ERISA fiduciary duties are the legal obligations owed by anyone who manages a private-sector retirement or health plan, its assets, or its administration to the workers and retirees who depend on it. The Employee Retirement Income Security Act of 1974 imposes four core duties — loyalty, prudence, diversification, and adherence to plan documents — and backs them with personal liability, excise taxes, and the possibility of court-ordered removal.1U.S. Department of Labor. Employee Retirement Income Security Act The rules apply to 401(k) plans, pensions, and employer-sponsored health coverage.
Who Counts as a Fiduciary
Your title does not decide this. ERISA uses a functional test. You are a fiduciary if you do any of three things: exercise decision-making authority over the plan’s management or control over its assets, provide investment advice for compensation, or hold decision-making power over day-to-day administration.2Office of the Law Revision Counsel. 29 USC 1002 – Definitions
That definition catches people who never appear in the plan documents. If you decide which investment options to offer, which claims to approve, or which service providers to hire, you are a fiduciary whether anyone gave you the label or not. Courts look at who actually wielded the power. Third-party administrators and investment consultants frequently cross into fiduciary status based on the scope of their influence over plan decisions.
An executive who signs off on moving plan assets into riskier investments cannot dodge responsibility by pointing at whoever holds the “plan administrator” title. The person who made the call is the person on the hook.
The Duty of Loyalty
Every fiduciary must act solely in the interest of participants and beneficiaries, for the exclusive purpose of providing benefits and covering reasonable plan expenses.3Office of the Law Revision Counsel. 29 USC 1104 – Fiduciary Duties The plan’s money exists for one reason: to pay benefits. Channeling assets toward propping up the employer or rewarding a favored vendor with an inflated contract violates this duty.
The “reasonable expenses” language drives many real-world disputes. A fee is reasonable only if the service is necessary and the price is competitive. Fiduciaries do not have to pick the cheapest option, but they do have to run a genuine process comparing alternatives and documenting why a particular provider was chosen. Rubber-stamping a fee schedule without shopping around is how breach-of-loyalty lawsuits typically start.
The duty holds even when the sponsoring company is struggling. The plan’s interests are legally separate from the employer’s, and the fiduciary protects the former even at the expense of the latter.
The Duty of Prudence
The second core duty requires fiduciaries to act with the care, skill, and diligence that a knowledgeable person in a similar role would use.3Office of the Law Revision Counsel. 29 USC 1104 – Fiduciary Duties This is often called the prudent expert standard. The bar is what a professional familiar with retirement plan management would do, not what a reasonable layperson would.
Courts evaluate the process, not the outcome. An investment that loses money is not automatically a breach. What matters is whether the fiduciary researched the options, consulted qualified advisors, weighed the plan’s specific needs, and documented each step. An investment that happens to make money can still be a breach if the fiduciary picked it on a hunch without doing any homework.
Documentation is the evidence that you followed a sound process. Meeting minutes, written comparisons of investment alternatives, records of advisor consultations, and periodic performance reviews build the paper trail that separates a defensible decision from an indefensible one. When the Department of Labor investigates, it asks to see the file. An empty file is a problem.
Prudence now extends to data protection. In 2021, the Department of Labor issued its first formal cybersecurity guidance for ERISA plans, treating the safeguarding of participant data and plan assets against cyber threats as a fiduciary responsibility.4U.S. Department of Labor. Cybersecurity Program Best Practices The guidance calls for annual risk assessments, encryption of sensitive data, multi-factor authentication, incident response plans, and rigorous oversight of third-party service providers. Selecting a recordkeeper without asking about security infrastructure no longer meets the standard.
Diversification
Fiduciaries must diversify plan investments to minimize the risk of large losses.3Office of the Law Revision Counsel. 29 USC 1104 – Fiduciary Duties The statute prescribes no specific percentages or asset classes, but concentration in a single stock, sector, or asset type is generally impermissible. The only exception is when concentration is “clearly prudent,” a narrow carve-out courts rarely accept.
