overlap, making ISO 27001 an excellent foundation for CPS 234 compliance. The two frameworks align on risk-based control selection, asset classification, and policy management. ISO 27001 certification does not satisfy CPS 234's APRA notification and board governance requirements but substantially addresses the technical control obligations.
  • NIST CSF: About 65% overlap. NIST CSF's five functions (Identify, Protect, Detect, Respond, Recover) map closely to CPS 234's control, detection, and incident response requirements.
  • Australian Government ISM: The Australian Cyber Security Centre's Information Security Manual shares about 55% overlap with CPS 234, particularly in technical control requirements. Entities already implementing ISM controls will find significant alignment.

For Australian fintech companies also subject to international frameworks, see the MAS TRM guide for comparison with Singapore's equivalent framework, and the SWIFT CSP guide for SWIFT network security requirements.

How Automation Helps

CPS 234's board reporting, third-party risk management, and continuous control testing requirements benefit directly from compliance automation:

  • Automated evidence collection from cloud providers demonstrates ongoing control effectiveness for internal audit
  • Third-party risk management workflows track security assessments of service providers and generate APRA-compatible documentation
  • Incident tracking systems with APRA notification timers support the 72-hour notification obligation
  • Dashboard reporting provides board-ready visibility into control health and emerging threats

LowerPlane provides AI-powered compliance automation supporting CPS 234 alongside ISO 27001 and other frameworks across the 50-plus framework library. At $4,000 per year entry pricing with a free tier, and rated 9.4/10 on AuditXYZ, LowerPlane helps Australian financial institutions reduce manual evidence collection effort and maintain audit-ready documentation year-round. Compare platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

What is a "material information security incident" under CPS 234?

APRA describes a material incident as one that has materially affected or could materially affect the entity's operational capability or financial interests, or those of its customers, depositors, beneficiaries, or policyholders. In practice, this captures significant data breaches, ransomware attacks affecting critical systems, and incidents that cause or threaten operational disruption. APRA supervisory guidance clarifies that entities should err on the side of notification when uncertain — regulators prefer to be informed and not need the information than to learn about an incident through media reporting.

Does CPS 234 apply to cloud service providers?

Cloud service providers are not directly regulated by APRA but are subject to CPS 234 requirements indirectly through their APRA-regulated customers. APRA-regulated entities must ensure cloud providers maintain information security commensurate with CPS 234 and include appropriate contractual protections. APRA has published guidance on cloud outsourcing requirements, and many major cloud providers have developed CPS 234 compliance documentation specifically for Australian financial institutions.

What qualifies as a "material control weakness" that requires APRA notification?

A material control weakness is one that the entity reasonably believes has the potential to materially affect its information security capability. Examples include: discovery that a critical system has been operating without appropriate access controls, identification of a significant vulnerability in a core system that cannot be remediated immediately, or a finding by internal audit that a substantial portion of the control framework is ineffective. The 10-business-day notification window creates urgency for robust internal processes that can identify and escalate control weaknesses rapidly.

How does CPS 234 interact with the Privacy Act for Australian entities?

CPS 234 addresses information security from a prudential perspective, while the Privacy Act (with the Australian Privacy Principles) addresses the collection, use, and disclosure of personal information. The two frameworks are complementary — CPS 234's technical and physical safeguards requirements help entities meet their Privacy Act obligations to protect personal information from unauthorized access. Mandatory data breach notification under the Privacy Act (required for eligible data breaches) may also be triggered by incidents that require APRA notification under CPS 234.

Is annual penetration testing required under CPS 234?

CPS 234 requires testing with frequency commensurate with risk — it does not mandate annual penetration testing as a blanket rule. However, APRA's supervisory expectations and guidance documents consistently reference annual penetration testing for critical systems as an expected minimum practice. Entities with particularly complex or high-risk environments may be expected to test more frequently. Internal audit must review the effectiveness of the information security controls annually, which typically includes assessing the penetration testing program.

Request a APRA CPS 234 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001Medium70%
NIST CSFMedium65%
ISMMedium55%

Related frameworks

Get matched with a APRA CPS 234 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.