Skip to content

Evidence request lists

APRA CPS 230 Operational Risk Management

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assurance

CPS230-66
Review of Operational Risk Management

As part of the risk management framework reviews required under CPS 220 and SPS 220 the entity must review its operational risk management, covering each of the operational risk elements the framework is required to contain.

Artefacts an auditor will ask for
  • Review reports covering operational risk management
  • Scope evidence covering every required framework element
  • Reviewer independence and competence records
Where this commonly fails
  • Framework review skips the operational risk elements
  • Scope narrower than the elements required by paragraph 16

Business Continuity

CPS230-26
Critical Operations Register, Continuity Plan and Activation

The entity must define, identify and maintain a register of its critical operations, take reasonable steps to minimise the likelihood and impact of disruption to them, maintain a credible business continuity plan setting out how it would hold critical operations within tolerance levels through disruption including disaster recovery planning for critical information assets, activate that plan when needed and return to normal operations promptly.

Artefacts an auditor will ask for
  • Register of critical operations
  • Approved business continuity plan including disaster recovery planning for critical information assets
  • Activation records and post disruption return to normal evidence
Where this commonly fails
  • BCP exists but omits disaster recovery for critical information assets
  • No evidence the plan has ever been activated or rehearsed for activation
CPS230-27
Identification and Escalation of Incidents and Near Misses

Operational risk incidents and near misses must be identified, escalated, recorded and addressed promptly, and must feed promptly into the assessment of the operational risk profile and of control effectiveness.

Artefacts an auditor will ask for
  • Incident and near miss register
  • Escalation records with timestamps
  • Evidence incidents updated the risk profile and control assessments
Where this commonly fails
  • Near misses not captured
  • Incidents recorded but never reflected in the risk profile
CPS230-33
Systematic BCP Testing Program

The entity must run a systematic testing program for its business continuity plan that covers all critical operations and includes an annual business continuity exercise, testing the effectiveness of the plan and the ability to meet tolerance levels across a range of severe but plausible scenarios.

Artefacts an auditor will ask for
  • Testing program and schedule covering all critical operations
  • Annual business continuity exercise reports
  • Results measured against tolerance levels
Where this commonly fails
  • Testing covers selected operations only
  • Exercises run but tolerance levels not measured
CPS230-34
Tailoring of the Testing Program

The testing program must be tailored to the material risks of the entity and include a range of severe but plausible scenarios, among them disruptions to services provided by material service providers and scenarios requiring contingency arrangements.

Artefacts an auditor will ask for
  • Scenario library with rationale linking scenarios to material risks
  • Evidence of service provider disruption scenarios
  • Contingency arrangement scenarios and results
Where this commonly fails
  • Same scenarios repeated each year
  • Material service provider failure never exercised
CPS230-P40
Required Content of the Business Continuity Plan

The business continuity plan must contain the register of critical operations and their tolerance levels, triggers for identifying a disruption and prompting activation together with arrangements for directing resources on activation, the actions the entity would take to hold critical operations within tolerance, an assessment of execution risks, required resources and preparatory measures including key internal and external dependencies, and a communications strategy supporting execution.

Artefacts an auditor will ask for
  • BCP document mapped against each required content element
  • Activation triggers and resource direction arrangements
  • Execution risk assessment and dependency analysis
  • Communications strategy
Where this commonly fails
  • Plan lists actions but omits execution risk and dependency analysis
  • Activation triggers undefined
CPS230-P41
BCP Execution Capability and Tolerance Breach Reporting

The entity must maintain the capabilities needed to execute the business continuity plan including access to people, resources and technology, must monitor compliance with its tolerance levels, and must report any failure to meet a tolerance level to the Board together with a remediation plan.

Artefacts an auditor will ask for
  • Capability inventory supporting BCP execution including third party held capability
  • Tolerance level monitoring records
  • Board reports of tolerance breaches with remediation plans
Where this commonly fails
  • Capability assumed available and never verified
  • Tolerance breaches handled operationally without Board reporting
CPS230-P45
Annual Update of the Business Continuity Plan

The entity must update its business continuity plan as necessary on an annual basis to reflect changes in legal or organisational structure, business mix, strategy or risk profile and to close shortcomings found through review and testing.

