Insight

APRA CPS 230: The Material Service Provider Register

10 Sept 2026

In short

APRA CPS 230 mandates that regulated entities maintain a register of material service providers. This requirement aims to enhance operational resilience and manage third-party risk effectively.

APRA Prudential Standard CPS 230 (Operational Resilience) fundamentally changes how regulated entities must manage operational risk and resilience, particularly regarding third-party service providers. A key component of this framework is the mandatory establishment and maintenance of a comprehensive register of all material service providers. This register is crucial for enabling entities to understand their third-party dependencies, assess associated risks, and ensure resilience across their operational ecosystem.

What is APRA CPS 230 and Why is it Important?

APRA CPS 230 is a new prudential standard released by the Australian Prudential Regulation Authority (APRA) focused on operational risk management and operational resilience. It consolidates and replaces several existing prudential standards, including CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management).

The standard aims to ensure that APRA-regulated entities (such as banks, insurers, and superannuation funds) can withstand and recover from disruptions, maintaining their critical operations. It introduces new requirements for risk management, business continuity planning, and the management of third-party interdependencies, reflecting an increased regulatory focus on systemic resilience.

Defining a Material Service Provider under CPS 230

Under CPS 230, a service provider is considered 'material' if the failure or degradation of the service it provides would have a significant impact on the entity's critical operations or its ability to manage risks. This definition is broader than previous outsourcing standards and extends beyond traditional IT or back-office functions.

Determining materiality requires a thorough assessment of each service provider's role in supporting critical operations, potential financial impact, reputational damage, and regulatory compliance obligations. Entities must develop clear criteria for identifying materiality, which should be regularly reviewed and updated.

What is the Material Service Provider Register?

The material service provider register is a central, dynamic repository of information about all third-party service providers deemed material to an APRA-regulated entity's critical operations. It is not merely a list of vendors but a strategic tool for risk management and operational resilience planning. The register must be accurate, complete, and readily accessible to demonstrate compliance and inform decision-making.

Effective management of this register underpins the entity's ability to monitor provider performance, assess inherent risks, and respond effectively to service disruptions. It facilitates proactive engagement with service providers to ensure alignment with the entity's operational resilience objectives.

Key Information to Include in the Register

To be effective and compliant, the material service provider register must contain specific details for each identified provider. This information allows for comprehensive risk assessment and ongoing monitoring.

  • Provider Identification: Full legal name, ABN/ACN, contact details, and primary business contact.
  • Service Description: A clear, detailed description of the services provided, including their criticality to the entity's operations.
  • Contractual Arrangements: Key terms of the service agreement, including commencement and expiry dates, renewal options, and key performance indicators (KPIs).
  • Risk Assessment: Summary of identified risks associated with the service and the provider, including operational, cyber, financial, and concentration risks.
  • Resilience Measures: Details of the service provider's operational resilience capabilities, such as business continuity plans, disaster recovery plans, and cybersecurity frameworks.
  • Exit Strategy: A summary of the exit plan for each material service, outlining how the entity would transition or insource the service if needed.
  • Dependencies: Identification of sub-contractors or fourth-party dependencies relevant to the material service.
  • Monitoring & Review: Schedule for periodic reviews, audit rights, and performance monitoring arrangements.

Establishing and Maintaining the Register: Practical Steps

Developing and managing a compliant and effective material service provider register requires a structured approach and ongoing commitment.

  1. Develop a Materiality Framework: Establish clear, documented criteria for determining which services and providers are material. This framework should be approved by senior management and reviewed periodically.
  2. Inventory All Service Providers: Conduct a comprehensive exercise to identify all existing third-party service providers across the organisation. This may require collaboration across multiple departments.
  3. Assess Materiality: Apply the established framework to each service provider to determine its materiality. Document the rationale for each determination.
  4. Gather Required Information: Collect all necessary data points for each material service provider as outlined above. This may involve engaging directly with providers and reviewing existing contracts.
  5. Implement a Centralised System: Establish a dedicated system or database for managing the register. This system should support data entry, retrieval, reporting, and version control.
  6. Integrate with Risk Management: Ensure the register is integrated with the entity's broader operational risk management framework. Information from the register should feed into risk assessments and control effectiveness reviews.
  7. Establish Governance and Review Cycles: Define clear roles and responsibilities for managing the register, including ownership, data input, and approval processes. Implement regular review cycles (e.g., quarterly or annually) to ensure the register remains accurate and up-to-date.
  8. Regularly Engage Providers: Proactively communicate with material service providers to confirm data accuracy and gather updates on their operational resilience capabilities.

For further guidance, entities can refer to APRA's official resources on CPS 230, including relevant prudential practice guides (PPGs) available on their website: apra.gov.au.

Consequences of Non-Compliance

Non-compliance with APRA CPS 230, including failures related to the material service provider register, can result in significant regulatory consequences. APRA has broad powers to enforce its prudential standards. These can include directions to rectify deficiencies, imposition of additional capital requirements, and potentially civil penalties for serious breaches.

Beyond regulatory action, a lack of a robust register can lead to undetected concentration risks, increased exposure to cyber threats, and an inability to respond effectively during operational disruptions. This can result in significant financial losses, reputational damage, and erosion of customer and stakeholder trust.

It is critical for regulated entities to proactively address these requirements to avoid adverse outcomes. Understanding contractual obligations with third parties is a key aspect of compliance. Our team can assist with reviewing and drafting business contracts to ensure they align with CPS 230 requirements.

Frequently asked questions

What is the primary purpose of the material service provider register under CPS 230?

The primary purpose is to provide APRA-regulated entities with a comprehensive overview of all external service providers crucial to their critical operations. This enables effective identification, assessment, and management of third-party risks, enhancing overall operational resilience and ensuring compliance with prudential standards.

How frequently must the material service provider register be updated?

APRA CPS 230 requires entities to ensure the register is accurate, complete, and current. While no specific frequency is mandated, industry best practice suggests at least annual formal reviews and updates. Entities should also update the register promptly upon any significant changes to a material service provider or the services they provide.

Does CPS 230 apply only to direct service providers?

No, CPS 230 extends beyond direct service providers to include 'fourth-party' or sub-contractor dependencies where these are material to the entity's critical operations. Entities must identify and understand these deeper dependencies. This ensures a holistic view of the operational resilience risks across the entire supply chain of critical services.

Talk to us

Ready to talk it through?

Send us a note about what you're working on. We'll respond within one business day and, if we're a fit, book a free 15-minute consultation with a senior lawyer.

We treat every message as confidential.

Talk to us

Reviewing this in your business?

Send us a note about what you're working on. We'll respond within one business day and, if we're a fit, book a free 15-minute consultation with a senior lawyer.

We treat every message as confidential.

CallBook Call