Skip to main content
401kROBSCheck eligibility
Free browser checklist

Provider Due-Diligence Checklist

Request evidence for a ROBS provider's legal identity, documented scope, setup steps, fee schedule, compliance boundaries, annual administration, audit support, cybersecurity practices, contract terms, referral conflicts, and transition records.

Direct answer: this checklist organizes questions for provider due diligence. It does not verify that provider statements are true, does not select or rank a provider, does not capture leads, and does not make a legal, tax, fiduciary, compliance, valuation, cybersecurity, investment, or suitability conclusion.

Author: Dennis ShirshikovUpdated: Aug. 13, 2026No affiliate ranking or lead form

Provider due-diligence checklist

Use the status menus to track evidence requests by provider-diligence category. Cleared and needs follow-up both count as reviewed applicable items. Not applicable is shown separately and removed from the completion denominator.

Reviewed applicable
0/24
Progress
0%
Needs follow-up
0
Not applicable
0

24 total checklist items. If every item is marked not applicable, progress is 100% because the applicable-item denominator is zero.

Provider identity, promoter history, and background checks

Verify the legal business, people, registrations, disciplinary history, and public-source proximity before relying on marketing claims.

Accountable owner: Plan sponsor with independent counsel

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Legal entity and trade-name verification

Red flag or follow-up cue: Refusal to identify the contracting entity, dissolved or inactive state records, mismatched invoice names, frequent rebrands, or pressure to sign before entity verification is complete.

Source or boundary: IRS warns ROBS arrangements are often aggressively marketed by promoters; a checklist cannot verify statements beyond source documents and public records.

Disciplinary, complaint, and professional-registration checks

Evidence to request: Request written disclosure of regulatory actions, litigation, arbitration, bankruptcy, license discipline, professional credentials, SEC IAPD or FINRA BrokerCheck results where investment advice or brokerage is claimed, BBB or state complaint history, and explanations for material findings.

Red flag or follow-up cue: Unlicensed investment advice, undisclosed disciplinary history, inconsistent answers across sales and contract teams, or a claim that a clean public search proves the arrangement is compliant.

Source or boundary: SEC Investor.gov says to check an investment professional's background, registration, licensing, and disciplinary history; state corporate and professional boards may also matter.

Source proximity, current dates, and authorship of provider materials

Evidence to request: Collect dated service descriptions, fee pages, engagement letters, plan-document summaries, methodology pages, author or reviewer names, and source URLs or PDFs showing when each claim was last updated.

Red flag or follow-up cue: Undated PDFs, anonymous compliance claims, copied generic articles, stale pricing, or oral promises that differ from written service documents.

Source or boundary: Use source proximity: primary contracts and regulator pages outrank sales copy. This site uses neutral, source-bounded content and does not rank or endorse a provider.

Written scope, roles, and service-provider boundaries

Separate what the provider does from what remains with the employer, trustee, TPA, recordkeeper, custodian, attorney, CPA, valuation professional, payroll provider, and lender.

Accountable owner: Plan sponsor and ERISA counsel

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Provider, TPA, recordkeeper, custodian, attorney, CPA, and valuation role map

Evidence to request: Request a written responsibility matrix naming each entity, whether it is a fiduciary or non-fiduciary service provider, who signs plan and corporate documents, who files returns, who values employer stock, and who answers audit or correction questions.

Red flag or follow-up cue: A single sales package blurs legal, tax, administration, valuation, custody, and investment roles or implies the provider accepts all plan-sponsor responsibilities.

Source or boundary: DOL states fiduciary status can arise from discretionary control over plan management or assets, plan administration authority, or compensated investment advice.

Included services, exclusions, and referral handoffs

Evidence to request: Request the master services agreement, SOW, onboarding checklist, annual-administration description, excluded-service list, referral relationships, third-party dependencies, and who pays each outside professional.

Red flag or follow-up cue: Key services such as payroll coordination, Form 5500 support, valuation, participant notices, amendments, corrections, or termination are described as included in sales calls but excluded in the contract.

Source or boundary: Contract language controls this checklist's evidence review; oral descriptions should be confirmed in writing before relying on them.

