In short
A Material Service Provider Agreement is a contract between an APRA-regulated entity and a supplier of a service that, if disrupted, would threaten a critical operation, drafted to meet the specific contractual content requirements of Prudential Standard CPS 230 Operational Risk Management, which took effect from 1 July 2025. It needs step-in, audit, subcontracting and termination assistance rights that most standard commercial services agreements simply don't contain.
Why CPS 230 changed how these agreements have to be drafted
CPS 230 requires APRA-regulated entities — banks, insurers and superannuation trustees — to identify their critical operations, tolerate specific levels of disruption to them, and manage the operational risk arising from service providers that support those operations, whether the provider is a large offshore technology vendor or a small local specialist supplier. Where a service provider supports a critical operation, CPS 230 sets out mandatory content the contract must contain, which means the entity can no longer simply accept a vendor's standard terms and negotiate price. We draft or negotiate these clauses from the regulated entity's side specifically to close the gap between a vendor's off-the-shelf terms and what the standard actually requires.
The clauses CPS 230 makes mandatory, not optional
The standard requires agreements supporting critical operations to include the regulated entity's access and audit rights (including regulator access), the provider's obligation to notify the entity of incidents affecting the service, subcontracting notification and approval rights so a critical function can't be quietly subcontracted offshore without the entity's knowledge, and — critically — a business continuity and exit plan obligation that gives the entity a genuine, tested path to transition the service to another provider or bring it in-house if the relationship fails. Vendor-drafted agreements routinely resist exactly these terms because they shift commercial leverage toward the customer, which is precisely why regulated entities need their own negotiating position going in rather than accepting redlines the vendor proposes.
- Access, audit and regulator step-in rights
- Incident notification obligations tied to defined severity thresholds
- Subcontracting notification and approval rights
- Business continuity and disaster recovery commitments
- Documented exit and transition assistance obligations
- Data location, security and return/destruction on termination
Concentration risk and the register that has to sit behind the contract
CPS 230 also requires entities to manage concentration risk across their service provider register, meaning a single agreement can't be assessed in isolation from the entity's broader dependency map. We advise on how a new material service provider agreement should be structured to support the entity's existing register and risk assessment obligations, including making sure the contract captures enough operational detail (service levels, sub-processor identities, data flows) for the entity to genuinely assess concentration and substitutability risk, not just legal risk.
How this interacts with existing outsourcing and technology contracts
Many regulated entities are retrofitting CPS 230 terms into existing supplier relationships rather than starting fresh, which raises a different problem: amending a live contract without triggering unintended consequences under its existing change-of-terms, pricing or termination provisions. We run a gap analysis against the existing agreement before drafting amendment terms, so the entity isn't inadvertently opening up unrelated commercial terms while trying to close a compliance gap.
What we deliver
A material service provider agreement (or amendment deed to an existing agreement) containing the mandatory CPS 230 content, negotiated from the regulated entity's position, plus a short gap analysis identifying which of the entity's current supplier contracts fall short of the standard's requirements.
What the fixed fee covers
- Access, audit and regulator step-in rights
- Incident notification obligations tied to severity thresholds
- Subcontracting notification and approval mechanism
- Business continuity, disaster recovery and exit/transition obligations
- Data handling, location and return/destruction terms
- Gap analysis against existing supplier agreements
Mistakes we see
- Accepting a vendor's standard terms without adding the mandatory CPS 230 contractual content
- No documented, tested exit plan for transitioning the service to another provider
- Subcontracting rights that let the vendor quietly change who actually delivers the service
- Incident notification triggers so vague they don't produce a timely alert to the regulated entity
- Treating the contract in isolation without checking concentration risk against the entity's other supplier relationships
Who this is for
- APRA-regulated banks, insurers and superannuation trustees
- Entities onboarding a new provider supporting a critical operation
- Businesses remediating existing outsourcing contracts to meet CPS 230
- Technology and BPO vendors negotiating with APRA-regulated customers
Frequently asked questions
- Does CPS 230 apply to every supplier contract we have?
- No. The mandatory contractual content applies to arrangements with material service providers supporting a critical operation, as identified through the entity's own critical operations and tolerance assessment. A supplier providing a genuinely non-critical, easily substitutable service typically falls outside the mandatory content requirements, though good governance still applies.
- What counts as a 'critical operation' under CPS 230?
- An operation that, if disrupted beyond the entity's tolerance levels, would have a material impact on the entity's depositors, policyholders, members or the broader financial system, as determined by the entity's own board-approved assessment. Payment processing, core banking systems and claims handling are common examples for banks and insurers respectively.
- Do offshore vendors need to comply with CPS 230 directly?
- No, CPS 230 is a prudential standard that binds the APRA-regulated entity, not the vendor directly, which is exactly why the mandatory content has to be built into the contract — it's the mechanism by which the regulated entity's obligations flow through to the vendor contractually.
- What's the difference between this and an ordinary outsourcing agreement?
- An ordinary commercial services agreement is negotiated primarily around price, service levels and liability. A CPS 230 material service provider agreement adds a mandatory compliance layer on top — audit and regulator access, incident notification, exit planning and subcontracting control — that exists to satisfy APRA's requirements regardless of what the parties would otherwise have negotiated commercially.
- How does this interact with our AML/CTF Program?
- They're separate regimes administered by different regulators, but where a material service provider also processes customer data relevant to AML/CTF obligations (such as a KYC verification vendor), the contract needs to address both the CPS 230 operational resilience requirements and the reporting entity's ongoing responsibility for the adequacy of outsourced identification procedures.
Related
