Navigating Peer Reviews and DOL Inspections of 401(k) Audits

Business Opportunities
October 24, 2025


When is it Compliance—and when is it just opinion? Peer reviews and Department of Labor (DOL) inspections of 401(k) audits can be challenging, especially for small and mid-sized firms. Brian Price, CEO of Autire Technologies, shares his top tips for auditors navigating the process.

Autire navigating peer reviews

Why Standards Matter

Compliance risks in auditing employee benefit plans can have serious consequences for CPA firms: heavy fines, reputational damage, even loss of license. These risks underscore why understanding the standards governing 401(k) audits is non-negotiable.

To effectively defend against a reviewer’s findings, auditors must not only be familiar with the standards but also be able to reference them during reviews. This will empower firms to push back when necessary and confidently challenge findings that are based on subjective opinions rather than clear requirements.

Standards vs. Opinion: The Form 5500 Example

A frequent source of confusion is Form 5500 documentation. AU-C 703 requires auditors to review the substantially complete draft Form 5500 and resolve any inconsistencies with the plan’s financial statements. It does not require retaining the final signed version if changes were immaterial.

For example, “Sam” reviewed the draft Form 5500, identified inconsistencies, and confirmed corrections were made. The documentation showed this process, but the final draft was not placed in the binder. A peer reviewer still penalized the firm, claiming the final version was required.

In reality, the standard was met. Had the firm familiarized themselves with the standards—in this case, AU-C Section 703, Considerations Relating to Form 5500 Filing—they could have confidently pushed back. Instead, they accepted the penalty, not because of a legitimate issue, but because the auditor didn’t know the standard well enough to defend his position.

Takeaway: Always anchor findings to codified standards. If it isn’t written there, it’s preference—not compliance.

Don’t Over-Audit: Census Data

Confusion doesn’t always start at the peer review level. It can happen before the audit is submitted, amongst your own audit team.

A compliance officer wanted her team to verify census data used for discrimination testing. But AU-C 703, Section .A31 requires only that the auditor confirm the plan’s TPA performed the tests, management reviewed them, and failures were addressed. While verifying census data line-by-line might seem like thorough auditing, it’s not required.

Takeaway: Over-auditing only adds unnecessary time to what is already a laborious audit process. Know where to draw the line between what’s required and what’s not.

Payment Testing in a Digital World

Benefit payment testing is another area where inspectors’ preferences may not match current practice. The AICPA Employee Benefit Plans Audit Guide lists multiple acceptable methods, including comparing EFTs to participant records. Cancelled checks remain valid, but most banks no longer provide them.

In one case, a DOL agent claimed a 401(k) audit was deficient because the firm didn’t use cancelled checks. The auditor had instead tested EFTs against participant records, a method specifically endorsed by the guide. By citing the guidance, the auditor persuaded the agent their approach was compliant.

Takeaway: Know all the testing methods permitted by the guide. If you follow one of them, your work is valid even if an inspector prefers another.

Practical Tips for Navigating Peer Reviews and DOL Inspections

While peer reviews and DOL inspections can seem intimidating, you can protect yourself and your firm by taking a few simple steps:

  1. Know the Standards: This can’t be emphasized enough. Knowing the codified standards allows you to differentiate between subjective opinion and objective requirements.
  2. Be Ready to Push Back: Not all findings are grounded in standards. Some reflect personal preferences or common practices that aren’t required. Always ask for clarification on where the requirement is codified before accepting a finding.
  3. Clear Documentation: Maintain thorough records is key. This doesn’t mean you need to over-audit, but you do need clear evidence of compliance with the required steps.
  4. Use the AICPA Audit Guide: This resource is essential for navigating gray areas like benefit payment testing.
  5. Seek Clarification on Ambiguities: Engage in a constructive dialogue with peer reviewers or inspectors to clarify what’s required versus what’s a matter of personal preference.

Closing Thoughts

Peer reviews and DOL inspections don’t have to be intimidating. A clear grasp of AU-C 703, the AICPA Audit Guide, and the latest regulatory updates help firms avoid over-auditing, defend their work, and separate real compliance issues from opinion.

With the right preparation and documentation, auditors can turn what feels like a minefield into a manageable process—standing firm when findings reflect preference rather than the standards.