Tower Hamlets Pension Board convened on Monday, July 20, 2026, to address a range of critical issues, with a significant focus on enhancing the fund's resilience against escalating cyber security threats.

The board reviewed the Pension Fund Risk Register, identifying increasing cyber security threats as a key strategic risk. The potential consequences of such incidents include data breaches, ransomware attacks, service disruption, financial loss, regulatory sanctions, and reputational damage.

This concern was echoed in the discussion of the Pension Board's annual report, which highlighted the need for robust governance and administration in the face of evolving challenges. Several enhancements were discussed to address identified risks. In terms of governance, these included the introduction of statutory roles such as the Senior LGPS Officer and the Independent Person , requirements for Independent Governance Reviews , revised governance requirements, and an emphasis on training and development for new committee members. Administration enhancements involved the implementation of a Pensions Administration Strategy (PAS) , the transition from the Member Self-Service (MSS) system to the new 'Engage' system , an ongoing data cleanse project to improve data quality, addressing backlogs in the pensions administration service , and the recruitment of Trainee Pension Officers due to difficulties in attracting experienced administrators.

In a comprehensive discussion of the Pension Fund Risk Register, board members noted emerging strategic risks associated with the implementation of the LGPS Regulations 2026. These reforms, including the LGPS (Pooling, Management and Investment of Funds) Regulations 2026, introduce new responsibilities and risks for administering authorities, pension committees, local pension boards, and investment pools. Specific risks highlighted include non-compliance with statutory requirements, insufficient knowledge and skills, delays in implementing constitutional changes, insufficient governance capacity, and ineffective decision-making.

The board also discussed the renewal of critical technology systems. The Pensions Administration system's contract expires on October 31, 2026, while the Corporate Financial Management system's contract expires in December 2026, with a three-year extension to December 2029 currently being negotiated. The HR/Payroll system, which supports pensioner payroll, has a contract expiry in February 2028. Potential risks associated with the replacement of these systems include service disruption, increased costs, regulatory breaches, and reputational damage.

The meeting's agenda and public reports pack can be accessed online: Agenda frontsheet 20th Jul 2026 and Public reports pack 20th Jul 2026.