Skip to main content
Edit Page Style Guide Control Panel
Topographical Lines.
AdobeStock_361942749

Can Plan Sponsors Be Held Personally Responsible for 401(k) Plan Mistakes?

Key Takeaways

Personal fiduciary liability under ERISA is real, and maintaining a prudent, documented oversight process is widely regarded as one of the most important factors in managing that exposure over time.

  • Under ERISA, individuals who serve as plan fiduciaries can be held personally responsible for breaches, and fiduciary status follows function, not title
  • Most exposure develops gradually through unclear responsibilities, inconsistent monitoring, or decisions that aren't documented, rather than from a single dramatic mistake
  • Hiring vendors and advisors can shift certain duties, but the committee generally retains the ongoing responsibility to prudently select and monitor them
  • Regular monitoring, clearly defined roles, and documented committee decisions are commonly cited among the most effective ways to manage both regulatory and personal risk

It’s an uncomfortable question. It’s also a reasonable one.

If you serve on a retirement plan committee, you likely didn’t join because you wanted personal fiduciary exposure. Oversight is simply part of your role, whether you work in HR, finance, operations, or leadership.

And most “plan mistakes” aren’t dramatic.

They tend to be small operational breakdowns, unclear responsibilities, or oversight processes that drift over time.

So let’s take the question directly. Under ERISA, individuals who serve as retirement plan fiduciaries can, in certain circumstances, be held personally liable for losses resulting from a breach of fiduciary duty .

That does not mean every operational error becomes personal liability. But the risk is real, particularly when oversight responsibilities are unclear or important decisions aren’t documented.

Committees that take the time to define roles early tend to manage risk more effectively, because responsibilities are organized and nothing quietly falls through the cracks. It also gives everyone a shared understanding of where authority sits and how oversight is actually carried out. 

The tool below is a practical place to begin.

Why Does This Question Matter for Plan Committees?

If you participate in plan oversight, it’s natural to assume that vendors and advisors are handling most of the operational details. In many cases, they are.

But fiduciary responsibility under ERISA focuses on something different: whether you and your committee are maintaining a prudent process for overseeing the plan.

That’s why many fiduciary issues don’t arise from major failures. Instead, they tend to develop gradually, when monitoring becomes informal, documentation becomes inconsistent, or responsibilities across the plan aren’t clearly defined.

This is what makes the question worth taking seriously. 

Committees rarely notice these gaps in the moment, because each individual task still appears to be getting done. 

The exposure builds quietly, in the space between what people assume someone else is handling and what is actually being reviewed. Understanding where that responsibility sits is the first step toward managing it.

What Does ERISA Actually Require from Plan Fiduciaries?

ERISA sets clear expectations for individuals who oversee retirement plans. 

Under ERISA §3(21), a person is generally treated as a fiduciary to the extent they exercise discretionary authority or control over plan management or plan assets, render investment advice to the plan for a fee, or have discretionary authority or responsibility over plan administration. 

Fiduciary status follows function, not title.

ERISA §404(a) sets out the core duties that apply to plan fiduciaries, often summarized as follows:

  • Acting solely in the interest of plan participants and beneficiaries, and for the exclusive purpose of providing benefits and defraying reasonable plan expenses.
  • Acting with the care, skill, prudence, and diligence that a prudent person familiar with such matters would use under the circumstances.
  • Diversifying plan investments to minimize the risk of large losses, unless clearly imprudent to do so under the circumstances.
  • Following the terms of the plan documents, to the extent those terms are consistent with ERISA.

In practice, this means your committee is responsible for ensuring that the plan is being monitored appropriately, even when much of the day-to-day work is performed by service providers.

Clarifying who owns each oversight decision, as opposed to the operational tasks handled by vendors or internal teams, is what keeps that responsibility from drifting over time.

Where Do Most Retirement Plan Mistakes Actually Occur?

