Swipe to see all columns →
| Clause | Requirement | Runback capability | Evidence |
|---|---|---|---|
| Operational risk management — incident identification & escalation | Identify, assess, and escalate operational risk incidents with timely internal reporting. CPS 230 is technology-agnostic — it does not name AI specifically — but the same obligation applies wherever an AI agent is part of a material business process. | Alert rules + immutable run ledger | An entry in the hash-chained, append-only ledger See it in the dashboard → |
| Operational risk management — incident recording | Maintain a complete, tamper-evident record of operational risk incidents sufficient to support APRA notification obligations. | Signed, hash-chained audit trail | A captured run in the audit trace See it in the dashboard → |
| Business continuity — critical operations | Maintain the ability to continue critical operations through disruption, with tested continuity arrangements. | Policy engine fail-open/fail-closed configuration | A policy rule evaluated on a real tool call See it in the dashboard → |
| Operational risk management — review & reporting | Regular review of the operational risk profile and reporting to the board or governing body. | Compliance report export (machine-readable) | Aggregated from real run data into a compliance report See it in the dashboard → |
Honest limits
What this page does not claim.
- Exact paragraph-level numbering below is a section-level citation, not independently re-verified against the current CPS 230 PDF for this page. Confirm the precise paragraph reference before citing this mapping in a regulator-facing document.
- CPS 230 governs the operational-risk program as a whole. Runback's ledger and policy engine are evidence inputs to that program, not the program itself.
- This is a capability map, not a conformity determination. Whether your deployment satisfies APRA CPS 230 is a determination for your own assessor — what's listed above is the evidence that argument draws on.