What counts as adequate diversification depends on the plan’s size, goals, and participant demographics. A plan with mostly young workers can tolerate more equity exposure than one serving participants near retirement. Investment regulations require fiduciaries to weigh the portfolio’s composition, its liquidity relative to anticipated cash flow needs, and its projected returns relative to the plan’s funding objectives.5eCFR. 29 CFR 2550.404a-1 – Investment Duties
Following the Plan Documents
The fourth duty ties the others together. Fiduciaries must administer the plan according to its governing documents.3Office of the Law Revision Counsel. 29 USC 1104 – Fiduciary Duties The plan document sets out how benefits are calculated, who is eligible, and how investments are managed. Deviating from it, even with good intentions, is a breach.
One qualifier matters: the plan documents themselves must be consistent with ERISA. If a document instructs the fiduciary to do something that violates federal law, the statute wins. Most plan-document breaches involve simpler mistakes, though — wrong eligibility rules, miscalculated vesting schedules, or late distribution of required notices.
Prohibited Transactions
ERISA flatly bans certain transactions on top of the four core duties. A fiduciary cannot knowingly cause the plan to engage in a sale, lease, loan, or transfer of assets with a “party in interest” — the employer, plan service providers, unions, and their relatives or affiliates.6Office of the Law Revision Counsel. 29 USC 1106 – Prohibited Transactions The plan also cannot buy employer stock or real property beyond statutory limits.
Self-dealing rules are stricter. A fiduciary cannot use plan assets for personal benefit, act on behalf of anyone whose interests conflict with the plan’s, or accept kickbacks from any party doing business with the plan.6Office of the Law Revision Counsel. 29 USC 1106 – Prohibited Transactions These are categorical prohibitions, not judgment calls. Good intentions create no exception.
The most common prohibited transaction is mundane: failing to deposit employee payroll deferrals into the plan on time. When a participant’s 401(k) contribution is withheld from their paycheck but sits in the employer’s general account for weeks, the delay is treated as a use of plan assets by a party in interest.
The tax consequences are severe. The Internal Revenue Code imposes an initial excise tax of 15% of the amount involved, assessed for each year (or partial year) the transaction remains uncorrected. If the transaction still isn’t fixed after the taxable period ends, a second-tier tax of 100% of the amount involved applies.7Office of the Law Revision Counsel. 26 USC 4975 – Tax on Prohibited Transactions These taxes are paid by the disqualified person who participated in the transaction, reported on IRS Form 5330.8Internal Revenue Service. Retirement Topics – Tax on Prohibited Transactions Fix the problem quickly or the penalty escalates.
When You’re Liable for Someone Else’s Breach
A fiduciary can be personally liable for another fiduciary’s misconduct in three situations: you knowingly participated in or helped conceal the breach; your own failure to meet fiduciary standards enabled the other person to commit the breach; or you knew about the breach and did not take reasonable steps to fix it.9Office of the Law Revision Counsel. 29 USC 1105 – Liability for Breaches by Co-Fiduciaries
That third scenario catches people off guard. Looking the other way when a fellow committee member makes a questionable decision is not a neutral act. Silence about a known breach can transfer liability to you. Committee members who skip meetings or skim reports have a problem here: ignorance is a defense only if you genuinely could not have known. Choosing not to look does not count.
The 404(c) Safe Harbor for Participant-Directed Plans
For participant-directed plans like most 401(k)s, ERISA offers a shield. If the plan meets certain conditions, fiduciaries are not liable for losses resulting from participants’ own investment choices. To qualify, the plan must offer at least three diversified investment options with meaningfully different risk and return profiles, give participants enough information to make informed decisions, and allow participants to change their investments at reasonable intervals.10eCFR. 29 CFR 2550.404c-1 – ERISA Section 404(c) Plans
The safe harbor covers individual investment outcomes. It does not excuse the duty to select and monitor the menu itself. Offering three terrible options does not qualify. The fiduciary still applies the prudent person standard when picking funds, monitoring performance, and replacing underperformers.
