Skip to main content

How to Leverage Ardoq to Support Australian APRA CPS230

Provides a how to implementation guide leveraging Ardoq to address regulatory requirements of the APRA CPS230 regulation.

Sean Gibson avatar
Written by Sean Gibson
Updated today

Written by Peter Houlihan (IM Systems)

Contents

Before You Begin

Familiarize yourself with these essential Ardoq solutions:


Purpose

Organizations can leverage Ardoq to address regulatory requirements of the Australian Prudential Regulation Authority's (APRA) Cross-Industry Prudential Standard for Operational Risk Management (CPS230). CPS230 came into force for organizations subject to the standard on July 1, 2025.

Building on concepts from Ardoq Compliance Assurance, we provide a framework for assessing and managing compliance to CPS230 and addressing related operational risks. This guide explains how to model relationships between CPS230's regulatory requirements and existing enterprise architecture components including business capabilities, processes, applications, and other information types.

We ensure these components undergo assessment for business criticality (as defined by CPS230), receive risk assessments, establish control and reporting structures, and identify resilience requirements.

This guide offers a step-by-step approach (pattern) you can tailor to different organizational needs, enabling companies to integrate CPS230's requirements into their existing compliance assurance processes effectively.

Note: While this guide focuses on CPS230 due to its recent introduction, you can apply this approach to any regulatory standard with equal effectiveness.


Prerequisites

To effectively implement CPS230 in Ardoq, develop a solid understanding of several key concepts and practices:

Essential Knowledge Areas:

  • Application Lifecycle Management - Oversee your organization's development, deployment, and ongoing support of applications and capabilities

  • Business Process Management - Manage operational flows and activities within your organization

  • Business Capability Realization - Focus on practical implementation and achievement of business goals

  • Organizational Patterns - Structure and manage enterprise components using proven frameworks

  • Application Risk Management - Mitigate risks associated with critical applications (optional but recommended)

These expertise areas form a comprehensive toolkit for successfully delivering CPS230 implementation in Ardoq.


Approach Summary

Follow this high-level process to implement CPS230 support in your organization:

  1. Model CPS230 requirements

  2. Identify relationships between CPS230 requirements and existing frameworks, controls, and policies

  3. Identify CPS230 Critical Operations and Critical Vendors

  4. Conduct CPS230 compliance assessments for Critical Operations

  5. Conduct CPS230 compliance assessments for Critical Vendors

  6. Model and implement CPS230 regulation maintenance processes

Implementation Notes

Ready-to-Use Model: We provide a working model of CPS230 requirements developed in conformance with the Compliance Assurance Ardoq Solution. Adopt these "as is" or review and model them to conform to your existing internal standards.

Business Capabilities as Foundation: We recommend using Business Capabilities as the principal concept for both planning and compliance assessment. However, we recognize many organizations either lack a widely recognized business capability model beyond the Enterprise Architecture team or have no agreed business capability model at all.

Alternative Approaches: We show how Organization Structure, Process or Functional Groupings, or your Conceptual Information Domain model can deliver similar results when business capability models aren't available.


Metamodel Elements of CPS230 Solution

This section explains the components and workspaces used in a CPS230 implementation. Ardoq introduces and defines these components in various Ardoq Solutions as described below.

Information Artifact

Regulation Workspace: Create a separate workspace for each regulation implemented in Ardoq. Use the Information Artifact component type template to represent the CPS230 regulation in this workspace.

Assessment Workspace: Create a single workspace to hold all assessments. Model assessments using the Information Artifact component type template.

For assessments, create fields to track CPS230 Criticality and potential financial data being processed. Use these fields to generate reports, copy them to the subject component, and identify further actions.

Reference: Information Artifact component types are introduced and defined in the Architecture Records Ardoq Solution.

Category

Use Category components to structure the Requirements that make up CPS230 and for categorizing assessments. Category components structure CPS230 requirements in a hierarchy of arbitrary depth, with leaf nodes being the component type organized within it.

Reference: The Category component type is described in How to use Categories in Ardoq.

Requirement

A requirement represents a specific obligation your organization must meet in addressing CPS230 regulation. It may also belong to a broader collection of requirements or characteristics that belong to an information artifact, such as a policy, set of principles, or formal specification (e.g., NIST Cybersecurity Framework or ISO 25010 Quality Model).

Business Capability

Ardoq defines a business capability as a logical activity or group of activities your organization performs. Unlike a business process, we define business capabilities by grouping activities that access or utilize a shared resource (like customer information) rather than in response to a particular trigger or event.

