EVOLUTN. ← BACK TO PERSPECTIVES
PERSPECTIVE· SERIES: MANDATE, MONEY AND USE · PART ONE· SEP 2026

CPS 230 never mentions data governance, but cannot be satisfied without it

Data governance has spent twenty years failing for want of a mandate and a budget. Both have now arrived: the mandate from APRA, the budget from enterprise AI. Neither addresses the reason governance decays, which is what this series sets out to argue. This first part deals with the mandate.

01 · THE MANDATE 02 · THE MONEY 03 · USE

The failure pattern is old, and its cause is not technical

Anyone who has run or observed an enterprise data governance programme recognises its shape. The programme opens with executive sponsorship and a budget. The catalogue is populated. Stewards are appointed and named in a policy document. Over the following two years those stewards move roles without replacement, exceptions accumulate, and the written policy separates from what people actually do. The catalogue continues to describe the organisation as it stood on the day the project closed: accurate as history, useless as control. Somebody then proposes a new data governance initiative.

Gartner puts a figure on the outcome, forecasting that 80 per cent of data and analytics governance initiatives will fail by 2027, and the attributed cause deserves closer reading than it usually gets. Gartner does not blame inadequate tools, poor data quality or the size of the estate. It blames the absence of a real or manufactured crisis, and states the test plainly: “A D&A governance program that does not enable prioritized business outcomes fails” (Gartner 2024).

18-MONTH CEILING LAUNCH POPULATED STEWARDS DRIFT STALE CATALOGUE HIGH LOW
FIG. 01 — The governance decay curve: sponsorship, population, drift

Two such crises have arrived within eighteen months of each other. APRA has made governance artefacts prudential evidence, and enterprise AI has produced a sponsor whose own objectives fail without them. The argument of this series is that neither will produce a working data governance capability, because both act on the supply of mandate and money while the failure has always occurred somewhere else: at the point where an accountable person is asked to maintain a record they cannot practically reach. Part two deals with the money and part three with that constraint. This part deals with the mandate, which arrived first and is the more concrete of the two.

An operational risk standard with a data governance core

Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025, replacing APRA's earlier outsourcing and business continuity standards for banks, insurers and superannuation trustees (APRA 2023a). It obliges an entity to identify its critical operations, set tolerance levels for the maximum disruption it will accept, maintain a credible continuity capability, and manage the risks presented by material service providers.

The data obligation is written in, not implied. APRA names data risk among the operational risks an entity must manage, alongside technology, legal, compliance, conduct and change risk. Entities must also identify and document the resources needed to deliver each critical operation, and those resources expressly include information and key data, together with their interdependencies and controls (APRA 2023a).

The practical consequences follow immediately. A board can name its critical operations, but it cannot map or manage them to the standard without knowing which information assets each operation consumes. Setting or testing a disruption tolerance requires lineage, meaning a documented path from source to user. Sustaining a defensible operational risk profile requires treating information assets as primary components of that profile, alongside people, technology and premises.

Consider a superannuation trustee's benefit-payment operation. Its credibility under the standard depends on the trustee understanding every upstream feed the payment relies on, including member records, unit pricing and banking details, together with the material service providers behind each. That is a lineage exercise before it is anything else, and metadata management is what keeps it current rather than leaving it as a one-off assessment. Data quality then operates as a control in its own right, because tolerance monitoring built on unreliable data produces unreliable declarations. The same holds for access control and retention: notifying APRA of a material operational risk incident within the 72-hour window requires an entity to locate, verify and produce incident data quickly (APRA 2023a).

The artefacts have not changed. Their status has

APRA's interest in data is not new. CPG 235 has set out expectations for managing data risk since 2013, and CPS 234 has required entities to identify and classify information assets by criticality and sensitivity since 2019 (APRA 2013; APRA 2019a). What CPS 230 changes is not the requirement but its purpose. Those artefacts now sit beneath the board's annual risk management declaration under CPS 220, and beneath the accountability statements executives lodge under the Financial Accountability Regime, which attaches personal consequences to named individuals.

APRA has thereby redrawn a boundary that has held for two decades. The chief risk officer's declaration now depends on the completeness of the chief data officer's catalogue. Catalogue coverage and lineage accuracy have become matters the risk function must assure, rather than housekeeping the data office performs at its own pace. In our experience of implementation work, a data governance framework that exists in a policy document but not in an accountability map does not survive supervisory review; that is our observation, not a requirement quoted from the standard.

An entity can outsource an operation but never its responsibility. A catalogue full of lineage is inert until someone accountable signs it.

DATA OFFICE CDO Catalogue · Lineage Quality · Ownership RISK OFFICE CRO Operational Risk Profile · Declaration EVIDENCE BOARD DECLARATION
FIG. 02 — The redrawn boundary: CDO catalogue ownership feeding the CRO's risk profile

The consequences are priced in capital, not fines

CPS 230 carries no fixed civil penalty. That should comfort nobody, because APRA's preferred instruments cost more: capital overlays, licence conditions, enforceable undertakings, and for individuals, consequences under the Financial Accountability Regime (Gilbert + Tobin 2025).

The precedents below predate CPS 230, so they evidence APRA's instruments and appetite rather than the standard itself. They are no less instructive for that.

Westpac is the cautionary case with a data failure at its centre. The bank failed to report more than 19.5 million international funds transfer instructions to AUSTRAC over roughly six years, a breakdown attributed substantially to technology failings including a reporting feed failure that went undetected, and it agreed a $1.3 billion Federal Court penalty in 2020 (AUSTRAC 2020). APRA had separately imposed $1 billion in operational risk capital add-ons during 2019 over risk governance concerns, in two tranches of $500 million. The final tranche was removed on 15 October 2025, after Westpac completed the multi-year risk transformation programme required under a court enforceable undertaking given in December 2020. The capital penalty stood for roughly six years (APRA 2019b; APRA 2025).

