ERISA · Form 5500
Employee benefit plan audit support
Your 401(k) audits arrive in one compressed window and the staffing math does not work. We prepare the file, both full-scope and ERISA Section 103(a)(3)(C), inside your methodology and your software, so your partners review rather than execute.
We do not sign the opinion and we are not a CPA firm licensed in any US jurisdiction. Your firm remains the auditor of record and retains responsibility for the engagement, including for our work on it.
The arrangement
Where we fit in your plan audit
Settled in the services agreement before the first engagement. A support relationship that is vague about this creates a professional standards problem rather than solving a capacity one.
You
Stays with your firm
- Client acceptance and continuance, and the engagement letter with the plan sponsor
- Independence for the firm and the engagement team, including our people
- Engagement-level risk assessment and the audit strategy
- The decision on whether an ERISA Section 103(a)(3)(C) election is permissible
- Direction, supervision, and review of every workpaper we prepare
- All communication with the sponsor, the committee, and the recordkeeper
- Reading the draft Form 5500 for material inconsistency before dating the report
- The opinion, the reportable findings communication, and the signature
Us
What we do
- Rolling forward the prior-year file and setting up the current-year binder
- Preparing the consolidated PBC list from your template and tracking it to closure
- Trust and recordkeeper reconciliations, and testing of contributions and distributions
- Participant-level testing: eligibility, deferrals, compensation, match, vesting, loans
- Evaluating the recordkeeper SOC 1 and testing complementary user entity controls
- Drafting financial statements, footnotes, and the supplemental schedules
- Drafting proposed reportable findings and management letter points for your review
- Clearing your review notes and documenting the resolution
Coverage
Plan types we staff
- 401(k) and profit sharing plans
- 403(b) plans
- Defined benefit and cash balance plans
- Health and welfare plans
- Employee stock ownership plans (ESOPs)
- Form 11-K filers
- Multiemployer (Taft-Hartley) plans
Each type has one or two areas that carry most of the review risk: compensation definition and match on a 401(k), universal availability on a 403(b), the appraisal and share release on an ESOP. Those are where our seniors go first. Form 11-K work is scoped explicitly against PCAOB Rule 2100 before it starts.
Scope
Full-scope and ERISA Section 103(a)(3)(C) engagements
We prepare both. The election changes the hours materially, so we confirm it per plan during capacity planning rather than discovering it at fieldwork.
Section 103(a)(3)(C)
We agree the certified investment information to the certification, prepare the related documentation, and build the file for the two-section report. Whether the election is permissible, whether the certifying institution qualifies, and whether the certified information is appropriately measured, presented, and disclosed are your firm’s determinations.
Full scope
Where no qualifying certification is available we prepare the investment testing as well: existence, valuation, and the year’s income and transactions. That covers hard-to-value holdings, employer securities, and providers whose statement does not meet the certification requirements. A recordkeeper statement is not automatically a certification.
For the avoidance of doubt: the Section 103(a)(3)(C) election is not a scope limitation, and since SAS 136 it does not produce a disclaimer of opinion. Any support provider still describing it as a “limited scope audit” is working from pre-2021 material.
Procedures
What we prepare and test
A plan audit is largely a test of whether the plan was operated the way its document says. Almost every finding traces back to a gap between the two, and that is where our seniors are trained to look.
- Eligibility and entry dates. Whether employees entered when the document says they should have, and whether anyone was admitted early.
- Deferral elections against amounts withheld. The election on file traced to what payroll actually deducted, tested in both directions.
- The plan’s definition of compensation. The most common source of operational failures. Bonuses, commissions, fringe benefits, and post-severance pay are where the document and the payroll system disagree.
- Employer match and profit sharing formulas. Recalculated from the document, including true-up provisions, allocation conditions, and any last-day or hours requirement.
- Distributions, rollovers, and hardships. Authorization, calculation, tax reporting, and whether the substantiation the document requires actually exists.
- Participant loans. Origination against the loan policy, amortization, and whether defaults were identified and reported when they occurred.
- Timeliness of participant contribution remittances. Tested against how quickly the sponsor’s payroll cycle demonstrably permits segregation, not against an outer limit.
- The recordkeeper SOC 1. We evaluate the report, its period, its exceptions, and the complementary user entity controls it assumes the sponsor performs, then test those controls and draft the reliance memo.
Delivery
How an engagement runs
Onboarding happens once. Everything after that is per engagement, and the elapsed times assume a returning plan with records in reasonable order.
- 01
Capacity plan and services agreement
1–2 weeks·Shared
We size your season from your plan list and agree the engagements we will carry. The services agreement covers confidentiality, data handling, independence, and your right to inspect our work.
- 02
Onboarding to your methodology
2–3 weeks, once·You lead, we execute
Your programs, templates, software, and review standards. We run two pilot engagements under close review before volume starts.
- 03
Planning and PBC management
2–3 weeks per engagement·We support
We prepare the request list in your format and track it to closure. Client contact stays with you: we draft the follow-ups, you send them.
- 04
Fieldwork and workpaper preparation
3–5 weeks per engagement·We execute
Testing under your programs, documented to your standard. Exceptions reach your in-charge as they arise, not in a memo at the end.
- 05
Internal review, then release to you
3–5 days·We execute
Every file passes our own review against your prior-season notes first. We track your review comments per engagement and report the count back monthly.
