APRA CPS 230 Operational Risk Management in Compliance Assistant
Latest Dynatrace
Explanation
3-min read
Published Sep 28, 2026
What is APRA CPS 230?
APRA CPS 230 Operational Risk Management is a prudential standard issued by the Australian Prudential Regulation Authority (APRA) that requires regulated entities, including banks, insurers, and superannuation funds, to identify, manage, and mitigate operational risks. CPS 230 mandates that entities identify and continuously monitor critical operations, maintain business continuity plans, and actively manage vulnerabilities and information security threats.
Compliance Assistant helps regulated entities manage CPS 230 compliance by mapping critical operations to monitored IT assets, surfacing operational risk signals from security and observability data, and supporting incident detection and management workflows aligned to CPS 230 obligations.
Prerequisites
Required
To use APRA CPS 230 framework in Compliance Assistant, you need to:
Install and configure Business Flow in your Dynatrace environment. At least one business flow must be created with Smartscape entity enabled. Business flows configured this way become available to designate as critical operations in the APRA CPS 230 framework.
Select at least one business flow as a critical operation in the APRA CPS 230 onboarding wizard. Critical operations are the compliance-critical entities used to detect potential incidents, assess economic impact, and track operational exposure. This supports the CPS 230 requirement to identify and document the processes and resources delivering critical operations, along with their interdependencies, risks, and controls (CPS 230 Para. 27(b)). Critical operations are processes that, if disrupted beyond tolerance, would materially impact customers or the financial system (CPS 230 Para. 35).
Recommended
To ensure a better experience, we also recommend that you set up the following:
Runtime Vulnerability Analytics (RVA) for vulnerability signals by severity, assessed over the last 30 minutes.
This adds vulnerability posture to the overall compliance score, supporting the requirement to actively maintain information security capability with respect to changes in vulnerabilities (CPS 230 Para. 25, CPS 234 Para. 17).
Set up Runtime Application Protection (RAP) for security detection findings by severity, assessed over the last 24 hours.
This adds threat detection posture, supporting the requirement to actively maintain information security capability with respect to changes in threats (CPS 230 Para. 25, CPS 234 Para. 17).
Use cases
Manage critical operations as business processes
APRA CPS 230 requires regulated entities to identify and document the processes and resources delivering critical operations, along with their interdependencies, risks, and controls (Clause 27(b)). Critical operations are processes that, if disrupted beyond tolerance, would materially impact customers or the financial system (Clause 35). Compliance Assistant allows you to designate critical operations by mapping compliance-relevant IT assets to end-to-end business processes. Compliance Assistant integrates with Business Flow to identify compliance-critical business process with configuration as an entity.
To add a critical operation
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework APRA CPS 230, select Add critical operations.
From the table, select business processes to add as critical operations.
Select Save to update the compliance framework.
To remove a critical operation
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework APRA CPS 230, select the menu icon of the critical operation to remove.
From the menu, select Remove critical operation.
Select Remove to confirm. Be aware that removing a critical operation impacts all Compliance Assistant users.
To edit the estimated cost per minute of an incident
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework APRA CPS 230, select the menu icon of the relevant critical operation.
From the menu, select Edit incident cost/min.
Add the estimated incident cost per minute to be used to calculate the economic impact of incidents impacting the relevant critical operation.
Select Save.
Continuously monitor operational resilience
Go to Compliance Assistant > APRA CPS 230 > Overview.
Compliance Assistant provides a consolidated view of your organization's CPS 230 operational resilience posture by surfacing operational risk signals across critical operation health, operational risk management, and incident exposure.
The Compliance Snapshot gauge reflects the current CPS 230 compliance risk posture as a tiered score. The score is determined by the most severe active signals.
CPS 230 requires regulated entities to actively maintain information security capability with respect to changes in vulnerabilities and threats (CPS 230 Para. 25, CPS 234 Para. 17). The Operational Risk Management section consolidates critical-severity findings from two integrated capabilities:
Runtime Vulnerability Analytics (RVA)—vulnerability findings by severity and runtime exposure, supporting continuous vulnerability assessment.
Runtime Application Protection (RAP)—security detection findings, providing visibility into active threats and suspicious activity across monitored assets.
Select a tile to go to the relevant capability for investigation and remediation.
Investigate and classify potential compliance incidents
Compliance Assistant:
Is designed to help you manage operational risk incidents in line with APRA CPS 230 requirements.
Automatically classifies incidents and accelerates the assessment of material operational risk events to support your APRA reporting obligations.
Streamlines the assessment of IT-detected incidents affecting business processes configured as critical operations unclassified problems, potential operational risk incidents, and classified material incidents.
Go to Compliance Assistant > APRA CPS 230.
See the Incidents section to see the tables of potential major incidents and unclassified problems.
Select the relevant incident to view the following details on any triggered classification threshold according to the APRA CPS 230 regulation:
Critical operations affected by the incident.
Incident duration, calculated on the basis of the duration of the underlying problem in nanoseconds. The materiality threshold for the classification criterion is met when the duration of the incident is longer than 24 hours.
The economic impact of the incident is calculated on the basis of the estimated incurred cost per minute of the affected critical operations and the duration of the underlying problem. To learn more about configuring the estimated cost value per minute, see Edit the estimated cost per minute of an incident. The materiality threshold for the classification criterion Economic impact is met where the costs and losses incurred by the regulated entity due to the incident have exceeded or are likely to exceed $100,000.
To classify an incident as major in line with APRA CPS 230, from the incident details view, select Classify as material.
Optional Add a comment to document your decision. This comment is added to the incident classification business event.
Select Confirm.
Be aware that classification triggers ingestion of a business event with the details of the classified compliance incident; the process may take a few seconds.
You can view the classified incident in Compliance Assistant > APRA CPS 230 > Incidents > Classified incidents.