The Barnet Pension Fund is exposed to significant risks including potential cyber security breaches and failures by strategic suppliers, according to an updated risk register. The register, which consolidates previous administration and governance risk registers into a single document, details 26 strategic and operational risks facing the fund. While most are assessed as low to moderate after mitigation measures, several remain a key focus for officers.

Among the highest residual risks are:
- Cyber security breaches: The risk of cyber-attack, fraud, or unauthorised access to pension data could lead to service disruption, regulatory sanctions, and reputational damage. Ongoing cyber security assurance measures are being implemented, with a target date of 31 December 2026 for continued monitoring and annual review of cyber security reports. The effectiveness is assessed through regular cyber reviews by WYPF and periodic security assurance reviews. The potential financial impact of a cyber security breach is assessed as £500,000 - £1,000,000.
- Strategic supplier failures: A failure by key suppliers, advisers, or third-party providers could result in operational disruption and increased costs. The potential financial impact of such failures is estimated between £100,000 and £500,000, primarily due to the costs associated with replacing the supplier.
- Business continuity and operational resilience: The risk that critical pension services cannot be maintained following a major disruptive event. Contingency plans include a Corporate Business Continuity Plan, IT disaster recovery arrangements, cloud-based and backed-up systems, flexible and remote-working arrangements, documented procedures, supplier resilience monitoring, periodic continuity testing, and management oversight and incident escalation procedures. The potential financial impact is assessed as £100,000 - £500,000 in increased operational costs.
- Employer contributions: The risk of employers failing to pay correct contributions in a timely manner, creating funding and cash flow pressures. This could lead to funding deficits increasing, cash flow pressures on the Fund, additional monitoring and enforcement activity, and potential regulatory breaches. The financial impact is assessed as £500,000 - £1,000,000.
- GDPR compliance: The risk of data breaches and associated regulatory action. The meeting documents detail several high residual risks, with financial impacts outlined for some. For instance, failure to effectively manage supplier costs could result in excessive fund expenditure, reduced net investment returns, poor value for money, increased administration costs, and budget pressures. The financial impact is assessed as £100,000 - £500,000 for service delivery disruption, and £10,000 - £100,000 for financial impact.

Mitigation activities underway include enhanced data quality monitoring, succession planning, regular review of strategic suppliers, and ongoing cyber security assurance.
The Pension Fund Committee noted the updated risk register and was invited to provide feedback on its format, content, and operation to assist officers in its ongoing development and refinement. The committee's discussions and feedback can be found in the Public reports pack 14th Sep 2026, and the agenda frontsheet is available here. The minutes of the previous meeting are also available here.
