Skip to content

Control mapping · APRA

CPS obligations, mapped to enforcement

A policy pack binds regulatory controls to the gates that enforce them. Packs are data, loaded through one loader, so a new jurisdiction is a new pack, not a fork. The apra-cps pack maps controls across CPS 230, CPS 234, SPS 220 to enforcement gates, and this page renders that register as it is.

Read the states before the rows

VERIFIED and UNVERIFIED-DRAFT render side by side and are never combined into one score. A drafted row stays visibly drafted until its clause is retrieved from the issuing authority's text and re-verified. Nothing on this page rounds a draft up to a claim.

apra-cps 0.1.0 / AU / APRA

17 mapped controls

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

16 gate bindings

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

15 distinct gate controls bound

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

17 provenance rows

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

17 VERIFIED

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

Recomputed from source text held under the pack's sources directory. This is a derived count, not an absence.

0 UNVERIFIED-DRAFT

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

Rows without verified provenance remain visibly separate from VERIFIED and are never combined into a sum or a single figure.

5 files in sources/

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps/sources

control_idinstrumentclausetitlestatereason
CPS220-REVIEWSPS 220para 27Comprehensive review of the risk management frameworkVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 27"
CPS220-RISK-APPETITESPS 220para 19Risk appetite statement and material risk declarationVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 19"
CPS220-RMFSPS 220paras 5 and 21Documented risk management frameworkVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 21"
CPS230-BCPCPS 230paras 33(c) and 42Business continuity plan and testingVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 42"
CPS230-CRITOPS-IDENTCPS 230para 33(a)Identification of critical operationsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 33(a)"
CPS230-INCIDENT-MGMTCPS 230para 31Operational risk incident and near-miss managementVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 31"
CPS230-NOTIFYCPS 230para 32Notification to the issuing authorityVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 32"
CPS230-OPRISK-CONTROLSCPS 230paras 28-29Operational risk controls and effectiveness assessmentVERIFIEDsource on disk, sha256 matches, quote verbatim at "paras 28-29"
CPS230-SPM-MATERIALCPS 230paras 48 and 50Material service provider registerVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 48"
CPS230-SPM-MONITORCPS 230para 59Ongoing monitoring of material service providersVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 59"
CPS230-TOLERANCECPS 230paras 21(b) and 37Tolerance levels for disruptionVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 37"
CPS234-ASSET-CLASSIFYCPS 234para 20Information asset identification and classificationVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 20"
CPS234-CONTROL-TESTINGCPS 234para 27Systematic testing of information security controlsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 27"
CPS234-INCIDENT-NOTIFYCPS 234para 35Notification of material information security incidentsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 35"
CPS234-INFOSEC-CAPABILITYCPS 234para 15Information security capability commensurate with threatsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 15"
CPS234-INTERNAL-AUDITCPS 234para 32Internal audit review of information security controlsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 32"
CPS234-THIRDPARTY-ASSURANCECPS 234para 22Assurance over third-party managed information assetsVERIFIEDsource on disk, sha256 matches, quote verbatim at "para 22"

Instrument and clause references are DRAFTED until a row recomputes VERIFIED — a clause number in an UNVERIFIED-DRAFT row has not been read from the issuing authority's text.

standards/policy-packs/packs/apra-cps/gaps.md:14-16

What this register is for

When an assessor or a due diligence questionnaire asks which obligations your agent activity touches, the answer is a row, not a paragraph. The control-gap briefing walks this register against your own critical operations: where agents act, what evidence exists today, and what an assessor will ask for.

Book a briefing

Facts derived 2026-09-01T22:47:09.312Z from commit 3f6b513007974db95549b439bcff08fa9f755db7