Direct Answer: A Provider Can Perform Work, But the Sponsor Must Still Govern
Use this page to separate who does the work from who owns the legal decision. DOL materials say fiduciary status turns on functions, not titles; fiduciaries must act prudently, follow plan documents, pay reasonable expenses, select and monitor service providers, provide participant information and file required reports. The Form 5500 instructions also preserve plan administrator and employer signature responsibility even when a preparer helps. A provider can be wrong, negligent, contractually liable or a functional fiduciary in a specific lane. That does not make the sponsor a passive bystander.[S1][S2][S3][S8][S9][S10]
For ROBS, the allocation is especially important because IRS guidance focuses on rollover records, participant information, stock valuation, stock purchases, Form 5500, Form 1120, Form 1099-R, discrimination, prohibited transactions and promoter fees. The sponsor authorizes corporation and plan actions, supplies employee coverage and business facts, and approves the operation. Providers can prepare documents, calculations and filings from those facts, but no universal agency blessing protects an unreviewed file.[S4][S5][S11]
Role Labels Do Not Decide Legal Responsibility
A responsibility file should identify actual function, written appointment, contract scope, year covered, records held and authority rejected. Attorneys, accountants and actuaries are not fiduciaries when acting only in their professional capacity, but any person with discretion or control can become a fiduciary for that function. Settlor acts, such as establishing, amending or terminating a plan, are business choices; implementing those choices for the plan can be fiduciary work.[S1][S8][S9]
Delegation Requires Selection, Monitoring and Usable Records
Delegation should be documented before the task starts: the responsible entity, accepted scope, excluded scope, required inputs, review deadline, approval authority, evidence file, cybersecurity terms, insurance, SLA, error rework, indemnity, limitation of liability and termination access. DOL fee guidance says fiduciaries should compare providers using complete and identical plan facts, evaluate services and compensation, and monitor provider performance after selection. Cybersecurity guidance adds questions about audit reports, breach history, confidentiality, notification, insurance and contract provisions limiting responsibility for IT incidents.[S1][S2][S15]
Monitoring does not require the sponsor to personally perform every calculation. It does require a process that can catch missing inputs, unsigned amendments, participant complaints, unfiled forms, unreasonable fees, late deposits, valuation gaps, unavailable records and vendor conflict warnings before the issue becomes harder to correct.[S1][S2][S12]
Responsibility Matrix: Owner, Reviewer, Approver, Evidence and Escalation
Use a RACI-style matrix without pretending that the matrix changes the law. The useful fields are operational owner, reviewer, approver, evidence and escalation. Each row below starts with the sponsor-side duty because that is where governance should be visible.
ROBS-Specific Allocation Without Provider Ranking
In a ROBS setup, the sponsor authorizes the C corporation, plan adoption, rollover sequence, employer-stock purchase, employee coverage and recurring administration calendar. A provider may form the corporation, draft plan documents, coordinate transfers, prepare calculations, support filings, refer or coordinate valuation work and help with corrections if the contract says so. An independent appraiser values private employer stock within the valuation engagement. Trustees or fiduciaries evaluate whether the plan transaction is prudent and supported. An auditor audits the plan if audit rules apply. Counsel and CPAs handle legal, tax and financial reporting lanes they accept in writing.[S1][S3][S4][S5][S11]
That allocation protects both sides. It avoids excusing providers for sloppy work, hidden exclusions or functions they actually controlled. It also avoids telling owners that a provider package transforms the sponsor's plan into a turnkey product with no continuing fiduciary, filing, employee, valuation, cybersecurity or correction duties.
Contracts, Insurance, Cybersecurity and Disputes
Private contracts matter because they define work, fees, deadlines, service levels, data access, rework, indemnity, limitation of liability, insurance, subcontractors and dispute procedure. They do not automatically bind agencies or participants. If a contract says the provider is not the plan administrator, fiduciary, trustee, legal representative or valuation expert, preserve that language and compare it with the provider's actual conduct. If the provider accepts discretion, controls assets or gives fiduciary investment advice, the function may matter more than the label.[S1][S8][S9][S10][S11]
For cybersecurity or data incidents, preserve contracts, SOC or audit reports, breach notices, access logs, portal exports, participant communications, claim files and insurance notices. Escalate through counsel when participant data, plan assets, claims, fiduciary breach allegations, correction programs or agency inquiries are involved. Fidelity bonds and fiduciary liability, professional liability, cyber liability and errors-and-omissions insurance are different protections and should not be treated as interchangeable.[S13][S14][S15]
Five Original Bounded Examples
These examples use facts, results and limits to show responsibility allocation. They do not predict a court, agency or contract outcome.
Recurring Controls for a ROBS Responsibility File
- Name the operational owner, reviewer, approver, evidence source and escalation path for every recurring task.
- Review provider scope before first payroll, first employee eligibility event, annual valuation, Form 5500 drafting, sale discussions and plan termination.
- Keep board, plan, payroll, trust, valuation, tax, participant and provider records in separate but cross-referenced folders.
- Document selection and monitoring of providers, including fees, cybersecurity, conflicts, insurance and transition rights.
- Preserve disputes early: contracts, tickets, emails, invoices, portal exports, workpapers, versions and signer approvals.
