ERISA Record Retention: Keeping the Receipts
Most plan sponsors think about retirement plan administration in terms of participant communications, investment oversight, compliance testing and government filings. Record retention rarely makes the list of strategic priorities — at least until an audit, participant claim, litigation or regulatory inquiry suddenly makes years-old documentation critically important.
Establishing an effective record retention policy is less about keeping everything forever and more about understanding what records matter, how long they should be retained, who is responsible for maintaining them, and how the retirement plan’s record retention policy relates to other organizational policies.
Here’s What You Really Need to Know:
- ERISA’s record retention obligations extend well beyond tax records. Plan sponsors often assume record retention requirements are driven primarily by Internal Revenue Service (IRS) rules. In reality, the Employee Retirement Income Security Act (ERISA), the Internal Revenue Code (IRC), the Department of Labor (DOL), and practical fiduciary considerations all create overlapping retention requirements.
- The “six-year rule” is often the floor, not the ceiling. ERISA generally requires records supporting required filings be retained for at least six years after the filing date. However, documents supporting participant benefits (and elections) may need to be retained for decades, and sometimes for the life of the participant and beneficiary relationship.
- Fiduciary processes should be documented contemporaneously. Investment reviews, fee benchmarking exercises, service provider evaluations and other fiduciary decisions are far easier to defend (and more likely to be accurate) when records were created at the time decisions were made rather than reconstructed years later.
Let’s Dive In…
Under ERISA, plan administrators must maintain records sufficient to determine the benefits due, or which may become due to participants and beneficiaries. ERISA section 107 requires records used in preparing annual reports to be retained for at least six years following the filing date of the report to which they relate.[i]
However, other provisions of ERISA and the IRC effectively extend retention periods for many plan records well beyond six years.
For example, participant contribution histories, vesting records, beneficiary designations, distribution elections and rollover documentation may all be needed decades later to determine benefit entitlements or defend fiduciary decisions.
As a practical matter, many experienced practitioners adopt a simple principle: Keep participant records for as long as benefits may be payable and keep fiduciary process documentation for as long as claims relating to those decisions could arise.
How Long Do We Need to Keep This?
Plan sponsors frequently ask, “How long do we need to keep this?” Unfortunately, there is rarely a single answer.
A prudent retention policy typically needs to consider:
· Applicable statutory requirements
· Potential participant claims
· Fiduciary litigation exposure
· Operational correction needs
· Service provider responsibilities
· The cost and feasibility of long-term storage
The result is often a tiered retention approach rather than a single retention period for all records. This approach should also consider how the record retention policy for the retirement plan may intersect with the organizational retention policy or strategy, which may seek to limit retention of records (particularly in electronic format). In some instances, there may need to be an exception in the organization’s record retention policy to ensure overall compliance.
Retention Tiers
- Participant Records
These records establish participant rights and benefits and often warrant the longest retention periods. Examples include enrollment elections, beneficiary designations, deferral elections, distribution requests, rollover documentation, loan applications and repayment histories, QDRO determinations, vesting and service records and payroll records supporting contributions.
RETENTION TIP: Because disputes regarding benefits can arise years or decades later, many practitioners retain these records indefinitely or for many years following final benefit payment.
NOTE: It’s one thing to hang on to these, potentially quite another to be able to locate them later. A good workable filing/retention system is essential, and if paper, then be sure to store them in a climate-controlled environment.
2. Fiduciary Governance Records
These records document the prudent process followed by fiduciaries. Examples include committee charters, meeting agendas and minutes, investment reviews, fee benchmarking studies, service provider evaluations, RFP responses, advisor reports, fiduciary training materials and documentation supporting fiduciary decisions.
RETENTION TIP: In fiduciary litigation, these records often become the primary evidence demonstrating prudence. Consequently, records documenting fiduciary prudence and process should be retained for at least six years, and often longer.
For example, when an investment is selected and retained for many years, fiduciaries should preserve documentation of both the initial selection and subsequent decisions to continue offering the investment, recognizing that the original selection records frequently contain the most detailed analysis supporting the investment’s ongoing inclusion.
3. Compliance and Regulatory Records
Examples include Form 5500 filings and supporting schedules, audit reports, nondiscrimination testing, plan corrections, government correspondence, determination or opinion letters and compliance testing workpapers.
RETENTION TIP: ERISA generally requires retention of records supporting annual filings for at least six years after filing.
4. Participant Disclosure Records
Examples include Summary Plan Descriptions (SPD), Summaries of Material Modifications (SMM), annual notices, fee disclosures, safe harbor notices, automatic enrollment notices and blackout notices.
RETENTION TIP: Increasingly, plan sponsors should retain evidence not only that notices were prepared, but that they were actually distributed.
Who Keeps What?
Another common misconception is that if a recordkeeper, third-party administrator (TPA), payroll provider, or advisor possesses records, the plan sponsor no longer bears responsibility for them.
Not necessarily. Plan administrators (typically the plan sponsor acting as a fiduciary) are responsible for the retention of the plan’s records. While service providers may offer a fiduciary vault or other assistance with records retention, it is ultimately the plan administrator that is responsible for retention of records. Plan fiduciaries should review service agreements where there may be additional information about access to data and information during the relationship and upon termination of the agreement; these provisions are increasingly important as records are primarily electronic and exportable so long as parties cooperate in the process.
Electronic Record Retention
Electronic retention systems may offer substantial advantages over paper records, including searchability, backup capabilities, disaster recovery protections, lower storage costs, and easier production during audits or litigation.
However, electronic records should remain accurate, readily accessible, reproducible in a legible form and protected from unauthorized alteration or destruction.
Cybersecurity protections and retention policies increasingly intersect; review service provider agreements to understand protections of plan information and periodically confirm that service providers continue to meet cybersecurity obligations.
Action Items for Plan Sponsors:
- Evaluate your current record retention practices.
- Inventory the records currently maintained by the organization and service providers.
- Review service agreements to understand record ownership and retention responsibilities.
- Develop or update a written record retention policy and ensure it aligns with the organization’s overall policy.
- Confirm that electronic records can be retrieved in a usable format.
- Review cybersecurity protections applicable to all retained records.
[i] See Employee Retirement Income Security Act of 1974, sec. 107, 29 U.S.C. sec. 1027 (2018).