Fiduciary Intelligence
August 17, 2026

How to Document Fiduciary Prudence and Protect Your Plan

Abhishek Ghosh

TABLE OF CONTENTS

A fiduciary paper trail is simply a record of how a benefits committee makes and reviews decisions about a self-funded health plan. It can include meeting notes, vendor reviews, and claims audit results. Under ERISA, this documentation helps show that the committee took a careful, reasonable approach to its decisions, even if one of those decisions later turned out to be wrong.

In fiscal year 2025, the Department of Labor’s Employee Benefits Security Administration recovered more than $1.4 billion for retirement, health and welfare plans. More than half came from enforcement actions, not voluntary corrections. Plaintiff firms filed 155 ERISA fiduciary class actions in 2025, including 39 involving health plans.

That is a major shift from the retirement-plan lawsuits that dominated a decade ago. Most benefits committees can explain what their plan did. Far fewer can show why they made those decisions, and that gap is often where investigators and plaintiffs’ attorneys start.

Key Takeaways
Process matters: ERISA judges fiduciaries on the process they follow, not just the outcome. A documented, repeatable review process is the primary legal defense against a breach claim.
Enforcement has real consequences: EBSA closed 878 civil investigations in FY 2025, with 63% resulting in monetary or corrective action against the plan.
Health plan litigation is increasing: ERISA litigation involving health plans is following the fee-scrutiny pattern that produced more than 600 excessive-fee lawsuits against 401(k) plans over the past decade.
Independent review finds hidden errors: Independent claims audits routinely identify 1% to 10% of claims dollars paid in error, compared with the 96% to 98% accuracy typically self-reported by TPAs.
Documentation can pay for itself: A defensible fiduciary paper trail costs a fraction of a single litigation defense and can also generate value through claims recoveries.
Bottom line: The strongest protection is not simply having good claims results. It is being able to prove that your plan followed a consistent, documented and prudent oversight process.

What a Fiduciary Paper Trail Actually Is

A fiduciary paper trail is the documented evidence that a benefits committee followed a prudent, repeatable process when making decisions about the plan. Most plan sponsors assume that if the plan works reasonably well and the TPA has a good reputation, the fiduciary duty is satisfied. That assumption is wrong under ERISA Section 404, which requires fiduciaries to act with the care, skill and diligence of a prudent expert, not merely to reach an acceptable result.

Courts and the DOL do not ask whether a claim got paid correctly in hindsight. They ask whether the committee had a process for finding out, and whether that process left a record. A plan that overpaid on a handful of claims but can show quarterly TPA reviews, documented vendor comparisons and audit engagement letters is in a fundamentally different legal position than a plan with the same errors and no record at all.

The key difference is between substantive and procedural prudence. Substantive prudence asks whether the decision was reasonable. Procedural prudence asks whether the committee used a careful, reasonable process to make it. Under ERISA, that process matters, which is why documentation, not perfection, is a committee’s strongest fiduciary protection.

Why Most Plans Have a Documentation Gap

The gap exists because benefits committees are staffed by HR and finance professionals whose core job is running the business, not building a compliance record. Claims administration gets outsourced to a TPA, and plan sponsors quietly extend that outsourcing to include oversight itself, even though ERISA does not allow fiduciary responsibility to be delegated away.

TPAs can make things look better than they really are by reporting their own performance numbers. They often report payment and financial accuracy rates above 96%, which may meet their contract requirements. But independent audits of the same claims can find very different results.

The problem is that a benefits committee cannot rely only on a TPA’s own scorecard to prove it provided proper oversight. Reviewing the vendor’s numbers shows that the committee checked the report. It does not necessarily show that the committee independently tested whether those numbers were accurate.

Turnover makes this problem worse. Committee members leave, brokers change, and people forget why certain plan decisions were made years ago. Without clear meeting notes and supporting documents, a plan sponsor facing a DOL investigation or lawsuit may have to piece together what happened from memory instead of showing a clear record.

