rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/iso-22301-business-continuity-cps-230
Printed 28 August 2026
ISO 22301 business continuity and APRA CPS 230: how the standard supports the prudential requirement
How ISO 22301 business continuity management supports APRA CPS 230: impact analysis, tolerance levels, testing, service providers, and where CPS 230 goes further.
ISO 22301:2019 specifies requirements for a business continuity management system (BCMS). APRA's Prudential Standard CPS 230 Operational Risk Management, which commenced on 1 July 2025, imposes business continuity obligations on APRA-regulated entities that overlap heavily with the standard — and diverge in ways that matter.
This article maps one onto the other, and sets out what an APRA-regulated entity cannot get from certification alone.
Does ISO 22301 satisfy CPS 230?
No. Certification to ISO 22301 does not satisfy CPS 230, and APRA does not recognise it as doing so.
CPS 230 is a prudential standard with its own defined concepts — critical operations, tolerance levels, material service providers — that do not appear in ISO 22301 in the same form. An entity can hold a valid ISO 22301 certificate and still fail a CPS 230 review because it has not identified its critical operations to APRA's definition or set tolerance levels the board has approved.
What ISO 22301 does provide is the management-system discipline underneath: the analysis method, the plan structure, the exercise regime and the review cycle. Entities that already ran a certified BCMS found the CPS 230 uplift materially smaller. See our standalone guide to CPS 230 operational risk management, the obligation cps-230-operational-risk, and check your position with the CPS 230 readiness scorer.
What ISO 22301 requires
ISO 22301 requires a management system for protecting against, reducing the likelihood of, preparing for, responding to and recovering from disruptions. The catalogue entry is ISO 22301:2019, with implementation guidance in ISO 22313:2020.
The distinctive requirements, on top of the harmonised clause 4 to 10 structure:
- Business impact analysis (BIA) — identify activities supporting products and services, assess impacts over time of not performing them, and set prioritised timeframes for resumption.
- Risk assessment of disruption to prioritised activities.
- Business continuity strategies and solutions selected on the BIA and risk assessment, with resource requirements identified.
- Business continuity plans and procedures with defined roles, activation criteria, communications and interdependencies.
- Warning and communication procedures, internal and external.
- Exercise programme to validate strategies and plans over time.
- Evaluation of business continuity documentation and capabilities, including after disruptions.
Like the other Type A standards it carries the 2024 climate action amendment — see ISO 22301:2019/Amd 1:2024.
The BIA is the load-bearing element. Everything downstream — recovery objectives, resourcing, plan design, exercise scenarios — derives from it, and a BIA that was done once and never revisited invalidates the rest.
Business impact analysis vs critical operations and tolerance levels
The vocabularies look similar and are not interchangeable. This is the most common source of confusion in a CPS 230 program built on an existing BCMS.
| ISO 22301 concept | CPS 230 concept | The difference |
|---|---|---|
| Prioritised activities | Critical operations | CPS 230 defines critical operations by reference to processes whose disruption would have a material adverse impact on depositors, policyholders, beneficiaries or the financial system — a prudential test, not an internal-impact test |
| Prioritised timeframes for resumption | Tolerance levels | Tolerance levels must be board-approved and expressed as the maximum period of disruption, maximum data loss and minimum service levels the entity would accept |
| Resource requirements | Resources needed to maintain critical operations within tolerance | CPS 230 ties resourcing explicitly to the tolerance levels the board has set |
| Suppliers in the BIA | Material service providers | CPS 230 imposes a defined register, contractual requirements and notification obligations for material service providers |
The practical consequence: an entity migrating from a BCMS to CPS 230 cannot simply relabel its prioritised activities as critical operations. The prudential test looks outward at impact on beneficiaries and the financial system; the BIA looks inward at impact on the organisation. The two sets overlap but are not the same, and an activity that is commercially important may not be a critical operation while one that is commercially minor may be.
Mapping ISO 22301 to CPS 230
Where a certified BCMS does most of the work:
- Governance and policy. ISO 22301 clause 5 leadership requirements align well with CPS 230's board accountability, though CPS 230 assigns specific board responsibilities that must be evidenced in board papers.
- Impact analysis method. The BIA method transfers directly; the classification criteria must be re-derived against the prudential test.
- Plans and procedures. Plan structure, activation criteria, roles and communications transfer largely intact.
- Exercise programme. Transfers, but scenario severity must be raised — see below.
- Post-incident review. ISO 22301's evaluation-after-disruption requirement aligns with APRA's expectation that incidents drive framework change.
- Continual improvement. The corrective action machinery is the same.
Where the certified BCMS gives you a head start but not the answer:
- Third parties. ISO 22301 requires you to consider suppliers in continuity planning. CPS 230 requires a material service provider register, specific contract terms, and notification to APRA. Transitional arrangements applied requirements to pre-existing service provider contracts from the earlier of the next renewal date or 1 July 2026.
- Data loss tolerance. ISO 22301 addresses recovery point objectives implicitly through resource requirements; CPS 230 requires the maximum acceptable data loss to be an explicit, approved tolerance.
APRA's own material sits at the CPS 230 standard page. Rules Mate profiles the regulator at /regulators/apra.
Where CPS 230 goes beyond the standard
Five requirements have no ISO 22301 equivalent.
- Board approval of tolerance levels. Not a management decision. The board sets and approves the tolerance for maximum disruption period, maximum data loss and minimum service levels for each critical operation.
- Material service provider register, submitted to APRA. A register requirement with a supervisory reporting dimension, plus prescribed contractual provisions and an obligation to notify APRA about certain arrangements.
