Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

CPS 230 and material service providers whitepaper hero graphic

CPS 230 and the supplier squeeze: what Australian businesses supplying banks and super funds must do now

Executive summary

APRA's operational risk standard, CPS 230, commenced on 1 July 2025, and its most important date for smaller businesses has just passed. The transitional relief that let banks, insurers and superannuation funds keep older supplier contracts as-is ran out on the earlier of each contract's next renewal or 1 July 2026. From that point, every APRA-regulated entity has to hold CPS 230-compliant agreements with its material service providers and manage those suppliers to a much higher standard.

Here is the part most commentary misses: CPS 230 is written for the regulated financial institution, but the cost, the paperwork and the new obligations land squarely on the suppliers. If your business provides IT, software, payroll, printing, cloud hosting, call-centre, claims handling, professional services or facilities to a bank, credit union, insurer or super fund, you may now be a material service provider, and you are being asked to sign up to audit rights, incident-notification clocks, business continuity testing and fourth-party disclosure whether or not you have ever heard of CPS 230.

We are seeing this play out in real client environments right now. Over the past few months, professional services firms and small technology providers across Sydney, Brisbane, Melbourne and Central West NSW have been handed 40-page vendor questionnaires and revised contracts by their financial-sector customers, with sign-by dates and the implied threat of losing the account. This whitepaper explains what changed, how to tell whether it applies to you, what the clauses actually require in plain terms, and the practical steps to protect the relationship (and the revenue) without over-committing your business.

What actually changed on 1 July 2026

CPS 230 Operational Risk Management is APRA's prudential standard designed to make regulated entities more resilient to disruption, whether that disruption comes from a cyber incident, a failed system, a natural disaster or a supplier going dark. It replaced a patchwork of older standards and guidance and pulled three things into one place: operational risk management, business continuity, and the management of service providers.

The standard commenced on 1 July 2025. But APRA recognised that regulated entities could not renegotiate every existing supplier contract overnight, so it allowed a transition for pre-existing material arrangements. For those older contracts, the service-provider requirements apply from the earlier of the contract's next renewal date or 1 July 2026. That backstop date has now arrived. APRA also finalised targeted amendments on 30 April 2026 that carved out a narrow exemption for certain non-traditional providers such as payment schemes and clearing facilities, with the updated CPS 230 and its guidance (CPG 230) taking effect from 1 July 2026.

For a bank or super fund, the practical consequence is simple and uncomfortable: as of now, they are expected to be able to show APRA a complete register of their material service providers, legally binding agreements that contain a specific list of protections, and evidence that they are actively managing the operational risk those suppliers carry. They cannot produce that evidence unless their suppliers cooperate. That is why the requests have landed on your desk.

Are you a "material service provider"?

Under CPS 230, a service provider is "material" if the regulated entity relies on it to perform a critical operation, or if the arrangement exposes the entity to significant operational risk. Critical operations are the processes that, if disrupted beyond an acceptable tolerance, would cause material harm to customers such as depositors, policyholders and fund members, or to the financial system itself. Think core banking, payments, claims processing, member administration, and the systems and people that keep those running.

The standard names some provider types that will usually be treated as material, including shared computing services such as cloud, core technology platforms, credit assessment, funds management, and the administration of member or policyholder data. The list is not exhaustive, and this is where smaller suppliers get caught out. Materiality is about the role you play, not the size of your invoice. A two-person firm that hosts a credit union's loan origination system, or a boutique consultancy that runs a super fund's member-facing portal, can be just as material as a multinational.

A useful test: if your service stopped tomorrow, or your systems were breached, could it stop the financial institution from serving its customers, or expose those customers' data? If the honest answer is yes, expect to be classified as material, and expect the contract and questionnaire that comes with it.

It is also worth knowing that you might be a "fourth party" rather than a direct supplier. If you subcontract to a company that itself services a bank, CPS 230 pushes the regulated entity to understand and manage that chain too, so the obligations can reach you indirectly.

What the flow-down clauses really require

When a regulated entity brings a contract into line with CPS 230, it is not adding vague "best endeavours" language. APRA sets out specific provisions the agreement must address. Translated out of legalese, here is what a material service provider is typically being asked to accept.

A binding agreement with defined service levels

The days of a one-page order form or a handshake are over for material arrangements. Expect a formal agreement that spells out the services, measurable service levels, and each party's rights and responsibilities, including a force majeure provision and clear termination rights.

Audit and access rights

The regulated entity, and APRA itself, must be able to obtain documentation and information and to conduct on-site visits and audits of your operations, processes and controls. In practice this means you can be inspected, and you need to be able to produce evidence that your controls actually work, not just that they exist on paper.