The Real Cost of an Undocumented Process

When a fiduciary process is not documented, a simple vendor mistake can become a much bigger legal problem. Under ERISA, fiduciaries who fail to meet their duties may have to repay losses suffered by the plan. This liability can apply to the individual committee members involved, not just the employer.

The scale of enforcement shows why this matters. In FY 2025, EBSA’s civil investigations recovered $714.4 million. The agency also closed 253 criminal investigations, leading to 62 indictments and 45 convictions involving the way plan assets were handled and controlled.

Health plan lawsuits are now following a similar path to the 600+ excessive-fee lawsuits filed against 401(k) plans over the past decade. Plaintiff firms are increasingly using the same arguments about excessive fees and poor oversight against health and welfare plans, especially as the Consolidated Appropriations Act, 2021 increased disclosure requirements.

What's Actually Happening Behind the Scenes

Committees That Meet Without Minutes

Many benefits committees hold regular meetings but treat them as informal check-ins rather than fiduciary proceedings. Decisions about plan design, stop-loss renewal or TPA retention get discussed and agreed upon verbally, with no minutes capturing what alternatives were considered or why the chosen option was selected.

Vendor Oversight That Stops at the Contract

Signing a services agreement with a TPA is treated as the end of the oversight process instead of the beginning. ERISA places fiduciary responsibility for claims accuracy on the plan sponsor regardless of delegation, yet many committees have no calendar for reviewing TPA performance against that contract after signature.

Audit Activity That Is Self-Reported, Not Independent

A claims audit conducted by the TPA on its own claims is not independent evidence of prudent oversight. Objectivity is inherently limited when the party being reviewed also produces the review, and reviews conducted this way are typically performed only once every three years, if at all.

Dependent Eligibility and Data Hygiene Left Unchecked

Ineligible dependents remaining on a plan after a divorce, a dependent aging out or a change in employment status is one of the most common and most avoidable sources of claims leakage, yet dependent eligibility is rarely treated as its own documented review workstream separate from broader claims auditing.

Why Current Approaches Aren't Enough

Status Quo Practice Fiduciary-Grade Approach
Annual or informal committee check-ins Scheduled quarterly meetings with a standing agenda and retained written minutes
TPA self-reported accuracy accepted at face value Independent, contingency-fee claims audit performed by a firm with no TPA ownership ties
Vendor contract filed away after signature Documented quarterly TPA performance review against SLA benchmarks
Claims reviewed only after a complaint or renewal Continuous or quarterly sampling across 100% of claim categories
Dependent eligibility assumed accurate Dedicated annual dependent eligibility audit with documented findings
Fiduciary training treated as optional Documented annual fiduciary training for every committee member, recorded in minutes

How to Fix It

1
Adopt a Written Committee Charter
Define who serves as a fiduciary, what decisions require committee approval and how often the committee meets. A charter turns informal habit into a documented governance structure.
2
Put Meeting Minutes on a Fixed Template
Record attendance, agenda items, alternatives discussed, the rationale for each decision and any dissenting views. Store minutes in a retained, searchable archive rather than a shared inbox.
3
Schedule TPA Oversight on a Calendar
Conduct quarterly reviews against SLA benchmarks and maintain a written summary of findings. A scheduled process demonstrates active oversight rather than passive trust.
4
Engage an Independent Claims Auditor
Choose a firm with healthcare claims expertise and no ownership ties to the TPA. Confirm your ASO agreement allows any qualified firm to audit any claim at any time.
5
Treat Dependent Eligibility as Its Own Audit Line
Review dependent eligibility as a separate audit workstream. These reviews are typically inexpensive relative to the savings they can identify and often pay for themselves within months.
6
Document Fiduciary Training Annually
Conduct an annual session covering ERISA Section 404 duties and retain an attendance sheet. This creates evidence that committee members understood their fiduciary obligations.
7
Set a Record Retention Schedule
Establish and follow a defined retention schedule for committee minutes, audit reports, vendor contracts and correspondence that exceeds the applicable statute of limitations for fiduciary breach claims.
8
Close the Loop on Every Finding
Document the corrective action for every finding and track it through completion. Record the remediation steps and the date each issue was closed.

