401k: Operational Inertia?
While many business owners focus heavily on the initial setup involved in sponsoring a 401k for employees—selecting a recordkeeper, choosing a fund menu, and enrolling staff—the ongoing administration of the plan often falls by the wayside as day-to-day business demands take over. However, passive oversight of a plan governed by the Employee Retirement Income Security Act (ERISA) is very risky. Under federal law, plan sponsors have a continuous fiduciary duty to monitor fees, investment performance, plan design, vendor cybersecurity and more. It’s essential for sponsors to guard against operational inertia, taking proactive steps to protect participants’ savings and safeguard personal assets.
What Operational Inertia Looks Like
You set up a 401(k) plan. You picked a provider. You selected a fund lineup. You enrolled your employees. And then… life happened. The business grew, the workforce changed, the market shifted—and your retirement plan stayed exactly the same.
If that sounds familiar, you are not alone. While it may not look like a dramatic failure, operational inertia is one of the most common—and financially risky—threats facing 401(k) plan sponsors today. The plan runs on autopilot, year after year, with nobody actively steering. Here is the catch: under ERISA, autopilot is not a defense against oversights and errors. For example, as ERISA defense attorney Marcia Wagner, founder of The Wagner Law Group, reminds us, the duty of prudence under ERISA requires a fiduciary to “engage in benchmarking and the peer review of investments, and at some point in time remove an underperforming fund.” Bottom line, if your retirement plan is merely drifting along, you—as the plan sponsor and fiduciary—remain personally responsible for where it ends up.
Operational inertia sets in when a plan sponsor treats the 401(k) as a set-it-and-forget-it benefit rather than one that requires consistent attention. The plan keeps running, contributions keep flowing, participants keep logging in. Everything looks fine on the surface.But underneath, critical fiduciary oversight questions are likely going unasked. Consider for example:
- When did you last review your fund lineup against its benchmarks?
- Do you know the current expense ratios on every investment option?
- When did you last request a full breakdown of recordkeeping and administrative fees?
- Has your plan design kept pace with changes in your workforce?
- Do you have documented evidence that your service providers are maintaining strong cybersecurity practices?
If you cannot answer these questions confidently and with specifics, your plan is running on inertia. That is not a minor housekeeping issue—it is a fiduciary gap that the Department of Labor (DOL) (and the plaintiff bar) takes seriously.
Where Inertia Creates Real Risk
Passive oversight creates compounding problems that accumulate slowly, precisely because nothing obviously breaks down day-to-day:
- Fee Inflation: Investment expense ratios and recordkeeping fees change over time. Plans that have grown in assets may qualify for lower fee tiers, but without active benchmarking, sponsors often continue paying rates that were competitive years ago. The result: participants lose money to fees they should not be paying, and fiduciaries cannot show they checked.
- Performance Drift: A fund that outperformed its benchmark five years ago may be dragging today. Without systematic review against your Investment Policy Statement (IPS), participants can remain defaulted into investments that no longer meet the standard your plan document set. Prudent process requires ongoing monitoring, not a one-time selection.
- Plan Design Misalignment: Your workforce today may look very different from when the plan was established. If matching formulas, vesting schedules, and auto-enrollment features have not evolved alongside your employee demographics, you may be spending benefit dollars in ways that do not effectively motivate participation or retention.
- Cybersecurity Oversight Gaps: Retirement plans rely on a web of vendors—recordkeepers, custodians, payroll systems, third-party administrators—with overlapping access to sensitive participant data. The Department of Labor’s Employee Benefits Security Administration (EBSA) has made cybersecurity a national enforcement project. Without a documented vendor oversight process, sponsors cannot answer the most basic question regulators will ask: who has access to what, and have you verified their
Small and Mid-Size Plans: Plan Oversight Pointers
You do not need a large internal team to break out of operational inertia. What you need is a structured, repeatable process—and the discipline to follow it. Consider these points in establishing your oversight process:
- Quarterly Investment Review: Meet with your investment advisor to evaluate fund performance against benchmarks and peers. Identify any fund that has slipped below your IPS criteria, document the discussion, and take action—whether that means placing a fund on a watch list or replacing it. The meeting itself is evidence of prudent process.
- Annual Fee Benchmarking: Request a comprehensive breakdown of all plan costs from your recordkeeper: investment fees, recordkeeping fees, per-participant charges, and any revenue-sharing arrangements. Compare these against industry benchmarks for plans of your size. If your assets have grown, you have leverage to negotiate better terms.
- Plan Design Assessment: Review participation rates, deferral rates, and demographic trends. Are auto-enrollment and auto-escalation features in place? Is your match formula still the right incentive for your current workforce? Small design changes can meaningfully improve outcomes without dramatic cost increases.
- Vendor and Cybersecurity Documentation: Maintain a data-flow inventory showing which vendors have access to participant information. Request and review each vendor’s SOC reports, security summaries, and incident response protocols.
- Employee Engagement Check: Low participation is a signal that your plan design, communication, or education strategy needs adjustment. Work with your third party providers and administrators to survey participants, review enrollment data, and act on what you learn.
The Personal Liability You Carry
Under ERISA, plan sponsors and fiduciaries can be held personally liable for oversights that harm participants’ savings. That includes failing to monitor fees, allowing imprudent investments to remain on the menu, neglecting vendor oversight, and failing to verify cybersecurity safeguards. As ADP underscores:
- The Employee Retirement Income Security Act (ERISA) sets a demanding bar for anyone in the fiduciary role: decisions have to be made purely for the benefit of participants and beneficiaries. Sponsors who overlook this, or who haven’t built a support structure around it, take on personal financial exposure they may not know exists.
- Most employers rely on outside professionals for recordkeeping, compliance testing and daily operations. As the plan sponsor, you retain oversight even when you delegate tasks, making sure the right expertise is in place so nothing falls through the cracks.
Summing up, operational inertia leads to oversights. Oversights lead to fiduciary breaches. And fiduciary breaches lead to personal liability. The plan oversight pointers above can help you avoid the problems associated with inertia. But even the most diligent plan sponsors still need a layer of personal protection—because diligent process does not eliminate the risk of a claim, and the cost of defending one can be devastating without coverage.
Colonial Surety Company puts three essential coverages into one seamless, affordable bundle for retirement plan sponsors:
- ERISA Fidelity Bond: Fulfills your federal mandate to protect plan funds from dishonesty. Remember, an ERISA Bond protects the plan–not you. Colonial Surety Company is a direct, Treasury-Listed bond writer.
- Fiduciary Liability Insurance (FLI): Shields your personal assets, providing up to $1,000,000 in legal defense costs and covered losses for claims alleging administrative errors, oversight omissions, or breach of fiduciary duty.
- Complimentary Cyber Liability Insurance: Provides $50,000 of protection for the plan and company against regulatory actions following a data breach, directly addressing the DOL’s response plan recommendations.
Protect your retirement plan, your business, and your personal assets in one smart move: bundle your ERISA Bond with Fiduciary and Cyber Liability Insurance at Colonial Surety Company.
👉Get Your Instant Quote & Download Proof of Coverage In Minutes
Colonial Surety Company:
- In business since 1930
- Rated “A” Excellent by A.M. Best Company
- US Treasury Listed
Helpful Resources
Frequently Asked Questions (FAQs)