The defined-contribution retirement system in the United States holds approximately twelve trillion dollars. The defined-benefit system, public and private combined, holds another fifteen trillion. United Kingdom occupational schemes manage in excess of three trillion pounds. Canadian registered pension plans aggregate roughly two trillion Canadian dollars. The slow drift of these pools toward tokenised allocations has begun, and the supervisory reaction has been firm. Tokenisation does not alter the fiduciary architecture of retirement saving.
Section 404(a) of the Employee Retirement Income Security Act of 1974 requires a fiduciary to discharge duties with respect to a plan solely in the interest of the participants and beneficiaries, for the exclusive purpose of providing benefits and defraying reasonable expenses, and with the care, skill, prudence and diligence under the circumstances then prevailing that a prudent person acting in a like capacity and familiar with such matters would use. The Department of Labor has reiterated in March 2026 guidance that this standard applies in full to allocations to tokenised assets, that the fiduciary cannot rely on the existence of a token to satisfy diligence obligations, and that the decision must be documented contemporaneously.
The Department's earlier guidance on cryptocurrency in defined-contribution plans, published in 2022 and not rescinded, called for extreme care when considering whether to include cryptocurrency or related products as a plan investment option. The 2026 guidance extends the same posture to tokenised securities and tokenised funds. The position is not a prohibition. It is an allocation of accountability. The fiduciary may include a tokenised allocation if the fiduciary can demonstrate, on the record, that the inclusion satisfies the prudence and diversification duties of Section 404(a) and meets any applicable safe-harbour or disclosure conditions.
The Prudent Investor Rule, adopted in most United States jurisdictions for trust fiduciaries and analogous to the ERISA standard, evaluates an investment not in isolation but in the context of the portfolio. A small tokenised allocation in a diversified portfolio may be defensible where the same allocation in a concentrated portfolio would not be. The control plane above the rail must capture, for each fiduciary decision, the portfolio context, the asset-class research, the conflict-of-interest analysis, the fee comparison and the documented reasons the fiduciary believed the allocation served the plan's interests.
Internal Revenue Code Section 401(a) qualification, which underpins the tax preferences of the plan, depends on plan operation. A plan that allocates to a tokenised asset structured in a manner the Internal Revenue Service treats as a prohibited transaction, or that engages in dealings with a party in interest as defined in Section 4975, places the plan's qualification at risk. The qualification analysis is independent of the settlement layer. The tokenised wrapper does not exempt the transaction from the prohibited-transaction rules.
United Kingdom occupational pension trustees operate under the Trustee Knowledge and Understanding requirement of the Pensions Act 2004 and the Pensions Regulator's Code of Practice number 7. The requirement is that trustees have knowledge and understanding of the law relating to pensions and trusts, the principles relating to investment, and the funding and investment principles of their own scheme, sufficient to enable them to exercise their functions. The Pensions Regulator has indicated in 2026 supervisory communications that a trustee body that includes a tokenised allocation in the scheme's investment strategy without trustee-level understanding of how the tokenisation rail operates and what the institutional control plane around it provides will not be considered compliant with the standard.
Canadian registered pension plans operate under the supervisory regime of the Office of the Superintendent of Financial Institutions and the relevant provincial authorities. The OSFI Statement of Investment Policies and Procedures requirement, paired with the prudent person standard codified in pension benefits legislation, sets an equivalent expectation. The 2026 OSFI guidance on tokenised assets requires that any allocation be supported by an independent valuation methodology that does not rely on the token's secondary-market price as a proxy for fair value, consistent with the OSFI Guideline E-23 expectations on model risk.
The Qualified Default Investment Alternative regulation under ERISA, codified at 29 CFR 2550.404c-5, permits a plan fiduciary to obtain relief from liability for the investment of participant assets in a default option, subject to specific conditions including diversification, professional management, and the alternatives' suitability as a long-term retirement vehicle. A QDIA that includes a tokenised component must be evaluated against the full set of conditions, not only the diversification limb. The Department of Labor has not authorised a blanket safe harbour for tokenised QDIAs, and the fiduciary's diligence file must demonstrate that the inclusion satisfies each condition independently.
Participant disclosure is the second axis on which tokenisation creates fiduciary exposure. ERISA Section 404(a)(5) requires plan administrators to provide participants with information about plan investments, including performance, fees and risks. A tokenised allocation must be described in plain language sufficient for a participant without specialised knowledge to understand the nature of the investment, the liquidity profile, the risks specific to the tokenised wrapper, and the fees attributable to the rail. Boilerplate cryptocurrency disclaimers do not satisfy the standard.
Custodial arrangements are the third axis. Plan assets must be held by a custodian that meets the requirements of ERISA Section 403, which permits assets to be held in a trust, in an insurance contract, or by a custodian authorised under Section 408 of the Internal Revenue Code. A tokenisation rail is not, by itself, a custodian. The control plane must document the custodial chain from the participant's account to the underlying asset, must demonstrate segregation from the custodian's general assets, and must satisfy the unrelated business taxable income rules where the underlying generates income that would be UBTI in a taxable account.
