Employee Benefit Plan Audit: Why Qualified Auditors Matter

Employee Benefit Plan Audit: Why Qualified Auditors Matter

An employee benefit plan audit is a critical compliance obligation for organizations that sponsor retirement plans, health and welfare plans, or other ERISA-covered arrangements. Large plans, generally those that cross the 100-participant threshold, must include an independent auditor’s report when filing Form 5500 each year. Choosing the right auditor is not just a regulatory checkbox. It directly affects the quality of the audit, the protection it offers your employees, and the operational insights you gain from the process.

Plan administrators carry fiduciary responsibilities under ERISA, including the duty to hire an independent, qualified public accountant. A poorly executed employee benefit plan audit can expose your organization to Department of Labor enforcement actions, penalties, and potential liability to plan participants. Understanding what makes an auditor qualified, and what questions to ask before and after the engagement, is essential for every plan sponsor.

ERISA audit requirements for employee benefit plans

ERISA requires that large employee benefit plans attach an independent auditor’s report to their annual Form 5500 filing. A plan is generally treated as a large plan, and therefore subject to the audit requirement, when it has 100 or more participants at the beginning of the plan year. This requirement applies to defined contribution plans like 401(k)s, defined benefit pension plans, and health and welfare plans that meet the participant threshold. The statutory basis for this obligation appears in 29 U.S.C. Section 1023, which governs the annual report and the independent qualified public accountant’s examination.

How you count participants matters. For plan years beginning on or after January 1, 2023, the Department of Labor changed the counting methodology for defined contribution plans such as 401(k)s. Instead of counting everyone eligible to participate, these plans now count only participants and beneficiaries with an account balance at the beginning of the plan year. The change has allowed many smaller plans to file as small plans and avoid the audit requirement. Defined benefit and health and welfare plans continue to count eligible participants under the prior approach.

The auditor must be a licensed or certified public accountant (CPA), and they must be independent of the plan and the plan sponsor. Independence means the auditor cannot have a financial interest in the plan, the sponsoring employer, or any related entity that could compromise their objectivity. This standard exists to ensure the audit opinion is unbiased and reliable.

Small plans, those with fewer than 100 counted participants, may qualify for a filing exemption from the audit requirement, but once a plan crosses the 100-participant threshold an audit generally becomes mandatory. The 80-120 rule offers some stability near the boundary: a plan with between 80 and 120 participants at the beginning of the plan year may file in the same category (large or small) as it did the prior year. The IRS Form 5500 Corner provides detailed guidance on filing requirements and the participant counting rules that determine whether your plan needs an attached audit report.

Why specialization matters when selecting a plan auditor

Not every CPA firm is equally equipped to handle an employee benefit plan audit. ERISA audits involve specialized accounting standards, unique regulatory requirements, and plan-specific operational knowledge that general-practice auditors may lack.

A firm that regularly performs benefit plan audits will be familiar with areas that are unique to these engagements, including contributions and contribution timing, benefit payment accuracy, participant data testing, party-in-interest transactions, and prohibited transaction identification. These are not standard financial statement audit procedures. They require specific training and experience with DOL regulations and AICPA audit guidance for employee benefit plans.

The AICPA’s Employee Benefit Plan Audit Quality Center (EBPAQC) sets practice standards and provides resources specifically for firms that perform plan audits. Hiring a firm that is a member of the EBPAQC, or that can demonstrate equivalent expertise, significantly reduces the risk of a deficient audit.

The Department of Labor has consistently flagged employee benefit plan audits as an area of concern. DOL reviews have found that a meaningful share of plan audits contain deficiencies, often because the auditor lacked the specialized knowledge required. Choosing a qualified, experienced auditor is your first line of defense against these risks, and it is one reason plan sponsors increasingly seek out dedicated audit and assurance services rather than treating the plan audit as an afterthought.

What to look for in an employee benefit plan auditor

Selecting the right auditor requires more than verifying a CPA license. Plan administrators should evaluate potential auditors on several criteria to ensure a high-quality engagement.

Experience with your plan type

Ask how many employee benefit plan audits the firm performs each year and whether they have experience with your specific plan type, whether that is a 401(k), defined benefit pension, ESOP, or health and welfare plan. Each plan type has unique audit considerations, and experience with similar plans translates to a more efficient and thorough audit.

Independence and objectivity

Confirm that the auditor meets ERISA’s independence requirements. The firm should have no financial interest in the plan, the plan sponsor, or any service provider to the plan. Ask about any relationships that could create a conflict of interest.

EBPAQC membership or equivalent credentials

Membership in the AICPA Employee Benefit Plan Audit Quality Center demonstrates a firm’s commitment to quality in this specialized area. Ask whether the firm participates in EBPAQC or holds other relevant credentials, such as peer review results specific to employee benefit plan engagements.

Communication and reporting

A qualified auditor does more than issue a clean opinion. They should communicate findings clearly, flag potential compliance issues, and provide management letter comments that help you improve plan operations. The audit should be a source of actionable insight, not just a filed document.

Key questions to ask after the audit is complete

The end of an employee benefit plan audit is a valuable opportunity to strengthen your plan’s operations and compliance posture. Plan administrators should use the post-audit debrief to ask targeted questions that go beyond the audit opinion itself.

