
Small Business Guide to ERISA Compliance and Avoiding Costly Mistakes
27 March 2026

For many business owners, ERISA compliance becomes urgent only when a filing deadline approaches, an employee requests plan documents, or a problem surfaces during renewal. By then, the underlying issue may have existed for months.
Most benefits programs involve several parties, including an insurance carrier, payroll platform, third-party administrator, and outside advisers. The challenge is determining where each provider’s responsibility ends and the employer’s begins.
A carrier may issue coverage materials without preparing a complete ERISA plan document. A filing vendor may draft Form 5500 but still rely on the employer to verify the data and authorize submission. Payroll may process deductions correctly while eligibility records in the benefits system remain outdated. When responsibilities are divided across teams and vendors, gaps can remain hidden until coverage is disputed, a deadline is missed, or leadership requests records no one can quickly produce.
HR and finance leaders must address these issues while managing renewal, open enrollment, employee communications, cost pressures, and limited internal capacity. They need a clear view of which plans are covered, which documents are required, who owns each task, whether plan operations match written terms, and which responsibilities remain with the employer even when outside providers are involved.
What Is ERISA? Employee Retirement Income Security Act Explained
The Employee Retirement Income Security Act (ERISA) is a federal law that establishes minimum standards for most private-sector retirement and employee welfare benefit plans. While ERISA does not require employers to offer benefits, it does regulate how covered plans are documented, administered, and managed once they are established.
Depending on the plan, employers may need to maintain formal plan documents, provide required employee disclosures, follow claims procedures, file government reports, and meet fiduciary responsibilities. ERISA also requires those who make discretionary decisions about a plan or its assets to act prudently and in the best interests of plan participants and beneficiaries.
What Plans Are Covered Under ERISA?
ERISA applies to many employer-sponsored retirement and employee welfare benefit plans–not just 401(k)s. Covered plans commonly include retirement plans, medical, dental, vision, disability, life insurance, health reimbursement arrangements (HRAs), flexible spending accounts (FSAs), certain wellness programs, employee assistance programs (EAPs), and some severance plans.
Not every workplace benefit is automatically subject to ERISA. Coverage depends on factors such as the employer's involvement, whether contributions are employer-funded or voluntary, and whether the arrangement qualifies for a regulatory exemption or safe harbor. Generally, a benefit becomes an ERISA plan when it involves an ongoing administrative program requiring analysis of individual circumstances, rather than a single, isolated payment made without any ongoing employer involvement. Governmental plans, church plans, and programs maintained solely to comply with workers' compensation, unemployment, or disability laws are generally excluded.
Retirement vs. Health and Welfare Plans
ERISA governs both retirement plans and health and welfare plans, but the compliance requirements differ. Retirement plans focus on investment oversight, participant disclosures, and plan administration, while health and welfare plans involve requirements such as plan documents, Summary Plan Descriptions (SPDs), claims procedures, and other employee disclosures. Employers should identify the type of plan before applying compliance requirements.
Self-Funded Plans Explained
In a self-funded health plan, the employer pays employee claims rather than transferring all financial risk to an insurance carrier. Although third-party administrators often handle day-to-day claims processing, the employer typically retains responsibility for plan governance, documentation, fiduciary oversight, and vendor monitoring. Likewise, fully insured plans do not eliminate the employer's compliance obligations. Regardless of funding method, responsibilities should be clearly assigned and documented.
Who Is Covered Under ERISA Plans?
ERISA protects eligible "participants" and their beneficiaries, generally meaning common-law employees, not independent contractors, sole proprietors, or partners, who are typically excluded from an employer's ERISA plans. Misclassifying a worker's status can unintentionally extend (or improperly deny) ERISA protections, making correct classification a foundational compliance step. Employers should clearly define eligibility rules, including waiting periods, employee classifications, dependent coverage, and termination provisions, and administer them consistently. Inconsistent eligibility practices can lead to denied claims, employee disputes, and costly administrative corrections.
How ERISA Coverage Works for Employers
Which Employers Must Comply?
ERISA generally applies to private-sector employers that establish or maintain covered employee benefit plans, regardless of company size. Unlike laws that exempt small employers below a certain headcount, ERISA does not include a general small-business exemption. For example, a company with a handful of employees and a single group health plan is generally subject to the same core requirements as a much larger employer.
While some plans may qualify for filing exemptions or simplified reporting, those exemptions do not eliminate other compliance responsibilities. Employers should first determine whether a plan is subject to ERISA, then identify which requirements apply to that specific plan.
Plan Sponsorship and Fiduciary Responsibilities
The employer is typically the plan sponsor and may also serve as the plan administrator if no one else is designated. Individuals who exercise discretionary authority over plan management, administration, or service-provider oversight may be ERISA fiduciaries and are expected to act prudently and in the best interests of participants. Hiring outside vendors does not transfer those fiduciary responsibilities.
Who Owns What? ERISA Responsibility Matrix
Many compliance issues arise because employers assume a carrier, payroll provider, or third-party administrator is "handling ERISA." In reality, responsibilities are often shared. Every compliance task should have a clearly identified internal owner, a supporting vendor where applicable, a documented deadline, and evidence of completion.