Artefacts an auditor will ask for
  • Annual BCP update records with change log
  • Traceability from test and review findings to plan changes
  • Approval of each updated version
Where this commonly fails
  • Plan reviewed annually but never changed despite test failures
  • Organisational change not reflected in the plan

Controls

CPS230-P30
Monitoring, Review and Testing of Control Effectiveness

The entity must regularly monitor, review and test controls for design and operating effectiveness at a frequency proportionate to the materiality of the risks controlled, report results to senior management, and rectify any gaps or deficiencies in the control environment promptly.

Artefacts an auditor will ask for
  • Control testing schedule with frequency rationale by risk materiality
  • Test results reported to senior management
  • Rectification tracker with closure evidence
Where this commonly fails
  • Uniform testing frequency regardless of risk materiality
  • Deficiencies recorded but left open
CPS230-P31
Remediation of Material Operational Risk Weaknesses

The entity must remediate material weaknesses in its operational risk management including control gaps, weaknesses and failures, supported by clear accountabilities and assurance, addressing root causes promptly, and must keep identified gaps, weaknesses and failures in its operational risk profile until they are remediated.

Artefacts an auditor will ask for
  • Remediation plans with named accountable owners
  • Root cause analyses
  • Evidence open items remain in the operational risk profile until closed
Where this commonly fails
  • Symptoms fixed without root cause analysis
  • Items removed from the risk profile before remediation completed

Critical Operations

CPS230-17
Mandatory Minimum Classification of Critical Operations

Unless it can justify otherwise the entity must classify as critical operations at least payments, deposit taking and management, custody, settlements and clearing for an ADI, claims processing for an insurer, investment management and fund administration for an RSE licensee, and for all entities customer enquiries together with the systems and infrastructure supporting critical operations.

Artefacts an auditor will ask for
  • Classification decisions against the mandatory minimum list
  • Documented justification for any listed operation excluded
  • Mapping of supporting systems and infrastructure
Where this commonly fails
  • Mandatory list not applied to the entity type
  • Exclusions taken without a documented justification
CPS230-19
Tolerance Levels for Each Critical Operation

For every critical operation the entity must set tolerance levels covering the maximum period of disruption it would tolerate, the maximum extent of data loss it would accept, and the minimum service levels it would maintain while operating under alternative arrangements during a disruption.

Artefacts an auditor will ask for
  • Tolerance level register covering all three dimensions per critical operation
  • Basis and rationale for each tolerance
  • Board approval evidence
Where this commonly fails
  • Only a time based tolerance set
  • Minimum service levels during alternative operation undefined
CPS230-20
Prevention, Adaptation and Return to Normal Operations

So far as practicable the entity must prevent disruption to critical operations, adapt its processes and systems to keep operating within tolerance levels during a disruption, and return to normal operations promptly once the disruption is over.

Artefacts an auditor will ask for
  • Preventive measures mapped to critical operations
  • Alternative operating arrangements and workarounds
  • Post disruption return to normal records
Where this commonly fails
  • Focus on recovery with no preventive measures
  • No defined path back to normal operations
CPS230-24
Design and Embedding of Internal Controls

The entity must design, implement and embed internal controls that mitigate its operational risks in line with its risk appetite and allow it to meet its compliance obligations.

Artefacts an auditor will ask for
  • Control library mapped to operational risks and compliance obligations
  • Control design documentation
  • Evidence controls are embedded in business process
Where this commonly fails
  • Controls documented but not operating
  • No linkage from controls to risk appetite

Governance

CPS230-P23
Senior Management Information to the Board on Resilience Decisions

Senior management must give the Board clear and comprehensive information on the expected impacts to critical operations whenever the Board is making decisions that could affect the resilience of those operations.

