Back to Blog
Insights10 min read

How to Prepare for a CPS 234 Audit: Your Path to Profit and Peace of Mind

A

Alexander Sverdlov

Security Analyst

7/20/2026
How to Prepare for a CPS 234 Audit: Your Path to Profit and Peace of Mind

CPS 234 is the prudential standard that most Australian financial firms underestimate right up until an assessor asks for evidence. I have run more than 200 security assessments across 14 countries since 2013, and the pattern with APRA-regulated entities is almost always the same: the policies look tidy, but the evidence behind them is thin, stale, or missing entirely. A CPS 234 audit is not a test of whether you have documents. It is a test of whether your information security capability actually works and whether you can prove it.

This guide walks through what CPS 234 requires, how APRA assesses it, and the exact preparation steps that separate a clean review from a painful one. No sales theatre, no invented case studies - just what I have seen work when a firm has to stand in front of an assessor or an APRA tripartite review.

What CPS 234 Actually Requires

CPS 234 (Information Security) took effect on 1 July 2019 and applies to all APRA-regulated entities: authorised deposit-taking institutions, general, life and private health insurers, and registrable superannuation entity licensees. Its aim is narrow and blunt - to ensure regulated entities can maintain information security to withstand attacks and other incidents.

The standard is short, but it carries five obligations that every assessment circles back to:

  • Roles and responsibilities. The Board is ultimately accountable for information security. Roles for the Board, senior management, governing bodies and individuals must be clearly defined, not implied.
  • Information security capability. Your capability must be commensurate with the size and extent of threats to your information assets, and it must enable continued sound operation. This scales with your risk, so a large ADI and a small super fund are held to different practical bars.
  • Policy framework. You need an information security policy framework commensurate with your exposures and vulnerabilities.
  • Controls and testing. Controls must protect information assets in line with their criticality and sensitivity, and you must test the effectiveness of those controls through a systematic testing program. Testing frequency has to reflect the rate of change of the assets and the threat environment.
  • Incident notification. You must notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after becoming aware of a material information security control weakness that you cannot remediate in a timely manner.

CPG 234, the accompanying Prudential Practice Guide, is where APRA sets out its expectations in detail. If you only read one supporting document before an assessment, read that one. It is effectively the checklist assessors reason from.

How CPS 234 Reviews Are Assessed

Most firms encounter CPS 234 assurance in one of three ways: an internal audit, an independent external review, or an APRA tripartite review where APRA commissions an independent expert to assess a specific area. Whatever the trigger, assessors are testing evidence against the standard, not opinions.

The single biggest reason firms struggle is the gap between a stated control and demonstrable operation. Saying multi-factor authentication is enforced means nothing without a configuration export, a coverage report, and a sample of access logs. The assessment mindset is straightforward: show me the control, show me it is running, show me you test it, show me what happens when it fails.

A Practical CPS 234 Preparation Plan

Here is the sequence I use when preparing a financial firm for CPS 234 assurance. It works whether you have three months or a full year of runway, though earlier is always cheaper than later.

1. Build and Maintain an Information Asset Register

You cannot protect or classify what you have not inventoried. CPS 234 hinges on information assets, so the register is the foundation everything else hangs off. Capture systems, applications, data stores, and the third parties that manage information assets on your behalf. For each, record criticality, sensitivity, the business owner, and who is accountable for its security.

Assessors will sample this register. If a critical customer database is missing, or if ownership is unassigned, that single gap undermines confidence in everything downstream. Keep it current, not a point-in-time artefact created the week before review.

2. Define Roles Clearly, Including at Board Level

CPS 234 places accountability with the Board. That does not mean directors run security, but it does mean they must understand their obligations and receive information good enough to discharge them. Document the decision rights and responsibilities of the Board, executive management, and operational security roles. Then make sure the Board minutes actually show information security being discussed, challenged, and decided on.

A fractional or virtual CISO is a common and legitimate way for smaller regulated entities to hold the security leadership role without a full-time executive hire. What matters to an assessor is that the accountability is real, named, and evidenced.

3. Run a Gap Assessment Against CPS 234 and CPG 234

Before anyone external looks at you, look at yourself honestly. Map each CPS 234 requirement to your current controls and rate the evidence you can produce today. This is not a maturity vanity exercise. It is about surfacing the items where you have a policy but no proof, or a control but no testing record. A structured IT security audit against the standard gives you a prioritised remediation list months before an assessor arrives.

4. Assess Your Third Parties

CPS 234 explicitly covers information assets managed by related parties and third parties. Cloud providers, SaaS platforms, managed service providers, and outsourced processors all fall in scope. You are expected to evaluate their information security capability and to have assurance that it meets your requirements. Collect their independent assurance reports, review the controls relevant to your data, and document the residual risk you are accepting. Do not assume a provider's certification covers your specific configuration - shared responsibility means the parts you configure are yours to prove.

5. Implement and Evidence Core Controls

The technical controls that come up in every financial-sector review are consistent. None of them are exotic:

  • Multi-factor authentication on all remote access, administrative access, and privileged accounts.
  • Encryption of sensitive data at rest and in transit.
  • A disciplined patch and vulnerability management process with defined timelines by severity.
  • Privileged access management with least-privilege and regular access recertification.
  • Endpoint detection and response, and centralised logging.
  • Network segmentation between corporate, production, and sensitive environments.

