Qualified Plan Audit Requirements: How CPAs Prepare Employee Benefit Plans for DOL Review
When a client's 401(k) or pension plan crosses 100 participants, a mandatory DOL audit lands on your desk — often with little warning. This operational guide walks CPAs through the filing trigger, document-gathering checklist, TPA coordination, SAS 136 auditor report requirements, common…
Qualified plan audit requirements catch many general-practice CPAs off guard. A long-time business client hires its 98th employee, total plan participants inch past 100, and suddenly the annual Form 5500 requires an independent auditor's report under ERISA. The plan sponsor calls you — their trusted CPA — expecting you to handle it. Whether you perform the audit yourself or refer it to an ERISA specialist, you need to know exactly what is required, what documents to gather, and how to price the engagement before the filing deadline arrives.
The Department of Labor enforces employee benefit plan audit requirements through the Employee Benefits Security Administration, and the penalties for late or deficient audits are steep — up to $250 per day with no statutory cap under ERISA Section 502(c)(2). Yet most guidance available to CPAs focuses narrowly on Form 5500 mechanics and ignores the operational reality of coordinating with a third-party administrator, satisfying post-SAS 136 auditor report standards, and building a sustainable fee structure for what is often the firm's most technically complex engagement. Understanding qualified plan audit requirements is essential for any CPA advising clients on ERISA compliance, given how aggressively the DOL pursues penalties for deficient or late filings.
This guide covers the full lifecycle: understanding the DOL audit trigger threshold, building your document request list, coordinating with the plan's TPA, identifying the deficiencies that draw DOL scrutiny, deciding whether to handle the audit in-house or refer it out, and pricing the work so it is profitable from year one. You will also find practical notes on how modern CPA practice management tools — including AI document extraction and structured pipeline management — can dramatically reduce the administrative burden of an employee benefit plan audit. Each stage of this lifecycle is shaped by qualified plan audit requirements that dictate not only what must be examined, but when and how findings must be reported.
The DOL Plan Audit Threshold: When the 100-Participant Rule Applies
The foundational trigger for qualified plan audit requirements is participant count. Under ERISA Section 103, a plan that files as a "large plan filer" on Form 5500 must attach an independent qualified public accountant (IQPA) report. Historically, large plan status applied when a plan had 100 or more participants at the beginning of the plan year.
The DOL modernized this threshold in 2023. Under the revised rules, plans with fewer than 100 participants at the beginning of the plan year that previously filed as large plans may elect to file as small plans — but plans crossing the 100-participant line for the first time as of the first day of any plan year must file as large plans and attach an audit. The DOL's Form 5500 filing instructions detail exactly how participant count is measured, including vested terminated participants and deceased participants whose beneficiaries are still receiving benefits. These threshold changes directly affect qualified plan audit requirements, since a plan's classification as large or small determines whether a full-scope independent audit must be attached to the Form 5500.
One common misunderstanding: participant count is not the same as active employee count. A plan with 80 active employees could easily have 120 participants when you include former employees with vested balances who have not yet taken distributions. When you inherit a new benefit plan client, your first task is to request the prior-year participant count schedule from the TPA — not just the year-end census — so you understand whether the large plan filer audit obligation is new or longstanding. For firms evaluating their qualified plan audit requirements approach, this trade-off compounds over time.
The 80-120 rule provides a narrow exception. Plans that had between 80 and 120 participants at the beginning of the plan year and previously filed as a small plan may continue to file as a small plan. Once a plan crosses 121 participants, no exception applies. For any plan approaching or over 100 participants, confirm current-year participant count with the TPA before the Form 5500 due date — which is the last day of the seventh month after the plan year ends (July 31 for calendar-year plans), with an available 2.5-month extension via Form 5558. Each of these factors directly shapes how qualified plan audit requirements plays out in practice, particularly when a plan hovers near the threshold for multiple consecutive years.

