Back to Blog
Insights9 min read

What is the Cost of CPS 234 Audits for Financial Institutions

A

Alexander Sverdlov

Security Analyst

7/20/2026
What is the Cost of CPS 234 Audits for Financial Institutions

If you run an APRA-regulated bank, insurer, or superannuation fund in Australia, CPS 234 is not optional and neither is being able to demonstrate that you actually meet it. The question I hear most from CEOs and CTOs is deceptively simple: what does a CPS 234 audit cost? The honest answer is that the audit itself is usually the smallest line on the invoice. What drives the total is the state of your controls before the auditor walks in, the complexity of your environment, and how much remediation you have to do to close the gaps.

I have run security assessments and readiness engagements for regulated financial firms across 14 countries since 2013, and the pattern is consistent: organisations that treat CPS 234 as a one-off compliance sprint pay far more than those that build the underlying controls properly the first time. This guide breaks down where the money actually goes, what a realistic budget looks like by institution size, and how to keep the cost under control without cutting corners that APRA will notice.

What CPS 234 Actually Requires

CPS 234 is APRA's Prudential Standard on information security. It applies to all APRA-regulated entities and, importantly, extends to information assets managed by third parties and related parties. The standard is principles-based rather than a checklist, which is precisely why costs vary so widely. At a high level it requires you to:

  • Clearly define information security roles and responsibilities, including at board and senior management level.
  • Maintain an information security capability commensurate with the size and threats you face.
  • Implement controls to protect information assets and test their effectiveness through a systematic testing program.
  • Have robust mechanisms to detect and respond to information security incidents in a timely way.
  • Notify APRA within 72 hours of a material information security incident, and within 10 business days of identifying a material control weakness you cannot remediate promptly.

There is no single mandated "CPS 234 audit" product. In practice, the assurance comes from a mix of internal audit, external reviews, and the tripartite reviews APRA can request where an independent party assesses your controls against the standard. Understanding that distinction is the first step to understanding the cost.

Where the Money Actually Goes

When people ask about audit cost, they are usually thinking about the auditor's day rate. In reality the total cost of getting through CPS 234 assurance breaks into five buckets, and the auditor fee is rarely the largest one.

Cost componentWhat it coversTypical relative weight
Gap assessment / readiness reviewIndependent review of your current controls against CPS 234 to identify weaknesses before formal assurance.Low to moderate
RemediationFixing what the gap assessment finds: MFA gaps, logging, access reviews, encryption, third-party controls, documentation.Usually the largest
External review / assuranceAuditor or independent expert time to assess control design and operating effectiveness.Moderate
ToolingLogging and SIEM, identity, vulnerability management, and monitoring capability needed to evidence controls.Ongoing operational cost
Third-party assuranceAssessing controls at cloud providers, SaaS vendors, and outsourced processors that touch your information assets.Moderate, scales with vendor count

The single biggest cost driver is almost always remediation. If your controls are already mature, the assurance engagement is short and cheap. If the reviewer finds missing multi-factor authentication, weak logging, no evidence of control testing, or unmanaged third-party risk, the cost of fixing those items dwarfs the audit fee itself.

Realistic Cost by Institution Size

I am deliberately not going to quote a single number, because anyone who gives you a firm price before seeing your environment is guessing. What I can give you is the shape of the spend and the factors that move you up or down within each band.

Small fintech or ADI startup

A smaller entity with a modern cloud stack, few legacy systems, and a limited vendor footprint has the lowest cost. The environment is simpler to assess, controls can be implemented natively in the cloud platform, and there is less legacy debt to unwind. The trap here is under-investment in evidence: startups often have the right controls switched on but no documentation or testing records to prove it, which turns a cheap review into an expensive one.

Mid-sized bank or insurer

This is where cost climbs fastest. Hybrid environments with a mix of cloud and on-premise systems, legacy core banking or policy administration platforms, and a meaningful number of third parties all add assessment scope. Legacy systems are frequently the most expensive part of remediation because they were never designed for modern access control, logging, or encryption.

Large insurer or established institution

Large entities have the highest absolute spend simply because of scale: more systems, more people, more vendors, and more regulatory scrutiny. The offsetting factor is that mature organisations usually already have security programs, internal audit functions, and tooling in place, so the marginal cost of CPS 234 assurance is lower as a proportion of their overall security budget.

The Factors That Quietly Inflate Your Bill

Across the assessments I have run, the same handful of issues consistently push CPS 234 costs higher than they needed to be.

