Regulated Customer Contract Checker
Regimes · CPS 234

APRA CPS 234 Information Security

Reaches every ICT service agreement with an APRA-regulated customer in Australia: the assessment of a third party's information security capability (para 16) and control design (P22), internal audit's assessment of the assurance the third party gives (para 27), and the 72-hour notification of a material incident (para 35).

On the register, tick "APRA CPS 234" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: APRA CPS 234 Information Security.

What it expects, term by term

security schedulepara 16 · P22On an ICT service arrangement
audit rightpara 27On an ICT service arrangement, or where processor terms are expected
breach clockpara 35On an ICT service arrangement

The clauses, quoted

4

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

CPS 234 para 16 Assessment of Related Party and Third Party Capability

Where a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.

Evidence an auditor accepts: Third party and related party security capability assessments; Register of parties managing information assets; Consequence rating driving assessment depth
Where it usually falls short: Assessment limited to outsourced material business activities
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 27 Internal Audit Assessment of Third Party Control Assurance

Internal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.

Evidence an auditor accepts: Reliance decisions recorded with supporting assessment; Assessment of the third party assurance reports relied upon; Materiality determination for each reliance
Where it usually falls short: Third party assurance accepted without assessment
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 Hours

APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 P22 Evaluation of Third Party Control Design

Where a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.

Evidence an auditor accepts: Design evaluations of third party control sets; Assurance reports reviewed with entity conclusions recorded; Scope evidence covering all parties managing information assets
Where it usually falls short: Reliance on a certificate with no design evaluation
APRA CPS 234 Information Security in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list