Industry asked APRA to exempt cloud and information technology providers from the CPS 230 contract requirements. APRA published a list of seven categories instead, and none of them is a technology vendor. That single decision, recorded in a consultation response most people skipped, settles an argument that has been running quietly inside risk committees since the transition deadline passed: whether "the vendor would not change the terms" is a position or a gap.
It is a gap. APRA has now shown, in writing, what it accepts as a genuine inability to negotiate, and drawn the perimeter somewhere else. This is the question that sits immediately after the CPS 230 contract deadline caught up with AI vendors: not what to remediate before the date, but what to do about the arrangements that were never remediated.
On 30 April 2026 APRA wrote to all regulated entities finalising targeted amendments to CPS 230, CPG 230 and the Material Service Provider Register Template. The amendments came into effect on 1 July 2026, the amended standard is made by determination F2026L00475, still recorded on the Federal Register as in force and current as at 17 September 2026, and they create the first relief from CPS 230's contractual requirements since the standard commenced.
What did APRA actually change?
CPS 230 requires a formal legally binding agreement for every material arrangement, and it prescribes the minimum contents. The agreement must specify services and service levels, set out rights and responsibilities including ownership and control of data, audit access, liability and indemnity, include provisions ensuring the entity can meet its legal and compliance obligations, require notification where the provider relies on other material service providers, make the provider liable for sub-contractor failure, carry a force majeure provision and carry termination rights. Separately, the agreement must include provisions that allow APRA access to documentation and data, allow APRA an on-site visit, and ensure the provider agrees not to impede APRA.
That is a demanding set of clauses to obtain from a counterparty who has never heard of APRA.
Paragraph 57 of the amended standard now says an entity "need not comply with the requirements in paragraphs 53, 54, 55(d), 59(a) and 59(c) for a material arrangement if: the arrangement is with a service provider that falls within a category listed in the Attachment to this Prudential Standard; and the arrangement uses standardised terms or is not documented in a formal agreement."
Both limbs. A listed provider that you did negotiate a bespoke contract with is not exempt, and an unnegotiable provider that is not on the list is not exempt either.

Who is on the list?
Seven categories, each with a definition in the Attachment to the standard: government agencies, regulators, central banks, financial market exchanges, operators of clearing and settlement facilities, operators of payment systems and schemes, and financial messaging infrastructures. The government agencies definition adds a boundary of its own, stating that the exemption does not extend to government business enterprises.
Read them together and the logic is obvious. These are counterparties a bank or insurer cannot meaningfully bargain with because of what they are, not because of how the commercial conversation went. You do not negotiate audit access with the Reserve Bank. You do not put a force majeure clause to a licensed clearing and settlement facility. The relationship is structural.
APRA's own framing in the letter is that the exemption covers "certain categories of non-traditional service providers (NTSPs), like central banks and clearing and settlement facilities, where contractual compliance is not practicable".
Why were cloud and technology left out?
Because someone asked, and APRA answered. This is the part of the document worth reading twice.
The consultation summary records that "some submissions recommended including a broader set of exempt provider types (compared with the illustrative list included in consultation). For example: information technology and cloud infrastructure, communications providers, digital wallet providers, and ADIs and correspondent banks."
APRA's response: "APRA has refined how exempt categories are defined but has not materially changed the scope." And then the reasoning, which is the sentence that matters most: "While APRA recognises that contract uplift has taken longer than expected with some types of service providers, the exemptions are reserved for types of provider where there is a universal contract gap and inability to negotiate bespoke terms."
Two ideas are doing work there. Universal means the gap has to be a property of the provider category, not of your particular commercial position. And APRA's acknowledgement that uplift "has taken longer than expected with some types of service providers" is a direct statement that slow progress was heard, considered, and treated as a reason to keep the pressure on rather than release it.
The second limb of the test carries the same message. APRA records that there was "general support for the second limb", specifically that "entities would still be expected to have CPS 230 compliant agreement for services where it is possible to have a bespoke contract". Possible, not easy.

