Skip to main content

Making workplace pensions work

Menu

Meeting the systems and processes requirements

Guidance on meeting the authorisation criteria for systems and processes set out in our collective defined contribution (CDC) code of practice.

Published: 31 July 2026

Who this guidance is for

This guidance is aimed at trustees of new CDC schemes, as well as any other roles involved in meeting the requirements for IT systems and scheme governance.

You should refer to this guidance when preparing an authorisation application as it will help you complete your systems and processes questionnaire and other documents we require. Prospective applicants should contact our innovation team first to discuss their application.

On this page

Overview

This guidance will help you understand the systems and processes requirements set out in our CDC code of practice to evidence CDC scheme:

What the application should include

The narrative and evidence submitted as part of an application must be clear, relevant and user friendly for example, by use of highlighting, tabs and cross-referencing.

You should describe how your IT systems and scheme governance meet, or are intended to meet, each of the requirements set out in legislation and in our code of practice.

You also need to provide specific evidence supporting your description.

Your evidence should do the following:

  • Identify the specific requirements which need to be met.
  • Describe how your IT systems and scheme governance meet that requirement.
  • Explain how any control objectives tested in independent external assessment reports are relevant to evidence against certain requirements.

You should create an index referencing the specific sections (pages, paragraphs, sentences) of your supporting evidence which relate to each specific requirement.

We will be unable to assess whether and how your systems and scheme governance meet the requirements unless we are able to answer the following questions against each requirement:

  1. Does the functionality or process exist, or is it planned to exist?
  2. How does it work, or how will it work?
  3. How will it be reviewed and monitored by the trustees to ensure it remains effective over time?
  4. How will any necessary development be carried out, and over what timescale?

Trustee accountability for outsourced services

Where administration, technology, communications or other operational functions are outsourced, trustees remain accountable for ensuring that the systems and processes requirements are met and continue to be met.

Trustees should be able to demonstrate how they:

  • have assessed provider controls
  • obtain assurance
  • challenge and monitor service providers where deficiencies or risks are identified

IT systems requirements

New systems and those in development

Schemes should be able to clearly demonstrate that their systems can support accurate benefit delivery from day one. 

As a best-practice approach, trustees should be able to demonstrate working, testable CDC specific system capabilities, not simply intent or theoretical functionality. Ideally, we would expect to see evidence that:

  • technology has been tested and provides stable core functionality
  • processes are documented and rehearsed
  • people have been trained and roles are clearly defined
  • governance, management information, reporting, and escalation processes are all in place

We understand that schemes may wish to apply for authorisation before they have fully completed all development work on their IT systems. Development completed too early may create avoidable risk and inefficiency, including stale assurance and configuration and an inability to create test data that accurately reflects the profile of the first employers and members. Different employers may have specific needs that need to be accommodated. Trying to anticipate all of these in advance is not good risk management and may lead to fractured development processes.  

It is important that we can see there are processes that show an ability to learn and adapt and also a reasonable level of resources to make well controlled changes post go-live. We recognise that the cost of being operationally ready may be significant, including where staff are ready but not yet used. However, we do expect IT and administration systems to be sufficiently developed that we can make a reasoned assessment. We would need evidence to satisfy us that there are sufficient systems and processes in place, and that they will be ready to go live when the scheme starts operating.

We do not authorise on a conditional basis, but in this instance, we are prepared to accept a more staged approach to technology assurance where this facilitates an efficient and effective development and testing process. We are more likely to be satisfied if the administration team (whether in-house or third party) has experience in administering other pension schemes and that the systems are being developed by teams and providers with appropriate experience. 

While there are many system development processes lifecycles, we would expect that a typical one might include the following stages: 

1.    Planning and requirement gathering (functional and non-functional).
2.    System design and architecture.
3.    Development and/or procurement.
4.    Testing and quality assurance.
5.    Deployment.
6.    Maintenance, evolution and optimisation.

We are more likely to be able to satisfy ourselves that an administration system will be adequate where schemes are at least part way through stage 4 at the point they apply for authorisation. By this stage you should be able to provide clear testing and quality assurance plans for all requirements. We will place a greater emphasis on evidence that supports the existence of functionality for processing contributions, allocating units, calculating benefits and updating member records.  

