top of page
Digital Sphere Design
Search

Are Retirement Funds Being Given a False Sense of Comfort?

  • wynand83
  • Jan 27
  • 3 min read

Every retirement fund Board receives assurance.


The real question is whether that assurance deserves to be trusted.

Across the retirement fund industry, governing bodies are inundated with reports, questionnaires, certifications, attestations, audit opinions, policies, presentations, and management representations from the service providers that support critical fund operations. Administrators provide updates, custodians submit reports, investment managers furnish attestations, technology providers present certifications, consultants offer opinions, and auditors deliver assurance.


On the surface, this appears reassuring. Retirement funds have access to more information, more documentation, and more assurance artefacts than ever before.

Yet despite this abundance of assurance, an uncomfortable reality persists.

Major organisations continue to experience cyber incidents. Sensitive information continues to be exposed. Operational disruptions continue to occur. Third-party failures continue to impact organisations that believed they had appropriate oversight and sufficient assurance over their service providers.


This raises a question that few governing bodies openly ask:

If organisations are receiving so much assurance, why do significant failures continue to occur?

Perhaps the answer is simpler than we would like to admit.

The retirement fund industry has become exceptionally good at collecting assurance. Whether it has become equally effective at evaluating and challenging that assurance is a different matter entirely.

For many organisations, assurance has evolved into a well-established process. Questionnaires are distributed. Responses are received. Evidence is reviewed. Findings are documented. Reports are tabled. The exercise is completed until the next review cycle begins.

The process creates comfort.

But does it create confidence?

There is an important distinction between the two.

Comfort is often generated by activity. Confidence is generated by understanding.


A Board can receive hundreds of pages of assurance documentation and still struggle to answer a fundamental governance question:


How much confidence should we actually place in this service provider?


In an era of increasing outsourcing, that question has never been more important.

Modern retirement funds operate within highly interconnected ecosystems. Critical services such as administration, investment management, custody, member communication, technology operations, cloud services, and data processing are increasingly delivered by third parties. In many cases, some of the most critical functions supporting members are performed by organisations operating outside the direct control of the fund itself.

Yet when incidents occur, regulators, members, and stakeholders seldom distinguish between internal failures and outsourced failures.

The expectation remains unchanged.

The governing body must demonstrate effective oversight.

This is where the assurance challenge begins.

Many assurance activities focus on whether information has been provided. Far fewer focus on whether that information genuinely supports confidence.


For example, does the completion of a questionnaire automatically provide meaningful assurance? Does possession of a certification necessarily indicate resilience? Does the existence of a policy prove that controls are operating effectively? Should a self-assessment carry the same weight as independently validated assurance? Can two service providers truly be compared when each submits entirely different forms of evidence?

These questions rarely feature prominently within traditional assurance discussions.

Yet they strike at the heart of effective governance.


The reality is that not all assurance evidence is equal. Not all control environments are equally mature. Not all service providers present the same level of risk. And not all assurance mechanisms deserve the same degree of reliance.

This becomes particularly relevant as cybersecurity threats continue to evolve, regulatory expectations mature, and dependence on third parties increases. Governing bodies are expected to oversee increasingly complex operational environments while making decisions based on assurance information that often varies significantly in quality, depth, and evidentiary value.

Against this backdrop, retirement funds may need to reconsider a long-standing assumption:


Does more assurance automatically result in better oversight?


The answer may not be as straightforward as many believe.

Perhaps the future of assurance is not about collecting more information. Perhaps it is about obtaining greater clarity regarding the information already being received.

Perhaps the focus should shift from measuring the volume of assurance to understanding the confidence that assurance should create.

Because ultimately, the responsibility of a governing body is not to collect assurance.

It is to determine whether that assurance justifies confidence.


And those are two very different things.


The retirement funds that recognise this distinction early may find themselves asking very different questions in the years ahead. Questions that move beyond compliance checklists and documentation reviews. Questions that challenge traditional assumptions about oversight. Questions that seek to understand not merely whether assurance exists, but whether that assurance is sufficient to support informed governance decisions.

The most important question of all may therefore be the simplest:


Is the confidence being placed in critical service providers truly earned, or merely assumed?



Recent Posts

See All

Comments


bottom of page