APRA CPS 230 compliance
August 12, 2026

APRA CPS 230 Compliance for Offshore Outsourcing: What Australian Banks and Fintechs Must Know

If your institution outsources any part of its operations — especially offshore — APRA CPS 230 compliance is now the standard that governs it. And the single most important thing to understand is this: the obligations stay with you. You can outsource the work, but not the accountability. When an Australian bank hands over loan processing, payments, or customer support to a provider, APRA still holds the bank responsible for how those functions are run, secured, and how any losses are recovered when something goes wrong.

Executive Summary: Key Takeaways
  • Uncompromising Accountability: APRA CPS 230 compliance requires APRA-regulated institutions to retain full accountability for operational risk when outsourcing to offshore partners.
  • Pre-Commitment APRA Notification: Institutions must notify APRA prior to entering into or significantly altering any material offshoring arrangement.
  • Incident Escalation Windows: Providers must support the institution’s mandatory 72-hour operational risk incident notification timeline to APRA.
  • MSP Governance: Any offshore function supporting core banking, loan processing, payments, or customer support qualifies as a Material Service Provider (MSP) requiring formal board oversight and register tracking.

This guide explains what CPS 230 requires, how it treats offshore providers, and what a compliant offshore partnership actually looks like. It is written for the institutions that outsource — banks, ADIs, and the fintechs that work alongside them.

Disclaimer
This article is general information, not legal or compliance advice. Confirm your obligations against the current standard and your own APRA requirements from the official portal.

From CPS 231 to CPS 230: What has changed?

For years, outsourcing by APRA-regulated entities was governed by CPS 231 (Outsourcing) and business continuity by CPS 232. Both are gone. CPS 230 Operational Risk Management came into force on 1 July 2025, consolidating them into a single, broader standard. The updated version of CPS 230 and its practice guide (CPG 230) took effect on 1 July 2026 following targeted amendments for non-traditional service providers.

The shift is more than a rename. CPS 230 replaces the old, narrow idea of “outsourcing” with the wider concept of a material service provider — and it puts operational resilience, not just contract management, at the center. That change is what makes APRA CPS 230 outsourcing obligations bite harder than the standard they replaced.

From CPS 231 to CPS 230: What Changed?
The shift from outsourcing governance to operational resilience.

Previous Framework
CPS 231 + CPS 232
Outsourcing & Continuity
Current Framework
CPS 230
 Operational Resilience

01
Outsourcing → Material Service Providers
Broader coverage beyond traditional outsourcing arrangements.

02
Contract Management → Operational Resilience
Focus shifts from agreements to service continuity.

03
Separate Standards → Unified Risk Framework
Outsourcing and continuity obligations combined.

04
Third-Party Oversight → End-to-End Accountability
Regulated entities remain responsible for resilience.

Know your requirements – Does CPS 230 apply to you?

CPS 230 applies directly to APRA-regulated entities: authorized deposit-taking institutions (ADIs, including foreign ADI branches), general, life and private health insurers, and superannuation (RSE) licensees.

For fintechs, the answer depends on status. A fintech that is itself an ADI or otherwise APRA-regulated is directly bound. A fintech that is not regulated by APRA is not directly subject to CPS 230 — but it almost always inherits the requirements contractually the moment it partners with a regulated bank, because the bank has to push those obligations down to everyone in its critical-operations chain. Either way, maintaining full APRA CPS 230 compliance shapes what you have to do if you sit anywhere in a regulated institution’s supply of critical services.

Is your provider a “material service provider”?

This is the question that determines how much of CPS 230 applies to a given arrangement. Under the prudential standard, a provider is defined as a material service provider (MSP) when the entity relies on it to undertake a critical operation, or when it exposes the entity to material operational risk. For ADIs, key functions are automatically classified as material, including credit assessment, funding and liquidity management, and mortgage brokerage.

Under APRA guidelines, critical operations are defined as functions that would cause material harm to customers or the financial system if disrupted beyond acceptable tolerance levels. APRA directly identifies several examples that align with BPO services, including payments, deposit-taking support, claims processing, investment management, fund administration, and customer inquiries. In addition, institutions must account for the costs of supporting IT infrastructure and maintain a formal register to track all critical functions.

