Provider Due-Diligence Checklist
Request evidence for a ROBS provider's legal identity, documented scope, setup steps, fee schedule, compliance boundaries, annual administration, audit support, cybersecurity practices, contract terms, referral conflicts, and transition records.
Direct answer: this checklist organizes questions for provider due diligence. It does not verify that provider statements are true, does not select or rank a provider, does not capture leads, and does not make a legal, tax, fiduciary, compliance, valuation, cybersecurity, investment, or suitability conclusion.
Provider due-diligence checklist
Use the status menus to track evidence requests by provider-diligence category. Cleared and needs follow-up both count as reviewed applicable items. Not applicable is shown separately and removed from the completion denominator.
- Reviewed applicable
- 0/24
- Progress
- 0%
- Needs follow-up
- 0
- Not applicable
- 0
24 total checklist items. If every item is marked not applicable, progress is 100% because the applicable-item denominator is zero.
How to use this provider checklist
Start with written materials, not sales claims. Save dated copies of the provider's agreement, SOW, fee schedule, methodology, privacy terms, security summaries, referral disclosures, and service descriptions. Capture source proximity, current dates, authorship, and whether each claim comes from a contract, regulator page, provider webpage, third-party referral, or oral statement.
Use status labels narrowly. Not started means no review has happened. In review means evidence is being evaluated. Cleared for planning means the evidence is sufficient for the current planning step. Needs follow-up means a gap, contradiction, or advisor question remains. Not applicable removes the item from the progress denominator, and a zero denominator returns 100% by design.
Do not use the checklist as a secure data room. It has no note fields, persistence, query-string state, cookies, local storage, provider grades, or lead capture. Keep contracts, tax IDs, participant data, account information, passwords, and private records in secure advisor-controlled systems.
Primary-source boundaries
IRS ROBS materials describe the core sequence as a C corporation, a qualified plan, rollover or transfer, and plan purchase of employer stock [1] [2]. IRS also warns that determination letters address plan terms rather than correct operation and identifies filing, valuation, prohibited-transaction, discrimination, promoter-fee, business-failure, bankruptcy, lien, and dissolution concerns [1]. Those warnings are why the checklist asks for concrete evidence rather than provider assurances.
DOL fiduciary guidance frames who may be a fiduciary and lists duties of loyalty, prudence, diversification, plan-document compliance, and conflict avoidance [3]. The checklist cannot decide fiduciary status or prudence. It routes role allocation, conflicts, compensation, valuation, and prohibited-transaction questions to independent ERISA counsel, CPA, valuation, and security review where needed.
DOL cybersecurity materials are relevant because ROBS providers, TPAs, recordkeepers, custodians, payroll vendors, and portals may handle participant or plan data [4]. SEC Investor.gov background-check guidance is relevant only where a person or firm claims investment-advice, brokerage, or advisory credentials [5]. State business, professional, insurance, attorney, CPA, and franchise records may also matter, and franchise-related provider referrals should be checked against the applicable franchise-disclosure documents and counsel review.
Editorial independence and no-ranking limitation
This page is not a provider marketplace. It does not accept provider inputs in the browser, does not route users to a salesperson, does not create a lead, does not use affiliate compensation to sort providers, and does not rank providers. Internal links below point to source-bounded comparison and methodology pages so users can understand available provider records without treating any record as a recommendation.
A provider that supplies every requested document can still be unsuitable, overpriced, conflicted, insecure, or wrong for a fact pattern. Conversely, an unavailable item may be not applicable. The checklist is a triage and documentation aid, not an endorsement, legal opinion, tax opinion, fiduciary process memo, investment recommendation, security certification, or compliance determination.
What to escalate before signing
Escalate unresolved role boundaries, valuation independence, prohibited-transaction questions, employee eligibility, undisclosed referral compensation, contract liability caps, data-export limits, security gaps, audit-support exclusions, and plan-termination records to independent ERISA counsel, CPA, valuation, cybersecurity, insurance, or contract counsel as appropriate.
Sources and verification
- [1] IRS ROBS compliance project. IRS describes ROBS as a retirement-plan rollover into a plan that buys stock of a new C corporation, warns that promoters aggressively market arrangements, states determination letters do not protect incorrect operation, and lists filing, valuation, prohibited-transaction, discrimination, promoter-fee, bankruptcy, lien, and dissolution concerns. Page last reviewed Nov. 16, 2025; checked Aug. 13, 2026.
- [2] IRS ROBS guidelines memorandum. The IRS memorandum describes C corporation formation, plan creation, rollover or transfer, and plan purchase of employer stock, and states ROBS arrangements are not noncompliant per se but must be developed case by case. Dated Oct. 1, 2008.
- [3] DOL fiduciary responsibilities. DOL states fiduciaries include persons or entities with discretionary control over plan management or assets, plan-administration authority, or compensated investment-advice authority, and must act solely in participants' interest, prudently, follow plan documents consistent with ERISA, diversify, and avoid conflicts. Checked Aug. 13, 2026.
- [4] DOL retirement-plan cybersecurity. DOL's EBSA cybersecurity page links best practices and tips for hiring service providers with strong security practices. Checked Aug. 13, 2026.
- [5] SEC Investor.gov professional background checks. SEC Investor.gov says to check an investment professional's background, registration, licensing, and disciplinary history through IAPD or BrokerCheck where applicable. Checked Aug. 13, 2026.