Six Months of CPS 2 3 0: What Does the Next Phase of Resilience Look Like?

Introduction

As APRA sharpens its focus on operational risk and organisations continuously embed regulatory requirements, the evolving business continuity landscape has exposed key areas where organisations can evolve to build true operational resilience.

Overview of CPS 2 3 0

It has now been six months since the Australian Prudential Regulation Authority (APRA) released the Standard (CPS) 2 3 0 for Operational Risk Management. The regulatory change seeks to ensure business continuity and service provider management principles are effectively developed.

Critical Operations and Material Service Providers

  • Critical Operations (COs) - processes undertaken by an AP that would have a material adverse impact on its customers.
  • Material Service Providers (MSPs) - entities relied on to understand and manage these risks.

Objectives of CPS 2 3 0

The aim of the CPS 2 3 0 is to ensure that an organisation is resilient to operational risks, able to manage disruptions, and effectively address the risks arising from third-party service providers.

Key Challenges and Considerations

Risk Profiles

  1. There is a lack of clarity and consistency in how risk profiles are consolidated, rated, and managed across divisions, particularly in relation to governance triggers, third-party performance, and incident response. The absence of a unified methodology for control ownership and integration hinders the development of enterprise-wide risk profiles.

Strategic Priorities

  • Ensure that asset registers for dependencies are clear, detailing asset name, description, type, and ownership.
  • Recovery objectives and contractual obligations must be established alongside criticality tier considerations.

Adoption of an End-to-End Value Chain Perspective

Shifting to an end-to-end value chain perspective means understanding risks that impact COs across interconnected processes. This approach contributes to value delivery and identifies vulnerabilities that may disrupt these processes.

Assessment of Critical vs Non-Critical Assets

  • Differentiate between critical and non-critical assets regarding their importance to operational risks. For example, a maximum allowable outage of 72+ hours signifies non-critical assets.

Enablers that Support Effective Management

Classification of MSPs

  • Service provider governance should include constructing a RACI Matrix to clarify responsibilities across stakeholders, ensuring preparedness for incidents and contractual obligations.

Technology and Systems

Organisations often utilize multiple poorly connected systems to manage operational risks, complicating the integration of critical data. A consistent approach must be established for incident notification and escalation management.

Conclusion

The implementation of APRA’s Prudential Standard CPS has shown significant areas for improvement in operationalising resilience in regulated entities. Senior management and the Board need strategic imperatives to address fragmented systems and methodologies. Moving forward, organisations must transition from fragmented risk practices to integrated frameworks that enable timely disruption response and continuity.