Fiduciary, legal, tax, and investment-advice boundary

Evidence to request: Ask whether any party acknowledges fiduciary status, provides investment advice, renders legal or tax opinions, or only supplies documents and administration support, and request the exact disclaimer language.

Red flag or follow-up cue: A provider says it is not your attorney, CPA, fiduciary, or investment adviser while marketing the setup as IRS-approved, guaranteed compliant, or suitable for your retirement assets.

Source or boundary: DOL fiduciary principles require loyalty, prudence, plan-document compliance, diversification, and conflict avoidance; this tool cannot determine fiduciary prudence.

Setup steps, plan documents, corporation records, and funding flow

Verify the exact sequence for C corporation formation, qualified plan adoption, rollover or transfer, employer-stock purchase, and corporate use of proceeds.

Accountable owner: Corporate counsel, ERISA counsel, and ROBS provider

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

C corporation, plan adoption, trust, rollover, and stock-purchase sequence

Evidence to request: Request a dated implementation timeline, articles, bylaws, EIN, board resolutions, plan adoption agreement, trust documents, rollover instructions, stock subscription agreement, stock ledger, certificate evidence, and corporate-bank receipt of plan stock-purchase proceeds.

Red flag or follow-up cue: Funds move before the corporation, plan, trust, stock purchase, or bank account is documented; the provider suggests using an LLC or S corporation without separate counsel review.

Source or boundary: IRS ROBS guidance describes a new C corporation, retirement plan, rollover or transfer, and plan purchase of employer stock.

Plan and corporate document ownership and amendment control

Evidence to request: Request final signed plan documents, summary plan description, corporate records book, amendment procedure, who keeps originals, how documents are updated, and what happens if you change providers.

Red flag or follow-up cue: Only templates are delivered, originals stay inaccessible, amendments require unknown fees, or the provider cannot explain who maintains plan and corporate records after setup.

Source or boundary: IRS says determination letters address plan terms, not correct operation or discriminatory administration.

Use-of-funds boundaries after stock purchase

Evidence to request: Collect written instructions identifying when corporate funds may be used for business expenses, acquisition costs, franchise fees, payroll, working capital, or reimbursements, and who reviews related-party payments.

Red flag or follow-up cue: Provider documentation treats plan assets and corporate assets interchangeably or suggests the owner can personally reimburse, borrow, guarantee, or redirect funds without counsel review.

Source or boundary: ERISA prohibited-transaction and fiduciary issues can arise around parties related to the plan; independent legal review is needed for boundaries.

Fee schedule, renewal, pass-through, and hidden-cost review

Turn sales pricing into a written total-cost schedule with setup, recurring, pass-through, employee, valuation, audit, correction, termination, refund, renewal, and escalation terms.

Accountable owner: Plan sponsor and CPA

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Setup, administration, employee, loan, valuation, audit, correction, and termination fees

Evidence to request: Request a line-item fee schedule covering setup, monthly or annual administration, per-participant or employee charges, loan administration, valuation, Form 5500, amendments, restatements, audit support, correction support, plan termination, document transfer, and late-payment charges.

Red flag or follow-up cue: The quote omits recurring fees, pass-through professional costs, employee-count changes, valuation costs, correction work, or exit charges that appear elsewhere in the contract.

Source or boundary: IRS project findings identify large recurring promoter fees as one possible factor in failed ROBS businesses; compare written scope, not provider rankings.

Renewal, refund, cancellation, and escalation mechanics

Evidence to request: Request auto-renewal terms, notice windows, cancellation rights, refund conditions, annual price increase formula, pass-through markups, payment method requirements, and what happens after missed payments.

Red flag or follow-up cue: Long auto-renewal windows, unilateral fee changes, nonrefundable setup fees despite nondelivery, service suspension that blocks record access, or vague escalation language.

Source or boundary: This checklist does not decide whether a fee is reasonable; plan fiduciaries and advisors should evaluate value, alternatives, and conflicts.

Affiliate, lender, franchisor, broker, or referral compensation

Evidence to request: Ask for written disclosure of referral fees, affiliate ownership, lender or franchisor relationships, broker compensation, insurance commissions, revenue sharing, and whether sales staff are compensated differently by product or partner.

