Join our Newsletter — 33% off our NHI Course

CPS 230

APRA Prudential Standard CPS 230 is an operational risk and resilience standard for regulated financial entities and their service providers. It brings governance, business continuity, incident management, and third-party risk into one framework so organisations can show how critical operations stay within tolerance when disruption occurs.

Expanded Definition

CPS 230 is best understood as a resilience standard that forces operational risk, continuity planning, incident response, and third-party oversight into one supervisory lens. For regulated financial entities, its practical effect is to require evidence that critical operations can continue within tolerance even when systems, providers, or dependencies fail. That matters in NHI-heavy environments because service accounts, API keys, automation tokens, and agent credentials often sit inside the same operational chains CPS 230 is meant to protect. Guidance across vendors is still evolving, but the governance expectation is clear: dependency mapping, accountability, and recovery testing must extend beyond human users. The standard aligns well with NIST Cybersecurity Framework 2.0 because both treat resilience as an outcome, not just a policy statement.

The most common misapplication is treating CPS 230 as a pure continuity document, which occurs when organisations focus on recovery plans while leaving machine credentials, outsourced tooling, and critical automations outside the operational risk scope.

Examples and Use Cases

Implementing CPS 230 rigorously often introduces more testing, documentation, and vendor coordination, requiring organisations to weigh operational confidence against the cost of tighter control and slower change.

  • A bank maps payment processing as a critical operation and verifies that the service accounts supporting settlement jobs can be rotated, recovered, and reissued without breaking tolerance objectives.
  • A payments provider classifies a cloud logging service as a material third-party dependency and tests what happens if its API token is revoked during an incident window.
  • An insurer includes CI/CD secrets in business continuity exercises so deployment pipelines do not fail during a failover event or infrastructure recovery.
  • A superannuation fund aligns its control testing to the operational guidance in Ultimate Guide to NHIs to reduce blind spots in credential inventory and offboarding.
  • A regulated firm uses incident simulations to check whether an automation agent can be safely disabled, reauthenticated, and monitored without interrupting critical workflows.

For resilience-oriented control mapping, NIST Cybersecurity Framework 2.0 is a useful external reference point, especially when translating tolerance objectives into measurable recovery actions.

Why It Matters in NHI Security

CPS 230 matters because NHI failures are rarely isolated identity issues. They often become operational failures: stale API keys interrupt payment runs, overprivileged service accounts expose sensitive workflows, and unmanaged third-party credentials make recovery uncertain. NHIMG research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, and only 5.7% have full visibility into their service accounts. Those conditions create a direct CPS 230 concern, since an entity cannot credibly prove resilience for operations it cannot fully see. The same research also shows that 92% of organisations expose NHIs to third parties, which makes supplier controls and recovery rights part of resilience governance rather than optional security hygiene, as detailed in the Ultimate Guide to NHIs.

CPS 230 also changes how incident teams think about identity. A secret leak, expired certificate, or broken automation path is no longer just an access problem if it can interrupt a critical operation or breach a tolerance threshold. Organisations typically encounter the full force of CPS 230 only after a supplier outage, credential compromise, or failed recovery drill, at which point the standard becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack surface, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, and DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 RC.IM-01 Recovery improvements and lessons learned are central to CPS 230 resilience expectations.
NIST Zero Trust (SP 800-207) JP-1 Zero trust requires verifying each access path, including service and machine identities.
OWASP Non-Human Identity Top 10 NHI-01 Poor NHI inventory and lifecycle control undermines resilience and recovery readiness.
CSA MAESTRO Agentic systems need governance over tool access, resilience, and failure containment.
DORA DORA and CPS 230 share operational resilience, third-party risk, and incident readiness goals.

Test critical NHI-dependent processes, then update recovery plans and controls from incident findings.