Download Whitepaper

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

From Spreadsheets to GRC Software: Why Pension Funds Need a Modern Approach to Risk Management

Phuong Pham
11 Jan 2022
5 min read

Pension funds today operate in an increasingly complex landscape of regulatory reform, emerging risks, and heightened societal expectations. Many still manage key governance and risk management processes through spreadsheets — a method that, while long embedded in operations, is becoming harder to scale in an environment that demands continuous oversight, transparency, and responsiveness. 

The Evolving Landscape for Pension Fund Risk Management 

A Sector Under Pressure — and Playing Catch-Up 

Dutch pension funds are entering a transformational period, marked by the transition to the new pension system (Wet toekomst pensioenen). Meanwhile, regulatory frameworks such as IORP II, guidance from DNB, and the growing emphasis on ESG and digital resilience — including  EU Digital Operational Resilience Act (DORA) — are rapidly expanding the scope and urgency of risk and compliance management.. 

While the financial sector has seen faster adoption of new risk and compliance technologies, pension funds have traditionally taken a more measured approach. This reflects the sector’s long-term orientation, multi-stakeholder governance, and deeply rooted public-sector culture — where stability and careful consensus-building are rightly prioritized. 

As noted by ING, some of the largest funds, including ABP, are postponing their system transitions until 2027 — while simultaneously ramping up risk hedges to stabilize coverage ratios. But caution comes with its own risks: delayed transitions increase pressure on already stretched compliance and risk teams. 

Common Challenges: Risk Fragmentation and Manual Processes 

Key Challenges Highlighted by DNB 

Recent supervisory reviews by DNB have exposed several weaknesses in risk management practices across the pension sector: 

  • Slow remediation of high-risk audit findings 
  • Overreliance on manual controls, rather than automated safeguards 
  • Insufficient oversight of outsourced functions, particularly in data quality and information security 

These challenges are amplified during the current pension transition, where accurate participant data and operational continuity are mission-critical. Risk management is no longer a static function — it’s a dynamic capability that needs to adapt in real time. 

Many of these challenges are often linked to fragmented processes and limited digital support — particularly where key risk activities are still managed through spreadsheets. 

The Limits of Spreadsheet-Based Risk Management 

Despite growing complexity and regulatory expectations, many pension funds continue to manage their risk frameworks through Excel files spread across departments or outsourced partners. However, this approach presents several limitations for modern governance, risk and compliance (GRC) requirements: 

  • Fragmented data and unclear ownership 
  • Lack of version control and audit trails 
  • Manual reporting burdens that slow decision-making 
  • Difficulty aligning with supervisory frameworks, such as DNB’s ATM model 

In an ecosystem where oversight is shared between boards, operations, and external service providers, this fragmentation creates not only inefficiency — but exposure. 

Integrated Risk Management: A Smarter, Structured Approach 

Building a Foundation for Integrated Risk Management 

Regulators and sector bodies are increasingly advocating for a shift toward Integrated Risk Management (IRM). As DNB emphasizes, effective risk management must be embedded in a coherent and continuous framework — one that balances risks and controls against organizational objectives. 

An IRM framework allows pension funds to: 

  • Clearly define risk categories, including strategic, financial, operational, and outsourcing risks 
  • Set and monitor risk appetite per category 
  • Map risks to fund objectives and scenarios 
  • Continuously assess control effectiveness and improvement actions 
  • Align with regulatory expectations like the Own Risk Assessment (ORA) under IORP II and DNB’s ATM supervision model 

IRM is more than a methodology — it’s a maturity journey. Implemented gradually, it transforms risk from a reactive obligation into a proactive, embedded discipline that enhances organizational resilience. 

Integrated Risk Management for Pension Fund Organizations

Empowering governance, audit, compliance teams in the Dutch pension sector

Download whitepaper

Strategic and Operational Risk: Two Sides of the Same Coin 

While financial risk (e.g., market, interest rate, liquidity) continues to dominate board agendas, strategic and operational risks are becoming equally important. 

For instance, understanding the impact of future risk scenarios — such as market volatility or demographic shifts — is crucial for long-term capital planning. At the same time, operational risks tied to IT, process design, outsourcing, and continuity require clear ownership, documentation, and controls. 

To manage this complexity, pension funds need: 

  • A robust risk taxonomy that captures all relevant categories 
  • The ability to map risks to strategic objectives and track performance indicators 
  • Regular risk assessments that reflect both internal and external developments 

From Awareness to Ownership: Creating a Risk-Aware Culture 

Being “in control” isn’t just about having policies — it’s about building a culture of risk ownership at all levels. This includes: 

  • Engaging boards and committees in scenario-based discussions 
  • Ensuring that improvement actions are visible, tracked, and completed 
  • Periodically evaluating the cost-of-control vs. risk exposure across processes 

Modern risk platforms can enable this by automating workflows, embedding controls, and visualizing risk profiles through dashboards — but the foundation is always strategic intent and governance maturity. 

In Practice: How Pension Funds Are Applying IRM with GRC Software 

Several Dutch pension funds — including Pensioenfonds Detailhandel, ABN AMRO Pensioenfonds, and Blue Sky Group — have begun translating Integrated Risk Management (IRM) principles into practice using modern GRC software such as CERRIX. The platform is designed to support key regulatory frameworks such as IORP II, the DNB ATM supervision model, and more recently, DORA. 