Most fiduciary exposure does not come from dramatic failures. It usually develops through smaller operational issues that accumulate when oversight becomes informal.

Many plan correction cases involve situations such as:

  • Contributions not being deposited within required timeframes
  • Service provider responsibilities becoming unclear over time
  • Investment monitoring happening inconsistently
  • Committee decisions not being documented in meeting minutes
  • Plan fees or vendor performance not being reviewed regularly

One area regulators review particularly closely is contribution timing. Even relatively small delays can create compliance concerns if they occur repeatedly. 

For that reason, it’s important to understand what happens when employee contributions are deposited late and how those situations are typically corrected.

These problems generally don’t happen because committees are careless. They occur because retirement plans involve many moving parts (payroll teams, recordkeepers, advisors, and internal staff), and responsibility for monitoring those processes is not always clearly defined.

Why this matters:

When responsibility isn’t clearly owned, small operational issues are often the ones that accumulate into meaningful fiduciary exposure.

When Does Personal Fiduciary Liability Become a Real Risk?

Under ERISA §409, a fiduciary who breaches a fiduciary duty can be held personally liable for losses to the plan resulting from the breach, and may be subject to other equitable or remedial relief.

In practice, personal liability concerns tend to arise when oversight responsibilities are ignored or when known issues continue without correction.

For example, risk may increase if a committee:

  • Fails to monitor service providers
  • Overlooks operational problems that come to its attention
  • Does not document how decisions were made or why
  • Allows known issues to continue without investigation

By contrast, committees that maintain a consistent governance structure tend to reduce their exposure. 

When meetings occur regularly, plan operations are reviewed, and decisions are documented, the committee creates a clear record supporting that fiduciary duties are being carried out through a prudent process.

Key principle:

ERISA focuses heavily on process. Courts and regulators often look at whether decisions were made through a prudent, documented process, not just at the ultimate outcome.

How Should Committees Think About Oversight Structure?

Many committees assume the safest strategy is simply avoiding mistakes altogether. 

In practice, retirement plans involve payroll processes, multiple vendors, and evolving regulatory expectations. Even well-run plans can experience occasional operational issues.

What matters most is whether your committee has a structure capable of:

  • Identifying problems when they occur
  • Addressing them promptly
  • Documenting how the issue was reviewed and resolved

Committees that maintain a clear governance framework tend to manage risk more effectively because responsibilities are organized and monitoring occurs consistently.

Risk this helps reduce:

Discovering, after the fact, that an issue was known but no one was clearly accountable for acting on it.

Putting It Into Practice

Personal fiduciary liability under ERISA is real. But it most often arises from oversight gaps rather than isolated operational mistakes.

If your committee clarifies responsibilities, maintains consistent monitoring practices, and documents its decisions, you meaningfully reduce both regulatory and personal risk exposure.

Many committees meet regularly yet still discover that responsibilities across the plan are not always clearly defined.

If You Want a Clearer View of Your Plan

If it would be helpful to step back and walk through how fiduciary responsibilities are currently structured, including where authority sits, how oversight is carried out, and how decisions are documented, you can schedule a brief high-level review below. 

Typically a short, structured discussion focused on fiduciary roles and plan governance.

Prefer to Evaluate This Internally?

Our Fiduciary Roles & Responsibility Mapping Worksheet can help your committee clarify who is responsible for key fiduciary functions across the plan.

Plan Sponsor FAQs

Not necessarily. Under ERISA §3(21), fiduciary status is based on the functions performed and the authority exercised. Individuals or committees that exercise discretionary authority or control over plan management or plan assets, render investment advice to the plan for a fee, or have discretionary authority over plan administration are generally treated as fiduciaries, regardless of title.

Yes. Under ERISA §409 and §502, fiduciaries can be held personally liable for breaches of fiduciary duty, and civil actions may be brought by participants, beneficiaries, other fiduciaries, or the Department of Labor. Whether any specific action rises to a breach depends on the facts and circumstances.

