Skip to content

Australia / CPS 234

CPS 234 · APRA

CPS 234 control assurance with defensible evidence chains

APRA expects a systematic information-security control testing program, performed by skilled, functionally independent specialists, with nature and frequency matched to threat change, asset criticality and material change. We deliver technical testing, remediation engineering and evidence packs. We do not claim to be the statutory auditor or an IRAP assessor.

Read the control-testing guide →

Obligation map

Where CPS 234 control testing sits in the full standard.

Governance & accountability

Board and senior management responsibility for information security capability and control effectiveness.

AiRAT: We support with evidence engineering and remediation, not Board governance consulting.

Information asset inventory

Classification and ownership of information assets, including those managed by third parties.

AiRAT: We map test scope to classified assets and criticality tiers.

Systematic control testing

Testing program with nature and frequency reflecting threat change, criticality, consequence, exposure and material change.

AiRAT: Core delivery: pentest, operating-effectiveness tests, retest and evidence chain.

Incident management & notification

Material incidents reported to APRA within 72 hours; non-material within 10 business days.

AiRAT: We help build detection and evidence trails that support notification decisions, not legal interpretation.

Internal audit & independence

Annual review of testing program sufficiency; functional independence of testers.

AiRAT: We work to independence models agreed with risk and internal audit, we are not the statutory auditor.

CPS 230 adjacency

Operational risk, continuity and material service-provider risk under CPS 230.

AiRAT: Adjacent, not a substitute. CPS 230 does not invent a mandatory 24/7 SOC requirement in CPS 234.


Testing programme

Beyond penetration testing: operating effectiveness across the estate.

Penetration testing

External, internal, application, red team where justified

Identity & privileged access

MFA, PAM lifecycle, conditional access, session controls

Endpoint & application control

EDR coverage, allow/block events, hardening baselines

Detection & response

SIEM use-case replay, alert-to-ticket evidence, playbooks

Cloud & configuration

Posture drift, entitlement reviews, IaC guardrails

Backup & recovery

Access controls, restoration testing, immutability

Third-party reliance

Assess whether vendor testing is commensurate with CPS 234

Evidence chain

  1. Control / asset scope documented
  2. Test objective, method and tester recorded
  3. Raw output retained (not summary-only)
  4. Finding → owner → remediation ticket → retest
  5. Escalation or risk acceptance where required

Deliverables

What a CPS 234 testing engagement produces.

  • Test universe matrix: control → asset → test → frequency → evidence → owner → retest
  • Raw test artefacts with findings mapped to controls
  • Remediation backlog with severity and retest criteria
  • Third-party testing commensurability assessment where applicable
  • Management-ready escalation summary for material gaps
Deep dive: control-testing evidence →

Related proof

Continuous assurance and SIEM evidence engineering.

Continuous penetration testing for a SaaS platform

  • Fixed-fee programme with included retest
  • Raw artefacts for audit review
  • Release-gate integration
Read case study →

SIEM cost reduction with zero detection coverage lost

  • 58% ingest reduction
  • Detection rules replayed before cutover
  • Evidence trail for control effectiveness
Read case study →

Common questions

Is AiRAT the statutory auditor for CPS 234?

No. AiRAT can deliver technical control testing, penetration testing, red teaming, evidence engineering and remediation, but we do not claim to be the statutory auditor.

Is AiRAT an IRAP assessor?

No. AiRAT is not an IRAP assessor and does not perform IRAP assessments.

Does CPS 234 require penetration testing?

CPS 234 requires systematic control-effectiveness testing, not a single named test type. Penetration testing is useful evidence for relevant technical controls but should sit inside a broader assurance program.

What are APRA's incident notification windows under CPS 234?

Material information security incidents must be reported to APRA within 72 hours. Non-material incidents must be reported within 10 business days.

Does CPS 230 require a 24/7 SOC?

No. CPS 230 covers operational risk, continuity and service-provider risk. Do not convert that into a claim that APRA mandates a 24/7 SOC unless another requirement applies.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →