CPS 230 and the supplier squeeze: what Australian businesses supplying banks and super funds must do now
Author: Dan Briggs Published: 20 July 2026 Reading time: 15 minutes
Executive summary
APRA's operational risk standard, CPS 230, commenced on 1 July 2025, and its most important date for smaller businesses has just passed. The transitional relief that let banks, insurers and superannuation funds keep older supplier contracts as-is ran out on the earlier of each contract's next renewal or 1 July 2026. From that point, every APRA-regulated entity has to hold CPS 230-compliant agreements with its material service providers and manage those suppliers to a much higher standard.
Here is the part most commentary misses: CPS 230 is written for the regulated financial institution, but the cost, the paperwork and the new obligations land squarely on the suppliers. If your business provides IT, software, payroll, printing, cloud hosting, call-centre, claims handling, professional services or facilities to a bank, credit union, insurer or super fund, you may now be a material service provider, and you are being asked to sign up to audit rights, incident-notification clocks, business continuity testing and fourth-party disclosure whether or not you have ever heard of CPS 230.
We are seeing this play out in real client environments right now. Over the past few months, professional services firms and small technology providers across Sydney, Brisbane, Melbourne and Central West NSW have been handed 40-page vendor questionnaires and revised contracts by their financial-sector customers, with sign-by dates and the implied threat of losing the account. This whitepaper explains what changed, how to tell whether it applies to you, what the clauses actually require in plain terms, and the practical steps to protect the relationship (and the revenue) without over-committing your business.
What actually changed on 1 July 2026
CPS 230 Operational Risk Management is APRA's prudential standard designed to make regulated entities more resilient to disruption, whether that disruption comes from a cyber incident, a failed system, a natural disaster or a supplier going dark. It replaced a patchwork of older standards and guidance and pulled three things into one place: operational risk management, business continuity, and the management of service providers.
The standard commenced on 1 July 2025. But APRA recognised that regulated entities could not renegotiate every existing supplier contract overnight, so it allowed a transition for pre-existing material arrangements. For those older contracts, the service-provider requirements apply from the earlier of the contract's next renewal date or 1 July 2026. That backstop date has now arrived. APRA also finalised targeted amendments on 30 April 2026 that carved out a narrow exemption for certain non-traditional providers such as payment schemes and clearing facilities, with the updated CPS 230 and its guidance (CPG 230) taking effect from 1 July 2026.
For a bank or super fund, the practical consequence is simple and uncomfortable: as of now, they are expected to be able to show APRA a complete register of their material service providers, legally binding agreements that contain a specific list of protections, and evidence that they are actively managing the operational risk those suppliers carry. They cannot produce that evidence unless their suppliers cooperate. That is why the requests have landed on your desk.
Are you a "material service provider"?
Under CPS 230, a service provider is "material" if the regulated entity relies on it to perform a critical operation, or if the arrangement exposes the entity to significant operational risk. Critical operations are the processes that, if disrupted beyond an acceptable tolerance, would cause material harm to customers such as depositors, policyholders and fund members, or to the financial system itself. Think core banking, payments, claims processing, member administration, and the systems and people that keep those running.
The standard names some provider types that will usually be treated as material, including shared computing services such as cloud, core technology platforms, credit assessment, funds management, and the administration of member or policyholder data. The list is not exhaustive, and this is where smaller suppliers get caught out. Materiality is about the role you play, not the size of your invoice. A two-person firm that hosts a credit union's loan origination system, or a boutique consultancy that runs a super fund's member-facing portal, can be just as material as a multinational.
It is also worth knowing that you might be a "fourth party" rather than a direct supplier. If you subcontract to a company that itself services a bank, CPS 230 pushes the regulated entity to understand and manage that chain too, so the obligations can reach you indirectly.
What the flow-down clauses really require
When a regulated entity brings a contract into line with CPS 230, it is not adding vague "best endeavours" language. APRA sets out specific provisions the agreement must address. Translated out of legalese, here is what a material service provider is typically being asked to accept.