Consider asking your auditor the following:

  • Have plan assets been fairly valued? Asset valuation issues can affect participant account balances and trigger DOL scrutiny.
  • Are plan obligations properly stated and described? This is particularly important for defined benefit plans where actuarial assumptions drive liability figures.
  • Were contributions received in a timely manner? Late contributions are one of the most common ERISA violations and a frequent DOL audit finding. Your auditor should identify any instances where employee deferrals were not deposited within the required timeframe.
  • Were benefit payments made in accordance with plan terms? Overpayments, underpayments, and payments to ineligible individuals all create compliance exposure.
  • Did the auditor identify any issues that may affect the plan’s tax-qualified status? Operational failures can jeopardize the plan’s favorable tax treatment. Early identification allows you to use the IRS correction programs before issues escalate.
  • Were any prohibited transactions identified? Prohibited transactions under ERISA Section 406 can result in excise taxes and personal liability for fiduciaries. Understanding whether any occurred, and how to correct them, is essential.

Experienced auditors can also recommend process improvements based on what they observed during fieldwork. These recommendations often cover areas like participant data management, payroll integration, loan administration, and distribution processing.

How an employee benefit plan audit protects your organization

An employee benefit plan audit serves multiple protective functions beyond regulatory compliance. It provides independent verification that plan assets are being managed appropriately and that participants are receiving the benefits they were promised.

For plan administrators, the audit is a fiduciary safeguard. It demonstrates that you took reasonable steps to ensure the plan’s financial statements are accurate and that operations comply with the plan document and applicable law. In the event of a DOL investigation or participant complaint, a clean audit report is strong evidence that you fulfilled your fiduciary duties.

For employees, the audit provides assurance that their retirement savings or health benefits are being administered correctly. Participants have the right to request a copy of the plan’s audited financial statements, and a qualified audit builds trust in the plan’s management.

From an operational perspective, the audit process often surfaces inefficiencies and control weaknesses that might otherwise go undetected. Addressing these findings proactively can reduce administrative costs, lower error rates, and improve the participant experience. Pairing the audit with broader risk advisory services can turn those findings into a structured plan for strengthening internal controls.

The cost of choosing the wrong auditor

Hiring an auditor who lacks employee benefit plan expertise can create more problems than it solves. A substandard audit may fail to identify compliance issues that could have been corrected early, exposing the plan sponsor to penalties, excise taxes, and potential litigation.

The DOL’s Employee Benefits Security Administration (EBSA) conducts its own reviews of plan audits and has the authority to refer deficient audits to state boards of accountancy. For the plan sponsor, a deficient audit means the filing is essentially incomplete. You met the letter of the Form 5500 requirement but did not receive the protection that a quality audit provides.

Investing in a qualified, experienced auditor is a cost-effective decision when measured against the potential consequences of a deficient engagement. The fees for a specialized benefit plan audit are modest compared to the cost of DOL penalties, plan disqualification, or fiduciary breach claims.

Frequently Asked Questions

What triggers an employee benefit plan audit requirement?

An employee benefit plan audit is generally required when a plan has 100 or more participants at the beginning of the plan year. For plan years beginning on or after January 1, 2023, defined contribution plans count only participants with an account balance, while defined benefit and health and welfare plans continue to count eligible participants. Plans that meet the threshold must attach an independent auditor’s report to their annual Form 5500 filing with the DOL.

What is the difference between a full-scope and limited-scope employee benefit plan audit?

A full-scope audit covers all plan assets and financial statements without restriction. An ERISA Section 103(a)(3)(C) audit, historically known as a limited-scope audit, allows the auditor to rely on a certification from a qualified institution such as a bank, trust company, or insurance company for the covered investment information. The auditor still tests all other areas, including contributions, benefit payments, and participant data. Note that this election is available only when a qualified institution certifies both the completeness and accuracy of the investment information.

How do I know if my auditor is qualified to perform an ERISA audit?

Look for a CPA firm that regularly performs employee benefit plan audits and has experience with your specific plan type. Membership in the AICPA Employee Benefit Plan Audit Quality Center is a strong indicator of specialized expertise. Ask about the firm’s peer review results and the number of plan audits they complete each year.

What happens if the DOL finds problems with my plan’s audit?

The DOL’s Employee Benefits Security Administration reviews plan audits and can reject deficient filings. Consequences include required re-audits at the plan sponsor’s expense, civil penalties for incomplete filings, and referral of the auditor to state licensing boards. In serious cases, the DOL may open a full investigation into plan operations.

Can the same firm that handles our company’s financial audit also audit our benefit plan?

Yes, as long as the firm meets ERISA’s independence requirements and has the specialized expertise needed for employee benefit plan audits. Plan administrators should still evaluate whether the firm’s benefit plan audit practice is sufficiently developed, rather than assuming that general audit competence translates to plan audit quality.

When should we start preparing for our employee benefit plan audit?

Begin preparation at least three to four months before your plan’s year-end. Gather participant census data, reconcile plan assets to trustee statements, review contribution deposit timing, and compile all plan amendments and board resolutions. Early preparation reduces audit costs and allows time to resolve discrepancies before the auditor arrives.

Let’s talk about your business.