If you sponsor a retirement plan large enough to require an annual employee benefit plan audit, the rules that govern that audit changed substantially under Statement on Auditing Standards (SAS) No. 136. The most visible change involves what used to be called the “limited scope audit.” It is now the ERISA Section 103(a)(3)(C) audit, and the election that triggers it carries responsibilities that fall squarely on you as the plan administrator, not on your auditor.
This is not a cosmetic rename. SAS 136 reframed the engagement, redefined the opinion your auditor issues, and made clear that the plan administrator owns the threshold decision about whether the election is even permissible. Getting this wrong can lead to a rejected Form 5500 filing and Department of Labor (DOL) scrutiny.
Quick answer: The ERISA Section 103(a)(3)(C) election lets a plan administrator instruct the auditor not to audit investment information that a qualified institution (a bank, trust company, or insurance carrier regulated and examined by a federal or state agency) has certified as both complete and accurate. Under SAS 136, this is no longer a “limited scope” audit and no longer produces a disclaimer of opinion. The auditor now issues a two-part opinion, and the plan administrator is responsible for confirming the election is permissible, that the certification meets DOL requirements, and that the certified information is properly presented in the financial statements.
What Is the 103(a)(3)(C) Election?
ERISA gives a plan administrator a limited option: when plan assets are held by a qualifying financial institution that certifies the investment information, the administrator may instruct the independent qualified public accountant (IQPA) to exclude that certified investment information from the scope of the audit. The DOL confirms this in its auditor selection guidance, noting that federal law “permits the administrator of an employee benefit plan to limit an audit when plan assets are held by banks or insurance companies and written certifications are provided by the institutions holding those assets” (dol.gov).
The mechanics live in the DOL regulations at 29 CFR 2520.103-1, with the limitation-on-scope rule in 29 CFR 2520.103-8 and the certification requirements in 29 CFR 2520.103-5. You can read the underlying regulation directly at the Legal Information Institute. The election does not reduce your filing obligation. It narrows the auditor’s testing of investments that a regulated custodian has already certified.
The label matters because it signals what changed. Before SAS 136, practitioners and the DOL referred to this as the “limited scope audit,” and the auditor responded with a disclaimer of opinion because so much of the financial statement detail sat outside the audit scope. SAS 136 retired that framing for periods ending on or after December 15, 2021, replacing the disclaimer with a structured two-part opinion. The distinction is practical, not academic: it changes what your auditor must do and what your filing will say.
Why Did SAS 136 Replace the Limited Scope Audit?
The American Institute of CPAs (AICPA) Auditing Standards Board issued SAS 136 to improve the quality and transparency of employee benefit plan audits. The change responded in part to DOL studies finding uneven audit quality across the profession, including DOL assessments that a meaningful share of plan audits contained deficiencies. SAS 136 is effective for audits of ERISA plan financial statements for periods ending on or after December 15, 2021.
The central reporting change is direct: making the 103(a)(3)(C) election is no longer treated as a scope limitation. Instead of a disclaimer, the auditor issues a report with two opinions. One opinion addresses whether the information in the financial statements not covered by the certification is presented fairly. The other addresses whether the certified investment information in the financial statements agrees to, or is derived from, the certification provided by the qualified institution.
That second opinion is the key shift. The auditor is no longer silent on the certified investments. The auditor must perform specific procedures to confirm the financial statement amounts trace back to what the qualified institution certified, and must read the certification to confirm it covers both completeness and accuracy. A certification that addresses only one of the two does not qualify. This is a frequent deficiency the AICPA flags, and it is one you should catch before the audit begins.
The result is a report that gives the DOL and plan participants more information than the old disclaimer did. Under the prior model, a reader saw a disclaimer and had little insight into the certified investments. Under SAS 136, the auditor states plainly whether the certified figures tie back to the institution’s certification, which makes the filing more useful and harder to fault.
What Are Your Responsibilities as Plan Administrator?
SAS 136 shifted several determinations onto the plan administrator and made them preconditions to the engagement. These are not optional courtesies. The auditor will require written acknowledgment of them, typically in the engagement letter and the management representation letter. If you cannot satisfy them, the auditor cannot perform a 103(a)(3)(C) audit, and the engagement reverts to a full-scope audit.
Your core responsibilities under the election include the following:
- Determine that the election is permissible. You must confirm the investment information is prepared and certified by a qualified institution as described in 29 CFR 2520.103-8, and that the institution is one ERISA recognizes: a bank or similar institution, or an insurance carrier, that is regulated, supervised, and subject to periodic examination by a federal or state agency.