A binding agreement with defined service levels
The days of a one-page order form or a handshake are over for material arrangements. Expect a formal agreement that spells out the services, measurable service levels, and each party's rights and responsibilities, including a force majeure provision and clear termination rights.
Audit and access rights
The regulated entity, and APRA itself, must be able to obtain documentation and information and to conduct on-site visits and audits of your operations, processes and controls. In practice this means you can be inspected, and you need to be able to produce evidence that your controls actually work, not just that they exist on paper.
Fourth-party and subcontractor transparency
You will usually be required to disclose the other providers you materially rely on, notify changes to them, and remain liable for any failure by a subcontractor. If you run the client's workload on someone else's cloud, or use an overseas development team, that now has to be visible and accounted for.
Business continuity coordination
CPS 230 leans heavily on the ability to keep critical operations running. Contracts increasingly require you to maintain, test and share business continuity and disaster-recovery arrangements, and to coordinate your recovery with the client's so the two plans actually line up during a real incident.
Incident notification
This is the clause with teeth, and it deserves its own section because the timeframes are short and they now flow through to you.
The 24-hour and 72-hour clocks that now touch you
CPS 230 imposes two notification deadlines on the regulated entity, and both depend on the supplier raising the alarm quickly.
Read those two deadlines from a supplier's point of view. If your platform is the critical operation, the bank cannot start its 24-hour clock until you tell them something has gone wrong. So the contract you are being asked to sign will almost certainly require you to notify the client within a very tight window, often two to twelve hours, sometimes faster, so they still have room to meet their own deadline. In effect, the regulator's clock has been pushed upstream onto your incident-response process.
The uncomfortable truth we see in many smaller providers is that they have no defined incident-response process at all, or one that lives in a single person's head. Under CPS 230-driven contracts, that gap becomes a breach waiting to happen. You do not need a security operations centre, but you do need a written, tested runbook that says who decides an incident has occurred, who they call at the client, and how fast. Our related explainer on what to do as the ASD retires the Essential Eight is a good companion here, because the underlying security baseline these contracts assume has not gone away.
What this means for your business, in dollars and risk
Let us be direct about the costs and the upside, because that is what actually matters for an owner or manager.
The revenue at stake
For firms with a financial-services client base, these accounts are often the largest and stickiest in the book. Failing to meet the new contract requirements is now a genuine way to lose them. Regulated entities are under pressure to reduce or exit relationships with suppliers who cannot demonstrate compliance, and some are consolidating their supplier lists to shrink the number of material arrangements they have to manage. If you are on the bubble, doing nothing is the riskiest option.
The compliance and remediation cost
Meeting the clauses is not free. You may need to formalise a business continuity plan, stand up proper logging and monitoring, document your controls, tighten access management, and potentially carry cyber insurance at a level you did not before. For a typical small professional services or technology firm we work with, the first-year uplift tends to sit in the low-to-mid five figures, mostly one-off, and much of it is work you should arguably have done anyway.
The breach cost you are trying to avoid
The reason all of this exists is that supplier-driven incidents are expensive and common. Small businesses are squarely in the firing line. We covered how the average cost of cybercrime for a small Australian business has climbed in our piece on the three pathways attackers use and what they cost. A single incident that takes down a client's critical operation, on top of the reputational damage, can wipe out the margin from that account for years.
The opportunity
Here is the angle we encourage clients to take. Being genuinely CPS 230-ready is a competitive moat. Most of your competitors are treating these questionnaires as a compliance nuisance and filling them in badly. If you can honestly answer them, produce evidence, and speak the language of operational resilience, you become the low-risk supplier the bank wants to consolidate towards, not away from.
The local picture: mutuals, super and professional services
This is not an abstract big-four-bank problem. Australia's financial system is full of smaller APRA-regulated entities, and they lean heavily on local suppliers.
Across Central West NSW, customer-owned mutual banks and credit unions serving Orange, Bathurst and Dubbo are APRA-regulated authorised deposit-taking institutions, and they source a lot of their technology, professional services and administration from firms in the same region. If your Orange or Bathurst business supports one of them, CPS 230 has almost certainly reached your contracts. We are having exactly these conversations with regional clients now.
