Self-selection and risk sharing in a modern world of life-long annuities

Abstract Communicating a pension product well is as important as optimising the financial value. In a recent study, we showed that up to 80% of the value of a pension lump sum could be lost if customer communication failed. In this paper, we extend the simple customer interaction of the earlier contribution to the more challenging lifetime annuity case. Using a simple mobile phone device, the pension customer can select the life-long optimal investment strategy within minutes. The financial risk trade-off is presented as a trade-off between the pension paid and the number of years the life-long annuity is guaranteed. The pension payment decreases when investment security increases. The necessary underlying mathematical financial hedging theory is included in the study.


Introduction
It has long been a hen-and-the-egg question in modern pension product development to decide where to start alleviating the many problems with opaque products that most people fail to understand. Many pension savers end up receiving suboptimal pension products that might be optimal for other people. An obvious reason for this is the poor communication. Pension communication has been notoriously difficult due to opaque products and cases with contradicting interests between pension providers and pension receivers. Also, financial advice is expensive and becomes even more so if it is based on opaque products with contradicting interests. An extreme solution to this financial advice question is to give all customers the same one-size-fits-all product. Another extreme is to let the pension saver make all the important investment decisions, even when he is not educated enough to carry out such a difficult financial optimisation.
This paper provides a simple intuitive framework that most pension savers would be able to understand. Within a few minutes, the pension saver should be able to select the optimal investment strategy *Correspondence to: Jens P. Nielsen, Faculty of Actuarial Science and Insurance, Cass Business School, City, University of London, London EC1Y 8TZ, UK. E-mail: jens.nielsen.1@city.ac.uk based on individual preferences of financial risk. Our main point is that, during this task, it is not necessary or relevant to know about the complicated underlying financial mathematical hedging. We suggest solving the financial communication problem of the risk of life-long pension annuities by changing the way that pension products are constructed, so that there is a one-to-one fit between the simple communication and the complicated underlying financial hedging. We believe we offer a genuine solution to the pension crisis challenge articulated by Merton (2014). We are not aware of any other solution enabling the pension saver to design the entire investment guarantee within a few minutes via a simple question that the pension saver can understand. Many alternative pension designs might be possible in future developments with the same set of positive features. Therefore, the reader should not dwell too long on our particular design, but on the fact that pension annuity products can be constructed in a way that pension savers can make informed decisions. Our specific solution incorporates many of the suggested pension principles in Merton (2014), shaped in a format that is simple to implement. Our approach builds on the recent research by Gerrard et al. (2017 and Donnelly et al. (2018) where similar tools and investment strategies are provided for the simple lump sum case. Gerrard et al. (2017 provide an example of a risk-averse investor who could lose up to 80% of his savings, calculated in certainty equivalents, if mistaken for a riskier investor. This paper introduces an approach where the pension saver picks his own risk appetite in a simple way that also exactly back-calculates the pension saver's optimal investment strategy. A major difference from the existing pension offers is that the pension saver picks the pension product directly without translation. The pension saver's decision has a one-to-one relationship with the financial investment strategy. Most existing pension products would let the pension saver decide whether he is, for example, of high, medium or low risk. The financial institution then translates the pension saver's message into an investment strategy, but the pension saver's real interests might be lost in such a translation. Our pension design provides the pension saver with the exact investment strategy he asks for. In addition, the pension saver might change his investment strategy: the financial question can be posed again at any given time, perhaps on a yearly basis, and the pension saver might then either adhere to the original or update the strategy based on his risk preferences at that time. The rest of the paper is organised as follows. In section 2, we explain how the communication of the simple lump sum can be generalised to the more complicated life-long annuity case, without compromising on the simplicity of financial advice, by diving into individual customer Emma's perspective. Section 3 highlights the differences from the classical defined contribution (DC) scheme. Section 4 discusses various details of the pension product. Section 5 presents the stochastic model. Section 6 and the Appendices provide all the mathematical details of the pension product.

