The Society of Pension Professionals (SPP) has published a “governance framework” designed to help scheme trustees navigate the use of AI by identifying the key questions trustees should be asking, the controls they should expect to see and the governance arrangements that should underpin AI use in a pensions context. The five overarching principles behind the framework are: transparency; accountability; proportionality to risk; security by design; and meaningful human oversight.
Trustee use of AI
The SPP warns that sharing a document with a public AI tool (eg to produce a summary) will put it into the public domain for future searches, so trustees need to take care not to put confidential information into public AI tools. It also warns against using AI for decision-making without human validation.
Adviser and administrator use of AI
The SPP says that trustees should understand where AI is being used on behalf of the scheme and whether it influences such matters as calculations, member communications or case prioritisation. It suggests questions for trustees to ask their advisers such as what AI is used in delivering services to the scheme, whether confidential data is used to train models, whether any significant decisions are made on a solely automated basis and what contractual rights trustees have to notification/audit.
The SPP suggests various actions trustees should take where AI and automated decision-making (ADM) are being used, such as establishing clear governance, accountability and oversight for AI use across administrators and other providers. The SPP flags that trustees are data controllers for data protection law purposes, and therefore remain responsible for the processing of personal data by scheme administrators. ADM triggers specific data protection law requirements, so it is crucial for trustees to understand in what circumstances ADM is being used and whether there is any meaningful human involvement in such decision-making. It stresses that nominal human oversight does not avoid the data protection regime for ADM.
Data governance
The SPP flags that large language models and generative AI tools introduce data governance questions that go beyond traditional data protection compliance. It suggests a list of questions that trustees should expect service providers to be able to answer, for example whether scheme or member data submitted to a tool is used to improve the underlying model, as distinct from being processed solely to generate the requested output. It says that any AI use that influences member benefit calculations or decisions should be assessed specifically against Article 22 of UK GDPR which imposes restrictions and safeguards in relation to ADM.
Incident and breach management
The SPP flags the need for AI-related risks to be incorporated into existing governance and breach frameworks. It says that trustees should have a defined threshold for when an AI-related incident must be escalated to trustees directly rather than handled at administrator level. It flags the need for AI-related breaches to be assessed against the Pensions Regulator’s breach reporting framework. It also suggests that trustees should have a communication plan for alerting members rapidly if a scheme-specific scam pattern is detected.
Covenant considerations
In relation to covenant monitoring, the SPP flags the need for trustees to assess the impact of AI on the sponsoring employer’s business, noting that the rapid adoption of AI will inevitably result in “winners and losers”. It also notes that AI is transforming the cyber-risk faced by employers and the potential for a significant cyber-event to affect a sponsoring employer’s covenant.
Contracting
The SPP notes that many current contracts with service providers will have been negotiated before the widespread adoption of AI. It suggests that contractual documentation should evolve to provide greater transparency and accountability where AI is used to provide services. In particular, it suggests trustees should consider requiring service providers to disclose to what extent AI is used in delivering the services, including notifying trustees of new or expanded AI use that occurs during the contract period. It suggests that contracts should require service providers to maintain appropriate internal governance arrangements for AI systems used in connection with the service provision, and to make evidence available of related quality assurance processes. It also suggests trustees require providers to give specific contractual commitments that confidential scheme information and personal data will not be inputted into public or shared AI models without the trustees’ express authorisation.
Scheme members and external use of AI
The SPP notes the risk that members may take “advice” from unregulated AI tools that provide inaccurate information which may in turn result in member complaints. Whilst trustees have no direct control over this, the SPP suggests that providing high quality scheme communications may reduce the risk of members turning to unofficial AI tools for information about their benefits. It also suggests trustees warn members of the risks of using AI tools for pensions information or retirement planning.
Implementation, accountability and oversight
The SPP flags that trustees remain ultimately accountable for the operation of the scheme regardless of whether decisions are delegated to third parties and/or informed by AI-enabled tools. It flags that this principle is reinforced by the Pensions Regulator’s recently published AI plan. This makes it important for trustees to establish accountability for AI use and document it in governance structures. AI should be embedded within existing trustee systems and processes, for example by being included in risk registers, internal controls processes, service provider oversight arrangements and cyber-security frameworks.
Our thoughts
Although this SPP publication does not have official status, we think it does an excellent job of highlighting issues that trustees need to be considering now in relation to AI. Advances in AI have been so swift that many existing scheme policies, risk registers and service provider contracts may not mention it at all, and trustees may have little awareness of how AI is being used by their scheme administrators or other service providers. As an initial step, trustees should be asking questions of their service providers to ensure they have oversight of how AI is currently being used in relation to the scheme.