Correction work should close the loop. EPCRS emphasizes reasonable and appropriate correction, administrative practices that prevent recurrence and adequate records. DOL materials point to VFCP for certain fiduciary corrections and DFVCP for delinquent Form 5500 filings. The sponsor should identify the correction owner, provider cooperation required, participant effect, tax effect, agency channel, filing signature and post-correction control.[S5][S6][S7]
Related Guides and Official Next Steps
Use this responsibility map with ROBS fiduciary responsibilities, ROBS annual administration checklist, ROBS Form 5500 deadlines, ROBS audit support from providers, changing ROBS providers, correcting ROBS administration errors and provider comparison fields.
Official next step
Read the DOL fiduciary guide and IRS ROBS compliance project before signing a service agreement, approving a stock transaction, filing Form 5500 or correcting a known failure.
FAQ
Can a ROBS provider be responsible for its own mistake?
Yes. A provider may have contract, professional, negligence or fiduciary responsibility depending on what it agreed to do and what functions it actually performed. The point is narrower: hiring a provider does not automatically transfer every statutory plan duty away from the sponsor or fiduciaries.[S1][S4][S8][S9][S10][S11]
Does a service agreement override ERISA, IRS rules or participant rights?
No. A contract can allocate work, fees, indemnity, deadlines and dispute procedures between the parties. It does not automatically bind agencies or participants, and it does not make an unavailable exemption available.[S1][S4][S8][S9][S10][S11]
Who should approve a ROBS stock purchase?
The plan fiduciaries should evaluate the transaction, fair-market-value support, conflicts, plan terms and evidence. The sponsor authorizes corporate actions, the provider may prepare documents, and an independent appraiser may value the stock, but there is no universal agency blessing.[S1][S4][S8][S9][S10][S11]
Sources
Research ledger: docs/research/provider-responsibility-vs-plan-sponsor-responsibility-research-ledger.json. Sources were checked Aug. 12, 2026. Reviewer initials: DS.
- S1. U.S. Department of Labor EBSA: Meeting Your Fiduciary ResponsibilitiesUsed for fiduciary functions, settlor distinction, service-provider selection and monitoring, documents, disclosures, bonding, employer stock, Form 5500, VFCP and DFVCP. Limit: September 2021 DOL booklet, educational and not individualized legal advice.
- S2. U.S. Department of Labor EBSA: Understanding Retirement Plan Fees and ExpensesUsed for necessary services, reasonable fees, bundled and unbundled service arrangements, monitoring, participant fee disclosures and cybersecurity pointer. Limit: DOL fee guide, not a ROBS-specific service contract.
- S3. U.S. Department of Labor, IRS and PBGC: 2025 Instructions for Form 5500Used for annual return/report purpose, electronic filing, who must file, plan administrator and employer signature obligations, preparer limits and penalties. Limit: 2025 filing-year instructions; actual plan year and form version control.
- S4. Internal Revenue Service: Rollovers as Business Start-Ups Compliance ProjectUsed for ROBS sequence, IRS concern areas, determination-letter limits, stock valuation, participant information, Form 5500, Form 1120, Form 1099-R, promoter fees and operational failures. Limit: IRS compliance project page, not a provider contract allocation source.
- S5. Internal Revenue Service: EPCRS overviewUsed for plan sponsor correction paths, reasonable and appropriate correction, administrative procedures, adequate records, SCP, VCP and Audit CAP. Limit: Overview page; Rev. Proc. 2021-30 and later guidance govern details.
- S6. U.S. Department of Labor EBSA: Voluntary Fiduciary Correction ProgramUsed for fiduciary breach correction channel, participant-contribution and prohibited-transaction correction context. Limit: Program availability depends on facts and current EBSA conditions.
- S7. U.S. Department of Labor EBSA: Delinquent Filer Voluntary Compliance ProgramUsed for late Form 5500 correction channel and plan administrator filing escalation. Limit: DFVCP rules and fees can change.
- S8. Office of the Law Revision Counsel: ERISA section 3, 29 U.S.C. 1002Used for administrator, fiduciary, employer, party in interest and plan-role definitions. Limit: Statutory definitions require fact application.
- S9. Office of the Law Revision Counsel: ERISA section 404, 29 U.S.C. 1104Used for exclusive-benefit, prudence, diversification and plan-document fiduciary duties. Limit: Fiduciary application depends on function and plan documents.
- S10. Office of the Law Revision Counsel: ERISA section 405, 29 U.S.C. 1105Used for co-fiduciary boundaries, knowing participation, concealment, enabling breach and duty to remedy. Limit: Does not make every sponsor liable for every vendor error.
- S11. Office of the Law Revision Counsel: ERISA section 408, 29 U.S.C. 1108Used for service-provider and employer-security prohibited-transaction exemptions, necessary services, reasonable compensation and adequate consideration. Limit: Exemptions require conditions; private contract labels do not satisfy them by themselves.
- S12. Office of the Law Revision Counsel: ERISA section 107, 29 U.S.C. 1027Used for report and disclosure record retention for evidence preservation. Limit: Not the only retention rule that may apply.
- S13. Office of the Law Revision Counsel: ERISA section 503, 29 U.S.C. 1133Used for claims procedure baseline for denied benefits and full and fair review. Limit: Detailed claims rules depend on plan type and regulations.
- S14. U.S. Department of Labor EBSA: Field Assistance Bulletin No. 2008-04Used for fidelity bond distinction from fiduciary liability insurance. Limit: Bonding guidance, not provider malpractice coverage.
- S15. U.S. Department of Labor EBSA: Tips for Hiring a Service Provider with Strong Cybersecurity PracticesUsed for cybersecurity diligence, breach notification, confidentiality, audit reports, insurance and contract provisions. Limit: Cybersecurity tips; actual incident duties require contract and law review.