The Pension Product from Customers' Perspective
Emma is 35 years old and wants to invest £300,000 received from an inheritance. The investment should cover a real annuity income after her retirement at age 65. The actuaries need to handle the underlying mortality, inflation and investment risk. We require a product that can be presented in a way that allows her to select her optimal strategy in consistency with her financial risk preferences. Our solution is communicated to her in the following simple way: • What is your age, when do you want to retire and what is the amount you want to invest? (See also • Half of the time your income will continue life long at a fixed high level. The other half of the time, it will continue life long at some level between the targeted high level and zero pension. Figure 2a shows the slider Emma can use in order to see the trade-off between the length of guarantee and monthly benefit size. All amounts are in real terms, i.e. in today's values, subject to future increases with inflation. This facilitates communication as the amount can be compared with today's purchasing power. Emma can choose between no guarantee, mimicking a classical financial product or a life-long guarantee, mimicking a deferred annuity and hence no exposure to risk. The accompanying percentage states the chance of ending up with the worst-case scenario of hitting rock bottom zero pension once the guaranteed pension income period is over.
Imagine that Emma chooses a guarantee period of 10 years providing her a monthly real income of £2,453 until at least the age of 75. If investments go well, with a 50% chance, the monthly payments of £2,453 will continue life long. However, there is also the worst-case scenario, with a probability of 22%, that Emma's pension income will run out when she reaches 75 years of age. In the remaining 28% case, Emma's life-long annuity will continue with payouts lower than the targeted £2,453. One could imagine that Emma would safeguard herself to minimise the consequences of such an unfortunate investment performance. She could, for example, incorporate the value of her house when reaching 75 years of age, or buy a second product, perhaps a smaller annuity starting when she is 75but then with a life-long guarantee. The annuity option in this paper could be considered as a building block in a more diverse financial planning of the particular household economy Emma faces. It is beyond the scope of this research to illustrate how a wide array of annuities could provide a flexible financial tool for individual households' financial planning.
In Figure 2b, we see the trade-off between length of guarantee and monthly benefit Emma faces. Note that if Emma did not want any guarantee, her most likely pension outcome would exceed £3,000 a year. Alternatively, if Emma wanted absolute lifetime certainty, the guaranteed income would be below £1,500. Emma can gain a lot by taking the risk of not buying a guarantee, and such should be made clear to her via the graph provided. Emma can also discover that by increasing the age at which pay-outs start in Figure 1, a life-long annuity becomes substantially cheaper. Figure 1. The customer prespecifies some points for the pension product. The age is used to determine the mortality rate.
Self-selection and risk sharing in a modern world of life-long annuities

Comparison with Traditional-DC Scheme
In this section, we compare the proposed pension product to a typical DC scheme where at retirement the lump sum is converted to an annuity.

Guaranteed Income
In the DC scheme, the pensioner is exposed to (a) risk from the financial market, i.e. investment performance in nominal terms, (b) inflation risk, i.e. uncertain development of average living cost and (c) mortality risk, i.e. fluctuations of the annuity price at retirement. These three risks make the final pension hard to predict. Financial planning is, therefore, a challenge for most pension savers holding traditional DC schemes. Our proposed pension product has a clearly stated minimum monthly income, expressed in real terms, aiding the financial planning.

Performance
We highlight two areas where our suggested pension product seems to outperform the classical DC scheme. First, in DC schemes, risky investments cease at retirement, whereas in our product investments stop at the end of the guarantee period. Those extra years of investment provide our pension saver with either a higher average return or a lower risk. This is because our pension saver This then determines the size of the monthly benefit and the probability of a zero pension after the guarantee period. The bottom figure shows the trade-off between guarantee and monthly benefit. In our example, Emma chose a guarantee of 10 years that yielded a monthly real income of £2,453 after retirement.
R. Gerrard et al. has more years to diversify the financial investment risk. Second, in our proposed life annuity product, the pension saver receives additional returns equal to the mortality rate. The full transparency of our pooled mortality provides our pension saver with a significant extra life-long return. In a DC scheme, the added mortality return is opaque and hidden, hence it is expected to be on the lower side. Both features of our product are expected to result in a significantly higher final pension, which is the direct financial benefit. More importantly, there is also an indirect benefit stemming from the fact that our pension saver is more likely to pick the financial risk profile sought, see next.

