The cost of resilience under CPS 230: Turning compliance effort into strategic value
The cost of resilience under CPS 230: Turning compliance effort into strategic value
CPS 230 represents a shift from compliance to strategic resilience, giving boards and executive management teams a practical lens to assess whether their operating model, critical dependencies and third-party relationships can withstand disruption. As organisations embed CPS 230 requirements, the focus is moving from implementation activity to demonstrating resilience in practice, making informed investment decisions, and balancing the cost of resilience against the operational, customer and regulatory consequences of failure.
For boards and executives, the practical question is no longer whether CPS 230 compliance activities have been completed, but whether those activities provide reliable evidence that critical operations can be sustained, service provider dependencies are understood, and resilience investment is being directed to the areas of greatest operational consequence.
What’s happened with CPS 230 so far?
- 1 July 2025 – CPS 230 commenced: CPS 230 came into effect for all APRA-regulated entities, requiring organisations to identify and manage operational risks, maintain critical operations within Board-approved tolerance levels during disruptions, establish robust business continuity arrangements, and effectively oversee material service providers.
- 30 April 2026 – Non-traditional service providers: APRA published guidance outlining categories of exempt service providers and providing targeted exemptions from certain CPS 230 contractual requirements for specific non-traditional service provider arrangements where standard contractual provisions may not be practical or achievable.
- By 1 July 2026 – End of transitional relief: Pre‑existing material service provider contracts must comply with CPS 230 by the earlier contract renewal date or 1 July 2026. All deferred requirements for non‑significant financial institutions to be met by 1 July 2026.
From cost of resilience to strategic value
Most APRA-regulated entities recognise that operational resilience requires ongoing investment. What CPS 230 does differently is make that investment visible, measurable, and accountable by requiring regulated entities to demonstrate that critical operations can continue through disruption in practice, not just in policy documents. As critical operations are identified and dependencies mapped, organisations gain a clearer understanding of where resilience risks are concentrated, often across legacy technology, manual processes, complex operating models, and third-party service providers.
Importantly, CPS 230 does not prescribe how much organisations should spend on resilience. It requires boards and executives to understand where the organisation is most vulnerable, the capabilities needed to withstand material disruptions, and the implications for the sustainability of current operating models. This shifts resilience from a compliance exercise to a strategic decision-making tool, enabling regulated entities to make informed trade-offs between the cost of resilience, the cost of disruption and the long-term value of operational sustainability.
This visibility allows resilience to be considered alongside other strategic priorities, rather than treated as an abstract risk management concept or a tick the box compliance exercise.
The resilience imperative across the financial services sector
While CPS 230 applies universally across APRA-regulated entities, its impact is shaped by the complexity of an organisation's operating model, the maturity of its operational risk framework, and the degree of reliance on third parties. Organisations with highly outsourced, technology-enabled or interconnected service delivery models typically face a greater resilience challenge, as CPS 230 requires a deeper understanding and oversight of the critical operations and dependencies that underpin service delivery.
In practice:
- Superannuation trustees are significantly impacted. Highly outsourced operating models, concentrated administrator and custodian arrangements, and a strong focus on member outcomes mean CPS 230 places operating model resilience, service provider dependency, and long-term sustainability under greater scrutiny
- Platform operators and integrated wealth businesses face heightened scrutiny due to multiple client‑facing critical operations and deep technology dependency. For these regulated entities, resilience is increasingly a business and brand issue
- Asset managers experience differentiated impact. Those with outsourced middle and back-office functions, complex products or reliance on single-service providers feel CPS 230 most acutely, while more vertically integrated or simpler managers face a more proportionate uplift
- Private wealth managers and boutiques are generally less complex, but CPS 230 still highlights concentration and key‑person risk where a small number of people, systems or providers support critical client services
- Authorised Deposit-taking Institutions (ADIs) are significantly impacted due to the criticality of customer-facing banking services, payment systems, lending operations and core technology platforms. CPS 230 places particular emphasis on the resilience of critical banking operations, recovery capabilities, service provider dependencies and the ability to operate within Board-approved tolerance levels during disruptions. For many ADIs, the focus has shifted from compliance to demonstrating operational resilience through testing, scenario analysis and end-to-end service continuity
- Insurers face heightened expectations given the importance of claims handling, policy administration, customer servicing and underwriting activities. CPS 230 requires insurers to clearly identify critical operations, establish measurable service tolerances and strengthen oversight of outsourced claims administrators, technology providers and other material service providers. Operational resilience failures can have significant customer, reputational and regulatory consequences, making resilience an increasingly important strategic and customer-outcome consideration.
