SPP AI Governance Framework: What “Human Oversight” Now Has to Mean
The Society of Pension Professionals’ new framework, Governance in the Age of AI, argues that artificial intelligence needs no new governance regime, only the honest application of duties that already exist. Its most demanding passage is about the people signing things off, and it reaches a long way beyond pensions.

Photo: Pavel Danilyuk / Pexels
Offered a clear opening to invent a new compliance discipline, with its own committees, its own consultants and its own budget line, the pensions industry has declined.
Governance in the Age of AI: A Practical Framework for Responsible Leadership, published on 29 July by the Society of Pension Professionals (SPP), runs against most of what boards are currently being sold. Trustees do not need a new governance discipline for artificial intelligence (AI). They need to apply the duties they already have to a set of facts those duties were not written for. Prudence, accountability, transparency, proportionality, effective risk management and appropriate challenge remain the right principles. What changes is where they have to reach.
The SPP is not a regulator and can compel nobody. What a trade body can do is raise the standard of practice among the firms that administer, advise and invest other people’s retirement money, and do it before a regulator arrives to do it less gently. That is what this paper is for, and the industry it is aimed at is not the only one that should be reading it.
The Pensions Regulator arrived at the same position in its AI Plan of 20 May 2026, stating that trustees “remain accountable for decisions and outcomes even when they delegate activities to providers or advisers”. No new obligation is created. An old one acquires more surface area.
Adoption is no longer experimental. In the SPP’s own 2026 survey, answered by 26 of its 88 corporate members against 32 the year before, every respondent reported using AI, and more than two thirds expect it in up to half of their services. The SPP supplied both response counts to CFI.co on request; neither appears in its published material. “The challenge is therefore not whether AI should be used, but how it can be used safely, transparently and with appropriate oversight,” said Jo Fellowes, chair of the SPP’s administration committee.
The Part That Bites
The framework’s five principles are the expected furniture. The passage worth the read concerns the humans.
Trustees should not assume that nominal human oversight is sufficient, the paper warns, invoking the Information Commissioner’s Office (ICO), whose draft guidance on automated decision-making went to consultation on 31 March. Its test for “meaningful human involvement” is unusually concrete. The reviewer must be trained to understand the system’s logic, outputs, limitations and risks; must hold the authority and the information to reach a different conclusion rather than endorse the machine’s; must review while the decision can still be changed; and must do it every time, because spot checks leave the rest unchecked.
Read that from the supplier’s side of the table and it becomes a test of a very common sentence. A great many organisations say they keep a human in the loop. Rather fewer could demonstrate that the human had the standing, the information and the time to overrule the machine, on every item, before anything left the building. A name at the end of a workflow is not oversight. It is a signature.
Asked whether current administrator and adviser practice would satisfy those criteria, the SPP does not claim that it would. “Trustees and the industry are still getting to grips with AI uses, and how to govern those uses, so there has not been enough challenge of administrators and advisers to date, to understand exactly what practices they have in place, and whether these would satisfy the ICO draft criteria,” Fellowes told CFI.co. The framework was published partly for that reason.
The people best placed to know whether the humans in the loop are real say the question has not yet been put hard enough to find out.
The scope is narrower than the principle. The guidance is still in draft, and bites only on decisions with legal or similarly significant effects, so a team drafting marketing copy is not in the frame. Anything determining what a particular person receives is: a benefit calculation made without human review, a pension suspended on suspicion of fraud. The paper concludes that automated decision-making is unlikely to be appropriate at all for ill-health cases, where health data, medical judgement and a life-changing outcome arrive together.
What to Be Sceptical About
The authority here is borrowed: every hard edge comes from the regulator, the ICO, the Financial Conduct Authority or the Five Eyes agencies, and anyone acting on it should go to those sources rather than the summary. The survey is the weakest evidence in the document, and the document does not need it. One respondent is worth nearly four percentage points, so figures quoted to the nearest whole per cent carry a precision the sample cannot support, and the two years are not the same sample. It is a directional signal, not a measurement.
