1 Oct 2026 Tetiana George 7 min read

CPS 230 Third-Party Oversight for Insurers, One Year In | Curium

Abstract neon light trails in blue, pink, purple and orange with the title “CPS 230 third-party oversight, one year in: why it got convoluted for insurers.

CPS 230's grace period is over. Why third-party oversight got convoluted for insurers, and how to make it straightforward, easy and automated.

One year after CPS 230 took effect, the challenge for insurers is no longer building third-party oversight but running it. Since 1 July 2026, every material service provider arrangement must comply. Oversight works when there is one record per provider, owners complete their checks on schedule, and the outsourced work itself is tested, not just the paperwork.

Key takeaways

  • CPS 230’s transition ended on 1 July 2026; every material arrangement must now comply, however old the contract.
  • 30% of CPS 230 project participants say operationalising the standard is their biggest challenge; 23% are struggling with material service provider management (EY).
  • APRA expects insurers to actively monitor providers, “not just hold the paper”.
  • An insurer’s heaviest outsourcing is usually underwriting and claims, where the evidence sits in the files.

What changed on 1 July 2026?

On 1 July 2026 the last piece of CPS 230’s transition fell away. Every material arrangement now has to meet the standard, however old the contract behind it. As one legal update put it, there is no grace period after the grace period.

For most insurers, the hard part of the build is done. Registers exist, critical operations are defined, tolerance levels have been set and contracts have been uplifted. The project teams that delivered all of that have mostly moved on.

What’s left is running it: every provider, every quarter, with the people who were there before the project started. That is where CPS 230 is proving hardest.

What are insurers and their advisers saying about CPS 230?

The challenge has moved from design to day-to-day operation. In EY’s lessons from CPS 230 project teams, 30% of participants named operationalising the foundations as their biggest challenge, and 23% said they were struggling with material service provider management. EY also notes that providers’ control maturity varies so much that few will be monitored the same way.

MinterEllison describes the patterns that follow. Due diligence is done at onboarding, then left alone. Firms rely on vendor self-assessments and audit certificates without independently verifying controls. And oversight roles are “often fragmented across procurement, IT, legal, and risk.”

APRA has been clear about where it wants insurers to land. Its April 2026 letter on AI, summarised by MinterEllison, called third-party and supply chain risk the widest gap between current practice and regulatory expectations. Institutions must “actively monitor supplier performance against those provisions, not just hold the paper.” APRA is running targeted CPS 230 reviews through 2025–26 and 2026–27 before moving to standard supervision.

Why has third-party oversight become so convoluted?

CPS 230 is the right standard. It asks a simple question: do you know who you rely on for your critical operations, and can you show you are managing that risk? The difficulty is structural, not conceptual.

The Head of Compliance owns the accountability, but not the relationships. Procurement holds the contracts. Claims manages the assessors, repairers and third-party administrators. Distribution manages the MGAs. IT manages the core systems and the cloud. Each keeps its own records, in its own way.

So the machinery gets heavy. Registers live in spreadsheets that are out of date by the next review. Questionnaires come back as self-assessments that nobody has time to verify. Compliance chases the business by email, and the Board pack is rebuilt by hand every quarter. None of it fails dramatically. It drifts, quietly, until a review or an incident finds the gap.

What does good CPS 230 third-party risk management look like?

Good third-party risk management under CPS 230 comes down to three qualities: it is straightforward, easy and automated.

Straightforward. One record per material arrangement, not five spreadsheets. The critical operation it supports, the provider and its owner, the risks raised against it, the controls that manage them, and the evidence that they work, all in one place. When the Board asks about a provider, the answer is one click deep.

Easy. The business does its part and compliance stops chasing. Each governance check and attestation is a task with an owner and a due date. Owners see what’s due, status updates as they complete it, and overdue items are visible the day they slip, not at the next audit. First line owns the work; second line sees the status.

