Case studies | Risk, resilience and compliance success stories | Protecht

Bank First CPS 230 Case Study | Protecht

Written by Protecht | Aug 18, 2026, 12:44:18 AM

CPS 230 is changing the operating model of risk management, not simply adding another compliance obligation.

The first phase was about implementation: defining critical operations, reviewing policies, building registers, updating business continuity plans and preparing for commencement. But once the deadline has passed and the project team steps back, organisations need to prove that CPS 230 works in business as usual.

For Bank First, the business-as-usual phase of CPS 230 became a catalyst for strengthening operational risk ownership across the organisation.

Working with Protecht, the customer-owned mutual bank has moved from a high-level enterprise risk profile to more detailed departmental operational risk profiles, with risk profiles, controls, incidents and critical operation linkages managed in a connected way.

At a glance: Bank First’s CPS 230 results to date

Bank First uses Protecht to connect departmental risk profiles, controls, incidents and critical operations, supporting the shift from CPS 230 implementation into business-owned embedment.

Built departmental operational risk profiles across the organisation Bank First has translated its CPS 230 program into risk profiles that give each area a clearer view of the risks it manages and the operational context around them.
Embedded operational risk ownership into business teams Responsibility is moving closer to the people who manage risk day to day, with business owners maintaining and updating their information in Protecht.
Connected risks, controls, incidents and critical operations Bank First is using Protecht to make the relationships between these elements visible, linking departmental risks to critical operations, controls and relevant incidents rather than managing them as standalone registers.
Shifted from project delivery to business-as-usual governance The focus is now on maintaining current information, clear ownership and connected evidence over time, rather than treating CPS 230 as a one-off implementation exercise.

The challenge: moving beyond the implementation deadline

CPS 230 was never designed to be a one-off compliance project. It requires organisations to manage operational risk end-to-end, maintain critical operations within tolerance and demonstrate that business continuity and service provider arrangements can stand up under pressure.

Bank First had already established a high-level enterprise risk profile. The CPS 230 journey created the need to build out a more detailed operational risk foundation underneath it, with departmental risk profiles that could support ownership, controls and decision-making across the business.

To operationalise CPS 230, Bank First needed to move from a high-level view of enterprise risk to a more practical, business-owned view of operational risk.

“How can you use those risk profiles going forward to drive your decision-making, drive prioritisation, drive resourcing… rather than seeing it just as a tick-the-box compliance exercise?”

Paul Deschepper
Head of Risk Embedment, Bank First

Building the operational risk foundation

Bank First approached the CPS 230 uplift by working directly with business areas to identify and document their operational risks and controls.

Rather than treating risk profiling as a documentation exercise, the process was designed to help business owners think through the risks they manage day to day, the controls already in place, the gaps that needed attention and the treatment plans required.

The risk profiling process helped Bank First move beyond a generic enterprise-level view and into the operational detail required to make CPS 230 useful in practice. It also helped business teams see risk management differently.

As business areas worked through their risks and controls, some teams recognised that activities they already performed every day were, in fact, controls. This is a good example of how CPS 230 embedment depends on business areas understanding not only what they do, but why it is important from a risk and resilience perspective.

Embedding ownership in the business

For Bank First, the focus of the operationalisation phase has been on ensuring the work built for CPS 230 does not sit separately from day-to-day management. Business areas need to understand what CPS 230 means for them, what they own and how their actions affect the broader operational risk profile.

Rather than Line 2 doing the work on behalf of the business, Bank First’s approach is to support, guide and challenge business owners while keeping accountability close to where the risks are managed, using Protecht as a key enabling tool for Line 1.

This is a gradual shift. It involves education, repetition and practical use of the system. But it is also what turns CPS 230 from a completed program into an operating discipline.

Protecht’s role: making the operating model work in practice

Protecht gives Bank First a working environment for the elements that need to stay connected after implementation. Business teams maintain departmental operational risk profiles and controls in Protecht. Incident owners can link incidents back to affected controls, while relevant departmental risks can be linked to the critical operations they may disrupt.

This makes the relationships visible in the operating model rather than relying on standalone registers. It also gives Bank First a practical way to move responsibility from the CPS 230 project team towards business, control and incident owners, while retaining a connected view for oversight.

As the model matures, the same structure can support the bank’s next goal: aggregating operational risk, business continuity and material service provider information at critical-operation level.

Bank First’s CPS 230 operating model

Current state: business-owned departmental profiles Connected through Protecht Next maturity step: critical-operation view
Operational risks
Risk profiles and operating context

Controls
Linked to the risks they address

Incidents
Can be linked back to controls
Critical operations

A shared lens for understanding what could disrupt services.

