APRA CPS 230 Compliance for Offshore Outsourcing: What Australian Banks and Fintechs Must Know
If your institution outsources any part of its operations — especially offshore — APRA CPS 230 compliance is now the standard that governs it. And the single most important thing to understand is this: the obligations stay with you. You can outsource the work, but not the accountability. When an Australian bank hands over loan processing, payments, or customer support to a provider, APRA still holds the bank responsible for how those functions are run, secured, and how any losses are recovered when something goes wrong.
- Uncompromising Accountability: APRA CPS 230 compliance requires APRA-regulated institutions to retain full accountability for operational risk when outsourcing to offshore partners.
- Pre-Commitment APRA Notification: Institutions must notify APRA prior to entering into or significantly altering any material offshoring arrangement.
- Incident Escalation Windows: Providers must support the institution’s mandatory 72-hour operational risk incident notification timeline to APRA.
- MSP Governance: Any offshore function supporting core banking, loan processing, payments, or customer support qualifies as a Material Service Provider (MSP) requiring formal board oversight and register tracking.
This guide explains what CPS 230 requires, how it treats offshore providers, and what a compliant offshore partnership actually looks like. It is written for the institutions that outsource — banks, ADIs, and the fintechs that work alongside them.
From CPS 231 to CPS 230: What has changed?
For years, outsourcing by APRA-regulated entities was governed by CPS 231 (Outsourcing) and business continuity by CPS 232. Both are gone. CPS 230 Operational Risk Management came into force on 1 July 2025, consolidating them into a single, broader standard. The updated version of CPS 230 and its practice guide (CPG 230) took effect on 1 July 2026 following targeted amendments for non-traditional service providers.
The shift is more than a rename. CPS 230 replaces the old, narrow idea of “outsourcing” with the wider concept of a material service provider — and it puts operational resilience, not just contract management, at the center. That change is what makes APRA CPS 230 outsourcing obligations bite harder than the standard they replaced.
Know your requirements – Does CPS 230 apply to you?
CPS 230 applies directly to APRA-regulated entities: authorized deposit-taking institutions (ADIs, including foreign ADI branches), general, life and private health insurers, and superannuation (RSE) licensees.
For fintechs, the answer depends on status. A fintech that is itself an ADI or otherwise APRA-regulated is directly bound. A fintech that is not regulated by APRA is not directly subject to CPS 230 — but it almost always inherits the requirements contractually the moment it partners with a regulated bank, because the bank has to push those obligations down to everyone in its critical-operations chain. Either way, maintaining full APRA CPS 230 compliance shapes what you have to do if you sit anywhere in a regulated institution’s supply of critical services.
Is your provider a “material service provider”?
This is the question that determines how much of CPS 230 applies to a given arrangement. Under the prudential standard, a provider is defined as a material service provider (MSP) when the entity relies on it to undertake a critical operation, or when it exposes the entity to material operational risk. For ADIs, key functions are automatically classified as material, including credit assessment, funding and liquidity management, and mortgage brokerage.
Under APRA guidelines, critical operations are defined as functions that would cause material harm to customers or the financial system if disrupted beyond acceptable tolerance levels. APRA directly identifies several examples that align with BPO services, including payments, deposit-taking support, claims processing, investment management, fund administration, and customer inquiries. In addition, institutions must account for the costs of supporting IT infrastructure and maintain a formal register to track all critical functions.
If your offshore provider touches any of these functions, treat the arrangement as material and plan for full APRA CPS 230 compliance.
What Does CPS 230 Require of the Institution?
CPS 230 sets out a lifecycle of obligations for managing material service providers. In plain terms, a regulated institution must maintain six core controls:
- A service provider management policy: Formal rules governing how providers are selected, managed, and exited.
- A material service provider register: A formal inventory of MSPs and critical operations. Institutions submitted their first MSP register to APRA by 1 October 2025 and maintain it on an ongoing basis.
- Due diligence and risk assessment: Mandatory evaluations conducted before signing or altering material arrangements.
- A formal agreement: Contracts that strictly satisfy CPS 230’s minimum content requirements.
