Employee Benefit Plan Audit: Requirements and Process

September 8, 2026
Table of contents
BG
Nisl dui hendrerit interdum

Ac quis vel auctor et pellentesque enim pretium sed commodo orci nulla.

Get Your Benefits Assessment
You’re overpaying for benefits. We’ll prove it.
Author

James Taylor

Founding Benefits Consultant, Ignition Benefits

An employee benefit plan audit is an independent ERISA review of a 401k or health plan, required each year once the plan has 100 or more participants.
Key takeaways
  • A 401k plan generally needs an audit once it has 100 or more participants with account balances on the first day of the plan year.
  • The 80-120 rule lets some plans delay that first audit, because a plan that was filed as small last year can keep filing as small between 80 and 120 participants.
  • Health and welfare plans follow a separate test. Unfunded and fully insured welfare plans can pass 100 participants and still avoid the auditor's report.
  • An independent Certified Public Accountant (CPA) performs the audit, and the plan administrator stays responsible for engaging that firm and filing on time.
This is some text inside of a div block.
This is some text inside of a div block.
Lorem ipsum porta pharetra risus molestie sem diam.

A Form 5500 that needs an audit report and does not have one is an incomplete filing. The Department of Labor (DOL) can reject it and assess up to $2,739 for every day it stays uncorrected, and the Employee Retirement Income Security Act (ERISA) sets no ceiling on that total.

A weak audit carries the same exposure. The Department of Labor reviewed 307 plan audits for its November 2023 Audit Quality Study and found major deficiencies in 30% of them.

The requirement itself is straightforward. An audit applies once a plan has 100 or more participants with account balances on the first day of the plan year, and health and welfare plans follow a separate test built around funding.

This guide covers when the requirement applies, which plans are exempt, what the auditor examines, how to prepare, and how to choose the firm that does the work.

What Is an Employee Benefit Plan Audit?

An employee benefit plan audit is an independent examination of a benefits plan's financial statements and related information under the ERISA. An Independent Qualified Public Accountant (IQPA) performs the audit, and the report is generally filed with the plan's Form 5500 annual report.

The auditor checks whether the plan is being run the way ERISA and the plan document require. That covers everything from how contributions are handled to whether participant records are accurate.

The Department of Labor specifically identifies plan assets, plan obligations, timely contributions, benefit payments, participant accounts, tax-status issues, and prohibited transactions as areas an auditor may examine.

The plan administrator, typically the employer sponsoring the plan, is legally responsible for engaging the auditor and ensuring the audit is completed and filed on time. That responsibility does not transfer to a Third-Party Administrator (TPA), recordkeeper, or broker, even though all three may supply information the auditor needs.

Note: A broker does not perform the audit. They help you shop the market, manage renewals, and administer the plan day to day, but the audit itself has to come from an independent CPA firm with no financial stake in the outcome.

When Is an Employee Benefit Plan Audit Required?

An audit is required once your defined contribution plan has 100 or more participants who have account balances at the start of the plan year. The 80-120 rule can delay that first audit for some plans. If your plan runs through a Professional Employer Organization (PEO) or a pooled arrangement, the audit is determined at the plan level rather than by your headcount. 

The 100 Participant Rule

Your plan needs an audit once it reaches 100 participants with account balances as of the first day of the plan year. With a 2023 rule change, the Department of Labor now counts only participants with actual account balances instead of everyone that’s technically eligible to join the plan.

For example, a company might have 140 employees eligible for its 401k, but only 95 of them actually hold an account balance. That company would qualify as a small plan and would not need an audit that year, assuming the other requirements are met.

Under the old counting method, based on eligibility rather than balances, that same company could have crossed the threshold and needed an audit.

Note: Participants who no longer work for the company can still count. Former employees who left money in the plan instead of rolling it over remain part of the relevant participant count, as long as they still hold a balance.