Suitable evidence may include: 

  • development and testing plans
  • test outputs
  • test strategies
  • test scripts
  • execution results
  • defect logs
  • user acceptance testing
  • change logs
  • formal sign-off processes

Particular emphasis should be placed on evidence supporting:

  • contribution processing
  • unit allocation
  • benefit calculation
  • annual adjustment exercises 
  • member record maintenance
  • key system interfaces

The role of assurance, accreditation and other independent external assessments

In assessing whether an IT or administration system is fit for purpose for a CDC scheme, we recognise the potential challenges and limits of the evidence that can be provided. CDC schemes that apply for authorisation are likely to be entirely new schemes and not currently functioning. This means that evidence will need to demonstrate how the systems are robust through appropriately detailed testing. 

This means that for our initial assessment in the authorisation of CDC schemes, we will need evidence of two key things:

  1. That a system is functional and operates as expected in testing (ie that it has the capability to complete tasks relevant to the running of the scheme).
  2. That there is a process to monitor the administration systems operation over time (so errors can be identified and addressed).

Third-party administrators or IT providers may be able to provide assurance reports as supporting evidence that an IT or administration system is able to process, for example, a transaction or a contribution. We expect applicants to have established that the IT or administration system was fit for purpose at either of the following points:

  • While carrying out due diligence on potential providers, but before appointing them.
  • After appointing them, but before applying for authorisation. 

There are various types of assurance report which are based on testing the effectiveness of processes related to systems and administration, including AAF reports and Agreed Upon Procedures. Other relevant, proven standards or approaches include the following:

  • ISO 27001-aligned information security and incident management: Annual UKAS audit, SOC monitoring and layered cyber controls.
  • ITIL-based change and release governance: Structured requirements, testing, risk assessment, and post-implementation review.
  • Operational control environment: Workflow validations, segregation of duties, daily cash/unit reconciliations and exception reporting.
  • Supplier oversight consistent with SYSC-style expectations: Due diligence, SLAs/KPIs, ongoing monitoring, escalation and audit.
  • Enterprise risk management with defined ownership, quarterly oversight, root-cause analysis and integration into planning.
  • Standards such as AAF01/20 reporting, SOC2 reporting and Master Trust Assurance.

Assurance reports are not mandatory but may be an effective method of demonstrating that the systems are sufficient to ensure the effective running of the scheme.

You may wish to commission an Agreed Upon Procedures report conducted by a reporting accountant in accordance with ISRS 4400 (Revised) that covers both point 1 and 2 above.

The reporting accountant should:

  • be engaged by the trustees to carry out test procedures that align with the systems and processes questionnaire on the IT and administration system’s capability to meet the requirements in the code and legislation
  • report to the trustees the factual results of the agreed testing procedures performed and any recommendations arising from the engagement, noting that this approach does not result in an assurance opinion

The trustees would review the Agreed Upon Procedures report and submit it, along with other appropriate materials, as evidence that the requirements in the code and legislation are met. 

The scope of any assurance review is not standardised but is defined by the entity being assessed. For example, control objectives can be removed by trustees from the scope of an assurance assessment and report. Similarly, the scope of an ISO 27001 assessment is agreed before a review is carried out and therefore may vary between CDC schemes. Trustees receiving an assurance report might find that some, or all, of their processes are not within the scope of the report.

Additionally, we have found the depth and quality of the methodologies used in assessing against these standards can also differ greatly. Reviews of the same control objective have on occasion generated significantly different levels of evidence depending on the methodology used. We encourage trustees to think about the level of detail that would be useful in evidencing capabilities. This will ensure the reporting they receive meets their standards and requirements.  

In relation to any independent external assessment report, we will want to understand the methodology used by the assessor to carry out the review against each standard or control objective and the evidence which informed the assessor in carrying out the review and coming to their conclusion.

Assurance reports will normally include a series of control objectives against which the reporting accountant (or other type of assessor) will assess your scheme, processes or systems. The objectives may not match the specific requirements laid out in the CDC code. However, there may be overlap between certain control objectives and the requirements (either in the control objective itself, or in what has been assessed by the reporting accountant). Where this is the case, it is imperative that your evidence describes how the control objective is relevant to the requirement and, in your narrative, explain how your CDC scheme meets that requirement.

We understand that this type of report comes at a cost to the applicant, so we do not insist on this approach. But in our experience, Agreed Upon Procedures reports will typically help provide a stronger evidential base.

Specific requirements for administration IT systems

We expect to see evidence of due diligence and assessment processes in selecting service providers, or anyone else who will be involved in the ongoing running and support of the scheme’s IT systems.