Red flag or follow-up cue: The provider claims independence but receives undisclosed compensation from financing, franchise, valuation, payroll, custody, investment, insurance, or legal partners.

Source or boundary: DOL fiduciary guidance highlights conflict avoidance for plan fiduciaries; compensation conflicts require source documents and independent review.

ROBS compliance, fiduciary, valuation, and prohibited-transaction controls

Confirm how the provider documents adequate consideration, employer-stock valuation, prohibited-transaction boundaries, and ongoing plan-operation risks.

Accountable owner: ERISA counsel, fiduciary, and valuation professional

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Formation and ongoing employer-stock valuation controls

Evidence to request: Request valuation engagement scope, appraiser credentials, independence disclosures, information relied on, update frequency, annual valuation process, cost, delivery date, and who reviews adequate-consideration support.

Red flag or follow-up cue: The provider performs or controls valuation without independence safeguards, treats purchase price as automatically fair market value, or cannot explain annual valuation updates.

Source or boundary: IRS ROBS materials identify valuation of assets and stock purchases as compliance-check topics; adequate consideration requires professional analysis.

Prohibited-transaction and related-party review process

Evidence to request: Request written screens for owner loans, personal expenses, guarantees, owner-owned leases, family employment, compensation, stock redemptions, corporate loans, and transactions involving plan assets or parties in interest.

Red flag or follow-up cue: The provider answers fact-specific related-party questions with blanket approval, or the contract disclaims legal advice while marketing prohibited-transaction clearance.

Source or boundary: DOL says fiduciaries must avoid conflicts and transactions that benefit parties related to the plan, including service providers and plan sponsors.

Employee eligibility, coverage, nondiscrimination, and employer-stock access

Evidence to request: Request plan eligibility provisions, employee census workflow, participant notice templates, nondiscrimination and coverage testing process, employer-stock investment availability, amendment controls, and who monitors benefits-rights-and-features issues.

Red flag or follow-up cue: The provider says employees can be kept out indefinitely, employer stock can be closed after the owner invests, or testing is unnecessary without reviewing census facts.

Source or boundary: IRS lists plan amendments preventing other participants from buying stock, coverage, discrimination, and benefits-rights-and-features problems as ROBS concerns.

Annual administration, tax filings, notices, and deadlines

Map who prepares, reviews, signs, files, and pays for plan, payroll, corporate, and information-return obligations.

Accountable owner: Plan sponsor, CPA, payroll provider, and TPA

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Form 5500, 1099-R, plan records, and participant reporting

Evidence to request: Request the annual administration calendar, Form 5500 or 5500-SF process, Form 1099-R process for rollovers or distributions, participant statements, contribution records, required notices, and signature responsibilities.

Red flag or follow-up cue: Provider says no annual return is needed because the owner is the only participant, ignores 1099-R handling, or does not identify who signs and files plan returns.

Source or boundary: IRS says many ROBS sponsors failed to file Form 5500 or 1120 and that the one-participant exception does not apply when the plan owns the business through employer stock.

Corporate, payroll, state, and information-return filing coordination

Evidence to request: Request the Form 1120 coordination plan, payroll-tax accounts, Form 945 or withholding support if applicable, state franchise or income tax obligations, secretary-of-state annual reports, and CPA handoff procedures.

Red flag or follow-up cue: The provider's scope stops at plan documents while marketing complete compliance, or the CPA assumes the provider handles plan returns and stock records.

Source or boundary: IRS ROBS compliance checks requested business information, Form 1120 explanations, contribution history, rollover information, participant data, and stock valuation records.

Deadline calendar, reminders, and owner signoff

Evidence to request: Request a dated calendar for plan restatements, amendments, valuations, testing, Form 5500, corporate filings, payroll deposits, insurance renewals, and service-renewal notice windows with each accountable owner.

Red flag or follow-up cue: No single calendar exists, reminders go only to the provider portal, owner approvals are not documented, or missed deadlines shift entirely to the sponsor after vague notices.

Source or boundary: A tool status does not prove filing compliance; owner signoff and advisor verification remain necessary.

Audit, investigation, correction, and termination support

Determine what the provider does if the IRS, DOL, lender, CPA, auditor, employee, or successor provider requests records or corrections.