- Operational risk profile and controls testing. CPS 230 requires assessment of the operational risk profile with a defined appetite supported by indicators, limits and tolerance levels, and internal controls that are designed and operating effectively — a broader operational risk requirement, not just continuity.
- Incident notification to APRA. Prudential notification obligations with defined timeframes. ISO 22301 requires internal and external communication planning; it does not create a regulator notification duty.
- Interaction with CPS 234. Information security obligations run in parallel, including their own incident notification. The two standards ask different questions about the same incident — see CPS 230 vs CPS 234 and the obligation cps-234-information-security. Map your notification obligations once, across regimes, using the cyber incident notification tool.
CPS 230 also absorbed the ground previously covered by CPS 232 Business Continuity Management. If your continuity documentation still references CPS 232 as the operative standard, it is out of date — see what CPS 232 required before CPS 230 took over.
Testing and exercising: the evidence that survives review
Both regimes require testing, and both are usually failed on the quality of the evidence rather than the absence of it.
CPS 230 expects business continuity plans to be tested regularly with severe but plausible scenarios. That phrase does the work. A test that assumes the primary data centre fails and the secondary works, that everyone is available, and that the third-party provider responds within its SLA is not severe but plausible — it is convenient.
Evidence that holds up:
- A scenario library with documented rationale for severity, refreshed as the threat environment changes.
- Scenarios that stress the actual dependency, including concurrent failure of a material service provider and loss of key personnel.
- Participant records showing the people who would actually respond took part, including executives.
- Timed observations against the approved tolerance levels — did we recover within the maximum period, and what was the actual data loss.
- Findings raised as corrective actions, with owners, dates and verification of effectiveness.
- Evidence the plan changed as a result.
An exercise report that concludes everything worked is a warning sign. Exercises that surface nothing usually were not severe enough.
For non-APRA businesses: why the standard still earns its keep
Most Australian businesses are not APRA-regulated, and ISO 22301 still earns its place for three reasons.
Procurement. Enterprise and government buyers increasingly ask for continuity evidence in supplier questionnaires. A certified BCMS answers the question in one document.
Critical infrastructure. Responsible entities under the SOCI regime must address hazards including those causing disruption in their risk management program, and have mandatory cyber incident reporting timeframes — see SOCI mandatory cyber incident reporting.
Insurance and contractual exposure. Continuity capability affects business interruption cover and the practical ability to meet contractual service commitments during a disruption.
For organisations without a regulatory driver, the pragmatic path is to implement the ISO 22301 method — BIA, strategies, plans, exercises, review — without pursuing certification until a customer asks for it. The analysis is where the value sits; the certificate is a market signal. For the wider financial services context, see the financial services topic hub.
Frequently asked
Does ISO 22301 certification satisfy APRA CPS 230?
No. CPS 230 uses defined prudential concepts — critical operations, board-approved tolerance levels and material service providers — that do not appear in ISO 22301 in the same form. A certified BCMS substantially reduces the CPS 230 uplift, but an entity can hold a valid certificate and still fail a CPS 230 review.
What is the difference between a prioritised activity and a critical operation?
A prioritised activity under ISO 22301 is identified by internal impact analysis. A critical operation under CPS 230 is identified by a prudential test — whether disruption would have a material adverse impact on depositors, policyholders, beneficiaries or the financial system. The two sets overlap but are not the same, and neither is a subset of the other.
What does 'severe but plausible' mean for continuity testing?
It means scenarios that genuinely stress the dependency being tested — concurrent failure of a material service provider, loss of key personnel, extended outage beyond the assumed recovery window — rather than convenient scenarios where the failover works and everyone is available. An exercise that surfaces no findings was usually not severe enough.
Is CPS 232 still in force?
CPS 230 commenced on 1 July 2025 and took over the ground previously covered by CPS 232 Business Continuity Management. Continuity documentation that still cites CPS 232 as the operative standard is out of date and should be remapped to CPS 230, including the concepts CPS 232 did not use.
Should a business that is not APRA-regulated bother with ISO 22301?
The method is worth adopting regardless — business impact analysis, continuity strategies, plans, exercises and review. Certification is a market signal worth paying for when enterprise or government buyers ask for continuity evidence in procurement, or when critical infrastructure or contractual obligations create a hard requirement.
How do CPS 230 and CPS 234 incident notifications interact?
They are separate obligations that can both be triggered by the same event, and they ask different questions — one about operational disruption and one about information security. Map notification obligations once, across every regime that applies to you, so a single incident does not produce three uncoordinated assessments under time pressure.
Related
Related reading
APRA CPS 230 Operational Risk Management: The Standalone Deep Dive
Plain-English deep dive on Prudential Standard CPS 230, which commenced 1 July 2025 and replaced CPS 231 Outsourcing and CPS 232 Business Continuity.
APRA CPS 232 Business Continuity: What It Required Before CPS 230 Took Over
Background on Prudential Standard CPS 232 Business Continuity Management, which was absorbed into CPS 230 from 1 July 2025 (with a transition for non-SFIs).
CPS 230 vs CPS 234: how APRA's operational risk and information security standards differ
A side-by-side of APRA's CPS 230 (Operational Risk Management) and CPS 234 (Information Security) — what each covers, who they apply to, commencement dates, and how they fit together.
ISO 31000 risk management: applying the standard to an Australian compliance program
ISO 31000 is guidance, not a certifiable standard. How to apply its principles, framework and process to an Australian compliance program that regulators will accept.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/iso-22301-business-continuity-cps-230