CPS 234 compliance requires APRA-regulated entities to run a systematic control testing programme, not a yearly CPS 234 penetration testing PDF in isolation. This guide covers CPS 234 control testing evidence, what an independent audit or assurance function expects to see, and CPS 230 adjacency for operational resilience, without inventing mandates like a required 24/7 SOC. We are not the statutory auditor or IRAP assessor.
Where control testing sits in CPS 234
The wider standard covers Board responsibility, asset classification, incident management, third parties and internal audit review of control design and operating effectiveness. The CPS 234 compliance pillar owns the full obligation map.
Notification thresholds that shape evidence:
- 72 hours: material information-security incident
- 10 business days: material control weakness not remediated in a timely manner
When you rely on a third party's testing, CPS 234 requires assessing whether that testing is commensurate with the standard.
Penetration testing is evidence, not the whole program
| Control area | Useful test | Key artefact |
|---|---|---|
| Internet-facing apps | External/web/API pentest | Scope, raw output, findings, retest |
| Identity | MFA bypass, privileged access review | IdP/PAM config, auth logs |
| Endpoint | EDR validation, execution test | Policy, telemetry, containment |
| SIEM / detection | Adversary simulation | Raw events, alert, analyst ticket |
| Cloud | Config review, IAM path test | CSPM export, remediation ticket |
| Backup / recovery | Restore exercise | RTO/RPO result, backup ACL evidence |
| Third parties | Provider assurance review | SOC report, gap assessment, contract map |
See threat-informed detection engineering and Splunk noise-first migration for detection evidence patterns.
APRA CPG 234 operating model
CPG 234 expects testing that validates design and operating effectiveness over time. A sufficient set of controls is normally tested at least annually; controls in untrusted environments are typically tested through the year.
Internet-facing critical apps: frequent scanning + periodic pentest
Privileged identity: recurring review as roles change
Backup and recovery: restore exercises on defined cadence
Third-party reliance: validate provider testing commensurate with CPS 234
The evidence chain assessors expect
- Control and asset in scope
- Test objective and method
- Tester identity, skills and functional independence statement
- Date and raw output (not summary-only)
- Result and finding severity
- Remediation owner and ticket
- Retest evidence or documented risk acceptance
- Management or Board escalation where required
Raw artefacts beat summary decks. SIEM logs, configuration exports and ticket trails should link to the control statement.
Who tests, and does CPS 234 require an independent audit?
CPS 234 requires testing by specialists who are appropriately skilled and functionally independent of the function that designed or operates the control. That is narrower than a CPS 234 independent audit in the statutory sense. It is an independence-of-tester requirement, not an instruction to appoint an external auditor for every test.
Separately, CPS 234 requires internal audit to review the design and operating effectiveness of information-security controls, including any testing performed by a related party or third party. Agree the independence model with risk and internal audit before the cycle starts, so evidence is not rejected after the testing is complete.
An external specialist can satisfy the functional-independence requirement for technical testing while internal audit retains its own review role. AiRAT delivers the technical testing side, we are not the statutory auditor.
CPS 230 adjacency (third-party risk)
CPS 230 covers operational resilience and material service providers. It does not mandate a 24/7 SOC unless another requirement applies. Keep CPS 234 assurance separate from operational-resilience narrative drift.
Remote engineering delivery is viable when access is controlled, session-logged and does not export bulk production data offshore without approval. See Australia residency.
Readiness checklist
- Define control population and risk-tiered test calendar
- Document functional independence model with internal audit
- Ensure raw test outputs are retained and ticket-linked
- Map escalation path for unremediated material weaknesses
- Review third-party testing commensurate with reliance
- Schedule annual sufficiency review of the testing programme
Limitations
Technical assurance guidance, not statutory audit, legal or APRA regulatory advice. Re-check CPS 234 and CPG 234 before board reporting.
Sources: APRA CPS 234, CPG 234, verified 8 August 2026.
Next step: Scope CPS 234 control testing · CPS 234 pillar · Pentest case study