Skip to content
Avrox Asset
Menu
The pension
Explore the tontine

Research papers

Working paper · Russ Oxley

Fair tontine transfers for arbitrary death batches

First published 4 September 2026 · Revised 15 September 2026

This paper formulates fair survivor-only transfers for arbitrary death batches as a transportation problem. It derives feasibility conditions, examines the entropy selection rule and develops a compressed method for evaluating fixed-count allocations. Mathematical existence, numerical approximation and empirical mortality assumptions are treated separately. The results apply under the stated mortality law.

1. The precise experiment

An unordered batch and a succession of chronologically processed deaths are different allocation experiments. This paper studies a specified random death set using balances and probabilities fixed before the event.

There are n members, with fixed pre-event balances s_i > 0. D is the random set of deceased members. Its probability is π_D. For now, every positive-estate event has at least one survivor. Investment returns, withdrawals, later entries and changes in balances during the bucket are outside this one-event experiment.

Define the deceased estate and each member's death probability under this event law:

ED=jDsj,αi=DiπD.E_D=\sum_{j\in D}s_j,\qquad \alpha_i=\sum_{D\ni i}\pi_D.

The survivor keeps their own balance. The rule allocates a share B_{iD} of E_D to member i, with

BiD0,BiD=0 (iD),iDBiD=1.B_{iD}\geq0,\qquad B_{iD}=0\ (i\in D),\qquad \sum_{i\notin D}B_{iD}=1.

Exact actuarial fairness means

D∌iπDEDBiD=siαi.(1)\sum_{D\not\ni i}\pi_D E_D B_{iD}=s_i\alpha_i. \tag{1}

Thus expected incoming mortality credits equal expected forfeited capital, member by member. Fairness is ex ante under π, not equality of realised gains and losses.

Set

YiD=πDEDBiD,ai=siαi,bD=πDED,A=iai=DbD.Y_{iD}=\pi_D E_D B_{iD},\quad a_i=s_i\alpha_i,\quad b_D=\pi_D E_D,\quad A=\sum_i a_i=\sum_D b_D.

Equation (1) is a transportation problem with row totals a_i, column totals b_D, and forbidden cells for deceased recipients. Zero-estate events contribute no column. No algorithm is needed to process a no-death outcome.

The all-dead event needs explicit treatment. If it has positive probability and its estate must go only to survivors, conservation is impossible: there is no eligible recipient. Conditioning the model on at least one survivor is a mathematical device, not a silent solution to unconditional fairness. A full contract must specify that event and include its payments/losses in the fairness equations.

2. General existence and the survivor-weight rule

For a set U of members, write a(U)=Σ_{i∈U}a_i. An event can pay at least one member of U unless every member of U is deceased. The necessary and sufficient Hall conditions are

a(U)+DUbDAfor every U{1,,n}.(2)\boxed{\quad a(U)+\sum_{D\supseteq U}b_D\leq A \quad\text{for every }U\subseteq\{1,\ldots,n\}.\quad} \tag{2}

Necessity follows because U cannot receive any capital from columns in which all of U is dead. Sufficiency follows from the max-flow/min-cut characterisation of the transportation problem. This applies to correlated mortality and arbitrary supported batch sizes as well as independent mortality.

For batches of at most K deaths, only sets with |U|≤K can create nontrivial exclusions; larger U cannot be contained in D. That reduction is not itself a scalable gate: the number of remaining subsets can still be large.

There is a direct gate when mortality is exchangeable. Let ρ_m be the probability that a specified set of m members all die; p=ρ_1. For |U|=m, with S=Σs_i,

DUbD=ρms(U)+ρm+1(Ss(U)).\sum_{D\supseteq U}b_D=\rho_m s(U)+\rho_{m+1}(S-s(U)).

Equation (2) is therefore equivalent to

s(U)Spρm+1pρm+1+ρm.\frac{s(U)}S\leq \frac{p-\rho_{m+1}}{p-\rho_{m+1}+\rho_m}.

For each m, only the m largest balances need be checked. In the fixed-k exchangeable case, ρ_m=(k)_m/(n)m, where the parentheses denote falling factorials, and ρ{k+1}=0. Sorting once and checking m=1,…,k gives the exact Hall gate in O(n log n+k).

A sharp example shows why checking members individually is insufficient. Let n=5, k=2, equal mortality odds, and balances (41,41,6,6,6). The singleton cap is 3/7 of the fund, so each 41% account passes. The two-member cap is 80%; the largest pair holds 82% and fails. Its required expected credits are 32.8, but only 31.8 of expected deceased capital is available in events with a survivor in that pair. The £1 shortfall is an economic infeasibility, not a numerical failure.