Hiring vendors can shift certain fiduciary functions, for example, appointing an ERISA §3(38) investment manager, but sponsors and named fiduciaries retain the ongoing duty to prudently select and monitor service providers. Responsibility for oversight typically remains even when execution is delegated.

Maintaining a consistent governance process (including regular monitoring, clearly defined responsibilities, and documented committee decisions) is commonly cited as one of the most effective practices for managing fiduciary risk. No process eliminates liability, but a prudent, documented process is often central to demonstrating that duties were carried out appropriately.

Important Disclosure

Educational purpose only. Provided by First Hill Trust Company for general informational and educational purposes only. It is not legal, tax, accounting, investment, or fiduciary advice, does not constitute a recommendation regarding any plan, investment, strategy, or course of action, and does not consider any recipient’s specific circumstances. Consult your own qualified advisors before acting.
No offer, agreement, or commitment
. Nothing in this material constitutes an offer, solicitation, agreement, or commitment to provide any particular service or to assume any particular responsibility. Descriptions of what a trustee, administrator, adviser, committee, employer, or other party “may” or “can” do are illustrative of how such arrangements commonly work and do not describe the terms of any specific engagement. The actual services provided, the allocation of responsibilities, the scope of any delegation, and the duties of any party are governed solely by the applicable plan documents, trust agreement, advisory agreement, and written service agreements. In the event of any inconsistency, those documents control.
Services and regulatory status
. First Hill Trust Company and its affiliates offer retirement plan services, recordkeeping and administrative services, trust and fiduciary services, investment advisory services, and group benefits services, in each case subject to applicable regulatory requirements and the terms of the relevant agreements. Not all services are offered to all clients, in all states, or in all circumstances. Investment advisory services are offered through an affiliated investment adviser; a copy of its Form ADV Part 2A is available upon request. Insurance and group benefits products are offered through appropriately licensed entities. The availability and scope of any service depend on eligibility and the applicable agreements.
Fiduciary status under ERISA.
Fiduciary status under the Employee Retirement Income Security Act of 1974, as amended (“ERISA”), is determined based on the functions performed and the authority exercised, not on titles or labels. Whether any particular party is acting as a fiduciary, and the scope of any related duties or potential liability, depends on the facts and circumstances specific to the plan and the relationship. Engaging a trustee, adviser, or other service provider does not eliminate a plan sponsor’s or committee’s own fiduciary responsibilities, including the duties to prudently select and monitor any party to whom responsibilities are delegated.
Affiliated entities and conflicts of interest.
First Hill Trust Company is affiliated with other entities, including an affiliated investment adviser and entities providing administrative, trust, or other services. These relationships may create conflicts of interest, including where an affiliate is engaged or compensated in connection with a plan. Such conflicts and compensation are described in the applicable service agreements and the affiliated adviser’s Form ADV Part 2A; fiduciaries should consider them when evaluating any engagement.
Statutory and regulatory references
. References to ERISA, the Internal Revenue Code, and related statutory or regulatory provisions are general summaries only. They are not a substitute for review of the actual statutory text, regulations, or guidance from the Department of Labor, Internal Revenue Service, or other relevant authorities, and they do not address how those provisions may apply to any particular plan, sponsor, fiduciary, or individual. Laws, regulations, and guidance are subject to change and to interpretation by the relevant agencies and courts. Examples, categories, and situations described are simplified for illustration and may not reflect the requirements or circumstances of any particular plan or person.
No guarantee of results; investment risk.
References to governance, fiduciary practices, risk reduction, or outcomes describe common industry approaches and potential benefits, not promises or guarantees of any result, of compliance, or of protection from liability, loss, or claims. All investing involves risk, including possible loss of principal; diversification does not ensure a profit or protect against loss. Past performance does not guarantee future results.
For more information, contact First Hill Trust Company at (206) 625-1800 or visit firsthilltrust.com.

Related Articles

Trees amongst fog.