The SPP describes the result as universal adoption across the industry, and it is very likely right. AI now arrives inside software firms already own, whether or not anyone went looking for it. But being right and having demonstrated it are different things, and this survey does the first rather than the second.
There is a structural point too. The framework asks for registers, audit trails, assurance reports and validation records, all of it private and seen only by the party that commissioned it. Put to the SPP, that draws a line rather than a refusal. Those records “would likely remain private to the trustee board to protect commercial confidentiality, cyber security, and member data privacy”, Fellowes said, but the SPP “would support publishing risk warnings, and in particular, informing members how AI is being used in financial decision making, to help protect them against AI driven scams and misinformation”.
The second half is the more consequential, and it is not yet in the paper. Members have already gone around everybody, using public AI tools to interpret their own benefits, tools that sometimes answer using another scheme’s information. The paper’s remedy is to publish better material so the machines have the right thing to read. The unsolved problem is not what your own AI does, but the accuracy of what other people’s AI says about you.
What the Rest of Finance Should Take from It
Almost nothing in this framework is specific to pensions. Its risk tiers sort AI by what happens if the output is wrong rather than by how the technology works, which is an exercise any organisation can run this week. Its contracting provisions, requiring providers to disclose what AI they use, what data it touches, which outputs a human reviews and which sub-processors sit behind them, are arriving across financial services generally, and most appointments predate generative AI. And its test of meaningful human involvement should concern anyone who has assured a client, a board or a regulator that there is a human in the loop.
It also stops one step short, and the step it stops short of is the one arriving fastest. The ICO’s test governs decisions about an individual. An agent that reconciles data, initiates a rebalancing or triggers a payment run decides nothing about any particular person, and so sits outside that frame while doing work which until recently required somebody accountable to do it. The paper notices such systems only in passing. Enterprise IT has been arguing the point for a year, in identity governance, where agents are given owners, risk tiers and revocable credentials on the workforce model. Fiduciary governance has not caught up. CFI.co’s view is that an AI agent operating inside an organisation should be tied to the same governance framework as the person whose work it took over: a defined mandate, a named owner, a record of what it did and why, and somebody with the standing to stop it.
The SPP has said the existing duties were always broad enough to cover this. That is almost certainly right, and it leaves the harder question standing, one the SPP has put more plainly than anyone else was going to. If the duties have not changed and the practice obviously has, how much of what currently passes for human oversight would survive being described precisely?
Sources
Society of Pension Professionals, Governance in the Age of AI: A Practical Framework for Responsible Leadership, published 29 July 2026: the-spp.co.uk/document/spp-guide-governance-in-the-age-of-ai-a-practical-framework-for-responsible-leadership/
Society of Pension Professionals, SPP 2026 AI Survey, April 2026 (response counts supplied to CFI.co directly): the-spp.co.uk
The Pensions Regulator, AI Plan, 20 May 2026: thepensionsregulator.gov.uk
Information Commissioner’s Office, consultation on draft guidance on automated decision-making, including profiling, opened 31 March 2026 and closed 29 May 2026: ico.org.uk
Five Eyes cyber security agencies, The AI shift in cyber risk: why leaders must act now, 22 June 2026: ncsc.gov.uk
Financial Conduct Authority, Perimeter Report, 26 March 2026: fca.org.uk
You may have an interest in also reading…
Boards and AI: From Oversight to Insight
How AI can improve the effectiveness of boards THE SHORT VERSION AI is now supporting boards to do their work.
Accenture: The Evolving Role of CEOs in Mitigating Cybersecurity Threats
In 2023, a complex, fragmented global geopolitical backdrop prompted a boost in the cybersecurity economy. It was propelled by the
Ten Recent Technology Advances That Asset Allocators Should Have on the Radar
A CFI.co briefing on the engineering breakthroughs, grid innovations and early deployments that are compressing cost curves and reshaping the










































