- 06
Your review, wrap, and access revocation
1–2 weeks·You lead
We clear your notes and document the resolution. You date and sign. Our access is revoked at wrap and re-provisioned next season.
Your side
What we need from your firm
Short list, and most of it is one-time. The recurring items are engagement access and a named in-charge.
- Your audit programs, workpaper templates, and file naming conventions
- Named access to your audit software and document portal, provisioned per engagement
- Your independence questionnaire and confidentiality agreement for our assigned staff
- The signed engagement letter and prior-year file for each plan
- Your review standards, and last season’s review notes if you have them
- A named in-charge on your side for day-to-day questions during fieldwork
Questions
Plan audit support FAQ
What partners and quality control leaders ask before they onboard a support provider.
Do you sign the opinion or issue any report?
No. We are not a CPA firm licensed in any US jurisdiction and we do not perform attest engagements in our own name. We prepare workpapers and draft deliverables under your direction, supervision, and review.
Your firm is the auditor of record. Your firm evaluates the evidence, forms the conclusions, dates and signs the report, and remains responsible for the engagement and for everything we produce on it. We put that in the services agreement so there is no ambiguity in your file or in an inspection.
What do we have to do before we can send you client data?
Under the AICPA Code of Professional Conduct, before disclosing confidential client information to a third-party service provider you must either enter into a contractual agreement with the provider to maintain confidentiality, with reasonable assurance that it has appropriate procedures in place, or obtain specific consent from the client. You remain responsible for the work either way.
We execute that agreement at onboarding and supply the security documentation your quality control team will want: our access model, data handling, background verification, and any independent report on our own controls. Many firms additionally disclose the use of an offshore provider to clients, and we will supply language for that. Whether you disclose, and how, is your call and your professional judgment.
How do you handle independence?
Our people who work on your attest engagements are treated as members of your engagement team. Each completes a written independence confirmation for each engagement, covering the relationships your independence policy asks about, and we retain those confirmations for your file.
We also maintain a restricted entity process at our end so that a person cannot be assigned to an engagement where a conflict has been identified. Independence for the engagement remains your firm’s responsibility and your conclusion to reach. We supply the evidence you need to reach it.
Whose methodology and software do you work in?
Yours. We work inside your audit software, your programs, and your templates, using your file conventions. We do not have a house methodology we ask firms to adopt.
The reason is practical rather than diplomatic. The file has to withstand your review, your internal inspection, and your peer review. A file built to somebody else’s conventions creates review time rather than saving it. Onboarding to a new firm’s methodology takes us two to three weeks and two pilot engagements.
How do you know whether a plan needs an audit at all?
The determination is yours. We track it because it decides how much capacity your season actually needs. For a defined contribution plan with a plan year beginning on or after January 1, 2023, the count is participants with account balances at the start of the year, and the 80–120 rule lets a prior-year small filer stay small until the count exceeds 120.
Send us the plan list at capacity planning and we will flag the ones that look borderline. A plan that turns out to need an audit, discovered in July, is a staffing emergency for you rather than a question of law.
How does SAS 136 affect what you prepare for us?
SAS 136 applies to ERISA plan audits for periods ending on or after December 15, 2021. The visible change is the report form, but the work it added is mostly in the file: engagement acceptance procedures, expanded written representations, a required read of the draft Form 5500 for material inconsistency before the report is dated, and a requirement to communicate reportable findings to those charged with governance.
We prepare the supporting documentation for each of those and draft the reportable findings for your review. The evaluation of whether something rises to a reportable finding, the representations you accept, and the communication itself are yours.
What is your turnaround, and what happens in busy season?
Turnaround is agreed per engagement in the capacity plan rather than quoted as a blanket number, because a first-year plan with three payroll systems is not the same job as a clean second-year rollforward. Typical fieldwork on a returning engagement runs three to five weeks.
Capacity is committed in advance for the season and staffed to that commitment. We would rather decline volume in April than accept it and miss in July. The failure mode that damages a support relationship is not slowness, it is a surprise in the last three weeks before a filing deadline.
How do you protect our clients’ data?
Our people work in your environment or in a controlled virtual desktop with no local storage, no removable media, no printing, and no outbound email. Access is provisioned per engagement, logged, reviewed, and revoked at wrap.
Personnel with client-data access are background-verified and under confidentiality obligations that survive employment. Where we hold an independent report on our own controls or an ISO/IEC 27001 certificate, it is named on this site and we will provide it under NDA. If we do not name one, we do not have one. We would rather tell you that than imply otherwise.
Are you PCAOB-registered, and does that matter for our 11-K plans?
It can matter. Under PCAOB Rule 2100, a firm must register if it prepares or issues an audit report for an issuer, or if it plays a substantial role in the preparation or furnishing of one, which includes performing material services that the signing firm uses or relies on.
For Form 11-K engagements we scope our involvement explicitly against that rule with you before the engagement starts, and we document the conclusion. Our current registration status is stated on this site; if it is not shown, we are not registered, and we will scope 11-K work accordingly or decline it.
Send us your plan list and we'll tell you what we can absorb.
Plan count, types, scope elections, software, and deadlines. You get a written capacity plan, a fee, and the list of what your quality control team will need from us before we start.