Voice AI and APRA CPS 230: Operational Resilience Requirements for AI Vendors

TL;DR

The current APRA CPS 230 Operational Risk Management standard commenced on July 1, 2026 after APRA finalized targeted amendments in April 2026. It does not automatically classify every voice AI vendor as material. An APRA-regulated entity must assess whether it relies on the provider for a critical operation or whether the arrangement exposes it to material operational risk. Providers of core technology services are presumed material unless the entity can justify otherwise. When a voice AI arrangement is material, CPS 230 requires a register, due diligence, a formal agreement, monitoring, business-continuity alignment, fourth-party risk management, and an orderly exit plan. Regulatory accountability remains with the APRA-regulated entity.

For Australian banks, insurers, and superannuation funds using voice AI in contact centers, CPS 230 brings operational risk, business continuity, and service-provider governance into one framework. The standard imposes prudential obligations on the regulated entity. Vendors support compliance through evidence, contractual commitments, testing, and cooperation, but should not market themselves as independently “CPS 230 compliant” as though the label transfers the institution's obligations.

As of September 2026, the operative source is APRA's CPS 230 standard, dated April 23, 2026 and in force from July 1, 2026, together with the current CPG 230 practice guide. Institutions should assess current arrangements against that text rather than rely on an old transition countdown. For the broader deployment picture, see the enterprise voice AI orchestration guide.

For voice AI deployment with CPS 230 evidence mapping, on-premise or private-cloud options, and contract-specific uptime SLAs, contact the Trillet Enterprise team. Materiality, residence, testing, notification, and SLA terms must be confirmed in the applicable enterprise agreement.

What Is APRA CPS 230 and Why Does It Replace CPS 231/232?

APRA CPS 230 (Operational Risk Management) consolidated the former outsourcing and business-continuity framework into a standard covering operational risk, business continuity, and service-provider management. The current 2026 instrument also introduced targeted amendments and limited exemptions for specified categories of non-traditional service providers; those exemptions do not create a general exception for technology vendors.

The consolidation reflects APRA's recognition that operational risk in 2026 does not fit neatly into the categories defined a decade ago. Modern financial institutions rely on interconnected technology vendors, including AI platforms, that span multiple risk categories simultaneously. A voice AI vendor is both an outsourcing arrangement (CPS 231) and a business continuity dependency (CPS 232). Separating governance across two standards created gaps.

CPS 230 addresses this by introducing three integrated pillars:

  1. Operational risk management: Institutions must identify, assess, and manage operational risks, including those introduced by AI systems, with board-level oversight and documented risk appetite.
  2. Business continuity: Critical operations must be maintained through disruptions, with tolerance levels defined for maximum acceptable downtime and data loss.
  3. Service provider management: The institution must identify material providers, maintain its register, put material arrangements under formal agreements where required, manage fourth parties, monitor performance, and plan substitution and exit.

APRA says the standard is designed so regulated entities can maintain critical operations through severe disruptions and manage service-provider risk. A voice AI platform used for essential inbound service, collections, payments, claims, or account access may fall within scope, but the institution must document the classification against its critical operations and material operational risks.

Why Voice AI Vendors Are Material Service Providers Under CPS 230

Under CPS 230, material service providers are those an entity relies on to undertake a critical operation or that expose the entity to material operational risk. Core technology services are among the categories an entity must classify as material unless it can justify otherwise. Whether a particular voice AI deployment is core technology or otherwise material depends on its role, volume, fallback path, data access, and impact on customers.

Consider an illustrative dependency: if a bank routes a substantial share of inbound calls through voice AI and cannot maintain a critical service when that platform fails, material classification is likely to require serious consideration. By contrast, a limited internal pilot with a tested manual fallback may present a different risk. The classification belongs in the institution's assessment, not in a vendor's generic marketing copy.

Material Service Provider Obligations

Once the arrangement is classified as material, the regulated entity's obligations include:

CPS 230 RequirementVoice AI Vendor Obligation
Formal service provider registerInstitution must maintain a register listing the voice AI vendor, services provided, and risk assessment
Formal agreementSpecify services and service levels, rights and responsibilities, data ownership/control, audit access, liability, compliance, force majeure, and termination terms
Business continuity alignmentVendor must demonstrate continuity capabilities aligned with the institution's tolerance levels
Fourth-party risk managementAddress material subcontractors and downstream dependencies, such as cloud, model, speech, and telephony providers
Substitutability assessmentInstitution must evaluate how quickly it could replace (substitute) the voice AI vendor if the relationship ended or the vendor failed
Ongoing monitoringRegular review of vendor performance against contractual and resilience commitments

The substitutability requirement deserves particular attention. APRA expects institutions to assess whether a material service provider can be replaced within a reasonable timeframe. For voice AI, this depends heavily on architecture: proprietary platforms with custom integrations are harder to substitute than platforms built on open standards with documented APIs.

