No. APRA Prudential Standard CPS 230 does not apply directly to Australian Financial Services Licensees (AFSL holders) or Australian Credit Licensees (ACL holders) that are not regulated by APRA. These licensees remain subject to ASIC’s licensing and compliance obligations, although CPS 230’s operational risk principles may provide a useful governance benchmark.
Expanded Answer
CPS 230 is a prudential standard issued by APRA for entities that it regulates, including authorised deposit-taking institutions (ADIs), insurers and registrable superannuation entity (RSE) licensees. A business does not become subject to CPS 230 simply because it holds an AFSL or ACL. Unless the entity is also APRA-regulated, compliance with CPS 230 is not a legal requirement.
Many ASIC-regulated licensees nevertheless adopt elements of CPS 230 to strengthen their governance, particularly where they rely on outsourced service providers, technology platforms or critical business processes. Practices such as documenting operational risks, maintaining business continuity arrangements, overseeing service providers and monitoring critical controls can support stronger compliance systems and operational resilience. These measures should complement, rather than replace, the licensee’s obligations under the Corporations Act, National Consumer Credit Protection Act and ASIC’s regulatory expectations.
Applies to: APRA-regulated entities only.
Not required for: AFSL holders and ACL holders that are regulated solely by ASIC.
Why it matters
Understanding the distinction prevents licensees from treating prudential standards as mandatory when they are not. It also helps businesses adopt useful operational risk practices without confusing voluntary governance improvements with enforceable regulatory obligations.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call
Practical guidance
- Confirm whether your organisation is regulated by APRA before assessing CPS 230 obligations.
- Align your compliance framework with ASIC’s licensing obligations while adopting operational resilience practices appropriate to your business.
- Review outsourcing, business continuity and operational risk controls regularly to strengthen governance and resilience.
Further reading
What are the requirements for an AFSL?
Why Australian Credit Licensees are adopting compliance infrastructure