Skip to content
Avrox Asset
Menu
The pension
Explore the tontine

Research papers

Working paper · Russ Oxley

Initial rung funding and simulated FTP income

First published 7 September 2026 · Revised 15 September 2026

This experiment asks how mortality sharing changes the initial investment for each dated income target, and what payments a specified heterogeneous fair transfer plan actually produces. It compares a survival-adjusted funding baseline with simulated investments, transfers and releases in three fixed cohorts. Paths on which the allocation policy stops remain in the coverage and accounting records.

Funding question before the simulation

A focal member aged 65 invests £100,000. There are 40 nominal annual target payments, at ages 66–105. Rung k pays at year k; its mortality commitment ends one year earlier, at year k−1. The first rung is therefore released at entry and receives no mortality credits. The last release is at year 39 and the last cash payment at year 40. Every member uses these same calendar dates, with survival weights appropriate to their own age. This is a controlled common-horizon experiment rather than a general age-specific retirement plan.

For a given rung let s be survival to release, G the investment growth including the following distribution year, and K its investment-only certainty-equivalent growth factor. With CRRA risk aversion gamma = 3,

K = E[G^(1−gamma)]^(1/(1−gamma)).

For the declared piecewise-constant GBM investment model this is

K = exp(sum_months (mu − 0.5 gamma sigma²) / 12 + 0.035).

The final 0.035 is the continuous return during the one-year distribution stage. An investment-only rung targeting a certainty equivalent C costs C/K. With ideal, deterministic survival pooling, independent of investment returns, survivors receive a multiplier 1/s, so the corresponding benchmark cost is s C/K. The difference (1−s) C/K is the mortality-sharing reduction. It is an exchange of rights: the member gives up the unreleased capital if death precedes release. The reduction is not an extra investment return and is not available without that commitment.

rung_funding.csv shows both costs for the same £1,000 target in every rung. It also shows two separately normalised allocations of the same £100,000: one for a level investment-only CE target, and one for a level ideal-pooling CE target. These are separate comparisons. Holding the income target fixed compares funding costs; holding capital fixed compares target income. The finite FTP simulation tests the second allocation, rather than assuming it achieves the ideal target.

Mortality, investment and cohorts

Mortality is synthetic unisex, with no claim of empirical calibration. A member entering at age a has annual hazard

h(a,m) = 0.01 exp((a − 65 + m/12)/10)

through month m, held constant within that month. Both the survival discounts and simulated deaths use the sum of exactly these monthly hazards. Independent exponential thresholds generate death times; their order within each month is observed in the model. Conditional next-death identity probabilities use hazards, not Bernoulli death odds. All hazards share the same time multiplier in this particular model, so their relative shares can be evaluated using entry hazards without changing the probabilities.

Each cohort contains the fixed focal member and peers with ages at equally spaced midpoints over 55–80 and starting capital at equally spaced midpoints over £60,000–£140,000. Age strata and capital strata are independently shuffled. There are 50, 200 or 500 members, and no subsequent entries or contributions. Each person commits their entire stated capital to their own age-weighted version of the same 40-rung calendar ladder. Cohort files list every age, capital amount and initial hazard.

The investment assumptions are stipulated for this experiment. Equity follows dS/S = 0.065 dt + 0.16 dW; 6.5% is the level drift, not the log drift. Bonds earn a deterministic continuous 3.5%. At each month start a rung's equity weight is 0.8 clip((years to release − 5)/25, 0, 1) and is held for that month. Thus equity is 80% at 30 or more years, 0% at five or fewer, with a linear path between. The portfolio is modelled as exact GBM for the weighted drift and volatility. These are stipulated assumptions, not estimates or an optimised glidepath.

The monthly Brownian shock is common across all members and rungs, and also across the three pool-size experiments and the investment-only comparator. Brownian bridges split that shock at each observed death. This means a credit receives only subsequent returns, not an entire month of returns when it arrived part way through. Different pools have independent bridge draws conditional on their common month-end shock; they do not share one fully specified continuous intramonth path. Annual unpooled rung growth depends only on the shared monthly shocks.

There are no fees, tax, inflation, mortality improvements, common-cause mortality, mortality-estimate revisions, guarantees, outside buffers or contractually specified closure payments.

The declared FTP and reinvestment rule

Immediately before each death, use actual unreleased balances and current hazards to propose single-death proportional survivor weights. The scalar-root procedure calibrates the weights to the current balances and mortality hazards. For balances s_i and hazards h_i, it solves

w_i (1−w_i) = c theta_i, where theta_i = s_i h_i / sum(s h) and sum(w)=1.

A distinct numerical audit evaluates each member's expected incoming transfer over every possible next identity of the deceased, then compares it with that member's expected forfeiture. The audit tolerance is £0.0001 per member per event. A direct, quadratic-work matrix calculation independently checks the audit on a small heterogeneous case. These are binary64 numerical checks. This run does not claim an outward-rounded, rational or symbolic fairness certificate.

When member j dies, each survivor receives estate_j × w_i / sum_{l != j}(w_l). The transferred estate is conserved. Each recipient reinvests that receipt over their own remaining rungs in proportion to conditional survival to release divided by remaining CE investment growth. Existing holdings stay in their original rungs. This is one declared reinvestment policy; alternatives could change outcomes. Fairness of member-level transfers does not by itself establish that each dated income target is met.

Current-state admissibility is checked before actual transfer events. The simulation does not enumerate all possible future death sequences or prove continuation. It does not establish batch-death fairness for an unknown event order. The batch-allocation paper and continuation research address separate requirements for a practical implementation.

