As the 1 July 2025 effective date for CPS 230 looms — now just days away — ReadiNow has continued its engagement with senior leaders across banking, insurance, superannuation, and financial services through a new series of roundtable discussions. These sessions build on insights gathered in 2024 and reveal a clear evolution in focus: from designing and building to embedding capabilities that will endure in BAU post effective date.
Participants also completed a short survey ahead of the discussions. The combination of real-time insights and structured feedback paints a compelling picture of an industry accelerating its transition from compliance programs to sustained operational resilience.
In 2024, most respondents were in the design and build phase. In March 2025, the majority were focused on implementation, though only around 20% had moved into embedding their new frameworks and processes.
That said, a powerful theme emerged: compliance is not a destination. As one participant put it, "We’re not aiming to cross a finish line — we’re building a new operating rhythm."
Key concerns included:
Some institutions are responding proactively. One major bank’s first-line COO is establishing a “Resilience Hub” to sustain oversight and drive enterprise-wide capability uplift beyond go-live.
While all CPS 230 components remain in focus, the top three areas receiving the most attention are:
Legacy incident management frameworks are also being redesigned to include critical operation owners, control owners, and service provider leads — a necessary step given the increased scale and complexity of incident scenarios under CPS 230.
Whilst the number one focus is still on Policy Framework and Processes, this has significantly reduced from 6 months ago, with the focus on Technology and Systems, and Data and Reporting, significantly increasing.
Organisations shared concern that recent tech investments may be point solutions that lack integration — and may not be ready to support the next generation of AI-powered resilience.
One attendee noted:
"We’ve made quick tech investments, but they aren’t future-proof. They won’t be able to take advantage of emerging AI capabilities."
In parallel, organisations are:
While risk, compliance, and technology teams remain heavily involved, 2025 is seeing more emphasis placed on first-line executives, control owners, and procurement functions, enabling hand over to BAU.
Procurement was consistently identified as a low-maturity capability, now under pressure to:
For many, this represents a major step-change — and a steep learning curve.
AI is no longer a futuristic concept — it is now being seen as a critical enabler of scale, efficiency, and insight.
Priority use cases include:
ReadiNow’s upcoming AI Agent Builder and OOTB AI Agents generated strong interest during the sessions, with many participants keen to explore practical applications in their environments.
To deliver strong outcomes by the CPS 230 effective date and beyond, risk leaders should consider:
The 2025 roundtables highlighted a significant mindset shift:
CPS 230 is ultimately a test of organisational maturity — in culture, change leadership, governance, and technology.
We thank all participants for their insights. ReadiNow remains committed to supporting this journey — with the tools, intelligence, and innovation required to build operational resilience that lasts.
With the July 2025 deadline fast approaching, now is the time to take stock of your CPS 230 readiness. If you’d like to discuss where your organisation stands, explore potential gaps, or see how AI can support a more efficient and confident approach to compliance, we’d be happy to connect.