Fiduciary Intelligence
August 5, 2026

Top DOL Audit Triggers Every Self-Funded Employer Should Know

Abhishek Ghosh

TABLE OF CONTENTS

The Department of Labor (DOL) often starts investigating a self-funded health plan when employees complain about their benefits, required compliance documents are missing, fee disclosures are incomplete, or the employer cannot prove it is monitoring its third-party administrator (TPA). In FY 2025, the DOL completed 878 civil investigations and recovered $714.4 million. If several employees raise similar complaints about the same plan, it may prompt the DOL to take a closer look.

A mid-size employer gets a letter from the Department of Labor. Not a lawsuit. A request for documents. The plan sponsor has never seen the claims data behind their own health plan, has no comparative analysis on file, and has no record of ever asking the TPA a hard question.

That letter is not random. EBSA closed 878 civil investigations in FY 2025 and recovered $714.4 million in the process, and most of those cases started with a pattern someone could have caught first.

Key Takeaways

1
DOL enforcement is active. In FY 2025, EBSA recovered $1.4 billion across all enforcement programs, including $714.4 million from 556 of 878 closed civil investigations.
2
Employee complaints can trigger investigations. Repeated complaints about the same health plan or service provider are a common reason the Department of Labor opens an investigation.
3
Mental health parity remains under scrutiny. Federal reviews continue to identify MHPAEA compliance gaps, with nearly all plans cited for violations being self-funded.
4
Limited claims reviews increase risk. Many self-funded employers review only a small percentage of paid claims, allowing payment errors and compliance issues to remain undetected.
5
Documented oversight is your strongest defense. Maintaining a recurring, documented claims oversight process demonstrates prudent fiduciary governance under ERISA Section 404 and helps prepare your plan for regulatory scrutiny.

What "DOL Audit Triggers" Actually Means

A DOL audit trigger is any pattern, complaint, or documentation gap that gives EBSA a reason to open a formal investigation into a self-funded health plan. Most plan sponsors assume audits are random, similar to a tax audit lottery. That assumption is wrong.

EBSA investigations are largely pattern-driven. Complaint volume, missing required disclosures, and known compliance gaps like NQTL comparative analyses generate referrals long before any letter arrives.

The gap between assumption and reality matters because plan sponsors who believe audits are random tend to under-invest in the documentation that would protect them. Prudent process, not luck, is what EBSA looks for once an investigation opens.

Why This Problem Exists

Self-funded plans hand claims processing, network access, and much of the compliance workload to a TPA. That arrangement creates a documentation and accountability gap that most sponsors never notice until it's tested.

ERISA places fiduciary responsibility for the plan on the sponsor, not the TPA. Selecting a service provider is itself a fiduciary act, and DOL guidance is explicit that hiring a TPA does not end the sponsor's duty to monitor performance and fees on an ongoing basis.

Most HR and finance teams were never trained to monitor a TPA the way they'd monitor a retirement plan recordkeeper. The retirement side of ERISA has decades of litigation and case law teaching sponsors to document process. The health side is catching up fast, and sponsors who haven't adjusted are exposed.

The Real Cost and Impact

EBSA's FY 2025 numbers show the scale of federal enforcement. The agency closed 878 civil investigations, and 556 of those, or 63 percent, produced monetary results or required corrective action, totaling $714.4 million in recoveries from enforcement alone.

Complaint-driven referrals are a meaningful share of that activity. EBSA opened 291 investigations from Benefits Advisor referrals in FY 2025, cases that typically start with repeated complaints about the same plan, employer, or service provider rather than a scheduled review.

DOL audits aren't the only concern. Many claim payment errors can remain hidden because most TPAs use sampling to review claims rather than examining every paid claim. Independent audits that review 100% of claims often identify overpayments that sampling-based reviews did not detect.

What's Actually Happening Behind the Scenes

MHPAEA Comparative Analysis Gaps

Mental health parity compliance is one of the clearest current audit triggers. A joint DOL and CMS review examined 56 plans for MHPAEA compliance and found 33 violations, and nearly every noncompliant plan was self-funded or included a self-funded option.

For plan years beginning on or after January 1, 2025, a named ERISA fiduciary must certify that the plan followed a prudent process to select and monitor whoever performs the NQTL comparative analysis. A comparative analysis that was written once and filed away does not meet that bar.

Participants can request a copy of the comparative analysis at any time under ERISA Section 104, which starts a 30-day disclosure clock. A plan that cannot produce a current, complete analysis on short notice has already created its own audit trigger.

Missing CAA 2021 Disclosures

The Consolidated Appropriations Act, 2021 requires brokers and consultants earning more than $1,000 annually in direct or indirect compensation to disclose those fees to the plan sponsor. Sponsors are responsible for confirming those disclosures exist and reviewing them, not just receiving them.

Gag clause attestations, another CAA 2021 requirement, must be submitted annually confirming the plan hasn't agreed to contract terms that restrict access to cost and quality data. A missed attestation is a simple, easily documented compliance failure, which makes it an easy first data point for an investigator.