In Sydney, and particularly across the Northern Beaches and Brookvale professional-services cluster, we see accountants, advisers, brokers, law firms and IT providers who service superannuation funds, insurers and lenders. Many of these firms were only recently brought under the Privacy Act's reach as well. We wrote about that in why Northern Beaches agents and accountants are now under the Privacy Act. CPS 230 stacks on top of that, so a single practice can be juggling privacy obligations and material-service-provider obligations for different clients at once.
Brisbane and Melbourne tell the same story with insurers, funds and fintechs. And the third-party risk theme is not unique to APRA. The OAIC's findings from the Qantas matter put a spotlight on how organisations are accountable for data held by their suppliers, which we unpacked in our note on what the OAIC's Qantas findings mean for third-party data. The common thread across all of it is that regulators now expect organisations to own the risk of everyone in their supply chain, and that expectation is being written into the contracts you sign.
Your CPS 230 supplier-readiness checklist
If a financial-services client has sent you a questionnaire or a revised contract, or you expect one, work through this before you sign anything.
| Action | Why it matters | Priority |
|---|---|---|
| Confirm whether you are classified as material, and for which service | Determines which obligations actually apply and how hard you should push back on scope | Immediate |
| Read the incident-notification clause and pin down the exact hours | This is the clause most likely to trip you up in a real incident | Immediate |
| Write and test a simple incident-response runbook | You cannot meet a two-to-twelve-hour notification promise without a defined process | High |
| Document your fourth parties (cloud, subcontractors, offshore teams) | You will be required to disclose and stay liable for them | High |
| Formalise and test a business continuity and disaster-recovery plan | Contracts require it, and clients may ask for test evidence | High |
| Evidence your security controls (access, logging, patching, backups, MFA) | Audit rights mean you must prove controls work, not just assert them | High |
| Check your cyber insurance limits and exclusions | Liability for subcontractor failure and audit obligations can change your risk profile | Medium |
| Negotiate proportionate audit and liability terms before signing | Standard templates are drafted for large vendors; smaller firms can and should negotiate | Medium |
| Assign a named owner for the client relationship and compliance evidence | APRA-driven requests recur; someone needs to own the responses | Medium |
"But we're not APRA-regulated": why it still matters
Plenty of business owners read a standard like CPS 230, see that it applies to banks and super funds, and assume it has nothing to do with them. That was a safe assumption two years ago. It is not any more. The whole design of modern operational-risk regulation is to make the regulated entity responsible for its suppliers, which means the obligations are deliberately engineered to flow downhill through contracts to businesses that the regulator never directly touches.
So even though APRA will never audit your small firm directly, your bank client effectively can, on APRA's behalf, through the rights in your contract. And the practical bar you are being held to is close to what a regulated entity has to meet for the slice of its operation you run. The sensible response is not to panic or to refuse, but to understand exactly where you sit, meet the requirements that are genuinely proportionate to your role, and push back professionally on anything that is not.
How All IT Services can help
We work with Australian small and mid-market businesses across Sydney, Brisbane, Melbourne and Central West NSW, including a good number who supply the financial sector. When a CPS 230-driven contract or questionnaire lands, we help you work out whether you are genuinely material, translate the clauses into a practical to-do list, close the real gaps in your security, business continuity and incident response, and produce the evidence your client's risk team is asking for, without gold-plating things your business does not need.
If you have been handed a vendor questionnaire, a revised agreement, or a due-diligence request from a bank, insurer or super fund and you are not sure how to respond, talk to us before the sign-by date. Call 1300 425 548 or get in touch online and we will help you protect the account and your business.
Frequently asked questions
Got a Vendor Questionnaire or Revised Contract?
Talk to us before the sign-by date. We help Australian businesses supplying banks, insurers and super funds understand exactly what CPS 230 requires of them, close the real gaps, and produce the evidence their clients need.