Artefacts an auditor will ask for
  • Board papers for resilience affecting decisions showing critical operation impacts
  • Evidence of the impact assessment supporting each paper
  • Board minutes recording consideration
Where this commonly fails
  • Strategic decisions taken with no critical operation impact assessment
  • Impact information limited to cost and benefit

Operational Risk Management Framework

CPS230-11
Identification, Assessment and Management of Operational Risk

The entity must identify, assess and manage the operational risks arising from inadequate or failed internal processes and systems, from the actions or inactions of people, and from external drivers and events, recognising that operational risk is inherent in all products, activities, processes and systems.

Artefacts an auditor will ask for
  • Operational risk taxonomy and register
  • Risk and control self assessment records
  • Coverage evidence across all products, activities, processes and systems
Where this commonly fails
  • Register covers technology risk only
  • Externally driven risks omitted
CPS230-13
Board Accountability for Operational Risk Management

The Board is ultimately accountable for oversight of the entity operational risk management, including business continuity and the management of service provider arrangements.

Artefacts an auditor will ask for
  • Board charter assigning operational risk accountability
  • Board minutes covering business continuity and service provider oversight
  • Board reporting pack contents
Where this commonly fails
  • Accountability recorded for operational risk but not for continuity or service providers
  • No Board level record of oversight
CPS230-14
Board Setting of Senior Manager Roles and Responsibilities

The Board must ensure the entity sets clear roles and responsibilities for senior managers covering operational risk management, business continuity and the management of service provider arrangements.

Artefacts an auditor will ask for
  • Accountability statements or role descriptions for senior managers
  • Board approval of the allocation
  • Coverage of continuity and service provider duties
Where this commonly fails
  • Roles allocated informally without Board endorsement
  • Continuity and service provider duties unassigned
CPS230-15
Operational Risk Elements of the Risk Management Framework

As part of the risk management framework required by CPS 220 and SPS 220 the entity must develop and maintain operational risk governance, an operational risk profile assessment with a defined risk appetite supported by indicators, limits and tolerance levels, effective internal controls, monitoring, analysis, reporting and escalation, tested business continuity plans, and processes for managing service provider arrangements.

Artefacts an auditor will ask for
  • Risk management framework documentation covering the six operational risk elements
  • Risk appetite statement with operational indicators, limits and tolerance levels
  • Escalation procedures for operational incidents and events
Where this commonly fails
  • Operational risk appetite stated without indicators or limits
  • Service provider processes sitting outside the framework
CPS230-16
Internal Audit Review of the Business Continuity Plan

Internal audit must periodically review the business continuity plan and give the Board assurance that it is a credible plan for holding critical operations within tolerance levels through severe disruption and that testing procedures are adequate and have been carried out satisfactorily.

Artefacts an auditor will ask for
  • Internal audit reports on the BCP
  • Assurance opinions provided to the Board
  • Assessment of the adequacy and conduct of testing
Where this commonly fails
  • Audit reviews testing paperwork without opining on plan credibility
  • No periodic cadence defined
CPS230-8
Board Oversight, Approval of the BCP, Tolerance Levels and Service Provider Policy

The Board must oversee operational risk management and the effectiveness of key internal controls in holding the risk profile within appetite with regular updates and action where concerns arise, approve the business continuity plan and the tolerance levels for disruption to critical operations and review testing results and the execution of findings, and approve the service provider management policy and review risk and performance reporting on material service providers.

Artefacts an auditor will ask for
  • Board approvals of the BCP, tolerance levels and service provider policy
  • Regular Board updates on the operational risk profile
  • Board review of testing results and material service provider reporting
Where this commonly fails
  • Tolerance levels set by management without Board approval
  • Testing results never reaching the Board
CPS230-9
Management of the Full Range of Operational Risks

The entity must manage its full range of operational risks including legal, regulatory, compliance, conduct, technology, data and change management risk, with senior management responsible for operational risk management across the end to end process for all business operations.

