Governance & accountability
Board and senior management responsibility for information security capability and control effectiveness.
AiRAT: We support with evidence engineering and remediation, not Board governance consulting.
CPS 234 · APRA
APRA expects a systematic information-security control testing program, performed by skilled, functionally independent specialists, with nature and frequency matched to threat change, asset criticality and material change. We deliver technical testing, remediation engineering and evidence packs. We do not claim to be the statutory auditor or an IRAP assessor.
Obligation map
Board and senior management responsibility for information security capability and control effectiveness.
AiRAT: We support with evidence engineering and remediation, not Board governance consulting.
Classification and ownership of information assets, including those managed by third parties.
AiRAT: We map test scope to classified assets and criticality tiers.
Testing program with nature and frequency reflecting threat change, criticality, consequence, exposure and material change.
AiRAT: Core delivery: pentest, operating-effectiveness tests, retest and evidence chain.
Material incidents reported to APRA within 72 hours; non-material within 10 business days.
AiRAT: We help build detection and evidence trails that support notification decisions, not legal interpretation.
Annual review of testing program sufficiency; functional independence of testers.
AiRAT: We work to independence models agreed with risk and internal audit, we are not the statutory auditor.
Operational risk, continuity and material service-provider risk under CPS 230.
AiRAT: Adjacent, not a substitute. CPS 230 does not invent a mandatory 24/7 SOC requirement in CPS 234.
Testing programme
Penetration testing
External, internal, application, red team where justified
Identity & privileged access
MFA, PAM lifecycle, conditional access, session controls
Endpoint & application control
EDR coverage, allow/block events, hardening baselines
Detection & response
SIEM use-case replay, alert-to-ticket evidence, playbooks
Cloud & configuration
Posture drift, entitlement reviews, IaC guardrails
Backup & recovery
Access controls, restoration testing, immutability
Third-party reliance
Assess whether vendor testing is commensurate with CPS 234
Deliverables
Related proof
No. AiRAT can deliver technical control testing, penetration testing, red teaming, evidence engineering and remediation, but we do not claim to be the statutory auditor.
No. AiRAT is not an IRAP assessor and does not perform IRAP assessments.
CPS 234 requires systematic control-effectiveness testing, not a single named test type. Penetration testing is useful evidence for relevant technical controls but should sit inside a broader assurance program.
Material information security incidents must be reported to APRA within 72 hours. Non-material incidents must be reported within 10 business days.
No. CPS 230 covers operational risk, continuity and service-provider risk. Do not convert that into a claim that APRA mandates a 24/7 SOC unless another requirement applies.
Get started
Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.
No spam. We only use your email to respond to this request.
Explore services →