CPS 230 Operational Risk Management

CPS 230 is not a blanket data-localisation rule. It does make offshore service delivery, including the physical location of relevant data or personnel, a specific governance and notification consideration when the arrangement is material.

Country
Australia
Rule type
Financial services
Regional pressure
Stronger offshore governance

Who this reaches

APRA-regulated banks, insurers, private health insurers, and superannuation entities when managing operational risk and material service-provider arrangements.

What the rule requires

Regulated entities must identify and manage material arrangements, maintain appropriate agreements and oversight, and notify APRA before entering or materially changing a material offshoring arrangement.

What changes when the email path is regional

A defined Australian processing path can reduce ambiguity in the offshoring assessment and give vendor-risk teams a narrower architecture, service location, and subprocessor surface to review.

What your team still owns

Boundry cannot determine materiality, critical-operation impact, APRA notification duties, or whether the customer's wider arrangement remains offshore through other services or personnel.

Read the primary sources

This is an engineering and vendor-evaluation guide, not legal advice. Confirm the current rule for your entity, contract, and workload from the primary source.

Turn this rule into an email path you can defend.

Start with one workflow. Classify the data, keep the message minimal, and trace it through the Sydney regional plane.