Employee Benefit Plan Audit: Investing in Your Company

Employee Benefit Plan Audit: Investing in Your Company

An employee benefit plan audit is one of the most important safeguards a company can put in place to protect both its workforce and its fiduciary standing. If your organization sponsors a retirement plan, health and welfare plan, or another benefit arrangement with 100 or more participants, federal law almost certainly requires you to have the plan’s annual report (Form 5500) audited by an independent qualified public accountant. That requirement exists under the Employee Retirement Income Security Act of 1974 (ERISA), and it carries real consequences when it is not followed correctly.

Despite the clear mandate, not all benefit plan audits are performed to the standard ERISA demands. Plan administrators who treat the audit as a routine compliance checkbox, rather than a critical fiduciary function, risk exposing participants to financial harm and the organization to regulatory penalties. The auditor you select directly shapes the quality of the work, the reliability of the findings, and the level of protection your plan receives. This article answers the central question every plan sponsor faces: how do you choose an auditor who actually protects your plan, and what does that audit involve?

What Triggers the ERISA Audit Requirement

ERISA requires this type of audit when a plan is a “large plan” for the year, generally meaning 100 or more participants counted under the applicable method at the beginning of the plan year. The threshold applies to defined contribution plans such as 401(k) plans, defined benefit pension plans, and health and welfare benefit plans. Once a plan crosses that line, the plan administrator must engage a licensed, independent certified public accountant to audit the plan’s financial statements and attach the auditor’s report to the annual Form 5500 filing submitted to the U.S. Department of Labor (DOL).

How you count participants matters, and the rule changed in recent years. For plan years beginning on or after January 1, 2023, a defined contribution plan such as a 401(k) counts only participants who have account balances at the beginning of the plan year, rather than every eligible employee. This methodology change, finalized by the DOL, EBSA, IRS, and PBGC for the 2023 Form 5500, was expected to move roughly 19,000 to 20,000 defined contribution plans out of audit status. Defined benefit pension plans and health and welfare plans still count participants on the broader eligible-participant basis.

The 80-120 rule offers flexibility for plans near the threshold. If a plan filed as a “large plan” in the prior year and has between 80 and 120 participants at the start of the current year, it may continue to file as it did the year before. Once participant count clearly exceeds 120, the large-plan audit requirement is firm. Understanding these requirements early gives plan sponsors time to select an auditor and prepare records rather than scrambling at year-end.

It is also worth confirming which counting method your plan uses before assuming an audit is or is not required. For a 401(k) or other defined contribution plan, the relevant figure is participants with account balances at the start of the year, which now includes retired, deceased, or separated employees who still hold assets in the plan. Misreading this number is one of the most common reasons a plan unexpectedly crosses into, or out of, audit territory.

Common Audit Deficiencies the DOL Has Identified

The U.S. Department of Labor’s Employee Benefits Security Administration has studied the quality of benefit plan audits more than once, and the findings remain sobering. In its most recent audit quality study, released in November 2023 and based on a sample of 307 audits from the 2020 filing year, EBSA found that roughly three out of ten audits contained one or more major deficiencies with respect to Generally Accepted Auditing Standards (GAAS). That 30 percent deficiency rate was an improvement over the 39 percent rate EBSA reported in its earlier 2015 study, which had flagged hundreds of billions of dollars in plan assets and millions of participants as exposed to risk, yet it still means a significant share of plans receive audit work that falls short.

The deficiencies clustered in areas unique to plan auditing, including inadequate testing of participant data and contributions and insufficient evaluation of benefit payments. In many cases the root cause was straightforward: the auditor lacked the specialized experience needed to perform a plan audit correctly. Both EBSA studies made clear that audit quality correlated strongly with how many benefit plan audits a firm performed each year.

Why Deficiencies Persist

Benefit plan audits are not the same as general financial statement audits. They involve unique areas such as participant eligibility testing, contribution allocation testing, benefit payment verification, party-in-interest transaction reviews, and plan document compliance. An auditor who handles these engagements infrequently may not recognize risks that an experienced benefit plan auditor would flag immediately. The DOL’s findings make a strong case that selecting the right auditor is itself a fiduciary act, not a clerical one.

How to Select a Qualified Benefit Plan Auditor

Plan administrators carry a fiduciary responsibility under ERISA to hire an independent qualified public accountant. That responsibility goes beyond confirming that an auditor holds a CPA license. It requires evaluating whether the auditor has the depth of experience, training, and independence necessary to perform a quality benefit plan audit. Treating auditor selection as a careful, documented decision is part of meeting your duty to act prudently.

Independence Requirements

ERISA guidelines require that the auditor be independent of the plan and the plan sponsor. The auditor cannot have a financial interest in either entity that would bias their opinion about the plan’s financial condition. Independence is not optional. It is a foundational requirement that protects the integrity of the audit opinion and, by extension, the participants relying on it.

Experience and Specialization

The more training and experience an auditor has with these engagements, the more familiar they will be with the practices, operations, and specialized auditing standards that apply to benefit plans. Look for firms that are members of the AICPA Employee Benefit Plan Audit Quality Center (EBPAQC), which signals a commitment to ongoing education and peer review in this area. Membership requires firms to meet specific standards designed to improve audit quality.

When evaluating a potential auditor, ask about the number of benefit plan audits they complete each year, the types of plans they work with, and whether they have experience with plans of similar size and complexity to yours. A firm that audits dozens of plans annually will be far better equipped to identify issues than one that handles a handful as a side practice. The same scrutiny you would apply to any major audit and assurance engagement applies here, with the added weight of personal fiduciary exposure.

