For years, third-party risk has occupied an awkward spot on the register. It is one of the most common ways an organisation actually gets breached, and yet it stays chronically under-invested, managed for the most part by an annual questionnaire that tells you very little about anyone’s real exposure. As of the first of July, that gap stopped being a question of good practice and became a question of obligation.

APRA’s CPS 230 is now fully in force, and its material service provider requirements have teeth. The standard expects regulated organisations to identify the providers they genuinely rely on, to understand and manage the risks those relationships carry, and, crucially, to be able to demonstrate all of it rather than simply assert it. SOCI pushes in the same direction for critical infrastructure, and across both regimes the accountability increasingly lands on named individuals rather than on the institution in the abstract.

Why the questionnaire era is ending

The problem with the way most organisations have handled this is not effort, it is method. A questionnaire is a point-in-time snapshot of what a supplier is willing to tell you about themselves, captured once a year and out of date almost immediately. It cannot see a change of ownership three months later, a new subcontractor brought in quietly behind the scenes, or a shift in a supplier’s own security posture. When a regulator or a board asks you to show where you stand today, a filing cabinet full of last year’s self-assessments is not an answer.

From attesting to proving

The shift CPS 230 forces is subtle but fundamental, because it moves the obligation from holding a policy to proving a position. Proving a position means your view of a supplier is current rather than annual, evidence-led rather than self-reported, and continuous rather than episodic. It means you can say, on any given day, not merely that you asked the right questions once, but that you know where you stand right now and can put that in front of anyone who is entitled to ask.

CPS 230 moves the obligation from holding a policy to proving a position.

What good looks like

In practice, a defensible third-party position tends to share a few features. It is continuous, recalculating as the world changes rather than waiting for the next review cycle. It is broad enough to cover the things that actually carry the risk, which means supplier relationships, ownership and control, and the people involved, not cyber hygiene alone. And it is independently validated, so that what you report rests on evidence rather than on a supplier’s word for it. None of that is exotic. It is simply the difference between managing third-party risk as an operation and managing it as a form-filling exercise.

The organisations that will find CPS 230 comfortable are the ones that were already treating third-party trust as something to be maintained rather than declared. For everyone else, the first of July was less a deadline than a starting line, and the work now is to build a position you can stand behind on the day someone asks. That is the work we spend our time on.