Skip to main content Scroll Top

Joint Standard: What is expected of trustees?

IN A NUTSHELL: Trustees aren’t expected to become cybersecurity experts themselves. However, the board should oversee the implementation of the Joint Standard, working with qualified cybersecurity professionals. Ultimately, trustees remain responsible for safeguarding members’ savings, which includes managing the risks associated with cyber threats.

There’s a new kind of criminal targeting financial institutions across the world: cybercriminals. And retirement funds are no exception.

Why are cybercriminals targeting retirement funds? Because these funds hold a lot of money and personal information – like members’ ID numbers, contact details, and bank account numbers. One successful hack could cause massive financial losses, serious disruptions to the day-to-day operations and reputational damage to your fund.

What is a hack? A “hack” is an informal word for a cyberattack. This happens when a cybercriminal gains unauthorised access to a computer system — like a digital break-in. A successful hack can lead to criminals accessing members’ private information or even fraud involving members’ funds.

A new rulebook for cybersecurity

To address the rising threat and impact of cybercrime, the Financial Sector Conduct Authority (FSCA) and the Prudential Authority (PA) introduced the Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience. It came into effect on 1 June 2025 and applies to retirement funds, administrators, insurers and other financial institutions as defined in the Joint Standard.

While it’s not a “law” in the traditional sense, the Joint Standard was issued under the Financial Sector Regulation Act of 2017—which gives it legal power. That means retirement funds must comply.

And yes—the FSCA and PA can take regulatory action against funds that don’t follow the rules.

What does this mean for trustees?

Being a trustee is a serious job. You have a fiduciary duty to act in the best interests of your fund and its members. Even if you outsource day-to-day tasks, the responsibility to protect the fund still lies with you.

If your fund—or your administrator—fails to comply with the Joint Standard, or if your fund suffers a cyberattack that causes a major data breach or financial loss to your fund members, the consequences can be severe:

  • You could receive a fine
  • You could be removed as a trustee
  • You could face criminal charges or jail time
  • You could be personally sued for financial losses by affected members

What trustees must do

The Joint Standard is there to help you protect your fund. Here’s what you need to do:

  1. Ensure your fund complies with the Joint Standard. You don’t have to do everything yourself—but you must ensure it’s being done by the right people.
  1. Develop a cybersecurity strategy. Work with legal and cybersecurity professionals to create a strategy. This document can’t gather dust in a drawer – it should be reviewed and updated regularly. Cybercriminals are constantly developing new methods, and funds should stay one step ahead of them.
  1. Oversee service providers. You may not store member data yourself, but you must check that your administrator (and any other service providers) is following the rules.
  1. Define clear roles and responsibilities. Make sure your contracts with administrators and insurers spell out exactly who is responsible for what when it comes to cybersecurity. If a service provider does not follow the Joint Standard, their contract may be ended.
  1. Have an incident response plan. Cyberattacks are no longer a question of if, but when. According to Interpol, almost 80% of companies in South Africa experienced ransomware attacks in 2023. Make sure your administrator has a tested response plan and that the fund can recover quickly from an attack. Service providers should report all cybercrime incidents to the trustees, who should also report it to the FSCA and PA.
  1. Manage cyber risk. Make sure that managing cyber risks is built into the fund’s overall governance and risk processes. You can appoint a committee to help with this, but the board remains responsible. 
  1. Test your defences. Ask your administrator to regularly run mock cyberattacks to test your fund’s systems. Learn from the results and improve.
  1. Train everyone regularly. Provide ongoing training for everyone involved, from trustees and administrators to members. In practice, cyberattacks are often launched because of human error. For example, a trustee or a member who clicks on a fake email link from a hacker could accidentally expose the entire fund to a data breach.

No one expects you, as a trustee, to know everything about computers or cybercrime. You can—and should—bring in experts to help. But you do need to understand your role. At the end of the day, it’s your job to protect your members’ savings. That’s what being a trustee is all about.

To learn more about cybercrime, check out the Cybercrime Learning Lab. Or if you would like more in-depth knowledge, Atleha-edu and the ASISA Academy offer workshops for South African trustees and members of retirement funds on cybersecurity and other themes.

Sources

EBnet video interview: How Joint Standard 2 of 2024 on cybersecurity applies to retirement funds;  Clarifying roles and responsibilities

Moonstone: Retirement fund trustees face personal liability for cybersecurity non-compliance

Michalsons: Joint Standard on Cybersecurity and Cyber Resilience Requirements

Funded by

Hi there, we can't wait to share our content with you. Please help us send you information that is most relevant to you.