The Composable Banking Playbook: What CPS 230's First Month in Force Just Taught APAC Banks
Executive Summary: CPS 230's First Month Has Made Composable Banking a Board-Level Decision Across APAC
On 1 July 2026 APRA's revised CPS 230 Prudential Standard on Operational Risk Management took full effect for Australian banks and insurers. In its first thirty days in force, the standard has already changed the boardroom conversation across the wider Asia-Pacific region. It has done so by making a single cost visible for the first time: the compounding price of architectural fragility. The banks that treated CPS 230 as a legal exercise are discovering that their Material Service Provider Register exposes the same brittleness their customers already feel. The banks that treated it as an architectural exercise are ahead and they share three characteristics: they instrumented observability before they migrated anything, they insourced their platform engineering, and they held themselves to composable design principles even inside the parts of the estate that still ran on legacy cores. This playbook sets out what composable banking now means in practice for APAC executives, what the first month of the standard has actually surfaced, where the return lives on a five-year horizon, and the ninety-day decisions that separate the leaders from the re-platformers.

Why CPS 230 Became the Forcing Function APAC Core Banking Modernization Was Waiting For
For most of the past decade, "core banking modernization" was a phrase that lived on strategic roadmaps and never quite made it into a funded programme. The technology was ready. The vendor landscape had matured across 10x Banking, Mambu, Thought Machine, Temenos and the modular offerings from the traditional incumbents. The economics of continuing to run a thirty-year-old mainframe core had become embarrassing on every quarterly review. Yet as recently as 2024, McKinsey's Global Banking Annual Review noted that global banking's return on tangible equity had begun to compress again - from 12.4 per cent in 2024 to 11.8 per cent in 2025 - under the weight of cost of risk, cost of capital and cost of technology change all pushing in the same direction. What was missing was a forcing function. Regulation, in the end, has provided it.
CPS 230 has become that forcing function for Australia, and its shape is now travelling across the region. As of 1 July 2026, APRA-regulated entities must identify their critical operations, document each material service provider, define maximum tolerable disruption windows for each, and demonstrate - under stress - that the whole apparatus works. The standard's most recent targeted amendments, finalized in May 2026, tightened the picture by clarifying limited exemptions for arrangements with non-traditional service providers such as central banks and clearing and settlement facilities, while retaining full accountability for the underlying operational risks. Boards can now delegate the paperwork of vendor management, but they cannot delegate the accountability.
The regulatory posture is Australian, but the boardroom conversation is now regional. The Monetary Authority of Singapore is running its Consultation Paper on Guidelines on AI Risk Management for Financial Institutions in parallel, moving from principle to supervisory expectation. Hong Kong's Insurance Authority and Monetary Authority are co-funding AI pilots for insurers and banks. Bank Negara Malaysia is signaling similar direction of travel on third-party risk. The pattern is unmistakable: operational resilience and technology architecture are now the same conversation across APAC BFSI, and the composable banking model has moved from a vendor talking point to a defensible board strategy.
The Three Modernization Clocks Now Running Simultaneously Across APAC BFSI in 2026
Across APAC, banks are running three modernization clocks at once, and the interference between them is what most strategy documents fail to model.
The first clock is regulatory. CPS 230 in Australia sets a July 2026 baseline for operational resilience that peer regulators are watching closely. The MAS AI Risk Management Guidelines are maturing from consultation into supervisory practice. Revised third-party risk expectations across the region are lifting the bar on what a defensible vendor governance narrative looks like. Each of these standards, taken alone, is manageable. Taken together, they compound: every new obligation lands on the same technology fabric, and that fabric decides whether the response is a governance configuration change or a programme.
The second clock is competitive. Digital banks in Singapore, Hong Kong, the Philippines and now Malaysia have been compounding their architectural advantage for three to four years. McKinsey's 2026 Review highlights China's WeBank - 420 million customers and the eleventh most valuable bank in the country's market as the archetype of what nonbank and superapp competition now looks like at scale. Incumbents defending market share on customer trust cannot indefinitely defend the same market share on unit cost of technology change. The gap is widening.