Administration system payments 

Trustees should be able to provide us with evidence of their administrator’s processes, which describe how contributions will be paid by employers. We also expect to see evidence that processes are in place to make payments to members at and beyond retirement. Any in-house or third party administrator should be able to demonstrate that their IT and administration systems are, or will be, capable of meeting our expectations in this area.

It may not be possible to provide us with evidence of historical payments being made for this specific scheme. However, the evidence provided should be able to demonstrate that the IT and administration systems are capable of processing electronic payments. 

Where relevant, evidence should include successful use of the chosen system(s) in other relevant contexts, such as delivering administration services to existing clients. Administrators may also have an independent external assessment which, if the scope and methodology of the assurance is fit-for purpose, provides additional evidence of the requirement being met. 

Administration system records 

Trustees should be able to demonstrate the sufficiency of any administration system, using (where possible) reference to member data processed on behalf of other clients using the same administration system. We do not wish to see personal data of members (which should be redacted), but rather examples of how the data is managed and monitored. This could include examples of administration reports and data sampling exercises. The administration provider may also have an independent external assessment report which may, if the scope and methodology is adequate, provide evidence for this requirement. 

Data quality framework

Trustees should be able to demonstrate that data quality standards have been established and are monitored. This may include controls over:

  • completeness
  • accuracy
  • validation
  • exception handling
  • correction of errors
  • regular reporting on data quality outcomes  

Administration system transactions 

The following evidence could be sought by trustees from the scheme’s proposed administrator to support the application: 

  • Administrators should have process documents describing how system functions work, or will work, in practice. This includes details of responsibilities for managing and implementing these processes, and how they will be monitored to ensure that errors are identified and addressed and do not recur. Third party administrators may have historical data related to other clients which demonstrate these processes working in practice, including examples of quarterly administration or stakeholder reports, which are sent to trustees to allow them to oversee scheme administration on an ongoing basis. 
  • All providers of administration services should engage an auditor to carry out an annual assessment of their systems and, critically, their management of core transactions. Trustees should ask their administrator for this document and seek to understand the scope and methodology used by the Reporting Accountant who carried out this testing. 
  • Any administrator should be able to provide internal process documents detailing how duties are, or will be, segregated. We expect trustees to demonstrate why these processes are fit for purpose and an understanding of how they work. 
  • We also need to see evidence of how the trustees have set their required level for the trustee mandate, and that this is recorded in their documented processes for governance and monitoring of scheme administration. 

Systems control environment

Trustees should understand the control framework operating within administration and IT systems. This includes:

  • role-based access controls
  • segregation of duties
  • dual authorisation
  • payment limits
  • audit trails
  • privileged-user monitoring 

CDC-specific annual processes

Trustees should be able to demonstrate that administration and IT systems can support CDC-specific annual processes. This includes: 

  • annual adjustment exercises
  • benefit increase or reduction calculations
  • production of annual benefit statements
  • actuarial data feeds 
  • reconciliation of annual exercises

Evidence may include:

  • test scripts, test results
  • user acceptance testing
  • defect logs 
  • sign-off documentation

Planning for change 

Trustees could seek evidence from the scheme’s proposed administrator on documented processes which cover our requirements on how changes to IT systems will be funded and delivered. We expect trustees to have sight of and be familiar with these processes and to explain how they are content that they are fit-for-purpose. This explanation should correspond with the narrative and other content in the scheme’s business plan. 

Protecting data 

Trustees could ask the scheme’s proposed administrator for evidence of its data protection and disaster recovery strategies and processes. A third-party administrator or IT provider will already have these, and they are likely to have been tested against industry standards. An in-house administrator may already have such processes, and we will expect to see that policies designed to meet the expectations for data and data protection set out in our code are in place and/or plausible. The trustees should similarly have a clear approach to monitoring compliance, and a timetable for obtaining independent assurance.

Operational resilience

In addition to disaster recovery and data protection, trustees should understand how operational resilience is maintained. Evidence may include:

  • business continuity arrangements
  • cyber incident response procedures
  • supplier failure arrangements
  • resilience testing
  • recovery exercises

Systems supporting member communications

Where systems support member communications, trustees should be able to demonstrate that communications:

  • are generated accurately
  • use appropriate member data
  • are subject to quality assurance and testing processes

Reconciliations 

Any in-house or third-party administrator should be able to demonstrate that reconciliations are undertaken across key processes. This includes:

  • contributions received
  • allocation to member records
  • benefit calculations
  • pension payments

Processes should include:

  • exception reporting
  • investigation
  • escalation 
  • resolution procedures

Trustees should understand what management information is produced and how reconciliation outcomes are monitored. We anticipate that a third-party administrator, if selected, would be able to provide an independent external assessment relevant to this requirement.