Let c_i be any positive nominal reference weights, and let

BiD0=cijDcj,RiD=bDBiD0.B^0_{iD}=\frac{c_i}{\sum_{j\notin D}c_j},\qquad R_{iD}=b_D B^0_{iD}.

Under the usual forward-KL/IPF interpretation, solve

minY satisfying the margins/supporti,D[YiDlogYiDRiDYiD+RiD].(3)\min_{Y\text{ satisfying the margins/support}} \sum_{i,D}\left[Y_{iD}\log\frac{Y_{iD}}{R_{iD}}-Y_{iD}+R_{iD}\right]. \tag{3}

This is an expected-capital-weighted KL distance between event allocation shares. The weighting and the direction of KL are part of the definition of 'closest'.

All KL sums run only over permitted cells in positive b_D columns. Use the convention 0 log 0=0 at permitted cells where Y vanishes; structural zero cells are excluded from the objective.

When a feasible allocation is strictly positive on every permitted cell, the first-order equations give

YiD=RiDexp(λi+μD).Y_{iD}=R_{iD}\exp(\lambda_i+\mu_D).

Enforcing the column totals and writing w_i=c_i exp(λ_i) yields

BiD=wijDwj,iD.(4)\boxed{\quad B^*_{iD}=\frac{w_i}{\sum_{j\notin D}w_j},\quad i\notin D.\quad} \tag{4}

This is the same allocation form for pairs, triples and any larger supported batch. A separate bespoke tensor of transfer coefficients is unnecessary. For one death j, normalising Σw_i=1 recovers B_{ij}=w_i/(1−w_j).

The allocation Y is unique by strict convexity. Weights have at least an arbitrary common scale; additional non-identifiability can arise if the support disconnects. For a complete fixed-k event family with k≤n−2, every pair of members can co-survive, giving the usual single-scale ambiguity. With one possible survivor per event, the event allocations are forced and weights do not identify anything.

On a boundary of the feasible set, some otherwise permitted cells can be forced to zero. Equation (4) with finite, strictly positive weights need not describe that boundary solution. Weak Hall feasibility must not be confused with the stronger interior condition required by a positive-weight solver.

One convex calibration objective, using x_i=log w_i, is

Φ(x)=DbDlog ⁣(iDexi)iaixi.(5)\Phi(x)=\sum_D b_D\log\!\left(\sum_{i\notin D}e^{x_i}\right)-\sum_i a_i x_i. \tag{5}

Its gradient is incoming expected capital minus the fairness target. Its Hessian is a sum of nonnegative multinomial covariance matrices. This supplies a general optimisation formulation, but evaluating the event sum directly is combinatorial.

3. What 'closest fair to nominal gain' does and does not establish

Fullmer–Sabin nominal gain uses c_i=s_i q_i/(1−q_i), where q_i is mortality over the specified interval. It is not simply q_i s_i. Their realised allocation is proportional to these c_i among survivors.

There is a qualification to the FTP interpretation. Every positive, member-only proportional seed has the same forward-KL projection onto the same exact margins.

To see this, expand the nonconstant part of (3):

i,DYiDlogYiDDbDlogbDiailogci+DbDlog ⁣(jDcj).(6)\sum_{i,D}Y_{iD}\log Y_{iD} -\sum_D b_D\log b_D -\sum_i a_i\log c_i +\sum_D b_D\log\!\left(\sum_{j\notin D}c_j\right). \tag{6}

All terms involving c are constant over the feasible set. Changing c from nominal gain to account balances, or to equal member weights, changes the objective value but not its minimiser.

Equivalently, the rule maximises

DbDH(BD),H(B)=iBilogBi,(7)\sum_D b_D\,H(B_{\cdot D}),\qquad H(B)=-\sum_i B_i\log B_i, \tag{7}

subject to fairness, conservation and survivor-only eligibility.

A 'closest fair to nominal gain' explanation is mathematically valid when 'closest' means (3). It does not, by itself, demonstrate that nominal gain uniquely selects the solution. The stronger interpretation is a maximum-entropy fair allocation, which can also be explained as the forward-KL correction of nominal gain. This observation is specific to separable references and fixed margins. Other distance functions or genuinely event-dependent reference preferences can select different fair allocations.

It also leaves a substantive modelling question open: why expected-capital-weighted entropy is the preferred selection principle among fair rules. Computational convenience and a clear audit trail are benefits; minimising payout variance or another economic loss is a separate objective.

