Skip to main content

Making workplace pensions work

Menu

IT functionality and maintenance

CDC code in force: 31 July 2026

  1. The regulations set out the matters we must take into account in deciding whether we are satisfied that a CDC scheme has sufficient IT systems to ensure that it is run effectively1. This applies to both the systems and processes and member communications authorisation criteria.
  2. System functionality is important as it provides a basis for good administration and ensures that members receive the correct benefits at the right time. It will be difficult for us to be satisfied that a scheme has sufficient IT systems to ensure it is run effectively if the required functionality is not in place and its effective use cannot be demonstrated.
  3. For multi-employer CDC schemes only: the IT systems must be of sufficient standard to allow the scheme to meet the objectives set out in the business plan2.

Functionality of IT systems

  1. We are more likely to be satisfied where the IT system has the features set out in the following sub-sections.

Transactions and annual events

  1. The IT system can:
    1. process transactions, including the processing of leavers, retirements, deaths and transfers
    2. process annual events, including the annual adjustment exercise and benefit statements
    3. reconcile data against transactions and annual exercises
    4. increase and reduce target and in-payment benefits on an annual basis
    5. rectify errors – and there is a clear process to do so
  2. Systems handling administration have:
    1. segregated duties, with a junior level of clearance to input data and request payments or benefit changes, and a senior level to authorise changes and transactions
    2. authorisation levels to prevent payments of certain sizes exceeding those allowed by the trustee mandate
  3. Multi-employer CDC schemes only: the IT system can reconcile contributions paid by or on behalf of an employer with the records of the member to whom they relate3.

Member records

  1. The IT system can record members’ benefits correctly, including:
    1. basic member information such as name, date of birth, NI number, address, pensionable service, pensionable salary, dependants’ information
    2. all contributions
    3. full record of target accrual and annual adjustments
    4. full record of pension payments and annual adjustments
    5. full record of periodic income during wind-up and adjustments made
    6. details of payments made into or out of the scheme including transfers, deaths and divorces
  2. The IT system can extract the necessary data for the annual valuation using automated routines, including the ability to check data quality.
  3. The IT system can provide complete and accurate data and meets the requirements of 
    pensions dashboards.

Administration system payments

  1. The default is for all payments into and out of the scheme to be made electronically, and manual payments are made by exception.
  2. The IT system can make monthly pension payments and calculate and deduct tax.
  3. The IT system has the capability to accept contributions from a range of sources and caters for different sizes of employers.
  4. The IT system can transfer data and monies from and to other IT systems, including those used by:
    1. employers (including third party payroll or other providers acting on behalf of employers)
    2. administration systems (in-house or third party)
    3. investment managers
    4. investment platform providers 

Member communications

  1. The IT system can produce member communications automatically, including individual transactions and annual exercises.
  2. The IT system can record members’ communication preferences.

Promotion or marketing

  1. The IT system can hold all required records relating to promotion and marketing.

Maintenance of IT systems

  1. It’s important that the data held in the IT system is maintained to reflect the scheme’s current needs and legal requirements. This includes the need to protect data appropriately.
  2. We are more likely to be satisfied where evidence demonstrates the following:

Planning for change

  1. How known changes to the system are planned and executed, and this is reflected in the governance plans, risk framework and estimates of costs for running the scheme.
  2. If there is no system functionality in place at authorisation to calculate benefits under continuity option 1, how and when this functionality will be developed and the costs of doing so. We will expect that the development of this functionality would not delay the progress of continuity option 1.
  3. The system can be updated.
  4. There is a robust methodology for releasing changes to systems, along with a portfolio of ongoing change to systems for a rolling five-year period.
  5. There is an IT process for making scheduled and known changes, including annual updates and changes in tax thresholds.
  6. There are adequate and sufficient resources, with appropriate skills, to carry out the work.
  7. The IT system can meet the expected physical system requirements, and the scheme has the funds to meet those requirements.
  8. There are plans for how planned and potential future upgrades can be managed in the administration system and the trustees are satisfied that the system can be upgraded to meet the needs of the scheme.
  9. There is a policy for maintaining, upgrading, and replacing hardware and software, and this is accounted for in the costs of running the scheme.

Protecting data

  1. There are cyber-defence strategies, including firewalls and intrusion detection systems.
  2. There are procedures and protocols for governance, identifying and resolving risks and breaches, and responding to cyber incidents.
  3. There are roles assigned to manage these protocols and procedures.
  4. Scheme, member and communications data are backed up at least daily, with backup servers at an external location and of-line backup.
  5. There is a disaster recovery process with roles assigned, which is tested every six months.
  6. Adequate steps are taken to ensure data security, including compliance with GDPR.

Legal references

1 Section 16 of the Pension Schemes Act 2021 and Regulations 6, 13, 14 and Schedules 4 and 5 of the 2022 Regulations

2 Paragraph 2 of Schedule 5 of the 2025 Regulations

3 Paragraph 1(i) of Schedule 5 of the 2025 Regulations

Is this page useful?

Thanks for your feedback.