If your offshore provider touches any of these functions, treat the arrangement as material and plan for full APRA CPS 230 compliance.

What Does CPS 230 Require of the Institution?

CPS 230 sets out a lifecycle of obligations for managing material service providers. In plain terms, a regulated institution must maintain six core controls:

Key CPS 230 Governance Requirements
Core controls for managing material service provider arrangements.

01
Service Provider Management Policy
02
Material Service Provider Register

03
Due Diligence & Risk Assessment
04
Material Arrangement Agreements

05
Ongoing Risk Monitoring & Reporting
06
Business Continuity & Resilience
  • A service provider management policy: Formal rules governing how providers are selected, managed, and exited.
  • A material service provider register: A formal inventory of MSPs and critical operations. Institutions submitted their first MSP register to APRA by 1 October 2025 and maintain it on an ongoing basis.
  • Due diligence and risk assessment: Mandatory evaluations conducted before signing or altering material arrangements.
  • A formal agreement: Contracts that strictly satisfy CPS 230’s minimum content requirements.
  • Ongoing risk management and monitoring: Continuous performance tracking paired with regular executive and board reporting.
  • Business continuity capability: The ability to maintain critical operations within defined tolerance levels through severe disruption, validated via scenario testing.

None of these responsibilities can be delegated to an external partner. The provider enables operational compliance; the institution owns regulatory accountability.

The Offshoring Rules: Where Offshore Outsourcing Compliance in Australia Gets Specific?

This is where an offshore arrangement diverges from a domestic one, and it is the part institutions most often underestimate.

CPS 230 defines a material offshoring arrangement as any material agreement where service delivery physically occurs outside Australia. Notably, this includes scenarios where the provider is incorporated locally in Australia but uses an overseas delivery team. Three specific offshore outsourcing obligations apply:

  • Notify APRA before you commit: An institution must formally notify APRA prior to entering into any material offshoring arrangement or making significant changes to an existing one. This pre-commitment step is distinct from the 20-business-day notification rule applied to general critical-operations agreements.
  • Internal audit review: The institution’s internal audit team must evaluate any proposed material outsourcing of a critical operation and report compliance findings directly to the Board or Board Audit Committee.
  • Data location and privacy controls: Where customer data is stored, processed, or accessed offshore, the arrangement must meet CPS 230 operational risk rules, CPS 234 information security standards, and the requirements of the Privacy Act.

The practical takeaway: choosing an offshore provider is a board-visible, APRA-notified decision. That raises the bar for providers who can be credibly chosen — and rewards those who come to the table already able to demonstrate compliance.

Improve Account Holder Experience
Connect with RCC BPO for a customized evaluation and discover the right outsourcing model for the Australian region.

What to demand from an offshore provider?

Because regulatory accountability stays with the institution, the provider’s job is to make compliance demonstrable rather than to claim it. When evaluating a partner for banking outsourcing compliance in Australia, insist on:

  • Auditability by default: Complete, retrievable call logs, transaction records, and verification trails the institution can produce for APRA or internal audit without a scramble.
  • Tested business continuity: Documented continuity and recovery plans, aligned to the institution’s tolerance levels and validated through scenario testing, not a plan that only exists on paper.
  • Contract terms that meet minimum-content requirements: Formal agreement terms that satisfy APRA CPS 230 compliance out of the box.
  • Data residency and access controls: Clear parameters on data storage and access map directly to CPS 234 and Privacy Act obligations.
  • Incident reporting that feeds your clock: Escalation protocols fast enough for the institution to meet its mandatory 72-hour operational risk incident notification deadline to APRA.
  • Support for notifications and registers: The MSP register stays current and supports accurate offshoring notifications through structured data output.

A provider that treats these controls as standard practice turns an offshore arrangement from a regulatory liability into a defensible operational asset.

What to keep in mind when outsourcing to offshore teams?

