CPS 230 came into force on 1 July 2025. APRA's message to boards has been consistent: you need to be genuinely satisfied — not just told by management — that your entity can deliver critical operations within tolerance during a disruption.
That's a significant shift. Being "genuinely satisfied" means asking harder questions than most boards have been asking. It means the answers need to be backed by evidence, not management assertions.
Here are the five questions every APRA-regulated board should be able to answer before their next meeting.
Being "genuinely satisfied" means the answers need to be backed by evidence. Not management assertions. Evidence.
1. What are our critical operations?
Sounds basic. It isn't. Most entities have a list of operations they consider critical, but the list is usually built from a top-down management view — what looks important from the executive floor. CPS 230 requires that view to be validated against how operations actually work.
The test isn't whether an operation matters. It's whether, if it were disrupted, the entity could continue to serve its customers and meet its obligations within tolerance.
2. What are our tolerances?
For each critical operation, APRA expects entities to define a maximum tolerable outage — the point beyond which disruption becomes unacceptable. Boards need to approve those tolerances, and they need to be based on something real: customer impact, regulatory obligation, financial exposure.
Many entities have tolerances on paper. Fewer have tolerances that their board has actually interrogated and signed off.
3. What do those operations actually depend on?
This is where most programs fall short. The dependency structure — which suppliers, systems, people and locations each critical operation depends on — is rarely documented with the precision CPS 230 now expects.
It's also the most important question. Because the recovery plan is only as good as the accuracy of the dependency map it's built on.
4. Can we actually recover within tolerance?
Not "do we have a plan." Not "have we tested the plan." The question is whether, given the actual dependency structure, the entity can restore each critical operation within its approved tolerance in a real disruption scenario.
That requires running the recovery pathway through the dependency model — not just through the documented procedure.
5. Do we know what we don't know?
The honest answer for most entities is that there are dependency gaps that haven't been mapped. Suppliers embedded in critical operations but not listed in the MSP Register. Systems technically decommissioned but still supporting critical processes. AI tools deployed without formal classification.
Boards that can acknowledge what's unknown — and have a program to close those gaps — are in a better position than boards that assume the picture is complete.
If your board can't confidently answer all five of those questions, the CPS 230 program needs work. AZON 360 builds the evidence base to make those answers credible. Get in touch if you want to talk through what that looks like for your client.

