An Employee Benefit Plan (EBP) audit is an independent examination of a retirement or welfare benefit plan’s financial statements and operations, required under ERISA for plans with 100 or more eligible participants, and the audit only goes smoothly when every party involved, the plan sponsor, the recordkeeper, HR and payroll, and the auditor, understands exactly what they are responsible for. Most plan sponsors only interact with this process once a year, which is exactly why confusion about who provides what tends to slow the audit down. This guide organizes the entire process by responsibility, not by audit phase, so plan sponsors know precisely what to prepare and who to ask when something is missing.
The plan sponsor bears ultimate fiduciary responsibility for the audit’s quality, even though much of the work is performed by other parties. Understanding where that responsibility actually sits is the foundation of everything else in this guide.
What the Plan Sponsor Is Responsible For
The plan sponsor, typically the employer offering the plan, is legally responsible for selecting a qualified, independent auditor and for the overall integrity of the audit process, even when most of the day-to-day coordination is handled by HR, finance, or an outsourced administrator. This responsibility cannot be fully delegated. The Department of Labor has been explicit that fiduciaries who hire an unqualified auditor, or who fail to review the auditor’s qualifications and the final report, can be held responsible for resulting deficiencies.
Practically, this means the plan sponsor should review the auditor’s specific EBP audit experience before engagement, not just their general audit credentials, since a CPA firm with strong general audit experience but limited EBP-specific volume is statistically more likely to produce a deficient audit according to past Department of Labor studies on audit quality across the profession. The plan sponsor should also personally review the final audit report and any management letter before it is filed with Form 5500, rather than treating the auditor’s sign-off as the final step requiring no further sponsor involvement.
What the Recordkeeper or Third-Party Administrator Handles
The recordkeeper or third-party administrator (TPA) maintains the plan’s transactional records: contributions received, distributions processed, loan activity, and investment transactions. During an audit, the recordkeeper typically provides the trust statements, transaction detail reports, and participant-level data the auditor needs to test against the plan’s records.
A common friction point is timing: recordkeepers often have a standard turnaround time for producing audit-specific reports, and if the plan sponsor does not request these reports early in the audit cycle, the recordkeeper’s response time becomes the bottleneck that delays the entire engagement. Plan sponsors working with a recordkeeper for the first time, or going through a recordkeeper transition during the plan year, should flag this early, since a mid-year recordkeeper change typically requires reconciling data from two separate systems for the audit period.
One responsibility that is easy to overlook sits at the boundary between the recordkeeper and the sponsor: the SOC 1 (System and Organization Controls 1) report. The recordkeeper should provide a SOC 1 report describing the controls at its service organization, which the auditor uses to assess those controls rather than testing them from scratch. That report also lists complementary user entity controls (CUECs), the control activities the plan sponsor is expected to perform on its side depending on the applicability of CUEC. Confirming those user entity controls are actually in place is the sponsor’s responsibility, and a gap here can create a finding even when the recordkeeper’s own controls are sound.
What HR and Payroll Need to Prepare
HR and payroll functions own the data that connects employee status to plan eligibility: hire dates, termination dates, compensation used for plan contribution calculations, and eligibility determinations. Auditors test a sample of employees against this data to confirm that the plan correctly applied its own eligibility and contribution rules, which means inconsistent or incomplete personnel records create audit findings even when the retirement plan itself was administered correctly.
The most frequent issue in this category is a mismatch between the compensation definition used for payroll purposes and the compensation definition specified in the plan document, particularly when bonuses, overtime, or other variable pay components are excluded from contribution calculations inconsistently across employees. Reconciling payroll’s compensation definition against the plan document before the audit begins, rather than during fieldwork, avoids a finding that otherwise takes considerable back-and-forth to resolve and document.
A practical way to compress the timeline is to assemble the standard audit request list before fieldwork begins. Auditors typically need: the signed plan document and all amendments, the current SOC 1 report from the recordkeeper, trust and custodial statements, the year-end census file, payroll registers reconciled to the plan’s compensation definition, contribution remittance records showing deposit dates, distribution and loan documentation, and the draft Form 5500. Having these ready in one place, reconciled, is the single biggest factor in how smoothly the audit runs.
