Venvera is CPS 234 compliance software that runs the standard the way it is actually assessed: all 24 requirements from paragraphs 13 to 36 with the evidence a reviewer accepts, third party coverage that reaches past the outsourcing register, and both notification clocks where someone can find them at 2am.
Pick the framework you already run. Every control domain that appears in both is listed with the requirement reference on each side, so you can see the reusable part of your existing programme before you scope any new work.
A row means the two requirements cover the same ground, so one implementation and one set of evidence can usually serve both. It does not mean satisfying one certifies the other: each framework keeps its own scope, wording and assessment, and some requirements have no counterpart at all. Treat this as a starting map for planning, then confirm each row against the requirement text.
Venvera ships APRA Prudential Standard CPS 234 as its 24 operative requirements, paragraphs 13 to 36, grouped under the standard’s own nine headings: roles and responsibilities, information security capability, policy framework, information asset identification and classification, implementation of controls, incident management, testing control effectiveness, internal audit and APRA notification. Each requirement carries an owner, a status, its own evidence and authored guidance on what satisfies it and what a reviewer rejects. A 42 question gap assessment scores the judgements the standard deliberately leaves open, and the recurring duties land on a compliance calendar with owners and dates.
CPS 234 Information Security is the APRA prudential standard requiring an APRA-regulated entity to be resilient against information security incidents, including cyber attacks. It applies to ADIs including foreign ADIs, general insurers, life companies and friendly societies, private health insurers and RSE licensees. It commenced on 1 July 2019, and where a third party manages your information assets it applied from the earlier of the next contract renewal or 1 July 2020. The Board is ultimately responsible for the information security of the entity, which is stated in paragraph 13 and is the sentence that shapes everything else: the evidence has to be good enough to put in front of directors who carry the accountability personally.

Every operative paragraph of CPS 234, from the Board’s ultimate responsibility in paragraph 13 to the 10 business day control weakness notification in paragraph 36, referenced by paragraph number because that is how APRA, your internal audit function and a tripartite reviewer all cite it. Each one carries authored guidance on the artefacts a reviewer asks for and, just as importantly, what gets rejected: an undated plan, a questionnaire standing in for an evaluation of control design, a capability assessment that has not moved in two years.

Commensurate appears again and again in CPS 234 and is deliberately left undefined, because APRA regulates everything from a small RSE licensee to a major bank. That shifts the burden onto you: it is not enough for controls to be adequate, you have to show the reasoning by which you decided they were the right size for the threats to your information assets. The 42 question gap assessment targets exactly these judgements, scoring them 0 to 4 so the sizing rationale becomes a record rather than an argument you have to reconstruct in a review.

Paragraphs 16, 22, 28 and 34 each carry a footnote saying they apply to all information assets managed by related parties and third parties, not only those under material outsourcing agreements per CPS 231 or SPS 231. Scoping that work to the outsourcing register is the most common real gap in the standard, and it is usually invisible until someone counts the parties that actually hold data against the parties that were assessed. Venvera tracks the four third party duties separately: capability assessment, evaluation of control design, assessment of the testing you rely on, and internal audit’s assessment of assurance.

Paragraph 27 asks for a systematic testing programme whose nature and frequency are set against five factors, including the risk from environments where you cannot enforce your own policies. Paragraph 30 asks that testing be done by specialists who are appropriately skilled and functionally independent, which is about reporting lines rather than about hiring an external firm. Paragraph 29 asks you to escalate deficiencies you cannot remediate in time, and that escalation record is usually the first thing a reviewer asks for. All three are tracked as separate requirements because entities commonly satisfy one and assume it covers the others.

Paragraph 35 gives you 72 hours from becoming aware of a material information security incident, and it has a second limb most procedures miss: an incident notified to any other regulator, in Australia or overseas, triggers APRA notification whether or not you assess it as material to yourself. Paragraph 36 is a separate 10 business day clock for a material control weakness you expect you cannot remediate in a timely manner, and it starts when you become aware of the weakness, not when you conclude it is unfixable. Both are carried as requirements with their own evidence, so the procedure and its rehearsal are recorded rather than assumed.

CPS 234 creates recurring work, and the year between reviews has to produce a record. Venvera carries those duties on the compliance calendar: the annual review and test of the information security response plans required by paragraph 26, the annual review of the testing programme’s sufficiency under paragraph 31, the internal audit review of control design and operating effectiveness under paragraphs 32 to 34, the refresh of the asset classification that paragraphs 20 and 21 depend on, and the reassessment of the third parties covered by paragraphs 16, 22 and 28. Each carries the paragraph it serves, so a calendar entry traces back to the standard.

Start with a free gap report on the framework that is blocking you - 10 minutes, no email to start.
✓ Every paid plan: audit-ready in 90 days, or your money back*
10 minutes · no email to start · no credit card · yours to keep