APRA CPS 234 compliance: what examiners check that audits miss

Key takeaways
CPS 234 clause 6 places information security oversight responsibility on the Board — not as a governance formality but as a demonstrable, evidence-backed function. APRA examiners distinguish between boards that approved a policy and boards that engaged with the risk.
The 72-hour incident notification requirement under CPS 234 clause 36 applies to material information security incidents. The definition of material is not self-evident: APRA expects entities to have documented materiality criteria, and examiners will ask how the organization determined a given incident did or did not cross that threshold.
CPS 234 clauses 27-32 require ongoing third-party security assessments — not initial due diligence. Organizations that conduct entry-point vendor reviews and then rely on contractual clauses for ongoing assurance are non-compliant with the monitoring obligation.
APRA examiners request evidence in formats that enable independent analysis: structured vulnerability data in CSV, not PDF summaries; incident timelines with system-level detail; and board minutes that show interrogation of security matters, not just approvals.
Fourth-party risk — the risk introduced by third parties' own suppliers — is assessed under CPS 234 even though most organizations' vendor risk programs stop at the direct supplier layer.
In Vulnox assessments of APRA-regulated entities, the most consistent finding is a gap between documented control frameworks and operational evidence that those controls are functioning. The documentation exists. The evidence that the controls produce the outcomes the documentation claims does not.
TL;DR
CPS 234 compliance programs that are built around passing the audit are built around the wrong question. APRA examiners are not auditors checking a list — they are supervisors evaluating whether the organization understands and manages its information security risk. The difference shows up in board minutes, vendor monitoring records, and incident notification evidence. Most APRA-regulated entities have the controls. They cannot produce the evidence chain that shows those controls are being actively managed.
The board meeting that looked compliant and wasn't
A superannuation fund passed its CPS 234 gap assessment. The information security framework was documented, the asset register was current, the third-party contracts included security clauses, and the incident response plan had been reviewed within the preceding 12 months. When APRA examiners reviewed the board minutes from the prior two years, they found 14 instances where the information security agenda item was resolved with a single line: 'Board approved the information security update presented by management.' No questions recorded. No challenge to assumptions. No discussion of specific threats, incidents, or test results. The examiners' position was that a board that approves without questioning has not demonstrated the active oversight CPS 234 clause 6 requires.
The fund's compliance program had been designed to satisfy an auditor's checklist. APRA examiners are not checking the list — they are forming a judgment about whether the board is genuinely governing information security risk. Those are different tests and they require different evidence.
What CPS 234 clause 6 actually requires from a board — and how APRA distinguishes oversight from rubber-stamping
CPS 234 clause 6 requires the Board to ensure that the entity maintains information security capability commensurate with the size and extent of its threats. The word 'ensure' is doing significant work here. APRA's Prudential Practice Guide CPG 234 elaborates that this means the Board must understand the entity's information security risk profile, challenge management's security assumptions, and hold management accountable for security performance. The mechanism for evidencing this is board minutes. APRA examiners read board minutes not as a formality but as a primary evidence source for board engagement quality.
Example
The evidentiary standard APRA applies to board minutes is practical: did the board ask questions that could only have been asked by people who understood the specific risk? 'What is the current patching lag for internet-facing systems?' is evidence of engagement. 'Noted and approved' is not. In Vulnox assessments of APRA-regulated entities, the most common board oversight finding is that minutes record approval events but not interrogation events. The board was in the room. The documentation does not show they were paying attention.
The CPG 234 guidance specifically addresses cyber literacy at board level, noting that boards are not required to have technical expertise but are required to ask questions of sufficient depth to assess management's security claims. Entities preparing for APRA examination should audit their own board minutes against this standard before examiners do.
What CPS 234 assessments consistently find in regulated environments
Assessment base: Vulnox gap analysis and compliance assessment engagements, APRA-regulated entities in banking, superannuation, and insurance sectors, 2023-2025.
Incident materiality criteria that have never been documented
CPS 234 clause 36 requires notification to APRA within 72 hours of a material information security incident. The framework does not define material — it expects entities to define it themselves, consistent with their risk profile and the nature of their information assets. In Vulnox assessments of APRA-regulated entities, the majority had not documented their materiality criteria. When asked how they would determine whether a given incident required notification, the answer was consistently a judgment call by the CISO or the incident response team. APRA examiners will ask to see the documented criteria and the application of those criteria to recent incidents.