Communication
In a classical DC scheme, it is necessary to determine the risk preferences of the pension saver. This is usually done indirectly by means of a procedure that is unrelated with the actual pension, raising the chance of miscommunication and investment in assets that do not fit the actual needs. In our proposed product, the pension saver can directly pick the level of risk sought. He can directly see the trade-off between guarantee and monthly benefit and can pick anything between a no-guarantee product with highest monthly pay-out and a deferred annuity which bears no risk but at the same time gives minimal monthly income. He can also buy more than one product, for example a deferred annuity that starts paying out at age 85 as well as a 20-year guarantee starting at 65. Finally, the choice can be changed at any time by either taking (parts) of the money out or changing the guarantee period.

The Customer Reveals His Risk Appetite
In the above example, Emma revealed her risk appetite in much the same way as proposed for the lump sum case in Gerrard et al. (2017. By specifying the required guarantee length, Emma directly specifies her financial risk appetite. A subsequent simple back-calculation provides us with Emma's optimal investment strategy. We are in the fortunate situation that the single most important financial risk question Emma faces is one that she understands, is directly linked to her pension, and she can give an immediate answer to: she wants 10 years of guarantee. Perhaps, this is due to children finishing education by then, and her willingness to sell her house when she is 75 renting a smaller apartment instead. Selling the house would only be necessary if investment income turned out to be too disadvantageous. This is rather unlikely and Emma may maintain her current lifestyle without having to withdraw further from her assets including her house. From a regulatory perspective, the pension provider selling the annuity has a full record, for future control purposes, of the financial communication: Emma answered the simple question posed to her with a 10-year period of guarantee ending at the age of 75. The one-to-one fit between communication and pension product drastically reduces the burden of recording the financial advice.

Annuity Principle
The pension system introduced in this paper uses the annuity overlay fund introduced in Bräutigam et al. (2017) and motivated by Donnelly et al. (2013Donnelly et al. ( , 2014 and Stamos (2008). As the authors point out, while the pooled annuity overlay fund includes the word annuity, the concept is quite distinct Self-selection and risk sharing in a modern world of life-long annuities from that of a standard life annuity. The main difference is that longevity risk is not transferred to an insurer, but is shared, instead, among the members of the pension fund. The result is an annuity that is transparent in its costs and is actuarially fair.
Whenever an individual in the pension fund dies, his wealth is distributed to the survivors in an actuarially fair way, i.e. at every instant the expected gain (gain when someone else dies less loss of wealth if own death occurs) is zero. Given that the pool is large enough (e.g. 1,000, refer to Donnelly et al., 2013Donnelly et al., , 2014 for how surprisingly small these annuity pools need to be), the mortality gains are given by where X i is the wealth of individual i and λ i (t) the individual's force of mortality. The relative annuity gains with magnitude λ i (t) coincide with the growth rate of a fairly priced life-long standard annuity, hence longevity risk is automatically hedged. If Emma reaches the optimal investment scenario, which happens most of the times, the payouts will continue life long.

The Overall Principle of Hedging and the Importance of Technical simplicity
The most important feature of our new class of pension products is the straightforward communication. Another obvious advantage is its simple technical implementation that will help minimising technical errors from actuarial and financial offices. The simplicity will ensure that actuaries and financial experts are on top of things so that a one-to-one fit is achieved between what actuaries and financial experts tell other departments and the board of directors and what these interested agents actually get. The hedging strategy can be expressed in terms of a simple probability that actuaries immediately understand. The optimal investment strategy before introducing risk sharing is given by investing the amount in the risky fund, where μ is the average mean return on the risky asset, r the average inflation per year, t the time passed since commencement, T i the time from commencement until the end of the guarantee period, λ i the force of mortality of individual i, X Ã i the wealth of individual i following an optimal unconstrained strategy, P i ð0Þ the initial price of the hedge, and G Ui ðT i Þ the actuarially fair price at T i for a life-long annuity; refer to section 6 for further details.

