Skip to content

Evidence request lists

APRA CPS 234

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

APRA Notification

CPS234-35
APRA Notification of Material Incidents within 72 Hours

APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.

Artefacts an auditor will ask for
  • Notification records with awareness and submission timestamps
  • Materiality assessment criteria and decision records
  • Register of notifications made to other regulators
Where this commonly fails
  • Clock started at incident confirmation rather than awareness
  • Incidents notified to other regulators not passed to APRA
CPS234-36
APRA Notification of Material Control Weakness within 10 Business Days

APRA must be notified as soon as possible and no later than 10 business days after the entity becomes aware of a material information security control weakness it expects it will not be able to remediate in a timely way.

Artefacts an auditor will ask for
  • Notification records with awareness dates
  • Weakness register with materiality and remediation feasibility assessments
  • Evidence linking testing and audit findings to notification decisions
Where this commonly fails
  • No process connecting the weakness register to the notification duty
  • Materiality threshold undocumented

Implementation of Controls

CPS234-21
Implementation of Information Security Controls

Controls protecting information assets must be implemented in a timely way and sized to the vulnerabilities and threats, the criticality and sensitivity of the assets, the asset life cycle stage and the potential consequences of an incident.

Artefacts an auditor will ask for
  • Control set mapped to classified assets
  • Evidence of timeliness of control implementation
  • Life cycle coverage from design through to disposal
Where this commonly fails
  • Controls applied uniformly with no reference to classification
  • Decommissioning and disposal stages uncontrolled
CPS234-30
Detection and Response Mechanisms

The entity must have robust mechanisms to detect information security incidents and respond to them in a timely way.

Artefacts an auditor will ask for
  • Detection tooling and monitoring coverage evidence
  • Incident records showing detection and response times
  • Defined response timeliness expectations
Where this commonly fails
  • Detection coverage gaps across classified assets
  • No measurement of detection or response timeliness

Incident Management

CPS234-32
Annual Review and Testing of Response Plans

Information security response plans must be reviewed and tested annually to confirm they remain effective and fit for purpose.

Artefacts an auditor will ask for
  • Annual review and test records for response plans
  • Exercise reports and resulting plan updates
  • Evidence of fitness for purpose conclusions
Where this commonly fails
  • Plans reviewed but never exercised
  • Test findings not fed back into the plans
CPS234-P24
Information Security Response Plans

The entity must maintain response plans covering the information security incidents it considers could plausibly occur.

Artefacts an auditor will ask for
  • Documented response plans
  • Plausible incident scenario analysis supporting plan coverage
  • Version and approval history
Where this commonly fails
  • Single generic plan with no scenario basis
  • Plausible scenarios identified but not planned for
CPS234-P25
Response Plan Content and Escalation Mechanisms

Response plans must set out the mechanisms for managing every stage of an incident from detection through to post incident review, and for escalating and reporting incidents to the Board and to those responsible for incident management and oversight.

Artefacts an auditor will ask for
  • Plan sections covering each incident stage
  • Escalation matrix with thresholds and recipients
  • Post incident review records
Where this commonly fails
  • Plans stop at containment with no post incident review
  • Escalation path to the Board undefined

Information Asset Identification and Classification

CPS234-20
Information Asset Classification

Information assets, including those held by related parties and third parties, must be classified by criticality and sensitivity reflecting the potential impact of an incident on the entity or on depositors, policyholders, beneficiaries and other customers.

Artefacts an auditor will ask for
  • Information asset register with criticality and sensitivity ratings
  • Classification scheme and rating rationale
  • Coverage evidence for third party held assets
Where this commonly fails
  • Register covers internally hosted assets only
  • Classification not tied to impact on customers or the entity

Information Security Capability

CPS234-15
Information Security Capability

The entity must maintain an information security capability sized to the threats facing its information assets and sufficient to keep the entity operating soundly.

Artefacts an auditor will ask for
  • Capability assessment covering resources, skills and controls
  • Resourcing and budget records for the security function
  • Skills matrix for security personnel
Where this commonly fails
  • Capability asserted but never assessed
  • No link between assessed threat level and resourcing
CPS234-P17
Active Maintenance of Capability Against Change

The entity must actively maintain its information security capability as vulnerabilities and threats change, including changes driven by its information assets or business environment.

Artefacts an auditor will ask for
  • Threat and vulnerability monitoring inputs
  • Records of capability adjustments following change
  • Change triggers linking asset or environment change to capability review
Where this commonly fails
  • Capability set once at implementation and not revisited
  • No trigger connecting business change to capability review

Internal Audit

CPS234-25
Internal Audit Review of Information Security Controls

Internal audit activities must include review of the design and operating effectiveness of information security controls, including those maintained by related parties and third parties.

Artefacts an auditor will ask for
  • Internal audit plan covering information security
  • Audit reports on control design and operating effectiveness
  • Scope evidence covering third party maintained controls
Where this commonly fails
  • Audit covers design only and not operating effectiveness
  • Third party controls out of audit scope
CPS234-27
Internal Audit Assessment of Third Party Control Assurance

Internal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.

Artefacts an auditor will ask for
  • Reliance decisions recorded with supporting assessment
  • Assessment of the third party assurance reports relied upon
  • Materiality determination for each reliance
Where this commonly fails
  • Third party assurance accepted without assessment
  • No record of why reliance was considered appropriate
CPS234-P33
Skill of Personnel Providing Control Assurance

The entity must ensure that information security control assurance is provided by personnel who are appropriately skilled in providing that assurance.

