Why CPS 230 Changes How Australian Insurers Should Be Writing Technology Contracts
Key Takeaways
-
CPS 230 does not just require insurers to know what their technology vendors do - paragraphs 53 to 55 require a formal, legally binding agreement with specific contractual content: service levels, audit and data access, sub-outsourcing disclosure, sub-contractor liability, force majeure and termination rights.
-
The transition relief for contracts signed before 1 July 2025 runs out at the earlier of contract renewal or 1 July 2026 - and APRA's own April 2026 amendments confirm that mainstream technology and cloud vendors do not get a carve-out from these obligations.
-
Most institutions are still running CPS 230 as a compliance review of existing paper, not a redraft exercise - the two produce very different outcomes when APRA (or a court) asks whether the contract actually allocates the risk it claims to.
-
Redrafting every material contract simultaneously is neither required nor sensible; the standard itself is built around renewal-linked sequencing, which is also how a technically credible delivery partner should approach the work.
-
source[code]'s view: a CPS 230-ready contract is not a legal abstraction - it is a checklist a delivery partner should be able to work through with a client, clause by clause, against the actual language on the page.

Introduction
CPS 230 has been in force since 1 July 2025. Most Australian insurers, banks and superannuation trustees spent the year that preceded it building service-provider registers, running concentration and exit-planning exercises, and briefing boards on third-party risk. That work matters - and this engine has covered it: what the register and exit-planning obligations actually demand (The Vendor Concentration Blind Spot), and what a defensible exit plan contains operationally (The Seven-Part Exit Anatomy).
What has had less attention is the document that everything else in CPS 230 ultimately depends on: the contract itself. APRA's standard does not just ask entities to understand their third-party risk. In paragraphs 53 to 55, it specifies what a legally binding agreement with a material service provider must actually say. Most technology contracts written before mid-2025 - master services agreements, SaaS terms, core-platform licences, claims and policy-administration contracts - were not drafted against that list. They were drafted against a much older assumption: that operational risk from a vendor failure is, to some meaningful extent, the vendor's problem.
CPS 230 removes that assumption. The entity remains accountable to APRA for the outcome regardless of whose infrastructure, whose code or whose staff caused it. That is not a new principle in Australian prudential regulation - the Actuaries Institute has pointed to APRA's response to service disruptions at a large superannuation trustee's administration provider as a clear precedent: APRA imposed additional licence conditions on the trustee itself, not on the provider whose failure caused the disruption. What CPS 230 does is convert that long-standing accountability principle into specific, auditable contract drafting requirements that apply across banking, insurance and superannuation alike. This piece works through what those requirements actually are, where the redrafting effort typically goes wrong, and a structured way to sequence it - because for most insurers, the binding constraint is not legal understanding of the obligation. It is the practical task of getting a large, uneven contract portfolio into a defensible state before the transition relief runs out.
What CPS 230 actually requires of a technology contract
Paragraph 53 of CPS 230 requires an APRA-regulated entity to maintain a formal, legally binding agreement for every material arrangement with a service provider. Paragraph 54 then sets out, in effect, a minimum drafting brief. The formal agreement must, among other things:
- Define the services and the service levels attached to them (54(a)) - not just describe what the vendor does, but specify the standard it is contracted to meet.
- Set out the rights, responsibilities and expectations of each party (54(b)), explicitly including ownership of assets, ownership and control of data, dispute resolution, audit access, liability and indemnity.
- Preserve the entity's ability to meet its own legal and compliance obligations (54(c)) - a clause type many existing vendor contracts simply do not contain, because it exists to serve the customer's regulator, not the commercial relationship.
- Require the service provider to notify the entity of its use of other material service providers it materially relies on (54(d)) - the fourth-party disclosure obligation.
- Make the service provider liable for the failure of any sub-contractor it uses (54(e)) - liability does not stop at the first tier of the supply chain.
- Include a force majeure clause specifying which parts of the contract survive (54(f)).
