Preview build — not the live site. Feedback welcome.

[email protected]

United Kingdom · South Africa · Australia

Solutions · Risk & regulatory

APRA CPG 235 Data Risk

CPG 235 expects data risk to be managed as part of change and business-as-usual, not ad hoc. We provide the framework that makes that practical across people, process and technology.

What we do

  • Assess data risk management against CPG 235 expectations
  • Put a formal data risk framework into change and BAU processes
  • Define roles, controls and reporting across people, process and technology
  • Give stakeholders timely access to accurate data for decisions

Outcomes

  • Data risk managed inside the board's risk appetite
  • Consistent practice rather than ad hoc, fragmented effort
  • Evidence of control for APRA and internal audit
  • A base that extends naturally to AI risk under CPS 230 and the AI letter

What the guide expects

APRA’s CPG 235 is clear that data risk management should not be ad hoc or fragmented. A regulated entity is expected to take a systematic and formalised approach, with data risk considered as part of both change and business-as-usual processes.

That single expectation has wide consequences. It means data risk needs owners, a defined appetite, controls that operate continuously, and reporting that reaches the people accountable. It applies across the data lifecycle: acquisition, storage, transformation, movement and use.

How we make it practical

We assess your current position against the guide, then put a formal framework in place across people, process and technology:

  • Accountability — named owners for critical data, with roles and responsibilities that survive reorganisation
  • Controls in the flow of work — data risk assessed as part of change, not as an annual exercise
  • Timely access to accurate data — so internal and external stakeholders can support their decisions
  • Risk inside appetite — exposures identified, measured and managed within the wider organisation’s risk appetite
  • Evidence — the documentation and reporting a supervisor expects to see

The framework is purpose-built and adapts to the entity: a general insurer, a bank and a superannuation trustee face the same guide with very different data landscapes.

The foundation for AI risk

CPG 235 was written for data risk, but the disciplines it asks for are the same ones AI governance now demands: inventories, ownership, lifecycle controls, and evidence that the controls work. Entities that have done this work have a base to build on as supervisors turn their attention to artificial intelligence. Those that have not are starting twice.

Common questions

What is CPG 235?

CPG 235 continues the concepts set out in BCBS 239. It is APRA's prudential practice guide for managing data risk in Australia, intended for executives as well as risk and technical specialists, and it expects data risk to be managed systematically rather than ad hoc.

Ready to move AI into production with proof?

Leave your details and we will arrange a conversation.

We reply within one business day. We never sell your details. Privacy notice