
There are two very different things people mean when they say "benefit plan audit," and mixing them up causes more unnecessary panic than almost any other compliance topic. One is a routine, expected financial statement audit tied to your Form 5500 filing. The other is a DOL investigation - something that can happen to any plan, audited or not, for entirely different reasons. Knowing which one you're dealing with, and being ready for both, is the actual goal here.
Do you even need a financial statement audit?
Large employee benefit plans - generally those with 100 or more participants at the start of the plan year - are typically required to include an audited financial statement, prepared by an independent qualified public accountant (IQPA), with their Form 5500 filing. Plans can sometimes use the "80-120 participant rule" to avoid triggering the large-plan audit requirement in a year where participant counts fluctuate right around the threshold, filing as a small plan if they qualified as one in the prior year and stayed under 120 participants.
- If you crossed 100 participants this year for the first time, don't assume you're automatically required to audit - check whether the 80-120 rule applies to your specific situation
- If you've been a large filer for several years, confirm your auditor engagement is locked in early, since qualified employee benefit plan auditors are in real demand around filing season
What auditors are actually looking for
Employee benefit plan audits changed meaningfully with the introduction of SAS No. 136, an auditing standard that reshaped how these audits are performed and reported, particularly for ERISA Section 103(a)(3)(C) audits (formerly called "limited scope" audits). Auditors under this standard are expected to:
- Test the accuracy of participant data - contributions, eligibility, distributions - against underlying source records, not just plan-level summaries
- Evaluate internal controls around plan administration, not solely the year-end financial statements
- Report specific findings tied to ERISA compliance, not only generic accounting opinions
This means an audit increasingly functions as a real check on whether your plan's data is accurate and well-documented - not just a formality that produces a clean opinion letter.
Common findings that surface during plan audits
- Participant contribution timing that doesn't match the DOL's requirement to remit employee deferrals as soon as administratively feasible, rather than on a delayed schedule
- Eligibility determinations that don't reconcile with HRIS or payroll records
- Missing or incomplete documentation supporting distributions, loans, or hardship withdrawals where applicable
- Outdated or inconsistent plan documents that don't match how the plan is actually being administered in practice - a gap we cover in detail in our companion piece, ERISA plan documents 101: summary plan description vs. wrap document explained.
A 2026 readiness checklist
- Confirm whether your plan meets the large-plan audit threshold this year, factoring in the 80-120 rule if applicable
- Engage your auditor early - waiting until close to the Form 5500 deadline compresses a process that benefits from lead time
- Reconcile participant eligibility and contribution data across payroll, HRIS, and the plan administrator's records before the audit begins, not during it
- Gather documentation for any plan amendments, distributions, or unusual transactions from the plan year in advance
- Review whether your plan document, SPD, and actual administrative practice are still aligned - auditors will notice if they aren't
- Confirm your data trail is actually auditable - can you produce a clear record of who approved a given eligibility or contribution decision, and when?
What actually happens in a DOL audit (a plain-language walkthrough)
A DOL investigation, typically conducted by the Employee Benefits Security Administration (EBSA), is a different process entirely from a financial statement audit, and it can happen regardless of whether your plan is subject to the large-plan audit requirement.
- It usually starts with a letter. EBSA typically opens an investigation with a written request for specific documents - plan documents, SPDs, Form 5500 filings, participant records, and often documentation of specific processes like eligibility determinations or vendor oversight.
- Document requests come first, interviews often follow. Depending on what the initial documents show, EBSA may follow up with interviews of plan administrators, HR staff, or third-party vendors.
- Scope can expand. An investigation that starts around one issue - say, a delinquent Form 5500 - can expand if reviewers identify unrelated red flags, like inconsistent eligibility data or missing fiduciary documentation.
- Corrections are often possible. If EBSA identifies issues, employers may have the option to correct certain problems voluntarily, sometimes through formal programs like the Voluntary Fiduciary Correction Program (VFCP), which can reduce exposure compared to a fully adversarial enforcement outcome.
