This page is an educational summary for professionals working with AI. It is not the law and not legal advice. Always work from the current authoritative text linked below.
What does CPG 230 do?
CPG 230 sets out APRA's view of sound practice for operational risk management, structured to follow CPS 230: the risk management framework, roles and responsibilities, operational risk management, business continuity, and management of service provider arrangements. It reproduces the enforceable CPS 230 paragraphs in blue boxes and surrounds them with guidance. Read the July 2026 guide on the APRA website.
Who does it bind?
No one directly. APRA states that practice guides discuss requirements from legislation, regulations or prudential standards but do not themselves create enforceable requirements. CPS 230 binds; CPG 230 explains what meeting it looks like, with stronger expectations of significant financial institutions.
What do practitioners get wrong?
Two version problems. Citing the June 2024 edition after the July 2026 one commenced, and attributing a blue box paragraph to the guide when it is CPS 230 text. Both make an obligation look softer or harder than it is. See CPS 220 for where the risk management pillar starts.
Where does AI use touch it?
Service provider arrangements. A model vendor an entity relies on to run a critical operation, or that exposes it to material operational risk, is a material arrangement. The 2026 exemptions relax certain contractual requirements where compliance is not practicable; they do not relax the duty to manage the arrangement. See AI vendor concentration on a common foundation model.
Bottom line
CPG 230 is the working manual for CPS 230. Read the current July 2026 edition, and keep the blue boxes and the guidance apart when citing it.
TheAICommand. Intelligence, At Your Command.
