Can we help you get a better audit experience? Schedule a call →

Employee Benefit Plan Audit: How to Prepare

pink pig figurine on white surface

Preparing for a 401(k) or employee benefit plan audit starts with understanding whether your plan is required to file one, gathering the right documents before fieldwork begins, and making sure your internal processes align with what the auditor will test. Most first-time plan sponsors underestimate the documentation involved, but with the right preparation you can significantly reduce back-and-forth with your auditor, protect the plan’s tax-qualified status, and meet your Form 5500 filing deadline.

Who Is Required to Have an Employee Benefit Plan Audit

Under ERISA, defined contribution retirement plans, defined benefit pension plans, and certain health and welfare plans must engage an independent qualified public accountant (IQPA) when they cross the “large plan” threshold. For defined contribution plans such as 401(k)s, that threshold is generally 100 or more participants with account balances at the beginning of the plan year.

The counting methodology changed meaningfully for plan years beginning on or after January 1, 2023. Before that date, plans counted all eligible participants, including employees who were eligible to join but had never contributed and had no account balance. Beginning with the 2023 plan year, defined contribution plans count only participants who actually have an account balance. The Department of Labor, IRS, and PBGC finalized this change in the February 2023 Form 5500 revisions and estimated it would remove nearly 20,000 plans from the large-plan audit requirement.

The 80-120 Rule

A mid-size buffer, known as the 80-120 rule, applies to plans that hover near the threshold. If your plan had between 80 and 120 participants at the beginning of the plan year, you may elect to file as either a large plan or a small plan, following whichever filing category applied to your prior-year Form 5500. Once you cross 120 participants (with account balances, under the current rule), an audit is required regardless.

Plans That Need an Audit Even Below 100 Participants

Certain pension plans with fewer than 100 participants still require an audit if they fail to meet specific conditions related to plan investments, fidelity bonding, and participant disclosure requirements. If you are unsure which category applies to your plan, consult your ERISA counsel or a firm experienced in employee benefit plan audits.

Understanding Audit Scope: Section 103(a)(3)(C) vs. Full-Scope

One of the first decisions you and your auditor will work through is audit scope, and it affects the documents you need to gather.

ERISA Section 103(a)(3)(C) Audit

Most 401(k) plans qualify for what was formerly called a “limited scope audit” and is now formally designated an ERISA Section 103(a)(3)(C) audit under AICPA SAS No. 136. Under this scope, the auditor does not independently verify investment information that has been certified as complete and accurate by a qualifying institution, meaning a federally regulated bank, trust company, or insurance carrier that holds the plan’s assets.

To qualify, your custodian must provide a written certification covering the completeness and accuracy of investment information for the entire plan year. This certification must be signed by an authorized representative of the custodial institution. If your custodian provides this certification, you can proceed with a 103(a)(3)(C) audit. If not, a full-scope audit is required, which expands the procedures significantly.

Full-Scope Audit

A full-scope audit requires the auditor to perform independent investment verification procedures, which typically means more time and cost. Plans that hold hard-to-value assets such as real estate, employer stock, or investments not held at a qualifying institution are more likely to require full-scope treatment.

Key Documents to Gather Before Fieldwork Begins

Plan sponsors who arrive at fieldwork with an organized set of documents move through the audit faster and with less friction. Below is the core set your auditor will request. Gathering these before the engagement kicks off is the single highest-leverage preparation step you can take.

Plan Governance Documents

  • Executed plan document and all amendments, including any SECURE 2.0 amendments
  • Trust agreement
  • Summary Plan Description (SPD) and any Summary of Material Modifications (SMMs)
  • Investment Policy Statement (IPS)
  • Minutes from plan committee meetings held during the plan year

Financial and Operational Records

  • Audited or reviewed financial statements from the prior year (for comparative purposes)
  • Year-end trust statement and monthly statements from the custodian or recordkeeper
  • Payroll records used to calculate participant deferrals and employer contributions
  • Participant census data: name, date of hire, date of birth, compensation, deferral elections, account balances
  • Records of loan originations, repayments, and any defaults during the year
  • Documentation of distributions and hardship withdrawals

Service Provider Information

  • SOC 1 (Type 2) reports from your payroll processor and recordkeeper, covering the plan year
  • Service agreements and fee schedules for all service providers
  • ERISA bond documentation

Regulatory and Compliance Records

  • Prior-year Form 5500 and all schedules
  • Draft of the current-year Form 5500
  • Any DOL or IRS correspondence, voluntary correction filings, or prior audit reports
  • Nondiscrimination testing results (ADP/ACP, top-heavy, 410(b) coverage)

The Role of Your Recordkeeper and Payroll Provider

Most plan sponsors do not process their own contributions or maintain their own participant records. Your recordkeeper and payroll provider are both critical participants in the audit, and their quality directly affects yours.

Your recordkeeper will generate the certified investment statement your auditor relies on for a 103(a)(3)(C) audit. They will also produce the participant-level transaction detail your auditor uses to test contributions, distributions, loans, and forfeitures. Request these reports well before fieldwork; some recordkeepers have lead times of several weeks for audit-specific packages.

Your payroll provider’s SOC 1 report covers the internal controls over payroll processing, including the controls that ensure deferral percentages are applied correctly to compensation. If the report has a qualified opinion or user entity control considerations that apply to your plan, you need to document how your own controls address those gaps.