- Include termination provisions that allow the entity to terminate the arrangement in whole or in part (54(g)).
Paragraph 55 adds a further, less commonly negotiated set of terms: the agreement must give APRA itself access to documentation, data and information about the service, the right to conduct an on-site visit to the service provider, and a commitment from the service provider not to impede APRA in exercising its powers. Very few pre-2025 technology contracts contemplate the regulator having a direct line of access to the vendor's premises and records - because until CPS 230, that was not something the customer's contract needed to secure.
There is a mechanical reason incident notification timelines matter as much as they do. Paragraph 33 of CPS 230 requires the regulated entity itself to notify APRA "as soon as possible, and not later than 72 hours," after becoming aware of an operational risk incident likely to have a material financial impact or to affect its ability to maintain critical operations. That is the entity's clock, not the vendor's. If the vendor's contract only obliges it to notify the entity "promptly" or "without undue delay" - standard boilerplate in most commercial technology agreements - the entity has no way of knowing how much of its own 72 hours it has already lost by the time it hears about the problem. The incident notification clause in a technology contract is not a security formality; it is the input to a regulatory deadline that the entity, not the vendor, is on the hook for.

On timing: CPS 230 commenced 1 July 2025, but APRA built in a transition phase for arrangements already in place, running to the earlier of the contract's next renewal or 1 July 2026. That relief is now closing. In April 2026, APRA finalised targeted amendments creating a narrow contractual exemption for a defined list of non-traditional service providers - government agencies, central banks, financial market exchanges, clearing and settlement facilities, payment system operators and financial messaging infrastructure. Industry submissions had asked for that exemption to extend to IT and cloud providers, communications companies and digital wallet providers on the basis that these vendors run standardised, non-negotiable terms. APRA declined, describing the amended framework as "intentionally narrow" and stating it expects the exemption's scope to shrink over time rather than grow. The practical read for insurers: your core platform vendor, claims system provider, cloud host and data/analytics partners are not getting a carve-out. Their contracts are exactly the ones paragraphs 53 to 55 are aimed at.
The buyer's actual decision problem
For a Head of Risk, General Counsel or Chief Procurement Officer, the legal requirement is rarely the hard part - reading paragraphs 53 to 55 is not difficult. The decision problem is what to do with a portfolio of, typically, dozens to several hundred material and near-material technology contracts, of wildly different sizes, ages, and vendor negotiating power, with a shared and approaching deadline.
Three constraints collide immediately. First, capacity: most legal and procurement functions cannot run full bespoke renegotiations on every contract at once without either headcount they don't have or external legal spend that dwarfs the compliance budget. Second, leverage: a hyperscale cloud provider or a global core-insurance-platform vendor will not accept the same clause set, on the same timeline, as a niche regional claims-software provider with three enterprise customers in Australia - and treating them identically wastes negotiating capital in both directions. Third, sequencing risk: contracts renewing in the next six months carry real urgency; contracts with two years left on the term do not need to be forced into an off-cycle renegotiation just because the calendar says 2026, particularly where a break fee or early-termination cost would outweigh the compliance benefit of moving early.
The decision, in other words, is not "how do we comply with CPS 230" - it is "in what order, with what negotiating posture, and using how much external legal time, do we bring several hundred contracts of uneven materiality into a defensible state before relief runs out." That is a portfolio management problem with a legal component, not a legal problem with a portfolio attached to it. Institutions that treat it as the latter tend to either stall (waiting for legal to clear every contract before touching any of them) or over-spend (running full external counsel review on low-materiality contracts that could be handled with a standard clause rider).
What most institutions get wrong
The most common failure mode is treating CPS 230 as a review exercise rather than a redraft exercise. A review asks: does this contract mention service levels, audit rights and termination? A redraft asks: do the actual clauses, as written, give the entity an enforceable right that would survive a dispute or an APRA inquiry? A contract with a "termination for convenience" clause subject to a 24-month notice period and an uncapped transition-services fee technically has a termination clause. It does not give the entity a right it can use inside the timeframe CPS 230 assumes.
