FAQ

How does outsourcing affect an entity’s obligations under CPS 230?

APRA Prudential Standard CPS 230 does not allow an APRA-regulated entity to transfer its operational risk obligations through outsourcing. The entity remains accountable for managing risks associated with material service providers. Outsourcing arrangements must be governed, monitored and supported by controls that ensure critical operations remain resilient and continue to meet prudential requirements.

Expanded Answer

CPS 230 recognises that APRA-regulated entities may outsource important business activities, but it makes clear that accountability remains with the regulated entity. The board and senior management remain responsible for ensuring operational risks arising from outsourced arrangements are identified, assessed, monitored and managed. Engaging an external provider does not reduce the entity’s responsibility for operational resilience or compliance with prudential requirements.

Entities should establish governance arrangements for all material service providers, including due diligence before appointment, clearly documented contractual responsibilities, performance monitoring, risk assessments, incident reporting, business continuity planning and regular review of provider performance. The entity should understand how disruption to a material service provider could affect its critical operations and maintain appropriate contingency arrangements. Oversight should be ongoing and supported by documented evidence demonstrating that outsourced services continue to meet operational, resilience and governance expectations.

Key obligations:

  • Remain accountable for operational risks arising from outsourced services.
  • Monitor the performance, resilience and risk profile of material service providers throughout the outsourcing arrangement.
  • Maintain contingency arrangements that enable critical operations to continue if a material service provider is disrupted.

Why it matters

Material service providers can introduce significant operational, technology and continuity risks. CPS 230 requires APRA-regulated entities to actively govern those risks because operational failures at an outsourced provider remain the responsibility of the regulated entity and may affect customers, critical operations and prudential outcomes.

Unsure how this applies to you?

Get a clear answer in a 15-minute call with a compliance specialist. Book your call

Practical guidance

  • Conduct documented due diligence before appointing any material service provider.
  • Monitor outsourced providers through regular performance reporting, risk assessments and resilience reviews.
  • Maintain tested contingency plans that support critical operations if an outsourced service is disrupted.

Further reading

APRA CPS 230 explained for financial services businesses

Outsourcing: Conflicts, compromises and compliance

Outsourcing compliance: Who do you want on your team?

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?