  1. Environment complexity. Hybrid cloud and on-premise estates, undocumented systems, and shadow IT all expand the scope an assessor has to cover. Every system that touches an information asset is in scope, including the ones nobody remembers to mention.
  2. Last-minute remediation. Fixing controls under audit pressure always costs more than fixing them on a normal project cadence. Rushed work also tends to be fragile, which means you pay again at the next review.
  3. Third parties. CPS 234 explicitly covers information assets managed by third parties. Every cloud provider, SaaS vendor, and outsourced processor needs to be assessed, and chasing evidence from vendors who are slow to respond adds both time and cost.
  4. Weak documentation. If you cannot evidence that a control exists and operates effectively, from the auditor's perspective it does not exist. Reconstructing policies, procedures, and testing records after the fact is expensive and avoidable.
  5. Choosing the cheapest reviewer. An assessor who does not understand APRA's expectations will either miss real issues, exposing you to a material weakness finding later, or raise noise that wastes your team's time. Neither is cheap.

How to Keep CPS 234 Costs Under Control

The goal is not to spend as little as possible. It is to spend on the things that reduce real risk and produce durable evidence, so you are not paying for the same fix twice. Here is the approach I recommend.

  • Start with a readiness review, not a formal audit. A focused gap assessment against CPS 234 tells you exactly where you stand and lets you remediate on your own timeline rather than under audit pressure. This is consistently the highest-return spend. Our IT security audit is built around exactly this: find the gaps before they become findings.
  • Fix the controls that actually reduce risk first. Multi-factor authentication everywhere, least-privilege access, centralised logging, and tested backups close the majority of real exposure. These are also the controls APRA cares most about.
  • Test your controls, and keep the evidence. CPS 234 requires a systematic testing program. Penetration testing and regular vulnerability assessments both satisfy the testing requirement and give you documented proof that controls work.
  • Get your third-party risk in order early. Inventory every vendor that touches an information asset, collect their assurance reports, and map their controls to your obligations before the reviewer asks.
  • Build the security capability once. Many mid-sized entities do not need a full-time security team, they need consistent senior direction. A fintech virtual CISO or virtual CISO engagement gives you the governance, oversight, and board reporting CPS 234 expects without the cost of a permanent hire.

The organisations that do CPS 234 cheaply over the long run are the ones that stop treating it as an annual event and build the underlying program properly. The audit then becomes a formality rather than a fire drill.

CPS 234 and the Broader Compliance Picture

If you sell to enterprise clients or operate internationally, CPS 234 rarely stands alone. Many of the controls overlap heavily with SOC 2 and ISO 27001. Building your control set once and mapping it to multiple frameworks is far cheaper than running separate compliance projects. If you are already pursuing SOC 2 for commercial reasons, a large share of the work also serves your CPS 234 obligations, and vice versa. Plan for this overlap deliberately rather than discovering it after you have paid for the same control twice.

Frequently Asked Questions

Is there a mandatory external CPS 234 audit?

CPS 234 does not prescribe a single audit product. Assurance typically comes from a combination of internal audit, external reviews, and tripartite reviews that APRA can request, where an independent party assesses your controls. The practical requirement is that you can demonstrate, with evidence, that your controls are designed and operating effectively.

What is the biggest driver of CPS 234 cost?

Remediation, not the audit fee. If your controls are already mature and well-documented, the review is quick and inexpensive. The cost climbs when the assessor finds gaps such as missing MFA, weak logging, untested controls, or unmanaged third-party risk that then have to be fixed.

How long does it take to prepare for CPS 234 assurance?

It depends entirely on your starting point. A cloud-native fintech with mature controls might be ready in a couple of months. A mid-sized entity with legacy systems and no formal security program should plan for a longer runway, because the remediation, not the assessment, sets the timeline.

Do we need a full-time CISO to comply?

Not necessarily. CPS 234 requires clearly defined roles and an information security capability appropriate to your size and threat profile. Many smaller and mid-sized entities meet this through a part-time or virtual CISO who provides the governance, oversight, and board-level reporting the standard expects.

How does CPS 234 relate to SOC 2 and ISO 27001?

The control sets overlap substantially. Access control, logging, incident response, and third-party management appear in all of them. If you build your controls once and map them to each framework, you avoid paying for the same work multiple times. This is one of the most effective ways to reduce total compliance cost.

What happens if we identify a control weakness we cannot fix quickly?

CPS 234 requires you to notify APRA within 10 business days of identifying a material information security control weakness that you cannot remediate promptly. This is why finding weaknesses early, through a readiness review, matters: it gives you time to remediate on your terms rather than under a reporting deadline.

Turning Compliance Into an Advantage

CPS 234 is a cost, but it is also proof to your clients, partners, and regulator that you take the protection of their data seriously. The firms that get the most out of it are the ones that build a genuine security capability rather than buying a certificate. If you want a clear, honest picture of where you stand and what it will realistically cost to get compliant, get in touch and we will start with a readiness review rather than a sales pitch.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.