- Ongoing risk management and monitoring: Continuous performance tracking paired with regular executive and board reporting.
- Business continuity capability: The ability to maintain critical operations within defined tolerance levels through severe disruption, validated via scenario testing.
None of these responsibilities can be delegated to an external partner. The provider enables operational compliance; the institution owns regulatory accountability.
The Offshoring Rules: Where Offshore Outsourcing Compliance in Australia Gets Specific?
This is where an offshore arrangement diverges from a domestic one, and it is the part institutions most often underestimate.
CPS 230 defines a material offshoring arrangement as any material agreement where service delivery physically occurs outside Australia. Notably, this includes scenarios where the provider is incorporated locally in Australia but uses an overseas delivery team. Three specific offshore outsourcing obligations apply:
- Notify APRA before you commit: An institution must formally notify APRA prior to entering into any material offshoring arrangement or making significant changes to an existing one. This pre-commitment step is distinct from the 20-business-day notification rule applied to general critical-operations agreements.
- Internal audit review: The institution’s internal audit team must evaluate any proposed material outsourcing of a critical operation and report compliance findings directly to the Board or Board Audit Committee.
- Data location and privacy controls: Where customer data is stored, processed, or accessed offshore, the arrangement must meet CPS 230 operational risk rules, CPS 234 information security standards, and the requirements of the Privacy Act.
The practical takeaway: choosing an offshore provider is a board-visible, APRA-notified decision. That raises the bar for providers who can be credibly chosen — and rewards those who come to the table already able to demonstrate compliance.
What to demand from an offshore provider?
Because regulatory accountability stays with the institution, the provider’s job is to make compliance demonstrable rather than to claim it. When evaluating a partner for banking outsourcing compliance in Australia, insist on:
- Auditability by default: Complete, retrievable call logs, transaction records, and verification trails the institution can produce for APRA or internal audit without a scramble.
- Tested business continuity: Documented continuity and recovery plans, aligned to the institution’s tolerance levels and validated through scenario testing, not a plan that only exists on paper.
- Contract terms that meet minimum-content requirements: Formal agreement terms that satisfy APRA CPS 230 compliance out of the box.
- Data residency and access controls: Clear parameters on data storage and access map directly to CPS 234 and Privacy Act obligations.
- Incident reporting that feeds your clock: Escalation protocols fast enough for the institution to meet its mandatory 72-hour operational risk incident notification deadline to APRA.
- Support for notifications and registers: The MSP register stays current and supports accurate offshoring notifications through structured data output.
A provider that treats these controls as standard practice turns an offshore arrangement from a regulatory liability into a defensible operational asset.
What to keep in mind when outsourcing to offshore teams?
<div style=”max-width: 900px; margin: 45px auto; font-family: Arial,Helvetica,sans-serif;”>
Frequently Asked Questions
Does APRA CPS 230 apply to my fintech?
Can Australian banks still outsource offshore under CPS 230?</summary>
Who is responsible if an offshore provider fails?</summary>
What is a material service provider under CPS 230?
What is a material offshoring arrangement?
How does CPS 230 relate to CPS 234?
Build a Compliant Offshore Partnership for Customers with RCC BPO
APRA CPS 230 compliance has raised the bar for outsourcing in Australian finance, and offshore arrangements sit at the sharp end of it — pre-commitment notification, board-level review, and continuous, evidenced management. Institutions that treat this as a checkbox exercise often inherit unnecessary risk. However, those that select a partner designed for the standard can achieve the cost and coverage advantages of offshore delivery while maintaining operational resilience and control.
RCC BPO works with Australian banks and fintechs as an offshore partner built around these expectations — auditable operations, tested continuity, controlled data handling, and reporting that supports your APRA obligations. To better understand how offshore banking BPO supports your broader operations, explore our guide to Banking BPO Services in Australia. Additionally, if you need guidance on aligning a specific outsourcing arrangement with APRA CPS 230 requirements, our team can help you evaluate the compliance considerations. Connect today to get a detailed evaluation of outsourcing strategies.