Why APRA-Regulated Entities Must Get Disposal Right
APRA CPS 234 (Information Security) is a prudential standard issued by the Australian Prudential Regulation Authority that applies to all APRA-regulated entities, including banks, insurers, superannuation funds, and other financial institutions. CPS 234 requires these entities to maintain information security capabilities commensurate with the threats they face, and this obligation extends to the disposal of IT assets containing sensitive data.
For the financial services sector, the intersection of CPS 234 with IT equipment disposal creates specific obligations that go beyond general Privacy Act requirements. Getting this wrong can result in both APRA enforcement action and reputational damage in a sector where trust is everything.
CPS 234’s Core Requirements
CPS 234 establishes several principles that directly affect how IT assets should be handled at end of life:
Information asset identification and classification: Entities must identify and classify information assets, including those managed by related parties and third parties. This requirement means you need a comprehensive inventory of all devices and the classification of data they hold. You cannot securely dispose of assets you haven’t identified.
Information security capability: The entity must maintain an information security capability commensurate with the size and extent of threats to its information assets. For disposal, this means having processes, tools, and expertise proportionate to the volume and sensitivity of decommissioned equipment.
Policy framework: Entities must maintain an information security policy framework that provides direction on responsibilities for all stages of the information asset lifecycle. Disposal is explicitly part of this lifecycle and must be addressed in policy.
Incident management: CPS 234 requires entities to have mechanisms to detect and respond to information security incidents. Improper disposal that leads to data exposure constitutes an information security incident that must be managed according to the entity’s incident response process and potentially reported to APRA.
- Comprehensive information asset identification and classification
- Security capability proportionate to threats, including disposal processes
- Policy framework covering the full information asset lifecycle
- Incident management for disposal-related security events
- Third-party management for outsourced disposal services
- Board-level accountability for information security
- Internal audit coverage of information security controls
Third-Party Disposal and CPS 234
One of CPS 234’s most significant requirements for disposal relates to third-party management. When an APRA-regulated entity outsources IT asset disposal, CPS 234 requires the entity to assess the information security capability of the third party and to ensure contractual arrangements cover information security requirements.
Specifically, the entity must evaluate the third party’s ability to protect the entity’s information assets throughout the disposal process. This goes beyond simply asking for certifications. The entity should assess the provider’s physical security, data destruction methods and verification processes, staff vetting and training, chain of custody procedures, insurance and liability coverage, and incident response capabilities.
APRA expects these assessments to be documented and reviewed periodically, not just performed once at engagement. If the disposal provider’s security posture changes (for example, if they lose a key certification), the entity needs to reassess the arrangement.
The entity’s Board must be satisfied that the entity’s information security is being maintained when activities are outsourced. This means disposal arrangements should be visible to the Board through regular reporting on third-party risk management.
APRA Notification Requirements
CPS 234 requires entities to notify APRA of material information security incidents, including those arising from improper disposal. The notification must be provided within 72 hours of becoming aware of the incident if the entity determines (or should have determined) that the incident is material.
A disposal-related incident might be considered material if it involves a large volume of customer records, if the data includes sensitive financial information, if the exposure could lead to fraud or identity theft, or if it indicates a systemic weakness in the entity’s disposal processes.
Additionally, CPS 234 requires entities to notify APRA within 10 business days if they become aware of a material information security control weakness that could not be remedied in a timely manner. If an internal audit or assessment reveals significant gaps in the disposal process, this notification requirement may be triggered.
Board and Senior Management Accountability
CPS 234 places explicit accountability on the Board for information security. The Board must ensure the entity maintains information security in a manner consistent with the standard. This includes oversight of disposal practices.
In practical terms, the Board should receive periodic reporting on IT asset disposal activities, including volumes processed, methods used, any incidents or near-misses, and third-party provider performance. Senior management responsible for information security should ensure disposal processes are resourced, documented, and operating effectively.
APRA has demonstrated through its enforcement actions that it takes Board accountability seriously. Directors who fail to ensure adequate information security controls, including disposal controls, risk personal regulatory consequences.
Internal Audit Requirements
CPS 234 requires that the internal audit function provides assurance on information security controls. This includes testing whether disposal controls are operating as designed.
An internal audit of IT disposal should test whether the disposal policy is current and comprehensive, whether the asset inventory accurately reflects the current device population, whether disposal events are being documented as required, whether destruction methods align with data classification levels, whether third-party providers are being assessed and monitored, whether certificates of destruction are being obtained and retained, and whether there are any gaps between policy and practice.
Audit findings related to disposal should be tracked through the entity’s remediation process and reported to the Board Audit Committee as part of the standard internal audit reporting cycle.
Practical Implementation for Financial Services
Financial services organisations handle some of the most sensitive data in any sector. CPS 234-compliant disposal processes should reflect this sensitivity level:
Classification-based destruction: Map data classification levels to destruction methods. Customer financial data, transaction records, and identity documents warrant Purge-level sanitisation or physical destruction. General business data may be adequately handled with Clear-level sanitisation.
Comprehensive scope: Don’t limit disposal controls to IT department equipment. Trading floor workstations, branch terminal devices, ATMs, kiosk systems, and even CCTV equipment may contain customer or financial data.
Encryption integration: Where devices are encrypted, cryptographic erasure (destroying the encryption keys) can be an efficient destruction method. However, this should be combined with either software wiping or physical destruction as a secondary measure for defence in depth.
Regulatory retention: Before destroying data, verify that retention requirements have been met. Financial services data is subject to various retention periods under the Corporations Act, Anti-Money Laundering legislation, and APRA requirements. Destroying data that should still be retained creates a different compliance problem.
- Maintain a classified inventory of all information assets
- Apply destruction methods proportionate to data classification
- Document every disposal with asset-level detail and verification
- Assess and monitor third-party disposal providers
- Include disposal in the entity’s information security policy
- Report disposal activities to senior management and the Board
- Include disposal controls in the internal audit scope
- Notify APRA of material disposal-related security incidents within 72 hours
CPS 234 treats information security as a lifecycle obligation, not just an operational one. Disposal is the final stage of that lifecycle, and it deserves the same rigour that APRA-regulated entities apply to access control, encryption, and incident response during the active life of their IT assets.
For more on the technical aspects of data destruction, see our NIST 800-88 guide and our guide to data breach prevention through proper disposal.
EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.
