The Australian Prudential Regulation Authority (APRA) has rescinded the 2018 Information Paper 'Outsourcing Involving Cloud Computing Services' in light of 'Prudential Standard CPS 230 Operational Risk Management' (CPS 230), which will come into effect on 1 July 2025.
The withdrawal of the paper aims to reduce regulatory burden and improve clarity about the expected approach for material service provider arrangements.
Regulated entities under APRA will be expected to comply with CPS 230 requirements when using cloud services to appropriately manage associated risks and ensure operational resilience.
Entities include general insurance companies, eligible foreign life insurers and private health insurers, as well as underwriting, claims management, insurance brokerage and reinsurance providers are included in the CPS 230.
CPS 230 can be accessed on APRA’s website.