Medibank supplies the data-specific analogue. Following its 2022 cyber incident, APRA applied a $250 million capital adjustment reflecting weaknesses in the insurer's information security environment (APRA 2023b). Medibank's half-year report for the period ended 31 December 2025 records that “at 31 December 2025 this requirement remains in place” — two and a half years after it was imposed (Medibank 2026).

In the United Kingdom, the Financial Conduct Authority and the Prudential Regulation Authority together fined TSB £48.65 million for operational resilience failings arising from its 2018 IT migration, a failure rooted in inadequate management of a critical third-party supplier — precisely the material service provider risk CPS 230 addresses (FCA 2022; Bank of England 2022).

$1.3bn WESTPAC AUSTRAC PENALTY · 2020 $1.0bn WESTPAC CAPITAL ADD-ON · 2019 $250m MEDIBANK CAPITAL ADJ. · 2023 £48.65m TSB FCA & PRA FINE · 2022
FIG. 03 — Penalty, capital and enforcement precedents for weak operational evidence.
Bars are scaled linearly on nominal amounts; the TSB figure is in pounds sterling and is not currency-adjusted.

The common feature is an absence of visibility. In each case the institution could not demonstrate how its critical operations depended on particular data, systems and suppliers until after the failure occurred. Under CPS 230, that absence is no longer merely a weakness exposed by an incident. It is a continuing non-compliance that APRA can examine at any time.

The transitional arrangements have expired

Both concessions ended on 1 July 2026: the deferral of business continuity and scenario analysis requirements for entities below APRA's significant financial institution threshold, and the grandfathering of service provider contracts entered into before commencement (MinterEllison 2024; APRA 2026b). APRA's targeted amendments, finalised on 30 April 2026, commenced on the same date and introduce limited exemptions from specific contractual requirements for material arrangements with non-traditional service providers such as central banks and clearing and settlement facilities, where contractual compliance is impracticable (APRA 2026a). Every other obligation now applies to every regulated entity.

APRA is also unlikely to relax what it expects by way of evidence. The regulator has signalled a firmer supervisory and enforcement posture on operational resilience, and has indicated it may consult on a formal reporting standard for CPS 230 by 2028, which would convert today's supervisory requests into standing regulatory returns (Gilbert + Tobin 2025; MinterEllison 2024).

What to do now

Three actions follow directly from the mandate. They are sequenced, because each creates the conditions the next depends on.

01
Close material service provider contract gaps.

Any agreement not updated to CPS 230 terms, outside the exempt categories, has been a live non-compliance since 1 July 2026. Sequence remediation by the criticality of the operations each provider supports, not by contract value.

02
Reconcile the critical operations map against data lineage.

Confirm that the entity can evidence, today, every information asset and provider dependency behind each critical operation. Gaps here undermine every declaration built on top of them.

03
Practise producing evidence, rather than only responding to incidents.

Scenario exercises should include assembling the incident data and notifications APRA may demand within its stated timeframes. The first genuine test of an entity's data management under CPS 230 will be a supervisory request, not an incident.

Institutions that treated the transition as a project deadline have achieved compliance. Those that treated it as an operating model redesign hold something more durable: a continuously evidenced account of how their business actually runs. As Westpac's six-year remediation shows, the distance between the two is measured in capital, in time and in supervisory patience.

DISCUSS THIS
Is your evidence attestable, or just accumulated?
Book an intro conversation →
REFERENCES

APRA (2013) Prudential Practice Guide CPG 235 Managing Data Risk, Australian Prudential Regulation Authority, September 2013. apra.gov.au

APRA (2019a) Prudential Standard CPS 234 Information Security, Australian Prudential Regulation Authority, July 2019. apra.gov.au

APRA (2019b) APRA launches Westpac investigation and increases capital requirement add-ons to $1 billion, Australian Prudential Regulation Authority. apra.gov.au

APRA (2023a) Prudential Standard CPS 230 Operational Risk Management, Australian Prudential Regulation Authority. apra.gov.au

APRA (2023b) APRA takes action against Medibank Private in relation to cyber incident, Australian Prudential Regulation Authority, 27 June 2023. apra.gov.au

APRA (2025) APRA confirms Westpac has met the obligations of the Court Enforceable Undertaking, Australian Prudential Regulation Authority, 15 October 2025. apra.gov.au

APRA (2026a) APRA finalises targeted amendments to CPS 230 Operational Risk Management, Australian Prudential Regulation Authority, 30 April 2026. apra.gov.au

APRA (2026b) Operational risk management (consultation and implementation page), Australian Prudential Regulation Authority. apra.gov.au

AUSTRAC (2020) AUSTRAC and Westpac agree to proposed $1.3bn penalty, Australian Transaction Reports and Analysis Centre, 24 September 2020. austrac.gov.au

Bank of England (2022) TSB fined for operational resilience failings, Prudential Regulation Authority news release, 20 December 2022. bankofengland.co.uk

FCA (2022) TSB fined £48.65m for operational resilience failings, Financial Conduct Authority, 20 December 2022. fca.org.uk

Gartner (2024) Gartner Predicts 80% of D&A Governance Initiatives Will Fail by 2027, Due to a Lack of a Real or Manufactured Crisis, press release, 28 February 2024. gartner.com

Gilbert + Tobin (2025) APRA enforcement of operational resilience & cyber preparedness. gtlaw.com.au

Medibank Private Limited (2026) HY26 Results — Appendix 4D and Financial Report, half year ended 31 December 2025. medibank.com.au

MinterEllison (2024) APRA's final guidance on CPS 230. minterellison.com