Artefacts an auditor will ask for
  • Risk taxonomy evidencing each named risk category
  • End to end process ownership records
  • Senior management responsibility assignments
Where this commonly fails
  • Named categories such as conduct or data risk absent from the taxonomy
  • Ownership assigned by function rather than end to end process
CPS230-P12
Key Principles for Operational Risk, Resilience and Service Providers

The entity must effectively manage its operational risks and set and maintain appropriate standards for conduct and compliance, hold its critical operations within tolerance levels through severe disruption, and manage the risks arising from its use of service providers.

Artefacts an auditor will ask for
  • Documented conduct and compliance standards
  • Evidence the three principles are reflected in the framework
  • Management attestation against each principle
Where this commonly fails
  • Conduct and compliance standards absent
  • Principles stated in policy with no operating evidence
CPS230-P18
Integration with the Risk Management Framework and Recovery Planning

Operational risk management must be integrated into the entity overall risk management framework and processes, and business continuity planning must be consistent with and must not conflict with or undermine the entity recovery and exit planning.

Artefacts an auditor will ask for
  • Evidence of integration into the enterprise framework and processes
  • Consistency review between the BCP and recovery and exit plans
  • Records reconciling conflicting assumptions
Where this commonly fails
  • Operational risk run as a standalone silo
  • BCP and recovery plan assumptions never reconciled
CPS230-P26
Assessment of Business and Strategic Decisions on the Risk Profile

As part of business and strategic planning the entity must assess the impact of its business and strategic decisions on its operational risk profile and operational resilience, including the impact of new products, services, geographies and technologies.

Artefacts an auditor will ask for
  • Operational risk assessments embedded in strategic planning papers
  • New product, service, geography and technology assessments
  • Evidence the assessments changed the risk profile record
Where this commonly fails
  • Strategic planning without operational risk input
  • New technology adopted with no resilience assessment
CPS230-P27
Comprehensive Assessment of the Operational Risk Profile

The entity must maintain a comprehensive assessment of its operational risk profile, supported by information systems that monitor operational risk and enable reporting to the Board and senior management, by documentation of the processes and resources needed to deliver critical operations including people, technology, information, facilities and service providers together with their interdependencies, risks, obligations, key data and controls, and by scenario analysis of severe operational risk events that tests resilience and identifies the need for new or amended controls.

Artefacts an auditor will ask for
  • Operational risk profile assessment and supporting systems
  • End to end process and resource maps with interdependencies for each critical operation
  • Scenario analysis results and resulting control changes
Where this commonly fails
  • Process maps stop at the department boundary
  • Scenario analysis performed but no control changes traced from it
CPS230-P28
Risk Assessment Before Providing a Material Service to Another Party

Before providing a material service to another party the entity must conduct a comprehensive risk assessment to confirm it will still be able to meet its prudential obligations after entering the arrangement.

Artefacts an auditor will ask for
  • Risk assessments for services provided to other parties
  • Prudential obligation impact conclusions
  • Approval records before the arrangement commences
Where this commonly fails
  • Only inbound service arrangements assessed
  • Assessment performed after the arrangement began

Operations

CPS230-P25
Information and Technology Capability and Asset Health

The entity must maintain sound information and technology capability to meet current and projected business requirements and to support critical operations and risk management, and in managing technology risk must monitor the age and health of its information assets and meet the information security requirements of CPS 234.

Artefacts an auditor will ask for
  • Technology capability assessment against current and projected requirements
  • Asset age and health monitoring records including end of life tracking
  • Evidence of CPS 234 compliance linkage
Where this commonly fails
  • Legacy asset age and health untracked
  • Capability assessed against current needs only

Regulatory

CPS230-P33
APRA Notification of Operational Risk Incidents within 72 Hours

The entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an operational risk incident it determines is likely to have a material financial impact or a material impact on its ability to maintain critical operations.

Artefacts an auditor will ask for
  • Notification records with awareness and submission timestamps
  • Materiality determination criteria and decision records
  • Escalation path from the incident register to the notification decision
Where this commonly fails
  • Clock started at incident classification rather than awareness
  • No documented materiality threshold
CPS230-P42
APRA Notification of Disruption Outside Tolerance within 24 Hours

The entity must notify APRA as soon as possible and no later than 24 hours after suffering a disruption to a critical operation outside tolerance, covering the nature of the disruption, the action taken, the likely impact on business operations and the timeframe for returning to normal operations.

