Control mapping · APRA
CPS obligations, mapped to enforcement
A policy pack binds regulatory controls to the gates that enforce them. Packs are data, loaded through one loader, so a new jurisdiction is a new pack, not a fork. The apra-cps pack maps controls across CPS 230, CPS 234, SPS 220 to enforcement gates, and this page renders that register as it is.
Read the states before the rows
VERIFIED and UNVERIFIED-DRAFT render side by side and are never combined into one score. A drafted row stays visibly drafted until its clause is retrieved from the issuing authority's text and re-verified. Nothing on this page rounds a draft up to a claim.
apra-cps 0.1.0 / AU / APRA
17 mapped controls
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
16 gate bindings
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
15 distinct gate controls bound
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
17 provenance rows
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
17 VERIFIED
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
Recomputed from source text held under the pack's sources directory. This is a derived count, not an absence.
0 UNVERIFIED-DRAFT
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps
Rows without verified provenance remain visibly separate from VERIFIED and are never combined into a sum or a single figure.
5 files in sources/
Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json
standards/policy-packs/packs/apra-cps/sources
| control_id | instrument | clause | title | state | reason |
|---|---|---|---|---|---|
| CPS220-REVIEW | SPS 220 | para 27 | Comprehensive review of the risk management framework | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 27" |
| CPS220-RISK-APPETITE | SPS 220 | para 19 | Risk appetite statement and material risk declaration | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 19" |
| CPS220-RMF | SPS 220 | paras 5 and 21 | Documented risk management framework | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 21" |
| CPS230-BCP | CPS 230 | paras 33(c) and 42 | Business continuity plan and testing | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 42" |
| CPS230-CRITOPS-IDENT | CPS 230 | para 33(a) | Identification of critical operations | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 33(a)" |
| CPS230-INCIDENT-MGMT | CPS 230 | para 31 | Operational risk incident and near-miss management | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 31" |
| CPS230-NOTIFY | CPS 230 | para 32 | Notification to the issuing authority | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 32" |
| CPS230-OPRISK-CONTROLS | CPS 230 | paras 28-29 | Operational risk controls and effectiveness assessment | VERIFIED | source on disk, sha256 matches, quote verbatim at "paras 28-29" |
| CPS230-SPM-MATERIAL | CPS 230 | paras 48 and 50 | Material service provider register | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 48" |
| CPS230-SPM-MONITOR | CPS 230 | para 59 | Ongoing monitoring of material service providers | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 59" |
| CPS230-TOLERANCE | CPS 230 | paras 21(b) and 37 | Tolerance levels for disruption | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 37" |
| CPS234-ASSET-CLASSIFY | CPS 234 | para 20 | Information asset identification and classification | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 20" |
| CPS234-CONTROL-TESTING | CPS 234 | para 27 | Systematic testing of information security controls | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 27" |
| CPS234-INCIDENT-NOTIFY | CPS 234 | para 35 | Notification of material information security incidents | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 35" |
| CPS234-INFOSEC-CAPABILITY | CPS 234 | para 15 | Information security capability commensurate with threats | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 15" |
| CPS234-INTERNAL-AUDIT | CPS 234 | para 32 | Internal audit review of information security controls | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 32" |
| CPS234-THIRDPARTY-ASSURANCE | CPS 234 | para 22 | Assurance over third-party managed information assets | VERIFIED | source on disk, sha256 matches, quote verbatim at "para 22" |
Instrument and clause references are DRAFTED until a row recomputes VERIFIED — a clause number in an UNVERIFIED-DRAFT row has not been read from the issuing authority's text.
standards/policy-packs/packs/apra-cps/gaps.md:14-16
What this register is for
When an assessor or a due diligence questionnaire asks which obligations your agent activity touches, the answer is a row, not a paragraph. The control-gap briefing walks this register against your own critical operations: where agents act, what evidence exists today, and what an assessor will ask for.
Book a briefing