
Ashley Bell, CPA
Partner
Retirement plan governance is not just a concern for large employers. Whether a plan has 25 participants or 2,500, the plan sponsor is responsible for overseeing the plan and protecting participants’ interests. One of the most effective ways to manage this responsibility is through a retirement plan committee.
Why Have a Committee?
ERISA does not generally require every retirement plan to have a committee with that specific title. However, a committee creates accountability and provides a structured process for overseeing the plan.
For a smaller organization, the committee may consist of only two or three individuals from management, finance, payroll, or human resources.
Committee Responsibilities
A retirement plan committee creates accountability and provides a structured process for fiduciary oversight.
Monitor Plan Operations
Review Investments & Fees
Identify Errors & Risks
Respond to Participant Concerns
Document Decisions & Corrective Actions
Hiring a recordkeeper, third-party administrator, or investment adviser does not eliminate the plan sponsor’s responsibility. Selecting and monitoring these providers are fiduciary functions. The Department of Labor recommends establishing and following a formal review process to evaluate provider performance, fees, and services. See its guidance on hiring and monitoring retirement plan service providers.
Due Diligence Requires Active Oversight
The Department of Labor emphasizes the importance of a prudent and well-documented process. Fiduciaries are not expected to prevent every error or guarantee investment results. They are expected to obtain appropriate information, make informed decisions, and investigate concerns.
Good oversight follows a “trust but verify” approach. Reports should not simply be received and filed. They should be reviewed, reconciled when appropriate, and questioned when information is incomplete or inconsistent.
Many errors and instances of fraud continue because no one independently reviews plan activity or follows up on warning signs.
Employee contributions that are not deposited timely.
Differences between payroll and recordkeeper reports.
Unexplained plan expenses or payments to unfamiliar parties.
Distributions or loans without adequate support.
Changes to participant banking information shortly before a distribution.
One person controlling payroll, approvals, processing, and reconciliation.
Repeated participant complaints or unresolved discrepancies.
Retirement Plan Committee Checklist
A committee should consider covering the following areas during the year:
Governance & Compliance
- Confirm committee members understand their fiduciary responsibilities.
- Maintain a committee charter or policy and written meeting minutes.
- Review the plan document and confirm operations follow its provisions.
- Monitor participant notices, Form 5500 filings, and plan audits.
- Review compliance issues and confirm corrective actions are completed.
Plan Operations & Internal Controls
- Review eligibility, contributions, compensation, vesting, and forfeitures.
- Monitor the timeliness of employee contribution deposits.
- Reconcile payroll information to recordkeeper reports.
- Review loans, distributions, and required minimum distributions.
- Evaluate whether system access and approval responsibilities are properly separated.
- Investigate unusual transactions, participant complaints, and recurring errors.
Investments, Fees & Providers
- Review investment performance and the plan's investment lineup.
- Evaluate whether fees remain reasonable for the services received.
- Monitor recordkeepers, administrators, advisers, and other providers.
- Obtain and review current SOC 1 reports from applicable service providers.
- Identify complementary user entity controls and confirm implementation.
- Review provider errors, service concerns, and cybersecurity practices.
- Periodically benchmark fees and services against available alternatives.
SOC 1 reports provide information about controls maintained by service providers that may affect the plan’s financial reporting. However, obtaining the report is only the first step. The committee should review the auditor’s opinion, control-testing exceptions, report coverage period, and any relevant subservice organizations. If the report does not cover the entire period, the committee may also need to obtain a bridge letter.
Of particular importance are the complementary user entity controls, or CUECs. These are controls the service provider assumes the plan sponsor has implemented, such as reviewing reports, approving transactions, restricting system access, and reconciling payroll information. The committee should assign responsibility for each applicable control and document that it is operating. A service provider’s controls cannot compensate for controls the plan sponsor was expected—but failed—to perform.
Quarterly meetings are practical for many plans, although the appropriate frequency will depend on the plan’s size and complexity. Each meeting should document the information reviewed, questions asked, decisions made, and follow-up responsibilities assigned.
Oversight Matters at Every Size
A retirement plan committee does not have to be complicated. Even a short, well-organized meeting can create accountability, identify problems earlier, and demonstrate that fiduciaries are actively fulfilling their responsibilities.The most important step is ensuring that plan oversight is assigned, performed, and documented—not assumed.
Additional Department of Labor Resources
The following Department of Labor resources provide additional support and guidance for plan sponsors and fiduciaries:
• Meeting Your Fiduciary Responsibilities
• Hiring and Monitoring Retirement Plan Service Providers
• Understanding Retirement Plan Fees and Expenses
• Cybersecurity Program Best Practices
Questions About Retirement Plan Governance?
Retirement plan governance does not need to be complicated, but it does require ongoing oversight and documentation. If you have questions about retirement plan committee responsibilities, fiduciary oversight, internal controls, or service provider monitoring, contact a member of HBE's Employee Benefit Plan team.
Contact Our Team