Insights / Retirement Fund Governance · Service Providers
Retirement Fund Governance Insight · Celagenix® Academy

Trustee Oversight of Service Providers: How a Fund Governs What It Outsources

A trustee raised the late reconciliations in March. The chair said the administrator was reliable - they had used them for years. By June, two hundred members were querying missing contributions.

In short: A retirement fund delivers nearly every function through outside providers, but under King V Principle 7 it can delegate the function and never the accountability. Only administrators approved under section 13B of the Pension Funds Act may administer a fund, and the principal officer coordinates providers while the board remains accountable for outcomes. Prudent oversight needs four things per provider - a clear mandate, defined performance standards, an escalation mechanism and scheduled review - plus a conflict of interest policy that is followed, not filed, and CRISA 2 mandates that carry the fund’s sustainability commitments into the contract. The working framework is three elements: mandate clarity, performance monitoring and consequence management, now extended to the digital perimeter under Joint Standard 2 of 2024 and Joint Communication 2 of 2025.

The board had not heard from the administrator in six weeks. Contribution reconciliations were late. A trustee raised it in March, and the chair said the administrator was reliable, they had used them for years. By June, two hundred members were querying missing contributions. When the board finally called the administrator in, the answer was simple: they had changed their internal system in January, and nobody had told the fund. The board had delegated the work. What it had not done was govern it. And under the Pension Funds Act, that gap was the board’s to answer for.

A fund that outsources almost everything

A retirement fund is an unusual organisation. It holds billions in assets, serves thousands of stakeholders, and employs almost no one in the traditional sense. Nearly every function it performs is delivered by someone outside the fund: the administrator who handles contributions, records and benefit payments; the actuary who values the fund’s liabilities; the investment advisors and asset managers who deploy the assets; and the employee benefit consultants, legal advisors and auditors around them. One constraint shapes the administration relationship in particular. Section 13B of the Pension Funds Act restricts who may administer a fund: only administrators registered and approved by the regulator may provide that service. This is not a preference, and the board must confirm that a provider holds section 13B approval before it delegates. Coordinating these relationships sits with the principal officer, the fund’s point of accountability for day-to-day operation, who is accountable to the board and may or may not be a trustee. But coordination is not absorption: the principal officer manages the relationships, and the board remains accountable for the outcomes.

You can delegate the function, not the accountability

So if the administrator does the work and the asset manager makes the investment calls, what is the board still responsible for? Under King V Principle 7, the answer is uncomfortable for anyone hoping delegation is an exit. You can delegate the function. You cannot delegate the accountability. When the board hands work to a provider, it hands over the doing and keeps the answering, and the standard of oversight it owes does not soften because the work moved outside. Adequate and prudent oversight applies whether a function is performed internally or by a third party, and in practice it requires four things for every provider: a clear mandate, so the provider knows exactly what it must deliver; defined performance standards, so delivery can be measured rather than assumed; an escalation mechanism, so problems surface early instead of in June; and regular, scheduled review. Contracts must be arms-length and transparent, and the board must satisfy itself that every provider meets applicable fit and proper standards.

Conflicts hidden in the contract

Service provider relationships are fertile ground for conflicts of interest, and the dangerous ones are rarely obvious. They hide in pooled investment vehicles, where fee allocations across funds may not be transparent; in the valuation of illiquid assets, where the party doing the valuing may also benefit from the number; and in sponsor-affiliated administrators, where the entity that established the fund also profits from administering it. Each arrangement is legitimate in itself, and each also creates a pull away from the stakeholders’ interests. The board’s obligation is twofold: to ensure a conflict of interest policy is in place, and to ensure that policy is actually followed, not merely filed. This is exactly where independent trustees earn their place, because their objectivity is most valuable when a decision touches a provider with something to gain.

CRISA 2 and the mandate

There is a further dimension to how trustees think about the providers who manage the fund’s assets. CRISA 2 is a voluntary responsible investment code for institutional investors, and retirement funds fall squarely within its scope; it sits alongside King V rather than competing with it. Its Principle 4 speaks directly to service provider relationships, asking trustees to align the mandates and contracts they give asset managers and advisors with the fund’s own sustainability objectives. In plain terms, if the fund has committed to responsible investment, that commitment cannot stop at the boardroom door. It must be written into the mandate the asset manager receives and monitored in the reporting that comes back. The contract is where intention becomes obligation.