A second, closely related error is assuming legacy contracts are effectively grandfathered because they predate 1 July 2025. They are not exempt - they are on a clock that runs to the earlier of renewal or 1 July 2026, and for many institutions that clock is now inside twelve months.
A third is applying uniform negotiating posture across a non-uniform portfolio, spending scarce legal capacity relitigating fourth-party disclosure language with a payments-infrastructure vendor that will not move, while a mid-tier SaaS vendor with genuine flexibility never gets asked.
A fourth - and this is where the contract and the exit-planning work this engine has already covered actually connect - is treating the termination clause and the exit plan as the same artefact. They are not. The exit plan is the operational document that describes how the entity would actually move away from a vendor: the data extraction sequence, the parallel-run period, the fallback arrangements. The termination clause is the legal instrument that determines whether the entity has the right to do any of that, on what notice, at what cost, and with what obligation on the vendor to assist. An excellent exit plan built against a termination clause that does not actually grant step-in rights, a capped transition-assistance fee, or a defined data-return format and timeframe is a plan with no legal footing to execute on.
The Redraft Six: a clause-by-clause tool
Reading paragraphs 53 to 55 as a flat list of requirements is one way to work through a contract. A more usable one, for a legal, risk or delivery team actually doing the redrafting, is to group the requirements into six clause families - each with a specific drafting question the existing contract has to answer.

1. Scope and service levels. Does the contract define the service precisely enough that a breach is objectively identifiable, with service levels tied to measurable, reported metrics - not general commitments to "use reasonable endeavours"?
2. Incident and escalation notification. Does the vendor's notification obligation give the entity enough runway, in hours rather than in vague commercial language, to assess an incident and still meet its own 72-hour notification duty to APRA under paragraph 33?
3. Audit, data and regulator access. Can the entity actually exercise the audit rights the contract claims to grant, and does the agreement separately and explicitly give APRA the documentation, data and on-site access paragraph 55 requires - with the vendor contractually barred from impeding it?
4. Fourth-party disclosure and sub-contractor liability. Does the contract require the vendor to disclose the other material service providers it relies on, and does it make the vendor liable for a sub-contractor's failure rather than leaving the entity to chase a party it has no direct relationship with?
5. Substitution and exit rights. Can the entity terminate in whole or in part, on a notice period it can live with, with a capped and defined obligation on the vendor to assist transition - including a specified data-return format and timeframe - rather than a termination right that exists on paper but is commercially unusable?
6. Liability, indemnity and compliance enablement. Does the liability cap and indemnity structure reflect where the regulatory and reputational exposure actually sits - with the entity, not the vendor - and does the contract include an explicit clause preserving the entity's ability to meet its own legal and compliance obligations, including this one?

Each of the six maps directly to specific CPS 230 content: family 1 to 54(a); family 2 to the interaction between the contract and paragraph 33; family 3 to 54(b) and 55; family 4 to 54(d) and 54(e); family 5 to 54(g) and the force-majeure provision in 54(f); family 6 to the remainder of 54(b) and to 54(c). Run against a contract, each family produces one of three outcomes: compliant as drafted, technically present but commercially unenforceable, or absent - and that classification is what determines whether a contract needs a full renegotiation, a targeted clause amendment, or a side letter.
Business and technology implications
Running the Redraft Six across a real contract portfolio is, first and foremost, a data problem before it is a negotiation problem. Most institutions cannot currently produce, in a structured form, a clause-level view of what every material technology contract actually says on service levels, audit rights, sub-outsourcing disclosure and termination. That information exists, but it exists inside PDFs and DOCX files scattered across legal, procurement and vendor-management systems, not in a form that can be queried against the six clause families or reconciled against the service-provider register CPS 230 also requires.