Error management and rectification

Trustees should seek evidence that providers operate documented incident and error management processes. This should include:

  • identification
  • escalation
  • correction
  • root cause analysis
  • remediation
  • lessons learned
  • reporting to trustees

Trustees should understand how members would be protected where errors affect member records, contributions or benefit payments.  

Management information and oversight

Trustees should identify the management information they require to oversee administration and IT systems. This may include:

  • data quality metrics
  • processing times
  • transaction volumes
  • reconciliation exceptions
  • service level performance
  • complaints
  • incidents
  • cyber events
  • change requests
  • remediation activity

Record-keeping 

The following evidence could be sought by trustees from the scheme’s proposed administrator to support the application: 

  • We expect any third-party service providers, including those providing administration services, to be able to provide examples of their current processes and procedures as part of their tendering process. An administrator may also be able to provide a suitable independent external assessment relevant to the quality of their record-keeping. 
  • In-house administration services should have a clearly demonstrable plan for meeting our expectations in this area, as laid out in our code. 

Scheme governance requirements

Organisation map

You should provide an organisation map which demonstrates how the trustee board governs and oversees the scheme. The organisation map should support the requirements in the Scheme governance module of the CDC code of practice by setting out:

  • the key functions that are monitored and governed by the trustees
  • the individuals accountable for each function
  • any committees or sub-committees involved in oversight and decision-making
  • reporting and escalation arrangements
  • how trustees obtain and use management information to oversee the scheme

The organisation map should provide a clear view of the scheme's governance framework and act as a central point of reference for trustee oversight. It should be consistent with, and where appropriate reference, other governance documents, including:

  • the risk register
  • business and activity plans
  • trustee skills and competence assessments
  • relevant policies, procedures and governance documents
  • the objectives statements described below

The organisation map should cover all functions relevant to the effective operation and governance of the scheme. We have broken these down into:

  • trustee board management
  • risk register and policy
  • communications strategy or policy
  • objectives statements

These areas are not prescriptive, and you may wish to change them to suit the operation of your scheme. If you take this approach, clear referencing to the code of practice is vital. Applicants may cross-reference evidence submitted elsewhere in the application where appropriate to avoid duplication.

Trustee board management policy

You should provide a trustee board management policy explaining how the trustee board operates and maintains effective governance. This should include:

  • trustee recruitment and succession arrangements
  • diversity and inclusion considerations
  • governance and decision-making arrangements
  • management of actual and potential conflicts of interest
  • committee structures and delegated responsibilities
  • how trustee knowledge, skills and experience are assessed, maintained and developed

Risk register and policy

As part of the documentary evidence connected to the organisation map, we would like to understand how risks are identified and managed by the trustee board. We need to see:

  • the risk register that will be used over time for risk management and governance
  • a risk management policy outlining how the register is used

You should provide evidence of the adequacy of your risk management, including operational, financial, regulatory and compliance risks. You should also identify the relevant risks under each of these risk types to include in your scheme’s risk management framework. 

You should describe the key operational, financial, regulatory and compliance risks identified for inclusion on the risk register, along with commentary on: 

  • how these risks have been identified, assessed and rated 
  • how they are to be mitigated, managed or monitored over time (including the management information required to facilitate this, where appropriate) 
  • who owns each risk
  • how, and how often, the risks on the risk register are reviewed and refreshed to ensure they are current

We expect you and other relevant parties to demonstrate you have identified all the risks that may affect the ongoing effectiveness and running of the scheme. 

You will need to explain and evidence in a risk management policy how particular risks are identified and managed. You should also describe how trustees know who is managing key risks to members and how they have considered whether that individual or organisation has the necessary skills, knowledge and resources to be the appropriate owner of that risk. 

You should describe how the scheme proprietor, responsible for managing and monitoring risks to the delivery of the business plan, has access to the management information and intelligence they need to carry out this task properly. 

You should also describe the evidence and management information that trustees and the scheme proprietor use to monitor and manage risks of various types and how they ensure they are getting this information from the relevant source. We are carrying out a desk-based assessment of this activity with little opportunity to ask for more information. This means the narrative must explain in detail how risk identification, monitoring and management work in practice, along with all relevant documentary evidence. 