Capability Instance: Apply to Business and Technical Capabilities using the existing Capability component type with a field to indicate Atomic or Instance. Use a brief naming convention and instance workspace to suggest the component is an instance.

Business Process

The Business Process component represents a series of interconnected activities or tasks that transform inputs into outputs, following a defined sequence and set of rules. It represents the operational flow of activities within your organization.

Application

An application is the configuration of lower-level software or technology to provide specific business capability or technology capability, perform a defined task, or analyze particular information.

Information Asset

CPS230 (paragraph 25) states that "In managing technology risks, an APRA-regulated entity must monitor the age and health of its information assets and meet the requirements for information security in Prudential Standard CPS234 Information Security (CPS234)."

Under APRA's CPS230 and CPS234 standards, an Information Asset encompasses any information that has value to your organization and requires protection to maintain its confidentiality, integrity, and availability. These assets include both the information itself and the systems, processes, and infrastructure that store, process, or transmit that information.

Implementation: Use the Workspace Information Assets holding Information Asset components as your Information Asset register. Categorize Information Assets according to Information Domains.

Organization Unit

An organization represents the top-level component of your organization and other organizations forming part of your broader ecosystem, such as partners.

Organizational Units decompose into business units, departments, sub-organizations, committees, teams, and groups to enable organizational hierarchy creation. Document both structural (hierarchical) and functional entities within your organization using the Organizational Unit component.

External Organisation

Create a separate workspace to hold External Organizations, particularly organizations considered Material Service Providers as defined in CPS230.


Implementation Guide

Step 1: Model the CPS230 Requirements

Model CPS230 requirements as 'Requirement' component types in the CPS230 Workspace. We provide an Excel template containing our analysis of CPS230 requirements to assist with importing regulation requirements. Review these requirements to ensure they meet your organization's understanding.

Implementation Steps:

  1. Create an information artifact representing CPS230

  2. Create regulation categories (subject areas) as children of CPS230

  3. Create all regulation requirements as 'Requirement' component types for children of the relevant category

Step 2: Connect CPS230 Requirements with Existing Frameworks

Integrate CPS230 regulation requirements into existing organizational standards, frameworks, and internal controls, including external frameworks like AS ISO 31000 (Risk Management), AS ISO/IEC 27001 (Information security management), or ITIL.

Integration Steps:

  1. Link baseline requirements - Once you have CPS230 regulation baseline requirements in Ardoq, link them to existing standards or frameworks you have in place

  2. Create relationships - Establish links between individual CPS230 regulations and specific parts of different frameworks you've implemented that support CPS230 regulation requirements

  3. Generate compliance reports - Create reports demonstrating compliance and show your progress in addressing CPS230 regulation requirements through implemented standards, frameworks, and policies

  4. Connect internal controls - Link internal controls and policies implemented as part of your risk management or IT service management practices directly to regulations addressing CPS230 concerns

Step 3: Conduct Business Capability Assessment

Create and configure an assessment workspace in Ardoq, including setting up a 'CPS230 Capability Assessment' to evaluate individual business capabilities. This process includes setting up fields to capture relevant data, establishing relationships between regulatory requirements and assessed capabilities, and using tools like surveys and scripts to manage and analyze assessment results.

Assessment Implementation:

  1. Create assessment workspace - Include information artifact and category component types (Architecture Records Metamodel provides further details)

  2. Create capability assessment - Use the information artifact component type to create a 'CPS230 Capability Assessment' to assess your capabilities individually

  3. Configure assessment fields - Create fields relevant to your assessment criteria that align with CPS230 regulation aspects you're evaluating. These fields capture details such as CPS230 criticality, financial information type being processed, and other relevant artifacts

  4. Create child assessments - Create child assessments in the Assessment Workspace for every capability as a 1:1 relationship. For example, if you have a card payment capability, assess it annually to ensure ongoing compliance

  5. Establish regulatory relationships - Create an 'is realized by' reference from CPS230 Regulation Requirement to the assessment component type created in step 2

  6. Establish capability relationships - Create an 'is subject of' reference from individual CPS230 Assessment to the related business capability that 'is subject of' the assessment component type

  7. Populate assessment data - Manually enter data or use the survey function to populate field values on capability assessment to assess each capability

  8. Assign criticality - After assessing capabilities, use assessment results to assign a 'CPS230 Criticality' field value to the capability. Create a Gremlin script to copy field values from your assessment to the capability, helping identify individual business capabilities for heat mapping and reporting

Step 4: Identify CPS230 Critical Business Capability Ecosystem Elements

For simplicity, we refer to the Processes, Applications, Information Assets, and Organizational structures that realize a Business Capability as the Capability Ecosystem.

