Cybersecurity Questions to Ask a TPA
A checklist for plan advisers helping sponsors choose and monitor a third-party administrator: what to ask, what a strong answer includes, and what should prompt a second question.
The short answer: ask for evidence, not assurances. That means a current independent audit report, the TPA’s rules for multi-factor authentication and access, how it verifies a distribution request, how quickly its contract requires it to report a breach, and what its insurance covers. The Department of Labor treats choosing a provider as a fiduciary act and tells plan sponsors to use providers with strong cybersecurity practices. The questions below turn that guidance into an adviser’s due-diligence format.
“Hiring a service provider in and of itself is a fiduciary function.” Source: EBSA, Meeting Your Fiduciary Responsibilities (opens in new tab)
Why the Adviser Ends Up Asking
Most plan sponsors do not have security staff, and many lean on their adviser when choosing providers. The Department of Labor has said as much: “plan fiduciaries often rely heavily on pension consultants and other professionals for help,” including in “selecting other service providers” (EBSA, Selecting and Monitoring Pension Consultants (opens in new tab)). A TPA holds the census, the Social Security numbers and the distribution paperwork for every participant, so its security belongs in that review alongside fees and service.
The fiduciary standard is about process. EBSA’s guidance puts it directly: “Prudence focuses on the process for making fiduciary decisions,” and it recommends documenting decisions and the reasons for them. A consistent set of questions, sent in writing and kept on file, is that process.
If your firm is an SEC-registered investment adviser, there may be a second reason. Amended Regulation S-P (opens in new tab), which all covered firms must now follow, requires oversight of service providers “including through due diligence and monitoring,” and requires firms to make sure those providers report a qualifying breach to them within 72 hours. The rule defines a service provider as one with access to customer information “through its provision of services directly to a covered institution,” so whether a particular TPA counts depends on the relationship. Our analysis of the 72-hour clause covers when it applies.
The Questions
Each group below lists the question, what a strong answer includes, and the answers that should prompt a follow-up. Most of the questions trace to EBSA’s Tips for Hiring a Service Provider with Strong Cybersecurity Practices (opens in new tab) and its 12 cybersecurity best practices.
1. Program and independent audit
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| Is your security program written down, and when was it last reviewed by an outside auditor? | A current independent report, such as a SOC 2 Type 2, that covers the systems holding plan data | “We’re compliant” with no report, or a report that covers only the hosting provider |
| Will the contract let the sponsor see future audit results? | A contract right to review results every year | Results available only at the TPA’s discretion |
EBSA tells sponsors to ask about “audit results,” to prefer providers that “use an outside (third-party) auditor to review and validate cybersecurity,” and to look for “contract provisions that give you the right to review audit results.”
2. Access to systems and data
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| Is multi-factor authentication required for email, remote access and the administration platform? Is any of it phishing-resistant? | MFA everywhere it is available, documented exceptions, and security keys or passkeys for administrators | MFA on email only, shared logins, or “we’re rolling it out” |
| Who can see participant data, including subcontractors and offshore staff? | Access by role, reviewed at least quarterly, and a current list of subcontractors with access | No subcontractor list |
| Is participant data encrypted at rest and in transit, including file transfers to the recordkeeper? | Yes, with the method named for each | “Where appropriate,” with no detail |
EBSA’s best practices call for multi-factor authentication “wherever possible,” phishing-resistant MFA if possible, access privileges “reviewed at least every three months,” and encryption of sensitive data at rest and in transit. The connections to recordkeepers and payroll providers are covered in The Connections Nobody Audits.
3. Distributions and account changes
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| How do you verify a distribution request, or a change of address, email or bank account? | A written procedure that confirms requests through contact details already on file, adds checks when details changed recently, and notifies the participant | Requests accepted by email or fax alone |
| What happens when several account details change shortly before a distribution request? | Extra review before the money moves | No answer, or “the recordkeeper handles that” |
This is where fraud succeeds. One line in EBSA’s best practices reads: “Confirm the identity of the authorized recipient of the funds.” Others call for alerts when account information changes and additional validation when personal information has changed before a distribution. In the federal account-takeover cases we reviewed, the losses ran through exactly these steps.
