Skip to content
  • Events
  • About Us
    • History
    • Our People
    • Corporate Social Responsibilities
  • OneClick
  • Our Offices
    • Bury St Edmunds
    • Cambridge
    • Huntingdon
    • Ipswich
    • London
    • Norwich
    • Saxmundham
  • Speak to an advisor
  • Services
    • Specialist services
      • Corporate Finance
        • Business Acquisitions
        • Business Sales and Valuations
        • Debt & Equity Advisory
        • Employee Ownership Trusts
        • Management Buy Outs &
          Management Buy Ins
      • Forensic Accounting
      • Business Advice and Restructuring
      • Tax Advice & Planning
        • Employment Tax
        • Inheritance Tax, Trusts & Estates
        • Large Corporate Tax
        • Owner Managed Business
        • Private Client
        • Residence & Domicile Taxation
        • VAT Advice
      • Insolvency & Business Recovery
    • General services
      • Accountancy Services
        • Bookkeeping
        • Business Outsourcing
        • Payroll
      • Audit & Assurance
      • International Business Support
      • Digital Accounting Software
      • Tailored Finance Function
  • Sectors
      • Academies and Education
      • Agriculture & Landed Estates
      • Charities & Not-For-Profit
      • Leisure and Tourism
      • Local Authority Trading Companies
      • Manufacturing and Engineering
      • Medical and Healthcare
      • Pensions
      • Professional Firms
      • Property Development and Construction
      • Technology and Innovation
      • Transport and Logistics
  • Careers
    • Vacancies
    • Accounting apprenticeships
    • Work Experience
  • Insights & Resources
  • Case Studies
  • Events
  • About Us
    • Our People
    • History
    • Corporate Social Responsibilities
  • OneClick
  • Our Offices
    • Bury St Edmunds
    • Cambridge
    • Huntingdon
    • Ipswich
    • London
    • Norwich
    • Saxmundham
  • Contact Us
Home Insights Single code of practice

Single code of practice

The OPS (Governance) (Amendment) Regulations 2018 came into effect in January 2019 and the Regulator has been reviewing their codes of practice to incorporate this and combine the content of 10 current codes of practice to form a single, shorter code.

Share:

Link copied

The OPS (Governance) (Amendment) Regulations 2018 came into effect in January 2019 and the Regulator has been reviewing their codes of practice to incorporate this and combine the content of 10 current codes of practice to form a single, shorter code.

Whilst these codes aren’t statements of law, they detail what’s expected for good governance to comply with Pensions law.

These new codes were developed in phases, and the draft content for the first phase of the new code of practice was issued for consultation earlier this year.

Risk management is a key area in the new code, and it includes:

  • Identifying and assessing risk
  • Managing risk using internal controls
  • Assurance of governance and internal controls
  • Continuity planning
  • Conflicts of Interest
  • Own risk assessment

The code states that “It is not necessary, nor possible, to eliminate all risks from a pension scheme. Governing bodies should use risk management as a tool to identify risk and develop internal controls”

Trustees are expected to have an effective system of governance, including internal controls proportionate to the nature of the scheme.

Cyber Risk

Cyber risk is wrapped up in the new single code of practice

The management of internal controls need to include measures to reduce cyber risk. In assessing cyber risk, trustees should not only consider the vulnerability to a cyber incident of the scheme’s key functions, systems, and assets, but also the vulnerability of service providers involved in the running of the scheme.

Many schemes use third party organisations to run their scheme and many have included a statement on their website of how they’ve continued to work and operate effective controls during the pandemic. Many also have audited Type 2 reports (AAF 01/06 and SAS70) on their controls.

The code usefully breaks down the guidance into practical steps of assessing and managing cyber risk. These are reproduced below and the full draft of the code can be found here: https://www.thepensionsregulator.gov.uk/-/media/thepensionsregulator/files/import/pdf/full-draft-new-code-of-practice.ashx

Assessing cyber risk

  • Ensure the governing body has knowledge and understanding of cyber risk.
  • Understand the need for confidentiality, integrity and availability of the systems and services for processing personal data, and the personal data processed within them.
  • Have clearly defined roles and responsibilities to identify cyber risks and breaches, and to respond to cyber incidents.
  • Ensure cyber risk is on the risk register and regularly reviewed.
  • Assess, at appropriate intervals, the vulnerability to a cyber incident of the scheme’s key functions, systems and assets (including data assets) and the vulnerability of service providers involved in the running of the scheme.
  • Consider accessing specialist skills and expertise to understand and manage the risk.
  • Ensure appropriate system controls are in place and are up to date (e.g. firewalls, anti-virus, and anti-malware products).

Managing cyber risk

  • Ensure critical systems and data are regularly backed up.
  • Have policies for the use of devices, and for home and mobile working.
  • Have policies and controls on data in line with data protection legislation (including access, protection, use and transmission).
  • Take action so that policies and controls remain effective.
  • Have policies to assess whether breaches need to be reported to the information commissioner (ico.org.uk).
  • Maintain a cyber incident response plan in order to safely and swiftly resume operations. Learn more in Continuity Planning.
  • Satisfy themselves with service providers’ controls (see Managing advisers and service providers).
  • Receive regular reports from staff and service providers on cyber risks and incidents.