To prioritize effort effectively, understand which Ecosystem parts directly support CPS230 Critical Business Capabilities. For CPS230 critical capabilities, assess all supporting Ecosystem parts that enable those capabilities within your organization.

Ecosystem Assessment Steps:

  1. Create ecosystem assessments - In the Assessment Workspace, create a 'CPS230 Application Assessment' as a 1:1 relationship for each Ecosystem element that realizes a CPS230 Critical Business Capability

  2. Configure ecosystem fields - Create relevant field values for CPS230 criticality for those Ecosystem elements. Use list fields for CPS230 Capability Criticality, multi-select lists for CPS230 Data Types, and CPS230 Status to identify element compliance status and information types stored or processed

  3. Establish element relationships - Create an 'is subject of' reference from Assessment to each individual CPS230 applicable Ecosystem element

  4. Assess ecosystem elements - Assess the related element that 'is subject of' the assessment component type created in step 1

  5. Deploy surveys - Use survey functionality to have owners respond to surveys completing assessment fields. Automate regular sending through Ardoq's broadcast functionality

  6. Transfer criticality data - After collecting application assessment data, create a Gremlin script to copy CPS230 Criticality field values to the element being assessed from the assessment component, enabling heat map generation and reporting

  1. Generate insights - Use Ardoq's reporting and visualization to identify relevant applications and their enterprise architecture integration

  2. Implement risk controls - Once you've determined CPS230-relevant elements, conduct further risk assessment using the Application Risk Management solution and implement controls on necessary applications

Step 5: Document and Assess CPS230 Material Service Providers

CPS230 defines a Material Service Provider as:

"Material service providers are those on which the entity relies to undertake a critical operation or that expose it to material operational risk."

Our model interprets Material Service Providers as entities external to your organization that provide:

  • A critical process, or possibly step in a Critical Process, as part of a contractual arrangement, OR

  • Licenses or supports a Critical Application

Material Service Provider Implementation:

  1. Create external organization workspace - Use or create an External Organizations Workspace using the Organization component type to hold Material Service Providers

  2. Configure provider fields - Create an additional field to identify CPS230 Material Service Providers and add fields to capture all relevant CPS230-specific information (address, business operation numbers, company numbers, contact information, support details)

  3. Identify critical providers - Start by identifying support/vendor organizations that provide critical CPS230 applications

Conducting CPS230 Vendor Assessments:

  1. Create vendor assessments - Create a 'CPS230 Vendor Assessment' as a 1:1 relationship for each organization identified as a Material Service Provider and update relevant fields

  2. Establish assessment relationships - Create an 'is subject of' reference from individual CPS230 Vendor Assessment to the related organization component that 'is subject of' the assessment

  3. Deploy vendor surveys - Use survey functionality to have application, process, information asset owners, or relevant third-party contacts respond to surveys completing assessment fields. Automate regular sending through Ardoq's broadcast functionality

  4. Transfer vendor data - After collecting vendor assessment data, create a Gremlin script to copy CPS230 Criticality field values to the relevant organization component, enabling heat map generation and reporting on suppliers connected to CPS230 critical applications


Complementary Activities

Document Your Incident Management Process

While Ardoq doesn't directly address incident management, you may already have an ITSM process for incident management and response. Use Ardoq to manage your processes and model processes relevant to your organization in this area.

Following Ardoq's business process management solution guidance, create each process relevant to your organization to demonstrate to external auditors how you realize your incident management process.

ITSM Integration Benefits:

  • Extract critical events from CMDB and ITSM tools

  • Create reports using field values to address individual applications

  • Combine ITSM data with Ardoq and your enterprise architecture model

  • Create reports and visualizations understanding major incident impact

  • Provide 360-degree view of critical incident impact

  • Assist with CPS230's reporting requirements through dashboards

Document Application Resilience Testing

While Ardoq doesn't directly address application resilience testing or business continuity plan production, you can easily manage documentation for these efforts and create groups to report on current resilience test status and business continuity plan existence.

Expand Application Component Fields:

  • Resilience Testing Results

  • Testing Documentation Scope URL

  • Testing Documentation Results URL

  • Resilience Test Date

  • Business Continuity Plan URL (if required)

  • Business Continuity Plan Approval Date

Use broadcasts to notify application owners annually to review and conduct resilience tests and update business continuity plans as necessary.

Information Sharing

CPS230 highlights the need to report internal and external information related to critical incidents, threats, and vulnerabilities.

