top of page

From CPS 230 to AI: What Operational Resilience Looks Like in 2026–27

Zoe Beesley

14 Sept 2026

How CPS 230, AI and emerging risks are changing the way financial institutions think about resilience.

Operational resilience used to sound like something belonging in a risk committee paper.


In 2026–27, it increasingly belongs in the operating model.


APRA's approach is clear: APRA-regulated entities need to be able to continue critical operations through disruption while understanding and managing the risks created by technology, third parties and increasingly complex operating environments.


CPS 230 is now in force, making operational resilience a current prudential requirement rather than a future compliance project.


Resilience is more than business continuity


CPS 230 requires APRA-regulated entities to manage operational risk, maintain critical operations through disruptions and manage risks arising from service providers.


That is broader than simply having a disaster recovery document.


A resilient organisation needs to understand:


  • what its critical operations are;

  • what could disrupt them;

  • how much disruption can be tolerated;

  • which systems, people and processes those operations depend on;

  • which third parties are critical;

  • how the organisation will respond; and

  • how management will know whether the response is working.


This is why operational resilience increasingly cuts across risk, technology, compliance, operations and executive leadership.


The question is not simply whether a business has a plan for disruption.


It is whether the business understands what needs to keep operating — and whether it has tested its ability to do so.


Third parties are part of the risk profile


One of the biggest changes in modern financial services is the number of activities organisations depend upon without directly controlling them.


Cloud platforms.


Software providers.


Outsourced administration.


Offshore teams.


Cybersecurity providers.


Data vendors.


External investment managers.


Technology platforms.


The fact that another organisation performs an activity does not mean the underlying operational risk has left your business.


CPS 230 specifically addresses service-provider risk. In April 2026, APRA also finalised targeted amendments clarifying and adjusting certain requirements for particular service providers, including limited exemptions from specified contractual requirements where compliance is not practicable.


Those amendments do not remove the broader obligation to manage operational risk and service-provider dependencies.


The practical question is:


Do we know which third parties could disrupt our critical operations?


If the answer is no, that may be a useful place to begin.


AI is becoming an operational resilience issue


AI has moved rapidly from an emerging technology issue into a governance and risk-management issue.


In April 2026, APRA called for a step-change in how regulated entities manage AI-related risks, including through appropriate governance, risk management, assurance and operational resilience.


APRA has also encouraged entities to consider the implications of increasingly capable AI models for operational resilience and business continuity, including AI-specific threats and attack paths.


That creates a new category of operational question:


What happens if an AI-enabled process behaves unexpectedly?


Imagine an automated system:


  • makes an incorrect customer assessment;

  • sends inaccurate communications;

  • exposes confidential information;

  • changes a workflow;

  • produces unreliable analysis; or

  • becomes unavailable during a critical event.


Who notices?


Who stops it?


Who makes the decision?


Who tells customers?


Who assesses whether an incident needs to be reported?


Those questions are worth answering before an incident occurs.


The technology may be changing quickly, but the need for appropriate oversight and accountability is not.


Geopolitical risk is becoming operational risk


Geopolitical risk is also becoming part of APRA's broader resilience conversation.


APRA's 2026–27 Corporate Plan includes continued work on geopolitical risk readiness, including targeted readiness assessments for larger entities with heightened exposure to geopolitical shocks.


For financial institutions, geopolitical risk can sound abstract.


Operationally, it is not.


Consider:


  • overseas technology providers;

  • offshore staff;

  • international data flows;

  • cloud concentration;

  • payment infrastructure;

  • critical suppliers;

  • market liquidity;

  • cyber threats; and

  • sanctions and counterparty risks.


A disruption does not have to happen inside Australia to affect an Australian financial institution.


The relevant question is not whether a particular geopolitical event can be predicted.


It is whether the organisation understands where its dependencies lie and how it would respond if one of them were disrupted.


Build resilience into normal management


The strongest operational resilience programs do not sit in a folder labelled "Business Continuity."


They appear in ordinary management conversations.


At the next executive meeting, ask:


What are the five things that absolutely cannot stop?


Then ask:


What could stop them?


Then:


How long could we operate without them?


Finally:


When was the last time we tested our answer?


Those four questions can reveal more than another hundred-page policy document.


They can also help connect operational resilience to everyday decisions about technology, outsourcing, staffing, data and investment.


Resilience is a leadership capability


Operational resilience ultimately comes down to decisions.


During a disruption, people need to know:


  • who has authority;

  • what information matters;

  • what can be stopped;

  • what must continue;

  • what risks can be accepted temporarily; and

  • when escalation is required.


That is leadership — not simply compliance.


The organisations that perform best under pressure are rarely those with the most policies.


They are the ones where people understand the business well enough to make good decisions when the policy does not contain the answer.


In 2026–27, resilience is not about predicting every crisis.


It is about building an organisation capable of responding intelligently when the unexpected arrives.




Sources:


Disclaimer: This article is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory requirements and guidance can change. Readers should check current primary sources and seek independent professional advice where appropriate.

Disclaimer: Compliance & Leadership Insights is an independent editorial blog. Content is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory information may change. Please check current primary sources and seek independent professional advice where appropriate.

© 2026 Compliance & Leadership Insights · Privacy · Terms · Disclaimer · Editorial Policy · About · Contact

bottom of page