Track every return from intake to filed with drag-and-drop pipeline management
In-House Audit vs. ERISA Specialist Referral: The Decision CPAs Must Make
Once you confirm a client's plan triggers the large plan filer audit, you face a real professional decision that almost no published guidance addresses directly: should your firm perform the employee benefit plan audit, or refer it to an ERISA audit specialist? Understanding qualified plan audit requirements in this context is what separates firms that scale from those that stall.
Performing the audit in-house is viable if your firm already has staff with ERISA audit experience, access to current audit software, and a working knowledge of the AICPA's Audit and Accounting Guide: Employee Benefit Plans. The work is technically demanding — ERISA audits involve testing participant data, investment valuation, contributions, benefit payments, and plan document compliance. Without that background, the first-year learning curve is steep and the professional liability risk is significant. The DOL's EBSA conducts periodic quality reviews of employee benefit plan audits, and deficient audits can result in rejection of the Form 5500. This is precisely where a deliberate qualified plan audit requirements strategy pays off.
Referring to an ERISA specialist is the right call for most general-practice CPAs encountering their first benefit plan audit. You retain the client relationship, manage the engagement coordination, and bill a project-management fee while the specialist handles the technical audit work. This is not a loss — it is a risk-appropriate service model. Many regional CPA firms build referral relationships with two or three ERISA audit specialists and generate meaningful revenue by owning the client-coordination and document-preparation layer. Qualified plan audit requirements sits at the center of this decision — get it wrong and the rest unravels.
If you do decide to perform the audit in-house, confirm your firm's professional liability (E&O) policy covers employee benefit plan audits — many policies exclude or sublimit this coverage. Also verify that at least one team member has completed AICPA or state CPA society training specifically on EBP audits. Check your state CPA society for available EBP audit training — this is a distinct competency from general audit work. When firms revisit their qualified plan audit requirements priorities, the gaps usually surface here.
Managing a benefit plan audit alongside your regular tax pipeline without dropping anything?
TaxScout's 12-stage pipeline and AI document extraction keep every document, deadline, and team task organized — so nothing falls through in a high-stakes engagement.

Click any extracted field to see its source highlighted on the original PDF

Smart intake auto-fills from uploaded documents and prior-year data
Qualified Plan Audit Requirements: The Core Document Checklist
Once your firm is engaged, document collection is the first operational bottleneck. Employee benefit plan audits require substantially more documentation than a standard tax engagement, sourced from multiple parties: the plan sponsor, the TPA, the custodian or trustee, and the plan document itself. Building a structured document request list before the engagement starts saves weeks of back-and-forth. Firms that have internalized qualified plan audit requirements from the outset know exactly which documents to request and from whom, which shortens the preliminary phase considerably.
The following categories represent the core document checklist for a first-year ERISA audit for CPAs handling a 401(k) or defined contribution plan:
Plan documents: the original plan document and all amendments, the most recent IRS determination or opinion letter, the Summary Plan Description (SPD) and any SMMs, the adoption agreement if using a prototype plan, and the trust agreement.
Administrative records: the prior three years of Form 5500 and all schedules, the prior year's auditor report if one exists, the TPA service agreement, the fidelity bond certificate (ERISA requires bonding of at least 10% of plan assets, minimum $1,000, maximum $500,000 per 29 CFR § 2550.412-1), and the investment policy statement.
Participant and payroll data: the beginning and end-of-year participant census with contribution elections, the payroll contribution remittance schedule and actual remittance dates (late contributions are among the most common DOL deficiencies), the loan register with origination dates and payment history, hardship withdrawal documentation, and required minimum distribution calculations for participants over age 73.
Financial records: trust statements or custodian reports for all 12 months, investment valuation reports at plan year-end, broker confirmations for any non-publicly-traded investments, and the financial statements prepared by the TPA.
Using a platform with structured file management and configurable pipeline stages means every document category gets a checklist item, an assigned owner, and a deadline — instead of living in a chaotic email thread. For CPAs who also use AI document extraction, Form 5500 schedules and trust statements can be parsed for key figures during the preliminary review phase, flagging inconsistencies before fieldwork begins.
Coordinating with the Plan's Third-Party Administrator
The TPA is the plan sponsor's operational backbone, but TPAs serve the plan sponsor — not the auditor. Your role as the IQPA (or the engagement coordinator if you have referred the audit) is to establish a direct working relationship with the TPA early, set clear timelines for data delivery, and understand exactly what the TPA's records cover versus what the plan sponsor must provide directly.
Request a TPA capabilities meeting before you issue your formal document request. In this meeting, confirm: (1) what formats the TPA uses for census and contribution files (CSV exports from most TPA platforms are standard but formats vary), (2) whether the TPA prepares draft financial statements or only trust accounting reports, (3) the TPA's internal deadline for finalizing year-end data, and (4) whether the TPA has previously worked with an independent auditor and has a standard auditor data package. TPAs that regularly support plans subject to qualified plan audit requirements typically have a structured auditor package ready to deliver, while those unaccustomed to large plan filings may need more lead time.
One area that trips up many first-time EBP auditors is the difference between what the TPA shows as employer contributions and what the payroll records show as actual remittance dates. ERISA requires employer contributions to be remitted to the plan as soon as reasonably segregable from employer assets — for plans with fewer than 100 participants the DOL provides a 7-business-day safe harbor, but large plans have no such blanket safe harbor. Payroll remittance testing is almost always on the DOL's radar. Reconcile the payroll register to the trust statements line by line and document the timing for every remittance.
Also verify that the TPA has filed or will file Schedule C of Form 5500 for all service providers receiving $5,000 or more in direct or indirect compensation during the plan year. Missing or inaccurate Schedule C entries are a frequent Form 5500 audit requirement deficiency. See our other resources on ERISA compliance topics for additional guidance on Form 5500 schedules.