The board-level question for plan fiduciaries is whether the institution that sponsors the plan, the investment committee that makes allocation decisions and the named fiduciary that signs the investment policy statement have stood up a documented diligence process that addresses prudence, diversification, custodial chain, valuation methodology, participant disclosure, prohibited-transaction analysis and ongoing monitoring, all in respect of any tokenised component the plan holds. Where that diligence file is incomplete, the prudent posture is to defer tokenised allocations until the file is built.
Cabier Consulting's 2026 brief, Governance Above the Rail, places retirement assets in the under-governed category for a reason. The instruments are increasingly available, the demand from plan participants is real, and the fiduciary architecture has not been redesigned to accommodate them. The architecture does not need to be redesigned. It needs to be respected.
Section. The board questions before going live.
Before the first tokenised pensions and retirement transaction settles in production, the institution's audit and risk committees should resolve a defined list of questions, on the record, with named accountability. The first question is whether the legal opinion supporting the use of the tokenisation rail covers every jurisdiction in which the institution will issue, hold, transfer or distribute the instrument, and whether the opinion is current as of the most recent supervisory communication in each jurisdiction. The second question is whether the institution has identified the named senior manager responsible for the programme under the relevant individual-accountability regime, including the United Kingdom Senior Managers and Certification Regime, the Australian Financial Accountability Regime, the Hong Kong Manager-in-Charge regime, the Singapore Senior Managers regime, and any equivalent in the home jurisdiction.
The third question is whether the model inventory has been updated to include every smart contract, oracle and pricing routine that influences a regulated outcome, and whether each new entry has been subject to independent validation under standards equivalent to Federal Reserve SR 11-7 and the Office of the Superintendent of Financial Institutions Guideline E-23. The fourth question is whether the institution has documented, in advance, the supervisory communications it will make in the event of a tokenisation rail outage, a smart-contract incident or an oracle failure, and whether those communications have been pre-cleared with the relevant regulators where pre-clearance is appropriate. The fifth question is whether the institution's professional-indemnity, directors-and-officers and cyber-insurance policies have been updated to reflect the new exposures, and whether the underwriters have been provided with the institutional control documentation.
Section. An operating model for the institution-owned control layer.
A credible above-the-rail control layer for tokenised pensions and retirement sits inside the second line of defence, reports through the chief risk officer, and is staffed by a small named team with explicit charters for valuation governance, model risk, regulatory reporting, conflict and incentive surveillance, operational resilience and cross-jurisdictional consistency. The team does not run the rail. It operates a continuous evidence file that consumes events from the rail, reconciles them to the institution's systems of record, and grades the effectiveness of each control on a daily cycle. The grading is not pass or fail. It is a defined scale of effective, degraded and failed, with a stated remediation latency for each grade, and with explicit escalation thresholds to the chief risk officer and the audit committee.
The control layer's outputs are designed to be regulator-readable without bespoke transformation. A single source of truth produces the figures that feed every supervisory return, every internal capital-adequacy assessment, every Pillar 3 disclosure and every public sustainability or operational-resilience statement. The auditor and the supervisor see the same chain of evidence. The institution does not produce one number for the regulator and a different number for the board. The discipline of a single source of truth is the precondition for any defensible cross-jurisdictional posture, and it is the principal operational benefit of building the control layer above the rail rather than inside it.
Section. A twelve-month plan to stand up the layer.
In month one, the institution maps every regulatory obligation that attaches to the tokenised pensions and retirement programme across every jurisdiction in scope, and produces a matrix that ties each obligation to a named owner, a control description, an evidence source, an effectiveness-grade definition, and a remediation latency. In months two and three, the institution stands up the evidence vault, ingests live data from the tokenisation rail, the legacy systems of record and the third-party data providers, and reconciles the three on a daily cycle. In months four through six, the institution writes the effectiveness-grade definitions for each control, validates them against historical data, and stress-tests them against scenarios developed in conjunction with internal audit.
In months seven through nine, the institution runs the control layer in parallel with the existing periodic control regime, identifies the divergences, documents the root causes and remediates. In months ten through twelve, the institution retires the periodic regime for the controls now operated continuously, formalises the operating model with the audit committee and the regulator of record, and produces the first regulator-readable evidence file. The plan is paced so that no production volume is committed to the rail in advance of the corresponding control evidence being in place. The discipline is uncomfortable in the early months and unmistakably valuable when the first supervisory examination arrives.
Section. What a regulator-ready evidence file looks like.
The regulator-ready evidence file for the tokenised pensions and retirement programme is not a folder of point-in-time reports. It is a continuously assembled, cryptographically anchored record that, on any day a supervisor walks into the institution, can answer five questions without rework. Which obligations attach to this programme in this jurisdiction. Which control discharges each obligation. What grade did each control hold on each day. Where the grade was below effective, what the remediation latency was and whether it was met. Which named individuals were accountable for the obligation, the control and the remediation. A file that cannot answer these five questions on the supervisor's first request will be treated as a control weakness in its own right, irrespective of the substantive quality of the underlying programme.
The Cabier institutional brief, Governance Above the Rail 2026, is the reference architecture this plan implements for the tokenised pensions and retirement use case. The brief is written for boards and senior risk committees and is available in full at the Cabier Consulting site. LUMINAIRE will continue to publish under this cluster as the under-governed asset classes evolve and as supervisory expectations are clarified through 2026 and beyond.