How Risk is Pooled
In what follows, our pension saver can invest only in an inflation fund or a risky fund. We assume that both have some risk that has to be taken into account in the financial hedge of the underlying long-term target. In Gerrard et al. (2017, it is assumed that a risk-free inflation fund exists at any given time. Here, we relax this assumption and allow some risk involved when hedging inflation. Most of the time this is not a concern as pension savers can adjust their investments and maintain the same level of risk as if the inflation fund were risk-free (see section 4.4). However, in some rare cases R. Gerrard et al. individuals want less risk than the safest option. This can be, for example, the case when 100% in the inflation fund still bears too much risk. The individuals can then take advantage of being part of a group. More specifically, the individuals' lack of risk appetite can be circumvented by transferring risk to the rest of the group with a risk appetite (see section 4.4). Finally, in extremely rare cases the entire group loses its aggregate risk appetite, rendering the inflow of investments with risk appetite necessary. This implies the need for an intermediary whose role is described in section 4.4.

Individual
Once the individual has specified the length of his guarantee period, an optimal financial hedge is back-calculated. The financial hedge is based on a risk-free inflation fund and a risky fund. It implies at every point in time a certain risk appetite and an optimal level of inflation hedge. When considering a risky inflation fund, those levels can be recovered by adjusting the proportions of the investments. This result is obtained by lowering the level of investment in the risky fund until the risk appetite from the financial hedge is achieved. This implies a slight increase of the investment in the risky inflation fund compared to the original investment in the risk-free fund.

Group
In rare cases, the risk appetite of the individual is so small that risk has to be transferred from the individual to the group. The group, then, chooses, as a solidarity of being part of the group, to borrow money at the risk-free inflation rate and include it in its investments. This allows our pension system to work almost frictionless.

Intermediary
In extremely rare cases with insufficient risk appetite in the group to cover the risk in the inflation fund, an intermediary provides capital with risk appetite. Note that the only promise the intermediary makes is to provide risk capital close to the market value. Therefore, it does not cost much to participate. Even so, the intermediary is allowed to charge some administration cost for being the "market maker" to ensure that risk appetite is available at all times and, therefore, ensure the underlying guarantee.

