What CPS 230 requires
CPS 230 requires APRA-regulated entities to manage operational risk end to end, maintain critical operations within tolerance levels through severe disruption, and manage the risks of material service providers. It applies across banking, insurance and superannuation.
Where AI fits
- Critical operations. If an AI system supports claims, lending decisions, customer service or fraud detection, its failure is an operational risk event.
- Service providers. Model providers, AI platforms and their subprocessors may be material service providers, with due diligence, contract and monitoring obligations.
- Business continuity. What happens when the model degrades, the API is unavailable or the provider changes terms? Plans need a fallback.
- Change management. Model updates can change behaviour without any code change on your side.
Practical controls
- Map each AI system to the business operations it supports.
- Identify AI service providers and assess whether they are material.
- Set tolerance levels and fallback procedures for AI-dependent processes.
- Monitor model performance and provider changes continuously.
- Test AI systems for security risks such as prompt injection and data leakage.
- Report AI risk to the board within the operational risk framework.
ISO/IEC 42001 can provide the management system that makes these controls repeatable, and Australia's privacy changes add automated decision-making disclosure requirements from 10 December 2026.
