At a glance
- Ways to elevate governance standards
- The role of enterprise risk management and its benefits
- The responsibilities of trustees
- Key takeaways
The rapid advancement of technology and continuous changes in regulations have increased risks and threats for pension and benefits plans. As a result, the importance of strong governance cannot be overstated.
The industry now expects those charged with governance (TCWG) to be more involved. As a result, it’s crucial that these plans are managed with the utmost diligence and that appropriate documentation supports the involvement of TCWG. This is where enterprise risk management (ERM) plays a critical role.
Elevating governance standards
Although the core fiduciary obligations of TCWG have remained the same, the industry has become more complex. Therefore, it’s necessary to implement additional risk assessments as well as put processes and controls in place for areas such as financial reporting, regulatory compliance, and managing the plan’s viability.
While TCWG may call upon third-party service providers to assist with the execution process, the requirement to validate the consistent application of processes and controls in the risk management process cannot be transferred. This results in a heightened level of involvement from TCWG for maintaining the trust and confidence of plan participants and stakeholders.
Here’s what should be considered when evaluating a third-party service provider’s risks and controls:
Conduct due diligence
- Evaluate the provider’s reputation by checking references, their industry standing, and track record regarding regulatory compliance.
- Ask for audited financial statements and review credit ratings to determine their financial stability.
- Check that the provider has adequate resources, staff, and experience with similar plans.
Contractual safeguards
- Specify which tasks will be performed by the provider and which ones will continue to be managed by the trustee.
- Create key performance indicators (KPIs) and service level agreements (SLAs) to define performance standards.
- Ensure trustees are able to audit provider operations and controls directly or through third-party reports.
Risk assessment and control evaluation
- Request and review independent reports on the provider’s internal controls.
- Examine policies related to data encryption, access controls, incident response procedures, and adherence to regulatory compliance.
- Check if the provider has business continuity plans in case of disruption.
Continuous monitoring
- Review SLAs, KPIs, and incident reports regularly.
- Re-evaluate providers’ risks and controls every year or when significant changes occur.
- Check if the provider is still complying with privacy laws and pension regulations.
Incident management and reporting
- Providers should notify trustees immediately of any breaches, errors or regulatory issues.
- Define how incidents are managed, investigated, and resolved.
Termination and transition planning
- Ensure contracts include provisions for data return, transition support, and continuity of service if the provider relationship ends.
Creating clear procedures for engaging, overseeing, and transitioning third-party service providers is essential for effective risk management and strong governance.
Also, the foundation for robust governance is an internal audit. Its main role is to give TCWG independent assurance regarding the effectiveness of internal controls, compliance processes, and risk management.
The benefits include:
An internal audit gives trustees objective assurance that processes are effective and comply with regulations. Boards must ensure the internal audit function is autonomous, that it has the proper resources, it’s integrated into the governance framework, and reports directly to TCWG.
The Role of ERM
ERM helps identify, estimate, and manage risks that might affect the achievement of an organization’s goals. ERM is essential for employee benefits plans when attempting to ensure possible risks are proactively mitigated and managed.
Boards can improve their ability to make informed decisions to protect plans’ long-term sustainability by integrating ERM into the governance framework.
ERM benefits include:
Improving documentation and validation
A fundamental component of strong governance is the ability to validate the decisions made by TCWG. Here are some ways to enhance documentation and ensure validation:
Trustees’ responsibilities
Trustees must be more active in pension and benefits plans governance as regulatory requirements and risks keep evolving. This active role is necessary in order for plans to be managed to highest standards. The integration of ERM can help trustees improve their ability to find, assess, and mitigate risks, which will make the plans more sustainable.
Actively participating in risk management improves decision-making while also encouraging transparency and trust with stakeholders. This approach helps trustees meet their fiduciary duties and allows them to maintain confidence with plan participants and other stakeholders.
Key takeaways
- Strong governance is fundamental to the success of pension and benefits plans. Trustees must be actively engaged as the risk and regulatory landscape changes.
- Boards can meet their fiduciary duties and safeguard the interests of plan members by involving stakeholders, using new technology, and prioritizing continuous improvement.
- If third-party service providers have deficient controls, it can compromise data integrity, financial reporting, and participant confidence, which may result in regulatory breaches or reputational damage.
- Integrating ERM into the governance framework can help boards make better-informed decisions that improve processes and controls while also protecting the long-term sustainability of plans.
How we can help
It’s important for pension and benefits plans to implement good governance practices. Our industry-focused teams have extensive experience assessing processes and controls in an employee benefit plan environment. If you would like assistance in developing risk management and governance processes or would like to perform testing on existing processes and controls, please contact us.