A little more than three years ago, the U.S. Department of Labor (DOL) posted cybersecurity guidance on its website for ERISA plan fiduciaries. That guidance extended only to ERISA-covered retirement plans, despite health and welfare plans facing similar risks to participant data.

Last Friday, the DOL’s Employee Benefits Security Administration (EBSA) issued Compliance Assistance Release

As discussed in an earlier blog post, the SECURE 2.0 Act of 2022 (the Act) expanded the Employee Plans Compliance Resolution System (EPCRS), a comprehensive IRS program for correcting common qualified retirement plan failures.  Plan sponsors have three ways to correct mistakes under EPCRS: the self-correction program (SCP), the voluntary correction program

The United States Department of Labor (the “DOL”) recently issued a proposed rule on the fiduciary requirements under the federal pension law, ERISA, that apply to the selection and monitoring of environmental, social, and corporate governance (“ESG”) investments in retirement plans.  Under the proposed rule, which would be effective 60 days after it becomes finalized,