Skip to content

Insights

SAS 136 401(k) Audit: What Plan Sponsors Must Provide

The short answer: A SAS 136 401(k) audit is the AICPA-defined examination (AU-C section 703) of an ERISA plan’s financial statements, and the standard has been required for plan years ending on or after December 15, 2021. It reshaped what plan sponsors must hand the auditor.

  • SAS 136 retired the “limited-scope audit” and replaced it with the ERISA Section 103(a)(3)(C) audit, which is no longer treated as a scope limitation.
  • Management now has written responsibilities, including providing a substantially complete draft Form 5500 before the auditor dates the report.
  • The DOL’s November 2023 audit-quality study found a 30% deficiency rate across 307 audits reviewed, so being ready with clean records matters.

A SAS 136 401(k) audit changed less about the numbers on your plan’s financial statements and more about who is responsible for what. The standard, effective for plan years ending on or after December 15, 2021, redefined the sponsor’s role, renamed the old “limited-scope” engagement, and reformatted the auditor’s report. If your 401(k) plan is a large-plan filer, this is the audit that attaches to your Form 5500.

This guide explains what SAS 136 actually changed for employee benefit plan (ERISA) audits, then gives plan sponsors and controllers the exact list of documents and records the auditor will ask for. Every standard and threshold cited here traces to the AICPA, the Department of Labor, or the underlying statute.

What Is a SAS 136 401(k) Audit?

A SAS 136 401(k) audit is the independent audit of an ERISA-covered retirement plan’s financial statements performed under AICPA Statement on Auditing Standards No. 136. The standard is codified in AU-C section 703, “Forming an Opinion and Reporting on Financial Statements of Employee Benefit Plans Subject to ERISA,” and it governs how the auditor forms an opinion and structures the report.

SAS No. 136 was issued in July 2019. It became effective for plan financial statements for periods ending on or after December 15, 2021. The original December 15, 2020 date was deferred one year by the AICPA Auditing Standards Board because of COVID-19. So calendar-year 2021 plan audits performed in 2022 were the first required to apply it, per the AICPA’s Journal of Accountancy.

What Is the Difference Between SAS 136 and a Limited-Scope Audit?

The difference is that SAS 136 eliminated the term “limited-scope audit” and replaced it with the “ERISA Section 103(a)(3)(C) audit,” which is expressly no longer treated as a scope limitation. Instead of the old disclaimer of opinion, the auditor now issues a two-part opinion. The engagement is a distinct type of audit, not a lesser one.

DimensionOld “Limited-Scope Audit” (pre-SAS 136)ERISA Section 103(a)(3)(C) Audit (SAS 136)
NameLimited-scope auditERISA Section 103(a)(3)(C) audit
Treated as a scope limitation?YesNo
Form of opinionDisclaimer of opinionTwo-part opinion
Sponsor’s written dutiesMinimalMust determine permissibility and confirm the certification
Report formatPrior AU-C formatReformatted under AU-C section 703

What Is an ERISA Section 103(a)(3)(C) Audit?

An ERISA Section 103(a)(3)(C) audit is one in which the auditor’s examination does not extend to investment information that a qualified institution has prepared and certified. It exists because the statute itself permits it. Under 29 U.S.C. 1023(a)(3)(C), the accountant’s opinion “need not be expressed as to any statements … prepared by a bank or similar institution or insurance carrier … if such statements are certified” and made part of the annual report. The plan still gets an audit. The auditor simply relies on the certified figures for those assets.

The implementing DOL regulation restates the scope. As 29 CFR 2520.103-8(a) puts it:

“Under the authority of section 103(a)(3)(C) of the Act, the examination and report of an independent qualified public accountant need not extend to any statement or information prepared and certified by a bank or similar institution or insurance carrier.” — 29 CFR 2520.103-8(a), U.S. Department of Labor / EBSA

Who Is a Qualified Institution Under ERISA Section 103(a)(3)(C)?

A qualified institution is a bank, similar institution, or insurance carrier that is regulated, supervised, and subject to periodic examination by a State or Federal agency. Broker-dealers and mutual fund companies do not qualify. The certification must comply with 29 CFR 2520.103-5: prepared and certified in writing as to completeness and accuracy, and signed by an authorized representative. The plan administrator, not the auditor, must confirm the certifier qualifies before the audit begins.

What Are Management’s Responsibilities Under SAS 136?

Under SAS 136, plan management (the sponsor) has expanded, explicit responsibilities that it must acknowledge in writing. These duties existed in substance before, but the standard now requires the sponsor to own them on the record rather than leave them implied.

  1. Maintain a current plan instrument, including all amendments, and acknowledge that responsibility in writing.
  2. Administer the plan and determine that transactions comply with the plan’s terms.
  3. For a Section 103(a)(3)(C) audit, determine the election is permissible, confirm the investment certification is from a qualified institution, and confirm it meets ERISA requirements.
  4. Provide the auditor a substantially complete draft Form 5500 for review before the auditor dates the audit report.

What this means for you: the draft Form 5500 is now a gating item. If it is not substantially complete, the auditor cannot date the report, and the July 31 filing deadline for a calendar-year plan does not move to accommodate the delay.

