APRA Prudential Standard CPS 230 does not allow an APRA-regulated entity to transfer its operational risk obligations through outsourcing. The entity remains accountable for managing risks associated with material service providers. Outsourcing arrangements must be governed, monitored and supported by controls that ensure critical operations remain resilient and continue to meet prudential requirements.
Expanded Answer
CPS 230 recognises that APRA-regulated entities may outsource important business activities, but it makes clear that accountability remains with the regulated entity. The board and senior management remain responsible for ensuring operational risks arising from outsourced arrangements are identified, assessed, monitored and managed. Engaging an external provider does not reduce the entity’s responsibility for operational resilience or compliance with prudential requirements.
Entities should establish governance arrangements for all material service providers, including due diligence before appointment, clearly documented contractual responsibilities, performance monitoring, risk assessments, incident reporting, business continuity planning and regular review of provider performance. The entity should understand how disruption to a material service provider could affect its critical operations and maintain appropriate contingency arrangements. Oversight should be ongoing and supported by documented evidence demonstrating that outsourced services continue to meet operational, resilience and governance expectations.
Key obligations:
- Remain accountable for operational risks arising from outsourced services.
- Monitor the performance, resilience and risk profile of material service providers throughout the outsourcing arrangement.
- Maintain contingency arrangements that enable critical operations to continue if a material service provider is disrupted.
Why it matters
Material service providers can introduce significant operational, technology and continuity risks. CPS 230 requires APRA-regulated entities to actively govern those risks because operational failures at an outsourced provider remain the responsibility of the regulated entity and may affect customers, critical operations and prudential outcomes.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call
Practical guidance
- Conduct documented due diligence before appointing any material service provider.
- Monitor outsourced providers through regular performance reporting, risk assessments and resilience reviews.
- Maintain tested contingency plans that support critical operations if an outsourced service is disrupted.
Further reading
APRA CPS 230 explained for financial services businesses