- Confirm the certification meets DOL requirements. The certification must be in writing, signed by a person authorized to represent the qualified institution, and must certify both the completeness and the accuracy of the investment information under 29 CFR 2520.103-5. A certification covering only accuracy, or only completeness, is not sufficient.
- Maintain a current plan document. You must provide the auditor a current, signed plan document, including all amendments.
- Prepare and fairly present the financial statements. This includes ensuring the certified investment information is measured, presented, and disclosed in accordance with the applicable financial reporting framework. The certification does not relieve you of presentation responsibility.
- Provide a substantially completed draft Form 5500. SAS 136 requires the administrator to give the auditor a substantially completed draft of the Form 5500 prior to the dating of the auditor’s report, so the auditor can read it for material inconsistencies with the audited financial statements.
The thread running through all of these is ownership. The auditor evaluates and reports, but the administrator decides whether the election applies and stands behind the underlying information. Because these determinations require reading custodial certifications against the specific regulatory text and reconciling them to the financial statements, many sponsors lean on their CPA firm’s audit and assurance services to vet the certification language before the engagement letter is signed.
How Does the Audit Threshold Interact With the Election?
The election only matters if your plan requires an audit in the first place. Generally, federal law requires plans with 100 or more participants to file an audited Form 5500. A separate DOL rule changed how you count those participants, and it affects which plans cross the threshold.
For plan years beginning on or after January 1, 2023, the DOL counts only participants with an account balance at the beginning of the plan year for purposes of the large-plan audit requirement, rather than all eligible employees whether or not they participate. The DOL estimated this change moved roughly 19,500 plans below the large-plan threshold, removing the annual audit obligation for many of them. If your plan still files as a large plan, the 103(a)(3)(C) election remains available to streamline that required audit when a qualified institution certifies your investments.
A transition rule continues to apply at the margin. Under the long-standing 80-120 participant rule, a plan that filed as a small plan in the prior year may continue to file as a small plan, and skip the audit, as long as participant counts stay below 121. Once a plan crosses into large-plan status, the audit requirement attaches, and that is where the 103(a)(3)(C) election becomes relevant.
Plan sponsors who want help confirming participant counts, reconciling payroll to contributions, and producing clean, audit-ready financial statements often coordinate that work through ongoing client accounting services so the records hold up under the auditor’s procedures. Strong year-round bookkeeping reduces audit friction regardless of whether you make the election.
Common Pitfalls That Derail the Election
A handful of recurring issues cause 103(a)(3)(C) audits to stall or fail. First, the certification comes from an entity that is not a qualified institution. A recordkeeper or third-party administrator that is not a regulated, examined bank or insurance carrier cannot provide a qualifying certification, even if it produces the investment statements.
Second, the certification language is defective: it omits the signature of an authorized representative, fails to certify both completeness and accuracy, or covers only a portion of the plan’s investments. Third, the administrator treats the election as a way to avoid responsibility for the numbers. The election narrows the auditor’s testing of certified investments, but you remain responsible for proper presentation and disclosure of those investments in the financial statements.
Catching these before fieldwork begins saves time and cost. Review the certification against 29 CFR 2520.103-5 and confirm the custodian qualifies under 29 CFR 2520.103-8 well ahead of the filing deadline. A short check of the certification at the start of the engagement can prevent a late scramble that pushes a 103(a)(3)(C) audit into a costlier full-scope audit. It also avoids the worst-case outcome: a filing the DOL deems deficient because the limitation was claimed without a valid certification behind it.
Frequently Asked Questions
Is an ERISA 103(a)(3)(C) audit cheaper than a full-scope audit?
It is often less costly because the auditor performs limited procedures on the certified investment information rather than fully auditing it. The savings are not guaranteed, though, because the auditor still performs required procedures on the certification and audits everything not covered by it, including contributions, benefit payments, participant data, and disclosures.
Who can provide the investment certification?
Only a qualified institution as described in 29 CFR 2520.103-8: a bank or similar institution, or an insurance carrier, that is regulated, supervised, and subject to periodic examination by a federal or state agency. The certification must be in writing, signed by an authorized representative, and certify both the completeness and accuracy of the investment information under 29 CFR 2520.103-5.
Does the election change the auditor’s opinion?
Yes. Before SAS 136, the auditor issued a disclaimer of opinion. Under SAS 136, the election is no longer a scope limitation, and the auditor issues a two-part opinion: one on the information not covered by the certification and one on whether the certified investment information agrees to or derives from the qualified institution’s certification.
What happens if the certification is invalid?
If the certification does not meet DOL requirements, or comes from an entity that is not a qualified institution, the plan administrator cannot make a valid 103(a)(3)(C) election. The engagement then proceeds as a full-scope audit, and an improperly limited filing can be rejected by the DOL and trigger further inquiry.




