Regulation, APRA CPS 234
APRA CPS 234: How to Ensure Vendor and Contract Compliance
Australian Prudential Standard CPS 234 Information Security was created to enhance resilience around security...
Police Bank and Pepper Money replaced spreadsheets with audit-ready vendor compliance. One platform for contracts, vendor risk, and spend.
Pre-existing vendor contracts must comply by 1 July 2026. The deadline is not moving.
APRA's Prudential Standard CPS 230 for Operational Risk Management sets obligations across vendor compliance, material service provider oversight, and operational resilience. These are the requirements most relevant to Procurement, Legal, and Finance teams.
Maintain a documented register of every vendor that performs a critical operation or creates material operational risk. Include service scope, SLA obligations, and materiality classification.
Contracts with material service providers must include seven mandatory clauses covering SLAs, risk management, security, audit and regulator access, subcontracting, contingency, and data ownership.
CPS 230 expects systematic vendor oversight with complete audit trails. Spreadsheets cannot deliver that at the standard APRA expects.
Police Bank's Procurement Lead described how spreadsheets created friction across every vendor management process. No centralised repository. No continuous oversight. No self-service access for business users. Read the Police Bank case study.
“CPS 230 is really asking the question of making sure you're effectively managing your vendors. Gatekeeper removed all that friction.”
Canstar's Legal Counsel described an ongoing risk of contracts auto-renewing before Legal and Finance could review them. Contracts lived in spreadsheets. Finance had no visibility of committed spend. Read the Canstar case study.
When that gap surfaces in a board-level audit, spreadsheets become a governance failure. CPS 230 makes this explicit.
Each CPS 230 requirement maps to a specific Gatekeeper capability. Evidence is generated automatically as part of normal operation, not assembled retrospectively when the auditor asks.
Maintain a current register of all material service providers with service scope, materiality classification, and risk profile.
Living vendor register with materiality tagging, linked contracts, Market IQ risk scores, SLA performance history, and fourth-party dependencies. Always current. Always exportable
MSP contracts must include SLAs, risk management, security, audit access, subcontracting controls, contingency, and data ownership.
Gatekeeper AI extracts contract metadata at upload and flags missing mandatory clauses. Approval workflows enforce clause compliance before signature.
Ongoing oversight of service provider performance against agreed service levels with documented evidence of review.
Smart Forms collect SLA performance monthly. Contract owners complete weighted assessments. RAG status, performance score, and 12-month historical trends produced automatically.
Entities must assess operational risks from vendors before engagement and not rely on a service provider unless compliance can be ensured.
Risk-first vendor onboarding: screening happens before the vendor reaches IT, Legal, or Procurement. Due diligence questionnaires, financial and cyber risk scoring, and sanctions checks built into the onboarding workflow.
Manage risks from fourth parties, your providers' key subcontractors, where those dependencies are material.
Fourth-party relationships tracked within the vendor record. Concentration risk flagged where multiple MSPs share a subcontractor. Subcontracting clauses monitored via contract extraction.
The Board is accountable for operational risk oversight. Senior management is responsible for end-to-end governance processes.
Board-level reporting dashboards showing MSP register status, SLA compliance rates, risk score trends, and contract renewal pipeline. Evidence exportable for APRA at any time.
Police Bank implemented risk-first vendor onboarding: screening happens before the vendor reaches IT, Legal, or Procurement.
Smart Forms track SLA performance monthly. Contract owners receive automated notifications, complete a five-question weighted assessment, and the system produces a RAG status and performance score. Historical trends give APRA the evidence of continuous oversight CPS 230 requires. Read the Police Bank case study.
Canstar's invested in NetSuite. Gatekeeper's native SuiteApp gave Finance contract visibility and spend without custom development.
Renewals are planned decisions, not budget surprises. Every contract follows standardised approval workflows: executive approval, finance budget validation, security review, legal sign-off, e-signature.
“"We now have a central place where we can see every renewal coming up across the entire year, which means no more surprises, no more last-minute reviews, and no more accidental auto-renewals."”
A practical checklist for Procurement, Legal, and Finance teams at APRA-regulated entities. Maps CPS 230 requirements to the vendor-facing processes you need in place: material service provider identification, mandatory contract clauses, SLA monitoring, fourth-party oversight, and audit trail evidence.
Use it to assess your current gaps and prioritise what needs to change before the 1 July 2026 deadline for pre-existing service provider contracts. Download your Checklist
Audit Read
Faster Onboarding
Average Saving from unwanted renewals
Unwanted renewals
CPS 230 is APRA's Prudential Standard for Operational Risk Management. It applies to all APRA-regulated entities: banks, insurers, and superannuation trustees. CPS 230 took effect on 1 July 2025. For pre-existing service provider contracts, requirements apply from the earlier of the next renewal date or 1 July 2026. Read the full CPS 230 guide
Gatekeeper maps every CPS 230 vendor obligation to a working platform control. This includes a material service provider register, risk-first vendor onboarding, continuous SLA monitoring via Smart Forms, automated audit trail generation, fourth-party dependency tracking, and AI-powered contract clause compliance checks. Police Bank uses these capabilities to demonstrate CPS 230 readiness.
Gatekeeper maps every CPS 230 vendor obligation to a working platform control. This includes a material service provider register, risk-first vendor onboarding, continuous SLA monitoring via Smart Forms, automated audit trail generation, fourth-party dependency tracking, and AI-powered contract clause compliance checks. Police Bank uses these capabilities to demonstrate CPS 230 readiness.s.
Weeks, not months. Import existing contracts and vendor records from spreadsheets or SharePoint. Gatekeeper AI extracts metadata automatically. Configure governance workflows and Smart Forms for SLA tracking. Canstar saw value within months of go-live.
CPS 230 requires oversight of material fourth-party dependencies, your providers' key subcontractors. Gatekeeper tracks fourth-party relationships within the vendor record, links them to SLA performance data, and flags concentration risk where multiple material providers depend on the same subcontractor.
Expert insight and opinion on the role of AI in Vendor & Contract Lifecycle Management
Australian Prudential Standard CPS 234 Information Security was created to enhance resilience around security...
APRA CPS 230 is the Prudential Standard for Operational Risk Management. It aims to ensure that APRA-regulated entities...
Before Gatekeeper, our contracts
Anastasiia Sergeeva, Legal Operations Manager, BlaBlaCar
were everywhere and nowhere.
Gatekeeper is that friendly tap on the shoulder,
Donna Roccoforte, Paralegal, Hakkasan Group
to remind me what needs our attention.
Great System. Vetted over 25 other systems
Randall S. Wood, Associate Corporate Counsel, Cricut
and Gatekeeper rose to the top.
Thank you for requesting your demo.
Next Step - Book a Call
Please book a convenient time for a quick call to discuss your requirements.