Across the financial services sector, CPS 230 makes resilience more visible to boards by linking critical operations, tolerances and third‑party dependencies in a way that exposes where complexity and concentration have historically been accepted without full transparency.
Where resilience becomes a board priority
Managing the extended organisation
CPS 230 places renewed emphasis on risks arising from critical operations and material service providers. For many regulated entities, critical operations are delivered through an extended ecosystem of technology vendors, third parties and specialist providers.
Boards are increasingly focused on whether concentration risk is understood, whether exit and substitution options are credible in practice, and whether resilience expectations remain realistic given the level of dependency on third and fourth parties. These are not procurement questions, they go to the heart of how services are delivered. CPS 230 places ultimate accountability for operational resilience firmly with the Board, requiring directors to oversee the regulated entity’s ability to continue delivering critical operations through disruption.
Lessons learned from CPS implementation efforts – beyond compliance to strategic enablement
A key lesson emerging from CPS 230 implementation across the industry so far is that compliance with operational risk requirements is rarely achieved through policy development alone. Across the sector, many regulated entities had established operational risk management frameworks, Board-approved policies, risk registers and governance structures, yet still had gaps in embedding those frameworks into day-to-day operations.
This mirrors one of the broader lessons from CPS 220 implementation, APRA’s foundational risk framework on which other prudential frameworks like CPS 230 is built, which is that organisations often achieve design compliance before achieving operational maturity. Regulated entities have consistently identified gaps in accountability clarity, documentation consistency, critical operations derivation and mapping, tolerance setting, business continuity execution planning, and evidence of Board oversight. This demonstrates that regulatory compliance increasingly depends on having a framework in place, and the ability to evidence ownership, challenge, oversight and operational effectiveness across the three lines of defence.
Another lesson from CPS 230 implementation is the importance of integrating operational risk management into business decision-making rather than treating it as a standalone risk tool. Many recurring themes centre on third-party risk management, business continuity planning and critical operations governance, all of which require close collaboration between business, technology, procurement, operations and risk functions.
Similar to the evolution of CPS 220, organisations with stronger operational resilience outcomes were those that had embedded risk ownership within business operations, integrated risk information into Governance, Risk and Compliance (GRC) platforms, established clear board reporting and aligned operational risk practices with strategic decision-making. The lessons learned suggest that future supervisory focus is likely to move beyond framework design and towards demonstrating resilience outcomes, including testing, scenario analysis, service provider oversight, and the ability to operate within Board-approved tolerance levels during periods of disruption.
A constructive lens for boards
Rather than viewing CPS 230 solely through a compliance lens, boards and executive management teams may find it helpful to adopt a resilience‑adjusted view of decision‑making.
This involves asking management to demonstrate, for each critical operation:
- How tolerances are monitored and acted upon
- Where resilience investment is concentrated
- How key dependencies are managed and tested
- What options exist if tolerances cannot be met sustainably
- Viability of exit strategies from material service providers
- Effectiveness of the tolerance levels for critical operations and documentary evidence that minimum service levels can be met during periods of disruption
- Evidence that oversight of material service providers is operating effectively.
This framing keeps the discussion grounded in evidence and proportionality, while enabling thoughtful change and prioritisation.
Looking ahead
CPS 230 requires boards to govern operational risk more explicitly, and as resilience becomes more observable and measurable, boards will become better placed to make informed choices about simplification, investment and growth. In that sense, CPS 230 can be seen not just as a regulatory obligation, but as an opportunity to strengthen organisational confidence.
The most effective CPS 230 programs are those that move from implementation evidence to sustainable, business-owned resilience capability. That requires practical assurance over whether critical operations, tolerances, service provider oversight and business continuity arrangements are operating as intended.
How BDO can help
BDO’s financial services and risk advisory specialists work with boards and executive management teams to move beyond technical compliance and embed operational resilience in a way that supports strategy, proportionate investment and sustainable growth.
We support regulated entities across the full CPS 230 journey, from defining critical operations and setting credible tolerances, to determining material service providers, transitioning from project-based implementation to business-as-usual capability, providing independent insight into dependency and concentration risk, and giving boards and management assurance over the effectiveness of CPS 230 frameworks and compliance with prudential requirements. We also help align CPS 230 with existing governance, risk and technology frameworks.
To discuss how BDO can support your organisation, contact us.