Accountable owner: Plan sponsor with ERISA counsel and CPA

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

IRS, DOL, CPA, lender, and auditor support scope

Evidence to request: Request written audit-support terms, response-time standards, included hours, extra fees, who prepares document packages, whether counsel is included, and how provider workpapers are delivered.

Red flag or follow-up cue: Audit support is advertised but the agreement excludes government responses, legal representation, document recreation, or historical records after termination.

Source or boundary: IRS ROBS compliance checks ask for plan status, contributions, rollover information, participant records, stock valuation, business information, and filing explanations.

Correction program and error-resolution responsibility

Evidence to request: Request the provider's process for missed Form 5500 filings, eligibility errors, valuation errors, late amendments, prohibited transactions, rollover reporting mistakes, and whether EPCRS, DFVCP, or VFCP advisors are outside scope.

Red flag or follow-up cue: Provider guarantees correction eligibility, downplays participant harm, or refuses to identify when independent ERISA counsel or CPA review is needed.

Source or boundary: Correction-program availability is fact-specific; this checklist cannot decide qualification, tax consequences, or DOL/IRS acceptance.

Provider transition, plan termination, and records export

Evidence to request: Request termination costs, cancellation steps, final valuation and Form 5500 process, stock redemption or rollover coordination, document export format, successor-provider cooperation, and record-retention obligations.

Red flag or follow-up cue: Records cannot be exported without large fees, termination support is undefined, or plan and corporate records are held hostage after payment disputes.

Source or boundary: IRS project findings mention business failure, bankruptcy, liens, and dissolutions; transition and termination records should be preserved before problems arise.

Data security, privacy, access, continuity, and contract terms

Review participant-data handling, portal access, security controls, insurance, service standards, liability allocation, and contract exit rights.

Accountable owner: Plan sponsor, security reviewer, and counsel

0/3 reviewed applicable · 0% · 0 follow-up · 0 N/A

Data security, access control, ownership, export, and business continuity

Evidence to request: Request SOC reports or security summaries if available, MFA requirements, encryption and backup practices, incident-notice terms, data ownership, subprocessors, data export steps, retention, deletion, and business-continuity or disaster-recovery materials.

Red flag or follow-up cue: No MFA, shared credentials, unclear data ownership, no incident timeline, broad subprocessors without notice, or no way to export participant and plan records.

Source or boundary: DOL cybersecurity materials include tips for hiring service providers with strong security practices; plan fiduciaries should document vendor-security review.

Indemnity, limitation of liability, arbitration, privacy, and unilateral change terms

Evidence to request: Request the complete contract, order form, incorporated policies, privacy notice, arbitration clause, venue, jury waiver, indemnity, limitation of liability, warranty disclaimers, unilateral change rights, and survival clauses.

Red flag or follow-up cue: Liability is capped below foreseeable correction cost, the provider can change terms by website notice, arbitration or venue is impractical, or privacy terms conflict with plan-record obligations.

Source or boundary: Contract review is legal work; this checklist only identifies clauses to route to counsel.

Insurance, credentials, service levels, complaints, and references

Evidence to request: Request proof of E&O, cyber, fidelity or crime coverage if represented, credential rosters, support channels, response-time standards, complaint escalation path, client-reference process, and service-level exclusions.

Red flag or follow-up cue: Insurance is expired or unrelated, credentials belong to referral partners, references are cherry-picked without comparable facts, or service standards are marketing-only.

Source or boundary: References and insurance certificates are evidence inputs, not endorsements or proof of compliance.

How to use this provider checklist

Start with written materials, not sales claims. Save dated copies of the provider's agreement, SOW, fee schedule, methodology, privacy terms, security summaries, referral disclosures, and service descriptions. Capture source proximity, current dates, authorship, and whether each claim comes from a contract, regulator page, provider webpage, third-party referral, or oral statement.

Use status labels narrowly. Not started means no review has happened. In review means evidence is being evaluated. Cleared for planning means the evidence is sufficient for the current planning step. Needs follow-up means a gap, contradiction, or advisor question remains. Not applicable removes the item from the progress denominator, and a zero denominator returns 100% by design.

