Operational & Cyber Risk, Business Continuity & Third-Party Risk Management

APRA CPS230: Operational Risk Management

Third-Party Risk Management Software Dashboard

For APRA CPS230: Operational Risk Management compliance, ProcessUnity provides a turnkey solution to create a resilient operational risk posture both internally and externally, enabling you to establish:

  • A risk management framework to identify, assess, and manage operational and cyber risks with effective internal controls, monitoring, and remediation;
  • A credible business continuity plan, maintaining oversight of your third parties to ensure they can continue delivering critical operations within tolerance levels during severe disruptions
  • An effective management strategy for risks associated with your third parties, including a comprehensive service provider management policy, formal agreements, and robust monitoring.

The focus of APRA CPS230 is to elevate operational resilience standards. APRA-regulated entities have until mid-2025 to comply with the new standard’s requirements, CPS 230. This standard will help entities understand and manage risks across their operational value chain, particularly those associated with providing essential services to customers.

In addition to taking preventative measures, entities regulated under CPS 230 must implement procedures to continuously assess and treat operational resilience, report and respond to incidents as they occur, and adjust in the aftermath of an incident to reduce the likelihood and impact of similar events in the future. For organizations impacted by CPS 230, it is not enough to know how to stop an incident; they must also understand how to control the impact after it occurs.

To protect your organization from the increasing threat of operational incidents and to achieve compliance in time to avoid APRA penalties, it is essential to understand the facets of risk management regulated by CPS 230 and the tools available for meeting the regulation’s demands.

 Key Benefits: Processunity for APRA CPS 230 

  • Accelerated APRA CPS230 Compliance: A comprehensive solution that meets complex requirements across the enterprise, with the ability to integrate with existing processes via API.
  • Simplified Executive Reporting and Notification: Provides executive reporting, operational resiliency thresholds, and notification requirements, offering clear visibility and reducing the effort needed for reporting and notifications.
  • Value Chain Visibility: Enables visibility across the entire value chain, linking lines of business, business processes, systems/applications, and vendors.
  • Automated Workflow Processes: Facilitates workflow processes to conduct operational risk assessments for internal systems and due diligence on third parties.
  • Multi-Risk and Threat Intelligence: Utilizes data partners for multi-risk domain and threat intelligence capabilities. Leverages the GRX exchange to enhance speed and scalability in managing third- and fourth-party concentration risk.
  • Operational Risk Identification: Identifies operational risk disruptions and assesses their impact on associated processes or customer-facing applications.
  • Collaboration and Compliance: Supports collaboration across different functions and demonstrates compliance to auditors and regulators.

ProcessUnity combines its offerings into one comprehensive solution designed to help you meet APRA CPS230 obligations. The table below outlines the core APRA CPS230 components and how ProcessUnity streamlines your adherence to these requirements.

Key Requirement  Detail ProcessUnity Solution Component 
Operational Value Chain and Board Reporting
  • Ability to identify business processes, supporting systems/applications, underlying assets, and associated vendors for key lines of business or essential customer-facing services.
  • Provide visibility of the value chain to the board
  • Relationship Architecture – Operational value chain connecting lines of business to associated business processes, supported by critical systems/applications with underlying assets.
  • Linkage of these processes, systems, and assets to third parties
  • Executive dashboards
Operational Risk Management Framework
  • Identification of controls
  • assessment of operational risk profile with periodic risk assessments
  • Monitoring & analysis of operational Risk Profile
  • Identification of key operational risk profiles
  • Control library AI capability leveraging regulations and standards
  • Control testing/evaluations
  • Issue register, Risk register, Remediation and action plans
Business Continuity Plans and Resiliency Thresholds
  • Business continuity plans across the operational value chain (capture internal and external dependencies)
  • Resiliency threshold data – RTO, RPO and MTD
  • Business continuity testing and updates
  • Ability to conduct business impact assessment across the value chain and build a business continuity plan. Test the business continuity plan for its effectiveness against range of scenarios.
  • Capture resiliency threshold data across value chain i.e LOB, business process, system/application and vendor and identify a gap across the value chain
Service Provider Arrangements
  • Identification of material service providers including offshore arrangements
  • Agreement and contract risk management- additional clauses for reporting
  • Vendor risk management program from inherent to residual risk across multi-risk domains
  • 4th Party concentration risk
  • Master vendor inventory with vendor attributes
  • Capture inherent risk based on key usage of third party as well as threat intelligence data.
  • Build questionnaire library as well as combination of predictive AI capability to perform due diligence across multiple risk domains.
  • Contract lifecycle management, including capability to capture key provisions of the contracts.
  • Grant ability to vendor to provide operational resiliency data i.e. BCP plans and thresholds, MTD, RTO and RPO
  • Grant the ability for the third party to report incidents and vulnerabilities through a vendor portal
  • Assess 4th Party concentration risk
Vulnerabilities Operational risk incidents
  • Identification of vulnerabilities in the key’s systems/assets, which can impact the operational value chain.
  • Notification requirement for notifying operational risk incidents both internally and externally.
  • Identification of vulnerability catalogue using API capabilities through intelligence sources
  • Leveraging GRX exchange capabilities to map vendors and leverage the operational value chain to identify operational risk incidents.
  • Incident reporting portal inclusive of identification, notification and reporting of incidents by internal users and vendor portal for vendor to report incidents in a timely manner.

WHO APRA Applies to  

This Prudential Standard applies to all APRA-regulated entities defined as:

  1. Authorised deposit-taking institutions (ADIs), including foreign ADIs, and non-operating holding companies authorised under the Banking Act (authorised banking NOHCs);
  2. General insurers, including Category C insurers, non-operating holding companies authorised under the Insurance Act (authorised insurance NOHCs), and parent entities of Level 2 insurance groups;
  3. Life companies, including friendly societies, eligible foreign life insurance companies (EFLICs), and non-operating holding companies registered under the Life Insurance Act (registered life NOHCs);
  4. Private health insurers registered under the PHIPS Act; and
  5. Registrable superannuation entity licensees (RSE licensees) under the SIS Act in respect of their business operations.

The obligations imposed by this Prudential Standard on, or in relation to, a foreign ADI, a Category C insurer, and an EFLIC apply only to the Australian branch operations of that entity.

Where an APRA-regulated entity is the Head of a group, it must comply with a requirement of this Prudential Standard:

  1. In its capacity as an APRA-regulated entity.
  2. By ensuring that the requirement is applied appropriately throughout the group, including in relation to entities that are not APRA-regulated, and
  3. On a group basis.

ProcessUnity for APRA CPS230 streamlines your adherence to new regulatory requirements. Schedule a call today to learn how ProcessUnity can help you meet your compliance obligations. We can assist with the entire compliance process or specific areas of the requirement. Leverage the flexibility of our offering to meet your unique compliance needs, whether internal control testing, business continuity, third-party risk management, incident management, or reporting. 

ProcessUnity’s Third-Party Risk Management platform creates a resilient operational risk posture for APRA CPS230 compliance.

Request a Demo: APRA CPS230

Third-Party Risk Management Software Demonstration