The Coverage Memo

Fiduciary Liability Insurance for Startup 401k Plans

Startup founders face personal liability for retirement plan decisions the moment they sign.

Features Editor · · 12 min read
Cover illustration for “Fiduciary Liability Insurance for Startup 401k Plans”
Founder Liability · September 15, 2026 · 12 min read · 2,641 words

The day a startup signs its 401(k) plan document, its founders become fiduciaries under federal law, whether they've read a word of ERISA or not. That means personal liability, not company liability, and it applies regardless of how small the plan is or how new. Most founders learn this from a lawyer after the fact, or worse, from a claim that's already landed on their desk.

Startups are adopting retirement plans earlier now, often within the first two or three years, largely chasing the tax credits covered later in this piece. What most of them miss is how wide ERISA casts the word "fiduciary." Anyone who exercises discretionary authority over plan administration or plan assets counts, no title required. The HR lead who signs off on the investment menu is one. So is the CFO who approves plan documents, and so is any founder sitting on a benefits committee deciding which funds employees get to pick from. ERISA makes fiduciaries personally liable to restore losses to the plan when a breach occurs, and personal assets, not just company assets, sit exposed. Bankruptcy protection may not even shield someone from that liability in a bad enough outcome.

Founders assume hiring a recordkeeper or third-party administrator moves this risk off their plate entirely. It does not, and this is the misconception that causes the most damage. A company can hire out the tasks of running a plan. It cannot hire out the underlying legal duty to pick and monitor whoever it hired to do them.

The specific roles that carry fiduciary responsibility inside a startup plan

The plan sponsor, meaning the employer itself and not any outside vendor, holds the baseline duty of setting up and running the plan under ERISA's rules. That job doesn't belong to the recordkeeper or the payroll provider. It belongs to the company, full stop.

Below the sponsor sit the people who actually make the calls: 401(k) committee members pulled from HR, finance, or leadership. When they pick which funds go on the menu, or decide which vendor runs the plan, they act as fiduciaries, bound to serve participants' interests rather than the company's convenience.

Then there's the 3(16) Plan Administrator role, and this is where most small business owners trip. Unless a professional 3(16) firm is formally engaged, someone inside the company holds that role. The recordkeeper handles a lot of the paperwork, but it doesn't take on the fiduciary designation unless a contract says so in writing. A company can hire a professional 3(16) firm to absorb much of that burden, but the duty to prudently pick and monitor that firm never leaves the plan sponsor. Hiring help narrows the exposure. It doesn't close it.

A related role, the 3(38) investment manager, takes direct discretionary control over investment decisions instead of just advising on them: picking, monitoring, and trading the fund lineup itself. A 3(38) must be a qualified investment professional and has to acknowledge fiduciary status in writing before taking the role on. Handing investment decisions to a 3(38) cuts the sponsor's exposure on that one function, but the duty to monitor whoever holds the role never goes away.

A case documented by the law firm Golan Christie Taglia makes the stakes concrete. A CFO named Dave appointed a friend as investment adviser after a short phone call and a look at a promotional brochure, skipping any real due diligence. The investment collapsed. The ERISA fidelity bond reimbursed the plan for its loss, but the bond's insurer then went after Dave personally through subrogation, arguing he'd picked the adviser carelessly and failed to monitor the arrangement afterward. His personal liability wasn't covered by the bond, wasn't covered by the company's fidelity coverage, wasn't covered by D&O, and wasn't covered by employment practices liability insurance. He was on his own, which was the whole point of this story.

What the ERISA litigation landscape actually looks like for small and mid-sized plans

Plaintiffs' firms filed 155 fiduciary class action lawsuits in 2025, a pace near record highs, and defined contribution plans, the 401(k) structure most startups run, showed up in 63% of them.

Excessive fee claims made up 94 of those filings, the highest count since 2020. These suits argue a plan's investment options or administrative fees cost more than a prudent fiduciary would have allowed, and they hit small and mid-sized plans just as often as large corporate ones now. Plan forfeiture litigation is the one to watch: it sat at just 5 cases in 2023, and by the first ten months of 2025 that number had climbed to 43, with more than 30 of those settling for an average north of $3 million. A claim type that barely existed two years ago is now a live, growing threat, and it belongs in every founder's risk calculation, not just the history books.

For a startup, the exposure shows up in a handful of recognizable forms. Excessive fees on investment options top the list, especially for founders who take whatever default fund lineup their provider hands them without checking it themselves. Enrollment errors and late or missed contribution remittances come next, often because payroll and plan systems don't talk to each other cleanly. Stale investment lineups, fund menus nobody's revisited in years despite high expense ratios or weak performance, create their own exposure. So do improper benefit denials and a failure to monitor whichever outside vendor the company hired to run the plan.

