Operational resilience is no longer a project — it's a supervised obligation. Here's where early reviews are focusing: tolerance levels that were set top-down, service provider registers missing fourth parties, and testing that never leaves the tabletop.
From 1 July 2025, every APRA-regulated bank, insurer and super fund must operate under CPS 230. The transition period is over for new contracts, and supervisors have signalled that the first review cycle will concentrate on evidence, not policy libraries.
Gap one: tolerance levels set without business input. Boards approved maximum disruption times, but the process owners who run critical operations often can't explain how the number was derived.
Gap two: the material service provider register stops at contract counterparties. CPS 230 expects entities to understand concentration and fourth-party exposure — especially where multiple providers ride on the same cloud region.
Gap three: testing programs that never escalate beyond tabletop. APRA's guidance expects severe-but-plausible scenarios to be exercised, including failover of critical operations.
Gap four: unclear interaction with CPS 234. Information-security incidents are operational-risk events; entities need a single taxonomy so the same event doesn't appear three ways in board reporting.
Gap five: reliance on hope for the 2026 legacy-contract deadline. Pre-existing arrangements get relief only until 1 July 2026 — renegotiation pipelines should already be sequenced.
Disclaimer
General information only — not legal, financial or professional advice. Verify obligations against the current instruments and your entity's circumstances.