How Did SAS 136 Change the Auditor’s Report?

SAS 136 reformatted the auditor’s report and moved the opinion to the top. For an ERISA Section 103(a)(3)(C) audit, the disclaimer was replaced by a two-part opinion. The first part covers whether the non-certified financial-statement information is presented fairly. The second covers whether the certified investment information agrees with, or reconciles to, the certification. The report also now describes management’s responsibilities and the nature of the 103(a)(3)(C) audit directly. That is why the written acknowledgments above matter.

What Do Plan Sponsors Need to Provide for a 401(k) Audit?

Plan sponsors need to provide the governing plan documents, participant and payroll data, the certified investment information, and a substantially complete draft Form 5500. The auditor uses these to test contributions, distributions, eligibility, and investment reconciliation. The table below is the working checklist most audit teams request at the start of fieldwork.

Document or RecordWhy the Auditor Needs ItWhere It Comes From
Executed plan document, all amendments, and the IRS determination or opinion letterConfirms the plan terms being audited and tax-qualified statusSponsor / plan document provider
Summary Plan Description (SPD)Corroborates eligibility, vesting, and contribution termsSponsor / TPA
Recordkeeper and third-party administrator service agreementsEstablishes duties, fees, and controls in placeSponsor
Certified trust statement / investment certificationSupports the Section 103(a)(3)(C) election and investment reconciliationQualified institution (bank or insurer)
Participant census and eligibility dataTests who was eligible, enrolled, and correctly includedSponsor / payroll
Payroll registers and contribution remittance detailTests deferrals, match, and timeliness of depositsSponsor / payroll provider
Distribution, rollover, and participant loan recordsTests that payouts and loans followed plan termsRecordkeeper
Board or committee minutes and the ERISA fidelity bondEvidences plan governance and required bondingSponsor
Substantially complete draft Form 5500Required before the auditor dates the reportSponsor / TPA
Prior-year audit report and financial statementsProvides opening balances and comparativesSponsor / prior auditor

Keep these records available even after filing. ERISA Section 107 (29 U.S.C. 1027) requires records supporting the annual report to be retained for not less than six years after the filing date, and the IRS advises keeping the plan document, amendments, and determination letters for as long as they are relevant.

For how these documents map to the filing calendar and the participant-count math that determines whether you need an audit at all, see our Form 5500 and 401(k) audit-readiness guide, and learn how we run these engagements on our employee benefit plan audit services page.

When Did SAS 136 Take Effect, and When Is the Audit Due?

SAS 136 took effect for audits of ERISA plan financial statements for periods ending on or after December 15, 2021. Separately, a 401(k) plan generally needs an audit attached to its Form 5500 once it is a large-plan filer. That means 100 or more participants at the beginning of the plan year. For plan years beginning on or after January 1, 2023, defined contribution plans count only participants with an account balance. The DOL estimated that change would relieve roughly 19,500 plans of the annual audit requirement.

The Form 5500, with the audited financial statements, is due the last day of the seventh month after the plan year ends, which is July 31 for a calendar-year plan, and it must be filed electronically through EFAST2.

Frequently Asked Questions

Is a Draft Form 5500 Required Before the Audit Can Be Completed?

Yes. SAS 136 requires the sponsor to provide the auditor a substantially complete draft Form 5500 for review before the auditor dates the audit report. A missing or incomplete draft is a common reason an audit stalls near the July 31 deadline.

What Is a Reportable Finding Under SAS 136?

A reportable finding is a matter the auditor is required to communicate in writing to those charged with plan governance. It can include an identified instance of noncompliance with the plan document, a deficiency in internal control the auditor considers significant, or a finding the auditor judges important enough to merit management’s attention.

Does the 80-to-120 Participant Rule Affect Whether I Need a SAS 136 Audit?

It can. Under the DOL’s 80-to-120 participant rule, a plan with 80 to 120 participants at the beginning of the plan year may continue filing in the same category (small or large) it used the prior year, which can defer a first-time audit until the count exceeds the threshold. Our audit-readiness guide works through the count.

Next steps: If your plan is approaching the 100-participant line or facing its first SAS 136 audit, the volume of work an auditor does matters. The DOL’s 2023 study found firms performing only one or two plan audits had a 70% deficiency rate, while firms auditing more than 100 plans had rates of 19.2% for simple 401(k) and 403(b) plans. Choosing an experienced benefit-plan auditor is a direct quality decision.

Contact Us

WhippleWood CPAs performs employee benefit plan audits under SAS 136 for Denver-area and Colorado plan sponsors. If you want a clear read on what your plan will need to provide and when, contact us and we will walk you through it.

About the Author

Ron Bass CPA

Ron Bass CPA

Ron has led WhippleWood’s auditing practice since 2010. His career began in 1990 and includes time spent as a private company controller and ten years as an auditor for the largest CPA firm in Florida. He has audited publicly traded corporations, consolidated international corporations, state and local regulatory agencies, employee benefit plans, internal processes and controls, and nonprofit entities.

View Bio

Contact Ron

Name*

Interested in Learning More?

Connect with us to find out how we can help address your most complex challenge.