top of page

WHEN RETIREMENT FUNDS MEET TECHNOLOGY, WHO OWNS THE RISK?

  • Writer: RFIN
    RFIN
  • 11 minutes ago
  • 5 min read

The retirement fund may outsource the technology. It cannot outsource the

responsibility.

It is 22:47 on a Sunday evening. A retirement fund member is sitting at home, using

a member portal on his phone to update his beneficiary nomination.


Traditionally, that process has involved completing, signing and submitting a physical

form. But what if the member could instead complete the entire process through a

secure digital platform that authenticates his identity, records the date and time,

captures an electronic signature and preserves an electronic record?


Years later, the member dies. A dispute arises. One family member produces an

earlier paper nomination form, while another points to the electronic record on the

administrator's system.


The questions may sound technological, but they are fundamentally legal and

governance questions. Who made the change? Did the member genuinely intend to

make it? Can the fund establish exactly what was submitted? Has the record

remained intact? And if something went wrong somewhere between the fund, its

administrator, a software provider, an electronic signature provider and a cloud

provider, who ultimately carries the risk?


The beneficiary nomination is only one example. Technology is now deeply

embedded in retirement fund administration. Member records are maintained

electronically, contributions are processed through administration systems,

information is stored digitally and funds increasingly depend on external technology

providers.


The question is therefore no longer whether retirement funds should embrace

technology. They already have. The more important question is whether governance

has kept pace.


The Financial Institutions and Markets Act, 2021 (Act No. 2 of 2021) (FIMA) provides

an important starting point. Administration services include maintaining and

safeguarding records, contribution administration, claims, benefit payments,

reporting and data management. Data management is therefore not something

separate from retirement fund administration. It is part of it.


FIMA also permits a retirement fund board to appoint a registered fund administrator

and delegate administrative powers, duties and functions. However, section 265

makes an important point: the board is not divested of, or relieved of, the powers,

duties or functions that have been delegated. It must continue to monitor delegated

functions and take remedial action where necessary.


In the digital environment, that means a fund may outsource the technology, but it

cannot outsource accountability.


From Administrator to Cloud Provider

A retirement fund may appoint an administrator. The administrator may use a third-

party platform, which may be hosted by a cloud provider, while cybersecurity,

technical support, electronic authentication and data backups are performed

elsewhere.


By the time the technology chain is complete, the fund may depend on several

entities and systems, some of which it has never directly contracted with.

This is where NAMFISA's outsourcing framework becomes important. GEN.S.10.10

recognises material outsourcing, off-shoring and sub-outsourcing arrangements. The

concern is not simply whether a function has been outsourced, but whether the risks

created by the entire arrangement have been properly identified, managed and

monitored.


The governance question should therefore not stop at, “Who is our service

provider?” It should also ask: Who supports that provider? Where is the information

processed? Who has access to it? And what happens if one part of the chain fails?

Outsourcing may change who performs a function, but it does not remove the need

to govern the risk.


When a System Fails

A technology failure can quickly become a member-protection problem.

If an administration system is unavailable, records may be inaccessible, claims

delayed and benefits affected. A cyber incident can compromise sensitive member

information or undermine the integrity of records on which the fund depends.


FIMA requires fund administrators to maintain proper records and ensure that they

are kept secure and continuously backed up. But having a backup is not necessarily

enough. The real question is whether information can actually be recovered and

whether operations can continue when primary systems fail.


Operational resilience must therefore form part of retirement fund governance. A

disaster recovery plan is of little value if it has never been tested. A business

continuity plan offers little comfort if critical information cannot be accessed during a

prolonged outage.


Cybersecurity should likewise not be treated as a problem belonging exclusively to

IT or an external provider. A cyber incident can quickly become an administration,

governance and legal problem.


“It Is in the Cloud” Is Not a Governance Strategy

Cloud technology may offer significant advantages, but saying that information is “in

the cloud” does not answer the questions that matter.


Where is the information stored? Who has access to it? Are subcontractors

involved? Is information processed outside Namibia? What happens when the

outsourcing relationship ends?


GEN.S.10.10 recognises the importance of managing risks associated with off-

shoring and sub-outsourcing, including access to information and continuity of critical

functions.


Perhaps the most important question is whether the fund could still access its

records and continue operating if its service provider suddenly became unavailable.

If the answer is uncertain, there may already be a governance problem.


Trustees Do Not Need to Be IT Experts But They Cannot Be IT Blind

Technology governance does not require trustees to become software engineers or

cybersecurity specialists. It does, however, require them to understand enough to

exercise meaningful oversight.


Technology should increasingly form part of the board's governance conversation.

Trustees should be asking whether critical systems are secure, whether records can

be recovered, whether disaster recovery arrangements have been tested, whether

cyber incidents are properly reported and whether service providers are being

effectively monitored.


The purpose of governance is not to wait for a system failure and then begin asking

who was responsible. It is to ensure that the right questions are asked before the

failure occurs.


The Paperless Fund Is No Longer a Future Idea

Namibia's Electronic Transactions Act, 2019, is significant in this changing

environment. Section 19 generally recognises that a reference to writing may include

a data message where the information is accessible for subsequent reference.

Section 20, which commenced on 15 June 2026, provides that a reference to a signature may include a recognised electronic signature, subject to the conditions in

the Act.


The Electronic Signature Regulations, 2025 further provide a framework for

electronic signatures. These developments are important in Namibia's transition

towards legally recognised electronic processes. However, retirement funds must still

consider whether the particular transaction, applicable law and fund rules permit a

process to be completed electronically.


The real question is not simply whether a member can click a button. It is whether

the process can establish identity and intention, preserve the integrity of the record

and provide reliable evidence when it is later required.


A properly designed electronic process may, in some circumstances, provide a

stronger evidential trail than paper by recording authentication, the date and time of

the transaction, the information submitted and subsequent changes.


Conclusion

Technology presents significant opportunities for Namibia's retirement fund industry.

It can improve efficiency, accessibility and administration. But it also creates new

dependencies.


The software may belong to one company. The administration system may be

operated by another. The data may be hosted elsewhere. Authentication and

cybersecurity may involve additional providers.


That complexity should never create a gap in accountability.


As retirement funds move from paper to digital processes, the central challenge will

be ensuring that technological convenience does not outpace governance. The most

important question is not simply who owns the technology, but whether the fund has

retained sufficient oversight, access and resilience to protect its members when

something goes wrong.


Because when the system fails, the consequences do not remain with the

technology provider. They come home to the retirement fund.

Comments


bottom of page