Automated. Test the work, not just the paperwork. A certificate tells you a provider says it is compliant. An audit of the provider’s actual files tells you what it did. AI file audits make that testing practical at a scale no review team could reach by hand, with every finding citing the file, the obligation and the provider responsible.

Which third parties should insurers focus on first?

Most third-party risk tooling was built around IT suppliers: security questionnaires, SOC reports, uptime. Those matter. But an insurer’s heaviest outsourcing is usually not IT. It’s the work done on its customers, under its name.

  • MGAs and underwriting agencies writing business on your paper under delegated authority. The Underwriting Agencies Council has flagged outsourced underwriting to agencies as an APRA focus.
  • Claims partners such as third-party administrators, assessors and repairers, making decisions your customers experience as yours.
  • Technology providers, including the AI inside them, where APRA’s April 2026 letter found dependencies often buried one layer below the contract.

For the first two, a questionnaire can’t tell you much. The evidence is in the files: the binder decisions, the claims handled, the customer communications. That’s where oversight needs to reach.

How does Curium make CPS 230 oversight simple?

Curium is compliance, risk and claims software built for insurance, not a general governance tool configured for it afterwards. For CPS 230, that means:

  • Your material arrangements in one record. Providers linked to the critical operations they support, each with an owner, governance details, linked risks and controls.
  • Governance checks and attestations that run on a schedule. Assigned to the business owner, tracked to completion, with status visible to compliance without a chaser.
  • AI file audits of outsourced work. Binder files from your MGAs and claims files from your partners, tested against your standards, with every finding citing its evidence. In our first client deployment, the audit engine cut reviewer time by 78%; results depend on file type and review depth.
  • Board-ready status from the live record. Who owns each provider, whether the controls are working, and where to look first.

We’ve made third-party oversight straightforward, easy and automated. It’s not convoluted any more.

Book a conversation to see how it works for your providers.

Frequently asked questions

What is a material service provider under CPS 230? A material service provider is a third party an APRA-regulated entity relies on to undertake a critical operation, or one whose arrangement exposes the entity to material operational risk. Insurers must keep a register of them and meet CPS 230’s contract, due diligence and monitoring requirements for each.

What is a critical operation? A critical operation is a process that, if disrupted beyond tolerance levels, would have a material adverse impact on policyholders or the insurer’s role in the financial system. For insurers, CPS 230 includes claims processing by default. Each critical operation needs tolerance levels for maximum disruption, data loss and minimum service levels.

What is a fourth party? A fourth party is a provider your third party relies on, such as the cloud host behind a claims platform or the AI model inside a vendor’s product. APRA expects insurers to understand these dependencies, not just their direct contracts.

What changed on 1 July 2026? The CPS 230 transition period for pre-existing contracts ended. Every material arrangement must now meet the standard, unless it falls within APRA’s narrow exemptions for providers such as regulators, central banks and payment system operators.

Are MGAs material service providers? Often, yes. An MGA underwriting on an insurer’s paper under a binder typically supports a critical operation, which puts the arrangement in scope. The Underwriting Agencies Council has flagged outsourced underwriting to agencies as an APRA focus.

How often should insurers review material service providers? CPS 230 expects ongoing monitoring, not a one-off review. In practice, insurers set a frequency for each governance check based on the provider’s risk, with more frequent checks for providers supporting critical operations.

Sources
EY — Lessons and advice for CPS 230 project teams in the final stretch

MinterEllison — CPS 230 raises the bar on third-party risk

MinterEllison — APRA’s AI letter: a wake-up call for managing your third-party suppliers

Corrs Chambers Westgarth — New insights for ensuring compliance with APRA’s CPS 230

AI Risk Aware — CPS 230’s grace period has ended

Underwriting Agencies Council — Regulatory change (CPS 230)

APRA — Operational risk management (CPS 230 and CPG 230) ** **

Regulation Tomorrow — APRA finalises targeted amendments to CPS 230

Ready to turn claims and compliance into your competitive advantage?