Regulatory

APRA CPS 230 (2024 (effective 1 Jul 2025))

APRA CPS 230 (Operational Risk Management) took effect 1 July 2025 for APRA-regulated entities — Australian banks, insurers, and superannuation trustees. It is technology-agnostic: it never names AI specifically, but its obligations on incident management, business continuity, and third-party/service-provider risk apply wherever an AI agent sits inside a material business process.

Below is the same static clause map the in-app Regulatory tab evaluates against your org's real data on every load — not a separate summary written for this page. There is no compliance verdict here, since that depends on your own data; sign in to see your org's live status per clause.

Swipe to see all columns →

ClauseRequirementRunback capabilityEvidence
Operational risk management — incident identification & escalationIdentify, assess, and escalate operational risk incidents with timely internal reporting. CPS 230 is technology-agnostic — it does not name AI specifically — but the same obligation applies wherever an AI agent is part of a material business process.Alert rules + immutable run ledgerAn entry in the hash-chained, append-only ledger
See it in the dashboard →
Operational risk management — incident recordingMaintain a complete, tamper-evident record of operational risk incidents sufficient to support APRA notification obligations.Signed, hash-chained audit trailA captured run in the audit trace
See it in the dashboard →
Business continuity — critical operationsMaintain the ability to continue critical operations through disruption, with tested continuity arrangements.Policy engine fail-open/fail-closed configurationA policy rule evaluated on a real tool call
See it in the dashboard →
Operational risk management — review & reportingRegular review of the operational risk profile and reporting to the board or governing body.Compliance report export (machine-readable)Aggregated from real run data into a compliance report
See it in the dashboard →
Honest limits

What this page does not claim.

  • Exact paragraph-level numbering below is a section-level citation, not independently re-verified against the current CPS 230 PDF for this page. Confirm the precise paragraph reference before citing this mapping in a regulator-facing document.
  • CPS 230 governs the operational-risk program as a whole. Runback's ledger and policy engine are evidence inputs to that program, not the program itself.
  • This is a capability map, not a conformity determination. Whether your deployment satisfies APRA CPS 230 is a determination for your own assessor — what's listed above is the evidence that argument draws on.