CERRIX provides: 

  • A flexible risk taxonomy aligned with pension sector needs and supervisory standards 
  • Support for regulatory frameworks including ISO 27002, ISO 22301, and Norea Privacy 
  • Capabilities to manage strategic, financial, operational, and outsourcing risks in an integrated way 
  • Workflow automation for activities such as risk assessments, incident tracking, and control testing 

By embedding these processes into one environment, pension funds are able to strengthen their control frameworks, increase transparency, and gradually raise their risk maturity level — all while ensuring compliance with sector-specific and European requirements. 

To dive deeper into how pension funds can structure their risk management approach — and see how Integrated Risk Management aligns with supervisory frameworks like IORP II, DORA, and the ATM model — download the full whitepaper

Share this post

Related content

From Spreadsheets to GRC Software: Why Pension Funds Need a Modern Approach to Risk Management

What to know about GRC software for nis2

Explore how GRC software helps businesses comply with the NIS2 Directive, enhancing cybersecurity and risk management.

Can automation reduce compliance costs?

Explore how automation can reduce compliance costs, enhancing efficiency and ensuring regulatory adherence.

What industries benefit from compliance automation?

Discover which 6 industries benefit most from compliance automation and how it transforms regulatory burdens into strategic advantages through risk reduction and operational efficiency.

How automation streamlines compliance processes

Discover how compliance process automation reduces costs by 40-60% while minimizing errors and risks. Transform manual workflows into strategic advantages for your organization.

Is cybersecurity compliance automation secure?

Discover if cybersecurity compliance automation strengthens or risks your security posture. Learn implementation best practices that enhance protection while simplifying regulatory management.

Does automation reduce compliance risks?

Explore how automation impacts compliance risks, its benefits, limitations, and integration strategies.

Key sectors affected by NIS2 compliance

Explore the impact of NIS2 compliance on key sectors like energy and healthcare, enhancing cybersecurity and data protection.

Are automated compliance tools reliable?

Exploring the reliability of automated compliance tools and their role in cybersecurity.

DORA compliance checklist for beginners

An essential guide for beginners to understand and implement DORA compliance effectively.

Key benefits of adhering to DORA compliance

Explore the key benefits of DORA compliance, enhancing security, efficiency, and regulatory adherence.

NIS2 compliance: top strategies for success

Explore effective strategies for NIS2 compliance to enhance cybersecurity and regulatory adherence.

EU AI Act vs. GDPR: what's the difference?

Explore the key differences and overlaps between the EU AI Act and GDPR, focusing on regulation, impact, and compliance.

Can GRC tools predict compliance risks?

Exploring if GRC tools can predict compliance risks and their role in risk management.

Can a GRC tool adapt to regulatory changes?

Explore if GRC tools can adapt to regulatory changes, covering compliance management and risk assessment.

How does AI governance impact compliance?

Explore the impact of AI governance on compliance, focusing on regulation, ethics, and risk management.

How to prepare for the EU AI Act implementation?

Learn how to prepare for the EU AI Act implementation with practical steps for compliance.

Is your business ready for the EU AI Act?

Explore readiness for the EU AI Act with insights on compliance, challenges, and strategic planning for businesses.

How does DORA compliance impact financial sectors?

Discover how DORA compliance strengthens financial sectors, enhancing risk management, digital resilience, and regulatory standards.

What is DORA compliance and why does it matter?

Explore DORA compliance, its significance in financial services, and strategies for effective implementation.

DORA compliance vs other regulatory standards

Explore the differences between DORA compliance and other regulatory standards, focusing on financial regulations and cybersecurity.

Can automation improve DORA compliance efforts?

Explore how automation can enhance DORA compliance efforts by streamlining processes and ensuring ongoing monitoring.

How to integrate GRC with existing systems?

Integrating GRC with existing systems enhances compliance, risk management, and efficiency.

Can settlement discipline improve market stability?

Exploring how settlement discipline can enhance market stability, focusing on its benefits and challenges.

Why real-time analytics in GRC are vital

Real-time analytics in GRC is crucial for proactive risk management and continuous compliance monitoring.

What features should a GRC tool have?

Explore essential GRC tool features like integration, risk management, compliance, governance, and customization.

How to prepare your business for CSDR compliance?

Guide to preparing your business for CSDR compliance, covering key strategies, challenges, and technology solutions.

Embedding ISQM 1 into the DNA of Your Audit Firm: A Risk-Based Approach to Quality Management

Discover how to implement ISQM 1 with a risk-based approach. Learn how audit firms can embed quality management into daily operations and governance.

CERRIX User Conference 2025

On March 12, 2025, industry leaders, assurance experts, and CERRIX customers came together for the CERRIX User Conference 2025—a day of knowledge-sharing, insightful discussions, and collaboration on the future of risk management, compliance, and AI-driven GRC solutions.

From Spreadsheets to GRC Software: Why Pension Funds Need a Modern Approach to Risk Management

CERRIX and BR1GHT Strengthen Long-term Partnership to Enhance Governance, Risk, Compliance and Audit Solutions

Implementing DORA: From Compliance to Long-Term Resilience

GRC Software Adoption: Overcoming Challenges & Achieving Compliance Success