Automation is nothing new in the pensions industry. Advances in technology have rendered many of the long-standing risks and challenges of pension scheme management obsolete. Gone are the days when a flooded basement might wipe out a swathe of member records, and the digitising of archive files means no more lengthy sessions in front of a microfiche reader. Every new digital development brings with it potential benefits for a scheme’s members, its trustees and their service providers. However, at the same time, new risks are introduced which all parties need to get to grips with.
But is the widespread adoption of AI the starkest example yet of technology sharpening the double-edged sword of risk and reward?
AI in pensions: opportunity and risk
Few trustee boards are likely to develop their own AI tools but as scheme administrators, consultants and advisers integrate AI into their services, trustees may not have full oversight of where it is being used or the controls that surround it. This presents a significant governance challenge.
In the same way that cyber risks, data protection and operational resilience are considered, trustee boards must consider the risks associated with the integration of AI into everyday scheme administration and management and take steps to ensure that appropriate governance frameworks are in place.
AI adoption can result in myriad improvements to trustees’ and members’ experience. Faster service delivery through automated processing of admin tasks, AI-assisted decision-making and minute-taking, data gap analysis, and improved member support are just some of the well-understood benefits of AI for pension schemes.
The Pensions Regulator (“TPR”) recently published its AI Plan, which clarified its own stance that trustees remain accountable for a scheme’s outcomes. TPR expects trustees to understand how AI is being used and to have appropriate assurance that controls are in place to manage and monitor AI-related risks.
In practical terms, that means trustees should be engaging with their service providers and asking them not only whether they use AI, but how it is governed and what assurances can be provided around its use.
Practical steps for managing AI-related risks
From a governance perspective, the following actions may support trustees in navigating the use of AI:
- Engage directly with advisers and providers to identify where AI is being used in relation to the scheme.
- Update risk registers to include AI-related risks, in order to identify potential issues and facilitate ongoing monitoring through existing risk management processes.
- Review supplier contracts to establish whether appropriate assurances around AI use and controls are clearly set out.
- Develop an AI policy as part of the overall governance framework.
- Engage with targeted training to understand both the opportunities as well as the risks of using AI in pensions.
The SPP’s new framework
The Society of Pension Professionals (“SPP”) has also just published a practical framework for pension governance in the age of AI, which brings to life many of the principles set out in TPR’s AI Plan. It divides types of AI activity into low, medium and high risk, noting that those classifications can be applied across the broad categories of AI use that schemes are likely to come across, including enterprise-level AI adoption and governance (used by the scheme, employers and administrators for day-to-day matters), investment management, and member use of public AI tools. The guide also draws attention to a number of AI-related risks including those stemming from automated decision-making (“ADM”) and uploading data and sensitive documents into public AI tools.
Building on the ADM point, trustees should check whether service providers proposing to use it have carried out a data protection impact assessment and also review their own data protection policy and privacy notice to ensure that ADM is covered.
Additionally, from a legal perspective, the guide usefully summarises some key contractual areas that trustees should seek to cover off with their service providers:
- disclosure of AI use by service providers. Provisions should identify matters such as the functions for which AI is used, the review of outputs by qualified personnel and material limitations or risks of the technology;
- requiring providers to maintain internal governance arrangements for AI systems, since trustees have a vested interest in any systems which impact upon scheme administration/decision-making;
- audit and assurance rights for the trustees, (e.g. to ensure that trustees can obtain evidence from providers of internal control testing, cybersecurity measures relating to AI, and quality assurance processes);
- data protection and confidentiality, including updating existing contracts to go beyond the scope of data protection legislation, so as to cover AI-assisted processing. Any confidentiality agreements should make clear that information processed via AI systems is covered; and
- requiring service providers to notify the trustees of new or expanded AI use, such as the introduction of new AI technology or making significant changes to how AI is used in producing advice or administrative outputs.
With the use of AI now prevalent in every corner of the pensions landscape, it’s understandable if trustees feel overwhelmed by the additional potential risks that need to be managed. But the landscape hasn’t really expanded – it’s just more densely populated than before. The same principles of good governance still apply and, if used responsibly and with appropriate oversight in place, AI can bring a host of benefits to a pension scheme.
If you would like to discuss how to implement appropriate AI governance into your pension scheme, we would be happy to help. Please get in touch with your usual contact in the pensions team or scheme governance team.
Written by
Related News, Insights & Events
Error.
No results.
Getting your data ducks in a row: putting the Data (Use and Access) Act 2025 into practice for pension schemes
09/06/2026
In this blog, we consider how The Data (Use and Access) Act 2025 (the “DUAA”) raises the bar for how pension trustees’ role as data controllers must be performed.
Own risk assessment – how effective is the ORA regime?
28/05/2026
This blog explores how trustees can use the ORA to enhance governance effectiveness and strengthen operational resilience in practice.
Pension Schemes Bill receives Royal Assent at last: the ‘ping pong’ has concluded
30/04/2026
This insight discusses the Pension Schemes Bill which received Royal Assent yesterday, becoming the Pension Schemes Act 2026.
{name}
{properties.pageSummary}
{properties.headline}
{properties.pageDate|date:dd/MM/yyyy}
{properties.shortDescription}