None of this requires the underlying claim to have merit. Defense costs start piling up the moment a complaint lands on the company's desk, win or lose.

Watch what's coming next: private equity is moving into defined contribution plans, with major asset managers exploring target-date fund structures built around private equity allocations. As these more complex investment structures work into 401(k) menus, plan sponsors adopting them will face monitoring obligations that look nothing like reviewing a simple index fund lineup. That's where fiduciary risk is headed next for growth-stage companies chasing more sophisticated plan design.

Diagram: Plan Forfeiture Litigation: From Fringe to Front-Line Threat. Visualizes: Visualize the explosive growth of plan forfeiture litigation as a concrete magnitude contrast across three data points: 5 cases in 2023, 43 cases in the first ten…

What fiduciary liability insurance actually covers, and what it does not

Fiduciary liability insurance pays for legal defense, settlements, and judgments tied to claims of retirement or health plan mismanagement. It protects both the company and the personal assets of whoever gets named in a suit, which is exactly the gap the Dave story exposes.

Coverage usually responds to administrative mistakes: failing to enroll an eligible employee, miscalculating a benefit, remitting contributions late or incorrectly. It responds to imprudent or poorly diversified investment choices, to bad advice or disclosure given to participants about their options, and to wrongful benefit denials that trace back to an administrative slip rather than intentional misconduct. It also covers conflicts of interest, prohibited transactions, and failures to follow the plan document or ERISA's duties of prudence and loyalty.

Newer policy forms go further. Many now pick up the cost of fixing errors through a federal agency's voluntary compliance programs, cover defense costs tied to regulatory investigations, and extend to penalties for inadvertent HIPAA or ACA violations. Some also cover claims brought by nonfiduciary parties or plan settlors.

What the coverage won't touch matters just as much. Fraud, criminal acts, and intentional wrongdoing sit outside every fiduciary liability policy, as does a deliberate failure to fund the plan. Claims known before the policy's effective date are excluded, along with bodily injury or property damage claims, which belong to other lines entirely. Errors made by outside vendors or advisors fall on those parties' own errors-and-omissions or fiduciary policies, not the sponsor's. Employment claims like wrongful termination or discrimination sit under EPLI, not here.

Fiduciary liability insurance exists for good-faith mistakes, exactly the category of risk a startup runs into constantly while managing a retirement plan for the first time with no in-house ERISA expertise to lean on.

The three coverages that confuse startup founders, and why each is necessary

Three separate policies get confused for one another constantly, and the confusion is exactly what creates the gaps.

The ERISA fidelity bond is legally required, full stop. It protects plan participants against losses from fraud or dishonesty committed by anyone who handles plan funds. ERISA sets the minimum at 10% of plan assets, capped at $500,000, or up to $1,000,000 for plans holding employer securities. Go back to Dave: the bond reimbursed the plan's $200,000 loss, which sounds like the story ends there. It doesn't. The bond's insurer turned around and pursued Dave personally through subrogation, because the bond exists to protect participants' money, not to protect the fiduciary who mishandled the decision. It doesn't cover good-faith errors, imprudent judgment calls, or ordinary administrative mistakes. Only fraud and dishonesty.

D&O insurance covers officers and directors acting in their corporate capacity, and it typically carries an explicit exclusion for claims arising from ERISA violations. That exclusion exists because fiduciary decisions get made in a fiduciary capacity, legally distinct from a corporate governance capacity, even when the same person wears both hats on the same afternoon. The two policies are built for different roles, and they don't overlap the way founders often assume they do.

Fiduciary liability insurance is the piece that fills what's left over. It's not legally required the way the bond is, but it sits in the gap between the bond, which covers theft, and D&O, which covers corporate governance, addressing good-faith errors in plan administration and fiduciary breaches that neither of the other two touches.

None of the three substitutes for another. A startup running a 401(k) needs all three doing their separate jobs at once, and treating any one of them as redundant is exactly how a gap like Dave's opens up again.

One detail matters more than founders tend to assume: there's no standard policy form for fiduciary liability coverage across the industry, so every proposal needs a careful read and a side-by-side comparison, especially around whether the coverage stands alone or gets bundled as an endorsement inside a broader management liability package. Bundled coverage often shares a single aggregate limit with D&O and EPLI, which means a large employment claim can burn through the shared pool before a fiduciary claim even gets addressed. Confirming whether limits are separate or shared isn't a minor line-item question. It decides whether the coverage is real or just theoretical.

Diagram: Three Policies, Three Separate Jobs — None Substitutes for Another. Visualizes: Show the three distinct insurance layers every startup 401(k) plan requires, illustrating what each covers and — critically — what it leaves exposed.

How to think about how much coverage a startup actually needs

There's no ERISA-mandated minimum for fiduciary liability insurance, unlike the bond. Plan asset value is the most common starting point for sizing coverage, though it works better as a benchmark than a formula, and treating it as the only input is how founders end up underinsured.