Do not use the checklist as a secure data room. It has no note fields, persistence, query-string state, cookies, local storage, provider grades, or lead capture. Keep contracts, tax IDs, participant data, account information, passwords, and private records in secure advisor-controlled systems.

Primary-source boundaries

IRS ROBS materials describe the core sequence as a C corporation, a qualified plan, rollover or transfer, and plan purchase of employer stock [1] [2]. IRS also warns that determination letters address plan terms rather than correct operation and identifies filing, valuation, prohibited-transaction, discrimination, promoter-fee, business-failure, bankruptcy, lien, and dissolution concerns [1]. Those warnings are why the checklist asks for concrete evidence rather than provider assurances.

DOL fiduciary guidance frames who may be a fiduciary and lists duties of loyalty, prudence, diversification, plan-document compliance, and conflict avoidance [3]. The checklist cannot decide fiduciary status or prudence. It routes role allocation, conflicts, compensation, valuation, and prohibited-transaction questions to independent ERISA counsel, CPA, valuation, and security review where needed.

DOL cybersecurity materials are relevant because ROBS providers, TPAs, recordkeepers, custodians, payroll vendors, and portals may handle participant or plan data [4]. SEC Investor.gov background-check guidance is relevant only where a person or firm claims investment-advice, brokerage, or advisory credentials [5]. State business, professional, insurance, attorney, CPA, and franchise records may also matter, and franchise-related provider referrals should be checked against the applicable franchise-disclosure documents and counsel review.

Editorial independence and no-ranking limitation

This page is not a provider marketplace. It does not accept provider inputs in the browser, does not route users to a salesperson, does not create a lead, does not use affiliate compensation to sort providers, and does not rank providers. Internal links below point to source-bounded comparison and methodology pages so users can understand available provider records without treating any record as a recommendation.

A provider that supplies every requested document can still be unsuitable, overpriced, conflicted, insecure, or wrong for a fact pattern. Conversely, an unavailable item may be not applicable. The checklist is a triage and documentation aid, not an endorsement, legal opinion, tax opinion, fiduciary process memo, investment recommendation, security certification, or compliance determination.

Compare documented provider records

Use side-by-side source-backed provider records without treating them as a ranking or recommendation.

Interactive ROBS Provider Comparison

Check fee math separately

Translate written setup, annual, pass-through, and termination fee terms into focused cost tools.

Review methodology and profiles

Read how provider pages use source dates, visible unknowns, profile pages, and ranking limitations.

What to escalate before signing

Escalate unresolved role boundaries, valuation independence, prohibited-transaction questions, employee eligibility, undisclosed referral compensation, contract liability caps, data-export limits, security gaps, audit-support exclusions, and plan-termination records to independent ERISA counsel, CPA, valuation, cybersecurity, insurance, or contract counsel as appropriate.

Sources and verification

  1. [1] IRS ROBS compliance project. IRS describes ROBS as a retirement-plan rollover into a plan that buys stock of a new C corporation, warns that promoters aggressively market arrangements, states determination letters do not protect incorrect operation, and lists filing, valuation, prohibited-transaction, discrimination, promoter-fee, bankruptcy, lien, and dissolution concerns. Page last reviewed Nov. 16, 2025; checked Aug. 13, 2026.
  2. [2] IRS ROBS guidelines memorandum. The IRS memorandum describes C corporation formation, plan creation, rollover or transfer, and plan purchase of employer stock, and states ROBS arrangements are not noncompliant per se but must be developed case by case. Dated Oct. 1, 2008.
  3. [3] DOL fiduciary responsibilities. DOL states fiduciaries include persons or entities with discretionary control over plan management or assets, plan-administration authority, or compensated investment-advice authority, and must act solely in participants' interest, prudently, follow plan documents consistent with ERISA, diversify, and avoid conflicts. Checked Aug. 13, 2026.
  4. [4] DOL retirement-plan cybersecurity. DOL's EBSA cybersecurity page links best practices and tips for hiring service providers with strong security practices. Checked Aug. 13, 2026.
  5. [5] SEC Investor.gov professional background checks. SEC Investor.gov says to check an investment professional's background, registration, licensing, and disciplinary history through IAPD or BrokerCheck where applicable. Checked Aug. 13, 2026.