The Stochastic Model Underlying the Financial Hedge
In this section, we present the financial model used for the financial hedging. We choose the simplest possible such model for the sake of transparency, noting that this research output is not aiming for optimal financial modelling. While in this paper we are concerned with connecting investment strategies with annuities and achieving a one-to-one communication to the customer, let us for a second assume that we change the underlying financial model. The financial hedge is about the target income and the length of the guarantee. Changing the financial model is expected to only slightly affect the size of the forecasted target income for given guarantees, however the decision of the pension saver remains more or less of the same nature; this approach seems robust under underlying financial model variations. Therefore, we pick the simplest most transparent model comprising a risk-free inflation fund S 0 ≡1-note that we operate in real terms-and a risky fund S 1 described via dS 1 ðtÞ = μS 1 ðtÞdt + σS 1 ðtÞdWðtÞ; (1) where μ, σ > 0, S 1 (0) = 1 and W is a standard Brownian motion.
Note that the financial model (1) is simpler than the investment universe provided to the pension customer consisting of a risky asset and an inflation fund, where also the latter carries some risk. The Self-selection and risk sharing in a modern world of life-long annuities risky inflation fund is expected to be constructed in a way that over the long run at least a return of inflation is obtained plus an additional return corresponding to the risk taken in the risky inflation fund. In section 6.5, we will see that a risk transfer can be made from the real investment universe of a risky inflation fund and a more risky fund to the artificial investment universe of a risk-free inflation fund and a risky fund. The transfer simply looks at the risk that the financial hedging strategy suggests and downplays the risky fund a little bit while upgrading the risky inflation fund a little bit. This is done until the pension customer has the same risk-return profile, as suggested by the very simple transparent financial model (1) consisting of an infeasible risk-free inflation fund and a risky asset.
In the example of section 2, we assume μ = 0:0337; σ = 0:1538; corresponding to 1-year mean returns and standard deviations of 3.43% and 16% for the risky asset (see equations (10) and (11)). The 3.43% return and 16% volatility of the risky asset are from Guillén et al. (2006), based on the empirical results in the book "Triumph of the optimist" (Dimson et al., 2002). In order to price a pension product, the pension provider requires an estimate of the mortality rate, λ(t), of the customer. In Figure 1, this is done by asking for customer's age. In practice, one may consider more covariates aiming to achieve a better estimate, however such is beyond the scope of this paper. For illustration purposes, we choose for simplicity the mortality rates from the National Life Tables, England, for females in the period 2013-2015 Office for National Statistics (2017). By using this data, we implicitly assume no future period effect on the mortality rates. Again, adopting a more realistic model is possible, but not the focus of this paper. Other information the pension provider receives is the amount of money that the customer wants to invest and the time when payouts should start.
To derive a customer-tailored pension product, it is important to communicate correctly the risk appetite of the customer. Following Gerrard et al. (2017, it is possible to describe the risk appetite with only one parameter that the customer understands. This is in contrast to an abstract risk aversion parameter of a utility function which is hard to communicate. In Gerrard et al. (2017, it is shown that, by specifying a minimum amount the pensioner wants to have guaranteed, an optimal investment strategy can be back-calculated, yielding a practically optimal performance specific to the customer's risk appetite. In section 6.3, we extend this result to the annuity case in which the customer now chooses how long he wants payouts guaranteed. From equation (8), one can then calculate the corresponding size of monthly payouts, so that there is a 50% chance that these continue life long after the guarantee period.
Note that the money paid in should be invested as long as possible. In particular, investments should not stop at retirement, as such would lead to significant losses in expected performance. In our implementation, we choose the investment to last to the end of the guarantee period. A longer investment horizon is not directly possible as it is a priori not known how long the money on the pension account will last. The customer himself is not concerned with these details and only sees Figure 2, visualising the trade-off between guarantee length and monthly benefit size. Once the decision is made, the pension provider is left with an investment strategy due to be implemented.
Whenever an investor in the pension fund dies, his wealth is distributed according to formula (4). The distribution of wealth is actuarially fair, meaning that, given the individual's mortality rate, the expected gain at every instant is exactly zero. Note that gains occur if others in the fund die and a R. Gerrard et al. loss occurs with own death, the full wealth being redistributed. In Proposition 1, we show that in a large pension pool, payouts from it have little volatility and the extra return from entering the annuity scheme is very close to the mortality rate, λ(t).
The theoretical optimal investment strategy is derived in a Black-Scholes world, hence needs to be adjusted to account for model (1). The main idea is that the strategy is adjusted in a way that the calculated optimal risk exposure from the Black-Scholes world is preserved. This is straightforward to do as long as all individuals in the pension fund have enough risk appetite for the adjustment to be feasible, i.e. equation (13) is fulfilled for everyone. If equation (13) is violated for an individual, the risk-sharing principle kicks in: those with sufficient risk appetite in the pension fund offer those who lack risk appetite a risk-free inflation return; refer to section 6.5.1 for more details. The result is that via this risk-sharing principle, everyone maintains the same risk as derived from the Black-Scholes world.

The Full Investment Model Including Mortality Risk
In this section, we incorporate mortality in our financial model. While almost any approach to mortality risk can be combined with our new pension design, we have particular preference for the modern risk-sharing approach of Bräutigam et al. (2017) as there are no hidden costs in it to the customers that cover each other's risk almost without any long-term cost. But again, what follows aims to just illustrate that it is possible to provide an easily communicated pension design including mortality risk. Just as our pension design itself may have several variations with similar positive properties, the underlying mortality approach used for the annuity may also take different shapes without compromising on our overall ideas of a simple pension product that is easy to communicate and where the entire investment strategy can be back-calculated from a short conversation with the pension saver. As pointed out in section 5, we will start with two assets: a risk-free inflation bond S 0 and a risky asset S 1 . The financial hedging principle is based on this simple model; mortality risk will be incorporated in section 6.2. The real investment universe the pension customer faces has a risky inflation fund rather than a risk-free inflation bond. Therefore, there is some risk transfer adjustment to be done, so that the pension saver can maintain the risk-return relationship that the financial hedging suggests. This is carried out in section 6.5.

