APRA’s operational-risk standard does not mention AI. The operations it covers increasingly run on it.
CPS 230 came into force on 1 July 2025, with targeted amendments commencing on 1 July 2026. It requires APRA-regulated entities, the banks, insurers and superannuation trustees, to manage operational risk with effective controls and monitoring, to keep critical operations running within board-approved tolerances through severe disruptions, and to manage the risks of their service providers. The board is accountable for oversight of all of it. When an operational-risk incident is likely to have a material financial impact, or to threaten a critical operation, the entity has to notify APRA quickly, within 72 hours, and within 24 hours where a critical operation falls outside its tolerances.
CPS 230 does not mention artificial intelligence. It does not need to. An AI system that approves, prices, triages or routes inside a critical or material operation is part of that operation, and the standard’s expectations apply to it the way they apply to any other operational process. The question CPS 230 puts to a board is not whether the entity has an AI policy. It is whether the entity can manage, monitor and, when something goes wrong, account for what its operations did. For the AI sitting inside those operations, many entities cannot answer that from what they currently keep.
The incident clock is where the gap shows
The sharpest edge is the notification duty. When an AI-driven operation produces an incident with material impact, the entity has hours, not weeks, to tell APRA what happened. That means reconstructing, under a 72-hour clock, what the system did, on what basis, and whether it acted within its bounds. An entity assembling that from logs never designed to answer the question, after the incident, is doing the hardest version of the task at the worst possible time. Operational-risk evidence that only comes into existence after the fact is not evidence the standard’s expectations are well served by.
What operational-risk evidence for an AI operation may need to show
Decision provenance is a record of what an autonomous system did, on what basis, under whose authority, and how each item was captured, kept so it can be reconstructed later. For an AI operation inside an APRA-regulated entity, it is what turns “we monitor our AI” into something that can be shown: what the system did, which authority it acted under, what controls were in place, and how each of those facts is known.
Because the record shows how each fact is known, whether it came from the infrastructure that ran the decision, was captured close to the event, was reconstructed, or was stated by a person, it supports the reconstruction an incident notification demands rather than papering over the gaps. That honesty about capture method matters more under a regulator’s eye, not less.
Custara prepares, structures and preserves that record. It does not assess whether the entity meets CPS 230, and it does not certify the entity’s operational risk management. Whether the evidence satisfies the standard is for the entity, its risk function, its counsel, and ultimately APRA. Custara’s job is to make sure the evidence exists and is legible when it is asked for.
Prepared in a consistent structure the entity did not set
Operational-risk evidence carries more weight when it is prepared in a consistent structure the entity did not set for itself, and can be reviewed independently. That is the logic APRA already applies elsewhere: where it sees material weakness, it can require an independent review. A record prepared to an external structure, that an independent assessor can examine, is built for that scrutiny rather than against it. A standard can define what the record should contain and how evidence quality is described, which is the work of the Decision Standards Institute, and an independent assessor can review the record separately, which is the role of Attestra. Custara prepares the record. It does not assess it, and it does not stand in for the entity’s own accountability under CPS 230.
CPS 230 asks a board to be able to show that its operations are managed, monitored and accountable. As more of those operations run on autonomous systems, that expectation reaches the AI whether or not the standard names it. The entity that can reconstruct what its AI did, quickly and honestly, is meeting the operational-risk expectation. The one that can only point to a policy is hoping the incident never comes.
See how one record supports oversight for a regulated operator in the worked examples, or read how Custara works with regulated enterprise.
This article describes CPS 230 in general terms and is not legal or compliance advice. APRA-regulated entities should rely on the standard itself and their own advisers. The framework behind this approach, and the book that sets it out, are forthcoming.