- Documentation is the difference-maker. Employers who can produce a clear, dated record of decisions, reviews, and corrections tend to navigate investigations far more smoothly than employers who can explain their process verbally but can't actually show it.
This exact walkthrough - in more depth, with real scenarios - is what we're covering in our upcoming webinar, Plan Documents, Filings & Audits: Mastering 2026 Employer Obligations, including a plain-language answer to what actually happens in a DOL audit from start to finish. Save your seat here.
The connection between audit readiness and clean data
Almost every item on this checklist traces back to the same root cause when it goes wrong: data that lives in disconnected systems and was never properly reconciled. Auditors and DOL investigators are both, in different ways, testing whether your plan's paperwork matches what actually happened operationally - and that match is only as good as the underlying data feeding it. It's part of why real-time system integration between payroll, HRIS, and plan administration has become less of a "nice to have" and more of a genuine audit-readiness tool in its own right.
This is also exactly why Form 5500 filing quality and audit readiness are really the same conversation - a plan that's audit-ready generally has few surprises left by the time the extended October 15 filing deadline arrives. And the same evaluation lens applies beyond major medical: our HSA administrator evaluation checklist covers exactly this kind of audit-trail and documentation criteria when choosing a vendor for account-based benefits. For the bigger-picture view of why regulators are focused on demonstrable process rather than just correct outcomes, see where 2026 compliance risk actually concentrates.
Auditors reviewing account-based benefits specifically will also want to see that your administrator can substantiate eligibility decisions the way we describe in our FSA vs. HSA vs. HRA administrator comparison, and that state-level tax treatment for HSA-enrolled employees - like the exceptions we cover in our piece on multi-state HSA compliance - has actually been applied correctly rather than assumed.
Frequently asked questions
How do I know if my plan needs an audited financial statement?
Generally, plans with 100 or more participants at the start of the plan year require one, though the 80-120 participant rule can allow some plans to avoid triggering the requirement in a transition year. Confirm your specific plan's status with your administrator or auditor.
What is the 80-120 participant rule?
It allows a plan that qualified as a small plan filer in the prior year to continue filing as one, even if participant count rises, as long as it stays under 120 participants - preventing plans from being forced into large-plan audit status due to minor, temporary fluctuations.
What is SAS No. 136, and how does it affect benefit plan audits?
SAS No. 136 is an auditing standard that reshaped how employee benefit plan audits are performed and reported, particularly for ERISA Section 103(a)(3)(C) audits (formerly "limited scope" audits) - requiring deeper testing of participant data and internal controls, not just year-end financials.
Is a DOL audit the same as a financial statement audit?
No. A financial statement audit is a routine part of Form 5500 compliance for large plans. A DOL investigation is a separate regulatory process that can happen to any plan, regardless of size or audit status.
What triggers a DOL investigation of a benefit plan?
Triggers can include participant complaints, red flags identified in a Form 5500 filing, referrals from other agencies, or simply random selection as part of EBSA's ongoing enforcement activity - there isn't always a single identifiable cause.
What is the Voluntary Fiduciary Correction Program (VFCP)?
VFCP is a DOL program that allows plan officials to voluntarily correct certain fiduciary violations and avoid civil enforcement action, often with reduced penalties compared to a fully adversarial DOL investigation outcome.
What's the single best thing an employer can do to prepare for either kind of audit? Maintain clear, consistent documentation of plan decisions - eligibility determinations, contribution timing, plan amendments - as they happen, rather than trying to reconstruct the reasoning after the fact.
Want the full walkthrough of what actually happens in a DOL audit, plus a readiness framework you can use before renewal season? Join us for Plan Documents, Filings & Audits: Mastering 2026 Employer Obligations on October 7, 2026, 11:00 AM ET / 10:00 AM CT. Save your free spot.
or schedule a demo or request more information today.
Get Clarity today!