An entity without documented materiality criteria cannot demonstrate that its notification decisions were principled rather than arbitrary. If an entity failed to notify APRA of an incident that should have been reported, the absence of documented criteria makes the failure look like concealment rather than miscalibration. The regulatory exposure from undocumented materiality is asymmetric: it turns a process gap into a potential conduct issue.
Third-party monitoring programs that stop at contract execution
CPS 234 clauses 27 to 32 establish ongoing third-party risk management obligations. The word 'ongoing' is explicit in the standard. In assessed APRA-regulated environments, the most common third-party risk pattern was thorough initial due diligence — vendor questionnaires, security assessments, contract review — followed by no structured monitoring activity until contract renewal. Annual questionnaires sent to vendors without independent technical validation of responses do not satisfy the ongoing monitoring obligation. One specific pattern: PII flowing to data analytics providers in unencrypted format, where the third-party contract specified encryption requirements but no one had verified implementation since contract execution.
APRA examiners request evidence of ongoing monitoring, not evidence of initial due diligence. An entity that cannot produce records of monitoring activity in the 12 months prior to examination has a compliance gap regardless of how thorough its onboarding process was. The third-party control failure is not the missing questionnaire — it is the absence of any mechanism to detect that a contractual security obligation is not being met.
Control testing that produces pass/fail results without evidence chains
CPS 234 clause 21 requires entities to test the effectiveness of their information security controls. APRA's expectation of what constitutes a test result goes beyond what most internal audit processes produce. Vulnerability scan outputs in PDF summary format showing aggregate counts do not satisfy the standard. APRA examiners request raw scan data in analyzable formats, evidence that identified vulnerabilities were remediated, and records showing the remediation timeline relative to the entity's own patching policy. In assessed environments, the gap between what the control testing program produced and what APRA would request was structural: the testing was genuine but the evidence retention practices had not been designed for regulatory examination.
A control testing program that does not retain evidence in examiner-ready formats is producing compliance effort that cannot be verified. The remediation work was done. The evidence that it was done, in the format regulators can independently analyze, was not preserved. Rebuilding that evidence after an examination request is not possible.
Fourth-party risk visibility that is effectively zero
CPS 234's third-party risk obligations extend to material fourth-party exposures — the risk introduced by the suppliers of critical third parties. In assessed environments, fourth-party risk was universally treated as out of scope. Vendor risk programs assessed direct suppliers and stopped there. For APRA-regulated entities whose critical third parties include cloud infrastructure providers, payment processors, and core banking system vendors, the fourth-party layer includes concentration risks that are material by any reasonable standard and invisible to the entity's risk management framework.
APRA has explicitly signaled concern about concentration risk in financial services technology supply chains. An entity that cannot articulate its fourth-party exposure in a critical vendor relationship is not meeting the spirit of the obligation, and increasingly not meeting the letter of it as APRA's supervisory focus on supply chain risk sharpens.
SOC 2 and ISO 27001 certification can make CPS 234 compliance harder, not easier
Common belief
Entities that hold SOC 2 Type II reports or ISO 27001 certification typically enter CPS 234 readiness assessments with the assumption that the hard work is done. The logic is that these frameworks are rigorous and comprehensive, and that CPS 234 is a subset of what has already been assessed. The CPS 234 gap analysis is treated as a mapping exercise — find the clauses, match them to existing controls, document the coverage.
What we found
In assessed environments where entities held current SOC 2 Type II reports, the average number of CPS 234-specific gaps identified in subsequent assessments was 7. The most common gap categories were board oversight evidence, documented materiality criteria for incident notification, and fourth-party risk visibility — none of which are addressed by SOC 2 scope.
The problem is that SOC 2 and ISO 27001 are designed for a different audience with different evidence standards. SOC 2 produces assurance for customers and counterparties. ISO 27001 produces assurance for certification bodies. CPS 234 produces evidence for a prudential supervisor whose mandate is systemic financial stability. APRA is not looking for assurance — it is forming an independent judgment. The evidentiary standard is higher, the scope of board oversight obligations has no equivalent in either framework, and the incident notification requirement is more specific than anything SOC 2 or ISO 27001 addresses. Entities that enter CPS 234 readiness with certified frameworks in hand are well-positioned on controls. They are typically unprepared on governance evidence, incident materiality documentation, and the operational detail APRA examiners request.