The third clock is technological. Cloud-native cores, event-driven architectures, observability-first operations, service meshes with policy-as-code - none of these are differentiated capabilities in 2026. They are the price of entry to compete for the next generation of retail and SME customers. The Asian Banker's 2026 assessment framed the challenge cleanly: APAC banks must modernize infrastructure without surrendering the trust advantage that comes from being the incumbent. Composable banking is what that instruction looks like in practice.
The interference pattern between these three clocks is what creates the opportunity for the composable operating model. A bank whose regulatory obligations, competitive positioning and technology fabric are all handled inside three separate programmes is running three costs. A bank whose composable architecture absorbs all three as configuration changes is running one.
What CPS 230's First Thirty Days Actually Surfaced Inside APAC Banks
Four challenges are surfacing consistently across sourceCode's APAC banking engagements in the first month of CPS 230 enforcement.
Challenge 1: The Material Service Provider Register Is a Mirror, Not a Document
When banks document who they depend on for critical operations, they routinely uncover concentrations that were invisible at business-unit level: a single settlements vendor supporting three business units, one data provider under six customer-facing products, one identity partner spanning both retail and wholesale, and increasingly common - one hyperscaler underneath the entire estate. Trace Consultants and other industry advisers have noted the same pattern: a small number of global hyperscale providers now underpin a significant and growing proportion of APAC banking technology, and the register is the first artefact that makes that concentration legible at board level.
Challenge 2: Tolerance Levels Expose Latency Debt in Legacy Cores
CPS 230 requires entities to define maximum tolerable disruption windows for each critical operation. Many banks are discovering that the tolerance they can defend to a regulator - sub-hour recovery for retail payments, minute-scale recovery for real-time payment rails - is significantly shorter than the recovery-time capability their current architecture can actually deliver. Legacy cores designed around nightly batch cycles cannot meet minute-scale objectives without architectural change, no matter how much runbook effort is invested.
Challenge 3: Third-Party Governance Is Not the Same as Fourth-Party Governance
The standard makes banks responsible for the resilience of the ecosystem beneath their material service providers. That has forced conversations about sub-processors, cloud-region concentrations, shared open-source dependencies and single-vendor identity providers that many risk committees have never had. It has also exposed that a significant proportion of "third party" relationships are, when unpacked, fourth-party dependencies on the same handful of hyperscalers.
Challenge 4: The Existing Board Reporting Layer Cannot Answer CPS 230's Monthly Questions
Directors are asking a specific set of questions monthly: what is our exposure, where is it concentrated, what is our recovery capability against tolerance, and what does the trend look like? A spreadsheet-based Material Service Provider Register cannot answer those questions live. Composable-first banks are already generating them from the observability fabric that sits underneath the architecture. Everyone else is generating them from month-old snapshots.
The Five Architectural Trends Consolidating into Composable Banking in 2026
Five trends are consolidating this year into what leaders now call composable banking - an operating model in which capabilities are assembled from interoperable components rather than delivered by a single monolithic core.
Trend 1: API-Mediated Cores Built Against a Stable Surface
New capabilities are built against a stable API surface. The core underneath can be replaced strangler-fashion without customer-facing disruption. 10x Banking's 2026 comparative work on 4th-generation platforms makes the case that this stable-surface property is now the primary vendor selection criterion for regulated tier-1 institutions, more so than feature parity with the incumbent core.
Trend 2: Event-Driven Data Fabrics as the Backbone for AI and Regulatory Reporting
Customer, transaction and risk events are streamed to a governed backbone. Downstream systems - including AI models and regulatory reporting engines - subscribe to events rather than owning private copies of data. This is what lets a bank recompute an exposure report in minutes instead of overnight, which is the difference between defending a CPS 230 tolerance and reporting a breach.
Trend 3: Observability-First Operations That Prove Tolerances Continuously
Service maps are generated automatically from live traffic. Tolerance levels defined for CPS 230 are enforced continuously, not audited annually. Recovery drills are executed in production-like environments, monthly, with the results published to the board pack. This is the single practice difference that separates the winning migrations from the failing ones.