External Reporting: Compile External Incident Reports in Ardoq including organizational impact and information relating to connected components' capabilities, applications, and vendors specific to incidents. Create reports and presentations to share with external regulators.

Internal Reporting: Compile Internal Incident Reports in Ardoq including organizational impact and details about capabilities, applications, and vendors connected to incidents. Create reports and presentations to share with internal stakeholders.

Process Documentation: Model internal and external information-sharing processes within your organization to demonstrate how your organization shares or will share information as necessary demands require.

Note: Ardoq recommends tracking threats and vulnerabilities in other systems and summarizing them in Ardoq.


Alternative Approaches

We recommend using Business Capabilities as the principal concept for both planning and compliance assessment. However, we recognize many organizations either lack a business capability model widely recognized beyond the Enterprise Architecture team or have no agreed business capability model at all.

You can use Organization Structure, Process or Functional Groupings, or your Conceptual Information Domain model as the organizing principle to deliver similar results with minor modifications.

Why Business Capabilities Work Best for CPS230

Strategic Alignment: CPS230 emphasizes operational resilience from a strategic perspective. Business capabilities represent what your organization needs to be able to do to deliver value to customers and stakeholders, directly aligning with the standard's focus on maintaining critical operations during disruption.

Risk-Based Approach: The standard requires entities to identify and manage operational risks that could materially impact business operations. Business capabilities provide a higher-level view helping identify dependencies and single points of failure across multiple processes supporting the same capability.

Service Delivery Focus: CPS230 fundamentally ensures continuity of service delivery to customers. Business capabilities map more naturally to customer-facing services and outcomes, while processes are often internal and fragmented across different organizational silos.

Tolerance Setting: The standard requires setting operational risk tolerances. Define these more meaningfully at the capability level (e.g., "ability to process customer payments") rather than at granular process or application levels.

Process-Oriented Approach

If you're a process-oriented organization, use the process hierarchy you've already documented or a common model such as APQC to act as your Business Capability equivalent. Create references to Applications and Information Assets to represent the "Realized By" relationship in our metamodel.

Information-Oriented Organization

Many organizations have an existing Information or Data Domain model and conceptual data model. Use this as a proxy for Business Capability (if you're adhering to the Business Architecture Guild approach to Business Capability modeling, there may be 1-to-1 alignment). Then follow the guide as above.

Using Organizational Structure

Many organizations have structures that are functionally or capability-aligned. If no other architectural models are available, use Organization Structure as a proxy for a Business Capability model to implement this guide in Ardoq. Keep the lowest organization levels as process or service equivalents and use Application to Organizational Unit ownership to represent "Is Supported By" in our CPS230 metamodel.


Extending the Solution

CPS230 requirements imply maintaining several information registers. The metamodel presented above allows us to identify and manage three of these registers (Operational Risk, Critical Operations, Material Service Provider, and Information Asset Register). You can extend the solution to include management of all registers required by CPS230 for compliance if these aren't already managed elsewhere.

Maintaining these items as formal organizational registers implies:

  1. Documented processes for maintaining, reviewing, and deprecating items within registers

  2. Clear ownership management kept up to date

  3. Regular reporting to Board and Management ensuring appropriate information provision for effective governance

Registers Addressed in the Metamodel

Register

Purpose

CPS230 Reference

Operational Risk Register

Tracks identified operational risks, control measures, and remediation actions

Operational Risk Management (Sec 16-19)

Critical Operations Register

Identifies and categorizes essential business operations that must be maintained during disruptions

Critical Operations & Tolerance Levels (Sec 34-39)

Material Service Providers Register

Maintains records of third-party service providers critical to operations

Service Provider Management (Sec 47-52)

Information Asset Register

Helps track critical IT systems, dependencies, and risks related to information security

Operational Risk Controls (Sec 25)

Additional Registers Possible to Implement in Ardoq

Register

Purpose

CPS230 Reference

Business Continuity Plan Register

Tracks BCP plans, their location, ownership, and status

Business Continuity Plan (Sec 40-46)

Business Continuity Testing Register

Tracks BCP tests and exercises to ensure operational resilience

Business Continuity Plan (Sec 40-46)

Service Provider Agreements Register

Documents formal agreements with third-party providers, ensuring compliance with APRA expectations

Service Provider Agreements (Sec 53-57)

APRA Notification Register

Tracks all reports and notifications submitted to APRA regarding operational risk events

Notification & Review (Sec 58-60)

Board & Senior Management Oversight Register

Tracks key decisions, risk discussions, and policy approvals by Board and senior management

Governance & Accountability (Sec 20-23)

Did this answer your question?