4. Incidents and notification
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| Have you had a security incident? What happened, and what changed afterward? | A direct answer with dates and the fixes made | A refusal to discuss it |
| How quickly will you notify the sponsor of an incident, and is that in the contract? | A specific window written into the contract, and a named contact | “Promptly,” with no number |
EBSA tells sponsors to ask “whether the service provider has experienced past security breaches, what happened, and how the service provider responded,” to check “public information regarding information security incidents, other litigation, and legal proceedings,” and to make sure the contract identifies “how quickly you would be notified.”
5. Insurance and contract terms
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| What cyber insurance do you carry, and does it cover losses caused by your own employees? | A certificate of insurance with limits, and confirmation of crime or employee-misconduct coverage | No cyber policy, or no certificate on request |
| Does the contract limit your responsibility for a security breach? | Terms the sponsor’s counsel has reviewed and accepted | Broad disclaimers of liability for breaches |
EBSA suggests sponsors look for coverage of “internal threats, such as misconduct by the service provider’s own employees or contractors,” and lists “cyber liability and privacy breach insurance, and/or fidelity bond/blanket crime coverage” among the terms to consider. It also tells sponsors to “beware contract provisions that limit the service provider’s responsibility for IT security breaches.” More on what carriers now expect is in Cyber Insurance for TPAs.
6. Ongoing monitoring
| Ask | A strong answer includes | Follow up if you hear |
|---|---|---|
| What will you send us each year without being asked? | An updated audit report, an insurance certificate, a statement of material incidents, and subcontractor changes | Nothing unless requested |
The Department of Labor’s general guidance on service providers tells fiduciaries to get “a commitment from your service provider to regularly provide you with information regarding the services it provides” (EBSA, Tips for Selecting and Monitoring Service Providers (opens in new tab)) and to “establish and follow a formal review process at reasonable intervals” (EBSA, Meeting Your Fiduciary Responsibilities (opens in new tab)).
Make It Part of the Plan File
The same guidance puts it plainly: “Prepare a written record of the process you followed in reviewing potential service providers and the reasons for your selection of a particular provider.” In practice:
- Send the questions in writing with the request for proposal, and ask for documents rather than descriptions.
- Keep the answers and the evidence in the plan’s fiduciary file, dated.
- Repeat the request at each annual review, and whenever the TPA reports an incident, changes platforms or adds a subcontractor.
If You Are the TPA Answering These
These are the questions your advisers and plan sponsors are asking. Our guide to answering a plan sponsor cybersecurity questionnaire covers the evidence to have ready, and the free TPA Cyber Rules Navigator shows which rules and deadlines apply to your firm.
Frequently Asked Questions
What cybersecurity questions should an adviser ask a TPA?
Ask for its latest independent audit report, its multi-factor authentication and access rules, how it verifies distribution requests and account changes, its incident history, how quickly its contract requires it to report a breach, and what its cyber and crime insurance covers. Then ask what it will send each year without being asked.
Is a SOC 2 report enough?
It is the strongest single piece of evidence, but check two things. A Type 2 report tests whether controls operated over a period; a Type 1 report covers design as of a single date. And the report has to cover the systems that hold plan data. A report may not describe how the TPA verifies a distribution request, so ask that separately.
How often should a TPA’s cybersecurity be reviewed?
At least once a year, and again after a breach, a platform change or a new subcontractor. EBSA’s guidance calls for a formal review process at reasonable intervals and for documenting each decision.
Advising a TPA That Needs These Answers?
A free IT and cybersecurity assessment shows a TPA where it stands against these questions, and which evidence it is missing.
Book Free IT & Cyber Assessment (opens in new tab)