More newsletters for you

View All chevron-right
  • Newsletters

Charity News Autumn/Winter 2025

By Ensors Team
1 min read 17th Nov 2025
  • Newsletters

Business E+ Autumn/Winter 2025

By Ensors Team
1 min read 12th Nov 2025
  • Newsletters

Manufacturing Matters: Summer 2025

By Ensors Team
1 min read 24th Jul 2025
  • Newsletters

Life on the Farm – Spring/Summer 2025

By Ensors Team
1 min read 28th May 2025

Sign up to our newsletters

Register here to receive updates on changes in the tax, investment and accounting world as they affect you and your business.

I would like to receive
This field is for validation purposes and should be left unchanged.

  • Services
  • Accountancy Services
  • Audit & Assurance
  • Business Advice and Restructuring
  • Corporate Finance
  • Digital Accounting Software
  • Forensic Accounting
  • Insolvency & Business Recovery
  • International Business Support
  • Tax Advice & Planning
  • Sectors
  • Academies and Education
  • Agriculture & Landed Estates
  • Charities & Not-For-Profit
  • Leisure and Tourism
  • Local Authority Trading Companies
  • Manufacturing and Engineering
  • Medical and Healthcare
  • Property Development and Construction
  • Professional Firms
  • Pensions
  • Technology and Innovation
  • Transport and Logistics
  • About Us
  • Our People
  • Careers
  • Vacancies
  • Our Offices
  • Bury St Edmunds
  • Cambridge
  • Huntingdon
  • Ipswich
  • London
  • Norwich
  • Saxmundham
  • Website Ts & Cs
  • Privacy Policy
  • Disclaimer
  • Accessibility
  • Sitemap
  • Cookies Policy
  • Partners
  • Complaints

© 2025 Ensors Accountants LLP - All Rights Reserved

Ensors is the trading name of Ensors Accountants LLP, a limited liability partnership registered in England & Wales under number OC396130. A list of members’ is available for inspection at our registered office, 2nd Floor, Regis House, 45 King William Street, London, EC4R 9AN.

Ensors is also a trading name of Azets Audit Services Limited, registered to carry on audit work in the UK by the ICAEW. Details of our audit registration can be viewed at www.auditregister.org.uk under reference number C004632199.

Certain directors/partners are licensed to act as an insolvency practitioner in the UK by The ICAEW. A list of our licensed Insolvency Practitioners is available here. https://www.ensors.co.uk/insolvency-practitioners/

Website by StrategiQ

  • Services chevron-right
    • chevron-right Back
    • Specialist services chevron-right
    • Corporate Finance chevron-right
      • chevron-right Back
      • Business Acquisitions chevron-right
      • Business Sales and Valuations chevron-right
      • Debt & Equity Advisory chevron-right
      • Employee Ownership Trusts chevron-right
      • Management Buy Outs &
        Management Buy Ins chevron-right
    • Forensic Accounting chevron-right
    • Business Advice and Restructuring chevron-right
    • Tax Advice & Planning chevron-right
      • chevron-right Back
      • Employment Tax chevron-right
      • Inheritance Tax, Trusts & Estates chevron-right
      • Large Corporate Tax chevron-right
      • Owner Managed Business chevron-right
      • Private Client chevron-right
      • Residence & Domicile Taxation chevron-right
      • VAT Advice chevron-right
    • Insolvency & Business Recovery chevron-right
    • General services chevron-right
    • Accountancy Services chevron-right
      • chevron-right Back
      • Bookkeeping chevron-right
      • Business Outsourcing chevron-right
      • Payroll chevron-right
    • Audit & Assurance chevron-right
    • International Business Support chevron-right
    • Digital Accounting Software chevron-right
    • Tailored Finance Function chevron-right
  • Sectors chevron-right
    • chevron-right Back
    • Empty chevron-right
    • Academies and Education chevron-right
    • Agriculture & Landed Estates chevron-right
    • Charities & Not-For-Profit chevron-right
    • Leisure and Tourism chevron-right
    • Local Authority Trading Companies chevron-right
    • Manufacturing and Engineering chevron-right
    • Empty chevron-right
    • Medical and Healthcare chevron-right
    • Pensions chevron-right
    • Professional Firms chevron-right
    • Property Development and Construction chevron-right
    • Technology and Innovation chevron-right
    • Transport and Logistics chevron-right
  • Careers chevron-right
    • chevron-right Back
    • Vacancies chevron-right
    • Accounting apprenticeships chevron-right
    • Work Experience chevron-right
  • Insights & Resources chevron-right
  • Case Studies chevron-right
  • Events chevron-right
  • About Us chevron-right
    • chevron-right Back
    • Our People chevron-right
    • History chevron-right
    • Corporate Social Responsibilities chevron-right
  • OneClick chevron-right
  • Our Offices chevron-right
    • chevron-right Back
    • Bury St Edmunds chevron-right
    • Cambridge chevron-right
    • Huntingdon chevron-right
    • Ipswich chevron-right
    • London chevron-right
    • Norwich chevron-right
    • Saxmundham chevron-right
  • Contact Us chevron-right