Trend 4: Insourced Platform Teams with Outsourced Delivery Elasticity
The banks moving fastest are the ones who insourced their platform engineering and product engineering functions while retaining variable capacity through partners for specific delivery workloads. The composable operating model requires composable teams. Ownership of the fabric cannot be a shared responsibility.
Trend 5: Policy-as-Code and Governance-as-Code Enforced at the Service Mesh
Controls that were previously documented in a policy PDF - data residency, encryption in transit, model approval - are now expressed as code enforced at the service mesh and CI/CD layer. This is the practical mechanism by which composable architecture creates future regulatory optionality. When MAS or HKMA issues the next guideline, the response is a pull request, not a programme.
Why Composable Banking Is a Governance Decision Before It Is a Technology Decision
The single most important insight from the first month of CPS 230 in force is that composable banking is not primarily a technology decision. It is a governance decision that then requires a technology response.
Consider what the standard is actually asking a board to prove. It is asking whether the bank can identify what breaks its critical operations, contain the failure inside a defensible tolerance window, and demonstrate - under stress - that this containment works. That is a set of properties of the whole system: architecture, operations, vendor management, people, and the reporting layer that ties them together. Meeting it with a re-platforming programme is possible; meeting it with a composable architecture is dramatically cheaper over a five-year horizon because each new obligation lands on the same fabric rather than requiring a new one.
Bain's From the Customer to the Cloud thesis and its follow-on Disruption from Within work reach the same conclusion from a different direction: banks that treat modernization as a series of discrete programmes accumulate architectural entropy, and each programme costs more than the one before. Banks that treat modernization as a compounding platform reduce the marginal cost of change. The composable operating model is the mechanism by which that compounding actually happens.
For APAC executives, the strategic frame is this: every dollar spent on composable architecture creates future regulatory optionality. When the next standard arrives - and the direction of travel from APRA, MAS, HKMA and Bank Negara Malaysia suggests several more are on the way in the next twenty-four months - a bank on a composable fabric absorbs it as a governance configuration change. A bank on a monolithic core absorbs it as a programme. The difference is not merely cost; it is the ability to keep shipping product while absorbing regulation, which is the ultimate competitive advantage in a market where nonbanks and superapps do not carry the same regulatory load.
There is a second, equally important, strategic point. The composable operating model transfers value from vendor to bank. In a monolithic-core world, the vendor captures the compounding value of the customer's product roadmap, because every change flows through the vendor's release cycle. In a composable-core world, the bank captures that compounding value, because change flows through its own platform teams operating against a stable API surface. This is why insourcing platform engineering is not a delivery-model preference - it is the mechanism by which the compounding value actually accrues to the bank instead of leaking out to the vendor.
APAC Core Banking Migration Case Studies: What the Winning Sequence Actually Looks Like

Case 1 - APAC Digital Bank: Nine-Month Strangler Migration, 40 Per Cent Cost Reduction
An APAC digital bank sourceCode partnered with completed its migration off a legacy general-ledger core in nine months against a vendor-estimated eighteen. It ran the strangler pattern, moving capabilities one customer journey at a time behind a stable façade. Critically, it instrumented full observability across the affected services before the first component moved. Every service map was generated from live traffic. Every recovery objective was continuously proven, not annually audited. The result: a documented 40 per cent reduction in core operations cost within the first year post-migration, zero customer-facing incidents through the migration window, and - crucially for the CPS 230-equivalent conversation with its local regulator - a live service map that satisfied the operational resilience audit on first pass, without a subsequent programme of remediation.
Case 2 - Tier 1 Southeast Asian Bank: Big-Bang Programme Now Being Unwound
A Tier 1 regional bank in Southeast Asia took the opposite path. It launched a big-bang re-platforming across retail deposits, cards and lending in parallel, with observability planned as a phase 3 workstream after migration completed. Eighteen months in, the programme is materially over budget, roughly nine months behind schedule against original plan, and its local regulator has flagged that its defined tolerance levels are not defensible against its current recovery-time capability. The bank is now unwinding parts of the programme to re-sequence individual capability cutovers as strangler moves, with observability instrumented first. The cost of that unwind is meaningful - but the cost of continuing was assessed as higher.
