Skip to content

Operational risk · APRA CPS 230

CPS 230 governs the outcome. Your agent is inside it.

CPS 230 has applied since 1 July 2025. It is an operational risk standard, not an information security one, and that distinction decides who owes what.

For an RSE licensee, CPS 230 names investment management and fund administration as critical operations. Not as an example. As a minimum classification, at paragraph 35(c). If an automated agent performs or assists a step in either, the agent is operating inside a critical operation, and everything the standard requires of that operation now applies to the part the agent ran.

Most of the market has answered this with information security language. CPS 234 is a different standard, asking a different question. Answering it does not discharge CPS 230.

What the standard asks of an automated control

Paragraph 29 requires you to regularly monitor, review and test controls for design and operating effectiveness. Design is a document. Operating effectiveness is a claim about what happened, on specific days, in production.

For a control a person performs, operating effectiveness is evidenced by an artifact that person left behind. For a control an agent performs, the artifact is whatever the agent logged. That log was built so an engineer could debug a failure. It was not built so a third party could establish that the control ran, on whose authority, and what it stopped.

Paragraph 28 is the other half. Controls exist to mitigate operational risk, which means the important events include the ones that did not happen. A control that prevented an action has to be able to show it prevented it. Silence is not evidence of refusal.

The clock is the part people underestimate

Paragraph 31 requires operational risk incidents and near misses to be identified, escalated, recorded and addressed in a timely manner. Paragraph 32 gives you 72 hours to notify APRA of an operational risk incident likely to have a material financial impact, or a material impact on your ability to maintain critical operations. Paragraph 41 gives you 24 hours if a critical operation is disrupted outside tolerance.

Twenty-four hours is not enough time to reconstruct an agent's behaviour from unsequenced logs across several systems. The reconstruction has to already exist.

It follows your service providers too

If the agent runs on someone else's platform, paragraph 48 likely makes that provider a material service provider, and paragraph 49(d) classifies core technology services as material for every APRA-regulated entity unless you can justify otherwise. Paragraph 59(b) then requires a regular assessment of the effectiveness of the controls managing that arrangement, and paragraph 54(a) requires the agreement to let APRA reach the documentation and data behind the service.

That is the same question again, asked of a system you do not own. A vendor console cannot answer it, because the reviewer would have to trust the system under review.

Checkable, not asserted

The CPS 230 obligations this repository binds

These rows are not written by hand. They are the CPS 230 entries of the apra-cps policy pack, rendered as the pack loader emits them, with the clause each row was verified against. Every state below is the state the loader reported at build.

  • paras 33(c) and 42Business continuity plan and testingVERIFIED
  • para 33(a)Identification of critical operationsVERIFIED
  • para 31Operational risk incident and near-miss managementVERIFIED
  • para 32Notification to the issuing authorityVERIFIED
  • paras 28-29Operational risk controls and effectiveness assessmentVERIFIED
  • paras 48 and 50Material service provider registerVERIFIED
  • para 59Ongoing monitoring of material service providersVERIFIED
  • paras 21(b) and 37Tolerance levels for disruptionVERIFIED

Instrument and clause references are DRAFTED until a row recomputes VERIFIED — a clause number in an UNVERIFIED-DRAFT row has not been read from the issuing authority's text.

See the full register, CPS 230 and CPS 234

What NOMARK does about it

Agents emit signed, sequenced records at the point of action. Records hash-chain into a stream, so removing one, reordering two or truncating the tail is detectable rather than invisible.

The verifier is a separate implementation, built from source in the repository, and it runs offline on a machine the assessor controls. NOMARK does not need to be present, or trusted, for the verdict to mean anything. Two independent implementations validate against the same conformance vectors, including the deliberately invalid streams counted below.

Refusal is captured as evidence. The control plane emits a real action_blocked record before the protected function executes, so a prevented action leaves an artifact instead of leaving nothing.

9 invalid stream categories

Counted by one .jsonl pair per category under packages/protocol/vectors/invalid/

packages/protocol/vectors/invalid

broken-chain, expired-key, replayed-record, sequence-gap, signature-mismatch, suppressed-stream, tampered-payload, truncated-tail, unknown-key

17 controls in the apra-cps pack

Counted by node standards/policy-packs/tools/pack-load.cjs --pack apra-cps --json

standards/policy-packs/packs/apra-cps

pack version 0.1.0

There is no account to create.

What is not finished

The reference collector covers the Decision Assurance direct-instrumentation workload. Generic MCP interposition, federation, high availability and managed key infrastructure are open scope, and the capability register on this site says so with the state of each item.

The apra-cps policy pack ships at version 0.1.0. Rows without matching provenance stay visibly drafted. A claim this site cannot derive from the repository fails the build.

The capability register

Map the gap before an assessor does.

Forty-five minutes with your risk or investment operations lead. Where agent activity touches your CPS 230 critical operations, what evidence exists today, and what an assessor will ask for. You leave with the gap mapped whether or not you go further.

Book a briefing

Facts derived 2026-09-01T22:47:09.312Z from commit 3f6b513007974db95549b439bcff08fa9f755db7