CPS 234 obligations that most compliance programs do not address
Information asset classification that maps to actual data sensitivity
CPS 234 clause 10 requires entities to classify information assets by criticality and sensitivity. The operative phrase is 'by criticality and sensitivity' — meaning classification needs to reflect the actual risk if the asset is compromised, not just the asset's functional category. In assessed environments, asset classification exercises consistently produced registers organized by system type (core banking, HR systems, email) with sensitivity labels that had been applied uniformly to asset categories rather than calibrated to the data each asset holds. A core banking system that holds 20-year transaction histories for retail customers has a different sensitivity profile than one that holds reference data. Classification that does not capture this distinction does not satisfy the standard.
Notification obligations when the incident involves a third party
CPS 234's 72-hour notification requirement applies when the entity becomes aware of a material information security incident — including incidents that originate at a third-party provider and affect the entity's information assets or operations. Most incident response plans are written around first-party breaches. Third-party-originated incidents fall into a procedural gap where the entity waits for the vendor's investigation before assessing its own notification obligation. That sequencing is incorrect. The notification clock starts when the entity becomes aware of potential materiality, not when the vendor concludes its forensic review.
Post-incident review obligations under clause 37
CPS 234 clause 37 requires entities to conduct a post-incident review after any material information security incident and report findings to the Board. The review must assess the effectiveness of the response and identify improvements. In assessed environments, post-incident reviews were conducted inconsistently and rarely reached the Board as a formal agenda item. The result is that APRA examiners reviewing board minutes find no evidence that material incidents informed security governance decisions — which undermines the board oversight evidence trail independently of the quality of the response itself.
Where APRA's CPS 234 supervision is heading
APRA will issue targeted guidance on fourth-party concentration risk in financial services technology supply chains before end of 2026, extending CPS 234 compliance expectations explicitly to material fourth-party relationships with cloud infrastructure and core banking system providers.
APRA has consistently followed a pattern of signaling supervisory concerns through examination findings before formalizing them in guidance. The concentration risk in Australian financial services technology supply chains — dominated by a small number of cloud providers and core banking vendors — has been a stated supervisory concern since 2022. The gap between the current CPS 234 text and examiner practice on fourth-party risk is visible in examination findings. Regulatory guidance typically follows when the gap becomes a pattern across multiple supervised entities.
Confidence: highAPRA guidance publication specifically addressing fourth-party risk under CPS 234 before end of 2026, or no such guidance published by that date.Within 24 months, APRA will introduce mandatory CPS 234 control testing frequency requirements with minimum annual penetration testing obligations for entities above a defined asset threshold, eliminating the current flexibility that allows entities to define their own testing cadence.
The variation in control testing frequency across APRA-regulated entities is wide — from quarterly for the largest banks to effectively ad-hoc for smaller superannuation funds. APRA's published examination findings consistently identify inadequate testing frequency as a CPS 234 gap. The trajectory of equivalent regulators internationally — PRA in the UK, OSFI in Canada — has been toward prescriptive testing requirements after similar periods of principles-based flexibility. APRA's regulatory development follows this pattern.
Confidence: mediumAPRA CPS 234 amendment introducing mandatory testing frequency requirements before mid-2027, or absence of any such amendment.
CPS 234 compliance programs optimized for audit passage are optimized for the wrong outcome
The compliance industry around CPS 234 has produced a large quantity of gap analysis tooling, mapping templates, and control frameworks that are designed to produce an audit-ready output. These tools are useful. They are also insufficient for the examination environment APRA actually runs. An audit checks whether controls exist and are documented. An APRA examination forms a judgment about whether the organization is genuinely managing information security risk. The evidence standards are different, the questions are different, and the preparation required is different. Organizations that invest in compliance infrastructure without investing in the governance evidence trail — board meeting quality, incident documentation discipline, third-party monitoring records — will pass their gap assessments and struggle with their examinations.
Counterargument
The counterargument is that building compliance infrastructure first is the right sequencing — get the controls in place, then worry about the evidence. Getting the documentation right is a second-order problem compared to having the security program right. That is true for organizations that are genuinely starting from zero. It is not true for the majority of APRA-regulated entities, which have adequate security controls and inadequate governance documentation. For them, the sequencing is already inverted.
