Back to Blog
Insights11 min read

How to Prepare for a CPS 234 Audit in Australia

A

Alexander Sverdlov

Security Analyst

7/20/2026
How to Prepare for a CPS 234 Audit in Australia

If you are a regulated entity in Australia, a CPS 234 assessment is not something you pass by tidying up a few policies the week before the auditor arrives. I have run more than 200 security assessments across 14 countries since 2013, and prudential-style reviews such as CPS 234 have a specific character: the auditor is testing whether your information security capability actually matches the threats you face, and whether your board can prove it. Most failures I see are not exotic. They are missing evidence, controls that exist on paper but were never tested, and third parties nobody could account for.

This guide walks through what CPS 234 actually requires, how APRA-regulated entities should prepare, and where preparation quietly goes wrong. No hype, no invented case studies. Just the work that gets you through the assessment and, more importantly, leaves you genuinely more secure afterward.

What CPS 234 Actually Requires

CPS 234, the APRA Prudential Standard on Information Security, has applied to APRA-regulated entities since 1 July 2019. That population includes authorised deposit-taking institutions (banks, credit unions, building societies), general and life insurers, private health insurers, and registrable superannuation entity licensees. If APRA regulates you, CPS 234 applies, and it also reaches the information assets managed by your related parties and third parties.

The standard is principles-based rather than a checklist, which is exactly why it trips people up. At its core it asks you to demonstrate a handful of things:

  • Clear roles and responsibilities. The board is ultimately accountable for information security. Senior management, governing bodies, and named individuals must have defined responsibilities, and you have to be able to show it.

  • Information security capability commensurate with your threats. Capability must scale to the size, nature, and vulnerabilities of your information assets, and to the sophistication of the threats against them. A small super fund and a major bank are held to the same principle at different scales.

  • A defined information security policy framework. Documented, maintained, and actually followed.

  • Classification and protection of information assets, including those managed by third parties, according to criticality and sensitivity.

  • Systematic testing and assurance. Controls must be tested for effectiveness through a systematic programme, with the frequency and scope driven by the rate of change and the materiality of the asset. Testing once and filing the report is not a programme.

  • Timely notification to APRA. You must notify APRA within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material information security control weakness you cannot remediate in time.

The companion Prudential Practice Guide CPG 234 fleshes out APRA's expectations. Read it alongside the standard, because it signals what "good" looks like in the assessor's eyes. Worth noting too: CPS 230 Operational Risk Management came into force on 1 July 2025 and overlaps with CPS 234 on third-party and resilience themes, so treat them as a connected programme rather than two silos.

Step 1: Establish an Honest Baseline With a Gap Assessment

Every credible preparation starts by measuring reality against the standard, control by control. The goal is not to produce a green dashboard. It is to find the gaps before the auditor does, while you still control the narrative and the timeline.

A useful gap assessment covers:

  • A current inventory of information assets, classified by criticality and sensitivity, including data and systems held by third parties.

  • Each CPS 234 requirement mapped to the control, the owner, and the evidence that proves it operates.

  • A clear rating of where you comply, partially comply, or do not comply, with the residual risk stated in plain language.

  • A remediation roadmap with owners and dates, prioritised by risk rather than by ease.

Technical scanning tools have their place here for finding unpatched systems, weak configurations, and exposed services, but a scanner does not assess governance, third-party assurance, or evidence quality. Those are judgement calls. If you want an independent read before APRA or your external auditor forms one, an independent IT security audit against the standard is the most efficient way to get it. Pair it with a vulnerability assessment so the technical baseline is real, not assumed.

Step 2: Make Governance Real, Not Decorative

CPS 234 puts the board on the hook, and assessors probe this hard. It is not enough to have a policy that says the board is accountable. You need to show the board received meaningful reporting, asked questions, and made decisions about information security risk.

Concretely, be able to produce:

  • Board and committee minutes that reference information security risk, incidents, and control testing results, not just a status colour on a slide.

  • A documented statement of who owns what: board, risk committee, senior management, the security function, and asset owners.

  • A stated risk appetite for information security that connects to actual control decisions.

  • Evidence that roles are resourced. A single overloaded IT manager nominally responsible for everything is a finding waiting to happen.

If your organisation does not have security leadership at the right level, this is where a virtual CISO earns its keep. A part-time but genuinely senior security leader can own the framework, brief the board in language it understands, and stand in front of the auditor with authority. For smaller regulated entities that cannot justify a full-time hire, a part-time CISO arrangement is often the difference between a governance narrative that holds up and one that collapses under a second question.

Step 3: Implement and Document Controls That Match Your Risk

CPS 234 expects controls to be commensurate with the criticality and sensitivity of the assets they protect. There is no fixed control list, but assessors expect to see the fundamentals done well and documented:

  • Identity and access. Multi-factor authentication on remote access, administrative accounts, and access to sensitive systems. Least-privilege access reviewed on a defined cycle. Joiner, mover, and leaver processes that actually run.

  • Data protection. Encryption of sensitive data in transit and at rest, with key management you can explain.

  • Vulnerability and patch management. A defined process with timeframes tied to severity, and records showing it operates.

  • Endpoint and network defence. Detection and response on endpoints, segmentation of critical systems, and logging that feeds somewhere a human actually looks.

  • Secure configuration and change management, so the environment does not drift out of a compliant state between audits.

Cloud is the recurring blind spot. Many entities assume a hyperscaler's certifications cover them, but CPS 234 makes you responsible for the information assets regardless of who runs the infrastructure. You still own configuration, identity, data classification, and monitoring in the shared-responsibility model. If a material share of your regulated workloads runs in AWS or Azure, a focused cloud security review closes the gaps that generic scanners never see. And to prove your controls actually resist attack rather than merely exist, commission a penetration test scoped to your material systems before the auditor asks whether one was done.

