The requirements page lists all 24 operative paragraphs of CPS 234. Each carries an implementation status, an owner, implementation notes, evidence and a review date, and each has authored guidance describing what satisfies it and what a reviewer rejects.
Status values
The same four values used across every Venvera framework: Not Implemented, Partial, Implemented and Not Applicable. Use Not Applicable sparingly here. CPS 234 contains very few requirements an APRA-regulated entity can genuinely exclude, and an exclusion needs a recorded justification a reviewer would accept.
The word "commensurate"
CPS 234 uses the word repeatedly and never defines it, because APRA regulates entities from small RSE licensees to major banks. That places the burden on you to show the reasoning behind your sizing decision, not merely that controls exist.
The third party paragraphs
Four requirements carry an explicit footnote in the standard stating they apply to all information assets managed by related parties and third parties, not only those under material outsourcing agreements per CPS 231 or SPS 231.
| Requirement | Duty |
|---|---|
| CPS234-16 | Assess the party's information security capability, scaled to what an incident affecting those assets would cost you |
| CPS234-22 | Evaluate the design of that party's controls. Design specifically, which a completed questionnaire does not establish |
| CPS234-28 | Where you rely on their testing, assess whether its nature and frequency is commensurate with the five factors in paragraph 27 |
| CPS234-34 | Where internal audit intends to rely on their assurance and an incident could materially affect you or your customers, internal audit must assess that assurance |
Scoping this work to the material outsourcing register is the most common real gap in the standard. Count the parties that actually hold your information assets against the parties you assessed.
Evidence
Attach evidence to the requirement it supports. The authored guidance on each requirement lists the artefacts a reviewer asks for and states what gets rejected, so use it as the acceptance test before you attach a document. Evidence that also answers another framework propagates through the crosswalk: CPS 234 shares mapping groups with ISO 27001 for policy framework, asset classification, third party risk, supplier due diligence, incident management, post incident review and incident reporting.