What do the CPS 230 requirements mean for customer interaction record keeping?
CPS 230 is an operational risk standard, not a call-recording regulation. It requires APRA-regulated entities to manage operational risks effectively, maintain critical operations through disruption and manage risks arising from service providers.
Customer interaction records matter where they support those wider responsibilities. A complaint call, service instruction, customer consent, incident escalation or operational decision may become part of the evidence used to show that a critical process operated as intended.
The practical question is therefore not, “Does CPS 230 require us to record every interaction?” It does not. The better question is, “Which interactions form part of our critical operations, controls or incident response, and can we produce reliable evidence of them when required?”
CPS 230 explained in operational terms
APRA’s standard focuses on three connected areas: operational risk management, business continuity and service-provider management. An organisation must understand the processes and resources needed to deliver critical operations, the interdependencies between them and the controls required to keep them within tolerance levels.
The current CPS 230 standard on APRA’s website sets out the official requirements and supporting guidance.
This shifts record keeping away from passive storage. Records need to support risk assessment, monitoring, escalation, testing and accountability across the operational environment.
Where customer interaction records fit
Customer interactions can support CPS 230 when they form part of an end-to-end business process. Examples may include:
- customer instructions that initiate or change a critical service;
- complaints or incidents that reveal a control weakness;
- communications used to escalate an operational disruption;
- service-provider interactions that document decisions, dependencies or remediation;
- customer notifications issued during a disruption;
- authorisations, consents or confirmations required by a controlled process.
Not every interaction will carry the same significance. The organisation should identify those that contribute to critical operations, regulatory obligations, risk decisions or evidence of control performance.
The relationship between records and operational resilience
Operational resilience depends on knowing what happened, how the organisation responded and whether controls worked. Where customer interactions form part of that story, incomplete or inaccessible records can make assurance more difficult.
A useful record-keeping approach should help the organisation answer:
- What interaction took place and through which channel?
- Which customer, employee, process or service provider was involved?
- Was the interaction part of a critical operation or control?
- Can the record be trusted as complete and unaltered?
- Can it be retrieved throughout the required retention period?
- Can access and handling of the record be audited?
Four CPS 230 use cases for interaction evidence
1. Incident reconstruction
After an operational event, teams may need to reconstruct the sequence of customer reports, internal escalations and remediation activity. A governed interaction record can help establish timing, ownership and decisions without relying entirely on recollection.
2. Business continuity testing
Testing may include whether customer communications can continue during disruption and whether records remain available when systems, sites or service providers are affected. The evidence from those exercises can support improvement and Board reporting.
3. Material service-provider oversight
Customer-facing services may depend on third parties. Records of escalations, service issues, commitments and remediation can contribute to oversight of those arrangements, particularly where they affect a critical operation.
4. Control assurance
Where a process requires a disclosure, confirmation, approval or escalation, the interaction record may provide evidence that the control was executed. Its value depends on whether it is complete, governed and linked to the relevant process.
Why simple recording may not be sufficient
A stored audio or video file may prove that something was captured, but it may not be enough to support operational assurance. If the record cannot be associated with the correct case, retained consistently, protected from alteration or retrieved promptly, its evidentiary value is reduced.
This is why organisations should consider three practical capabilities:
- Capture: identify and preserve the interactions that carry operational or compliance significance.
- Governance: apply controlled access, integrity safeguards, retention policies and auditable handling.
- Retrieval: locate and produce the correct record quickly across the full retention window.
These capabilities do not replace CPS 230 risk management. They support the evidence environment around it.
Questions for risk and operations leaders
- Have we mapped customer interactions within each critical operation?
- Do we know which channels create records that may be needed during an incident or review?
- Are interaction records covered in business continuity and service-provider scenarios?
- Can we retrieve records if a source platform or provider is unavailable?
- Are retention and access controls consistent across current and legacy systems?
- Can we show who accessed, exported or amended the information?
Where the answer is unclear, the issue should be assessed alongside process mapping, data governance, business continuity and third-party risk management.
How Liquid Voice supports governed interaction records
Liquid Voice helps regulated organisations capture, retain, retrieve and review communications across complex estates. Its compliance solution provides a platform-independent approach to interaction governance, helping organisations maintain control as communication technologies and service providers change.
Explore the Liquid Voice Compliance Solution for more information on recording, retention, access control and retrieval.
Read the Compliance Readiness Guide
The Compliance Readiness Guide offers a practical way to assess whether relevant interactions are captured, governed and retrievable. It can support internal conversations between compliance, risk, operations and technology teams as they review the evidence surrounding critical processes.