4. Fixed death counts and mortality robustness

For independent Bernoulli mortality, let the raw probabilities be q_i∈(0,1), and define odds r_i=q_i/(1−q_i). Conditional on K=k deaths,

πD[k]=jDrjek(r),D=k,αi[k]=riek1(ri)ek(r).(8)\pi_D^{[k]}=\frac{\prod_{j\in D}r_j}{e_k(r)},\quad |D|=k, \qquad \alpha_i^{[k]}=\frac{r_i e_{k-1}(r_{-i})}{e_k(r)}. \tag{8}

Here e_k is the elementary symmetric polynomial of degree k; e_0=1. The fairness target is s_i α_i^[k], not s_i q_i. The latter belongs to the unconditioned experiment.

Proposition: count-stratified fairness is robust to changes in count probabilities that preserve the conditional identity laws. If each supported layer satisfies E[net transfer_i | K=k]=0, any mixture of those layers is fair by iterated expectations. Conversely, fairness for every possible mixture requires fairness in each layer individually.

A concrete case is a common mortality-odds shock:

riλrifor every i.r_i\longmapsto\lambda r_i\quad\text{for every }i.

Every size-k event numerator and its normalising constant acquire the same factor λ^k. Therefore the identity law in (8), the layer targets, and its calibrated weights remain unchanged. Exact layers are robust to this common change in mortality odds. This is an exact statement about odds, not proportional hazards in general. Age-specific changes or dependence changing which members die together are outside the result.

The qualification is coverage: robustness applies to the certified supported layers. Moving probability into uncertified or all-dead events does not inherit the guarantee.

5. A sharp limit: fairness at every nonterminal count

Theorem. Under independent Bernoulli mortality with 0<q_i<1 and positive balances, survivor-only, fully redistributive, nonnegative-credit rules can be fair separately for every k=1,…,n−1 if and only if

siqi1qi=Cfor all i.(9)\boxed{s_i\frac{q_i}{1-q_i}=C\quad\text{for all }i.} \tag{9}

Necessity is already forced by k=n−1. Let S=Σs_i. If i is the sole survivor, their final balance must be S. Conditional on exactly one survivor, their probability of being that survivor is

hi=1/rij1/rj.h_i=\frac{1/r_i}{\sum_j1/r_j}.

Fairness requires S h_i=s_i. Rearrangement gives s_i r_i=S/(Σ_j1/r_j), constant across members.

For sufficiency, suppose s_i r_i=C. Give every survivor the equal monetary credit E_D/(n−k). The unnormalised expected credit to i is

Cnkjiek1(ri,j)=Cek1(ri).\frac{C}{n-k}\sum_{j\ne i}e_{k-1}(r_{-i,-j}) =C e_{k-1}(r_{-i}).

Each degree-(k−1) monomial in the variables other than i is counted n−k times. Dividing by e_k(r) gives s_i α_i^[k], which proves fairness.

Equal survivor shares also maximise each event's entropy. Since they jointly satisfy the constraints in this special case, they are the entropy optimum for every layer and for any mixture of those layers.

This is a feasibility theorem, not just a limitation of entropy or separable weights. With equal mortality probabilities, it requires equal balances. Most heterogeneous pools cannot have exact conditional fairness at every possible death count, however effective the solver. The theorem does not say that a useful range of small or moderate batch sizes is infeasible; the forcing event can be exceptionally rare.

An exact rational check uses s=(9,4,3,2) and q=(1/10,1/5,1/4,1/3). Each s_i r_i=1. Equal survivor credits meet the fairness targets for k=1,2,3 without numerical approximation.

6. Why a mixed-count rule can exist when one layer cannot

Consider three members with balances (4,3,3), independently dying with probability 1/3, conditioned on at least one survivor. The no-death event has probability 4/13; each single-death event 2/13; each two-death event 1/13.

The following are monetary credits, in addition to survivors retaining their own balances:

Death set Probability Credit to member 1 Credit to member 2 Credit to member 3
{1} 2/13 0 2 2
{2} 2/13 5/2 0 1/2
{3} 2/13 5/2 1/2 0
{1,2} 1/13 0 0 7
{1,3} 1/13 0 7 0
{2,3} 1/13 6 0 0

Every row distributes exactly its deceased estate. Expected credits are (16/13,12/13,12/13), exactly matching each balance times its conditional death probability 4/13.

Yet fairness conditional on two deaths is impossible: each member is equally likely to be the only survivor, so their expected final balance is 10/3, unequal to (4,3,3).

The expected net transfers conditional on one death are (1/3,−1/6,−1/6). Conditional on two deaths they are (−2/3,1/3,1/3). The count probabilities 6/13 and 3/13 cancel these differences. This example is a feasible allocation, not a claim that it is the entropy optimum.

