APRA CPS 234 has been in force since 1 July 2019, and most Australian banks, insurers and superannuation funds long ago ticked the box that says “we are compliant”. The uncomfortable question, seven years on, is whether that box still reflects reality — because the standard is written in terms of outcomes and capability, not a fixed control list, and the environment it governs has changed enormously. Identity is where that gap shows up first. This article sets out a practical CPS 234 compliance checklist through an identity security lens: what the standard actually asks for, where identity controls typically fall short, and what evidence a board or an APRA reviewer will expect to see.
What CPS 234 requires — in plain terms
Prudential Standard CPS 234 Information Security applies to APRA-regulated entities: authorised deposit-taking institutions, general and life insurers, private health insurers, and RSE licensees. Its objective is straightforward — an entity must maintain information security capability commensurate with the size and extent of the threats it faces, so it can continue to operate soundly if an incident occurs.
Stripped of the legal drafting, the standard imposes a handful of obligations that matter operationally:
- Board accountability. The Board is ultimately responsible for the entity’s information security. Roles and responsibilities across the Board, senior management and governing bodies must be clearly defined.
- Information asset identification and classification by criticality and sensitivity — including assets managed by third parties.
- Controls commensurate with the threat, implemented to protect those assets, with the vulnerabilities and threats considered explicitly.
- Systematic testing and assurance of control effectiveness, with a testing programme whose frequency reflects the rate of change in the environment.
- Internal audit review of the design and operating effectiveness of information security controls, including those of third-party providers.
- Incident detection, response and notification — including notifying APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after identifying a material control weakness the entity does not expect to remediate in a timely manner.
- Third-party assurance where information assets are managed by a service provider.
Note the recurring word: commensurate. CPS 234 does not tell you which multi-factor authentication method to deploy. It asks you to demonstrate that your control set is proportionate to your risk, and that you have tested it well enough to know. That is a much harder standard to satisfy with a spreadsheet.
The CPS 234 identity security checklist
Identity is not named as a separate chapter in the standard, but it sits underneath almost every clause. Access is the control layer that determines whether an information asset is actually protected, and identity systems are themselves critical information assets. Work through the following.
1. Are your identity systems classified as critical information assets?
Directory services, single sign-on, the privileged access vault, the identity governance platform and the MFA service are not supporting infrastructure — they are the control plane for everything else. Many asset registers still classify them as internal IT tooling. If your identity provider is compromised, every downstream classification becomes theoretical. Classify accordingly, and make sure the register reflects the SaaS identity services you have adopted since the register was last reviewed.
2. Can you produce a complete, current inventory of privileged access?
This is the single most common evidence gap. Named administrators are usually well documented; what tends to be missing are service accounts, embedded credentials in scripts and pipelines, break-glass accounts, vendor support access, and standing cloud roles with entitlements nobody has reviewed. If you cannot answer “who and what holds privileged access to this asset today” within a working day, the underlying control cannot be said to be effective. A structured privileged access management capability exists precisely to make that answer available on demand.
3. Is access granted on entitlement, and removed on change?
Joiner-mover-leaver is where policy meets payroll. Leavers are typically handled well because they trigger an obvious event. Movers are not: someone transfers from operations to finance and accumulates both entitlement sets. Over a few years, this produces the privilege creep that turns a single compromised account into an enterprise-wide incident. Recertification campaigns are the standard answer, but they only work if reviewers are given meaningful context rather than a list of cryptic group names to rubber-stamp.
4. Are third-party and non-human identities inside the same control set?
CPS 234 explicitly extends to information assets managed by related parties and third parties. In practice, that means the managed service provider’s engineers, the offshore development team, the integration partner’s API credentials and the automation accounts running in your pipelines all sit within scope. Machine identities now routinely outnumber human ones in cloud estates, and they rarely pass through the same governance. APRA’s expectation is not that you own every control, but that you have assessed the provider’s capability and can evidence that assessment. The tightening of service provider expectations under CPS 230 Operational Risk Management has raised the bar here further.
5. Do you test identity controls, or only document them?
“Systematic testing” is a deliberate phrase. A policy stating that MFA is enforced is not evidence; a test result showing that authentication without a second factor was attempted and blocked — across every access path, including legacy protocols and emergency routes — is. The paths that fail testing are almost always the exceptions: the legacy application that could not support modern authentication, the VPN bypass created during a migration, the vendor account exempted “temporarily” in 2023.
6. Would your incident response plan survive an identity compromise?
Most response plans assume the identity system is available and trustworthy during the incident. If the directory itself is the compromised asset, how do you authenticate responders, revoke sessions at scale, or issue emergency credentials? Test that scenario specifically. It also sharpens the 72-hour notification clock: you cannot assess materiality without knowing which identities were affected and what they could reach, which brings you straight back to points 1 and 2.
7. Can internal audit form an independent view?
The standard requires internal audit to review design and operating effectiveness. That requires audit to have access to identity data and enough capability to interpret it. Where the identity function also produces the evidence and defines the tests, independence is weak. Sequencing an external assessment before your next internal audit cycle is a reasonable way to find the gaps on your own terms.
Where compliance programmes typically go wrong
Three patterns recur across Australian financial services engagements.
Point-in-time attestation. An assessment is completed, findings are remediated, and the artefacts age quietly for eighteen months while cloud migrations and new SaaS adoption change the estate underneath. CPS 234 asks for a capability that is maintained, not a project that was completed.
Treating identity as an IT deliverable. When the identity roadmap lives entirely inside infrastructure, business context — who should hold which entitlement and why — never reaches the control design. Recertification then becomes a compliance ritual instead of a risk decision. If the distinction between broad access governance and privileged control is unclear in your organisation, our explainer on IAM vs PAM and why Australian enterprises need both is a useful starting point.
Evidence that cannot be produced on demand. The remediation is genuine, but the proof is scattered across ticketing systems, vendor portals and email threads. Assurance work then costs more than the control itself. Design the evidence trail at the same time as the control — automated access reviews, exportable entitlement reports and logged approvals — rather than reconstructing it under review pressure.
Turning the checklist into a programme
The sequencing that works is unglamorous: establish the asset and access inventory first, because nothing downstream is credible without it; close privileged access gaps next, because that is where the material risk concentrates; then move to governance, recertification and automated evidence; and finally build testing into business-as-usual rather than treating it as an annual event. Aligning that roadmap with related obligations — the Essential Eight, CPS 230, and your own operational resilience commitments — avoids running three overlapping programmes with three sets of evidence.
Delivery Centric works with Australian banks, insurers and superannuation funds on exactly this problem, from enterprise identity design and implementation through to governance, privileged access and ongoing assurance. If you are approaching an internal audit cycle, an independent assessment, or a cloud migration that changes your control landscape, a focused gap review against CPS 234 is a sensible first step — and considerably cheaper than discovering the gap during an incident.
If you would rather build this capability in-house, we are also hiring identity and cyber security consultants across Australia and APAC — see our current openings. Otherwise, get in touch and we will talk through where your programme actually stands.
Recent Comments