Guidance from Vouch suggests starting around $1 million for smaller plans and scaling up toward $5 million for plans exceeding $50 million in assets, with plan asset value serving as the primary benchmark. Policies typically sell in $1 million increments, which keeps the sizing conversation fairly concrete.

Plan asset value is only one input, though. Participant count matters just as much: a plan with 50 participants carries a meaningfully different exposure than one with 10, since every added participant is a potential claimant. Plan complexity adds another layer, since a single 401(k) is a simpler risk than a company running a 401(k) alongside an equity plan and a health plan, each with its own compliance obligations. Company growth trajectory matters too. Coverage that looks adequate at 15 employees can fall short at 80, so limits deserve a fresh look whenever headcount or plan assets grow materially. Underwriters also weigh governance and compliance practices directly: documentation quality, whether the company runs regular plan audits, whether committee members get any fiduciary training, and stronger practices there can translate into lower premiums. Industry plays a role too, since financial services, healthcare, and life sciences draw more ERISA scrutiny than sectors like software or marketing.

The forfeiture litigation trend belongs in this sizing conversation too. Going from 5 cases in 2023 to 43 in the first ten months of 2025 is a substantial jump. It's a new claim category appearing almost from nothing, and coverage decisions should account for where litigation is heading rather than where it's been. The same logic applies to private equity's move into defined contribution plans: as sponsors add these more complex options, emerging private equity target-date structures being one example, monitoring obligations rise, and underwriting scrutiny will likely rise right along with them.

What SECURE 2.0 changed and the compliance deadlines that create new fiduciary exposure right now

The SECURE 2.0 Act of 2022 is a major reason so many startups are adopting 401(k) plans in the first place. It built a tax credit structure generous enough to change the math for a small company weighing whether a retirement plan is worth the administrative lift.

New plans can claim up to $5,000 a year in startup tax credits for the first three years. Adding automatic enrollment adds another $500 annually. Employers can also claim up to $1,000 per employee per year in contribution credits during the first two years, a benefit that phases out over five years depending on company size. Businesses with 50 or fewer employees can qualify for a credit covering 100% of administrative costs. Stack it all together for a Safe Harbor plan with automatic enrollment, and a company can generate up to $16,500 in credits across three years.

These incentives are working, and that's exactly the problem: Cerulli projects the number of 401(k) plans will top a million by the end of the decade, a 36% increase, which translates directly into more first-time plan sponsors acting as first-time fiduciaries with no prior experience to draw on.

SECURE 2.0 also mandates automatic enrollment for new 401(k) and 403(b) plans starting in 2025. The initial default deferral rate has to fall between 3% and 10%, with automatic annual escalation of 1% until it reaches at least 10%, capped at 15%. Plans with fewer than 10 employees are exempt.

A hard deadline sits just ahead: most 401(k) plans must formally adopt SECURE 2.0 provisions through a written plan amendment by December 31, 2026. Missing that date is a mistake that creates real compliance exposure and warrants prompt attention.

State-level mandates are stacking more pressure on top of the federal picture. California now requires employers with at least one employee to offer retirement savings options, with penalties of $250 per employee after 90 days of noncompliance and an added $500 per employee after 180 days. Colorado, Illinois, Oregon, Maryland, and Virginia have all passed similar state mandates.

Every new rule SECURE 2.0 introduces, the automatic enrollment default, the escalation schedule, the amendment deadline, is another step a startup fiduciary can get wrong while acting in good faith. Good-faith error is exactly the category fiduciary liability insurance was built to cover.

How to get the right coverage in place when launching a plan

Buy fiduciary liability insurance the same day the plan launches, not after the first compliance review flags a gap. Claims can trace back to day-one administrative decisions, and policies exclude anything known before the effective date, so waiting even a quarter can leave early missteps uninsured.

Confirm the policy stands on its own, with a dedicated limit rather than a shared aggregate buried inside a broader management liability package alongside D&O and EPLI. A large employment claim should never be able to eat through the pool before a fiduciary claim gets its turn.

Make sure the ERISA fidelity bond sits alongside the fiduciary policy and is sized right under the federal formula: 10% of plan assets, up to $500,000, or up to $1 million if the plan holds company stock. The bond and the fiduciary policy aren't redundant. They're two different tools solving two different problems, and a startup running a 401(k) needs both in place before the first payroll contribution ever lands in a participant's account.

Sources

  1. Vouch: Understanding Fiduciary Liability Insurance
  2. Why fiduciary liability insurance is necessary as PE enters the 401(k) space
  3. Do You Need Fiduciary Liability Insurance? « Golan Christie Taglia LLP
  4. paychex.com
  5. planadviser.com
  6. 401kspecialistmag.com

More in Founder Liability