Two Asset Case: Inflation Fund and Risky Fund
Let us first restate our simple transparent financial model used for financial hedging. There are two assets: a risk-free inflation bond, S 0 , and a risky asset S 1 , described by dS 0 ðtÞ = rS 0 ðtÞdt; dS 1 ðtÞ = μS 1 ðtÞdt + σS 1 ðtÞdWðtÞ; t ≥ 0 where μ, σ, r > 0 and S 0 (0) = S 1 (0) = 1. The only source of randomness is the standard Brownian motion, W, defined on a complete probability space ðΩ; F ; PÞ. The information available to the investor is represented by the filtration F t = σfWðsÞ; s 2 0; tg _ N ðPÞ, where N ðPÞ denotes the collection of all P-null sets so that the filtration obeys the usual conditions. We denote by X i (t) the amount of wealth invested by individual i in the fund at time t, of which π i (t) is invested in the risky asset and the remaining in the risk-free asset. There is also a deterministic stream of payments into where θ = (μ − r)/σ is the market price of risk.

Adding Pooled Mortality Gains
Next, we consider a fixed, deterministic rate of mortality and the risk pooling principle of Bräutigam et al. (2017), and explain how actuarially fair mortality gains can be incorporated in our pension system. In this attempt, we make two assumptions: A1 The mortality rate of the individuals is known, with no extra parameter uncertainty.

A2 The pension fund has an infinite number of individuals.
We denote the mortality rate of individual i by λ i (t). Whenever an individual in the pension fund dies, his remaining wealth is distributed to the survivors in the pension fund. We denote by LðtÞ the index set of people alive at time t. The wealth is distributed in an actuarially fair way. Assume that individual j is alive at time t − . If he dies at time t, then the surviving pension saver i≠j receives where A is an adjustment factor implicitly defined by equation (A1) which converges to zero with growing pool size. More precisely, the individual mortality gains at time t, when individual j dies, are given by dH i ðtÞ = λiðtÞXiðtÞ 1 + AiðtÞ ½ P l2LðtÀÞ λ l ðtÞX l ðtÞ 1 + A l ðtÞ ½ where the case i = j is derived as a consequence of the definition of A.
Proposition 1. The expected mortality gain at every instant is given by hence wealth is distributed in an actuarially fair way. In addition, conditional on surviving, the expected mortality gain is given by Then, with growing pool size, the variance of the actuarial gains converges to zero and the expected gains, conditional on not dying, to λ i (t)X i (t)dt.

Proof. See Appendix A. ∎
In the following, we assume that the pool size is large enough so that any noise can be ignored. Then, if the financial model (3) of the previous section is combined with the annuity pool, as long as the individual is alive the development of wealth is given by This means that when an optimal strategy π i is considered, such should incorporate the additional gains λ i (t)X i (t)dt.
Proposition 2. Under model (5), the optimal strategy maximising U(X i (T i )) for an exponential utility function, UðxÞ = Àγ À1 i e Àγ i x , is given by where C i = θ/(σγ i ). Under this strategy, the evolution of the optimal wealth is given by

From Lump Sum to Annuities
When considering a retirement product, the focus should not be on a lump sum but on the monthly income level at retirement and the duration of payment. In this section, we extend the lump sum case to an annuity.
Assume that the pension saver has T 0 i years until retirement. Assume that individual i chooses to have guaranteed payout duration of D i years with payouts of ÀdC i . Payouts stop, however, at the Self-selection and risk sharing in a modern world of life-long annuities time of death. We set T i = T 0 i + D i . Then, the discounted remaining guaranteed amount of payments as at t > 0 is given by where N i has value 1 while the individual is alive, otherwise it becomes 0. We also consider the optimal outcome to be a life-long payout, hence we define the top value based on receipt of payments until death Then, t years from now, is the survival function, i.e. the unconditional probability of surviving until a certain age, and We can now modify the unconstrained strategy of the previous section. The aim is to guarantee the payment stream for a period of D i years, while maximising the chance of getting the payouts life long. Technically, this translates to finding an optimal strategy maximising U(X i (T i )), for a given utility function U, subject to the constraint 0 = G Li (T i ) ≤ X i (T i ) ≤ G Ui (T i ). Note that the optimal strategy will then naturally satisfy that, at any given time, the wealth remains always above the price of an annuity with D i years payout and below a life-long annuity.
Proposition 3. For there exists an optimal strategy yielding wealth X ÃÃ i ðtÞ with Furthermore, it holds for all t ∈ (0, T i ] that G Li ðtÞ ≤ X ÃÃ i ðtÞ + The corresponding optimal strategy is given by where P i ð0Þ is defined via HðxÞ = xΦðxÞ + ϕðxÞ, and Φ and ϕ are, respectively, the standard normal cumulative distribution and density functions.
Proof. See Appendix C. ∎

