🏦 Financial Services 🔒 CPS 234 Compliance

APRA CPS 234 Require Secure Data Destruction?

For a bank, insurer or super fund, information security does not end when a device is retired. APRA CPS 234 ties your controls to the whole life of an information asset, and disposal is explicitly part of that life. Here is what the standard actually says, why your retired IT sits squarely inside it, and how regulated entities destroy end-of-life data in a way they can prove to an auditor.

Certified to ISO 27001:2022 NIST 800-88 Destruction Certificate for Every Device

The Quick Answer

Does CPS 234 require secure data destruction?

Not in those exact words, but in effect, yes. CPS 234 does not contain the phrase "data destruction". What it does require is that an APRA-regulated entity maintain information security controls "commensurate with the stage at which the information assets are within their life-cycle", and the standard defines that life-cycle as running "from planning and design through to decommissioning and disposal". In plain terms, your duty to protect the information on a device does not stop when you stop using the device. It runs right through to the point you dispose of it. For a bank, insurer or super fund, meeting that duty means retiring IT through a process that destroys the data to a recognised standard and documents that it was done. That is exactly what secure IT disposal for financial services is built to deliver.

The reason this matters is that end-of-life is where information security is easiest to forget. A retired laptop, a decommissioned server, a returned payment terminal or a swapped-out photocopier can sit in a store room for months, still holding customer records, and never appear on a risk register. CPS 234 closes that gap by making the whole life-cycle, disposal included, part of the controls you are expected to maintain. This guide walks through who the standard covers, what it says about disposal, why your disposal provider is itself in scope, and what a compliant, provable destruction actually looks like.

Who Does CPS 234 Apply To?

CPS 234 is a prudential standard that applies across every APRA-regulated industry. If APRA regulates you, disposal of your information assets is in scope.

Banks
Authorised deposit-taking institutions. Banks, building societies and credit unions holding customer financial records.
ADIs
Insurers
General, life and private health insurers. Holding policyholder, claims and health information.
Insurance & friendly societies
Super
Superannuation trustees. RSE licensees holding member records and beneficiary data.
RSE licensees

The common thread is that all of these entities hold large volumes of sensitive personal and financial information, and all of them refresh IT constantly, so all of them retire equipment that held that information. CPS 234 does not treat a small institution differently in principle from a major bank; the obligation to protect information assets across their life-cycle applies to every regulated entity, scaled to the size and sensitivity of what it holds. If your organisation answers to APRA, the way you dispose of old IT is a compliance question, not just an operational one. You can read the standard itself on the APRA website.

What CPS 234 Actually Says About Disposal

The disposal obligation is not a separate clause you can look up. It is built into how CPS 234 defines the life-cycle your controls must cover.

The information asset life-cycle CPS 234 covers

CPS 234 requires controls at every stage. Disposal is not an afterthought outside the standard - it is the final stage inside it.

Plan & design Acquire Operate & maintain Decommission Dispose CPS 234 controls apply here too the data still exists until it is destroyed

Source: life-cycle definition per APRA Prudential Standard CPS 234 (planning and design through to decommissioning and disposal).

CPS 234 requires a regulated entity to implement information security controls that are commensurate with several things, and one of them is, in the standard's own words, "the stage at which the information assets are within their life-cycle". A footnote then defines that life-cycle as "the process from planning and design through to decommissioning and disposal of an information asset". Put those two together and the conclusion is unavoidable: the standard expects your controls to follow the asset all the way to disposal, because the sensitive data an asset holds does not disappear when you decommission the hardware. It disappears when the data is destroyed.

This is why treating disposal as a facilities or waste task, separate from information security, is a mistake under CPS 234. A decommissioned server is still an information asset until its drives are sanitised or destroyed. A retired laptop in a cupboard is still holding whatever it held on its last day of use. The standard does not prescribe a specific destruction method, which is deliberate; it sets an outcome-based obligation to protect the asset across its life and leaves you to choose controls commensurate with the sensitivity of the data. For a financial institution, that sensitivity is high, so the bar for how you destroy the data, and how you evidence it, is correspondingly high.

Your Disposal Provider Is In Scope Too

This is the part most organisations miss. CPS 234 does not let you transfer the obligation by handing devices to a contractor. It extends the obligation to that contractor.

CPS 234 requires a regulated entity to classify its information assets "including those managed by related parties and third parties", and to assess the information security capability of any party that manages its information assets, commensurate with the potential consequences of an incident. A data destruction or IT asset disposal company that collects your retired equipment is, by definition, a third party managing your information assets at their most vulnerable moment. So the standard's logic is direct: you remain accountable for that data, and you are expected to have assessed the capability of the provider you hand it to.

