CPS 230 When Your Service Provider Is an AI System
APRA's operational risk standard never mentions artificial intelligence. It doesn't need to. If your AI sits inside a bank's critical operation, the obligations arrive through the contract — and the transition period has already expired.
APRA's Prudential Standard CPS 230 does not mention artificial intelligence. Neither does the practice guide that supports it. If you searched both documents for the word "model" expecting to find something about machine learning, you would come away thinking the standard has nothing to say about AI at all.
That reading is wrong, and expensively so. CPS 230 reaches AI systems the same way it reaches every other dependency: not by naming the technology, but by asking what the regulated entity relies on. A system that sits inside a critical operation is captured on that basis alone, and the obligations that follow land on the vendor through the contract even though the vendor is not regulated by anyone.
For technology businesses selling into Australian banking, insurance or superannuation, this is the most consequential regulatory instrument most of them have never read. This is general commentary rather than legal advice.
The date most vendors missed
CPS 230 commenced on 1 July 2025. That much was widely reported.
Less widely understood is what happened to contracts that were already in place. The standard provided that where an APRA-regulated entity had pre-existing contractual arrangements with a service provider, the requirements would apply to those arrangements "from the earlier of the next renewal date of the contract with the service provider or 1 July 2026."
That transition has now expired. As of July this year, CPS 230 applies to legacy service arrangements regardless of whether anyone got around to renegotiating them. A vendor still operating under a 2023 master services agreement is not outside the standard. The regulated entity on the other side of that agreement is simply non-compliant, which is a problem the vendor will hear about.
Three separate things carry the date 1 July 2026 in the commentary — the pre-existing contracts transition, a twelve-month extension for smaller institutions on business continuity and scenario analysis, and the commencement of an amended version of the standard. They are routinely conflated. The one that matters for vendors is the first.
What makes a provider "material"
CPS 230 defines the trigger in terms of reliance rather than spend or size. Material service providers are those "on which the entity relies to undertake a critical operation or that expose it to material operational risk." Material arrangements are defined in the same terms.
There is no dollar threshold, no headcount test, and no carve-out for small suppliers. A three-person company can be a material service provider to a major bank if the bank relies on it for something critical. Vendors consistently assume they are too small to be captured, and the definition contains nothing that supports the assumption.
The standard then goes further, listing services that an entity must classify as material unless it can justify otherwise. For all APRA-regulated entities that list includes core technology services, along with risk management and internal audit. For an ADI specifically, the list includes credit assessment, funding and liquidity management, and mortgage brokerage.
An AI system doing meaningful work inside a bank will usually engage both routes at once — the general reliance test, and the core technology services category. That is how a standard with no AI provisions ends up governing AI vendors.
I will declare an interest in that list, since I hold a credit licence: mortgage brokerage appears on the face of a prudential standard as a service an ADI must presumptively treat as material. Brokers and aggregators are therefore on the receiving end of CPS 230 flow-down as suppliers, not because APRA regulates them — it does not — but because APRA named the service. Any AI tooling adopted inside that supply chain becomes part of a dependency chain the bank is expected to be able to see into. What the broker's own obligations say about that tooling is the subject of this article's companion piece, AI and the Best Interests Duty.
The 2026 amendments are not about AI
In April 2026 APRA finalised targeted amendments to CPS 230, and a certain amount of commentary treated this as the regulator responding to AI. It was not.
The amendments create a limited exemption from specific contractual requirements for material arrangements with non-traditional service providers. APRA's listed categories are government agencies, regulators, central banks, financial market exchanges, operators of clearing and settlement facilities, operators of payment systems and schemes, and financial messaging infrastructures. The exemption applies where the counterparty falls in one of those categories and the arrangement uses standardised terms or is not formally documented.
The logic is straightforward: a bank cannot negotiate audit access rights with the Reserve Bank. The relief exists because the contractual requirements are impossible to satisfy, not because they are burdensome.
A commercial AI vendor is an ordinary commercial supplier. None of this helps. If anything the amendments confirm the position by showing how narrow APRA was prepared to be about who gets relief.
What APRA asked for in April
Separately, on 30 April 2026, APRA wrote to all regulated entities on artificial intelligence, reporting the findings of a targeted supervisory review conducted in late 2025.
