Prudential Practice Guide CPG 235, plain-English definition from TheAICommand
← Glossary
Reference

What is APRA Prudential Practice Guide CPG 235?

CPG 235 Managing Data Risk is APRA's practice guide on data risk. Dated September 2013, it defines data risk, sets out six dimensions of data quality, and asks entities to classify data by business criticality and sensitivity across its end-to-end use.

Quick answer

CPG 235 Managing Data Risk is an APRA prudential practice guide, dated September 2013. It sets out APRA's view of sound practice for managing data risk, including six dimensions of data quality and classification by business criticality and sensitivity. Practice guides do not themselves create enforceable requirements.

Verified against the current authoritative text on by the editorial team at TheAICommand.

This page is an educational summary for professionals working with AI. It is not the law and not legal advice. Always work from the current authoritative text linked below.

What does CPG 235 do?

CPG 235 sets out APRA's view of sound practice for managing data risk. It defines data as the representation of facts, figures and ideas, and data risk as the risk of loss from inadequate or failed internal processes, people and systems, or from external events, impacting on data. It asks entities to assess data quality across six dimensions, to classify data by business criticality and sensitivity taking the end-to-end use into account, and to adopt a systematic rather than ad hoc approach. Read the guide on the APRA website.

Who does it bind?

Nobody, on its own terms. APRA is explicit that practice guides do not create enforceable requirements. The duties live in the prudential standards, including CPS 220 and CPS 234; CPG 235 describes how APRA expects sound entities to meet them.

What do practitioners get wrong?

Both directions. Citing a CPG paragraph as though it were a standard obligation, or dismissing the guide because it is not enforceable. Neither survives supervision. APRA wrote the guide to target areas where it keeps finding weaknesses.

Where does AI use touch it?

Fitness for use is the dimension that bites. Data that is accurate and complete can still be inappropriate for the purpose a model is being pointed at, and the classification test looks at end-to-end use, which for a model pipeline includes the prompt, the retrieval store and the output. See rebuilding the inputs behind an AI run.

Bottom line

CPG 235 is old and still useful. It gives data risk a definition, quality a vocabulary, and classification a method, which is most of what an AI data pipeline needs before controls are argued about.

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Is CPG 235 enforceable?
No, not by itself. APRA states that prudential practice guides discuss legal requirements from legislation, regulations or prudential standards, but do not themselves create enforceable requirements. The enforceable obligations sit in the prudential standards. CPG 235 tells a regulated entity what APRA regards as sound practice when meeting them.
What are the six dimensions of data quality?
Paragraph 16 lists accuracy, completeness, consistency, timeliness, availability and fitness for use. Accuracy is the degree to which data is error free and aligns with what it represents. Fitness for use is the degree to which data is relevant, appropriate for the intended purpose and meets business specifications.
How does CPG 235 define data risk?
Paragraph 11 defines data risk as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events, impacting on data. The guide states that data risk is relevant regardless of whether the data is held in hard copy or electronically.
Does a 2013 guide still matter for AI work?
Its subject matter does. Paragraph 3 already identified process automation and greater reliance on analytics as drivers of data dependence. The guide predates generative AI, so it names no model-specific control, and an entity should read it alongside the current operational risk and information security standards.

Primary sources

← Back to the glossary

General information and education only. Not legal, compliance, financial, or professional advice. Always confirm obligations against the primary source and current regulator guidance.