Why Current Compliance Approaches Aren't Enough

Area Status Quo Recommended Approach
Claims Review TPA self-reports its own claims accuracy. Independent, plan-specific claims audit reviewing a full or high-percentage sample.
MHPAEA Compliance Comparative analysis is prepared once and rarely revisited. Named fiduciary performs and certifies an annual review of the NQTL comparative analysis.
Fee Transparency Broker compensation is disclosed only during renewal. CAA 2021 compensation disclosures are tracked, reviewed and archived every year.
Documentation Verbal approvals and scattered email records. Dated, written documentation supporting every fiduciary decision.
Vendor Monitoring TPA performance is largely left unmonitored between renewals. Continuous performance benchmarking against contractual obligations and service guarantees.

How to Fix It

1
Schedule Independent Claims Audits
Commission an independent claims audit on a recurring basis using a firm with no financial relationship to your TPA. Do not rely solely on the TPA's self-reported accuracy statistics when evaluating plan performance.
2
Assign an MHPAEA Fiduciary
Designate a named fiduciary to oversee the MHPAEA Non-Quantitative Treatment Limitation (NQTL) comparative analysis and formally document its annual review and approval.
3
Maintain CAA 2021 Disclosure Records
Track, review and archive all CAA 2021 broker and consultant compensation disclosures for every service provider supporting your health plan.
4
Create a Fiduciary Governance Calendar
Establish a written governance calendar covering quarterly claims reviews, annual TPA performance evaluations and yearly MHPAEA comparative analysis reviews to ensure oversight occurs on schedule.
5
Document Participant Complaints
Respond to every participant complaint in writing and maintain a log of the issue, investigation and resolution. Repeated complaints can become evidence during regulatory reviews.
6
Benchmark Your TPA Agreement
Review your TPA contract against current industry standards to evaluate audit rights, performance guarantees, reporting requirements and fiduciary protections before your next renewal.
Effective fiduciary oversight requires more than annual compliance. A structured governance calendar, independent claims verification, documented decision-making and regular vendor reviews help demonstrate the prudent process expected under ERISA while strengthening overall plan performance.

Red Flags That Signal Your Plan Is Exposed

Your health plan has never undergone an independent claims audit.
Your MHPAEA comparative analysis was completed once but has never been reviewed or updated.
CAA 2021 broker and consultant compensation disclosures are missing, incomplete or not retained for review.
Fiduciary committee meeting minutes either do not exist or never document discussions about claims oversight, vendor performance or payment accuracy.
Multiple employees have reported the same type of denied claim, suggesting a recurring operational or plan administration issue.
Your TPA has never been asked to provide a sample of paid claims for independent review or validation.
Reality Check: If three or more of these statements describe your plan, your fiduciary oversight process may have significant gaps. Independent claims audits, updated compliance reviews and documented governance help reduce financial leakage while strengthening ERISA compliance and regulatory readiness.

The ROI of Doing It Right

Independent oversight isn't just a compliance cost. Claims-auditing benchmarks across the industry typically show recoverable overpayments in the low single digits as a percentage of annual claims spend, and for many self-funded plans that translates into six or seven figures a year in identified errors alone.

Beyond dollars recovered, a documented oversight process is the single strongest piece of evidence a fiduciary can produce during an EBSA inquiry. Prudent process, not a clean outcome, is what ERISA actually requires.

The plans least likely to face a lengthy, costly investigation are the ones that can hand over a complete file the day a request arrives.

Conclusion and Next Steps

DOL audit triggers aren't a mystery, and they aren't random. They come from documentable gaps: complaints that pile up, a comparative analysis that's gone stale, fee disclosures nobody tracked, and a TPA relationship nobody independently checked. Self-funded employers who close those gaps before a letter arrives put themselves in a fundamentally different position than plans that wait.

Start with an honest inventory. If your plan can't produce a current comparative analysis, a full CAA 2021 disclosure file, and a recent independent claims audit today, that's the starting point for next quarter's fiduciary calendar.

Frequently Asked Questions

What triggers a DOL audit of a self-funded health plan?

Common triggers include repeated participant complaints, incomplete MHPAEA comparative analyses, missing CAA 2021 fee disclosures, and no documented TPA oversight process.

How many investigations did EBSA close in FY 2025?

EBSA closed 878 civil investigations in FY 2025, with 556 producing monetary results or corrective action.

How much did EBSA recover in FY 2025?

EBSA recovered $1.4 billion across all enforcement programs, including $714.4 million from civil investigations alone.

Is the plan sponsor or the TPA responsible for ERISA compliance?

The plan sponsor holds fiduciary responsibility under ERISA, even though the TPA handles day-to-day claims administration.

Does hiring a TPA satisfy fiduciary duty?

No. Selecting a TPA is itself a fiduciary act, and sponsors must also monitor performance and fees on an ongoing basis.

How often should a self-funded plan complete a claims audit?

Most compliance advisors recommend a recurring, independent audit rather than a one-time review, since TPA self-reported metrics rarely catch every error.

What is an MHPAEA comparative analysis?

It's a required written analysis comparing how a plan applies nonquantitative treatment limitations to mental health versus medical and surgical benefits.

Can participants request a copy of the comparative analysis?

Yes. Participants can request it at any time under ERISA Section 104, which starts a 30-day disclosure deadline.