The framing is important and frequently misreported. This is a letter setting out observations and expectations, not a rule change, and APRA is explicit that the existing regime already covers the ground: "While most entities recognise that existing prudential standards apply to AI risk, few have operationalised governance in practice."
The letter also records a tendency among regulated entities to treat AI risk as "just another technology" — a framing APRA rejects, pointing to the distinct characteristics of predictive and adaptive systems. It was APRA's own letter, not a joint communication with ASIC.
Within that framing, the third-party section is the one vendors should read. APRA's stated expectations include:
- Mapping and maintaining visibility over "the full AI supply chain, including material, third-party and fourth-party dependencies"
- Contractual and governance arrangements providing "sufficient transparency, auditability and assurance over AI services"
- An ability to "understand model behaviour, material changes, performance issues and outcomes"
- Active management of concentration risk, including the "credibility and feasibility of substitution, portability or exit arrangements"
APRA introduces that list by noting that the variables involved "challenge an entity's ability to completely and effectively assess and manage risk" — which is a fair description of most of the AI supply chain as it currently exists.
None of these expectations bind a vendor directly. Every one of them will arrive in a vendor's next contract negotiation, because the entity cannot meet them otherwise.
What actually flows down
Strip out the regulatory framing and here is what a technology business supplying an APRA-regulated entity should expect to sign, or to be asked why it won't.
Due diligence before contracting. A selection process, an assessment of your ability to deliver on an ongoing basis, and an assessment of financial and non-financial risks including geographic concentration. Small vendors are routinely surprised by how far this reaches into their own finances.
Audit and regulator access. The agreement must allow APRA access to documentation, data and other information relating to the service — and give APRA the right to conduct an on-site visit to the service provider. That is a right of entry to your premises, written into a contract you sign with your customer.
Fourth-party transparency. The entity must take reasonable steps to identify parties in the chain beneath you, and agreements must require you to notify your use of other material service providers. Your subprocessors, model providers and infrastructure dependencies become disclosable. Obligations frequently cascade, meaning you may be required to flow equivalent terms down to your own suppliers.
Liability for sub-contractors. Not merely disclosure of them. If the model provider underneath you fails, that is contractually your failure.
Notification timelines. The entity must notify APRA within 20 business days of entering or materially changing a material agreement, and before entering any material offshoring arrangement. You will be contractually obliged to give them what they need to do that, on time.
Exit and portability that is real. APRA's April letter is explicit that substitution and exit arrangements must be credible and feasible. A contractual exit right that is technically unexercisable does not satisfy this.
AI-specific overlays. Model update notification, inspection rights and incident notification timelines are now appearing in these contracts as a matter of course.
The point for vendors who aren't regulated
CPS 230 binds the regulated entity. It does not bind you. That distinction is legally correct and practically irrelevant, because the entity cannot comply unless your contract delivers compliance to it.
What this means in practice is that operational discipline becomes a commercial precondition rather than an internal virtue. Being able to explain what your model does, notify when it materially changes, evidence your own supply chain, and demonstrate an exit path that works is not a maturity milestone you reach eventually. It is the price of the conversation.
The vendors who will struggle are not the ones with weak technology. They are the ones who built something capable and never built the ability to describe it — no change log, no model versioning, no documented dependencies, no incident process. That gap is invisible right up until a procurement team asks, at which point it takes months to close and the deal does not wait.
Build it before the question arrives. It is considerably cheaper than retrofitting evidence of a discipline you did not have.
AI and the Best Interests Duty: Where Automation Stops in Mortgage Broking
No Australian law addresses AI use by mortgage brokers. That doesn't mean the question is open — the best interests duty already answers most of it, and a privacy deadline in December closes the rest.
Evaluating Language Models for Regulated Work: Accuracy, Auditability, Cost
In finance and professional services you can't ship an AI feature on vibes. Evaluating models for regulated work means measuring accuracy, auditability and cost as one system.
The Integration Layer: Turning Fragmented Systems Into One Intelligence Surface
Most business AI value isn't blocked by the model. It's blocked by data trapped in disconnected systems. The unglamorous integration layer is where intelligence becomes possible.