<div style=”max-width: 900px; margin: 45px auto; font-family: Arial,Helvetica,sans-serif;”>

CPS 230 Offshore Arrangement Checklist
Use this checklist as a starting point when assessing whether an offshore outsourcing arrangement aligns with CPS 230 expectations.

Have you determined whether the provider is a material service provider?
Does the arrangement support a critical operation on your register?
Is the arrangement recorded in your material service provider register?
Was due diligence and risk assessment completed before signing?
Does the formal agreement meet CPS 230’s minimum content requirements?
Have you notified APRA before entering the material offshoring arrangement?
Has internal audit reviewed it and reported to the Board?
Are tolerance levels defined, and can the provider operate within them through disruption?
Is there a tested business continuity and recovery plan?
Are data residency and access controls documented and aligned with CPS 234 and the Privacy Act?
Does the provider’s incident escalation let you meet your 72-hour notification obligation?

Frequently Asked Questions

Does APRA CPS 230 apply to my fintech?
CPS 230 applies directly to APRA-regulated entities, such as ADIs. However, non-regulated fintechs partnering with regulated banks inherit these requirements contractually because banks must ensure their third-party service providers comply with CPS 230 expectations across critical operations.
Can Australian banks still outsource offshore under CPS 230?</summary>
Yes. CPS 230 does not prohibit offshore outsourcing; it regulates it. The institution must notify APRA prior to entering a material offshoring arrangement, complete an internal audit review, and manage the provider under the full Material Service Provider framework.
Who is responsible if an offshore provider fails?</summary>
The APRA-regulated institution retains full accountability and cannot transfer responsibility for operational resilience or compliance to a third-party service provider. This makes provider selection a board-level compliance decision.
What is a material service provider under CPS 230?
An institution classifies a provider as a Material Service Provider (MSP) when it relies on that partner to perform a critical operation or when the arrangement creates material operational risk. For ADIs, core functions like credit assessment, funding, and liquidity management are automatically classified as material.
What is a material offshoring arrangement?
A material offshoring arrangement covers any material agreement under which the vendor performs services or handles data outside Australia. This includes arrangements where an Australian-incorporated vendor operates offshore delivery centres, which triggers APRA’s mandatory pre-commitment notification requirement.
How does CPS 230 relate to CPS 234?
CPS 234 regulates information security controls, while CPS 230 governs overall operational risk and third-party service resilience. Offshore partnerships must satisfy both CPS 230 for operational continuity and CPS 234 for data and cybersecurity protection.

Build a Compliant Offshore Partnership for Customers with RCC BPO

APRA CPS 230 compliance has raised the bar for outsourcing in Australian finance, and offshore arrangements sit at the sharp end of it — pre-commitment notification, board-level review, and continuous, evidenced management. Institutions that treat this as a checkbox exercise often inherit unnecessary risk. However, those that select a partner designed for the standard can achieve the cost and coverage advantages of offshore delivery while maintaining operational resilience and control.

RCC BPO works with Australian banks and fintechs as an offshore partner built around these expectations — auditable operations, tested continuity, controlled data handling, and reporting that supports your APRA obligations. To better understand how offshore banking BPO supports your broader operations, explore our guide to Banking BPO Services in Australia. Additionally, if you need guidance on aligning a specific outsourcing arrangement with APRA CPS 230 requirements, our team can help you evaluate the compliance considerations. Connect today to get a detailed evaluation of outsourcing strategies.

Share on:
Sayan Sinha

Sayan Sinha

Sayan Sinha is an insurance-focused CX and BPO professional who helps insurers turn complex customer journeys into growth-ready, compliant experiences. At RCC BPO, he works closely with sales and delivery teams to design scalable CX solutions that improve efficiency, build trust, and deliver measurable business impact.

Categories

Ready to Get Started? Discover smarter, scalable solutions built around your business

    Certification

    Security & compliance is our top priority

    We utilize state of the art encryption and rigorous auditing to safeguard your information.
    All our services meet the industry specific ISO 27001, SOC 2, and PCI DSS compliance standards.

    bsi-27001
    pci-dss
    SOC-2
    Talk to an Expert