Under APRA's Prudential Standard CPS 230 (Operational Risk Management, effective 1 July 2025, in full effect since 1 July 2026), a material service provider is any third party an APRA-regulated entity relies on to deliver a critical operation, or that exposes it to material operational risk, including AI and cloud vendors.
A service provider is material under CPS 230 when the regulated entity relies on it to undertake a critical operation, or when the provider exposes the entity to material operational risk. Either condition is enough on its own, an otherwise low-risk vendor can still be material if the operation it supports is critical, and a vendor supporting a non-critical function can still be material if it carries enough operational risk exposure.
This is a deliberately broader test than CPS 230's predecessor, CPS 231, which only applied to the outsourcing of activities an entity could otherwise perform in-house. CPS 230 extends to services that were never candidates for in-house delivery, which is why AI and cloud vendors, foundation model providers, and specialist AI tooling routinely qualify even though no regulated entity would build a foundation model itself.
Regulated entities must maintain a current register of every material service provider, covering the provider's identity, its materiality status and the reasoning behind it, a description of the service, agreement details, and the individual accountable for the relationship internally. The register is a live compliance artefact, not a one-off exercise, entities are expected to keep it current as vendor relationships and AI deployments change.
Before entering into, or substantially modifying, a material arrangement, the regulated entity must conduct due diligence and a risk assessment on the provider. This does not end at signing, CPS 230 expects ongoing monitoring of the relationship for the life of the contract, including visibility into the provider's own subcontractors (its fourth parties), since a failure two links down the chain can still disrupt the regulated entity.
APRA sets out mandatory content for agreements with material service providers. A contract missing any of these is a compliance gap regardless of how the commercial terms read:
CPS 230 became effective 1 July 2025, but pre-existing contracts had a transition window, they needed to comply by their next renewal date or 1 July 2026, whichever came first. That window has now closed: as of 1 July 2026, every material service provider arrangement, including AI vendor contracts signed before the standard existed, must meet CPS 230's requirements in full.
In practice, this means AI vendor contracts negotiated before mid-2025 are now the highest-risk gap for many regulated entities, they were written without APRA access clauses, fourth-party notification requirements, or subcontractor liability provisions, because CPS 230 did not yet exist when they were signed.
This page is general information about material service providers under APRA CPS 230, not legal or compliance advice, and does not capture every nuance or exception. Always verify against APRA's own published standard and your own qualified legal counsel before relying on it.