What the Auditor Actually Tests During Fieldwork
The auditor’s fieldwork centers on five core areas: plan financial statement balances, contribution testing, including timeliness of remittance, distribution and loan testing against plan document terms, eligibility and enrollment testing, and investment valuation, with the depth of investment testing depending on whether the engagement is an ERISA Section 103(a)(3)(C) audit (Formerly know as limited scope) or Non-ERISA Section 103(a)(3)(C) audit (Formerly known as full scope audit).
Contribution remittance timing deserves specific attention because it is consistently one of the most cited findings in EBP audits nationally. The Department of Labor’s guidance treats delayed deposit of employee contributions withheld from payroll as a fiduciary breach, and auditors are required to test the actual time elapsed between withholding and deposit against the plan’s established remittance pattern, not against a generic regulatory deadline. Plan sponsors who do not have a documented, consistent remittance schedule make this testing area harder to clear cleanly.
What Happens After the Audit Report Is Issued
The signed audit report and the auditor’s opinion are attached to Form 5500 as part of the annual filing. If the auditor issues a qualified, adverse, or disclaimed opinion, or if a management letter identifies operational deficiencies, the plan sponsor needs a documented plan for addressing those findings before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory scrutiny.
Plan sponsors should also use this period to review whether the audit process itself ran efficiently. If specific data requests took unusually long to fulfill, or if the same finding keeps recurring, that is the signal to fix the underlying process, whether it is a payroll reconciliation gap or a recordkeeper reporting delay, well before the next plan year closes, rather than waiting until the next audit surfaces it again.
A note for plans undergoing their first audit: a first-year engagement generally requires the auditor to establish that the opening balances are fairly stated, which can mean additional procedures over the prior period that was never audited. This is a common surprise for sponsors and is part of why a first-year audit typically takes more time and costs more than a recurring one. Flagging a first-year plan to the auditor early lets both sides plan for this.
Common Fiduciary Mistakes That Lead to DOL Attention
A few patterns show up repeatedly in plans that draw additional Department of Labor scrutiny. Hiring an auditor based primarily on price rather than EBP-specific experience is one of the most consequential, since the Department of Labor has specifically flagged audit quality variance tied to how much EBP audit volume a given CPA firm actually handles. Treating the 80-120 participant rule as a permanent exemption rather than a one-time buffer is another, where sponsors assume they remain a small plan indefinitely after using the exception once.
Failing to document a consistent contribution remittance schedule and not reviewing the final audit report personally before filing rounds out the most common patterns. None of these mistakes is about dishonesty. They are almost always about treating the audit as an annual compliance task handled entirely by someone else, rather than a fiduciary responsibility the plan sponsor needs to stay actively engaged with.
Where CPA Firms Can Get Outsourcing Support for EBP Audit Fieldwork
For CPA firms performing these audits, the fieldwork-heavy testing areas described above, contribution remittance testing, distribution sampling, census data reconciliation, and workpaper preparation, are well-suited to structured outsourcing support, particularly during the concentrated filing season when EBP audit volume spikes sharply. This lets the engagement partner focus review time on judgment calls, like evaluating the severity of an exception or assessing investment valuation methodology, rather than the repetitive testing work that consumes most of an EBP engagement’s hours.
This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms managing EBP audit engagements, working within the engaging firm’s own methodology and review standards rather than as a generic offshore staffing arrangement.
Frequently Asked Questions
Who is legally responsible for the quality of an Employee Benefit Plan audit? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified auditor and reviewing the final audit report, even though the recordkeeper, payroll, and the auditor each handle specific pieces of the process.
What is the most common finding in Employee Benefit Plan audits? Delayed remittance of employee contributions withheld from payroll is one of the most frequently cited findings, since the Department of Labor treats inconsistent or delayed deposit timing as a fiduciary breach regardless of intent.
Why do payroll records matter so much in an EBP audit? Auditors test employee eligibility and contribution calculations against payroll and HR data. A mismatch between the plan document’s compensation definition and how payroll actually calculates contributions creates findings even if the retirement plan itself was administered correctly.
What should a plan sponsor do if the auditor issues a qualified or adverse opinion? The plan sponsor needs a documented remediation plan addressing the underlying issue before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory attention.
Can a CPA firm outsource parts of an Employee Benefit Plan audit? Yes. Fieldwork-heavy testing areas like contribution testing, distribution sampling, and workpaper preparation are commonly outsourced to specialized support teams working within the engaging firm’s methodology, letting the engagement partner focus on judgment-heavy review work.