Pension schemes need a clearer picture of where artificial intelligence (AI) is being used across their operations and supply chains as adoption accelerates, according to technology firm Penfold.

The provider said schemes should identify AI use across both their own systems and those of third-party providers, with clear accountability for how the technology is governed and how member data is handled.

The call comes as AI use becomes increasingly widespread across the pensions industry. A recent Society of Pension Professionals survey found that 100% of respondents reported using AI, up from 87% in 2025.

“Outsourcing the use of AI does not remove an organisation’s responsibility for appropriate governance and oversight.”

Chris Eastwood, Penfold

AI is being used across areas including administration, member communications, analytics, fraud detection and document processing. The Pensions Regulator has also set out initial expectations for its use, covering governance, transparency, cybersecurity and safeguards for members.

Chris Eastwood, CEO of Penfold, said: “AI isn’t always introduced through a standalone system developed by the scheme itself. Increasingly, it can be embedded within third-party administration, consultancy and communications platforms, making it harder to understand exactly where and how AI is being used.

“Therefore, pension schemes and providers need to be asking the core questions. Where is AI being used across their network, what member data is being accessed, what controls are in place, and how are AI-generated outputs being assessed? Outsourcing the use of AI does not remove an organisation’s responsibility for appropriate governance and oversight.”

Penfold set out a series of steps schemes could take in response, including mapping where AI is used internally and by service providers and defining responsibility for approving and challenging its use.

Schemes should also assess what member and scheme data AI systems can access, process or retain, and ask administrators and technology providers about their governance and testing processes.

The provider also recommended identifying AI-generated outputs that could materially affect members, establishing where human review or intervention is required and putting consistent monitoring in place.

Eastwood said the technology could support fraud detection and operational processes, but could also create risks including AI-generated impersonation and fraud and inappropriate use of member data.

“Schemes shouldn’t avoid AI – the opportunity is significant. But adoption needs to go hand in hand with proper oversight,” he said. “Getting AI governance right now will give the industry the confidence to make greater use of these technologies in future.”