CPS 230: What Lands on 1 July 2026 and What to Do About It
Executive Summary
On 1 July 2026, the last of the transition arrangements under APRA's Prudential Standard CPS 230 Operational Risk Management run out. From that date, every contract a regulated bank, insurer or superannuation trustee holds with a material service provider must meet the standard's requirements, whether or not the contract has come up for renewal.
On the same day, smaller institutions lose the extra year APRA gave them on business continuity and scenario analysis, and the targeted amendments APRA finalised on 30 April 2026 come into effect, along with an updated Material Service Provider Register template.
If you run an APRA-regulated entity, none of this should be news, but our experience says the contract uplift is where timetables have slipped. If your register lists agreements that still don't contain APRA access rights, data ownership clauses or proper termination provisions, you have three weeks to close the gap, or to be able to show APRA a credible plan for closing it.
The bigger story is for everyone else. CPS 230 reaches well beyond the banks, insurers and super funds APRA supervises, because it forces those entities to rewrite their contracts with the businesses that serve them. Software vendors, IT providers, fund administrators, claims handlers, brokers, BPOs, payroll bureaus and document management firms have spent the past year receiving "contract uplift" letters from their financial services clients. This whitepaper explains what lands on 1 July 2026, who is directly caught, what the uplift letters actually ask for, and what to do in the next three weeks.
A Quick Refresher: What CPS 230 Actually Is
CPS 230 is APRA's cross-industry standard for operational risk. It commenced on 1 July 2025 and replaced the old outsourcing and business continuity standards (CPS 231 and CPS 232, and their industry equivalents). It applies to all APRA-regulated entities: banks, mutual banks and credit unions, general insurers, life insurers, private health insurers, friendly societies and superannuation trustees. APRA supervises institutions holding about $9.8 trillion in assets, so the standard's reach across the economy is considerable.
In plain terms, CPS 230 asks three things of a regulated entity.
Identify the processes that would materially hurt customers or the financial system if they stopped: payments and deposit-taking for a bank, claims processing for an insurer, fund administration and investment management for a super trustee. Set Board-approved tolerance levels for how long each can be down, how much data can be lost, and the maximum acceptable extent of disruption.
The BCP must be tested annually against severe but plausible scenarios, and those scenarios must include disruptions to services provided by material service providers. APRA can direct an entity to run a specific scenario it nominates.
Identify material service providers, maintain a register, submit it to APRA annually, conduct due diligence before signing or materially changing agreements, and ensure those agreements contain a specific set of contractual protections. The first registers went in by 1 October 2025.
The standard also sets hard notification clocks. An entity must tell APRA within 72 hours of becoming aware of an operational risk incident likely to have a material financial impact, and within 24 hours if a critical operation is disrupted beyond tolerance. New or materially changed agreements supporting critical operations must be notified within 20 business days.
Three Deadlines Land on the Same Day
What makes 1 July 2026 worth a whitepaper rather than a footnote is that three separate transition tracks converge on it.
Pre-existing contracts run out of road
When CPS 230 commenced last year, APRA allowed existing contractual arrangements with material service providers to keep running on their old terms until the earlier of the contract's next renewal date or 1 July 2026. That grace period is what ends in three weeks. Any agreement that hasn't been renegotiated since, including evergreen arrangements that never formally renew, must comply from 1 July.
Smaller institutions lose their extension
In 2024, APRA gave non-significant financial institutions (non-SFIs) an extra 12 months on the business continuity and scenario analysis requirements. Broadly, non-SFIs are most mutual banks and credit unions, smaller and captive insurers, and boutique super trustees. They were allowed to keep operating under the old business continuity standards in the interim. From 1 July 2026 that concession ends, and the full CPS 230 requirements apply in full.
For a 60-person mutual or a small trustee office, this is the harder deadline. Contract uplift is mostly a legal exercise. Scenario analysis is an operational one: it requires knowing your systems, your dependencies and your actual recovery capability, then proving it with a test.
The April amendments and the new register template take effect
On 30 April 2026, APRA finalised targeted amendments to CPS 230, the accompanying practice guide CPG 230, and the register template. The amendments create a narrow exemption from some contractual requirements for material arrangements with what APRA calls non-traditional service providers (such as central banks and clearing and settlement facilities), where demanding bespoke contract terms simply isn't practicable. Everything else still applies. The changes commence 1 July 2026.
The Wider Blast Radius: Are You a Material Service Provider?
A material service provider is one the entity relies on to maintain a critical operation, or one that exposes it to material operational risk. You don't get a vote on the classification. The regulated entity makes the call, and APRA can override it by deeming a provider or a whole class of providers material.
On top of that judgement call, CPS 230 deems certain services material by default:
- For every regulated entity: risk management, core technology services and internal audit.