The 80 to 120 Participant Rule

If your plan was filed as a small plan the previous year, you can generally continue filing as a small plan. This lets you skip the audit as long as your participant count stays between 80 and 120 at the start of the current plan year. 

The 80–120 rule exists to stop plans from flipping in and out of audit status every time headcount changes by a few employees near the threshold. A plan with 115 participants can continue filing as a small plan if it filed as small the previous year. A plan that reaches 121 moves to large-plan reporting. 

The rule does not work in reverse, so a plan already in large-plan status cannot return to small-plan filing at 119 participants. 

Pro tip: Check your participant count as of the first day of the plan year instead of the date you happen to review it. A mid-year headcount change does not normally rewrite the plan's filing status for that year.

What If You're Using a PEO, MEP, or PEP?

The 100-participant rule applies to the plan and not your headcount. If your retirement plan runs through a PEO, a Multiple Employer Plan (MEP), or a Pooled Employer Plan (PEP), the pooled plan provider files one Form 5500 covering every participating employer.

The 2026 Pooled Employer Plan Bulletin identified 244 active PEPs for statistical year 2023, and 110 of them were large plans under the account-balance test. It also reports that 96.6% of participating employers had fewer than 100 employees. A small employer can therefore belong to a plan that receives a full ERISA audit every year.

Ask your provider for the plan's Form 5500 and Schedule MEP, because those show the plan-level count that determines audit status. If you are moving to a standalone plan, confirm the new count directly as part of any PEO exit plan.

Which Plans Need an Audit: Retirement vs. Health and Welfare

The audit rules are easiest to understand when you separate retirement plans from health and welfare plans, since they follow different logic.

Retirement Plans

401k, pension, and profit-sharing plans can become subject to the ERISA audit requirement once they meet the applicable large-plan threshold, subject to the exceptions described above. For a typical 401k, the 100-participant rule and the 80-120 rule are the key starting points.

Health and Welfare Plans

Funding structure decides whether a welfare plan needs an auditor's report, while participant count decides whether the plan files as a large plan. Those are two separate questions with two separate answers.

Welfare plan type Files Form 5500 at 100+ participants Auditor's report required
Unfunded, fully insured, or a combination Yes No, under 29 CFR 2520.104-44
Self-funded or partially self-funded Yes Generally yes
Multiple Employer Welfare Arrangement (MEWA) Yes, plus Form M-1 Depends on funding and structure

‍

An unfunded, fully insured, or combination welfare plan with 100 or more participants still files a Form 5500. Under 29 CFR 2520.104-44, it does not attach an auditor's report or the Schedule H financial statements that large plans normally file.

Note: The exemption does not remove every disclosure. The plan still reports non-exempt transactions, such as a late contribution or a prohibited loan, on Schedule G, Part III.

Self-funded and partially self-funded welfare plans hold plan assets directly, which is why the exemption usually does not apply. These plans generally face the audit requirement at the same 100-participant threshold that applies to retirement plans. The choice between self-funded and fully funded coverage therefore changes your annual compliance work in addition to your claims risk.

MEWAs file Form M-1 regardless of size, and their audit treatment depends on their own structure. Do not assume a MEWA follows the single-employer exemption.

The same reasoning applies when you compare level-funded and self-funded plans, because the funding decision and the reporting obligation move together. A broker who keeps your plan documents, funding details, and participant counts current can tell you which side of the threshold you are on before the plan year begins rather than after an auditor asks.

What Does an Employee Benefit Plan Audit Cover?

The exact procedures depend on the plan and audit type, but an auditor may examine:

  • Participant data and accounts
  • Contributions received and receivable
  • Benefit payments and distributions
  • Plan obligations
  • Investments and investment transactions
  • Internal controls
  • Prohibited transactions
  • Financial statement presentation and disclosures

DOL research on audit quality shows why employee benefit plan experience matters specifically. Participant data, plan obligations, benefit payments, and prohibited transactions were among the areas that generated the most problems in the deficient audits reviewed by the DOL. 

