Most Australian entities ran their CPS 230 contract work off renewal dates. Insert the new terms when the agreement comes up, and the problem solves itself.

For a large part of the book, the renewal never arrived in time. The backstop did.

A 2019 core technology agreement with a 2031 expiry is now read against exactly the same clause list as one signed last week.

That stopped being a scoping exercise. It is remediation of paper you already signed, against a counterparty with no commercial reason to reopen it.

What exactly expired on 1 July 2026, and why is no legacy arrangement out of scope any more?

CPS 230 commenced on 1 July 2025. Paragraph 2(6) is flat about it.

Paragraph 2(7) is the clause that carried legacy paper: "Where an APRA-regulated entity has pre-existing contractual arrangements in place with a service provider, the requirements in this Prudential Standard will apply in relation to those arrangements from the earlier of the next renewal date of the contract with the service provider or 1 July 2026."

Two triggers. The earlier one wins.

Short-cycle arrangements hit the renewal trigger in the first year. Anything long-dated, evergreen or auto-renewing past mid-2026 hit the calendar instead. Those are the ones most likely to sit under a critical operation, because long-dated deals are what you sign for core technology, fund administration and custody.

Read the clause for what it does not say. It does not grandfather the arrangement. It defers the application date. Past that date paragraph 2(7) has no further work to do, and the standard applies to the contract as written today.

The reach is wide. Paragraph 2(2) binds ADIs, general insurers, life companies, private health insurers registered under the PHIPS Act and RSE licensees under the SIS Act in respect of their business operations, plus the relevant NOHCs. For a foreign ADI, Category C insurer or EFLIC, paragraph 2(3) confines the obligations to Australian branch operations.

One relief valve exists and it is not self-service. Paragraph 11 lets APRA adjust or exclude a specific prudential requirement for an entity, and paragraph 10 requires that discretion to be exercised in writing. An internal memo concluding a clause is impractical is not an adjustment.

Which of your pre-existing arrangements are "material arrangements" in the first place?

The clause obligations attach to material arrangements, not to every supplier you pay. The first output of remediation is a defensible boundary.

Paragraph 49 sets the test twice. Material service providers "are those on which the entity relies to undertake a critical operation or that expose it to material operational risk." Material arrangements are defined in the same words, and the same paragraph requires you to identify and maintain a register of material service providers.

That register is not an internal artefact. Paragraph 51 requires an APRA-regulated entity to submit its material service provider register to APRA annually, so remediation status is visible on a recurring cycle, not only when a supervisor asks.

Paragraph 50 removes most of the discretion. Classify a provider of the following as material unless you can justify otherwise:

→ ADI: credit assessment, funding and liquidity management, mortgage brokerage → insurer, general, life or private health: underwriting, claims management, insurance brokerage, reinsurance → RSE licensee: fund administration, custodial services, investment management, and arrangements with promoters and financial planners → all APRA-regulated entities: risk management, core technology services, internal audit

"Unless it can justify otherwise" is a documented rebuttal, not silence. If a legacy mortgage brokerage arrangement is missing from the register, the file has to say why.

Two details in the paragraph 50 footnote catch legacy portfolios. A material service provider may be a third party, a related party or a connected entity, so intragroup arrangements are in. And a provider may be material "as a result of an individual arrangement or multiple arrangements". Five small contracts with one vendor can aggregate into materiality none of them reaches alone.

Paragraph 52 keeps the last word with the regulator: APRA may require you, or a class of entities, to classify a provider or arrangement as material.

Which clauses must a legacy formal agreement contain, and which ones are actually missing?

Paragraph 54 requires a formal legally binding agreement for every material arrangement, with a minimum content list:

→ the services covered and associated service levels (paragraph 54(a)) → rights, responsibilities and expectations of each party, including ownership of assets, ownership and control of data, dispute resolution, audit access, and liability and indemnity → provisions ensuring the entity can meet its legal and compliance obligations → notification by the provider of other material service providers it materially relies on, through sub-contracting or otherwise → liability for any sub-contractor failure resting with the service provider → a force majeure provision indicating which parts of the contract continue in a force majeure event → termination rights reaching the arrangement in its entirety or in parts (paragraph 54(g))

For an RSE licensee, paragraph 54(g) adds a termination right where continuing the arrangement would be inconsistent with the licensee's duty to act in the best financial interests of beneficiaries, citing subsection 52(2)(c) of the SIS Act.