The Cross-Case Pattern: Sequencing Beats Vendor Selection
The pattern across our engagements - and across the case work published by 10x Banking, Backbase and Finastra on APAC migrations - is remarkably consistent. The debate between "big-bang" and "strangler" migration is functionally over: every successful APAC core migration in the last twenty-four months we have visibility of used incremental strangler patterns with observability instrumented before migration began, not after. Vendor selection matters less than most vendor sales cycles suggest; sequencing and instrumentation matter more. A weaker technology choice, sequenced correctly, will out-perform a stronger technology choice sequenced badly. That single practice difference is worth more than most vendor selection decisions.
Case 3 - Mid-Tier Australian Bank: Rebuilding the Register as an Object Graph
A third example, from a mid-tier Australian bank preparing for CPS 230 through the first half of 2026, is instructive on the governance side. The bank chose to rebuild its Material Service Provider Register not as a spreadsheet update but as an object graph - every provider entry linked to the critical operations it supports, the tolerance levels defended, and the specific observability signals that prove the tolerances are being met. When APRA supervision engaged in June 2026, the register could be interrogated live rather than exported to PDF. That single design decision cut audit response time from days to minutes and reframed the supervisor relationship from adversarial to collaborative.
Seven Ninety-Day Actions for APAC BFSI CIOs Post-CPS 230 Effective Date
For CIOs, CTOs and Chief Operational Risk Officers navigating the next ninety days post-effective date, seven moves compound faster than any other spend.
- Rebuild the Material Service Provider Register as an architecture object, not a spreadsheet. Attach each entry to the critical operation it supports, the tolerance level defended, the fourth-party dependency chain beneath it, and the specific observability signal that proves the tolerance is met. If the register is exportable to PDF but not interrogable live, it is not doing its job.
- Instrument observability before you migrate - and before you re-architect. No component moves off the legacy core, and no new capability is stood up on the composable core, until the service it delivers is fully observed from the API surface down to the underlying infrastructure. Retrofitted observability is more expensive than instrumented observability and misses the events that matter most.
- Publish an internal composable reference architecture and enforce it with policy-as-code. Every product team should be building against the same API surface, the same event backbone, and the same governance controls. Diversity in delivery patterns is a resilience liability. Consistency does not slow innovation; it is what makes innovation cheap.
- Insource the platform team. The composable operating model requires custody of the fabric. Delivery capacity around the fabric can flex through partners; the fabric itself cannot be a shared responsibility. The banks compounding fastest have permanent platform teams and variable delivery teams - not the reverse.
- Rehearse recovery quarterly, at board level. CPS 230 tolerance levels are only real if they are exercised. Make the tabletop and full-recovery exercise a standing quarterly board agenda item, not an annual compliance ritual. The board's mental model of resilience is a leading indicator of the organisation's actual resilience.
- Address hyperscaler concentration explicitly. If a single cloud provider underpins more than a defined threshold of your critical operations, that concentration is now a board-level risk item under CPS 230 fourth-party expectations. Multi-region is not the same as multi-cloud. Have the honest conversation about what "material" means at that scale, and what an actual recovery-to-alternative-provider capability would require - even if the answer is that the concentration is retained with eyes open.
- Redesign the board pack. Directors are asking specific monthly questions: exposure, concentration, recovery capability against tolerance, and trend. Redesign the operational resilience section of the board pack to answer those four questions, generated automatically from the observability fabric. If a director has to ask "compared to last month, is this getting better or worse?" the pack has failed.
How CPS 230 Has Changed the Board-Level Conversation About Core Banking Architecture
The most consequential outcome of CPS 230's first month in force is that boards now have the vocabulary to hold their executive teams to composable-architecture standards without needing to be technologists themselves. The register, the tolerance levels, and the recovery drills are all objects a non-technical director can understand and interrogate. That has changed the internal politics of core modernization in a way no prior standard managed. The programme is no longer a technology-team ask that management must defend to a sceptical board - it is a board expectation that the technology team must satisfy. Executives who understand that shift are already re-scoping their next twelve months around it.