One thing to do this week
Pull the board minutes from your last four information security agenda items and read them as an APRA examiner would. Count the number of questions recorded — not approvals, not presentations noted, but questions that management was asked to answer. If the count is zero, you have identified the highest-priority CPS 234 gap in your organization, and it has nothing to do with your security controls. The fix is not a new policy — it is a board briefing designed to elicit interrogation rather than approval, with a minute-taker instructed to document the questions alongside the decisions.
Further Reading
Gap Analysis
framework gap analysisDigital Footprint
digital footprint analysisAPAC cybersecurity and privacy compliance frameworks: the complete guide
APRA CPS 234 compliance gaps and what examiners check that audits do notNational Vulnerability Database NIST
NIST National Vulnerability DatabaseOWASP ZAP for Penetration Testing
OWASP ZAP penetration testingThird-Party Risk Management
third-party risk management
Frequently Asked Questions
What does APRA actually examine in a CPS 234 supervision review beyond the documented control framework?
APRA examiners focus on three things that most audit processes do not capture: board meeting records that demonstrate active oversight rather than passive approval; evidence chains showing that controls are functioning and producing outcomes, not just existing; and incident notification documentation that shows how materiality was assessed, not just whether notification was filed. The gap between having a CPS 234-compliant control framework and satisfying an APRA examiner is almost entirely a governance evidence gap, not a security control gap.
How does an APRA-regulated entity define what counts as a material information security incident for CPS 234 notification?
CPS 234 does not define material — entities are required to document their own materiality criteria consistent with their risk profile and the sensitivity of their information assets. APRA examiners will request the documented criteria and review how those criteria were applied to recent incidents. Entities without documented materiality criteria cannot demonstrate that notification decisions were principled. The absence of documentation turns a process gap into a potential conduct issue if a notifiable incident was not reported.
Does holding a SOC 2 Type II report satisfy APRA CPS 234 compliance requirements?
SOC 2 addresses controls relevant to customer and counterparty assurance. CPS 234 requires evidence for a prudential supervisor. The evidentiary standards differ significantly. In Vulnox assessments of entities holding current SOC 2 Type II reports, an average of 7 CPS 234-specific gaps were identified. The most common gaps were board oversight evidence, documented incident materiality criteria, and fourth-party risk visibility — none of which fall within SOC 2 scope.
What does CPS 234 require for ongoing third-party risk management after contract execution?
CPS 234 clauses 27 to 32 require ongoing monitoring of third-party information security practices, not just initial due diligence. Annual questionnaires without independent technical validation of responses do not satisfy the ongoing monitoring obligation. APRA examiners request evidence of monitoring activity in the 12 months prior to examination. Entities that cannot produce monitoring records — as distinct from onboarding records — have a compliance gap regardless of how thorough their initial vendor assessment was.
What is fourth-party risk under CPS 234 and how should regulated entities address it?
Fourth-party risk refers to the security risk introduced by the suppliers of an entity's direct third-party providers. CPS 234's third-party risk obligations extend to material fourth-party exposures. Most APRA-regulated entities' vendor risk programs stop at the direct supplier layer. For entities whose critical third parties include cloud infrastructure providers and core banking system vendors, fourth-party concentration risk is material and is expected to be within scope of the risk management framework. APRA has signaled this as a growing supervisory focus.
What evidence format does APRA expect for CPS 234 vulnerability scanning and control testing?
APRA examiners request structured, analyzable data — vulnerability scan results in CSV format rather than PDF summaries, incident timelines with system-level detail, and remediation records that show when identified vulnerabilities were addressed relative to the entity's own patching policy. PDF summary reports showing aggregate counts are insufficient. The evidence standard is designed for independent analysis, not for confirming that a scan was run.
When does the 72-hour CPS 234 notification clock start for a third-party-originated incident?
The CPS 234 notification obligation is triggered when the entity becomes aware of a material information security incident — including incidents that originate at a third-party provider. The clock does not wait for the vendor's investigation to conclude. Incident response plans that defer notification assessment until after vendor forensic review are operating on incorrect sequencing. The entity's materiality assessment and notification decision must begin when the entity first becomes aware of potential impact, not when the vendor provides its findings.
Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard
GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong
GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard
GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.
Ready to Secure Your Digital Assets?
Get a comprehensive vulnerability assessment for your website today.