- For banks and other ADIs: credit assessment, funds management, custody, settlement and clearing.
- For insurers: underwriting, claims management, insurance brokerage and reinsurance.
- For super trustees: fund administration, custodial services, investment management and arrangements with promoters and financial planners.
The standard also looks one layer further down, at what it calls fourth parties: the providers your business relies on to deliver the service. Uplift questionnaires now routinely ask suppliers to disclose their own subcontractors and key dependencies, including which cloud platforms and data centres they run on. If your service to a super fund runs on Microsoft 365 and Azure, expect to be asked exactly that, in writing.
What the Contract Uplift Letter Actually Asks For
CPS 230 prescribes minimum content for any agreement with a material service provider. When the uplift letter arrives, the attached amendment deed will usually track the standard clause by clause.
| What the contract must now include | What it means for you as the supplier |
|---|---|
| Specified services and service levels | Vague statements of work are out. Expect defined deliverables, measurable SLAs and reporting against them. |
| Ownership and control of data and assets | The client will want it recorded that their data is theirs, with clarity on where it lives, who can access it and how it's returned or destroyed on exit. |
| Audit and access rights for the entity | Your client can inspect documentation, data and operations related to the service. Negotiate notice periods and confidentiality boundaries rather than resist the right itself. |
| APRA access and on-site visit rights | The regulator itself gets the right to access information about the service and visit your premises. This clause is non-negotiable; the entity cannot sign without it. |
| Notification of subcontracting | You must disclose other material providers you rely on to deliver the service, and usually notify changes to them. Quietly swapping a key subcontractor is no longer an option. |
| Liability for subcontractor failure | If your subcontractor drops the ball, contractually that's your failure. Check your own back-to-back agreements and insurance reflect that. |
| Force majeure provisions | The contract must specify which parts of the service continue during a force majeure event, which means you need a real continuity capability, not a clause that excuses you from everything. |
| Termination rights, in whole or in part | The client must be able to exit the arrangement, including where staying in it would breach their legal obligations. Expect transition-out assistance obligations too. |
| Support for legal and compliance obligations | Catch-all provisions requiring you to cooperate with the entity's regulatory obligations, including the incident notification clocks. |
Alongside the deed, there's usually a due diligence questionnaire covering your financial position, security posture, business continuity arrangements and incident history. Because CPS 234 Information Security continues to operate alongside CPS 230, expect specific questions about your information security controls.
If You're the Supplier: How to Respond Without Signing Away the Farm
- Don't ignore the letter. The entity has a hard deadline and no discretion about the minimum clauses. Suppliers who stall past 1 July aren't strengthening their negotiating position; they're creating a compliance problem their client must report and manage. The entities we work with have already identified which suppliers they would substitute if uplift fails.
- Understand which clauses are fixed and which are drafting. APRA access, audit rights, data ownership, subcontractor disclosure and termination rights have to be there in substance. But notice periods for audits, the scope of what's auditable, cost recovery for assistance, liability caps and the mechanics of transition-out are all negotiable drafting. Spend your legal budget there.
- Build the evidence pack once. Every uplift questionnaire asks roughly the same things: who can access client data and how access is controlled, where data is stored and replicated, what your backup and recovery capability actually is (with test results, not assertions), how you'd detect and report an incident within your client's 72-hour window, and which subcontractors and platforms you depend on. Answering this once, properly, turns every subsequent questionnaire into a half-day job instead of a three-week scramble. It also becomes a sales asset.
- Map your own dependencies properly. Your Microsoft 365 tenancy, your hosting provider, your RMM tooling and your offshore development partner are all disclosable. If you don't have a current dependency map, build one before you answer the questionnaire, not while you're answering it.
- Check your insurance. Accepting liability for subcontractor failure and committing to incident notification timeframes has consequences for your professional indemnity and cyber cover. Tell your broker what you're signing.
If You're the Regulated Entity: A Three-Week Triage
For non-SFIs and any entity with uplift still in flight, here is the triage we'd run between now and 30 June.
- Reconcile the register against reality. Pull the register you submitted last October and confirm every material arrangement on it has either a compliant agreement or a dated, documented uplift plan. The updated template takes effect for the 2026 submission, so check what's changed before you populate it.
- Prioritise by criticality, not by contract value. A $30,000-a-year software dependency that sits inside a critical operation matters more than a $300,000 facilities contract that doesn't.
- Paper the stragglers. Where a supplier can't complete uplift by 1 July, document the gap, the interim controls and the remediation date. APRA's supervisors respond very differently to a known, managed gap than to one they find first.
- Decide whether you're relying on the NTSP exemption. If any material arrangements are with exempt-category providers on standardised terms, document the reliance and reflect it in the register.