The sourceCode Perspective: Composable Architecture as a Regulatory Optionality Engine
Across our APAC banking engagements, sourceCode has watched the difference between banks that use CPS 230 as a compliance milestone and banks that use it as an architecture forcing function. The second cohort is smaller, and it is accelerating away from the first on every measure that boards care about: unit cost of technology change, time-to-market for regulated product, defensibility of the operational resilience narrative, and - perhaps most importantly - the ability to keep shipping while absorbing the next regulatory obligation.
Our position is not that composable is universally better than monolithic - every architecture has trade-offs, and there are estate segments where a well-maintained monolith continues to be the right answer for another five years. The argument is more precise: composable is the only architecture that turns a rolling stream of regulatory obligations from a cost center into an option-value engine. Where a bank has visibility of two or more meaningful obligations arriving in the next twenty-four months - and every APAC BFSI institution now does - composable is the economically dominant choice on a five-year horizon.
That is why we have organized our engineering practice around insourced platform teams, observability-first delivery, and policy-as-code enforcement from day one of every engagement. Not because these are ideological preferences, but because the outcomes are reproducible: shorter migrations, lower unit cost of change, first-pass regulatory audits, and most importantly - a compounding capability that stays with the client rather than leaking out to a vendor's release cycle.
The Five-Year Competitive Gap Between Composable-First and Monolith-Patching APAC Banks
The first month of CPS 230 in force will not be remembered for enforcement actions. There have not been any, and there may not be many. It will be remembered as the moment the economics of composable banking became boardroom-legible in Asia-Pacific. Some banks used the multi-year runway to change their architecture. Others used it to update their policies. The gap between those two cohorts will define competitive position over the next five years, and it will widen faster than most executives currently expect, because the compounding effect of composable architecture is asymmetric: every dollar spent on the fabric reduces the marginal cost of the next dollar of change, while every dollar spent on monolithic patching increases it.
The ninety-day window post-effective date is the highest-leverage decision period APAC banking executives have seen in a decade. What is decided in it will show up in board packs for the rest of the cycle.
Book a 30-Minute Core Banking Architecture Review with a sourceCode Delivery Lead
If you are inside that ninety-day window and want a second read on where your architecture actually sits against the operational resilience narrative you have to defend to your board, sourceCode's Core Banking Engineering leads are running complimentary thirty-minute Architecture Reviews through August. Book a session with a sourceCode delivery lead and one of our client CTOs - we will walk your current state and identify the top three CPS 230 exposure points, in writing, no obligation.
Frequently Asked Questions About CPS 230 and Composable Banking in APAC
What is composable banking, in one sentence? Composable banking is an operating model in which banking capabilities are assembled from interoperable, independently deployable components - cores, ledgers, payment rails, identity, risk - connected through a stable API surface and a governed event backbone, so that any capability can be replaced or added without disturbing the others.
What did CPS 230 actually require from 1 July 2026? APRA-regulated entities in Australia must identify their critical operations, document each material service provider that supports those operations, define maximum tolerable disruption windows for each, demonstrate operational resilience against those tolerances under stress, and maintain a register that a director could interrogate - with targeted exemptions applying to certain non-traditional service providers such as central banks and clearing facilities.
What is a Material Service Provider? A Material Service Provider is any external party - cloud, data, identity, payments, settlements, and increasingly AI model providers - whose failure would materially disrupt a bank's critical operations beyond its defined tolerance level. Every provider on the register carries board-level accountability.
What is a tolerance level, in practice? A tolerance level is the maximum period of disruption the board judges the bank can absorb for each critical operation before customer, financial or reputational damage becomes unacceptable. For real-time payments in APAC, tolerances are trending toward minutes. For batch reporting, hours to a business day.