What does this mean for AI arrangements?
AI providers are the sharpest case of the problem the exemption does not solve. A frontier model vendor typically offers standard commercial terms, changes the model on its own release schedule, relies on hyperscaler infrastructure it will describe only in general terms, and has no reason to grant an Australian prudential regulator a right of on-site visit. Every one of those facts makes the CPS 230 contract requirements hard to meet, and none of them puts the provider inside the perimeter.
Note the definition. CPS 230 says standardised terms means "the terms prepared by a service provider where a regulated entity has no, or substantially no, ability to negotiate or amend rights and obligations relating to matters covered by this Prudential Standard." Your AI vendor's terms may satisfy that description precisely. It does not help, because limb (a) fails.
There is a route, and it is a narrow one. APRA "may, by written notice to an APRA-regulated entity, exempt an arrangement with a service provider that does not satisfy the conditions set out in paragraphs 57(a) or 57(b)". That is a decision APRA makes and communicates in writing, on a case-by-case basis. It is not a position an entity adopts and documents internally. And the direction of travel is stated plainly: "Over time, as domestic and international operational resilience practices mature, APRA expects the scope of exemptions to narrow rather than expand."
What survives when the contract does not?
Everything else. APRA's letter is unusually direct: "The exemption applies only to the specified CPS 230 contractual requirements. All other CPS 230 requirements continue to apply. These amendments do not reduce the expectation that regulated entities actively manage the operational risks arising from reliance on these service providers."
That is the practical instruction even for entities that do qualify, and it is the whole instruction for entities that do not. The standard still requires you, for each material arrangement, to identify and manage risks that could affect the provider's ability to deliver on an ongoing basis, to identify and manage risks such as step-in and contagion, and to be able to execute your business continuity plan. APRA also retains the power to require an entity to review and change a service provider arrangement where it identifies heightened prudential concerns.
The orderly exit requirement is not on that list, and this is the detail worth reading the numbers for. Paragraphs 53 and 54 are the formal agreement with its minimum contents and the APRA access provisions. Paragraph 55(d) is the requirement to be able to conduct an orderly exit, and paragraphs 59(a) and 59(c) are the monitoring of performance against agreed service levels and of both parties' compliance with the agreement. All five are switched off for a qualifying arrangement, so the exemption reaches further than the drafting. For a provider that is not on the list, none of it is switched off at all.
APRA does concede that the work looks different where a contract cannot carry it. In the consultation response it accepts that "risk management may look different for arrangements with exempt service providers given information asymmetry, market dynamics and structure", and CPG 230 was updated so that "due diligence and selection processes may look different for an exempt service provider compared to other material service providers".
Different, and still evidenced. That distinction is the one to carry into your next vendor review.

How do you evidence a gap you cannot close?
The honest position is a documented one. If an AI arrangement is material and its terms will not move, the file should show four things, and the first is the one most registers skip.
First, the classification decision. Is this a material arrangement, and on what basis? The Material Service Provider Register Template now lets entities classify arrangements as exempt, which also means the register is where an incorrect exemption claim will be visible.
Second, the specific requirement that cannot be met, named at clause level rather than described as "contract gaps". Audit access is a different problem from fourth-party notification, and they fail for different reasons.
Third, what replaces it. If the provider will not accept an APRA access clause, what does your evidence pack contain instead, and who produces it. If the provider will not notify you of material sub-processors, what monitoring detects a change. If termination rights are thin, what does an orderly exit actually look like, and has anyone tested it.
Fourth, the accountability. Someone is accountable for the residual risk, that person should be named, and under the Financial Accountability Regime the question of who that is will not stay theoretical.
Two adjacent controls are worth checking at the same time, because both depend on terms you may not have. Notification is one: an AI vendor breach starts a clock you may not control, and the contractual notification limb is exactly what a standard-terms arrangement tends to omit. Continuity is the other: every model has a retirement date, so an exit you cannot execute is not an exit, whatever the register records. Neither of these is discharged by a clause you did not get, and because an AI vendor is not on the list, neither is switched off by the exemption either.
The bottom line
- APRA's targeted CPS 230 amendments took effect on 1 July 2026 and create a limited exemption from specified contractual requirements for seven listed provider categories on standardised terms.
- Both limbs of paragraph 57 must be met. Being unnegotiable is not enough if the provider is not listed.
- Industry asked for information technology and cloud infrastructure to be added. APRA did not materially change the scope, and reserved exemptions for categories with a universal contract gap.
- Everything other than the specified contractual requirements continues to apply, including the obligations to manage provider risk and execute a business continuity plan. The orderly exit requirement in paragraph 55(d) is itself one of the requirements the exemption switches off, so it survives only where the arrangement is not exempt.
- APRA expects the scope of exemptions to narrow rather than expand, so a strategy built on future relief is a strategy with a stated direction against it.
Do this Monday
- Pull your material service provider register and mark every arrangement someone has treated as exempt. Test both limbs of paragraph 57 on each one, and expect some to fail on limb (a).
- List the AI and AI-dependent arrangements where the contract requirements were never fully met, and name the specific clauses that are missing rather than recording a general gap.
- For each of those, write the compensating control on one page: what the clause would have given you, what you do instead, who performs it, and what record it produces.
- Check whether an orderly exit from your most material AI arrangement has ever been tested, as opposed to described. If it has not, book the test.
- Take one arrangement to your next operational risk forum with the gap, the compensating control and a named accountable owner, and see whether the forum accepts it. That is the rehearsal for the supervisory conversation.
- Read APRA's consultation response in full. Attachment A answers nine issues in a single table, and it tells you which arguments the regulator has already heard and rejected.
References
- APRA, Final targeted amendments to CPS 230 Operational Risk Management, 30 April 2026
- Federal Register of Legislation, Banking, Insurance, Life Insurance, Health Insurance and Superannuation (prudential standard) determination No. 1 of 2026, F2026L00475, which makes the amended Prudential Standard CPS 230, registered 29 April 2026
- APRA, Operational risk management consultation page
- APRA letter to industry on artificial intelligence, 30 April 2026
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.
TheAICommand. Intelligence, At Your Command.