In practice this reframes how a bank, insurer or super fund should choose an IT disposal partner. It is not enough that a provider turns up and takes the equipment away. You need to be able to show that you assessed their capability, and that assessment should rest on evidence: recognised certifications, a documented chain of custody, and a destruction record for every asset. A provider whose information security is itself certified to ISO 27001:2022 gives you a defensible basis for that assessment, because the certification is independent evidence of the controls the standard expects you to check for.

It is worth being clear about where the risk actually sits during a disposal, because it is not where most people assume. The moment of greatest exposure is not the destruction itself, which a competent provider performs to standard; it is the handover and transit, the window between a device leaving your control and its data being destroyed. That is precisely the window CPS 234 is concerned with, and it is why an unlogged pickup, however convenient, is the weakest link in an otherwise sound program. A provider who accounts for every asset from the moment of collection closes that window, and a provider who cannot, leaves it open with your data inside it. When you assess a disposal partner against CPS 234, the transit and custody controls deserve as much scrutiny as the destruction method, because that is where a regulated entity is most likely to lose sight of an information asset it remains accountable for.

The question a CPS 234 assessment should ask

Before a single device leaves the building, the assessment comes down to three things: is the provider's own information security independently certified, can they prove an unbroken chain of custody from collection to destruction, and do they issue a certificate of destruction for every asset. If the answer to any of those is no, the gap is yours, not theirs. ITC's process is built around exactly these three, so the assessment is straightforward to document.

General Disposal vs CPS 234-Grade Disposal

The difference is not the truck that collects the equipment. It is the evidence that comes back, and whether it would survive an APRA review.

What matters under CPS 234General IT disposalCPS 234-grade disposal
Data destruction methodOften a factory reset or a single-pass wipe, unverifiedCertified wiping or physical destruction to a recognised standard such as NIST 800-88
Chain of custodyDevices handed over with no logged trackingEvery asset logged at collection and tracked to destruction
Proof of destructionA verbal assurance, or nothingA certificate for every device, reconcilable to your asset register
Third-party capabilityUnassessed, so the gap sits with youProvider certified to ISO 27001:2022, giving documented evidence to assess
If APRA asksYou cannot show a specific device was clearedYou produce the certificate and custody record for that asset

Read down the right-hand column and a pattern emerges: every row is about producing evidence, not just moving hardware. That is the shift CPS 234 asks a financial institution to make. A general disposal might destroy the data perfectly well, but if it leaves no record, you cannot demonstrate that it did, and under a prudential standard the ability to demonstrate a control is much of the point. The value of a CPS 234-grade process is that it turns each disposal into a defensible artefact: a specific asset, a specific method, a specific certificate, all traceable back to the day the device left your floor. When end-of-life IT is handled this way, an APRA information-security review of your disposal practices becomes a matter of retrieving records rather than reconstructing what probably happened.

Why Regulators Are Watching Disposal

Financial services is one of the most breached sectors in the country, and the penalties for getting personal information wrong are now among the largest in the world. Figures from named sources.

2nd
Finance was the second highest-reporting sector for notifiable data breaches, at 14% of all breaches, behind only health
Source: OAIC, Jan to Jun 2025
532
Notifiable data breaches reported to the OAIC in the first half of 2025, with breaches remaining at a high level
Source: OAIC, Jan to Jun 2025
$50M+
Maximum penalty for a serious or repeated privacy breach under the Privacy Act 1988
Source: OAIC

The Office of the Australian Information Commissioner reported 532 notifiable data breaches in the first half of 2025, and finance was the second most affected sector at 14% of all breaches, behind health. Of those breaches, 59% were attributed to malicious or criminal attack and 37% to human error. A retired device that leaves your control without its data destroyed sits at the intersection of both risks: it is a target for theft and it is a human-error waiting to happen when someone assumes a factory reset was enough. Against a maximum privacy penalty of $50M or more, the cost of certified destruction is trivial, and CPS 234 makes it an expectation rather than a nice-to-have. You can review the current breach statistics on the OAIC website.

What CPS 234-Grade Data Destruction Looks Like

The standard is outcome-based, so it does not hand you a checklist. In practice, four things turn a disposal into one you can defend to APRA.

1

Destruction to a recognised standard

Data is destroyed to a published method such as NIST 800-88, by certified wiping for reusable equipment or physical shredding for drives that cannot be verified. Solid-state media is handled by a method matched to flash, not a legacy hard-drive technique. See data destruction services for the methods.

2

An unbroken chain of custody

Every asset is logged at collection and tracked to the point of destruction, so there is never a window in which a device holding member or customer data is unaccounted for. This is the evidence an assessment against CPS 234 relies on.