That is the unglamorous, high-volume work a delivery partner is well placed to do: extracting clause-level status across a large contract set, mapping it against the register, flagging gaps by materiality tier, and producing the structured output that legal counsel then negotiates from - rather than counsel spending its time reading contracts to find out what they say before it can start deciding what to do about it. It also has a forward-looking half: procurement templates, RFP contract schedules and vendor onboarding playbooks need to be rebuilt so that new technology contracts are written against the six families from the outset, rather than being added to next year's remediation backlog the moment they're signed.
A fair counterargument: the case for not doing this all at once
The instinct to renegotiate the entire portfolio immediately is understandable and, in most cases, wrong. Legal advisers working through this transition have made a consistent point: CPS 230 does not require every contract to carry unrestricted termination rights or maximalist fourth-party disclosure language, and pushing for that regardless of vendor type produces exactly the outcome the standard is trying to avoid - protracted negotiations that leave institutions with neither a compliant contract nor a negotiating partner willing to move quickly on the clauses that actually matter. A break-fee-bounded termination right, staged partial termination, and materiality-scaled audit rights are legitimate, compliant answers for many arrangements; they are not a compromise of the standard.
APRA's own April 2026 amendments make the same point from the regulator's side. Having heard submissions that full contractual compliance is genuinely impractical for a defined category of standardised, low-negotiating-leverage providers, APRA built in relief - narrowly, for infrastructure and market-utility counterparties, and explicitly not for mainstream IT and cloud vendors. That is a useful signal for how institutions should think about their own portfolios: the transition period and the renewal-linked deadline are not a loophole to be closed as fast as possible, but a sequencing mechanism the standard itself assumes. The sensible response is materiality-and-renewal-based triage - highest-risk, soonest-renewing contracts first, side letters and standard riders for lower-tier vendors, full bespoke renegotiation reserved for the arrangements that genuinely warrant it - not a simultaneous scramble across the entire vendor book.
What leaders should do next
Four steps, roughly in order: build or validate a single inventory of material and near-material technology contracts, each tagged with renewal date and current clause status against the six families; triage by materiality and renewal proximity rather than alphabetically or by vendor size; decide, contract by contract, whether the gap needs a full renegotiation, a targeted amendment, or a side letter, and route legal capacity accordingly; and put a standing item on the risk committee agenda tracking closure against the 1 July 2026 deadline, because a portfolio-level gap analysis run once in mid-2025 is now stale.
The sourceCode’s perspective
A CPS 230-ready technology contract is not primarily a legal drafting problem - it is an operational one wearing legal language. The six clause families above are, deliberately, not abstract legal principles; they are a checklist a delivery partner should be able to sit down with a client's legal and risk teams and work through, contract by contract, against the actual text on the page: present, absent, or present-but-unenforceable.
That is the kind of work a technology delivery partner is positioned to do well - structured, high-volume, evidence-based extraction and gap analysis that turns a stack of PDFs into a prioritised remediation list legal counsel can act on quickly, rather than a problem counsel has to solve from a blank page.
It sits alongside, not in place of, the register and exit-planning work this engine has already covered: the register tells you which vendors are material, the exit plan tells you how you would leave, and the contract is what makes either of those things legally exercisable when it matters. Talk to us!
Conclusion
CPS 230 did not create the principle that an insurer remains accountable for a vendor's failure - Australian prudential regulation has assumed that for years. What it did was convert the principle into a specific, checkable list of contract content, with a regulator that now has a direct contractual right to walk in and look.
For institutions with a contract portfolio still written against the older assumption, the task between now and 1 July 2026 is not a compliance review. It is a redraft, sequenced sensibly, clause by clause, against a deadline that is closer than the phrase "transition period" tends to suggest.
Frequently Asked Questions
Does CPS 230 apply to every technology contract an insurer holds, or only to "material" ones? The formal agreement requirements in paragraphs 53 to 55 apply to material arrangements - those supporting critical operations or otherwise carrying material risk, as defined and recorded in the entity's service-provider register. Non-material technology contracts are not subject to the same drafting requirements, which is precisely why an accurate, current register (not a static list built once in 2025) is the starting point for any contract redraft programme.
