Good governance in an AI-enabled world

Sharon Bellingham

Sharon Bellingham

Master Trust Lead, Scottish Widows

Artificial Intelligence (AI) is already influencing many aspects of our daily lives. Whether it's helping us find the quickest route home, suggesting the perfect holiday destination, or assisting with homework, AI is becoming an increasingly familiar part of everyday life.​

Pension schemes are no exception; AI is already being used, and it offers significant opportunities to improve efficiency, enhance member experiences and support good outcomes. ​

While trustee boards may not be directly deploying AI tools themselves, AI is increasingly being used by administrators, advisers and technology providers. Trustees need to understand how it is being applied and be satisfied that any use of AI is consistent with their obligation to act in the interests of members. ​

The Pensions Regulator (TPR) AI Plan specifically highlights the importance of governance, oversight, testing, assurance and understanding. The key question is not whether AI should be permitted or prohibited, the focus is on trustees ensuring appropriate governance and controls.​
 

Trustee accountability​

TPR’s message is straightforward: trustees remain responsible for outcomes even where AI is used by their suppliers.  ​

If an AI tool generates an inaccurate member communication, makes an incorrect assumption or contributes to a flawed decision, the trustee board cannot simply point to the technology. Accountability remains with the trustee board. AI may support decision-making, but it does not replace trustee judgement or responsibility.​
 

Data protection and confidentiality​

Pension schemes hold significant volumes of personal and financial information. Trustees need to understand how member data is being used by AI systems, whether it’s being used for model training and what controls exist to prevent unauthorised access, data leakage or inappropriate processing.​
 

Hallucinations and inaccurate outputs​

Generative AI can produce responses that appear convincing but are factually incorrect. This presents obvious risks where AI is used to draft communications, prepare advice, analyse data or answer member queries.​

Robust validation and human oversight of AI-generated outputs is critical.​
 

Bias and fairness​

TPR has highlighted bias as one of the risks schemes should consider when using AI. AI systems can reflect biases present within underlying datasets and may unintentionally produce outcomes that disadvantage particular groups. Trustees should ensure fairness and inclusion remains a central consideration when assessing AI-enabled processes. ​
 

Cyber and scam risks​

AI is changing the threat landscape. TPR has warned of increased risks from AI-generated scams, phishing attacks, impersonation and wider cyber threats. Trustee boards need to ensure their cyber resilience frameworks continue to evolve alongside these emerging risks. ​
 

Oversight of third parties​

For many schemes, this is the most immediate challenge.​

Administrators, auditors, investment consultants and legal advisers are likely to be using AI in some form. Trustees should understand the extent to which AI supports services provided to the scheme, the governance arrangements surrounding its use and the safeguards in place to manage associated risks.​
 

AI governance: the Scottish Widows Master Trust approach​

Recognising both the opportunities and risks presented by AI, and reflecting the themes emerging from TPR’s recent guidance, the Scottish Widows Master Trust (SWMT) Trustees have developed an AI policy designed to support the responsible use of AI. ​

The policy is founded on the simple principle that AI should support good member outcomes and be in members’ best interests. AI does not replace trustee judgement and trustees remain accountable for acting in members’ best interests.​

Jonathan Reynolds, Chair of SWMT says: “AI may change how services are delivered, but it does not change our responsibility to act in members’ best interests. Trustees should approach AI with curiosity and openness; while ensuring the governance and controls needed to use it responsibly are firmly in place.”1

The policy has been developed with regards to Lloyds Banking Group’s AI Assurance Framework and Responsible AI principles, and considers fairness, accountability, transparency, human oversight, safety and sustainability. ​

Key areas of focus include:​

  • AI usage across service providers​
  • Regular AI-related risk assessments​
  • Trustee education and awareness​
  • Maintenance of an AI use register​
  • Trustee approval mechanisms​
  • Clear expectations around human oversight and accountability. ​

A particular area of focus is third-party oversight. The policy requires the Trustees to understand how AI is being used by suppliers and seeks assurance around the controls that are in place. It also establishes clear expectations around data protection, cyber resilience, transparency and accountability throughout the supply chain.​

While every scheme’s approach will differ, the principles are broadly applicable: understand where AI is being used, establish clear accountability, seek assurance from suppliers and ensure that member interests remain at the centre of decision-making.​

The aim is not to restrict innovation. Instead, it is to ensure that opportunities to improve efficiency and member experience are pursued in a controlled, transparent and responsible manner. ​
 

A practical checklist for Trustee Boards​

  • Understand where AI is being used​
    Be clear on where AI is already being used by suppliers and advisers. TPR expects trustees to understand where and how AI is deployed. ​
  • Embed AI within governance frameworks
    AI should not be treated as a standalone issue. Instead, it should be considered as part of existing frameworks and risk management.​
  • Seek assurance
    Trustees should understand what controls, validation, testing and monitoring exist for AI-enabled processes and how suppliers assure themselves that those controls remain effective.​
  • Protect member data and cyber resilience
    Ensure suppliers can demonstrate appropriate data governance, privacy protections and resilience against emerging AI-enabled cyber threats. ​
  • Invest in trustee knowledge and understanding
    Trustees do not need to become AI specialists, but they should have sufficient understanding to provide effective oversight and challenge. ​
     

Looking ahead​

While there is currently no pension scheme-specific AI legislation in the UK, the regulatory landscape continues to develop. TPR has signalled that more detailed guidance on the responsible adoption of AI will follow. ​

TPR has described AI as having the potential to transform pensions for the better, improving administration, decision-making and member engagement. However, it has also made clear that trust remains the foundation of the pensions system and that schemes must adopt AI safely and responsibly. ​

Importantly, AI does not recognise regulatory boundaries. Pension schemes operate within a wider ecosystem of administrators, advisers, insurers and technology providers, many of which are also subject to FCA regulation. Reflecting this, TPR and the FCA are increasingly working together to promote a coordinated approach. ​

In its workplan, TPR committed to “work with the Financial Conduct Authority (FCA) to ensure regulatory alignment across the pensions sector and within the pension supply chain, build and maintain joint supervision touchpoints, and share lessons learnt."1

TPR has also indicated that it intends to make use of the FCA's AI testing and innovation capabilities, recognising the value of shared learning as AI adoption accelerates across financial services.​

For trustee boards, the question is not whether AI will feature but how it can be governed effectively and used responsibly. As expectations evolve across both pensions and financial services regulation, trustees will need to remain alert to emerging guidance and ensure governance frameworks keep pace.​

Ultimately, AI is not first and foremost a technology challenge for trustees; it is a governance challenge. Boards that focus on accountability, oversight and member outcomes will be best placed to harness the benefits of AI while ensuring it is used safely, responsibly and in members’ best interests.​
 



Sources:​

1AI plan, The Pensions Regulator. May 2026