Artefacts an auditor will ask for
  • Notification records with disruption and submission timestamps
  • Evidence the notification covered all four required content elements
  • Tolerance breach detection records feeding the notification
Where this commonly fails
  • Tolerance breach detected late so the 24 hour clock is missed
  • Notification sent without impact or return timeframe
CPS230-P51
Annual Submission of the Material Service Provider Register to APRA

The entity must submit its register of material service providers to APRA on an annual basis.

Artefacts an auditor will ask for
  • Submission records and dates for each annual cycle
  • The register as submitted
  • Reconciliation between the submitted register and the live register
Where this commonly fails
  • Register maintained internally but never submitted
  • Submitted register out of step with the live register
CPS230-P59
APRA Notification of Service Agreements and Offshoring

The entity must notify APRA as soon as possible and no more than 20 business days after entering into or materially changing an agreement for a service it relies on to undertake a critical operation, and must notify APRA before entering into any material offshoring arrangement or when a significant change to such an arrangement is proposed, including where data or personnel relevant to the service will be located offshore.

Artefacts an auditor will ask for
  • Notification records with execution and submission dates
  • Offshoring notifications evidencing they preceded execution
  • Identification of arrangements where data or personnel move offshore
Where this commonly fails
  • Offshoring notified after signature instead of before
  • The 20 business day clock tracked from contract start rather than execution

Service Provider Management

CPS230-37
Service Provider Management Policy

The entity must maintain a comprehensive service provider management policy covering how it identifies material service providers and manages service provider arrangements, including managing the material risks those arrangements create.

Artefacts an auditor will ask for
  • Approved service provider management policy
  • Board approval evidence
  • Identification criteria for material service providers
Where this commonly fails
  • Policy covers procurement only
  • Criteria for materiality left to judgement with no policy basis
CPS230-39
Register of Material Service Providers

The entity must identify and maintain a register of its material service providers and manage the material risks of using them, material providers and arrangements being those the entity relies on to undertake a critical operation or that expose it to material operational risk.

Artefacts an auditor will ask for
  • Register of material service providers and material arrangements
  • Materiality determinations with supporting rationale
  • Risk management records per provider
Where this commonly fails
  • Register limited to outsourcing contracts
  • Providers exposing the entity to material operational risk omitted
CPS230-40
Mandatory Minimum Classification of Material Service Providers

Unless it can justify otherwise the entity must classify as material service providers at least those supplying credit assessment, funding and liquidity management and mortgage brokerage for an ADI, underwriting, claims management, insurance brokerage and reinsurance for an insurer, fund administration, custodial services, investment management and arrangements with promoters and financial planners for an RSE licensee, and for all entities risk management, core technology services and internal audit.

Artefacts an auditor will ask for
  • Classification decisions against the mandatory minimum list
  • Documented justification for any exclusion
  • Entity type specific coverage evidence
Where this commonly fails
  • Internal audit or risk management providers not classified as material
  • Exclusions undocumented
CPS230-43
Due Diligence Before Entering or Modifying a Material Arrangement

Before entering into or materially modifying a material arrangement the entity must undertake appropriate due diligence including a proper selection process and an assessment of the provider ability to deliver on an ongoing basis, and must assess the financial and non financial risks of relying on the provider including risks from the geographic location or concentration of the provider or of the parties it relies on.

Artefacts an auditor will ask for
  • Due diligence files and selection records
  • Financial and non financial risk assessments
  • Geographic location and concentration analysis
Where this commonly fails
  • Due diligence performed at onboarding but not on material modification
  • Concentration across providers never assessed
CPS230-45
APRA Access Provisions in Formal Agreements

Formal agreements must also give APRA access to documentation, data and other information relating to the service, give APRA the right to conduct an on site visit to the provider, and secure the provider agreement not to impede APRA in performing its duties as prudential regulator.