Common Deficiencies and How to Avoid Them

The DOL’s November 2023 audit quality study, which reviewed 307 audits of 2020 plan-year filings, found that 30% contained major deficiencies. Firms that performed only 1 or 2 plan audits per year had a deficiency rate of 70%, compared to 17% for firms auditing more than 100 plans. That gap is a strong argument for working with an auditor who concentrates specifically on employee benefit plans and participates in the AICPA’s Employee Benefit Plan Audit Quality Center (EBPAQC).

The most common operational errors auditors find on the plan side include:

  • Late salary deferrals. The DOL’s general rule requires that employee deferrals be deposited as soon as they can be reasonably segregated from company assets. Small plans have a seven-business-day safe harbor. Late deposits require correction, including earnings restoration to affected participants.
  • Compensation definition errors. Plans define “compensation” specifically, and the definition varies. Using the wrong pay codes when calculating deferrals or employer match is one of the most frequent errors found.
  • Eligibility failures. Employees who met the plan’s service or age requirements but were not enrolled, or were enrolled late, create a correction obligation.
  • Loan administration errors. Loans not originated or administered according to the plan document, or loans that went into default without proper handling, are a consistent finding.

Addressing these items before auditors begin testing, or at minimum being able to explain and document any known failures with a correction plan, demonstrates operational maturity and reduces audit time.

Filing Deadlines and Extensions

For calendar-year plans (plan year ending December 31), Form 5500 is due July 31 of the following year. Plans that need more time can file Form 5558 by July 31 for a 2.5-month extension, pushing the deadline to October 15. The audit must be substantially complete and the financial statements attached to the Form 5500 before you can file, so a realistic audit timeline needs to account for the filing date.

If you are approaching your first audit, plan for an initial engagement that takes longer than subsequent years. The auditor needs to establish opening balances, understand the plan’s design and operations, and build out baseline workpapers that will carry forward to future periods. Many plans underestimate the time required for a first-year audit by two to four weeks.

How to Select an Auditor

The DOL has published guidance emphasizing that plan sponsors should not select an auditor based solely on the lowest fee. Key criteria to evaluate include:

  1. Number of employee benefit plan audits performed annually
  2. Whether the firm is an EBPAQC member
  3. Peer review results and any disciplinary history
  4. Familiarity with your type of plan (defined contribution, defined benefit, health and welfare)
  5. Whether the engagement will be staffed with professionals who work on EBP audits regularly, not generalists rotating in for one engagement

The DOL’s publication “Selecting an Auditor for Your Employee Benefit Plan” provides a practical checklist for plan sponsors evaluating auditor qualifications.

At Modus, our audit and assurance practice uses AI-assisted workpaper tools that link findings directly to source documents, which shortens fieldwork and reduces the volume of follow-up requests plan sponsors receive. This approach is particularly valuable in first-year engagements where establishing a reliable, organized workpaper structure pays forward across every subsequent year.

Frequently Asked Questions

How do I know if my 401(k) plan needs an audit?

For plan years beginning on or after January 1, 2023, defined contribution plans must have an audit if 100 or more participants had account balances at the beginning of the plan year. The 80-120 rule gives plans in that range the option to follow prior-year filing status in some cases. Plans below 80 participants with account balances are generally not required to have an audit.

What is the difference between a full-scope and a 103(a)(3)(C) EBP audit?

A Section 103(a)(3)(C) audit (formerly called a limited scope audit) relies on a written certification from a qualified custodian for the investment information. The auditor does not independently verify those assets. A full-scope audit requires the auditor to independently test and verify investment data. Most 401(k) plans held at a bank, brokerage, or insurance carrier qualify for the 103(a)(3)(C) scope.

When is Form 5500 due for a calendar-year plan?

Form 5500 is due July 31 following the close of the plan year. Plan sponsors can file Form 5558 by July 31 to extend the deadline to October 15. Since the completed audit report must be attached to the filing, the audit needs to be finished before the Form 5500 is submitted.

What are the penalties for filing a deficient or late Form 5500?

The DOL can assess penalties of up to $2,670 per day for late or incomplete Form 5500 filings, an amount adjusted annually for inflation and with no statutory maximum. The IRS can separately assess up to $250 per day, capped at $150,000 per plan year, for the same failure. A deficient audit that results in a rejected filing can trigger these penalties and may also expose plan fiduciaries to personal liability. The DOL’s Delinquent Filer Voluntary Compliance Program (DFVCP) offers substantially reduced penalties for sponsors who correct a late filing before the DOL makes contact.

What is the EBPAQC and why does it matter?

The AICPA’s Employee Benefit Plan Audit Quality Center is a voluntary membership center for CPA firms that perform ERISA plan audits. Member firms commit to maintaining designated EBP audit partners, performing annual internal inspections of their EBP practice, and completing continuing education specific to plan auditing. DOL data consistently shows that EBPAQC member firms produce significantly fewer deficient audits than non-members.

How long does a first-year employee benefit plan audit typically take?

A first-year audit generally takes four to ten weeks of elapsed time, depending on plan complexity, how quickly the plan sponsor can provide documents, and the recordkeeper’s turnaround for audit packages. Subsequent years are typically shorter because the auditor carries forward prior-year workpapers. Starting document collection six to eight weeks before you want fieldwork to begin is a reasonable planning horizon.

Filed under: Employee Benefit Plan Audits