CPS 230 Compliance Mapping: What Voice AI Vendors Must Demonstrate

Financial institutions evaluating voice AI vendors for CPS 230 compliance should assess against five specific capability areas.

1. Data Residency and Sovereignty Controls

CPS 230 requires institutions to manage operational risks from service provider arrangements, including jurisdictional risks. For voice AI, this means knowing exactly where call data is processed, stored, and potentially transmitted.

Voice AI platforms may route audio through infrastructure spanning multiple jurisdictions. Under CPS 230, a regulated Australian institution must assess geographic and concentration risk when entering or materially modifying a material arrangement and notify APRA before a material offshoring arrangement. The required data-location terms depend on that assessment and the institution's other legal and policy obligations.

Trillet Enterprise can address this through configurable data residency with APAC, North American, and EMEA options. For institutions requiring a client-controlled application and storage boundary, on-premise deployment via Docker is available. Neither option eliminates jurisdictional or fourth-party risk automatically: the agreement and architecture must identify every external telephony, speech, model, support, monitoring, and backup path.

2. Business Continuity and Failover Architecture

CPS 230 requires institutions to define tolerance levels for critical operations, specifically the maximum duration and extent of disruption they can absorb. Voice AI vendors must demonstrate continuity capabilities that meet these tolerances.

In practice, this means financial institutions need to verify:

  • Uptime commitments: What is the vendor's SLA, and is it financially backed or merely aspirational?
  • Failover architecture: Does the platform support active-active redundancy (multiple live systems sharing traffic, so callers feel nothing when one fails) or active-passive redundancy (a standby system that takes over when the primary fails)?
  • Recovery time: How quickly can the platform recover from infrastructure failure?
  • Degradation strategy: What happens during a partial outage: do calls drop, or do they route to human agents?

Where approved in an enterprise agreement, Trillet can provide a financially backed 99.99% uptime SLA. Four nines corresponds mathematically to about 52.6 minutes in a non-leap year, but the contractual measurement window, exclusions, dependencies, and remedy determine what the commitment actually covers. Disaster recovery and failover, including any human-queue fallback, should likewise be tested and specified for the engagement rather than assumed.

3. Audit Trails and Operational Transparency

CPS 230 governance requires ongoing monitoring of material service providers. This is only possible if the voice AI vendor provides sufficient operational transparency.

Financial institutions should require:

  • Audit logging: Define which system access, configuration changes, administrative actions, and data events are logged, retained, reviewed, and attributable to a user or service.
  • Incident reporting: The vendor must contractually commit to incident notification timelines aligned with the institution's APRA reporting obligations (72 hours for material incidents under CPS 234).
  • Performance reporting: Regular reporting on SLA adherence, call volumes, error rates, and system health.
  • Audit access: The institution, and APRA, must have the right to audit the vendor's operations, either directly or through independent assessors.

Trillet Enterprise can support security audit preparation with documentation, access logging, and third-party assessment support. Penetration-testing scope, assessor qualifications, report access, remediation evidence, and any regulator cooperation must be confirmed in the applicable agreement.

4. Vendor Accountability and Contractual Safeguards

CPS 230 raises the bar on what must appear in service provider contracts. Generic terms of service are insufficient for material service provider relationships.

The current CPS 230 text gives buyers a concrete contractual baseline. For every material arrangement, the formal agreement must specify services and service levels; allocate rights, responsibilities, data control, audit access, liability, and indemnity; support legal obligations; address material subcontractors; preserve relevant obligations through force majeure; include termination rights; and allow APRA access without impediment. These are requirements for the regulated entity's arrangement, not a generic vendor badge.

For voice AI specifically, CPS 230-aligned contracts should address:

  • AI performance measures: Defined, measurable thresholds for the specific workflow, together with review, escalation, and remediation procedures. Avoid a broad promise that no model can reliably guarantee.
  • Data handling obligations: Explicit terms on data retention, deletion, and prohibition on using client data for model training without consent.
  • Termination and transition: Provisions for data portability and transition assistance if the relationship ends.
  • Sub-contractor disclosure: Requirements to notify the institution of changes to downstream service providers.
  • Regulatory cooperation: Terms that allow APRA access to relevant documentation, data, information, and on-site visits without the provider impeding APRA.

5. Operational Resilience Testing

CPS 230 expects institutions to test their operational resilience, including the resilience of material service providers, through scenario-based testing. For voice AI, this means the vendor must participate in or support:

  • DR testing: Simulated failover events to verify recovery capabilities.
  • Load testing: Verification that the platform can handle peak call volumes under stress conditions.
  • Scenario planning: Joint exercises addressing plausible disruption scenarios (cloud provider outage, telephony carrier failure, cyber incident).
  • Penetration testing: Regular security testing by independent assessors.