3

A certificate for every device

Each asset receives a destruction certificate recording what was destroyed and how, reconcilable to your asset register. A single blanket statement is not enough for a regulated entity that may be asked to prove a specific device was cleared.

4

Independent certification behind the process

The provider's own information security is certified to ISO 27001:2022, giving you documented evidence of the third-party capability CPS 234 expects you to assess, rather than an unverified assurance.

Reuse and value recovery still fit

Compliant destruction does not mean everything is shredded. Where data is destroyed by certified wiping to a recognised standard, working equipment can be securely refurbished and its value recovered, which for a large IT refresh can offset the cost of the program. The obligation is that the data is destroyed and evidenced, not that the hardware is scrapped. ITC routes reusable assets through buyback only after the data is destroyed and certified.

CPS 234 Does Not Stand Alone: The CPS 230 Connection

From 1 July 2025, a second APRA standard sharpened the focus on the third parties who handle your data, disposal providers included.

APRA's Prudential Standard CPS 230 Operational Risk Management took effect on 1 July 2025, and it strengthens how regulated entities must manage the material service providers they rely on. Where CPS 234 makes you responsible for the information security capability of a third party handling your information assets, CPS 230 adds a broader operational-risk lens over service-provider management, including the need to understand and manage the risks those providers carry. For IT disposal, the two standards point the same way: the company that collects, transports and destroys your retired equipment is a service provider whose capability and controls you are expected to understand and evidence.

The practical takeaway is that end-of-life IT has quietly become a board-level operational-risk topic for financial institutions, not a back-office errand. Choosing a disposal partner whose certifications, custody and reporting are documented is now the simplest way to satisfy both standards at once. You can read CPS 230 on the APRA website.

Bring disposal onto the risk register

If retired IT is not currently tracked as an information-security and operational-risk item, that is the first gap to close. ITC works with financial-services risk and technology teams to make end-of-life disposal a documented, repeatable control. See how it fits together on our financial services IT disposal page, or call our team.

APRA CPS 234 & Data Destruction: FAQ

The questions financial-services risk and technology teams ask most about disposal under CPS 234.

No, CPS 234 does not use the phrase "data destruction". It requires information security controls commensurate with the stage of an information asset's life-cycle, and defines that life-cycle as running from planning and design through to decommissioning and disposal. The obligation to protect the data therefore extends to the disposal stage, which in practice means destroying it to a recognised standard and documenting that it was done.

All APRA-regulated entities: authorised deposit-taking institutions such as banks, general and life insurers, private health insurers, friendly societies, and superannuation RSE licensees. The obligation scales to the size and sensitivity of the information an entity holds, but the requirement to protect information assets across their life-cycle applies to every regulated entity.

Yes. CPS 234 requires you to classify information assets including those managed by third parties, and to assess the information security capability of any party managing your assets. Handing devices to a disposal contractor does not transfer the obligation; it extends it to that contractor, and you are expected to have assessed their capability. Recognised certifications, a documented chain of custody and per-device certificates are the evidence that assessment relies on.

CPS 234 is outcome-based and does not mandate a specific method, so you choose controls commensurate with the sensitivity of the data. For financial-services data that sensitivity is high, so a recognised standard such as NIST 800-88 is the practical benchmark: certified wiping for reusable equipment, and physical destruction for drives or solid-state media that cannot be verifiably wiped, with a certificate issued for each asset.

No. The obligation is that the data is destroyed and evidenced, not that the hardware is scrapped. Where data is destroyed by certified wiping to a recognised standard, working equipment can be refurbished and its value recovered through buyback, which can offset the cost of a refresh. The sequence matters: the data is destroyed and certified first, then the asset is remarketed.

CPS 230 Operational Risk Management, effective 1 July 2025, strengthens how regulated entities manage service providers. It reinforces CPS 234's third-party expectations by adding an operational-risk lens over the providers you rely on. For IT disposal, both standards point the same way: your disposal provider is a service provider whose capability, controls and reporting you are expected to understand and evidence.

Keep three things for every disposal: the destruction certificate for each asset, the chain-of-custody record tracing it from collection to destruction, and your assessment of the provider's information security capability, such as their ISO 27001:2022 certification. Together these let you show, for any specific device, that the data was destroyed to a recognised standard by a party whose capability you assessed. That is the evidence trail an information-security review is looking for, and it is produced as routine when disposal runs through a certified process.

Reviewing your disposal against CPS 234? Contact our team or call 1300 048 226.

Make End-of-Life IT a Control You Can Prove

See how ITC delivers certified, documented data destruction for banks, insurers and super funds, with the chain of custody and per-device certificates that turn a disposal into evidence for CPS 234.

Evidence for your auditor

Disposal that stands up to a compliance review

Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.

Talk to a compliance specialist View certifications

Book Your Free Collection

Request a callback