Many employee benefit plan sponsors receive a SOC-1 report from their third-party administrator (TPA) each year, but many are uncertain about their responsibility once it is received. Should it be reviewed and if so, by whom? A common misconception is that because the plan’s auditors examine the SOC-1 report during the annual audit, no further action is required by the plan sponsor. However, in reality, plan sponsors retain responsibility for understanding and evaluating the report, and failing to do so can expose the plan to unnecessary compliance, operational, and fiduciary risks.
While auditors review SOC-1 reports as part of their audit risk assessment procedures, responsibility for overseeing service providers remains with plan management and plan fiduciaries. Because key plan functions are outsourced to the third-party administrator (TPA), controls at the TPA may be relevant to the plan’s internal control over financial reporting and overall control environment. As part of prudent oversight of service providers, management should obtain, review, and understand the SOC-1 report and evaluate whether any matters identified may affect the plan. Delegating administrative functions to a third party does not transfer fiduciary responsibility for maintaining effective oversight and monitoring of those services.
What Is a SOC-1 Report?
A SOC-1 (System and Organization Controls) report is an independent examination of a service organization’s internal controls that are relevant to its clients’ financial reporting.
For employee benefit plans, SOC-1 reports are commonly issued by:
- Recordkeepers
- Payroll providers
- Trustees and custodians
- Third-party administrators (TPAs)
- Other service organizations that process plan transactions
The report provides information about:
- The service organization’s control environment
- Control objectives and key control activities
- Testing performed by the independent service auditor
- Results of the auditor’s testing
- Any control deficiencies or exceptions identified
- Complementary User Entity Controls (CUECs) that the plan sponsor is responsible for implementing
Why Should Plan Sponsors Review a SOC-1 Report?
Many plan sponsors outsource significant plan administration functions and assume those processes are operating effectively. However, outsourcing administrative responsibilities does not relieve plan fiduciaries of their oversight obligations. Fiduciary responsibility for the plan remains with management, even when key functions are performed by a third-party service provider.
As plan fiduciaries, management should understand:
- Whether the service provider’s controls are designed and operating effectively
- Whether any control deficiencies, exceptions, or findings were identified
- The potential impact of those findings on plan operations and financial reporting
- Which controls and responsibilities remain with the plan sponsor
A strong governance framework includes obtaining, reviewing, and documenting the review of SOC-1 reports on an annual basis. Because SOC-1 reports are typically issued each year, they may identify changes to the service provider’s control environment, new control exceptions, or updates to the provider’s control environment. Regular review helps plan sponsors demonstrate effective oversight, fulfill fiduciary responsibilities, and proactively address areas of risk.
Who Should Receive the Results of the Review?
Reviewing the SOC-1 report is only part of the oversight process. Any significant exceptions should be considered for communication to those charged with governance rather than remaining solely within Human Resources or Benefits Administration.
Depending on the plan’s governance structure, review results could be shared with:
- Retirement Plan Committees / Benefits Committees
- Board of Directors or other oversight committees, where applicable
Documenting the review and discussing significant findings during committee meetings demonstrates prudent oversight of service providers and helps fulfill fiduciary responsibilities.
The Most Overlooked Section: Complementary User Entity Controls (CUECs)
One of the most important sections of a SOC-1 report is often the one that receives the least attention: the Complementary User Entity Controls (CUECs) section. CUECs are controls that the service organization assumes the plan sponsor has implemented and are operating effectively. In other words, the service provider’s controls are designed to work only if certain controls are also in place at the plan sponsor’s organization. Report users should assess how their organization addresses these controls and consider documenting that assessment as part of their oversight process.
For example, a TPA may assume that the plan sponsor:
- Submits complete and accurate payroll files
- Reviews contribution data before submission
- Restricts system access to authorized personnel
- Communicates user access changes promptly
- Performs reconciliations and monitoring activities
If these controls are not in place, the effectiveness of the TPA’s controls may be significantly reduced. Strong controls at the TPA cannot compensate for a plan sponsor’s weak controls. As the saying goes, “garbage in, garbage out.”
What If the SOC-1 Report Contains Findings?
A common misconception is that control exceptions identified in a SOC-1 report are only relevant to auditors. In fact, plan sponsors should carefully review exceptions identified by the service auditor and document:
- Its understanding of the issue and the circumstances surrounding the exception
- Whether the finding has a direct or indirect impact on the plan
- Any compensating controls that exist
- Any follow-up discussions with the service provider
- Any corrective actions needed within the plan sponsor’s control environment
Ignoring identified exceptions could expose the plan to unnecessary operational, compliance, and financial reporting risks. Management letters commonly recommend that sponsors evaluate relevant exceptions and document their conclusions regarding potential impacts.
What Will Auditors Ask For?
Auditors are increasingly requesting evidence that plan management has reviewed and evaluated SOC-1 reports. While auditors rely on these reports during the audit process, they also look for evidence that plan sponsors are actively monitoring the controls of their service providers.
Typical documentation may include:
- A documented SOC-1 review checklist
- A memorandum summarizing management’s review
- Committee meeting minutes documenting discussion of the report
- Evidence of follow-up on identified exceptions or findings
- Documentation demonstrating that Complementary User Entity Controls (CUECs) have been evaluated and implemented, where applicable
While auditors review SOC-1 reports for audit purposes, management’s review is essential for fulfilling fiduciary responsibilities, overseeing service providers, and maintaining an effective control environment.
Key Takeaway
Obtaining a SOC-1 report is only the first step. To demonstrate effective oversight and fulfill fiduciary responsibilities, plan sponsors should:
- Obtain the SOC-1 report annually
- Review and document their review and conclusions
- Evaluate any identified control exceptions and their potential impact on the plan
- Review CUECs
- Ensure that required controls exist within their organization
- Communicate significant findings and risks to those charged with governance
While your TPA may perform many day-to-day plan administration functions, responsibility for oversight remains with plan management and plan fiduciaries. Implementing a documented annual SOC-1 review process strengthens the plan’s control environment, supports fiduciary compliance, and helps facilitate a more efficient audit process.
How Can Our Unique Perspectives Assist You?
At McConnell Jones, we partner closely with plan sponsors to strengthen audit readiness in practical, scalable ways without unnecessary burden. If you’d like to discuss your plan’s audit readiness or governance practices, please contact Sharjeel Ahsan, EBP Audit Partner, at sahsan@mjlm.com.
Stay connected for more insights to keep your employee benefit plan (EBP) running smoothly.
About McConnell Jones
Founded in 1987, McConnell Jones (MJ) is a nationally recognized CPA firm delivering Assurance, Tax & Accounting, and Advisory services across a broad range of industries. Headquartered in Houston, Texas with offices in Washington, DC; Dallas and Austin, Texas; Durham, North Carolina; and Atlanta and Columbus, Georgia, MJ provides integrated, high-quality solutions backed by specialized expertise and a client-focused approach.
Disclaimer: This article is intended for educational purposes only and should not be considered legal, accounting, or fiduciary advice. Plan sponsors should consult with their legal, accounting, or benefits advisors regarding their specific circumstances.