Employers should build a responsibility matrix covering at least the following:
| Compliance Function | Internal Owner | External Support | Evidence to Retain |
|---|---|---|---|
| Plan document approval | Executive or benefit committee | Consultant / legal counsel | Signed plan document |
| SPD preparation | Plan administrator | Consultant / document provider | Current SPD and revision history |
| Employee distribution | HR | Benefits platform | Distribution records |
| Eligibility administration | HR & Payroll | Carrier or TPA | Eligibility reconciliations |
| Form 5500 filing | Plan administrator | Filing provider | Filed return and confirmation |
| Fiduciary oversight | Executive leadership or benefits committee | Consultant | Meeting minutes and reviews |
| Cybersecurity oversight | IT & fiduciaries | Security vendors | Due diligence documentation |
| Claims procedures | Plan administrator | Carrier or TPA | Claims and appeal records |
The agreement with each vendor should be reviewed against this matrix. Marketing language such as “full administration” or “compliance support” does not replace a written scope of work.
How Do Business Owners Stay Compliant With ERISA?
ERISA compliance is an ongoing process, not a once-a-year filing. Start by identifying every benefit plan that may be subject to ERISA, not just retirement and medical plans, and maintain an accurate inventory of governing documents and filing requirements. Build a calendar that tracks both annual deadlines and event-driven requirements, such as new hires, plan changes, or carrier transitions, and schedule regular reviews to catch gaps before they surface elsewhere.
ERISA Compliance Checklist for Employers
Use this checklist to confirm your benefit plans meet the core administrative and documentation requirements of ERISA. While specific obligations vary by plan type, these are the key areas every employer should review regularly.
- Determine which plans are covered by ERISA and document any applicable exemptions.
- Maintain current plan documents and ensure they reflect how the plan is actually administered.
- Provide a compliant Summary Plan Description (SPD) and keep records showing it was distributed.
- Review Form 5500 filing requirements and meet all applicable deadlines.
- Follow ERISA claims and appeals procedures for covered benefit plans.
- Reconcile employee contributions and investigate payroll or billing discrepancies promptly.
- Administer eligibility consistently according to the written terms of the plan.
- Monitor fiduciary responsibilities and service providers, including cybersecurity practices.
- Maintain organized compliance records so required documents are readily available during audits or participant requests.
Common ERISA Compliance Mistakes Employers Make
Many ERISA compliance issues result from routine administrative gaps rather than intentional misconduct. These are the mistakes employers encounter most often, and what tends to prevent them.
Failing to Stay Updated on Regulatory Changes
Benefit plans are affected by multiple federal requirements beyond ERISA. When regulations change, employers should verify that plan documents, employee communications, and vendor processes have all been updated, and not just one piece of the program.
Missing or Delayed Form 5500 Filings
Missed filings often occur because responsibility is unclear between the employer and the filing vendor. Maintain a compliance calendar, confirm who prepares and approves each filing, and retain proof of submission rather than relying solely on vendor reminders.
Lacking Proper or Updated Plan Documentation
Plan documents often go untouched after a carrier change, a design update, or a new eligibility rule, even though the underlying benefit kept running. The gap between what's written and what's actually happening is usually invisible until a claim or audit forces a side-by-side comparison.
Mishandling Employee Contributions
Payroll deductions, carrier invoices, and enrollment records can easily fall out of sync, particularly after a mid-year plan change or a payroll system transition. Discrepancies are far cheaper to fix at the reconciliation stage than after a participant dispute.
Overlooking Eligibility and Participation Requirements
Applying eligibility rules inconsistently or failing to update systems after employee status changes can result in denied claims, retroactive corrections, and employee disputes. Periodic audits help confirm that plan operations match written eligibility provisions.
Weak Fiduciary Oversight and Governance
A vendor being responsible for day-to-day administration doesn't mean the employer is out of the decision-making loop. What matters in an audit or dispute is whether the employer can show how and why a benefits decision was made–not just what vendor was hired to help.
Risks of ERISA Non-Compliance
The impact of ERISA noncompliance extends beyond regulatory penalties. Missing filings, outdated plan documents, inconsistent administration, or weak fiduciary oversight can lead to corrective costs, employee claims, government enforcement, and operational disruptions. Employers may also face additional expenses from professional services, system corrections, and resolving coverage disputes. Because employees typically hold their employer accountable when benefits issues arise, compliance failures can also erode trust and complicate future plan changes. Maintaining consistent documentation, governance, and administrative processes helps reduce these risks while supporting a more reliable and effective benefits program.
Building a Stronger Compliance Strategy
As organizations grow, ERISA compliance becomes more complex. New benefit offerings, additional vendors, changing workforce needs, and evolving regulations all increase the importance of having consistent processes in place.
As organizations grow, ERISA responsibilities rarely stay with one person. HR manages eligibility, payroll handles deductions, carriers administer claims, and outside vendors prepare filings. The strongest compliance programs make those handoffs explicit so responsibilities don't disappear between teams.
And, ultimately, ERISA compliance is about creating a benefits program that operates as intended. When plan documents, administrative practices, and vendor responsibilities remain aligned, employers are better positioned to reduce compliance risk, support employees effectively, and adapt confidently as their organization grows.