These aren't necessarily the same issues a CPA encounters in an ordinary corporate financial statement audit, which is why a firm experienced specifically with employee benefit plans tends to outperform a generalist accounting firm that happens to also offer audits.

Full-scope audit: The auditor performs the procedures necessary to form an opinion on the plan's financial statements, including appropriate testing of investment information. This is the default audit type.

ERISA Section 103(a)(3)(C) audit: Historically called a "limited-scope" audit, this allows the plan administrator to instruct the auditor not to perform certain procedures on investment information. This applies when a qualifying institution, typically the recordkeeper or custodian, certifies the accuracy and completeness of that information, usually through a System and Organization Controls (SOC 1) report. 

This limitation is narrow, but it does not mean the auditor can skip participant data, contributions, benefit payments, or the rest of the plan's financial statement audit work. The auditor still performs full procedures everywhere else, so this certification is not a blanket audit waiver.

How to Prepare for an Employee Benefit Plan Audit

Engaging a firm six to nine months before the Form 5500 deadline leaves room for document requests, SOC 1 reports, and any reconciliation problems those requests surface. For a calendar-year plan, that means starting in the autumn of the plan year.

Step 1: Gather the plan documents. Have the current plan document, amendments, trust documents, relevant service agreements, and prior-year audit materials on hand, and confirm the documents actually match how the plan operated during the year.

Step 2: Request System and Organization Controls (SOC 1) reports early. These reports document the internal controls at your plan's service providers. Providers issue them on their own schedule rather than on request, so a late request is a common reason a first-year audit starts behind.

Step 3: Reconcile participant data. Compare your census with payroll and plan records, paying particular attention to hire and termination dates, eligibility dates, compensation, deferral elections, employer contributions, forfeitures, and account balances. 

Participant-data problems can affect eligibility, contributions, and benefit payments simultaneously, so correcting them early prevents several audit issues at once. Based on DOL assessment, this is the single most frequent category of deficiency findings.

Step 4: Organize contribution records. Gather payroll registers, contribution reports, and deposit records. Auditors will test whether employee deferrals were transmitted to the plan within the required timeframe and whether employer contributions were calculated according to the plan document.

Step 5: Reconcile financial records. Reconcile trust or custodian statements against the plan's accounting records and investigate unexplained differences before fieldwork starts, since this is one of the first things an auditor checks. If the plan uses multiple custodians, recordkeepers, or investment platforms, make sure the auditor knows about each one.

Step 6: Coordinate with service providers, including your broker. Request the information your recordkeeper, custodian, TPA, and other providers need to supply, and confirm your broker has clean, current census and eligibility data on file. A broker who has kept accurate records throughout the year can hand that data over immediately, allowing you to consolidate it before the auditor’s request.

Once you engage a CPA firm, expect an engagement letter, followed by a formal document request list, then a 1–2 week fieldwork phase once your documentation package is complete. From engagement to final report, the full process commonly takes several weeks to a few months, depending on plan complexity and how quickly requested items come back.

How to Choose an Employee Benefit Plan Auditor

Choose on plan audit volume and relevant experience rather than on price. The Department of Labor's guidance on selecting an auditor names independence, state licensing, and employee benefit plan experience as the criteria that matter.

Audit volume is the strongest available signal. In its November 2023 Audit Quality Study, the DOL found that firms performing one or two plan audits a year had a deficiency rate of roughly 70%. Firms performing 100 or more had a rate of roughly 17%.

One finding removes a common shortcut. The DOL reported that peer review and practice monitoring do not help identify deficient plan audits, so a clean peer review report tells you little about ERISA audit quality. Audits by members of the American Institute of Certified Public Accountants (AICPA) Employee Benefit Plan Audit Quality Center carried a significantly lower deficiency rate in the same study, which makes membership worth asking about alongside volume.

