Sections

The Pensions Regulator

Codes of practice

Codes of practice

Code of practice 09
Internal controls

The exercise of judgement

  1. Trustees should, having considered the nature and circumstances of their scheme, decide what internal controls are appropriate to mitigate the key risks they have identified and how best to monitor them. This requires them to exercise judgement, both in assessing the risk profile of the scheme and in designing appropriate controls.
  2. The extent to which the trustees seek professional advice in this area will again be a matter requiring judgement. The regulator would expect advice to be taken when trustees feel they have insufficient knowledge to complete a risk review.

The need to review risks and internal controls

  1. Trustees should be prepared to monitor, challenge and review their risk assessment process and outputs. As referred to above, trustees should also ensure that they can recognise when professional advice is required.
  2. Risk assessment is a continuous process and must take account of a changing environment. It is not simply concluded when an internal control is implemented. Internal controls should be reviewed periodically, at least on an annual basis, or sooner if substantial changes take place, such as a deterioration in funding, change in investment manager, or where a control has been found to be inadequate.

Related documents
Code of practice 09: Internal controls (PDF)
Related pages
Supporting guidance to be read in conjunction with the code: Internal controls guidance