We would typically expect the trustee board to be at the centre of, and ultimately responsible for, these activities. However, we also understand that there may be other risk-management activities elsewhere in the structure of a multi-employer CDC scheme, including the scheme proprietor. Where this is the case, you should provide narrative and evidence for both the other parties’ risk management activities and the trustees’ and scheme proprietor’s scrutiny of those activities.

You should also explain how the use of the risk register for identifying and monitoring risks interacts with the use of the organisation map in terms of overall trustee governance and oversight.

Communications strategy or policy 

Applicants should have a fully documented and evidenced approach to member communications, describing how they will be developed, reviewed and maintained. 

This policy should cover:

  • accountability on the trustee board for overseeing member communications and the team that supports their work, including: 
    • how those involved have the skills and experience to manage member communications
    • the basis for appointing any external advisers 
    • how the individuals involved have sufficient capacity to do the work needed
  • the data used in developing communications, including how the trustees have established an understanding of their membership profile and the feedback that they receive
  • the communications work that will be undertaken over the next year, highlighting any major undertakings and longer-term work

The code sets out that “member communications should be consistent with any promotional or marketing material that has been used to induce prospective or existing employers to join or remain within the scheme.” 

We will expect to see evidence on how feedback will be sought from different parties on the accuracy and comprehensibility of communications. This could be on an ad-hoc or planned basis. We recognise that it may not be easy to seek feedback from a range of members, but it is an important task and could be achieved through focus groups or surveys.

We will want to understand how this feedback is reported into the trustee board as a whole and would like to see it being discussed at least quarterly. It will also be important for members to understand the work that is being done on communications and how their views are being taken on board. We will want to know how this work will be reported back to members on an annual basis. This could be in the form of a separate communication or as part of other planned work. 

We will expect to see evidence of how key communications have been developed. This evidence could focus on the member booklet and benefit statement template, including how:

  • these key communications have been designed
  • feedback has been sought from stakeholders and then acted on
  • trustees are satisfied that the communications are suitable

Submissions in this area will be supported through an associated section of the systems and processes questionnaire.

Objectives statements

The code of practice requires a statement for each function setting out its aims, objectives and key activities. In your application, this should be provided as an objectives statement. These will form part of the appendix to the business plan. 

Objectives statements should explain how trustees oversee each function and how compliance, performance and risks will be monitored on an ongoing basis. They should also demonstrate how trustees will satisfy themselves that the function is operating effectively and how issues will be identified, escalated and addressed where necessary. This should include supporting key documented processes (indexed and referenced) which the trustees manage and follow. Applicants may signpost to evidence provided elsewhere within the application and do not need to duplicate material already submitted.

Function-specific objectives statements

Objectives statements should be provided, where relevant, for:

  1. managing service provider
  2. administration
  3. investment
  4. actuarial matters
  5. the function of the scheme proprietor
  6. management of financial resources
  7. commercial activities

For each function, applicants should explain:

  • how the activity is governed and overseen
  • the management information available to trustees
  • how performance, compliance and risks will be monitored
  • the roles and responsibilities of accountable individuals and committees
  • how trustee challenge, review and decision-making will take place

The level of detail provided should be proportionate to the nature, scale and complexity of the function, but sufficient to demonstrate effective governance and ongoing trustee oversight. This information will allow us to understand and assess not only how these requirements are met at the point of inception of the scheme, but also how trustees will monitor the scheme’s compliance with them. We will seek to understand in detail the management information that will be available to the trustee board over time, how it will be used and what action can and would be taken by the trustee board if problems arise.

For statements 1 to 4 we will need some further, more specific detail about certain activities, so we have set out additional guidance below. For the final three statements we are keen that there is not overlap or duplication, so these may be shorter and link to other parts of your submission as necessary (for example, the business plan).

1. Objectives statement: Managing service providers

Evidence relating to the management of key service providers should focus on three key points of assessment:

  • The due diligence carried out in relation to each key service provider before appointment.
  • The measures and metrics agreed at appointment which will be used to monitor the effectiveness of service delivery over time, including agreement on frequency and scope of performance reviews.
  • The relevant skills, knowledge and competence of individuals (either on the trustee board or in the business) who are accountable for monitoring and managing each key service provider.

As part of the evidence submitted in the authorisation application, you should provide a detailed objectives statement which includes a list of key service providers (who will be subject to detailed oversight and monitoring) and a narrative description. This should include key process and policy documents where relevant – related to the three points of assessment above.