Trillet Enterprise can support operational resilience testing through its fully managed service model. Monitoring coverage, test cadence, scenarios, assessor qualifications, evidence delivery, remediation deadlines, and client participation are engagement-specific and should be recorded in the SOW and service levels.

CPS 230 vs. CPS 234: How the Standards Interact for Voice AI

Financial institutions already meeting CPS 234 (Information Security) requirements for their voice AI vendor may assume CPS 230 compliance follows naturally. It does not.

CPS 234 and CPS 230 address different, though overlapping, risk domains:

DimensionCPS 234 (Information Security)CPS 230 (Operational Risk Management)
Primary focusProtecting information assets from security threatsEnsuring operational continuity through disruptions
Vendor scopeThird-party information security capabilitiesMaterial service provider resilience and substitutability
TestingSecurity control effectivenessOperational resilience scenarios
Board reportingInformation security incidentsOperational risk appetite and tolerance breaches
Incident triggerSecurity breachesAny material operational disruption

Trillet holds SOC 2 Type II and ISO 27001 certifications and can support CPS 234-related due diligence. APRA and IRAP outcomes remain engagement- and assessment-specific, HIPAA processing requires an executed BAA and covered Order Form, and none of these substitutes for the institution's CPS 230 assessment. CPS 234 focuses on information security; CPS 230 adds operational resilience, critical-operation tolerances, service-provider management, and exit planning.

A Realistic Assessment: What CPS 230 Compliance Cannot Guarantee

Meeting CPS 230 obligations does not eliminate operational risk. It creates a structured framework for the regulated entity to manage it.

Several limitations deserve acknowledgment:

No voice AI platform can guarantee zero disruption. A 99.99% uptime SLA still permits approximately 52 minutes of annual downtime. For a financial institution processing thousands of calls daily, even a brief outage during peak hours affects customers. CPS 230 requires tolerance levels, not zero-risk guarantees.

Regulatory interpretation remains evolving. The amended standard and practice guide commenced July 1, 2026. APRA's supervisory application to AI-specific risks will continue to develop, so institutions should monitor official guidance and discuss uncertainty with their responsible supervisor and legal advisers.

AI-specific metrics need careful drafting. The industry has not converged on one standard for measuring hallucination, intent accuracy, transcription quality, or safe task completion. Institutions should define workflow-specific test sets, thresholds, sampling, exclusions, escalation, and remedies instead of relying on an unscoped “accuracy guarantee.”

On-premise deployment changes, rather than eliminates, risk. It can reduce some cross-border and cloud concentration exposure while shifting infrastructure, capacity, patching, backup, and recovery responsibilities to the institution or its managed provider. The responsibility matrix and continuity tests must match the deployment boundary.

July 1, 2026 Is Past: What Should Institutions Do Now?

The amended CPS 230 and CPG 230 are now in force. A regulated institution should treat remediation as a current governance program, not a future deadline checklist:

Classify and document:

  • Map the voice AI workflow to critical operations, customer impacts, data access, concentration, fallback, and exit dependencies.
  • Determine whether the provider is a material service provider. If the service is core technology, document any justification for not treating it as material.
  • Record the provider and arrangement in the material-service-provider register when required, and prepare the annual APRA submission process.

Review the formal agreement:

  • Check services, service levels, responsibilities, data ownership/control, audit access, liability, indemnity, subcontractors, force majeure, termination, APRA access, and non-impediment terms against current CPS 230.
  • Confirm which fourth parties deliver the service, how changes are notified, and who remains liable for subcontractor failure.
  • Align incident and disruption notifications with the institution's own APRA deadlines. Current CPG 230 lists up to 72 hours for qualifying operational-risk incidents, 24 hours for a critical operation outside tolerance, 20 business days for specified material-service arrangements, and prior notice for material offshoring.

Test continuity and exit:

  • Set board-approved tolerance levels for the critical operation, not merely a vendor uptime percentage.
  • Exercise severe but plausible scenarios across telephony, models, cloud, integrations, cyber events, capacity, and human fallback.
  • Test data export, number routing, operational handover, and orderly exit so substitutability is demonstrated rather than asserted.

Monitor and govern:

  • Give senior management regular reporting on performance against service levels, control effectiveness, incidents, near misses, remediation, concentration, and agreement compliance.
  • Escalate gaps through the institution's operational-risk framework and obtain legal or supervisory advice where current arrangements do not meet the amended standard.

For a detailed framework on evaluating voice AI vendors against compliance and operational criteria, see our enterprise vendor evaluation framework.