Research stops and rights after release

Stop before making a proposed transfer if a member's hazard-weighted balance share reaches one half, or if the numerical fairness audit cannot be accepted. Also stop immediately after a transfer leaves fewer than three people with unreleased assets. Stops leave the remaining unreleased capital visible and unallocated to a hypothetical closure contract.

A stop is a model/research boundary, not a realised loss of every retained pound. It also does not prove that no alternative policy could have continued. Conversely, subsequent payments are not invented for stopped unreleased rungs. Already released money belongs to its assigned member or estate, grows at the stipulated distribution-fund return, and pays one year after release even if the member dies during that interval. The terminal ledger includes these payments and their deterministic growth, including for stopped paths.

The 39-year closed-pool stop frequency is not an annual probability, a forecast for an open pool, or a general FTP failure rate. Pool-size comparisons combine finite-pool behaviour with different fixed heterogeneous cohort compositions.

Comparators, conditioning and uncertainty

The proper unpooled comparator uses the same £100,000 with its own allocation for a level investment-only CE target. It has the same investment model and monthly shocks. It is paid without a mortality commitment, so its assets remain the owner's or estate's. It is not optimised drawdown, an annuity or a priced guarantee.

A second series uses exactly the same survival-weighted opening allocation as the pooled case but turns transfers off. This isolates the contribution of credits to that underfunded ladder. Its late low payments must not be presented as the best unpooled pension £100,000 can buy.

For each rung:

  • Eligible count: focal member would be alive at release, based on their independently generated lifetime, including paths whose pool has already stopped.
  • Completed count: that eligible rung was actually released before a research stop.
  • Stopped-eligible count: eligible but not completed.
  • Coverage: completed divided by eligible, with null if there were no eligible samples.
  • FTP p05, median, p95 and CE: conditional on eligibility and completion. They are not unconditional pension outcomes. No zero payout is silently assigned to retained assets, and no failed eligible path is silently removed from coverage.

The comparator is reported both on those exact completed paths and on all release-eligible paths. Its all-market-path statistics are also included. The CE uses gamma=3 and is a conditional moment of the simulated cash payments. Its standard error is the delta-method Monte Carlo error. Neither this standard error nor the p05–p95 range is an allowance for model, calibration or policy uncertainty. In late rungs, very few eligible lives make both percentiles and CE estimates unstable. A chart's annual medians do not describe one person's lifetime path.

Data and accounting

The source and results package contains the files described below. summary.json records the aggregate results. rung_funding.csv and funding.json retain the deterministic comparison. For every pool:

  • pool_N_cohort.csv: member ages, capital and hazards.
  • pool_N_paths.csv: each whole-pool path's stop, retained assets, scheduled payments from released assets, returns, transfers and numerical residuals. The raw paid field means eventual payments on all assets released before the stop; it is not cash already paid at the stopping date. The raw alive_end field means membership remaining when the calculation stops; at a pre-transfer stop it includes the unresolved deceased member, and is not a final-date survivor count.
  • pool_N_rungs.csv: each rung's conditional statistics, counts and comparators.
  • pool_N_focal_outcomes.csv: all path-by-rung focal eligibility/completion/payment results, including gaps and both comparators.
  • pool_N_example_events.csv: every observed death/transfer, annual release and research stop on the example path, with current fairness and conservation errors.
  • pool_N_example_releases.csv: that focal member's initial principal, investment return on it, receipts allocated to the rung, return on those receipts, release value and following distribution-year return. These components sum to the actual payment. The beneficiary flag identifies payment after the member's death.

The example is the first numbered path where the focal member survives to the final release date. This selection makes a long ladder visible; it does not make the path representative, successful or typical. A pool can still stop on that path. Whole-pool accounting checks

opening capital + unreleased investment gain + full scheduled distribution investment gain = scheduled payments from released assets + retained unreleased assets.

This is an accounting identity across known cashflows at their stated dates, not a common-date valuation or a statement of cash already paid at a stop. It includes deterministic growth and eventual payments on money already released, which can fall after the stop. Transfers do not create an extra asset in that identity. A retained balance at a research stop is valued at the stopping time and receives no invented future investment or distribution rule.

What this does and does not establish

The deterministic funding calculation demonstrates the mechanism and states the price of giving up unreleased estate rights. The simulation then asks how a particular finite heterogeneous policy behaves under precisely stated investment and mortality assumptions. It records current numerical fairness, transfer conservation, actual payments and uncompleted eligible rungs separately. It does not convert those observations into a proof of a complete fair pension contract, or an investment recommendation.

The next substantive comparison is between reinvestment and admission/distribution policies that preserve both member fairness and acceptable late income coverage, with calibrated mortality, more tail observations and explicit terminal rights. A jointly specified policy must then be tested against correlated mortality, revised hazards, new entrants, market stresses and all relevant settlement batches.

Reproduction

Tested with Python 3.12.13, NumPy 2.3.5 and SciPy 1.17.0. Download and extract the source and results package, install the packages in requirements.txt, then run from its root directory:

OPENBLAS_NUM_THREADS=1 python ladder_simulation.py --paths 1000 --pools 50 200 500 --output results

--paths 2 provides a short execution check, not a research result. The production experiment uses 1,000 independent market/mortality paths for each of three fixed cohorts. The base seed is 2026090717; streams are separated by path, pool size and purpose. NumPy's default_rng supplies PCG64. Changing the pool size creates a different fixed cohort and mortality stream; the 1,000 paths are not 1,000 different demographic compositions. Floating-point/platform differences can alter final digits or a state very close to a stopping boundary.