What questions should fiduciaries ask vendors about cybersecurity?
Last updated October 2, 2026
Following DOL guidance, fiduciaries should ask vendors for their security program and standards, third-party audit results (like SOC 2 reports), breach history and response, data encryption practices, and contractual commitments to notification and liability — then revisit the answers annually.
Retirement plan data and money move through recordkeepers daily, and the DOL's cybersecurity guidance makes vendor security a fiduciary agenda item. A practical annual questionnaire covers:
- The vendor's information security program and the standards it follows
- Independent validation — SOC 2 or equivalent audit reports, penetration testing
- Breach history, response performance, and participant-notification practices
- Encryption of data in transit and at rest; access controls; employee training
- Contract terms: security warranties, breach notification timelines, liability, and insurance
- Participant-facing protections — account monitoring, MFA, fraud guarantees
File the responses with committee records and note the review in minutes. The DOL's own investigators use question lists much like this one — answering them proactively is the easiest audit preparation available.
Thanks for your feedback!