We do not need copies of contracts with key service providers, but the objectives statement should contain evidence that appropriate objectives and performance indicators have been agreed and also show how they will be monitored (including the frequency and by whom).

Trustees should also be able to demonstrate how they have assured themselves that the provider has staff with the necessary skills and experience. 

The trustees must demonstrate that the scheme proprietor will be informed of the appointment of contract and service providers, their roles and responsibilities, and their removal. 

When preparing the objectives statement, you should ensure you have provided evidence to demonstrate how each of the requirements listed as bullet points under the section on managing service providers in the Processes module of the code have been met.

Bear in mind that the evidence submitted for administration and IT services needs to reference the monitoring of compliance with requirements set out in sections covering IT and administration and the processes which relate to their ongoing effectiveness.

The objectives statement should be linked to the organisation map for clarity of use both by TPR in carrying out an assessment of the scheme’s systems and processes related to governance, and by trustees in their ongoing governance and oversight of the scheme.

2. Objectives statement: Administration

As well as the evidence you will provide in the questionnaire on the systems used for management of member records, we will also need to be satisfied that the trustee board has implemented adequate oversight of scheme administration, including record-keeping, member events, annual valuations, missed contributions and the protection of data.

Key to understanding how oversight of administration will function will be our ability to answer the following questions:

  • What are the trustees’ expectations of the administrator in terms of delivering scheme  administration and record keeping?
  • What management information will be required for them to be able to effectively monitor the proper execution and maintenance of scheme administration against those expectations?
  • How that management information is provided, in what format, by whom?
  • How is this management information scrutinised to enable trustee oversight and monitoring over time?

There will likely be some overlap between the narrative, description and evidence provided here and the evidence presented in the questionnaire. You should ensure you signpost and reference responses in the questionnaire where relevant, describing how any documents cited would support the trustee board in their ongoing oversight of scheme administration.

3. Objectives statement: Investment

In providing evidence related to the trustees’ oversight of investment, there are a number of standard investment-related documents that will help us understand how investment strategies are selected, implemented and monitored, including:

  • proposed templates or formats for quarterly investment performance and risk analytics reports
  • statement of investment principles and – where appropriate – investment implementation planning documents 
  • investment management agreements and/or fund guidelines

Given that we are keen in our assessment of CDC scheme governance to understand how a trustee board gathers the requisite management information and evidence to enable proper ongoing investment governance, we do not want to be overly prescriptive about the other evidence we need to carry out our assessment. 

In the processes module of the code, there is a detailed list of investment requirements we expect the scheme to meet in the investment sub-section. There is also some additional information about how to structure your application in the questionnaire.

We would suggest that, linked to the organisation map, the scheme prepares a detailed objectives statement describing how the requirements are met through trustee oversight and investment governance. This should include copies of the relevant sections of any process, policy, advice or other documents which are referenced as part of the narrative description. You should ensure any page numbers or specific paragraphs are properly signposted in this document.

When drafting an objectives statement describing the trustees’ investment governance, you should also review the investment module in the Sound scheme design section of the code.

4. Objectives statement: Actuarial matters

The scheme must have the following documents available:

  • The viability certificate (and the Scheme Actuary’s report which supports the certificate).
  • The viability report.

The viability report will give us, scheme members and stakeholders an annual insight into the trustee board’s view on the health of scheme design and viability. We expect, as part of our assessment for authorisation, to be able to understand the scope of this report and the principles which inform both its development and trustee review and approval.

You should provide an objectives statement describing the following activities. This should include references to how data and management information, which will inform drafting and decision-making, is sourced:

  • The expected deliverable from the scheme actuary (the content of the Scheme Actuary’s report which supports the annual viability certificate).
  • The scope of the review by trustees of the annual viability certificate.
  • The scope of discussions around scheme investments and whether and how they are supporting the ongoing viability of the scheme.
  • The proposed content of the annual viability report.
  • The scope and decision-making criteria for signing off the viability certificate and viability report.

You must provide the viability report and certificate as part of the evidence related to scheme design, so there is no need to provide them again as part of the evidence related to systems, processes and governance. 

Contact and further support

If you have any questions about this guidance, including the use of assurance reporting, AAF reports or other forms of independent audit as supporting evidence for your application, contact your allocated supervisor. If you are at an earlier stage of developing your proposition you can also contact our innovation team.

Is this page useful?

Thanks for your feedback.