Then paragraph 55, where legacy paper almost always fails. The agreement must also allow APRA access to documentation, data and any other information related to the provision of the service, allow APRA the right to conduct an on-site visit to the service provider, and ensure the service provider agrees not to impede APRA in fulfilling its duties as prudential regulator.

A contract signed in 2018 was negotiated against a different standard and its own commercial logic. It usually has service levels, termination and indemnity in some form. It rarely has an unqualified APRA on-site visit right, an express non-impedance undertaking, or sub-contractor liability pinned to the provider rather than disclaimed by it. Data ownership and control, as distinct from confidentiality, is the other standing hole.

Paragraph 56 adds the operating duty: manage risks to the provider's ongoing ability to deliver, manage risks to you from the arrangement "such as step-in risk or contagion risk", ensure you can execute your BCP, and ensure you can conduct an orderly exit. Termination rights with no transition assistance, no usable data extraction and no continuity during handover leave that last limb unsatisfiable at the paper you hold.

Does renegotiating a grandfathered contract count as a material modification, and what does that trigger?

This is the point most remediation plans miss, and it is structural.

Paragraph 53 applies "before entering into or materially modifying a material arrangement". Inserting a missing APRA access right, reallocating sub-contractor liability or rewriting exit terms is not a clerical amendment. It is a material modification of a material arrangement.

So the remediation act itself pulls paragraph 53 forward. Before executing the variation you must undertake appropriate due diligence, including an appropriate selection process and an assessment of the provider's ability to provide the service on an ongoing basis. You must also assess the financial and non-financial risks from reliance on the provider, including geographic risks of the service location, concentration of the service provider or providers, and concentration in the parties that provider relies on.

Read that against a fifteen-year-old arrangement. You are producing a current ability-to-deliver assessment and a current concentration and geographic-risk assessment on a provider you have never re-diligenced, because the original selection file predates the standard.

That is the real cost of the lapsed carve-out. Not the redline. The diligence pack the redline requires.

What must you notify APRA about once a legacy contract moves, and on what clock?

Paragraph 59 carries two duties on different clocks.

Paragraph 59(a): notify APRA "as soon as possible and not more than 20 business days after entering into or materially changing an agreement for the provision of a service on which the entity relies to undertake a critical operation."

Backward-looking, with an outer limit. If the arrangement supports a critical operation, executing the variation starts a 20 business day window. Sequence the notification into the signing workflow, because the trigger is execution.

Paragraph 59(b): notify APRA "prior to entering into any material offshoring arrangement, or when there is a significant change proposed to the arrangement, including in circumstances where data or personnel relevant to the service being provided will be located offshore." Forward-looking, no stated number of days. Prior means prior.

The footnote defining a material offshoring arrangement cuts against instinct. It is a material arrangement where the service is undertaken outside Australia. It covers a provider incorporated in Australia delivering the service offshore. It excludes a provider not incorporated in Australia that performs the service within Australia.

The test is where the work happens, not where the counterparty is registered. Many legacy contracts are silent on delivery location, which makes the remediation variation the first document where offshoring becomes explicit. That is exactly when the prior-notification duty bites.

One more clock runs regardless of contract state. Paragraph 42 requires notification as soon as possible and not later than 24 hours after a disruption to a critical operation outside tolerance.

How do critical operations and tolerance levels decide what a legacy contract has to guarantee?

The clause list tells you what must be in the agreement. Critical operations and tolerance levels tell you what the numbers inside those clauses have to be.

Paragraph 35 defines critical operations as processes undertaken by the entity "or its service provider" which, if disrupted beyond tolerance levels, would have a material adverse impact on depositors, policyholders, beneficiaries or other customers, or on the entity's role in the financial system. Provider processes are inside the definition, not adjacent to it.

Paragraph 36 sets defaults, subject to justified departure: payments, deposit-taking, custody, settlements and clearing for an ADI; claims processing for an insurer; investment management and fund administration for an RSE licensee.

Paragraph 38 then requires tolerance levels for each: the maximum period of time you would tolerate a disruption, the maximum extent of data loss you would accept, and the minimum service levels you would maintain under alternative arrangements during a disruption.

