CPS 234 information security made measurable

Map APRA CPS 234 capability requirements, centralise evidence, and give boards and risk committees a clear view of information security posture.

From policy binders to defensible capability

CPS 234 requires APRA-regulated entities to maintain information security capability commensurate with the size and extent of threats to their information assets - not just documented policies.

Boards must understand whether controls are designed and operating effectively. Spreadsheets and scattered artefacts make that hard to prove under time pressure.

Constant structures CPS 234 domains, assigns owners, collects evidence, and tracks remediation so assurance conversations focus on outcomes rather than file hunting.

Board-ready assurance views

Risk committees need a consistent story: what capability exists, where gaps remain, and what remediation is underway. Constant turns control status and evidence into reporting your board can act on - without implying APRA certification.

Built for APRA-regulated organisations

  • Banks, insurers, and superannuation trustees subject to CPS 234
  • Risk and compliance teams preparing for APRA engagement or internal assurance
  • CISOs and security leaders reporting information security capability to the board
  • MSPs supporting regulated financial services clients

CPS 234 capability domains

Explore the capability areas Constant organises around CPS 234. Expand each domain for how teams typically evidence and assure it.

Document how information security is governed: roles, policy hierarchy, and accountability. Constant tracks whether policies are current, owned, and linked to the controls they enable - so assurance reviews start from a complete picture rather than a shared drive.

Entities need to know which information assets matter and who owns them. Assessments capture asset scope, classification, and control coverage so capability claims stay tied to what is actually protected.

Map technical and process controls to CPS 234 expectations. Evidence collection shows whether controls are implemented in production (not only described in policy) with remediation workflows when gaps appear.

Schedule and record control testing, penetration testing outcomes, and independent reviews. Findings become tracked work items so testing drives improvement instead of becoming a one-off report.

Maintain incident playbooks, detection evidence, and notification workflows. Constant helps you show that incident capability is defined, tested, and owned before an event forces the issue.

Internal audit findings feed the same remediation backlog as day-to-day assessments. Boards see whether issues are closed, overdue, or accepted with rationale.

What you get with Constant

Capability mapping

Structure assessments around CPS 234 information security capability domains with clear control guidance.

Evidence at control level

Link policies, test results, and operational artefacts to the controls that demonstrate capability.

Assessor-led validation

Certified assessors review critical controls so gaps are identified before APRA or internal audit.

Committee reporting

Summarise open gaps, owners, and remediation progress for risk committees and board packs.

CPS 234 Information Security FAQs

Start your compliance journey today

Choose the right plan for your organisation. Scale seamlessly as your compliance needs evolve.

Ready to simplify your compliance process?

Book a demo and see constant in action.

All Paid Plans Include

  • Certified assessors

  • Automated evidence collection

  • Unlimited assessor reviews

  • AI-powered pre-reviews

  • Real-time compliance dashboards

  • Priority support

  • Advanced reporting & exports

  • Single sign-on (SSO)

  • Audit-ready documentation

  • Role-based access controls

  • API & integrations

  • Australian data residency