Fourth-party and subcontractor transparency

You will usually be required to disclose the other providers you materially rely on, notify changes to them, and remain liable for any failure by a subcontractor. If you run the client's workload on someone else's cloud, or use an overseas development team, that now has to be visible and accounted for.

Business continuity coordination

CPS 230 leans heavily on the ability to keep critical operations running. Contracts increasingly require you to maintain, test and share business continuity and disaster-recovery arrangements, and to coordinate your recovery with the client's so the two plans actually line up during a real incident.

Incident notification

This is the clause with teeth, and it deserves its own section because the timeframes are short and they now flow through to you.

The 24-hour and 72-hour clocks that now touch you

CPS 230 imposes two notification deadlines on the regulated entity, and both depend on the supplier raising the alarm quickly.

A regulated entity must notify APRA within 72 hours of becoming aware of an operational risk incident likely to have a material financial impact or material impact on its critical operations. Separately, it must notify APRA within 24 hours of a disruption to a critical operation that breaches its approved tolerance levels. Both clocks depend on your speed.

Read those two deadlines from a supplier's point of view. If your platform is the critical operation, the bank cannot start its 24-hour clock until you tell them something has gone wrong. So the contract you are being asked to sign will almost certainly require you to notify the client within a very tight window, often two to twelve hours, sometimes faster, so they still have room to meet their own deadline. In effect, the regulator's clock has been pushed upstream onto your incident-response process.

The uncomfortable truth we see in many smaller providers is that they have no defined incident-response process at all, or one that lives in a single person's head. Under CPS 230-driven contracts, that gap becomes a breach waiting to happen. You do not need a security operations centre, but you do need a written, tested runbook that says who decides an incident has occurred, who they call at the client, and how fast. Our related explainer on what to do as the ASD retires the Essential Eight is a good companion here, because the underlying security baseline these contracts assume has not gone away.

What this means for your business, in dollars and risk

Let us be direct about the costs and the upside, because that is what actually matters for an owner or manager.

The revenue at stake

For firms with a financial-services client base, these accounts are often the largest and stickiest in the book. Failing to meet the new contract requirements is now a genuine way to lose them. Regulated entities are under pressure to reduce or exit relationships with suppliers who cannot demonstrate compliance, and some are consolidating their supplier lists to shrink the number of material arrangements they have to manage. If you are on the bubble, doing nothing is the riskiest option.

The compliance and remediation cost

Meeting the clauses is not free. You may need to formalise a business continuity plan, stand up proper logging and monitoring, document your controls, tighten access management, and potentially carry cyber insurance at a level you did not before. For a typical small professional services or technology firm we work with, the first-year uplift tends to sit in the low-to-mid five figures, mostly one-off, and much of it is work you should arguably have done anyway.

The breach cost you are trying to avoid

The reason all of this exists is that supplier-driven incidents are expensive and common. Small businesses are squarely in the firing line. We covered how the average cost of cybercrime for a small Australian business has climbed in our piece on the three pathways attackers use and what they cost. A single incident that takes down a client's critical operation, on top of the reputational damage, can wipe out the margin from that account for years.

The opportunity

Here is the angle we encourage clients to take. Being genuinely CPS 230-ready is a competitive moat. Most of your competitors are treating these questionnaires as a compliance nuisance and filling them in badly. If you can honestly answer them, produce evidence, and speak the language of operational resilience, you become the low-risk supplier the bank wants to consolidate towards, not away from.

We have watched providers win business off less-prepared rivals precisely because they had their house in order. CPS 230 readiness is not just about keeping the account you have. It is a differentiator when competing for new ones.

The local picture: mutuals, super and professional services

This is not an abstract big-four-bank problem. Australia's financial system is full of smaller APRA-regulated entities, and they lean heavily on local suppliers.

Across Central West NSW, customer-owned mutual banks and credit unions serving Orange, Bathurst and Dubbo are APRA-regulated authorised deposit-taking institutions, and they source a lot of their technology, professional services and administration from firms in the same region. If your Orange or Bathurst business supports one of them, CPS 230 has almost certainly reached your contracts. We are having exactly these conversations with regional clients now.

In Sydney, and particularly across the Northern Beaches and Brookvale professional-services cluster, we see accountants, advisers, brokers, law firms and IT providers who service superannuation funds, insurers and lenders. Many of these firms were only recently brought under the Privacy Act's reach as well. We wrote about that in why Northern Beaches agents and accountants are now under the Privacy Act. CPS 230 stacks on top of that, so a single practice can be juggling privacy obligations and material-service-provider obligations for different clients at once.

Brisbane and Melbourne tell the same story with insurers, funds and fintechs. And the third-party risk theme is not unique to APRA. The OAIC's findings from the Qantas matter put a spotlight on how organisations are accountable for data held by their suppliers, which we unpacked in our note on what the OAIC's Qantas findings mean for third-party data. The common thread across all of it is that regulators now expect organisations to own the risk of everyone in their supply chain, and that expectation is being written into the contracts you sign.