Real-time dashboard showing returns in progress, revenue, and upcoming deadlines
SAS 136 and the New Auditor Report Format for Benefit Plans
The AICPA's Statement on Auditing Standards No. 136, Forming an Opinion and Reporting on Financial Statements of Employee Benefit Plans Subject to ERISA, became effective for plan years ending on or after December 15, 2021. Implementation was uneven, and the 2023 audit cycle was the first year DOL reviewers applied heightened scrutiny to SAS 136 compliance. If you are inheriting a plan that was previously audited, one of your first steps should be reviewing the prior auditor's report format for SAS 136 compliance. This review is itself part of satisfying qualified plan audit requirements, since the DOL can reject a Form 5500 when the attached auditor report fails to meet current professional standards.
SAS 136 made three structural changes CPAs must understand. First, it eliminated the "limited scope" audit designation and replaced it with an "ERISA Section 103(a)(3)(C) audit" — an audit where the auditor does not audit investment information certified by a qualified institution (typically the plan's custodian or trustee). This is now a distinct, named engagement type with its own auditor report language, not simply a scope limitation. Second, the new standard requires management to formally acknowledge in writing that it is responsible for maintaining the plan document, determining the plan's compliance with ERISA, and assessing whether the certified investment information is from a qualified institution. Third, the auditor's report must now include a separate section titled "Basis for Opinion" and must specifically describe procedures performed on the certified investment information even when that information is excluded from the audit opinion.
If the prior auditor used a pre-SAS 136 report format, the DOL may treat the filing as non-compliant regardless of the underlying audit quality. For a practical reference on the new report language, the AICPA's EBP audit resources published in the Journal of Accountancy provide illustrative reports that you can adapt with your engagement-specific facts.
From a workflow perspective, SAS 136 also requires you to obtain the certifying institution's name and the scope of the certification before fieldwork. Build this into your TPA coordination meeting — you need the custodian's certification letter on file before you can issue your auditor's report, and custodians sometimes have multi-week turnaround times for producing these letters on formal letterhead.

AI classifies, extracts, and validates every document automatically
Common Deficiencies That Draw DOL Penalties
The DOL's EBSA publishes annual enforcement statistics, and the patterns in rejected or deficient Form 5500 filings are consistent year over year. Understanding these deficiencies protects your client and protects your firm from being associated with a substandard filing. The DOL's most recent enforcement data documents the most common areas of civil and criminal enforcement.
Late contribution remittances are the single most common operational deficiency. When employer or employee contributions are not remitted to the trust within the plan's standard remittance timeline, the plan has a prohibited transaction under ERISA Section 406. The correction mechanism is the DOL's Voluntary Fiduciary Correction Program (VFCP), which requires the plan sponsor to restore lost earnings calculated using the IRS underpayment rate from the date the contribution should have been deposited. If you find late remittances during your review, advise the client to initiate VFCP before the Form 5500 is filed — filing without correction increases the likelihood of an EBSA investigation.
Inadequate fidelity bonding is pervasive among smaller large plans. ERISA requires every plan official who handles plan funds to be bonded. Many plan sponsors allow their original fidelity bond to lapse or fail to update the bond amount as plan assets grow. Verify the bond amount against current plan assets and confirm the bond covers all required parties. The DOL's bonding guidance provides a clear explanation of who must be bonded and for how much.
Failure to follow plan document terms is another frequent finding. Common examples include failing to apply the correct vesting schedule to terminated participants, allowing hardship distributions without documenting all required elements, or failing to update the plan document when IRS determination letter cycles expire. During your review, select a sample of participant transactions — contributions, loans, distributions, and forfeitures — and trace each transaction to the specific plan document provision authorizing it. Each of these operational failures represents a breakdown in qualified plan audit requirements compliance that the DOL's enforcement program is specifically designed to detect and penalize.
For general-practice CPAs who have also worked on the client's business return, it is worth noting that the S corp reasonable compensation issue and benefit plan participation for owner-employees are closely linked — the compensation used to calculate contributions must be correctly defined compensation under the plan document and IRS rules, not simply W-2 wages.

