What questions should fiduciaries ask vendors about cybersecurity?

Last updated October 2, 2026

Following DOL guidance, fiduciaries should ask vendors for their security program and standards, third-party audit results (like SOC 2 reports), breach history and response, data encryption practices, and contractual commitments to notification and liability — then revisit the answers annually.

Retirement plan data and money move through recordkeepers daily, and the DOL's cybersecurity guidance makes vendor security a fiduciary agenda item. A practical annual questionnaire covers:

  • The vendor's information security program and the standards it follows
  • Independent validation — SOC 2 or equivalent audit reports, penetration testing
  • Breach history, response performance, and participant-notification practices
  • Encryption of data in transit and at rest; access controls; employee training
  • Contract terms: security warranties, breach notification timelines, liability, and insurance
  • Participant-facing protections — account monitoring, MFA, fraud guarantees

File the responses with committee records and note the review in minutes. The DOL's own investigators use question lists much like this one — answering them proactively is the easiest audit preparation available.

Thanks for your feedback!

Put these answers to work

Fiduciary In A Box walks your team through every one of these requirements step by step — documenting decisions, organizing files, and keeping your plan compliant year-round.

See how FIAB works