CPS 234 doesn't regulate financial planning practices directly - but it's showing up in more and more of their client and partner agreements anyway. If a bank, insurer, or super fund you work with has started asking pointed questions about your security controls, CPS 234 is very likely the reason why.
What CPS 234 Actually Is
CPS 234 (Information Security) is a prudential standard set by the Australian Prudential Regulation Authority. It requires the entities APRA regulates to maintain information security capability commensurate with the size and extent of threats to their information assets, to clearly assign accountability for information security at the board level, to classify information assets by criticality and sensitivity, to test the effectiveness of security controls, and to notify APRA of material information security incidents within a defined timeframe.
Who CPS 234 Directly Applies To
CPS 234 applies to entities APRA regulates: authorised deposit-taking institutions (banks, building societies, credit unions), general insurers, life insurers, private health insurers, and superannuation trustees. It does not directly apply to financial planning practices, mortgage brokers, accountants, or most professional services businesses, which typically fall under ASIC's regulatory remit rather than APRA's.
Why It Matters Even If It Doesn't Apply to You Directly
The part of CPS 234 that reaches beyond APRA-regulated entities themselves is its requirement that they manage information security risk across their material service providers and third parties, not just their own internal systems. A regulated entity has to satisfy APRA that the organisations it depends on - including advice networks, outsourced service providers, and contracted partners - meet an appropriate security standard, because a weak link anywhere in that chain is treated as the regulated entity's own exposure.
In practice, this is why a Perth financial planning practice aligned with a licensee, or a business providing services to a bank or insurer, increasingly gets asked to complete security questionnaires, provide evidence of controls, or demonstrate alignment with a recognised framework - not because CPS 234 regulates the practice itself, but because the regulated entity above it in the chain is being held accountable for that relationship.
The Practical Controls That Satisfy Most of These Requests
- Multi-factor authentication enforced across email, remote access, and any system holding client data.
- Documented incident response capability - not just tools, but a plan for who does what if something goes wrong, and how quickly.
- Tested, immutable backups that would actually survive a ransomware event affecting production systems.
- Formal access reviews - who has access to client data, whether it's still appropriate, and evidence it's checked periodically rather than set once and forgotten.
- A basic third-party and vendor risk register - knowing what your own suppliers and software vendors can access, and whether their security has ever been assessed.
- Regular staff security awareness training, since most incidents in small advice practices still start with a phishing email rather than a technical exploit.
How CPS 234 Relates to the Essential Eight and ISO 27001
These frameworks aren't competing standards so much as different lenses on largely the same underlying controls. A Perth business already working through the Essential Eight maturity model, or pursuing ISO 27001 pragmatically, will find it's already covering most of what a CPS 234 flow-down security questionnaire is actually asking for. The value in understanding CPS 234 specifically is knowing why the questions are being asked, and being able to answer them with evidence rather than assurances.
Frequently Asked Questions
Does CPS 234 apply directly to my financial planning practice?
In most cases, no. CPS 234 is an APRA prudential standard that directly regulates APRA-licensed entities - banks and other authorised deposit-taking institutions, general and life insurers, private health insurers, and superannuation trustees. A financial planning practice, mortgage broker, or accounting firm is generally regulated by ASIC rather than APRA, and CPS 234 doesn't apply to it directly.
So why would a non-APRA-regulated business ever need to care about it?
Because CPS 234 requires APRA-regulated entities to manage information security risk across their material service providers and third parties, not just internally. If your business is a service provider, adviser network member, or contracted party connected to a bank, insurer, or super fund, that regulated entity may be required to assess your security controls as part of its own compliance - and increasingly asks for evidence, not just assurances.
How quickly does an APRA-regulated entity have to report a security incident?
APRA-regulated entities are required to notify APRA within a short, defined window (commonly cited as 72 hours) of becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or its stakeholders. This obligation sits with the regulated entity itself, but a service provider's own incident often triggers that clock.
Is CPS 234 the same thing as the Essential Eight or ISO 27001?
No, though there's significant overlap in the practical controls involved. CPS 234 is a principles-based prudential standard specific to APRA-regulated entities and their supply chains, the Essential Eight is a technical mitigation framework from the Australian Signals Directorate, and ISO 27001 is an internationally recognised certifiable information security management standard. Meeting a solid Essential Eight maturity level and having ISO 27001-aligned practices in place will satisfy most of what a CPS 234 flow-down request actually asks for.
We help Perth financial services and advice practices build the security controls that satisfy CPS 234 flow-down requests, and provide the evidence to prove it.
Cybersecurity Services →Been asked to complete a security questionnaire by a licensee or partner?
Call 0433 087 091 for a free, no-obligation review of where your current setup stands.
Book a Free ConsultationFor related reading, see our guides to IT Support for Financial Planners in Perth and Essential Eight and Cyber Insurance.