That is the calibration input. A legacy agreement whose restoration commitment is "commercially reasonable endeavours", or whose recovery point is weaker than your accepted data loss, cannot support the tolerance the Board has approved. Paragraph 54(a) requires service levels. Paragraph 38 decides whether they are the right ones.

Paragraph 44 closes the loop on evidence: the testing program must include severe but plausible scenarios "including disruptions to services provided by material service providers", inside the annual business continuity exercise paragraph 43 requires. A commitment that cannot meet tolerance surfaces there if it has not surfaced in the redline first.

Paragraph 15 is the principle underneath. An entity "must not rely on a service provider unless it can ensure that in doing so it can continue to meet its prudential obligations in full and effectively manage the associated risks."

Who owns the remediation: the Board, internal audit, or the service provider management policy?

All three, with roles the standard names.

The policy is the instrument. Paragraph 47 requires a comprehensive service provider management policy covering how you identify material service providers and manage service provider arrangements. Paragraph 48 requires it to cover entering into, monitoring, substituting and exiting those agreements, the risks associated with the providers, and the risks associated with any fourth parties they rely on to deliver a critical operation. A fourth party, per the footnote, is a party a service provider relies on in delivering services to the entity.

That limb matters for legacy paper. Paragraph 54 only obliges the provider to notify you of other material service providers it materially relies on. No notification clause, no feed for your fourth-party policy commitment.

Internal audit has a named gate. Paragraph 60 requires the internal audit function to review any proposed material arrangement involving the outsourcing of a critical operation, and to report regularly to the Board or Board Audit Committee on compliance of such arrangements with the service provider management policy. A remediated critical-operation outsourcing is a proposed material arrangement in substance, so put internal audit in the path, not after it.

The Board owns the outcome. Paragraph 20 makes it ultimately accountable for oversight of operational risk management, including business continuity and the management of service provider arrangements. Paragraph 22 requires it to approve the service provider management policy, review risk and performance reporting on material service providers, and approve the BCP and tolerance levels.

Paragraph 58 sits between them: senior management must receive reporting on material arrangements, including regular assessment of performance against agreed service levels, control effectiveness, and compliance of both parties with the agreement. Both parties includes the APRA-regulated entity.

So every material arrangement now carries four linked artefacts: a clause checklist from paragraphs 54 and 55, a tolerance set from paragraph 38, a diligence pack from paragraph 53, and a notification event under paragraph 59. Run in spreadsheets, those drift apart inside a quarter and the annual register submission becomes a reconstruction project.

Run as structured data, the register is a query and the clause gaps are a ranked remediation list. One organisational profile, deterministic mapping across 245+ regulations in 28 jurisdictions, every obligation traced to a verbatim quote from the source text. Not a model's recollection of what CPS 230 says. The clause, with the words in it.

Map your arrangements against what CPS 230 actually requires at agrc.ai/third-party-risk. The operational risk and tolerance model sits at agrc.ai/risk-management, the engine behind both at agrc.ai/platform.

FAQ: CPS 230 legacy contracts, material service providers and APRA notifications

Does CPS 230 still give any relief for contracts signed before it commenced?

No. Paragraph 2(7) applied the requirements to pre-existing contractual arrangements from the earlier of the next renewal date or 1 July 2026. Both triggers have passed. The only remaining relief is an adjustment or exclusion granted by APRA under paragraph 11, in writing.

Which clauses are most commonly missing from a legacy material arrangement?

The paragraph 55 provisions: APRA access to documentation and data, APRA's right to an on-site visit to the provider, and the provider's agreement not to impede APRA. Then the paragraph 54 items older contracts disclaim rather than accept: sub-contractor liability resting with the provider, ownership and control of data, and termination rights reaching parts of the arrangement rather than the whole.

Is inserting missing CPS 230 clauses into an old contract a material modification?

Treat it as one. Paragraph 53 attaches its due diligence and its concentration, geographic and ability-to-deliver assessments to entering into or materially modifying a material arrangement. Where the arrangement supports a critical operation, the executed variation also starts the paragraph 59(a) clock: as soon as possible and not more than 20 business days after materially changing the agreement.