- Compliance with TPA Policies – The TPA should commit to comply with its own cybersecurity policies and agree not to materially degrade the level of security reflected in those policies during the term of the contract. Plan sponsors and/or plan administrators should request copies (or at least summaries) of the TPA’s policies and have their internal IT security personnel review them from a due diligence perspective.
- Compliance with Applicable Law – The TPA should commit to comply with all U.S. and foreign data security and privacy laws applicable to the TPA’s services.
- Compliance with Industry Standards – The TPA should commit to meet industry standards relating to data security. For example, the International Organization for Standardization (ISO), which is an international standard-setting body, publishes information security standards codified in ISO 27001 / 27002. It would be reasonable to require that the TPA agree to comply with these standards and maintain ISO 27001 certification.
- Security Audits – The TPA should commit to have a nationally recognized independent third party conduct annual (or more frequent) audits or reviews of the TPA’s cybersecurity practices at facilities used to deliver the services and provide a copy (or at least a summary) of the audit report to the plan sponsor. One of the more common types of audit reports furnished by service providers is a SOC 2, Type II report under Attestation Standards Section 101 published by the American Institute of Certified Public Accountants. The SOC 2, Type II audit addresses the operating effectiveness of the TPA’s controls relating to security, availability, processing integrity, confidentiality and privacy.
Benefits Think Negotiating cybersecurity contractual protections for retirement plans
Hutchings is a partner in Pillsbury's Global Sourcing group, represents clients in complex sourcing transactions.
Lutrin is an associate in Pillsbury's Executive Compensation & Benefits practice and is located in the New York office.
Serota leads Pillsbury's Executive Compensation & Benefits practice and is located the New York and Washington, DC offices.