Think of fiduciary documentation like a flight data recorder. Nobody expects a plan year to run without any turbulence, and regulators do not expect one either. What they want to know after something goes wrong is whether the committee followed procedure the whole way through.

The paper trail does not prove the plan never made a mistake. It proves the committee was flying the plane on purpose.

Red Flags That Signal Your Plan Is Exposed

Committee meetings happen, but no one takes or retains formal minutes.
The plan has never had an independent claims audit performed by a firm unaffiliated with the TPA.
TPA performance is measured only through the vendor's self-reported scorecard.
No one on the committee can produce documentation explaining why the current TPA or stop-loss carrier was selected.
Dependent eligibility has not been independently audited in more than two years.
The ASO agreement restricts who can audit claims or how often an audit can be performed.
New committee members receive no fiduciary training or formal orientation.
Audit findings exist in email threads but were never formally logged, assigned for remediation or closed out.

The ROI of Doing It Right

A defensible fiduciary process pays for itself twice, once in claims recoveries and once in avoided liability. A comprehensive independent claims audit typically recovers between 1% and 3% of annual claims spend in its first year, an amount that regularly exceeds the full cost of the audit engagement itself. On a $15 million claims book, that range translates to $150,000 to $450,000 in first-year recoveries alone.

The liability side of the equation is harder to quantify but larger in scale. EBSA's FY 2025 enforcement activity alone moved $1.4 billion, and individual ERISA breach settlements in the 401(k) space have run into the tens of millions of dollars per case over the past decade. A documented process is inexpensive insurance against exposure of that magnitude, and unlike claims recoveries, its value is realized only when it is needed most.

Good documentation can also make a DOL investigation faster and less expensive. If a plan has its records organized and ready, investigators can quickly see what happened and why. Without those records, the plan may have to spend extra time searching for documents and piecing together what happened, which can lead to more questions and requests.

Conclusion and Next Steps

Fiduciary prudence is not measured by whether a self-funded plan avoided every error. It is measured by whether the committee overseeing that plan can produce a record showing it looked, asked the right questions and acted on what it found. That record, built consistently over time, is what separates an ordinary vendor mistake from a documented fiduciary breach.

Start with what is fastest to fix. Put a committee charter and minutes template in place this quarter [internal link: benefits committee charter template], schedule your next TPA performance review [internal link: TPA performance guarantees guide], and confirm your ASO agreement actually allows independent claims auditing [internal link: independent claims oversight guide]. If it has been more than a year since your plan's last independent claims audit, that is the single highest-leverage next step available.

Frequently Asked Questions

What does ERISA Section 404 actually require of a plan fiduciary?

It requires fiduciaries to act with the care, skill and diligence of a prudent expert, solely in the interest of participants.

Is a self-funded plan sponsor personally liable for TPA errors?

Yes. Fiduciary responsibility for claims accuracy stays with the plan sponsor even when claims processing is delegated to a TPA.

How often should a benefits committee meet to stay fiduciary-compliant?

Quarterly meetings with retained minutes are the common baseline used by fiduciary-grade committees.

Can a TPA's self-reported audit satisfy fiduciary oversight requirements?

No. Independent review is needed because a TPA auditing its own claims lacks the objectivity courts and regulators expect.

How long should fiduciary committee records be retained?

Retain minutes, audit reports and vendor contracts beyond ERISA's statute of limitations for breach claims, typically six years or longer.

What triggers a DOL investigation of a self-funded health plan?

Common triggers include participant complaints, Form 5500 irregularities, and EBSA's targeted enforcement priorities for a given year.

Does a documented process protect against every fiduciary breach claim?

No single record eliminates risk, but a consistent, documented process is the strongest evidence of prudence available in litigation or investigation.

What is the difference between substantive and procedural prudence?

Substantive prudence judges the decision itself; procedural prudence judges the process used to reach it, and ERISA case law favors the latter.