Every client gets organized documents, status tracking, and a complete history
Pricing the Employee Benefit Plan Audit as a Recurring Engagement
The complete absence of pricing benchmarks in CPA literature on employee benefit plan audits is a genuine gap. Most CPAs either underprice their first EBP audit — treating it as an extension of the tax return — or pass on the engagement entirely because they cannot confidently scope it. Neither outcome serves the firm.
ERISA audits for CPAs are priced on a combination of plan complexity, participant count, investment type, number of transactions to test, and whether an ERISA Section 103(a)(3)(C) election is available. Based on published fee surveys and AICPA data, first-year full-scope audits for plans with 100-300 participants typically range from $8,000 to $18,000 depending on plan type and the number of investment options. ERISA Section 103(a)(3)(C) audits (where investment information is certified by the custodian) are less time-intensive and commonly priced $4,000-$10,000 in the same participant range. Defined benefit plans and plans with employer stock or hard-to-value investments command significant premiums.
Price the engagement separately from the Form 5500 preparation. Many CPAs bundle the audit with Form 5500 preparation, which obscures the audit's true cost and makes it harder to raise fees in subsequent years as your team becomes more efficient. A separate engagement letter for the audit — signed before fieldwork begins — is both a professional standards requirement and a billing best practice. For guidance on structuring your engagement terms, see the engagement profitability analysis guide and the related discussion of value-based pricing.
Structure the recurring engagement as an annual retainer that includes: the audit itself, the Form 5500 preparation or review (if the TPA prepares the draft), and a mid-year compliance checkup call to flag any contribution remittance or plan document issues before year-end. This positions you as a proactive ERISA partner rather than a once-a-year filing vendor, and it makes the annual fee conversation straightforward. Bill the engagement using your firm's standard invoicing workflow — platforms like TaxScout support Stripe-based invoicing that keeps benefit plan engagements in the same billing system as your tax work, simplifying accounts receivable management.
For CPA firms building out their service menu, the employee benefit plan audit is a strong anchor for a broader advisory offering that includes plan design consulting, investment committee support, and fiduciary compliance reviews. The business valuation for CPAs guide offers a parallel example of how CPAs can expand into technically specialized engagements without building a separate practice from scratch.

Review with AI assist — 9 agents answer questions with full client context
Using Practice Management Technology to Run the EBP Audit Workflow
An employee benefit plan audit involves more parties, more document categories, and more external deadlines than virtually any other engagement type. Without a structured workflow system, the administrative overhead alone can eliminate the engagement's profitability.
A pipeline management system with customizable stages lets you map the EBP audit workflow explicitly: engagement letter signed, TPA coordination meeting completed, document request issued, documents received and inventoried, preliminary analytics completed, fieldwork in progress, draft report to client, client response received, final report issued, Form 5500 filed. Each stage has an owner, a due date, and a checklist. When a document arrives late from the TPA or a client confirmation is outstanding, the system surfaces the bottleneck before it delays the filing.
Document handling is where AI tools provide the clearest efficiency gain. Form 5500 schedules, trust statements, and participant census files all contain structured data that can be extracted and cross-referenced using AI document extraction — reducing the manual reconciliation work that makes first-year EBP audits so time-intensive. The 5-layer validation pipeline (document quality routing, AI extraction with confidence scoring, OCR cross-verification, deterministic math rules, and cross-document validation) is particularly valuable when reconciling TPA-reported figures against custodian statements.
Client communication during an EBP audit is heavier than in a standard tax engagement — you will be requesting documents from both the plan sponsor and the TPA, sending draft reports for management review, and documenting responses to audit findings. Centralizing all of this through a client portal with structured document requests and OTP-secured access eliminates version-control problems and creates a defensible paper trail if the DOL later requests your workpapers.
Finally, use your AI research agents to stay current on EBSA guidance, DOL enforcement letters, and IRS determination letter updates — all of which affect the plan documents and compliance representations you are auditing. The 9 specialized research agents in TaxScout connect in real time to IRS, Treasury, Cornell Law, and SSA sources, giving you current regulatory context without a separate research subscription.
Managing your first employee benefit plan audit without losing the rest of your tax season?
TaxScout gives CPA firms a structured pipeline, AI document extraction, and a secure client portal — everything you need to run a high-stakes ERISA engagement without adding headcount.

Your clients see your brand — OTP login, document upload, and real-time status
Frequently Asked Questions
A plan must attach an independent auditor's report to its Form 5500 when it files as a large plan filer — generally when it has 100 or more participants at the beginning of the plan year. Participant count includes active employees, vested terminated employees who have not taken distributions, and beneficiaries receiving benefits. The 80-120 rule allows plans between 80 and 120 participants to continue filing as small plans if they previously filed as small plans, but once a plan exceeds 120 participants the exception no longer applies.
Keep reading
Stay up to date
Get the latest tax tech insights delivered to your inbox.