Ask these questions before hiring:

  1. How many ERISA plan audits do you perform each year?
  2. How many plans of our type and size have you audited?
  3. Does your firm belong to the AICPA Employee Benefit Plan Audit Quality Center?
  4. Who will perform and supervise the engagement day to day?
  5. How do you test contributions, benefit payments, and participant data?
  6. What does the quoted fee include, and what would increase it?
  7. Does our plan qualify for a Section 103(a)(3)(C) audit?

The fifth question comes straight from the study. Deficiencies appeared most often in four areas: contributions, benefit payments, participant data, and party-in-interest transactions. 

A party-in-interest transaction is any dealing between the plan and someone connected to it, such as the employer, a trustee, or a paid service provider. A firm should be able to describe its approach to each area without preparation.

Ignition Benefits runs a full market audit at every renewal and keeps client census, plan documents, and funding details current between renewals. Get your free benefits review.

Employee Benefit Plan Audit Cost and Timeline

No government schedule sets audit fees. Cost depends on participant count, investment complexity, payroll frequency, record quality, and whether this is a first-year audit.

Cost factor Effect on the fee
Participant count More participants require larger testing samples
Investment complexity Multiple platforms or hard-to-value assets add procedures
Number of payrolls More payroll runs create more contribution data to test
First-year audit The firm must build an understanding of the plan and its controls
Record quality Missing or inconsistent records add hours
Audit type A Section 103(a)(3)(C) limitation reduces investment testing
Compliance history Unresolved operational errors add corrective work

‍

The timeline is fixed and easier to plan around. The standard Form 5500 deadline is the last day of the seventh month after the plan year ends, and a timely Form 5558 adds two and a half months.

Milestone Timing for a calendar-year plan
Engage the audit firm Six to nine months before the deadline, so the autumn of the plan year
Request SOC 1 reports At engagement, since providers commonly take four to six weeks
Receive the document request list After the engagement letter
Fieldwork One to two weeks once records are complete
Form 5500 due July 31
Extended deadline with Form 5558 October 15

‍

Missing the deadline triggers two separate penalties. Under Internal Revenue Code section 6652(e), the IRS can assess $250 per day up to $150,000 per return. Under ERISA section 502(c)(2), the DOL can assess up to $2,739 per day, and ERISA sets no aggregate ceiling on that amount. Both are maximums, and the DOL applies discretion when it assesses. 

Relief is available if you act first. The DOL's Delinquent Filer Voluntary Compliance Program reduces penalties for administrators who file voluntarily before the DOL makes contact. Reasonable-cause relief can also apply in some circumstances.

Staying Audit Ready Year-Round

Most audit preparation belongs in the months between audits. Reconcile your census against payroll each quarter, record the date every deferral reaches the plan, and keep plan documents matched to how the plan actually operated.

Many employers do not hold that data themselves. In the 2026 CFO Leadership and Ignition Benefits survey, one in five respondents had access to none of the benefits data types that affect their costs.

That gap tells you where to start. If your records live with a PEO or a recordkeeper you cannot query directly, the first task is obtaining your own copy of the census and plan documents. If you already hold that data, the first task is reconciling it against payroll before the next plan year begins.

Ignition Benefits keeps client census, plan documents, and funding details current between renewals. Get a free benefits review to see which of those your health and welfare plans are missing.

Conclusion

FAQs

Why Do Employee Benefits Plans Need to Be Audited?

Large plans need audits because ERISA requires independent assurance over plan financial statements and operations for participants, regulators, and the plan administrator.

What Triggers an Audit of an Employee Benefit Plan?

Reaching 100 participants with account balances at the start of the plan year, unless the 80-120 rule applies, or a health and welfare plan's funding structure exempts it.

Who Benefits the Most From an Employee Benefit Plan Audit?

Plan participants benefit most, since the audit confirms their contributions and account balances are accurately tracked and protected.

You’re overpaying for benefits. We’ll prove it.