You've done the fiduciary training. You've reviewed the investment menu. You've filed Form 5500 on time. You're compliant, right?
Not so fast. The risk most sponsors overlook sits inside the plan itself, and it has nothing to do with stock funds or fee disclosures. It is the claims adjudication system, the software that decides what gets paid and what gets denied thousands of times a day. Most plan sponsors never once audit its logic.
Those automated decisions carry fiduciary weight. ERISA section 404(a)(1)(D) requires you to administer the plan “in accordance with the documents and instruments governing the plan.” If your system's code silently contradicts your plan document, every claim processed that way is a potential breach. You own that risk, and a service agreement that labels your TPA a non-fiduciary doesn't move it off your books.
The gap no one talks about
Most plan sponsors treat their third-party administrator like a utility. You pay them to process claims. They send reports. Everyone moves on. Meanwhile, the typical TPA agreement casts the administrator as a service provider rather than a fiduciary. That label carries less weight than most sponsors assume: ERISA fiduciary status turns on the TPA's actual authority and control over plan money, regardless of the words in the contract. You provide the plan document. The tool is supposed to follow the document. What if it doesn't?
Take a plan document that says physical therapy is covered at 80% after a $500 deductible. The system's configuration applies 70% because of an old data mapping error. That mistake can run for months, even years, and cost the plan tens of thousands. The plan sponsor is the one who carries the loss.
Three system risks that keep me up at night
1. The repricing engine that bleeds money
Your self-funded plan uses a PPO network to get discounts. But the repricing engine in most TPA systems applies a hierarchy: first contracted rate, then a percentage of billed charges, then a “usual and customary” fallback. If that fallback is set to the 50th percentile instead of the 80th, every out-of-network claim is overpaid by a few percentage points. It doesn't sound like much, but over 10,000 claims, it adds up to real dollars. And it's on you to validate the trigger hierarchy in that code.
2. Auto-adjudication defaults that rewrite your plan
Most TPA systems auto-pay claims below a set dollar amount without human review, applying benefit rules from configuration tables rather than from your plan document. If a deductible, coinsurance, or network tier was entered wrong at implementation, the system pays or denies at the wrong level on every claim in that category until someone catches it. That configuration change is an unauthorized plan amendment, and ERISA allows amendments only through the plan's formal amendment procedure. If a participant is denied because the system applied a rule your plan document never contains, you're on the hook.
3. The subrogation latency gap
Your plan has a subrogation clause. When a third party settles a liability claim, the plan should recoup what it paid out. How often does your system run that matching check? Quarterly? Annually? A 90-day gap between a settlement and a recoupment means the plan leaves recoverable dollars uncollected, and some recoveries get missed entirely. Collecting plan assets is a core fiduciary duty, and a recoupment system that runs months behind makes that duty hard to meet.
What you should audit right now
Stop auditing your TPA's processes and audit the system's data instead. The three requests below are the first step, and they are documents. The real audit runs a sample of paid and denied claims against your plan document to see whether the system did what the document says. Ask for these this week:
- The adjudication rule stack: a single-page document showing the order of claim payment operations, from eligibility and coordination of benefits to network discount and medical necessity flag. If your TPA can't provide it, that's a red flag.
- The outlier threshold table: the dollar amount at which a claim is automatically flagged for manual review. Many systems ship with a default set well into five figures, so a claim has to get large before a human sees it. You have a duty to set that threshold based on your plan's actual risk profile.
- The reason code reconciliation: a report of the top five denial reason codes used by the system that are not explicitly described in your Summary Plan Description. If the system denies claims for “missing prior authorization” but your SPD requires prior auth only for inpatient procedures, the system is overwriting your plan language.
A radical but practical solution
A small number of sophisticated plan sponsors go further and name a “systems fiduciary”, a named fiduciary under ERISA section 402(a)(1) who is explicitly responsible for the integrity of the claims adjudication algorithm. The role belongs to someone who understands both ERISA law and database logic, not to the investment advisor or the HR director. That person ensures the system's code matches the plan document exactly and that any discrepancy is corrected within a defined window.
It sounds radical, but the law is already moving this way. In May 2025, the Sixth Circuit revived a plan sponsor's suit against Blue Cross Blue Shield of Michigan, holding that the plan plausibly alleged the TPA acted as an ERISA fiduciary when “flip logic” in its claims processing system systematically overpaid out-of-state claims. Courts now look past the plan document to how the claims system operates.
Delegation and the duty to monitor
Some sponsors respond to this by pointing at the service agreement: the TPA runs the claims system, so the TPA owns the mistakes. ERISA doesn't work that way. When a named fiduciary appoints another person to perform plan functions, the appointing fiduciary keeps a duty to monitor that person's performance. The Department of Labor described this continuing duty in Interpretive Bulletin 75-8. A quarterly report nobody reads doesn't satisfy it. The audit is the monitoring.
Your next step
This week, ask your TPA this exact question: “Show me the last time a system logic error caused an incorrect claim payment or denial that took more than 90 days to correct.” If they can't produce a documented answer, you have found the gap.
Run the audit on your own terms now, or explain the gap later in a claim dispute where the standard is no longer your choice.
This article is for general information only and is not legal, tax, or medical advice. Employers should consult their own advisors.
Contact