- Close out business continuity, if you're a non-SFI. Tolerance levels approved by the Board, a BCP that reflects them, and at least one severe-but-plausible scenario exercise completed including a provider-disruption scenario. If you haven't scheduled the exercise yet, do it this week.
- Test the notification clocks. Run a tabletop: an incident hits at 2pm Friday, who decides it's material, who drafts the APRA notification, and can you actually do it inside 72 hours? The clock starts when you become aware, and awareness depends entirely on your monitoring.
Where Your IT Environment Does the Heavy Lifting
CPS 230 is a risk standard, not a technology standard, but nearly every obligation in it lands on technology eventually. Four areas decide whether compliance is a document or a capability.
The 72-hour and 24-hour notification windows only work if incidents are detected when they happen, not when a customer complains. That means centralised logging and alerting across your environment, including your Microsoft 365 tenancy, with someone responsible for triage out of hours. We're seeing clients fail their own tabletop exercises not on the reporting step but on the awareness step: the incident had been visible in logs for two days before anyone classified it.
Contract clauses about data ownership are only as good as the tenancy configuration behind them. Who actually holds global admin on your Microsoft 365 tenant? If your IT provider does and you're a regulated entity, that provider is exercising control over your information assets, and your uplifted contract needs to say so. We structure client tenancies so the business, not the provider, retains ownership and ultimate admin control.
Tolerance levels imply recovery time and recovery point commitments. The only honest way to set them is from tested numbers: how long a full restore of your line-of-business system actually takes, verified this year, not estimated from a vendor datasheet. Scenario analysis that uses real restore timings takes about the same effort as scenario analysis that uses guesses, and only one of them survives contact with APRA's supervision team.
Whether you're filling in the register or answering an uplift questionnaire, you need an accurate map of which systems support which operations and which providers sit behind each system, down to the fourth-party layer. Most organisations discover their documentation is two restructures out of date the first time they try. Keeping that map current is exactly the kind of thing a managed IT partner should be doing for you as a matter of course.
What Happens If You Miss the Deadline
CPS 230 doesn't come with a fine schedule, and that has led some businesses to underrate it. APRA's tools are arguably worse than fines: heightened supervision, formal requirements to remediate, conditions on licences and, for individuals in regulated entities, intersections with the Financial Accountability Regime. Operational risk is a stated supervision priority, and the regulator has been signalling for two years that it expects the transition to be done on time.
For suppliers, the consequence is commercial rather than regulatory. The standard requires entities to plan for substituting providers, and the uplift process has forced them to identify alternatives. A supplier who can't produce security evidence, continuity test results or a subcontractor map is now measurably riskier than one who can, and procurement teams in financial services have a fresh mandate to act on that difference.
One More Thing About 1 July
This deadline shares its date with two others: the Microsoft 365 price rises that take effect 1 July, and the start of AML/CTF Tranche 2 obligations for lawyers, accountants and real estate professionals. If your budget and compliance calendars are converging on the same fortnight, you're not alone, and it's a good argument for getting the CPS 230 items that depend on other people, like contract signatures and scheduled tests, locked in this month rather than during the EOFY crush.
Your Pre-1 July Checklist
| Action | Regulated entity | Supplier to one |
|---|---|---|
| Reconcile MSP register against signed agreements | ✓ This week | Not applicable |
| Document gaps, interim controls and remediation dates | ✓ Before 30 June | ✓ Where uplift is in flight |
| Sign or escalate outstanding uplift deeds | ✓ Before 30 June | ✓ Respond within days, not weeks |
| Complete BCP and scenario exercise (non-SFIs) | ✓ Before 30 June | ✓ Have your own continuity evidence ready |
| Tabletop the 72-hour and 24-hour notifications | ✓ This month | ✓ Test your client-notification process |
| Map dependencies, including fourth parties | ✓ This month | ✓ This month |
| Review insurance against new contractual liability | ✓ Recommended | ✓ Strongly recommended |
| Verify backup restore times with a live test | ✓ This month | ✓ This month |
Talk to Us Before the Deadline Does the Talking
We support both sides of this equation: smaller regulated entities that need their technology environment, monitoring and recovery capability brought up to what CPS 230 assumes, and the suppliers who need a credible evidence pack before the next questionnaire lands. Three weeks is enough time, if you start this week.
Sources
- Prudential Standard CPS 230 Operational Risk Management. APRA Prudential Handbook
- APRA finalises targeted amendments to CPS 230. APRA, 30 April 2026
- Operational risk management. APRA
- APRA provides an update on the implementation of the new operational risk standard. APRA
- APRA releases material service provider register template. APRA
- CPS 230 and material service providers: what you need to do before 1 July 2026. Dwyer Harris
- Prudential Standard CPS 234 Information Security. APRA Prudential Handbook