Key Questions to Ask Your Auditor

The conclusion of audit fieldwork is the right time to ask substantive questions about what the auditor found. Consider asking:

  • Have plan assets been fairly valued in accordance with the plan’s valuation policies?
  • Are plan obligations properly stated and described in the financial statements?
  • Were employer and employee contributions received in a timely manner as required by DOL regulations?
  • Were benefit payments made in accordance with plan terms and participant elections?
  • Did the audit identify any issues that may impact the plan’s tax-qualified status with the IRS?
  • Were any prohibited transactions identified under ERISA, and if so, how should they be corrected?

These questions go beyond surface-level compliance. They help plan administrators understand the operational health of the plan and take corrective action before small issues become costly problems. Building a strong working relationship with experienced risk advisory professionals gives sponsors a clearer view of where their exposure actually lies.

What a Benefit Plan Auditor Examines During the Engagement

A qualified plan auditor performs procedures that go well beyond what a standard financial audit covers. The engagement typically includes testing in several areas unique to benefit plans, each tied to a specific fiduciary or compliance risk.

Contributions and Allocations

The auditor tests whether contributions, both employer and employee, were deposited into the plan trust in accordance with the plan document and within the time frames required by DOL regulations. Late deposits of employee deferrals are one of the most common operational failures in 401(k) plan audits, and they can trigger prohibited transaction reporting. Correcting these failures often requires lost-earnings calculations and, in some cases, filing with regulators.

Benefit Payments and Distributions

Every distribution must conform to the plan document’s terms. The auditor verifies that benefit payments were calculated correctly, paid to eligible participants, and processed in accordance with the applicable plan provisions, including hardship withdrawal rules, required minimum distributions, and loan repayment schedules. Errors in this area can create both tax problems for participants and compliance problems for the plan.

Participant Data and Eligibility

Accurate participant data is the foundation of a well-run plan. The auditor tests whether eligible employees were enrolled in a timely manner, whether census data used for nondiscrimination testing is accurate, and whether terminated participants were handled properly. Faulty census data can quietly invalidate compliance testing that the entire plan relies on.

Party-in-Interest and Prohibited Transactions

ERISA restricts certain transactions between the plan and parties who have a relationship to it, such as the plan sponsor, fiduciaries, or service providers. The auditor evaluates whether any transactions during the year fall into a prohibited category and whether any applicable exemptions apply. Identifying these issues early allows sponsors to pursue correction before penalties accumulate.

Why the Audit Matters for Plan Administrators and Employees

This audit process is not simply a regulatory hurdle. It serves as a safeguard for plan administrators who carry personal fiduciary liability under ERISA, and it protects employees whose retirement savings or health benefits depend on the plan being managed properly. A weak audit leaves both groups exposed.

A high-quality audit uncovers operational errors that can be corrected before they compound. It identifies compliance gaps that could lead to penalties from the DOL or the IRS. And it provides an independent assessment that gives participants confidence their benefits are secure. When errors do surface, sponsors can often resolve them through programs such as the IRS Employee Plans Compliance Resolution System rather than facing the harsher outcome of plan disqualification.

Plan administrators who invest in selecting a qualified, experienced auditor are not just meeting a legal obligation. They are actively protecting the financial well-being of every participant in the plan, and they are documenting that they took their fiduciary duty seriously. For organizations that want a partner across compliance, assurance, and advisory needs, a full slate of accounting services can keep the plan audit connected to the broader financial picture.

Frequently Asked Questions

When Is an Employee Benefit Plan Audit Required?

This audit is required under ERISA when a plan qualifies as a large plan, generally meaning 100 or more participants counted under the applicable method at the beginning of the plan year. For defined contribution plans such as 401(k)s, plan years beginning on or after January 1, 2023 count only participants with account balances, while defined benefit and health and welfare plans count eligible participants. The audit must be performed by an independent certified public accountant and submitted with the plan’s annual Form 5500 filing to the Department of Labor.

What Are the Most Common Benefit Plan Audit Deficiencies?

The DOL’s November 2023 audit quality study found that roughly three out of ten audited plan reports contained major deficiencies related to Generally Accepted Auditing Standards, an improvement over the 39 percent rate reported in its 2015 study. Common issues include inadequate testing of contributions, insufficient review of benefit payments, failure to evaluate participant data accuracy, and incomplete analysis of prohibited transactions.

How Do I Choose a Qualified Benefit Plan Auditor?

Select an auditor who specializes in benefit plan audits, holds CPA licensure, and maintains independence from the plan and plan sponsor. Prioritize firms that are members of the AICPA EBPAQC and can demonstrate significant annual volume of plan audit engagements.

What Is the Difference Between an ERISA Audit and a Regular Financial Audit?

An ERISA audit focuses on areas unique to benefit plans, including contribution timing, benefit payment accuracy, participant eligibility, plan document compliance, and prohibited transaction identification. A general financial audit does not cover these specialized areas and is not sufficient to meet ERISA’s reporting requirements.

What Happens If My Plan Fails Its Benefit Plan Audit?

If the auditor identifies deficiencies, the plan administrator must take corrective action. Issues such as late contribution deposits, improper distributions, or prohibited transactions may need to be reported to the DOL or corrected through IRS voluntary correction programs. Failure to address audit findings can result in penalties and increased fiduciary liability.

Does a 401(k) Plan Need an Audit?

A 401(k) plan generally requires an audit when it is a large plan, meaning 100 or more participants at the start of the plan year. For plan years beginning on or after January 1, 2023, that count is based on participants with account balances rather than all eligible employees, a change that removed the audit requirement for thousands of smaller defined contribution plans. Plans near the threshold may benefit from the 80-120 participant rule, which allows plans that filed as large plans in the prior year to maintain the same filing status if participant count stays within that range.

Let’s talk about your business.