Employee Benefit Plan Auditors: How to Choose the Right Firm
When choosing a 401(k) plan auditor, evaluate employee benefit plan auditors on three things: membership in the AICPA’s Employee Benefit Plan Audit Quality Center (EBPAQC), a high annual volume of ERISA plan audits, and a clear record of favorable peer reviews specific to benefit plan work. Auditor quality matters: the DOL’s most recent audit quality study found that 30% of sampled EBP audits had deficiencies, and firms performing fewer than 25 audits per year showed deficiency rates far above that average. The right auditor protects both the plan and the plan sponsor from significant liability.
Why Choosing the Right Employee Benefit Plan Auditor Matters
Plan sponsors have a fiduciary duty under ERISA to act in the interest of plan participants. Selecting a qualified auditor is part of that duty, and the consequences of getting it wrong run in both directions. An auditor who lacks ERISA-specific experience can issue a deficient report, exposing the plan sponsor to DOL enforcement action, penalties on the Form 5500, and potential personal liability. At the same time, a thorough, well-executed audit protects participant assets and confirms that plan operations match plan documents.
The DOL’s Employee Benefits Security Administration (EBSA) published its fourth assessment of employee benefit plan audit quality in November 2023, reviewing 307 plan audits for the 2020 filing year. Overall, 30% of audits contained one or more deficiencies, a meaningful improvement from 39% in the 2015 study, but still a rate that should give any plan sponsor pause. The data point plan sponsors should keep in mind: firms that performed only 1-2 plan audits per year had a deficiency rate of 70%. Firms performing 100 or more had a deficiency rate of 17%.
Volume is a proxy for specialized competence, and it is one of the clearest signals available when evaluating employee benefit plan auditors. For plan sponsors weighing where benefit plan work fits alongside their broader assurance needs, our audit and assurance services explain how the pieces connect.
Does Your Plan Actually Need an Audit?
Before selecting an auditor, confirm whether your plan is required to have one. ERISA generally requires an independent audit for “large plans,” which are defined contribution plans with 100 or more eligible participants at the beginning of the plan year.
The 2023 rule change you need to know
For plan years beginning on or after January 1, 2023, the DOL changed how participants are counted for purposes of the large-plan threshold. Under the new rule, only participants who have an account balance in the plan are counted, regardless of whether they are still actively deferring. Previously, any employee eligible to participate was counted even if they had never contributed a dollar. The DOL estimated this change would remove the audit requirement for approximately 20,000 defined contribution plans.
If your plan was borderline large under the old counting method, recheck the math under the new standard before assuming an audit is still required.
The 80-120 rule
Plans that had between 80 and 120 eligible participants at the beginning of the plan year may continue to file in the same category, large or small, as they did the previous year. A plan that filed as small in year one can continue to file as small in year two even if it crosses 100, provided it stays within the 80-120 window. Once a plan clearly exceeds 120 participants with account balances at the start of the plan year, a large-plan audit is required.
ERISA Section 103(a)(3)(C) audits
Many plan audits are conducted under ERISA Section 103(a)(3)(C), previously called “limited scope” audits. Under AICPA Statement on Auditing Standards No. 136, effective for plan years ending on or after December 15, 2021, these are no longer labeled limited scope audits. The auditor issues an opinion on whether plan financial statement information that falls outside the certified investment data is presented fairly, while separately stating that the certified investment information agrees to the qualified institution’s certification. This format requires a specific, experienced auditor, and the engagement letter must confirm that the trustee or custodian is a qualified institution under the standard.
Key Criteria for Selecting Employee Benefit Plan Auditors
Once you confirm that an audit is required, the evaluation process should be methodical. The DOL publishes formal guidance, Selecting an Auditor for Your Employee Benefit Plan, which outlines the baseline criteria plan sponsors should apply. The sections below expand on those criteria.