A framework you apply every time

When a provider’s name comes up in a review meeting, good governance is not a feeling that the provider is reliable. It is a structure you apply every time, the same way, whether the news is good or bad. That structure rests on three elements. Mandate clarity: does the provider have a written, current mandate, and does everyone agree on what it covers? Performance monitoring: are you measuring delivery against the standards you set, on a schedule, with evidence rather than assurance? And consequence management: when a provider falls short, what actually happens? A framework with no consequence is not oversight, it is hope. Around these three elements sit the red flags that should trigger board intervention: persistent underperformance, regulatory breaches, fee increases nobody can explain, and related-party transactions surfacing without disclosure. Any one of them is a signal that the relationship needs the board’s direct attention, not another quiet quarter. This discipline now has to reach the digital perimeter too. Joint Standard 2 of 2024 addresses cybersecurity and cyber resilience, and Joint Communication 2 of 2025, issued in July 2025, signals the Financial Sector Conduct Authority and Prudential Authority’s intention to develop a Joint Standard on cloud computing and data offshoring. When your administrator stores member data in the cloud or processes it offshore, delegating the technology does not delegate the responsibility for it, and an annual service provider review is the scheduled moment to test every relationship against every standard.

The answering stays with you

Every function a fund outsources still ends at the board’s table. The administrator, the asset manager, the cloud provider three steps removed from the boardroom: the answering always comes back to the board. So the next time someone says a provider is reliable because the fund has used them for years, treat that not as reassurance but as a question. Where is the mandate? Where is the evidence? What happens when they fall short? Reliability is not a reputation. It is something you govern, deliberately and on a schedule. Build that habit, and the June surprise never reaches your members.

Explore BoardEvaluator™

How well does your fund govern its providers?

BoardEvaluator™ gives the principal officer and trustees a structured, evidence-based view of how the fund oversees the providers it depends on - mandate clarity, performance monitoring and consequence management - and a defensible record of the oversight the Pension Funds Act expects.

See the Principal Officer evaluation

Frequently asked questions

Can a retirement fund board delegate its accountability to a service provider?

No. Under King V Principle 7 the board can delegate the function but not the accountability. When it hands work to an administrator, actuary or asset manager, it hands over the doing and keeps the answering, and the standard of oversight it owes does not soften because the work moved outside the fund. Adequate and prudent oversight applies whether a function is performed internally or by a third party.

Who is allowed to administer a pension fund?

Only administrators registered and approved by the regulator under section 13B of the Pension Funds Act. This is not a matter of preference - the board must confirm that a provider holds section 13B approval before it delegates administration to them.

What does prudent oversight of a service provider actually require?

Four things for every provider: a clear mandate so the provider knows what it must deliver; defined performance standards so delivery can be measured rather than assumed; an escalation mechanism so problems surface early; and regular, scheduled review. Contracts must be arms-length and transparent, and the board must satisfy itself that each provider meets applicable fit and proper standards. In practice this reduces to three elements: mandate clarity, performance monitoring and consequence management.

Where do conflicts of interest hide in provider relationships?

In pooled investment vehicles, where fee allocations across funds may not be transparent; in the valuation of illiquid assets, where the valuer may also benefit from the number; and in sponsor-affiliated administrators, where the entity that established the fund also profits from administering it. Each is legitimate in itself, so the board must ensure a conflict of interest policy is both in place and actually followed - which is where independent trustees earn their place.

How does cyber and cloud risk affect a fund’s service provider oversight?

Directly, because so much administration now runs on outsourced technology. Joint Standard 2 of 2024 addresses cybersecurity and cyber resilience, and Joint Communication 2 of 2025 (July 2025) signals the FSCA and Prudential Authority’s intention to develop a Joint Standard on cloud computing and data offshoring. When an administrator stores member data in the cloud or offshore, delegating the technology does not delegate responsibility for it, and the annual service provider review is where the board tests every relationship against every standard.

← Back to Insights