The Probabilities
In this section, we want to find the monthly payment stream dC i corresponding to monthly constant real income. More specifically, we define C i ðtÞ = À P 12t s = 1 M i e rs = 12 , t > T 0 i and aim to find M i , i.e. the monthly income measured in today's purchasing power, such that where T D i is the time until death, i.e. given that individual i outlives the guarantee period, there is a 50% chance that the payment stream will continue life long. Assuming independence of the time of death and the performance of the investments, we have that , then, in distribution, where Z is a standard normal random variable. Hence, R i ffiffiffiffi ffi T i p 2 6 6 6 4 3 7 7 7 5 dt: Self-selection and risk sharing in a modern world of life-long annuities If C i ðtÞ = 0 for t < T 0 i , the above can be rewritten to

No Risk-Free Asset but an Inflation Fund
We now relax the assumption of a risk-free asset of the previous section. The reason is that nearly risk-free assets, like bonds, provide a certain nominal return, but a pensioner is more interested in a return with respect to his purchasing power at retirement. By subtracting the inflation rate from an investment return, one derives the real return which, however, bears some risk.

Adjusting for extra risk in the inflation fund and the risk sharing principle
To account for the change from the risk-free bond model (2) to the inflation fund (9), we propose an ad hoc adjustment to the optimal strategy (7).
The mean return, μ 1 , and risk, σ 1 , on £1 in S 1 are given by In the same fashion for the case when £1 is invested solely in e S 0 , we derive μ 0 and σ 0 by replacing μ, σ in equations (10) and (11) with e μ, e σ. For the risk-free case, i.e. when investing in S 0 and S 1 , the yearly risk for an individual investing π in S 1 is πσ 1 . When we replace the risk-free fund S 0 by the inflation fund e S 0 , additional risk (and return) needs to be considered. For wealth X and π invested in S 1 , the remaining X − π is invested in e S 0 and the yearly risk is given by Hence, the risk of individual i is preserved by investing π with π 2 σ 2 1 + σ 2 0 À2ρσ 1 σ 0 is well-defined for sufficiently large π ÃÃ i : Condition (13) is violated if the individual does not have enough risk appetite, i.e. the optimal strategy involves less risk than any combination of e S 0 and S 1 can offer. This leads to the risk sharing principle. More specifically, we arrange the people in the pension fund into three groups. Individuals in groups I and J are those with sufficient risk appetite so that equation (13) holdssee later.
Individuals in group K are those with insufficient risk appetite and given the opportunity to invest in the risk-free asset S 0 instead of the risky inflation fund e S 0 . In turn, the inflation fund e S 0 replaces S 1 as the risky fund. By slight abuse of notation, we denote by π ÃÃÃ k , for members of group k ∈ K, the amount invested in e S 0 , whereas the remaining is invested in S 0 . Strategy π ÃÃÃ k is adjusted via the riskpreserving relationship π ÃÃ k σ 1 = π ÃÃÃ k σ 0 : Note that a solution π ÃÃÃ k 2 0; X k ½ exists as the members of group K violate condition (13), hence π ÃÃ k ≤ σ 0 X k = σ 1 .
For the strategy to be feasible, the fund S 0 needs to be created internally in the pension fund. This means that those in group I and J have to short S 0 with the amount required by group K. The aggregate amount that needs to be borrowed by members of I and J is χ = P k2K X k Àπ ÃÃÃ k . The maximum amount individual i ∈ (I ∪ J) is willing to borrow is The members of group J do not have enough risk appetite for a full support. The subgroups of J are defined iteratively, starting with If J 1 is empty, the iteration terminates. Otherwise by the mth iteration, the subgroup J m ⊂J is created: The iteration stops once an empty set is created. We then define J = ∪ l J l . All remaining members of the pension fund are allocated to group I = ðJ ∪ KÞ { . The final strategies for members of I and J are as follows: π ÃÃÃ l in S 1 , − q l in S 0 and the remaining in e S 0 ; q l = ξ l for members of J, whereas for members of I. Finally, π ÃÃÃ l satisfies (12) when X l is replaced by X l + q l .