Are cloud and SaaS providers exempt from these contractual requirements? No. APRA's April 2026 targeted amendments created a narrow exemption for a defined set of infrastructure and market-utility providers - government agencies, central banks, exchanges, clearing and settlement facilities, payment system operators and financial messaging infrastructure. APRA explicitly declined to extend that relief to IT, cloud, communications or digital wallet providers, describing the exemption framework as "intentionally narrow."
What happens to contracts that are already mid-term and don't renew before 1 July 2026? CPS 230's transition arrangements for existing contracts run to the earlier of the contract's next renewal or 1 July 2026 - whichever comes first. A contract with a renewal date beyond that point still needs to be brought into compliance by 1 July 2026; the renewal date does not extend the deadline, it can only bring it forward.
Does the vendor's standard contract usually already cover most of this? Rarely in full. Standard commercial technology agreements typically address service levels and general liability, but seldom include CPS 230-specific requirements such as fourth-party disclosure obligations, sub-contractor liability flow-through, explicit regulator (APRA) access and on-site visit rights, or a clause preserving the customer's ability to meet its own legal and compliance obligations. These usually require targeted amendment even where the underlying commercial terms are otherwise acceptable.
How is this different from the exit-planning work already required under CPS 230? The exit plan is an operational document - the sequence of steps the entity would actually follow to leave a vendor. The termination and substitution clauses in the contract are the legal instrument that determines whether the entity has the right to execute that plan, on what notice, at what cost, and with what assistance obligation on the vendor. A strong exit plan resting on a weak termination clause is not, in practice, executable.
Should procurement wait for legal to finish reviewing existing contracts before updating RFP and vendor-onboarding templates? No. The two should run in parallel. Every new material technology contract signed before the existing-contract remediation is complete adds to the backlog if it is not already drafted against the six clause families described above; fixing the intake process is as time-sensitive as fixing the back book.
Reference List
Australian Prudential Regulation Authority (APRA) (2024) Prudential Standard CPS 230 Operational Risk Management. Available at: https://www.apra.gov.au/standards/cps-230 (Accessed: 21 September 2026).
Australian Prudential Regulation Authority (APRA) (2024) APRA finalises new prudential standard on operational risk. Available at: https://www.apra.gov.au/news-and-publications/apra-finalises-new-prudential-standard-on-operational-risk (Accessed: 21 September 2026).
Australian Prudential Regulation Authority (APRA) (2026) Final targeted amendments to CPS 230 Operational Risk Management. Available at: https://www.apra.gov.au/final-targeted-amendments-to-cps-230-operational-risk-management (Accessed: 21 September 2026).
Actuaries Institute (2026) What is third-party risk? CPS 230 explained, Actuaries Digital. Available at: https://www.actuaries.asn.au/research-analysis/what-is-third-party-risk-cps-230-explained (Accessed: 21 September 2026).
MinterEllison (2024) CPS 230: Your roadmap to compliance. Available at: https://www.minterellison.com/articles/cps-230-your-roadmap-to-compliance (Accessed: 21 September 2026).
Gilbert + Tobin (2025) Updating super fund service provider agreements for CPS 230. Available at: https://www.gtlaw.com.au/insights/Updating-super-fund-service-provider-agreements-for-CPS-230 (Accessed: 21 September 2026).
McCullough Robertson Lawyers (2026) CPS 230 compliance countdown: Material Service Providers and what must be fixed before 1 July 2026. Available at: https://mccullough.com.au/2026/05/01/cps-230-compliance-countdown-material-service-providers-and-what-must-be-fixed-before-1-july-2026/ (Accessed: 21 September 2026).
Insurance Business Australia (2026) CPS 230 recalibrated: Regulator refines landmark resilience rule. Available at: https://www.insurancebusinessmag.com/au/news/breaking-news/cps-230-recalibrated-regulator-refines-landmark-resilience-rule-573581.aspx (Accessed: 21 September 2026).