Departmental risks, controls and relevant incidents can be linked to the operations they may disrupt.
A single view bringing together:
  • Operational risk
  • Business continuity
  • Material service providers

A practical model for moving responsibility from the CPS 230 project team to business, control and incident owners, while retaining connected oversight.

Linking departmental risks to critical operations

The bank built departmental operational risk profiles to provide a more complete view of operational risk across the organisation. Relevant risks are then linked back to critical operations through Protecht’s operational resilience solution.

This creates two useful views:

  • A vertical view of operational risk within business areas
  • A horizontal view of the risks and dependencies that affect critical operations

By linking departmental risks to critical operations, Bank First can build a more connected view of what could disrupt its business.

It also helps avoid a narrow interpretation of CPS 230: departmental risk profiles give Bank First a broader foundation, while critical operation linkages help connect that foundation back to resilience obligations.

Business continuity through a member lens

Business continuity is one of the harder parts of CPS 230 to embed, because it is not always part of the daily operating rhythm.

Operational risk profiles, controls and incidents are active in BAU. Business continuity plans can feel more distant until they need to be tested or used.

An important lens for Bank First to understand business continuity was to consider it from the perspective of its members. Are the manual workarounds realistic? Are the scenarios severe enough? Will the plan deliver the continuity of service members expect?

That question brings CPS 230 back to its purpose. Operational resilience is primarily about protecting members from disruption, harm and loss of confidence when something goes wrong.

“Any decisions we make always tie back to: how does this help us protect our members from harm?”

Paul Deschepper
Head of Risk Embedment, Bank First

Managing the next wave of CPS 230 maturity

Two areas remain especially important for Bank First’s next phase of CPS 230: material service providers and aggregated critical-operation-level reporting.

Like many banks, Bank First relies on third parties for important parts of its operating model. That creates practical challenges for business continuity testing and service provider assurance, especially where the same provider supports multiple regulated entities.

Organisations need to understand which critical operations rely on which providers, how those dependencies are monitored, what alternatives exist and how disruption would be managed in practice.

The next maturity step is to bring together the pieces that already exist: operational risks, business continuity health, material service provider information and contract status. The aim is to make critical operations a more useful aggregation point for operational risk and resilience.

Five lessons every APRA-regulated organisation should learn from Bank First

1. Compliance projects don’t create operational resilience

A project can establish the program, but resilience depends on the operating discipline that follows: current risk information, owned controls, usable evidence and regular decision-making.

2. Risk ownership belongs in Line 1

Second-line oversight remains essential, but business teams need to understand, maintain and act on the risks within their own operations.

3. Connected data beats static registers

Risks, controls, incidents and critical operations become more useful when their relationships are visible. This gives teams stronger context when assessing change, disruption or control gaps.

4. Critical operations should become the operating lens

Looking through the services that matter most helps organisations bring together departmental risk, business continuity and service-provider information around the outcomes they need to protect.

5. BAU is where CPS 230 succeeds or fails

The real test begins after implementation: whether ownership remains active, information stays current and the organisation can use its operating model under pressure.

From compliance delivery to operational discipline

For Bank First, CPS 230 has been more than a regulatory implementation exercise. It has become a catalyst for strengthening operational risk ownership across the organisation.

Protecht supports that journey by helping Bank First manage risk profiles, controls, incidents and critical operation linkages in a connected way. As the bank continues to mature its CPS 230 operating model, the focus is moving from building the foundations to keeping them alive in BAU.

That is the shift now facing many APRA-regulated organisations. CPS 230 is not just a question of whether the framework has been delivered. It is a question of whether the organisation can run it, evidence it and improve it.

Organisations that continue to treat operational resilience as a regulatory project alone will struggle to maintain the ownership, evidence and connected information it requires over time.

Next steps for your organisation

About Bank First

Bank First is a customer-owned mutual bank supporting people who care for others in the community.

Founded over 50 years ago to meet a social need, Bank First provides banking and financial services with a particular focus on educators, healthcare professionals and the communities they serve. As a mutual bank, Bank First is centred on its members and remains focused on delivering a better banking experience for the people and occupations that help build stronger communities.

About Protecht

Protecht helps organisations manage risk, resilience and compliance in a connected way.

Protecht’s CPS 230 and Operational Resilience capabilities support Australian financial services organisations in bringing together operational risk, controls, incidents, critical operations, business continuity and service provider oversight.

With Protecht, organisations can move beyond policies and registers toward a more connected operating model for managing CPS 230 in practice.