Appendix A. Proof of Proposition 1
The death of an individual is modelled by a counting process N i (s) with value 1 indicating that the individual is alive. By definition, the counting process has intensity lim h#0 h À1 E N i ðt + hÞ À À Á ÀN i ðt À Þ j F tÀ Â Ã = λ i ðtÞ1 fi alive at tÀg : Hence, where A j satisfies A j ðtÞ = λ j ðtÞX j ðtÞ 1 + A j ðtÞ Â Ã P l λ l ðtÞX l ðtÞN l ðt À Þ 1 + A l ðtÞ ½ À λ j ðtÞX j ðtÞN j ðt À Þ ; which can be solved iteratively. Feasibility of this strategy is ensured as P where the last equality follows from equation (A1). The expected growth of the gains dH i at time t given that i is alive at t − is given by Based on standard optimal control theory, the optimal value function at time t is given by Vðt; yÞ = sup π E½UðYðTÞÞ j YðtÞ = y; strategy π is used: The Hamilton Jacobi Bellman equation describing the dynamics of V is given by where V t , V y and V yy are the partial derivatives with respect to t and y (first and second order). By utilising the first-order condition in the optimisation problem above, the optimal value of π is π Ã ðt; yÞ = À θ σ e ÀrðTÀtÞÀ Ð T t λðsÞds V y V yy ; hence V satisfies V t À θ 2 2 V 2 y V yy = 0:

Appendix C. Proof of Proposition 3
Lemma. Wealth X ** described in equation (7) is feasible.
Proof. Define the process PðtÞ = X Ã ðtÞ + Pð0Þ; where X * (t) satisfies equation (6). Further, define the martingale measure Q such that W ℚ (t) = W(t) + θt is a standard Brownian motion. Hence, PðtÞ = Pð0Þ + RW Q ðtÞ: Conditional on the history of the process up until time t > 0, PðTÞ = Pð0Þ + RðW Q ðtÞ + ffiffiffiffiffiffiffiffiffi TÀt p ZÞ; where Z is a standard normal random variable under Q. We note that PðTÞ > G U ðTÞ , W Q ðtÞ + ffiffiffiffiffiffiffiffiffi TÀt p Z > R À1 G U ðTÞÀPð0Þ ð Þ , Z > d U ; where d U = 1 ffiffiffiffiffiffiffiffiffi TÀt p R À1 G U ðTÞÀPð0Þ ð Þ À W Q ðtÞ Â Ã and, similarly, we have that P(T) < G L (T) is in distribution equivalent to Z < d L with The price of Y ** (T) = X ** (T) at time t is given by the present value of wealth at time t under Q: Self-selection and risk sharing in a modern world of life-long annuities As H ' (x) = Φ(x) ∈ (0,1) and d L < d U , we deduce that 0 ≤ Hðd U ÞÀHðd L Þ ≤ d U Àd L = 1 ffiffiffiffiffiffiffiffiffi TÀt p R À1 ðG U ðTÞÀG L ðTÞÞ: Returning to the standard measure ℙ, we can write both d L and d U as functions of t and w = W(t): ; ∂d L ∂w = À 1 ffiffiffiffiffiffiffiffiffi TÀt p ; and similarly for d U . By exploiting the expressions for d L and d U , we rewrite Y ** (t) = η(t,W(t)), where η satisfies We now prove that it is possible to choose P(0) in such a way that the budget constraint X(0) = x 0 is satisfied. The budget constraint is Yð0Þ = ηð0; 0Þ = G U ðTÞÀR ffiffiffi ffi T p H R À1 G U ðTÞÀPð0Þ ffiffiffi ffi T p ÀH R À1 G L ðTÞÀPð0Þ ffiffiffi ffi T p ! R. Gerrard et al.