Artefacts an auditor will ask for
  • Qualifications and experience records for assurance providers
  • Training and competency evidence
  • Co sourcing or specialist engagement records where in house skill is absent
Where this commonly fails
  • General auditors assuring specialist security controls
  • Competency assumed and never evidenced

Policy Framework

CPS234-19
Information Security Policy Framework

The entity must maintain an information security policy framework proportionate to its exposure to vulnerabilities and threats.

Artefacts an auditor will ask for
  • Approved policy, standard, guideline and procedure set
  • Approval and version history
  • Mapping of policy coverage to assessed exposures
Where this commonly fails
  • Policy set not refreshed against changing exposures
  • Standards and procedures missing beneath the top level policy
CPS234-P19
Policy Direction to All Responsible Parties

The information security policy framework must give direction on the responsibilities of every party obliged to maintain information security, including staff, contractors, consultants, related parties, third parties and customers.

Artefacts an auditor will ask for
  • Policy clauses addressed to each party type
  • Acknowledgement records for staff and contractors
  • Contractual or terms of use flow down to third parties and customers
Where this commonly fails
  • Policy addressed to employees only
  • No evidence the policy reached third parties or customers

Roles and Responsibilities

CPS234-13
Board Responsibility for Information Security

The Board carries ultimate responsibility for the entity information security and must ensure it is maintained in proportion to the threats facing the information assets.

Artefacts an auditor will ask for
  • Board charter or terms of reference assigning information security responsibility
  • Board minutes evidencing oversight of information security
  • Board reporting pack on the threat environment
Where this commonly fails
  • Responsibility delegated to management with no Board level accountability
  • No Board record of considering the threat environment
CPS234-14
Definition of Information Security Roles and Responsibilities

Information security roles and responsibilities must be clearly defined for the Board, senior management, governing bodies and individuals holding decision making, approval, oversight or operational duties.

Artefacts an auditor will ask for
  • Documented roles and responsibilities matrix
  • Committee and working group terms of reference
  • Position descriptions naming information security duties
Where this commonly fails
  • Roles defined for IT only and not for the Board or governing bodies
  • Matrix exists but is not approved or maintained

Testing Control Effectiveness

CPS234-22
Systematic Control Testing Program

Control effectiveness must be tested through a systematic program whose nature and frequency reflect the rate of change in vulnerabilities and threats, asset criticality and sensitivity, incident consequences, exposure to environments where the entity cannot enforce its policies, and the materiality and frequency of change to information assets.

Artefacts an auditor will ask for
  • Documented testing program and schedule
  • Test results and coverage records
  • Rationale linking test frequency to the five listed factors
Where this commonly fails
  • Ad hoc testing with no program
  • Untrusted environments excluded from scope
CPS234-28
Escalation of Unremediated Testing Deficiencies

Testing results that identify control deficiencies which cannot be remediated in a timely way must be escalated and reported to the Board or senior management.

Artefacts an auditor will ask for
  • Escalation records for unremediated deficiencies
  • Board or senior management reporting packs
  • Remediation tracker with timeliness assessment
Where this commonly fails
  • Deficiencies tracked operationally but never escalated
  • No definition of what timely remediation means
CPS234-P30
Independence and Skill of Testing Personnel

Testing must be carried out by specialists who are appropriately skilled and functionally independent of the activity being tested.

Artefacts an auditor will ask for
  • Tester qualifications and credentials
  • Independence declarations or engagement letters
  • Reporting lines demonstrating functional independence
Where this commonly fails
  • Controls tested by the team that operates them
  • Skill of testers never evidenced
CPS234-P31
Annual Review of Testing Program Sufficiency

The sufficiency of the testing program must be reviewed at least annually, and also whenever there is a material change to information assets or the business environment.

Artefacts an auditor will ask for
  • Annual sufficiency review records
  • Change triggered reviews with the triggering event recorded
  • Program amendments arising from review
Where this commonly fails
  • Testing performed annually but the program itself never reviewed
  • No trigger for review on material change

Third Party Arrangements

CPS234-16
Assessment of Related Party and Third Party Capability

Where a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.

Artefacts an auditor will ask for
  • Third party and related party security capability assessments
  • Register of parties managing information assets
  • Consequence rating driving assessment depth
Where this commonly fails
  • Assessment limited to outsourced material business activities
  • Related parties excluded from assessment
CPS234-P22
Evaluation of Third Party Control Design

Where a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.

Artefacts an auditor will ask for
  • Design evaluations of third party control sets
  • Assurance reports reviewed with entity conclusions recorded
  • Scope evidence covering all parties managing information assets
Where this commonly fails
  • Reliance on a certificate with no design evaluation
  • Evaluation limited to outsourcing arrangements
CPS234-P28
Assessment of Reliance on Third Party Control Testing

Where the entity relies on a related party or third party testing of controls over its information assets, it must assess whether the nature and frequency of that testing meets the same factors that govern its own testing program.

Artefacts an auditor will ask for
  • Assessment of third party testing scope and frequency
  • Register of testing reliance decisions
  • Comparison against the entity own testing factors
Where this commonly fails
  • Third party test reports filed without assessment
  • No record of which controls the entity relies on the third party to test
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the APRA CPS 234 framework page.