WHEN RETIREMENT FUNDS MEET TECHNOLOGY, WHO OWNS THE RISK?
- RFIN

- 11 minutes ago
- 5 min read

The retirement fund may outsource the technology. It cannot outsource the
responsibility.
It is 22:47 on a Sunday evening. A retirement fund member is sitting at home, using
a member portal on his phone to update his beneficiary nomination.
Traditionally, that process has involved completing, signing and submitting a physical
form. But what if the member could instead complete the entire process through a
secure digital platform that authenticates his identity, records the date and time,
captures an electronic signature and preserves an electronic record?
Years later, the member dies. A dispute arises. One family member produces an
earlier paper nomination form, while another points to the electronic record on the
administrator's system.
The questions may sound technological, but they are fundamentally legal and
governance questions. Who made the change? Did the member genuinely intend to
make it? Can the fund establish exactly what was submitted? Has the record
remained intact? And if something went wrong somewhere between the fund, its
administrator, a software provider, an electronic signature provider and a cloud
provider, who ultimately carries the risk?
The beneficiary nomination is only one example. Technology is now deeply
embedded in retirement fund administration. Member records are maintained
electronically, contributions are processed through administration systems,
information is stored digitally and funds increasingly depend on external technology
providers.
The question is therefore no longer whether retirement funds should embrace
technology. They already have. The more important question is whether governance
has kept pace.
The Financial Institutions and Markets Act, 2021 (Act No. 2 of 2021) (FIMA) provides
an important starting point. Administration services include maintaining and
safeguarding records, contribution administration, claims, benefit payments,
reporting and data management. Data management is therefore not something
separate from retirement fund administration. It is part of it.
FIMA also permits a retirement fund board to appoint a registered fund administrator
and delegate administrative powers, duties and functions. However, section 265
makes an important point: the board is not divested of, or relieved of, the powers,
duties or functions that have been delegated. It must continue to monitor delegated
functions and take remedial action where necessary.
In the digital environment, that means a fund may outsource the technology, but it
cannot outsource accountability.
From Administrator to Cloud Provider
A retirement fund may appoint an administrator. The administrator may use a third-
party platform, which may be hosted by a cloud provider, while cybersecurity,
technical support, electronic authentication and data backups are performed
elsewhere.
By the time the technology chain is complete, the fund may depend on several
entities and systems, some of which it has never directly contracted with.
This is where NAMFISA's outsourcing framework becomes important. GEN.S.10.10
recognises material outsourcing, off-shoring and sub-outsourcing arrangements. The
concern is not simply whether a function has been outsourced, but whether the risks
created by the entire arrangement have been properly identified, managed and
monitored.
The governance question should therefore not stop at, “Who is our service
provider?” It should also ask: Who supports that provider? Where is the information
processed? Who has access to it? And what happens if one part of the chain fails?
Outsourcing may change who performs a function, but it does not remove the need
to govern the risk.
When a System Fails
A technology failure can quickly become a member-protection problem.
If an administration system is unavailable, records may be inaccessible, claims
delayed and benefits affected. A cyber incident can compromise sensitive member
information or undermine the integrity of records on which the fund depends.
FIMA requires fund administrators to maintain proper records and ensure that they
are kept secure and continuously backed up. But having a backup is not necessarily
enough. The real question is whether information can actually be recovered and
whether operations can continue when primary systems fail.
Operational resilience must therefore form part of retirement fund governance. A
disaster recovery plan is of little value if it has never been tested. A business
continuity plan offers little comfort if critical information cannot be accessed during a
prolonged outage.
Cybersecurity should likewise not be treated as a problem belonging exclusively to
IT or an external provider. A cyber incident can quickly become an administration,
governance and legal problem.
“It Is in the Cloud” Is Not a Governance Strategy
Cloud technology may offer significant advantages, but saying that information is “in
the cloud” does not answer the questions that matter.
Where is the information stored? Who has access to it? Are subcontractors
involved? Is information processed outside Namibia? What happens when the
outsourcing relationship ends?
GEN.S.10.10 recognises the importance of managing risks associated with off-
shoring and sub-outsourcing, including access to information and continuity of critical
functions.
Perhaps the most important question is whether the fund could still access its
records and continue operating if its service provider suddenly became unavailable.
If the answer is uncertain, there may already be a governance problem.
Trustees Do Not Need to Be IT Experts But They Cannot Be IT Blind
Technology governance does not require trustees to become software engineers or
cybersecurity specialists. It does, however, require them to understand enough to
exercise meaningful oversight.
Technology should increasingly form part of the board's governance conversation.
Trustees should be asking whether critical systems are secure, whether records can
be recovered, whether disaster recovery arrangements have been tested, whether
cyber incidents are properly reported and whether service providers are being
effectively monitored.
The purpose of governance is not to wait for a system failure and then begin asking
who was responsible. It is to ensure that the right questions are asked before the
failure occurs.
The Paperless Fund Is No Longer a Future Idea
Namibia's Electronic Transactions Act, 2019, is significant in this changing
environment. Section 19 generally recognises that a reference to writing may include
a data message where the information is accessible for subsequent reference.
Section 20, which commenced on 15 June 2026, provides that a reference to a signature may include a recognised electronic signature, subject to the conditions in
the Act.
The Electronic Signature Regulations, 2025 further provide a framework for
electronic signatures. These developments are important in Namibia's transition
towards legally recognised electronic processes. However, retirement funds must still
consider whether the particular transaction, applicable law and fund rules permit a
process to be completed electronically.
The real question is not simply whether a member can click a button. It is whether
the process can establish identity and intention, preserve the integrity of the record
and provide reliable evidence when it is later required.
A properly designed electronic process may, in some circumstances, provide a
stronger evidential trail than paper by recording authentication, the date and time of
the transaction, the information submitted and subsequent changes.
Conclusion
Technology presents significant opportunities for Namibia's retirement fund industry.
It can improve efficiency, accessibility and administration. But it also creates new
dependencies.
The software may belong to one company. The administration system may be
operated by another. The data may be hosted elsewhere. Authentication and
cybersecurity may involve additional providers.
That complexity should never create a gap in accountability.
As retirement funds move from paper to digital processes, the central challenge will
be ensuring that technological convenience does not outpace governance. The most
important question is not simply who owns the technology, but whether the fund has
retained sufficient oversight, access and resilience to protect its members when
something goes wrong.
Because when the system fails, the consequences do not remain with the
technology provider. They come home to the retirement fund.




Comments