How does Annie support APRA CPS 234 compliance?
APRA CPS 234 requires regulated entities to maintain information security capabilities commensurate with the threats facing their information assets, and to notify APRA of material information security incidents.
Annie supports CPS 234 compliance in four key areas:
Data residency — Annie can be deployed on Australian infrastructure with no cross-border data transfers, supporting the control requirements CPS 234 imposes on cloud and outsourced arrangements.
Access controls — Annie's role-based access control and audit logging are designed to meet CPS 234's requirements for controlling and monitoring access to information assets.
Third-party risk — Because Annie's inference runs on your infrastructure rather than a third-party cloud, the AI inference function is not treated as a third-party arrangement for CPS 234 purposes. This substantially reduces the third-party risk management burden associated with AI adoption.
Incident documentation — Annie's audit trail and Judgment Panel records support the documentation requirements that underpin CPS 234 incident assessment and notification obligations.
Annie does not provide legal or compliance advice. Engage your compliance team and external advisers to assess CPS 234 applicability to your specific deployment.