The choice between stratified and mixed fairness has economic content. Stratification prevents this cross-count compensation and provides the robustness in Section 5. Mixed fairness admits more pools but its balance depends on the modelled frequency of batch sizes. Neither convention should be adopted implicitly.

7. Computing larger fixed-count layers without enumerating death sets

For positive weights, write W_surv(D)=Σ_{i∉D}w_i. Use the exact identity

1Wsurv(D)=0etWsurv(D)dt.(10)\frac{1}{W_{\rm surv}(D)}=\int_0^\infty e^{-tW_{\rm surv}(D)}\,dt. \tag{10}

Define the polynomial

fj(z,t)=(1qj)etwj+qjz,pk=[zk]j((1qj)+qjz).f_j(z,t)=(1-q_j)e^{-tw_j}+q_j z,\qquad p_k=[z^k]\prod_j((1-q_j)+q_jz).

The expected incoming credit in the k-layer becomes

gi(w)=wi(1qi)pk0etwi[zk]jisjqjzi,jf(z,t)dt.(11)g_i(w)=\frac{w_i(1-q_i)}{p_k}\int_0^\infty e^{-tw_i} [z^k]\sum_{j\ne i}s_jq_j z\prod_{\ell\ne i,j}f_\ell(z,t)\,dt. \tag{11}

All summands are nonnegative, so exchanging the finite event sum and integral is valid. Expanding the factors enumerates deaths algebraically rather than storing their combinations. The estate is handled by a second polynomial channel that accumulates the balance of selected deceased members.

Truncate the polynomial arrays at degree k. A forward recursion computes the probability and estate channels; reverse differentiation supplies all member derivatives in a further pass. This evaluates all n incoming credits at one quadrature node in O(nk) arithmetic. With M quadrature nodes, one evaluation is O(nkM), rather than enumerating binomial(n,k) possible batches. Optimisation takes multiple evaluations, and quadrature difficulty depends on weight concentration and the survivor-weight denominator. This is not an O(nkM) bound for the complete calibrated solution.

For reproducibility, put A_i(t)=(1−q_i)exp(−tw_i) and B_i=q_i. Starting with P_0=1 and estate channel F=0, the forward updates for member i are

Pm=AiPm+BiPm1,Fm=AiFm+Bi(Fm1+siPm1).P'_m=A_iP_m+B_iP_{m-1},\qquad F'_m=A_iF_m+B_i(F_{m-1}+s_iP_{m-1}).

Out-of-range coefficients are zero. After all members, F_k is the unnormalised estate-weighted transform. Reverse differentiation evaluates

gi(w)=wipk0Ai(t)Fk(t)Ai(t)dt.g_i(w)=\frac{w_i}{p_k}\int_0^\infty A_i(t)\frac{\partial F_k(t)}{\partial A_i(t)}\,dt.

The compressed IPF update is w_i←w_i a_i/g_i(w), followed by normalisation. It represents alternating row and column scalings of the full coupling without constructing that coupling. The current vectorised implementation stores O(nkM) values; a different checkpointing strategy could reduce memory.

The mathematical representation is exact. Finite numerical quadrature and optimisation are approximations that must be checked. For a finite integration cutoff T, define σ_i as w_i plus the smallest n−k−1 other weights. Then the omitted row-i integral is bounded by

wiσiE[ED1iDK=k]eσiT.(12)\frac{w_i}{\sigma_i}\, \mathbb E[E_D\mathbf1_{i\notin D}\mid K=k]e^{-\sigma_i T}. \tag{12}

This follows from W_surv(D)≥σ_i whenever i survives. It bounds truncation error, not the error of the numerical integration on [0,T]. A full certified implementation must control both.

The implementation uses an even simpler bound for the total omitted credits. Let L be the sum of the smallest n−k weights. Summing all row tails gives E[E_D exp(−T W_surv(D)) | K=k], bounded by A exp(−TL). Each row tail is nonnegative and hence no larger than this total bound. The code selects T from that inequality and separately compares quadrature orders.

The conditional law also permits a numerical normalisation: multiply every mortality odds by the same factor until the corresponding base probabilities sum to k. This preserves equation (8) while making the conditioning event less numerically rare. The prototype's demonstrations use this normalisation for heterogeneous test cases. The constructor does not yet apply it automatically and rejects severely underflowing count probabilities.

An accurate positive-weight solution supplies a strong numerical feasibility witness. Solver failure is not a proof of infeasibility. Independent Hall/max-flow tests remain appropriate for small validation cases, and near-boundary cases need explicit diagnostics.

