Most plan sponsors do not think about their ESOP audit until the engagement letter arrives. By then, the documentation window is already tight, and any gaps in records take longer to close than anyone expects. Advisors who understand what an ESOP audit actually requires, and when, can help clients avoid that scramble entirely.
This is less about knowing audit procedure in technical depth and more about knowing what to ask for, and when to ask for it. A client who starts gathering the right records months ahead of engagement moves through the audit with far less friction than one who starts the week the auditor requests them.
| QUICK ANSWER An ESOP audit involves examining areas such as the plan’s financial information, participant records, plan documents, stock valuation, and transactions relevant to the audit. The specific information and documentation requested will depend on the plan and the scope of the audit. Advisors can help clients prepare by understanding what information may be needed and coordinating with the audit team early in the process. |
When an ESOP Audit Requirement Applies
An ESOP may be subject to an annual independent audit when the plan meets the participant-count threshold that triggers an audit requirement under ERISA. For Form 5500 purposes, plans generally must include an independent auditor’s report when they are required to file as a large plan. The determination is based on the participant count reported on the plan’s Form 5500 and can depend on the plan’s specific circumstances.
Because the audit requirement is tied to the plan’s Form 5500 filing, plan sponsors typically become aware of the requirement during the annual filing process, often through their third-party administrator (TPA). Advisors working with an ESOP that is approaching the applicable threshold should encourage the plan sponsor to confirm the requirement and begin planning for the audit early.
Documentation Plan Sponsors Should Prepare
The specific list varies by plan, but most ESOP audits request records across the same core categories:
| Documentation Category | What It Typically Includes |
| Stock valuation | The current year’s independent appraisal report and prior year’s report for comparison |
| Plan governance | The plan document, all amendments, and trust agreement |
| Participant records | Census data, eligibility records, and allocation calculations |
| Distributions | Distribution requests, diversification elections, and related approvals |
| Related-party activity | Loan agreements, stock purchase or sale transactions, and any dealings between the trust and the sponsoring company |
| Prior compliance | The prior year’s Form 5500 and any related correspondence with the DOL or IRS |
Not every plan will have all of these in the same format, and an experienced ESOP audit team will clarify what applies to a specific plan early in the engagement rather than requesting a generic list.
A Realistic ESOP Audit Timeline
Timelines vary by plan size and complexity, but most ESOP audits move through a similar sequence:
- Engagement and planning. The audit team confirms scope, requests the initial document list, and schedules key milestones.
- Document collection. The plan sponsor gathers and submits the requested records, ideally supported by a secure, trackable system rather than email attachments.
- Fieldwork and testing. The audit team performs risk-based testing across allocation, distribution, valuation reliance, and related-party areas.
- Review and communication. Findings, if any, are communicated to plan management, typically through a communications with governance letter.
- Report delivery. The final audit report is issued for inclusion with the plan’s Form 5500 filing.
Plans that begin document collection early and use a single, organized system to track outstanding requests generally move through fieldwork faster than plans coordinating everything through scattered email threads.
How Proprietary Audit Technology Changes the Experience
A dedicated document portal that tracks exactly what has been requested, submitted, and still outstanding removes a significant amount of the back and forth that otherwise slows an ESOP audit down. This is one of the areas where a firm’s investment in its own audit technology shows up directly in the plan sponsor’s experience, not just in efficiency behind the scenes. Technology in this context supports the audit team’s professional judgment. It does not replace it. Advisors who want to see how this fits into our audit process, or who have a client ready to move forward, can request a proposal directly.
Compliance Versus Audit Assurance: What Advisors Should Clarify for Clients
It is worth setting this expectation early with clients: an ESOP audit provides independent assurance based on applicable auditing standards, using risk-based testing procedures. It does not test 100% of the plan’s transactions, and it does not guarantee that the plan is fully compliant with every ERISA requirement. An audit finding is something for the plan sponsor to review further, not automatically evidence of a compliance failure. Advisors who set this expectation up front help clients interpret audit results accurately rather than reacting to a finding as a crisis.
A Preparation Checklist Advisors Can Walk Clients Through
- Confirm the current independent stock valuation report is finalized and available.
- Reconcile participant census and payroll data against plan records before the audit begins.
- Gather the plan document, all amendments, and the trust agreement in one place.
- Document any related-party transactions between the company and the ESOP trust from the plan year.
- Confirm who on the plan sponsor’s team owns document collection and response deadlines.
- Ask the audit firm early which items on this list apply to the specific plan, since not every category applies to every ESOP.
Key Takeaways
- An ESOP audit generally involves areas such as stock valuation, plan governance, participant records, distribution activity, and related-party transactions, although the specific audit procedures and information needed vary by plan.
- Having an organized timeline that coordinates the plan sponsor and key service providers is important to keeping the audit and related plan reporting on schedule and ensuring a timely filing.
- A dedicated document tracking system reduces the back and forth that otherwise slows an ESOP audit down.
- An audit provides independent assurance through risk-based testing. It does not guarantee full ERISA compliance or review every transaction.
- Advisors add real value by walking clients through a preparation checklist before the audit engagement begins, not just at referral.
The Bottom Line
An ESOP audit runs more smoothly when the plan sponsor knows what to prepare well before the engagement starts. For advisors, walking a client through documentation expectations and a realistic timeline ahead of time is a concrete way to add value beyond the initial referral, and it sets the client up to interpret the audit’s results accurately rather than being caught off guard by a routine finding.
If a client is preparing for an upcoming ESOP audit, Caron Bletzer’s ESOP audit team can walk through what applies to their specific plan before the engagement begins.
This article was reviewed by Kimberly Jarry, Partner at Caron Bletzer, PLLC. Kimberly has concentrated her practice on employee benefit plan audits for more than 13 years, including the audit of employee stock ownership plans, and is a licensed CPA in the state of New Hampshire.
Frequently Asked Questions
Most ESOP audits request the current independent stock valuation report, the governing plan document and amendments, participant census and allocation records, distribution and diversification records, related-party transaction documentation, and the prior year’s Form 5500.
Many plan sponsors should begin preparing several months before the audit engagement starts. The plan’s reporting can take time to complete because the stock valuation must be finalized before the reporting can be prepared. Starting the process early gives the plan sponsor and its service providers enough time to complete the necessary reporting before the audit begins.
No. ESOP audits, like other employee benefit plan audits, use risk-based testing procedures focused on the areas most likely to contain material misstatements, rather than reviewing 100% of the plan’s transactions.
Incomplete documentation typically extends the audit timeline, since the audit team cannot complete testing in an area until the underlying records are available. Early preparation is the most effective way to avoid this.
Not entirely. An audit provides independent assurance based on applicable auditing standards. It is one part of a broader compliance picture, not a guarantee that every ERISA requirement has been met.
Most plans designate one internal owner, often in finance or HR, to coordinate document requests and deadlines. A single point of contact tends to reduce delays compared to requests spread across multiple people.
A secure portal that tracks outstanding document requests in real time can meaningfully reduce delays compared to coordinating everything by email, though it works alongside the audit team’s professional judgment rather than replacing it.