Artefacts an auditor will ask for
  • Contract clauses granting APRA access, on site visit rights and non impedance
  • Clause coverage review across all material arrangements
  • Remediation plans for legacy agreements lacking the clauses
Where this commonly fails
  • Legacy contracts never uplifted
  • Offshore providers resisting on site visit rights
CPS230-46
Ongoing Risk Management of Each Material Arrangement

For each material arrangement the entity must identify and manage the risks that could affect the provider ability to deliver on an ongoing basis, identify and manage risks to the entity arising from the arrangement such as step in risk or contagion risk, ensure it can execute its business continuity plan if needed, and ensure it can exit the arrangement in an orderly way if needed.

Artefacts an auditor will ask for
  • Per arrangement risk assessments covering step in and contagion risk
  • Exit plans and evidence of their feasibility
  • Linkage between provider arrangements and BCP execution
Where this commonly fails
  • Exit plans asserted but never tested for feasibility
  • Step in and contagion risk not considered
CPS230-47
Monitoring and Senior Management Reporting on Material Arrangements

The entity must monitor material arrangements and ensure senior management receive reporting proportionate to the nature and usage of the service, including regular assessment of performance against agreed service levels, the effectiveness of controls managing provider risk, and compliance by both parties with the agreement.

Artefacts an auditor will ask for
  • Service level performance reporting
  • Control effectiveness assessments for provider risks
  • Two way compliance reviews against the agreement
Where this commonly fails
  • Monitoring covers provider performance but not the entity own compliance
  • Reporting not reaching senior management
CPS230-49
Internal Audit Review of Proposed Critical Operation Outsourcing

Internal audit must review any proposed material arrangement that would outsource a critical operation, and must report regularly to the Board or Board Audit Committee on whether such arrangements comply with the entity service provider management policy.

Artefacts an auditor will ask for
  • Internal audit reviews of proposed critical operation outsourcing
  • Reports to the Board or Board Audit Committee
  • Compliance assessments against the service provider policy
Where this commonly fails
  • Audit engaged after signature rather than at proposal stage
  • No regular reporting cadence to the Board
CPS230-P15
Precondition for Reliance on a Service Provider

The entity must not rely on a service provider unless it can ensure that in doing so it can continue to meet its prudential obligations in full and can effectively manage the associated risks.

Artefacts an auditor will ask for
  • Pre reliance assessments confirming prudential obligations can still be met
  • Approval records for each reliance decision
  • Risk manageability conclusions
Where this commonly fails
  • Reliance assumed rather than assessed
  • No assessment of the effect on prudential obligations
CPS230-P48
Required Content of the Service Provider Management Policy

The service provider management policy must set out the entity approach to entering into, monitoring, substituting and exiting agreements with material service providers, its approach to managing the risks of those providers, and its approach to managing risks from any fourth parties that material service providers rely on to deliver a critical operation.

Artefacts an auditor will ask for
  • Policy clauses covering entry, monitoring, substitution and exit
  • Fourth party risk management approach
  • Evidence of fourth party identification for critical operations
Where this commonly fails
  • Fourth party risk not addressed
  • Policy covers onboarding but not substitution or exit

Third Party

CPS230-50
Formal Agreement Content for Material Arrangements

Every material arrangement must be covered by a formal legally binding agreement specifying the services and service levels, the rights, responsibilities and expectations of each party including asset ownership, data ownership and control, dispute resolution, audit access, liability and indemnity, provisions securing the entity legal and compliance obligations, notification of the provider reliance on other material service providers, provider liability for sub contractor failure, a force majeure provision, and termination rights.

Artefacts an auditor will ask for
  • Executed agreements for every material arrangement
  • Clause mapping against the required minimum content
  • Sub contractor notification and liability clauses
Where this commonly fails
  • Verbal or intra group arrangements with no formal agreement
  • Sub contracting and force majeure clauses absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA CPS 230 Operational Risk Management framework page.