EBPAQC membership
Membership in the AICPA’s Employee Benefit Plan Audit Quality Center is one of the strongest credentialing signals available. EBPAQC member firms commit to specific requirements:
- Designating a partner with firm-wide responsibility for the EBP audit practice
- Completing a minimum of 8 hours of EBP-specific CPE within the three-year period before signing or managing an ERISA audit
- Conducting annual internal inspections of the firm’s ERISA audit work
- Ensuring EBP engagements are included in the firm’s peer review and reviewed by individuals from other EBPAQC member firms
- Making peer review results publicly available
The DOL’s 2023 quality study confirmed what the previous studies suggested: EBPAQC member firms had significantly lower deficiency rates than non-members. That credential should be a threshold requirement, not a nice-to-have.
Volume and specialization
Ask how many ERISA-covered employee benefit plans the firm audits each year, and specifically how many are similar to yours (401(k) plans, defined benefit plans, health and welfare plans, ESOPs). A firm that audits 5 benefit plans per year alongside 200 commercial engagements will not have the same depth of ERISA knowledge as a firm where benefit plan audits represent a meaningful, recurring portion of the practice.
Peer review results
All CPA firms performing attest services must undergo peer review at least every three years. Ask specifically whether the firm’s benefit plan audits have been selected as part of a prior peer review, and whether the reviewer had ERISA-specific experience. A clean peer review from a reviewer with no benefit plan background may not be informative. The DOL’s own research has noted that favorable peer review ratings do not automatically correlate with higher EBP audit quality, because the peer review process is broad enough that EBP-specific deficiencies can go undetected without a specialized reviewer.
Independence
ERISA requires that the plan auditor be independent of the plan, the plan sponsor, and any party in interest. The EBSA updated its interpretive guidance on auditor independence in 2022 (Interpretive Bulletin 2022-01), including clarifying rules around the holding of publicly traded securities of the plan sponsor. Before engagement, both the firm and plan sponsor should perform an independence check to confirm there are no financial relationships, service overlaps, or other conflicts that would disqualify the auditor under ERISA Section 103(a)(3)(A).
Communication and responsiveness
Benefit plan audits run against firm compliance deadlines. The Form 5500 is generally due seven months after the close of the plan year, and filing IRS Form 5558 extends that deadline by two and a half months, to nine and a half months after the plan year ends. An auditor who is slow to communicate, slow to issue the report, or who creates last-minute scrambles for the plan administrator is a liability. In the engagement interview, ask how the firm manages the year-end schedule, what information they will need from the plan administrator and when, and what their typical turnaround is from fieldwork completion to report issuance.
Fee structure and scope clarity
Lower fees sometimes reflect less experienced staff or an auditor who is taking on more plans than the team can handle well. Higher fees do not guarantee quality either. What matters is a clear engagement letter that defines scope, deliverables, timing, and how out-of-scope work will be handled. Ask for an itemized estimate and compare it against the proposed approach, not just the bottom-line number.
Questions to Ask Prospective Employee Benefit Plan Auditors
The following questions can be used to evaluate and compare firms during the selection process:
- How many ERISA-covered benefit plan audits does your firm perform each year, and what types?
- Is your firm a current member of the AICPA EBPAQC?
- Were any of your benefit plan audits selected in your most recent peer review? What was the outcome?
- Who will be the engagement partner and manager, and what is their EBP-specific experience?
- What information will you need from us, and on what timeline?
- How do you handle situations where plan documents do not match actual plan operations?
- What is your process if you identify a compliance issue during the audit?
A firm that provides direct, confident answers to these questions is a better indicator of quality than one that hedges or redirects. If a prospective auditor cannot clearly explain their ERISA practice depth, take that seriously.
401(k) Audit Services: What the Engagement Covers
A 401(k) audit services engagement covers the plan’s financial statements for the applicable plan year, the related notes, and the supplemental schedules required by ERISA. The auditor will typically:
- Confirm participant data and eligibility determinations
- Test contributions received and benefit payments made
- Evaluate controls over plan operations
- Review investment information against custodian certifications (for Section 103(a)(3)(C) audits)
- Confirm that plan operations comply with the plan document
Under SAS 136, the auditor is also required to perform specific procedures related to the plan’s ERISA compliance, including reviewing the plan document for terms that might affect the financial statements and inquiring about whether the plan has maintained its tax-qualified status. These procedures are distinct from a tax compliance review but can surface operational issues that the plan administrator should address.