Your CPS 230 supplier-readiness checklist

If a financial-services client has sent you a questionnaire or a revised contract, or you expect one, work through this before you sign anything.

Action Why it matters Priority
Confirm whether you are classified as material, and for which service Determines which obligations actually apply and how hard you should push back on scope Immediate
Read the incident-notification clause and pin down the exact hours This is the clause most likely to trip you up in a real incident Immediate
Write and test a simple incident-response runbook You cannot meet a two-to-twelve-hour notification promise without a defined process High
Document your fourth parties (cloud, subcontractors, offshore teams) You will be required to disclose and stay liable for them High
Formalise and test a business continuity and disaster-recovery plan Contracts require it, and clients may ask for test evidence High
Evidence your security controls (access, logging, patching, backups, MFA) Audit rights mean you must prove controls work, not just assert them High
Check your cyber insurance limits and exclusions Liability for subcontractor failure and audit obligations can change your risk profile Medium
Negotiate proportionate audit and liability terms before signing Standard templates are drafted for large vendors; smaller firms can and should negotiate Medium
Assign a named owner for the client relationship and compliance evidence APRA-driven requests recur; someone needs to own the responses Medium

"But we're not APRA-regulated": why it still matters

Plenty of business owners read a standard like CPS 230, see that it applies to banks and super funds, and assume it has nothing to do with them. That was a safe assumption two years ago. It is not any more. The whole design of modern operational-risk regulation is to make the regulated entity responsible for its suppliers, which means the obligations are deliberately engineered to flow downhill through contracts to businesses that the regulator never directly touches.

So even though APRA will never audit your small firm directly, your bank client effectively can, on APRA's behalf, through the rights in your contract. And the practical bar you are being held to is close to what a regulated entity has to meet for the slice of its operation you run. The sensible response is not to panic or to refuse, but to understand exactly where you sit, meet the requirements that are genuinely proportionate to your role, and push back professionally on anything that is not.

Supply-chain and third-party obligations are the direction of travel across Australian regulation, from the Privacy Act reforms to the Cyber Security Act 2024 to APRA's standards. Getting your operational resilience basics right once, properly, means you can answer the next questionnaire from the next client in a different sector without starting from scratch.

How All IT Services can help

We work with Australian small and mid-market businesses across Sydney, Brisbane, Melbourne and Central West NSW, including a good number who supply the financial sector. When a CPS 230-driven contract or questionnaire lands, we help you work out whether you are genuinely material, translate the clauses into a practical to-do list, close the real gaps in your security, business continuity and incident response, and produce the evidence your client's risk team is asking for, without gold-plating things your business does not need.

If you have been handed a vendor questionnaire, a revised agreement, or a due-diligence request from a bank, insurer or super fund and you are not sure how to respond, talk to us before the sign-by date. Call 1300 425 548 or get in touch online and we will help you protect the account and your business.


Frequently asked questions

Under CPS 230, a service provider is material if an APRA-regulated entity relies on it to perform a critical operation, or if the arrangement exposes the entity to significant operational risk. It is about the role you play, not the size of the contract, so a small firm running a core system for a credit union can be just as material as a large vendor.
Not directly. CPS 230 applies to APRA-regulated entities such as banks, insurers and super funds. But those entities are required to hold compliant contracts with their material service providers and to manage them closely, so the obligations flow through to suppliers via the contracts you sign. In practice, if you service a regulated entity, you are being asked to meet CPS 230-aligned requirements.
A regulated entity must notify APRA within 72 hours of an operational risk incident likely to have a material financial impact or a material impact on its ability to maintain critical operations. It must notify APRA within 24 hours of a disruption to a critical operation that breaches its approved tolerance levels. Because those clocks depend on suppliers raising the alarm, your contract will usually require you to notify the client much faster than either deadline.
You risk losing the account, because regulated entities are under pressure to reduce reliance on suppliers who cannot demonstrate compliance. The better path is to identify which requirements are genuinely proportionate to your role, meet those, and negotiate the rest professionally. Most standard templates are drafted for large vendors and smaller firms can reasonably negotiate audit scope and liability terms.
Straight away if you have already received a questionnaire or revised contract, because your client is now expected to hold compliant arrangements and may have its own deadline. Even if nothing has landed yet, use the time to write and test an incident-response runbook, document your fourth parties, and evidence your security controls, so you are ready when the request comes.

Got a Vendor Questionnaire or Revised Contract?

Talk to us before the sign-by date. We help Australian businesses supplying banks, insurers and super funds understand exactly what CPS 230 requires of them, close the real gaps, and produce the evidence their clients need.