The difference between a firm that sails through and one that stalls is rarely the presence of these controls. It is the coverage and the evidence. If MFA is on the VPN but not on your cloud admin console, that is the gap that gets written up. A vulnerability assessment and periodic penetration testing give you independent evidence that controls hold under real conditions, which is exactly what the systematic testing obligation asks for.

6. Stand Up a Systematic Control Testing Program

CPS 234 does not just ask you to have controls. It asks you to test their effectiveness on a schedule that matches how fast your assets and threats change. Build a testing calendar: vulnerability scans on a defined cadence, penetration tests at least annually and after major change, access reviews quarterly, backup restoration tests, and control self-assessments. Keep the results, the findings, and the remediation tracking. The testing program is one of the most commonly under-evidenced parts of the standard.

7. Prepare Incident Response and the Notification Path

The 72-hour notification clock and the 10-business-day control-weakness notification are hard obligations. Your incident response plan must include the trigger for materiality, who decides, and how APRA is notified within the window. Run a tabletop exercise against a realistic scenario - ransomware, a cloud misconfiguration exposure, a third-party breach - and time your decision path. If nobody in the room knows who signs off the APRA notification, you have found a gap that matters far more than a policy typo.

8. Assemble Audit-Ready Evidence

Finally, organise your evidence the way an assessor will ask for it: by control, with the artefact attached. Configuration exports, log samples, test reports, risk acceptances, Board papers, and third-party assurance letters. When evidence is scattered across inboxes and shared drives, reviews drag and confidence drops. When it is indexed against the standard, the review moves quickly and the finding count falls.

CPS 234 Readiness Checklist

Requirement areaWhat assessors look forCommon gap
Asset registerCurrent inventory with owners, criticality, sensitivityMissing systems, unassigned ownership
Roles and Board accountabilityDefined responsibilities, Board oversight in minutesSecurity absent from Board agenda
Policy frameworkPolicies mapped to real exposuresGeneric templates with no evidence of use
ControlsMFA, encryption, patching, privileged access, loggingPartial coverage, especially in cloud admin
Testing programScheduled, systematic, documented resultsAd hoc testing, no remediation tracking
Third partiesAssurance over information assets they manageReliance on certification without review
Incident notification72-hour path, materiality decision, tested planUntested plan, unclear decision owner

How CPS 234 Connects to CPS 230

If you are preparing for CPS 234, keep CPS 230 (Operational Risk Management) in view. It came into effect on 1 July 2025 and broadens the lens to operational resilience, critical operations, and material service provider management. The information asset register, third-party assurance, and incident processes you build for CPS 234 are the same foundations CPS 230 draws on. Doing this work once, properly, serves both standards rather than duplicating effort.

Where Firms Waste Time

Two failure modes account for most wasted CPS 234 preparation budget. The first is polishing documents while ignoring evidence. A beautiful policy set with no operating records will not survive a review. The second is treating the audit as a one-off event rather than a steady-state capability. CPS 234 assumes continuous operation, so a firm that scrambles annually and lets controls drift in between will keep re-earning the same findings. Build the register, the testing calendar, and the evidence discipline into business as usual, and each subsequent review gets cheaper and calmer.

Getting Help

If you want an independent read on where you stand before an assessor gives you one, that is exactly the kind of engagement we run. We assess your posture against CPS 234 and CPG 234, produce a prioritised remediation roadmap, and can hold the security leadership role on a fractional basis through our virtual CISO service if you need it. For a scoped conversation about your situation, get in touch. Financial-sector firms often start with a focused IT security audit to establish the baseline.

Frequently Asked Questions

How long does it take to prepare for a CPS 234 audit?

It depends entirely on your starting point. A firm with a maintained asset register, tested controls, and organised evidence can be review-ready in a few weeks. A firm starting from generic policies and no testing records should plan on several months, because building genuine evidence takes time that cannot be compressed the week before an assessor arrives.

Who does CPS 234 apply to?

All APRA-regulated entities, including authorised deposit-taking institutions, general, life and private health insurers, and registrable superannuation entity licensees. The practical bar scales with the size and threat exposure of the entity, so requirements are proportionate rather than identical for every firm.

What has to be reported to APRA and how fast?

You must notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after becoming aware of a material information security control weakness that cannot be remediated in a timely manner. Your incident response plan should make the materiality decision and the notification path explicit.

Do we need a full-time CISO to satisfy CPS 234?

No. CPS 234 requires clearly defined security roles and Board accountability, not a specific job title or headcount. Many smaller regulated entities meet the leadership requirement with a fractional or virtual CISO, provided the accountability is genuine, named, and evidenced in governance records.

How does CPS 234 treat cloud providers and other third parties?

Information assets managed by third parties are in scope. You are expected to assess the provider's information security capability, obtain assurance relevant to your data, and document any residual risk you accept. A provider's certification does not automatically cover the parts you configure under the shared responsibility model, so those remain your evidence to produce.

How often should controls be tested under CPS 234?

The standard ties testing frequency to the rate of change of your information assets and the threat environment, so there is no single number. In practice, financial firms run continuous or frequent vulnerability scanning, at least annual penetration testing and after major changes, quarterly access reviews, and periodic backup restoration and incident exercises, all documented with remediation tracking.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.