Fidelity Bond Requirements
Every person who handles plan funds or property must be covered by a fidelity bond. The bond amount must equal at least 10% of the plan assets handled in the preceding year, with a floor of $1,000 and a ceiling of $500,000.11Office of the Law Revision Counsel. 29 USC 1112 – Bonding The bond protects the plan against losses from fraud or dishonesty by plan officials. Registered broker-dealers subject to self-regulatory organization bonding rules and corporate trust companies with adequate capital and surplus are exempt.
Fidelity bonds are not fiduciary liability insurance. A bond covers theft and fraud; fiduciary liability insurance covers negligent management decisions. Many sponsors carry both, but only the bond is required. Plans holding employer stock face a higher maximum — the Secretary of Labor may prescribe amounts above $500,000, still capped at 10% of handled funds.
Reporting Deadlines That Trigger Penalties
Plan administrators must file the annual Form 5500 within 210 days after the end of the plan year.12Office of the Law Revision Counsel. 29 USC 1024 – Filing With Secretary and Furnishing Information to Participants and Beneficiaries Failure to file can trigger penalties of up to $2,670 per day under the most recent published DOL inflation-adjusted schedule.13U.S. Department of Labor. Fact Sheet – Adjusting ERISA Civil Monetary Penalties for Inflation Those penalties accrue daily.
Participants must receive a Summary Plan Description within 90 days of becoming covered by the plan. Beneficiaries receiving benefits get the same 90-day window.12Office of the Law Revision Counsel. 29 USC 1024 – Filing With Secretary and Furnishing Information to Participants and Beneficiaries The Summary Plan Description explains what the plan covers, how to file a claim, and what rights participants have.
What a Breach Costs You Personally
A fiduciary who breaches any of these duties is personally liable to restore all losses the plan suffered as a result and to give back any profits made through misuse of plan assets.14Office of the Law Revision Counsel. 29 USC 1109 – Liability for Breach of Fiduciary Duty Personally liable means your own assets, not just the employer’s. Courts can also order equitable relief, including removal from the fiduciary role.
The scope depends on the breach. Late deposit of participant deferrals might require restoring a few hundred dollars of lost earnings. Steering plan assets into conflicted investments over several years can produce judgments in the tens of millions. Either way, the remedy makes the plan whole, which includes the investment returns the plan would have earned if the money had been handled properly.
Participants, beneficiaries, other fiduciaries, and the Secretary of Labor all have standing to sue.15Office of the Law Revision Counsel. 29 USC 1132 – Civil Enforcement The Department of Labor’s Employee Benefits Security Administration investigates mismanagement and brings its own lawsuits. Participant class actions have become a major enforcement mechanism, particularly in the excessive-fee litigation wave that has hit large employer plans over the past decade.
Fiduciary breach claims must generally be filed within six years of the last act constituting the breach, or within three years of the date the plaintiff first gained actual knowledge of it, whichever comes first.16Office of the Law Revision Counsel. 29 USC 1113 – Limitation of Actions Fraud or active concealment extends the clock to six years from discovery. You are not liable for breaches that happened before you took the role or after you left it.14Office of the Law Revision Counsel. 29 USC 1109 – Liability for Breach of Fiduciary Duty
Fixing a Mistake Before Enforcement Finds It
The Department of Labor’s Voluntary Fiduciary Correction Program lets plan officials fix certain violations proactively and reduce the risk of enforcement.17U.S. Department of Labor. Voluntary Fiduciary Correction Program The program covers specific categories, including late participant contributions, improper loans, and incorrect asset valuations. Applicants calculate and restore any losses with interest, then submit an application to the Employee Benefits Security Administration documenting the corrective action.
As of March 2025, the program added a self-correction component for two common errors: late participant contributions and loan repayment deposits, and certain inadvertent participant loan failures. Self-correction lets plan officials fix these problems without filing a full application, provided they restore participants’ losses and keep records of the correction.
For a fiduciary who discovers a mistake, voluntary correction is almost always the smarter move than waiting for the DOL to find it. It demonstrates good faith, typically avoids civil penalties, and resolves the matter without litigation.