APRA Prudential Standard CPS 230 is an operational risk and resilience standard for regulated financial entities and their service providers. It brings governance, business continuity, incident management, and third-party risk into one framework so organisations can show how critical operations stay within tolerance when disruption occurs.
Expanded Definition
CPS 230 is best understood as a resilience standard that forces operational risk, continuity planning, incident response, and third-party oversight into one supervisory lens. For regulated financial entities, its practical effect is to require evidence that critical operations can continue within tolerance even when systems, providers, or dependencies fail. That matters in NHI-heavy environments because service accounts, API keys, automation tokens, and agent credentials often sit inside the same operational chains CPS 230 is meant to protect. Guidance across vendors is still evolving, but the governance expectation is clear: dependency mapping, accountability, and recovery testing must extend beyond human users. The standard aligns well with NIST Cybersecurity Framework 2.0 because both treat resilience as an outcome, not just a policy statement.
The most common misapplication is treating CPS 230 as a pure continuity document, which occurs when organisations focus on recovery plans while leaving machine credentials, outsourced tooling, and critical automations outside the operational risk scope.
Examples and Use Cases
Implementing CPS 230 rigorously often introduces more testing, documentation, and vendor coordination, requiring organisations to weigh operational confidence against the cost of tighter control and slower change.
- A bank maps payment processing as a critical operation and verifies that the service accounts supporting settlement jobs can be rotated, recovered, and reissued without breaking tolerance objectives.
- A payments provider classifies a cloud logging service as a material third-party dependency and tests what happens if its API token is revoked during an incident window.
- An insurer includes CI/CD secrets in business continuity exercises so deployment pipelines do not fail during a failover event or infrastructure recovery.
- A superannuation fund aligns its control testing to the operational guidance in Ultimate Guide to NHIs to reduce blind spots in credential inventory and offboarding.
- A regulated firm uses incident simulations to check whether an automation agent can be safely disabled, reauthenticated, and monitored without interrupting critical workflows.
For resilience-oriented control mapping, NIST Cybersecurity Framework 2.0 is a useful external reference point, especially when translating tolerance objectives into measurable recovery actions.
Why It Matters in NHI Security
CPS 230 matters because NHI failures are rarely isolated identity issues. They often become operational failures: stale API keys interrupt payment runs, overprivileged service accounts expose sensitive workflows, and unmanaged third-party credentials make recovery uncertain. NHIMG research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, and only 5.7% have full visibility into their service accounts. Those conditions create a direct CPS 230 concern, since an entity cannot credibly prove resilience for operations it cannot fully see. The same research also shows that 92% of organisations expose NHIs to third parties, which makes supplier controls and recovery rights part of resilience governance rather than optional security hygiene, as detailed in the Ultimate Guide to NHIs.
CPS 230 also changes how incident teams think about identity. A secret leak, expired certificate, or broken automation path is no longer just an access problem if it can interrupt a critical operation or breach a tolerance threshold. Organisations typically encounter the full force of CPS 230 only after a supplier outage, credential compromise, or failed recovery drill, at which point the standard becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack surface, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.IM-01 | Recovery improvements and lessons learned are central to CPS 230 resilience expectations. |
| NIST Zero Trust (SP 800-207) | JP-1 | Zero trust requires verifying each access path, including service and machine identities. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Poor NHI inventory and lifecycle control undermines resilience and recovery readiness. |
| CSA MAESTRO | Agentic systems need governance over tool access, resilience, and failure containment. | |
| DORA | DORA and CPS 230 share operational resilience, third-party risk, and incident readiness goals. |
Test critical NHI-dependent processes, then update recovery plans and controls from incident findings.
Related resources from NHI Mgmt Group
- How should APRA-regulated organisations build CPS 230 compliance so operational risk, business continuity, and third-party risk do not stay in separate silos?
- Why does CPS 230 force boards and GRC teams to care about material service providers more directly than older outsourcing rules?
- Who is accountable when a material service provider affects a critical operation under CPS 230, the regulated entity or the provider?
- What breaks when remote access into CPS is treated like ordinary IT access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org