A framework is not a control. Somebody has to run it.
AI Governance, fractional CAIO, AI program office, ~5 min read
There is a moment that arrives a few weeks after a good governance document lands on your desk. You have read it. You agree with all of it. The five principles are sensible, the risk tiers make sense, and you cannot name a single person whose job it is to do any of it by Friday.
That moment is where most AI governance programs quietly stop.
On 29 July the Society of Pension Professionals published Governance in the Age of AI: A Practical Framework for Responsible Leadership, aimed at pension scheme trustees and the advisers and administrators who serve them. Finextra covered the launch the same week. If you do not work in pensions, read it anyway. Almost nothing in it is specific to pensions, and the argument it makes is the one every department head is about to have.
What the pensions industry actually said
The paper’s central claim is refreshingly unglamorous: AI does not need a new governance regime. It needs the duties that already exist, applied to facts those duties were not written for.
Trustees already owe a duty of prudence. They already have risk registers, service provider oversight, internal controls, and cyber and data governance frameworks. The SPP’s position is that AI belongs inside all of those, not in a separate binder next to them. The framework sets out five principles: transparency, accountability, proportionality to risk, security by design, and meaningful human oversight. It recommends classifying every AI use as low, medium, or high risk, and keeping an AI register that records current use cases, who owns each one, how it was approved, how often it is reviewed, and what gets reported to the board.
The urgency is in the adoption curve. The SPP’s own annual surveys found 87% of pension firms using AI in 2025 and 100% in 2026, as Pensions Age reported. Jo Fellowes, who chairs the SPP’s administration committee, framed it this way: “The challenge is therefore not whether AI should be used, but how it can be used safely, transparently and with appropriate oversight.”
The Pensions Regulator reached the same place in its AI Plan of 20 May 2026, stating that trustees remain accountable for decisions and outcomes even when they delegate activities to providers or advisers. No new obligation was created. An existing one grew a much larger surface area.
The gap between a principle and a control
Here is where the paper gets uncomfortable, and where it earns the attention of anyone outside pensions.
“Meaningful human oversight” is the principle everyone signs. It is also the one almost nobody can currently evidence. The SPP invokes the Information Commissioner’s Office, whose draft guidance on automated decision-making went to consultation on 31 March, and the ICO’s test for meaningful human involvement is unusually concrete. The reviewer has to be trained to understand the system’s logic, outputs, limits, and risks. They have to hold the authority and the information to reach a different conclusion, not merely endorse the machine’s. They have to review while the decision can still be changed. And they have to do it every time, because spot checks leave everything else unchecked.
Asked by CFI.co whether current administrator and adviser practice would satisfy those criteria, the SPP declined to claim it would. Fellowes said trustees and the industry are still getting to grips with AI uses and how to govern them, so there has not been enough challenge of administrators and advisers to understand what practices they actually have in place.
That is an unusually honest answer from a trade body, and it names the real problem. The distance between writing “a human reviews the output” in a policy and being able to prove it under questioning is enormous. It is filled with people, calendars, tooling, records, and someone senior enough to say no.
Who owns this on Monday
Every organization I talk to about AI governance is somewhere on the same three-step path, whether they run a pension scheme or a 60-person manufacturer.
They write the policy. That part is fast, and increasingly there is a good published framework to start from, which is exactly what the SPP has just given the pensions industry for free.
Then they discover the policy describes an operating model nobody is operating. There is no register, because building one means asking eleven departments what they are actually using and getting honest answers. There is no risk tiering, because tiering requires someone with the standing to tell a director their favorite tool is high risk. There is no evidence trail, because nobody specified what evidence looks like before the systems went live.
Then they either staff it or they do not. Staffing it properly means a Chief AI Officer, and for most mid-market organizations that role is real but not full-time. That is the gap Modular Technology Group’s fractional CAIO practice exists to fill: an executive who owns the AI program, writes and maintains the policy, runs the AI register and the sanctioned tool list, tiers the use cases, sets the review cadence, and shows up to the board meeting with the reporting the framework asks for. An AI Program Office behind that keeps the artifacts current between meetings, because a register that is six months stale is worse than none, since it looks like control.
The framework tells you what good looks like. It does not tell you who does it, and it cannot. That part is an org chart decision, and it is the only part that changes anything.
Your data, your rules, and that includes the AI working on it
Your AI, your rules. Not the vendor’s rules, not the model provider’s terms of service, and not a control that exists in a document and nowhere else.
Ask the three questions the SPP is really asking. Where is AI being used across your operation right now, including the parts nobody approved? Who is accountable for each of those uses by name? If a regulator, a client, or your own board asked you to reconstruct why an AI-assisted decision came out the way it did, could you?
If the answers are uncomfortable, you are in normal company. The SPP just told an entire industry the same thing in writing. The organizations that come out of this well will be the ones that treated the framework as a starting position rather than a finished deliverable, and put a name next to every line of it.