On 9 December 2025, The Pensions Regulator (‘’TPR’’) published revised guidance on the administration of pension schemes in the UK. The guidance is aimed at pension schemes, and clarifies TPR’s expectations for trustees, scheme managers and administrators across all scheme types, including new guidance on cyber risk. While administration has historically been viewed as a supporting or back-office function, this guidance marks a regulatory shift: administration is now considered a core driver of good outcomes for savers. In this blog, we look at what this means for trustees and administrators in practice.

Background to the guidance – from market oversight to formal guidance

The publication of this guidance follows on from TPR’s market oversight report on administrator relationships, published on 11 September 2025, which we discuss in more detail in our previous blog here. The report highlighted progress and challenges across the market, including governance, technology, data quality and cyber resilience, and signalled that further regulatory clarification would follow.

This guidance is the next step in TPR’s revised administration strategy and formalises TPR’s expectations based on the market insight and research. The guidance reinforces TPR’s administration expectations in its General Code of Practice.

What trustees, scheme managers and administrators should focus on

The guidance is detailed, but some of the key points emerging from the guidance for trustees, scheme managers and administrators are as follows:

  • Trustees and scheme managers remain accountable. This is true even where day-to-day administration is delegated. Trustees and scheme managers retain responsibility at all times and must hold and maintain sufficient knowledge and understanding of administration processes, keep up to date with relevant developments and best practice, understand the scope and suitability of their administrator’s tasks and responsibilities; and actively oversee performance resourcing and risk management.
  • A written administration policy must be prepared. This must enable the proper planning and maintenance of scheme administration. This should align cover the objectives and scope of administration, the roles and responsibilities of trustees, governing bodies, administrators, employees and other relevant individuals, reporting and monitoring practices, and management of administration risks. This should align with the wider scheme strategy to ensure scheme objectives can be delivered effectively.
  • Cyber resilience and IT systems must be understood and scrutinised. Trustees and scheme managers must understand what IT systems the scheme is using and how data flows between systems. Trustees and scheme managers must seek evidence from administrators that their IT systems, available hardware, software and personnel resources are adequate the meet the scheme’s operational and legal requirements. There must be an appropriate level of governance of the administrator’s technology. This includes having a good understanding of the scheme’s cyber resilience and security. TPR has published guidance on the cyber security principles it expects to be applied to pension schemes, which we recap below.
  • Communications with members must be timely, accurate, and personalised communications. This applies to all communications, including digital and alternative formats for those with specific needs. Trustees and scheme managers should monitor feedback, complaints, and engagement to improve the member experience.
  • Contributions from employers and members, and benefit payments, must be collected, monitored and processed promptly and accurately. Trustees and scheme managers should ensure that appropriate controls, reconciliation, and authorisation processes are in place. Any issues or weaknesses in the administrator should be scrutinised to maintain efficiency.
  • Disaster recovery and business continuity must be tested and secure. Trustees and scheme managers must ensure that administrators can maintain services during disruption periods, including cyber incidents, system failures, in the absence of key individuals or due to staffing issues, or due to supplier issues. This will involve understanding how administrators anticipate, plan for and mitigate potential disruption. Plans should be reviewed annually to reflect any changes in key staff, scheme strategy, or the system, and to cover any emerging types of incidents, and should be rested with realistic scenarios.

A recap of TPR’s cyber security expectations

Given the focus on cyber resilience in the revised administrator guidance, trustees, scheme managers and administrators should also be aware of TPR’s guidance on cyber security principles for pension schemes, which can be accessed here. This guidance focuses on cyber risk generally and sits alongside the specific obligations that trustees, scheme managers and administrators have in relation to personal data under data protection law, including obligations on schemes in relation to the appointment of third party administrators.

TPR originally published this guidance on 11 April 2018 and updated it on 11 December 2023 [MAS1] [JB2] to reflect best practice approaches to managing cyber risk, including when to report cyber incidents to TPR. The administration guidance provides a further update.

Some of the key points set out in TPR’s cyber security guidance for trustees, scheme managers and administrators are as follows:

  • Trustees and scheme managers remain accountable for the security of scheme data and assets, even when day-to-day tasks are delegated and administrators or third-party providers handle systems.
  • The scheme’s cyber footprint must be understood by identifying the digital presence of all parties involved in the scheme, critical functions, data holders, and the potential operational, financial, or reputation impacts of cyber incidents.
  • There must be collaboration across the scheme and supply chain, and administrators, suppliers, and service providers must all have effective cyber controls.
  • Preventative measures must be taken, including through training staff and trustees on cyber risks, phishing, and secure device and email use.
  • Technical controls must be implemented to ensure resilience and security, for example, multi-factor authentication, access controls, firewalls and vulnerability testing.
  • Critical systems and data must be backed up regularly to minimise the risk of data loss.
  • Continuous monitoring must take place for incidents, and processes to detect, report and address cyber risks of breaches should be implemented.
  • A documented and tested plan must be prepared to handle any incident responses, setting out roles, escalation procedures, system shutdowns, and recovery priorities.
  • Significant cyber incidents must be reported to TPR (in addition to reporting obligations to the ICO under UK data protection law).

Next steps for trustees, scheme managers and administrators

Trustees, scheme managers and administrators should take steps to ensure their schemes meet TPR’s updated regulatory expectations. Immediate steps that should be taken include setting out objectives, roles, reporting lines and risk management, and aligning with the scheme’s wider strategy.

Importantly, IT systems should be reviewed to determine that systems, data flows, and security controls are adequate. We recommend trustees and scheme managers use TPR’s cyber security guidance as a benchmark to ensure compliance and that they have the resource and expertise to review and assess responses provided by third party administrators..

Furthermore, a clear disaster recovery and business continuity plan should be maintained and regularly reviewed, covering realistic disruption scenarios such as cyber incidents, system failures, staffing issues, or supplier interruptions. This will require collaboration between trustees, scheme managers and administrators to identify who is responsible for which aspect of business continuity and how different plans interact.

Trustees and scheme managers will want to ensure that cyber risk and business continuity is properly addressed in the contracts that they have in place with third party administrators.

Ongoing performance monitoring and reporting are essential, and trustees and scheme managers must hold themselves and administrators accountable to challenge performance where needed, and ensure that governance, controls, and processes are regularly reviewed and appropriate.

If you would like to discuss any of the issues raised in this blog, please contact a Juliet Bayne, Martin Sloan, or your usual Brodies contact.

Contributors

Juliet Bayne

Partner

Ellie McWilliams

Senior Solicitor

Ussamah Nasar

Senior Solicitor

Martin Sloan

Partner