Step 4: Build Incident Response That Meets the 72-Hour Clock

The notification obligations are specific and time-bound, and they are a common source of grief. You must notify APRA within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material control weakness you cannot remediate promptly. To meet those clocks under pressure, the machinery has to be built in advance:

  • A documented incident response plan with defined roles, severity criteria, and a decision path for materiality.

  • A clear trigger and owner for the APRA notification itself, so the 72 hours is not lost debating who sends it.

  • Logging and monitoring sufficient to detect incidents in the first place. You cannot notify what you never saw.

  • Tabletop exercises that test the plan and the notification decision, with the results documented as evidence of your testing programme.

The materiality judgement is where teams freeze. Decide in advance, with legal and risk input, what "material" means for your organisation, and rehearse the call. An auditor who sees a well-run exercise and a clear decision framework treats notification readiness very differently from one who sees an untested document.

Step 5: Get Your Third Parties and Evidence in Order

CPS 234 explicitly extends to information assets managed by related parties and third parties. This is where entities lose the most points, because ownership of a vendor relationship rarely equals ownership of that vendor's security assurance. Before the assessment:

  • Build a register of third parties that touch your material information assets, with the classification of what they handle.

  • Collect current assurance for each: independent audit reports, certifications, or your own review. Confirm the scope covers the service you actually use.

  • Check that contracts carry security obligations and, crucially, incident notification clauses that let you meet your own 72-hour clock.

  • Document how you assess and monitor these parties over time, not just at onboarding.

On evidence generally: assessors trust what you can show, not what you assert. Assemble a single evidence pack mapped to each requirement, with dates and owners. If a control operates but leaves no trace, treat it as a gap and fix the record-keeping. Fintech entities under APRA's remit often carry the heaviest third-party footprint, and pairing readiness work with a fintech-focused virtual CISO keeps vendor assurance from becoming the finding that sinks the assessment.

CPS 234 Preparation at a Glance

Focus area

What the assessor wants to see

Common failure

Governance

Board engagement in minutes; defined, resourced roles

Accountability on paper, no evidence of decisions

Asset classification

Inventory by criticality, including third-party assets

Shadow systems and unclassified data

Controls

MFA, encryption, patching, monitoring, with records

Controls exist but were never tested

Testing and assurance

A systematic programme scaled to risk

One-off tests with no cadence

Incident notification

Plan, materiality criteria, rehearsed 72-hour path

Untested plan, unclear decision owner

Third parties

Register, current assurance, contract clauses

No visibility into vendor security

A Realistic Timeline

For most regulated entities, meaningful preparation takes three to six months, sometimes longer where remediation is significant. Compress that if you must, but understand the trade: a rushed programme produces a clean checklist and a shallow evidence base, and assessors are good at telling the difference. A workable sequence is roughly a month for the gap assessment and asset inventory, two to three months for remediation and control testing, and a final stretch assembling evidence and running the incident-response exercise. Start from the notification obligations and work backward, because those are the deadlines you cannot negotiate once an incident is live. If your internal team is stretched, an experienced cyber security consultant can carry the programme management while your staff keep the business running.

Frequently Asked Questions

Who has to comply with CPS 234?

All APRA-regulated entities: authorised deposit-taking institutions, general and life insurers, private health insurers, and registrable superannuation entity licensees. The obligations also extend to information assets managed on your behalf by related parties and third parties.

How quickly must we notify APRA of an incident?

Within 72 hours of becoming aware of a material information security incident. Separately, you must notify APRA within 10 business days of identifying a material information security control weakness that you expect will not be remediated in a timely manner. Decide your materiality criteria in advance so the clock does not run out during a debate.

Does CPS 234 tell us exactly which controls to deploy?

No. It is principles-based. It requires controls commensurate with the threats to and criticality of your information assets, then requires you to test their effectiveness systematically. The companion guide CPG 234 describes what APRA considers sound practice and is the best signal of expectations.

We run in the cloud. Does the provider handle CPS 234 for us?

No. Under the shared-responsibility model you remain accountable for the information assets, your configuration, identity, data classification, and monitoring. A provider certification covers the provider's layer, not your use of it. Cloud environments need their own review against the standard.

Do we need an external consultant, or can we prepare internally?

Many entities prepare internally with sound results, especially where they already have security leadership. External help is most valuable for an independent gap assessment, for stress-testing your evidence the way an auditor will, and for supplying senior security leadership if you lack it. The point of outside help is objectivity, not a rubber stamp.

How often do we need to test controls?

There is no single fixed frequency. Testing cadence should reflect the rate of change in your environment, the materiality of the asset, and the results of prior tests. Critical, fast-changing systems warrant more frequent testing than stable, low-criticality ones. The key is a documented, systematic programme rather than ad hoc checks.

Prepare Once, Prepare Properly

The entities that sail through a CPS 234 assessment are not the ones with the glossiest documentation. They are the ones where the board genuinely engages, controls are tested on a real cadence, third parties are accounted for, and every claim is backed by evidence someone can produce on request. Do that work and the assessment becomes a confirmation rather than a scramble.

If you want an independent view of where you stand before your external auditor forms one, Atlant Security runs gap assessments and readiness reviews against CPS 234 and supplies senior security leadership where you need it. Get in touch to scope a realistic path to your assessment.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

CPS 234 Audit Prep: A Practical Guide (Australia) | Atlant Security