Does CPS 230 apply outside Australia? Directly, no - it is an APRA standard. But its shape is influencing operational resilience thinking across APAC regulators including MAS, HKMA and Bank Negara Malaysia, and multinational banks are aligning group-wide practice to the highest applicable standard rather than running two operating models.
What is the difference between strangler and big-bang migration? Big-bang migrates all functionality at a single scheduled cutover, accepting concentrated risk in exchange for speed. Strangler migrates capability-by-capability behind a stable façade, spreading risk across many small cutovers. Every successful APAC core migration sourceCode has visibility of in the last two years used strangler with observability instrumented first.
What is the fastest way to start? Instrument observability across your critical operations before any architectural change, then rebuild the Material Service Provider Register as an architecture object rather than a spreadsheet. Those two moves alone unlock most of the compounding value; everything else builds on them.
References
Australian Prudential Regulation Authority (APRA), 2026. APRA finalises targeted amendments to CPS 230 Operational Risk Management. Available at: https://www.apra.gov.au/news-and-publications/apra-finalises-targeted-amendments-to-cps-230-operational-risk-management [Accessed 28 July 2026].
Australian Prudential Regulation Authority (APRA), 2026. CPS 230 Operational Risk Management. Available at: https://www.apra.gov.au/standards/cps-230 [Accessed 28 July 2026].
Bain & Company, 2026. Banks' New Growth Path: From the Customer to the Cloud. Available at: https://www.bain.com/how-we-help/banks-new-growth-path-from-customer-to-cloud/ [Accessed 28 July 2026].
Bain & Company, 2026. Disruption from Within: De-risking Banking Transformations at Speed. Available at: https://www.bain.com/how-we-help/disruption-from-within-de-risking-banking-transformation-at-speed/ [Accessed 28 July 2026].
Capgemini, 2026. Empowering Financial Innovation with Composable Banking. Available at: https://www.capgemini.com/insights/research-library/empowering-financial-innovation-with-composable-banking/ [Accessed 28 July 2026].
Finastra, 2026. Reimagining Banking in APAC with Composable Architecture. Available at: https://www.finastra.com/viewpoints/articles/reimagining-banking-apac-composable-architecture [Accessed 28 July 2026].
Forbes / Visa BrandVoice, 2026. How To De-Risk Core Banking Modernization With Composable Architecture, 24 June. Available at: https://www.forbes.com/sites/visa/2026/06/24/how-to-de-risk-core-banking-modernization-with-composable-architecture/ [Accessed 28 July 2026].
McKinsey & Company, 2026. Global Banking Annual Review 2026: Precision with Speed. Available at: https://www.mckinsey.com/industries/financial-services/our-insights/global-banking-annual-review [Accessed 28 July 2026].
PolicyRix, 2026. Australia's APRA CPS 230 Operational Risk Standard Takes Full Effect July 1 for Insurers and Banks, 27 June. Available at: https://www.policyrix.com/news/2026-06-27/apra-cps-230-operational-risk-july-2026-insurers-banks [Accessed 28 July 2026].
The Asian Banker, 2026. Asia Pacific Banks Must Modernize Infrastructure Without Surrendering Their Trust Advantage. Available at: https://www.theasianbanker.com/updates-and-articles/asia-pacific-banks-must-modernise-infrastructure-without-surrendering-their-trust-advantage [Accessed 28 July 2026].
10x Banking, 2026. Core Banking Platforms Compared: The 2026 Enterprise Buyer's Guide. Available at: https://www.10xbanking.com/core-banking-platforms-compared [Accessed 28 July 2026].
10x Banking, 2026. Core Banking Migration Strategies: Choosing the Right Path to a 4th-Generation Platform. Available at: https://www.10xbanking.com/insights/core-banking-migration-strategies-choosing-the-right-path-to-a-4th-generation-platform [Accessed 28 July 2026].
Trace Consultants, 2026. CPS 230 for Banks: Operational Resilience and Third-Party Risk. Available at: https://www.traceconsultants.com.au/thinking/cps-230-what-this-means-for-banks-and-why-operational-resilience-is-a-supply-chain-problem [Accessed 28 July 2026].