A modern 401k audit services engagement at a well-run firm should not require excessive back-and-forth. Audit teams that work from source-linked workpapers and leverage technology for data validation can reduce the documentation burden on plan administrators while maintaining a rigorous audit trail. The audit services Modus provides are structured around clear information requests and defined milestones so plan sponsors know exactly what is needed and when.
Timing and Transition Considerations
Switching benefit plan auditors mid-cycle creates complexity. If possible, make the change before the plan year you want audited begins, or at the very start of the cycle. The new auditor will need to perform opening balance procedures, which may require communication with the predecessor auditor. Under professional standards, the successor auditor must request permission from the plan administrator to communicate with the predecessor. If the predecessor raises unresolved concerns, the new auditor is required to evaluate those concerns before accepting the engagement.
For plans with new audit requirements because they crossed the 100-participant-with-balances threshold under the 2023 rule, timing the selection carefully can avoid unnecessary delays. Start the selection process no later than six months before the plan year end.
Frequently Asked Questions
How do I know if my 401(k) plan needs an audit?
For plan years beginning on or after January 1, 2023, your plan requires an audit if it had 100 or more participants with account balances at the beginning of the plan year. Plans in the 80-120 participant range may be able to continue filing as they did the prior year under the 80-120 rule. Plans with fewer than 80 participants with account balances generally qualify as small plans and are not required to have a full audit.
What is the EBPAQC and why does it matter?
The EBPAQC is the AICPA’s Employee Benefit Plan Audit Quality Center, a voluntary membership program for CPA firms that commit to specific quality standards for their ERISA audit practices. Member firms have lower deficiency rates on DOL audit quality reviews. EBPAQC membership should be treated as a baseline requirement when selecting an EBP auditor, not a bonus credential.
What is the difference between a full-scope audit and an ERISA Section 103(a)(3)(C) audit?
A full-scope audit covers all plan assets and operations. An ERISA Section 103(a)(3)(C) audit, formerly called a limited-scope audit, is available when a qualified institution such as a bank or insurance company certifies the investment information. Under this type of audit, the auditor issues a specific form of opinion that distinguishes between certified investment information and other financial statement elements. The plan’s trust agreement and the identity of the custodian determine whether this audit type is available.
How much does an employee benefit plan audit cost?
Fees vary based on plan type, size, complexity, and the number of investment options and transactions. A straightforward 401(k) plan audit for a single-employer plan may range from $5,000 to $15,000 or more depending on the firm and scope. Plans with defined benefit provisions, ESOPs, or complex investment structures will cost more. Price alone is not a reliable quality indicator, but extremely low fees can be a signal that the firm is understaffing the engagement.
Can my plan use the same auditor as my company’s financial statement audit?
Yes, in many cases. The requirement is that the auditor be independent of the plan and the plan sponsor under ERISA’s independence standards. If the company’s regular audit firm meets those independence requirements and has sufficient EBP-specific experience, using the same firm can simplify coordination. However, plan sponsors should independently confirm the firm’s EBP qualifications rather than assuming that general audit competence carries over.
What happens if my plan auditor finds a compliance problem?
Under SAS 136, the auditor is required to communicate certain findings directly to those charged with governance, including identified or suspected noncompliance with laws and regulations that could have a material effect on the financial statements. The auditor will also note whether plan operations did not conform to the plan document. These findings do not necessarily result in a qualified audit opinion, but they do require a response from the plan administrator. In many cases, issues can be corrected through the DOL’s Voluntary Correction Program or the IRS’s Employee Plans Compliance Resolution System before they become enforcement matters.
Filed under: Employee Benefit Plan Audits