
Australia’s CPS 230 is no longer a roadmap, it’s the rulebook. As of 1 July of last year, QA and software testing teams across banks, insurers and superannuation funds are being asked to evidence resilience, not just assert it: rigorous scenario exercises, repeatable continuity tests, and vendor-chain controls now sit squarely inside the testing remit.
Michael Stojanovic, Special Counsel Australia at international law firm Bird & Bird, analysed the relatively young legislation and the impact the rules are having on the financial services space and its banktech ecosystem.
The seasoned lawyer explained that “CPS 230 brings a more structured, accountable, and forward-looking approach to managing risk, business continuity and service provider arrangements to those parts of Australia’s financial services sector that are regulated by APRA.”
He added that “the requirements of CPS 230 should also be front-of-mind for all suppliers of services to those regulated businesses.”
For those responsible for software testing and digital resilience, that translates into mapping and continuously testing and validating the systems and processes that keep critical services running under stress.
“CPS 230 applies to all APRA-regulated entities, including banks, insurers, and superannuation trustees,” Stojanovic stressed, meaning a sector-wide uplift in test coverage, evidence, and board-level reporting.
Testing brief
At the heart of the standard is a crisp testing brief: identify what truly matters, set hard limits for disruption, and prove you can stay within them.
“Under CPS 230, regulated entities are required to identify their ‘critical operations’, those essential functions that, if disrupted, could have a material impact on financial markets, customers, or the broader economy.”
For each of those, Stojanovic continued “entities must now establish disruption tolerance thresholds and demonstrate how they will remain within these limits under a range of stress scenarios.”
That push extends into specific business domains QA teams will recognize from their regression and failover books.
“APRA mandates that, at a minimum, certain core business operations be classified as ‘critical’ unless the entity can justify otherwise,” he explained, citing examples from deposit-taking and payments to claims processing and fund administration, alongside customer enquiries across regulated entities.
Test design and execution will need to reflect that criticality, and produce evidence regulators can rely on.
“Entities must maintain a comprehensive operational risk management framework that enables them to identify, assess and control potential threats.”
– Michael Stojanovic
CPS 230 also codifies the test-and-assure loop around continuity. “To support these requirements, entities must maintain a comprehensive operational risk management framework that enables them to identify, assess and control potential threats,” Stojanovic pointed out.
He continued by saying that “this includes developing and regularly testing up-to-date business continuity plans to ensure effective response and recovery to operational incidents.”
Supplier assurance is no longer a peripheral exercise; it is an explicit regulatory expectation. Stojanovic clarified: “A significant focus of CPS 230 is managing risks related to external suppliers. A regulated entity must ensure that contracts with its service providers contain appropriate safeguards, particularly for services supporting critical functions.”
Operational QA chores
That comes with concrete operational chores for QA and vendor-risk teams: “Regulated institutions are now required to keep a register of all material service providers and maintain a service provider management policy,” Stojanovic shared.
He added that, for the first time, institutions must formally document their approach to managing the risks associated with fourth party suppliers that material suppliers rely upon, sometimes known as sub-outsourcing, which could include a wide range of cloud service, telecommunications and other IT industry suppliers.”
Governance has moved from backdrop to front stage. “CPS 230 strengthens the role of boards and senior management in operational risk oversight,” Stojanovic wrote.
“Boards must oversee the effectiveness of risk management practices and ensure that adequate resources are allocated to meet the new requirements.”
For QA leaders, this implies tighter alignment with risk, architecture and procurement, plus board-ready reporting that turns test outputs into operational-resilience assurance.
“A significant focus of CPS 230 is managing risks related to external suppliers.”
– Michael Stojanovic
Most institutions have already done the groundwork, but the real test begins now.
“Many institutions have spent the last two years undertaking readiness assessments, updating internal controls, mapping critical operations, and renegotiating external contracts to meet the new obligations,” Stojanovic said.
And while the lift has been heavy, the direction of travel is clear: “While the transition has not been without challenges, particularly around resourcing and compliance costs, many institutions recognise CPS 230 as a necessary response to the growing complexity and interconnectedness of operational risks in today’s financial market.”
The message for QA teams is to treat CPS 230 as a program of continuous assurance rather than a one-off certification sprint.
“Institutions that approach CPS 230 as a one-off project risk falling behind in an environment where operational disruptions are increasingly complex and interdependent.”
As Stojanovic concluded: “In a financial landscape defined by constant change, resilience is not merely about ticking regulatory boxes, it’s about maintaining the trust and confidence of regulators and customers alike. CPS 230 has been designed to facilitate this, but it’s up to industry to achieve it.”
16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