How Trillet Enterprise Maps to CPS 230 Requirements

CPS 230 RequirementTrillet Enterprise Capability
Material service provider registerService descriptions and dependency information can support the institution's own classification and register process
Data residency controlsConfigurable residency (APAC, North America, EMEA) or on-premise Docker deployment
Business continuityContract-specific SLA and failover options; a financially backed 99.99% target is available where approved in the agreement
Operational resilience testingTesting and evidence support can be scoped in the SOW; cadence and assessors are not universal defaults
Audit trail and transparencyLogging, incident reporting, audit evidence, and APRA cooperation terms should be written into the agreement
Fourth-party disclosureInfrastructure and subprocessor dependencies should be confirmed for the selected architecture
Information security (CPS 234 overlap)SOC 2 Type II and ISO 27001 are in place; APRA and IRAP requirements remain engagement-specific
Ongoing monitoringManaged monitoring and support are available; coverage, response targets, and reporting are contractual
Integration compatibilityViciDial, Avaya, Cisco CUCM, Mitel, Asterisk, SIP, and CTI options reduce migration friction but do not establish compliance by themselves

For organizations already evaluating voice AI for financial services compliance, CPS 230 adds an operational resilience layer on top of existing security and privacy requirements. The standards are complementary, not duplicative. See Trillet for financial services for the full sector offering.

Frequently Asked Questions

Does CPS 230 apply to all voice AI vendors used by APRA-regulated entities?

CPS 230 governs how an APRA-regulated entity manages service-provider arrangements, but the material-provider requirements depend on classification. A voice AI platform handling a critical customer-facing service may be material, and a core technology service is presumed material unless the institution can justify otherwise. A limited internal pilot may not be. The institution must document whether it relies on the provider for a critical operation or whether the arrangement creates material operational risk.

What happens if our voice AI arrangement does not meet CPS 230 after July 1, 2026?

The current standard is in force. The APRA-regulated entity, not the vendor, bears the prudential obligation. It should identify the gap, assess risk, implement remediation, update governance reporting, and seek legal or supervisory guidance where necessary. Do not wait for a renewal cycle on the assumption that an old transition provision still applies.

How does on-premise voice AI deployment simplify CPS 230 compliance?

On-premise deployment via Docker can reduce selected data-location and vendor-cloud concentration risks when the agreed boundary stays inside institution-controlled infrastructure. It does not remove telephony, model, support, supply-chain, or operational risk unless those dependencies are also addressed. It shifts hardware, network, capacity, backup, and recovery responsibilities toward the institution, supplemented by the vendor's managed service support.

Does APRA CPS 234 compliance automatically satisfy CPS 230?

No. CPS 234 (Information Security) and CPS 230 (Operational Risk Management) are complementary but distinct standards. CPS 234 addresses information-security capability, controls, testing, and incident notification. CPS 230 adds operational resilience, critical-operation tolerances, service-provider management, and exit planning. Strong security evidence for a voice AI arrangement does not establish that the regulated entity has met CPS 230.

What contractual terms should financial institutions negotiate with voice AI vendors for CPS 230?

At minimum, map the agreement to CPS 230's required service levels, rights and responsibilities, data control, audit access, liability, indemnity, subcontractor responsibility, force majeure, termination, APRA access, and non-impediment terms. Add data portability, transition support, incident timelines that leave the institution time to meet its own deadlines, resilience-test participation, and workflow-specific AI performance measures where appropriate.

How does CPS 230 affect voice AI integrations with legacy telephony systems?

CPS 230's fourth-party risk requirements extend to dependencies a material provider uses to deliver a critical operation, which can include telephony infrastructure. Institutions must assess the complete call chain, from PSTN carriers through PBX systems to the voice AI platform. Trillet Enterprise's compatibility with Avaya, Cisco CUCM, Mitel, and Asterisk can reduce migration scope, but the institution must still test end-to-end resilience and fallback.

What changed on July 1, 2026?

APRA's April 2026 targeted amendments produced an updated CPS 230 and CPG 230 that commenced on July 1, 2026. The changes include limited exemptions from specified contractual requirements for listed categories of non-traditional service providers where contractual compliance is impracticable. Buyers should use the current standard and guidance, not the superseded 2023 instrument or an earlier transition timeline.


CPS 230 makes voice AI procurement part of operational-resilience governance when the arrangement supports a critical operation or creates material operational risk. The current amended standard has been in force since July 1, 2026.

For CPS 230 evidence mapping, on-premise options, and contract-specific uptime and resilience terms, contact the Trillet Enterprise team. The applicable agreement defines the commitments; the regulated entity retains accountability. For a broader overview, visit our enterprise voice AI orchestration guide.

Updated September 2026: aligned the article to APRA's April 2026 amended CPS 230 and CPG 230, effective July 1, 2026; removed the obsolete transition countdown; made materiality entity-specific; added current notification and agreement requirements; and qualified Trillet residency, IRAP, testing, and SLA claims by contract.