Who this reaches
APRA-regulated entities and the information assets they manage directly or through related parties and third parties.
What the rule requires
Entities must maintain information-security capability and controls proportionate to threats and asset sensitivity, test control effectiveness, evaluate relevant third-party controls, and notify APRA of material incidents.
What changes when the email path is regional
Boundry's architecture and planned Region Manifest are structured around the data classes a third-party review asks about: content, metadata, queues, events, logs, support, subprocessors, retention, and exceptions.
What your team still owns
Boundry is not 'CPS 234 certified'. The regulated entity remains responsible for classifying the asset, evaluating Boundry's controls, testing reliance, and governing the complete service chain.
Read the primary sources
This is an engineering and vendor-evaluation guide, not legal advice. Confirm the current rule for your entity, contract, and workload from the primary source.