8. Numerical validation

All inputs below are synthetic. They test mathematical implementation and scale, not a calibrated pension population. Relative fairness residual means max_i |g_i−a_i|/a_i. The numerical study uses random seed 20260904.

Test Independent comparison Result
21 evaluator cases: n=8,10,12 and k=1,…,7 Enumerate every death set and sum its allocation directly Worst relative difference 9.88×10^−15
n=12, k=7; heterogeneous mortality and balances Exhaustive Hall test; direct enumeration of final expected credits Maximum relative fairness residual 3.40×10^−12
n=1,000, k=10; equal mortality, heterogeneous balances Exchangeable Hall gate; higher quadrature order Maximum relative fairness residual 1.45×10^−12
n=1,000, k=10; heterogeneous mortality and balances Higher quadrature order; positive-weight numerical solution Maximum relative fairness residual 4.01×10^−13

The seven-death solution required 15 IPF updates. The two large solutions required two and three updates respectively. The heterogeneous large case took approximately 0.45 seconds for the local solve, excluding independent refinement and any general Hall certification. This is one well-conditioned demonstration, not a timing guarantee or a claim about worst-case convergence.

There are exactly 263,409,560,461,970,212,832,400 possible ten-death sets in the 1,000-member tests. The polynomial evaluator never constructs them. In the heterogeneous large case, conditional member death probabilities range from approximately 0.1110% to 4.8765%, with positive normalised weights between approximately 0.0000818 and 0.005658.

The 21 evaluator comparisons include feasible and potentially infeasible pool inputs; they test the expected-credit calculation at specified positive weights, not existence of a fair solution in every case. The seven-death solve separately passes exhaustive Hall feasibility. The equal-mortality large solve passes the exact-form exchangeable gate with ample numerical slack. For the heterogeneous large case, no exhaustive general Hall certificate is claimed: the evidence is a positive-weight solution and its small independently refined residual.

The prototype does not yet provide rigorous interval error bounds for quadrature, automatic count-law recentering, robust boundary decomposition, or a scalable heterogeneous Hall certification routine. It rejects all-dead layers and weights too close to a degenerate survivor denominator. Numerical non-convergence must not be reported as proof of economic infeasibility.

9. Relation to the literature

Transportation is already explicit in Sabin's 2011 work. Entropy projection and matrix scaling are established mathematical methods. The potential contribution is their precise survivor-only batch formulation, the mortality assumptions and feasibility limits, and scalable evaluation of larger exact layers.

The one-dimensional integral with polynomial differentiation provides the computational formulation examined here. The sections on entropy interpretation, count conditioning and all-count feasibility specify its scope. A detailed comparison with related multiple-death methods is still needed to assess novelty.

The closest comparisons require distinguishing unordered batch fairness, sequential-death fairness, fairness across an entire period, and payments allowed to deceased members' estates. A paper can solve a related period problem exactly by allowing transfers that are excluded here.

Selected references and comparison topics:

  1. Sabin (2010), Fair Tontine Annuity. Single-death starting point.
  2. Sabin (2011), A Fast Bipartite Algorithm for Fair Tontines. Restricted-transportation formulation.
  3. Fullmer and Sabin (2019), Individual Tontine Accounts. Nominal gain s_i q_i/(1−q_i), survivor allocation, and actuarial bias.
  4. Weinert and Gründl (2021), The modern tontine. Annual multiple-death extension using pairwise FTP fractions and approximations. A detailed equation-by-equation comparison is needed before claiming novelty.
  5. Feng and Liu (2025), Spatio-temporal risk sharing and transfer. Discusses accumulating sequential FTP transfers over a period.
  6. Zhou et al. (2025), Risk-sharing rules for mortality pooling products with stochastic and correlated mortality rates. Distinguishes exact period rules allowing decedent allocations from almost-fair alive-only nominal gain.
  7. Denuit, Hieber and Robert (2022), Mortality credits within large survivor funds. Conditional-mean allocation, including payments to beneficiaries on death.
  8. Csiszár (1975), I-Divergence Geometry of Probability Distributions and Minimization Problems.
  9. Sinkhorn and Knopp (1967), Concerning nonnegative matrices and doubly stochastic matrices.

10. Further research

Fixed-count fairness offers the robustness property proved above. Practical implementation requires separate numerical acceptance criteria, feasibility checks and a policy for counts outside the supported range. The companion paper, Auditable FTP for heterogeneous pools, examines those implementation requirements.

Mixed-count fairness is a separate comparator. Its wider feasible set is a real benefit, but it accepts model-dependent compensation between mild and severe mortality outcomes. Whether that trade-off belongs in the eventual design is a judgement for the research programme, rather than a numerical implementation choice.