SPP Publishes AI Governance Framework for UK Pension Schemes
The Society of Pension Professionals (SPP) has published a new governance framework for pension schemes using artificial intelligence, titled Governance in the Age of AI: A Practical Framework for Responsible Leadership. The guidance acknowledges that AI adoption has accelerated rapidly across the industry, but it stresses that trustees' core fiduciary duties have not changed. Instead, scheme leaders are expected to adapt their existing governance, data security and risk management arrangements to oversee the growing influence of AI on scheme administration, investment strategies and member communications.
The framework sets out five principles. The first is proportionality to risk: schemes should classify AI usage into low, medium and high-risk tiers, with enhanced governance and robust validation for high-risk uses such as outputs that directly affect member benefits or advice. The second is meaningful human oversight, requiring qualified human reviewers with real authority to evaluate and alter automated decisions. The third covers data security and privacy, warning that confidential scheme information and sensitive personal data should never be entered into unapproved or public AI models.
The fourth principle concerns third-party and adviser governance: supplier contracts should be updated to mandate transparency about AI tools, human review policies and protection against AI-enabled cyber fraud or deepfakes. The fifth focuses on member guidance, calling for clear scheme communications so that members do not rely on inaccurate or hallucinated output from public AI tools. The SPP argues that AI governance is not a separate discipline but an essential part of fulfilling fiduciary responsibilities under existing regulatory standards, and that the controls should be embedded into risk registers and service reviews.
Jo Fellowes, Chair of the SPP Administration Committee, said: “Artificial Intelligence has moved from an emerging technology to an everyday reality across the pensions industry. The challenge is therefore not whether AI should be used, but how it can be used safely, transparently and with appropriate oversight. This SPP guide should help schemes achieve this.”
What the Five Principles Mean for Trustees and Administrators
Trustees Can Delegate Tasks, Not Accountability
The central message of the framework is that AI does not change who is responsible for a pension scheme. Trustees may use automated tools to run administration, shape investment strategies or draft member communications, but the fiduciary duty to act in members' interests sits with the board. That is why the SPP places such emphasis on high-risk classifications: any AI output that directly affects member benefits or advice must carry enhanced governance and validation, because a mistake there is a member outcome, not a back-office issue.
Contracts Are the Front Line for Data and Fraud Risks
Pension schemes rarely build AI themselves; they rely on administrators, actuaries, investment managers and other advisers. The SPP's focus on updating supplier contracts reflects that reality. By mandating transparency about which AI tools are used, how human review works and how AI-enabled cyber fraud or deepfakes are handled, schemes push governance obligations down the supply chain. The warning against putting confidential scheme data or sensitive personal data into unapproved or public AI models addresses one of the most concrete risks in the current environment: staff or advisers using general-purpose chatbots with commercially sensitive or personal information.
Member Communications Become a Governance Issue
Public AI tools can produce persuasive but incorrect answers, and members may rely on them when trying to understand their pension. The SPP treats this as a governance problem rather than a mere communications problem. Schemes need to make sure official channels are clear and authoritative enough that members do not fall back on hallucinated guidance, and they should consider what their communications say about where members can get reliable answers.
An Industry Trend With Regulatory Resonance
The framework does not introduce new law or name a specific regulator, but it explicitly ties AI governance to existing fiduciary duties and regulatory standards. That framing is significant: it positions AI oversight as something supervisors and auditors could reasonably expect to see reflected in a scheme's risk register, rather than as an optional innovation project. Schemes that embed the SPP's controls early will be better placed to demonstrate that they acted consistently with their duties if AI-related failures are later examined.
Practical Steps for Pension Schemes Adopting AI
The SPP's framework is addressed directly to pension scheme boards and their advisers. The practical steps below follow from the five principles it sets out.
- Classify every current and planned AI use across administration, investment and member communications into low, medium and high-risk tiers, and apply enhanced governance and validation to high-risk outputs that affect member benefits or advice.
- Ensure automated decision-making includes qualified human reviewers with real authority to evaluate and alter outcomes, and keep records of those reviews.
- Ban the input of confidential scheme information or sensitive personal data into unapproved or public AI models, and reflect that prohibition in staff and adviser guidance.
- Update supplier and adviser contracts to require transparency on AI tools, human review policies, and protections against AI-enabled cyber fraud and deepfakes.
- Review member-facing communications to ensure members know how to get reliable, scheme-specific answers rather than relying on output from public AI tools.
- Embed AI controls into risk registers and scheduled service reviews so that governance is tested continuously, as the SPP recommends.
Risk & Opportunity Assessment
| Commercial Risk | Medium | AI failures in benefit calculations or member-facing advice could lead to financial loss and complaints; the SPP explicitly flags high-risk uses affecting member benefits as needing robust validation. |
| Competitive Risk | Low | The framework is voluntary best practice rather than a new market requirement, so it does not directly shift competitive position between schemes. |
| Regulatory Risk | Medium | The SPP ties AI governance directly to existing fiduciary duties and regulatory standards, meaning schemes may be expected to demonstrate AI controls under current supervision and audit processes. |
| Reputation Risk | Medium | The SPP warns against data breaches and members relying on hallucinated AI guidance, both of which could damage member trust if they occur. |
| Technology Disruption | Medium | AI is already reshaping scheme administration, investment processes and member communications, and the framework is a direct response to that rapid adoption. |
| Commercial Opportunity | Medium | The SPP argues that with proper controls in place, schemes can capture AI efficiencies in administration and investment while protecting member interests. |
Comments 0