What Is a DOL Compliance Assistance Release for a 401(k) Plan?
A DOL Compliance Assistance Release is guidance about how EBSA expects regulated parties or its own investigators to approach an ERISA issue. It can clarify, warn, standardize investigations or rescind an earlier position. It does not become a regulation or exemption merely because the guidance materially changes enforcement risk.
Before you read this
- What Is an ERISA Fiduciary?Prerequisite
- What Is a DOL FAQ for a 401(k) Plan?Builds on
- What Is a 401(k) Employer Match?Builds on
- What Is a Summary Plan Description (SPD)?Builds on
- What Is a 401(k) Fee Disclosure?Builds on
- What Is an ERISA Fiduciary?Builds on
- What Is an ERISA Prohibited Transaction?Builds on
A Compliance Assistance Release can materially change how EBSA describes an ERISA issue or approaches compliance without changing ERISA itself. The clearest example is cryptocurrency: DOL used a 2022 release to tell 401(k) fiduciaries to exercise “extreme care” and announced an investigative program, then used a 2025 release to rescind that guidance in full and restore ordinary, neutral fiduciary analysis.[1][2][3][14]
That history explains the document better than a generic definition.
This guidance format can:
- explain an investigative approach
- clarify the scope of existing guidance
- communicate an enforcement concern
- identify practices EBSA expects to examine
- rescind a prior agency position.[1][2][4][7]
It is still guidance.
The controlling legal question remains:
What does current ERISA require?
The compliance-release question is different:
What is EBSA currently telling plans, service providers or its investigators about that requirement?
Which CARs Are Currently Listed by DOL?
EBSA maintains a separate Compliance Assistance Releases collection.[1]
The current index includes four especially instructive releases:
- 2021-01 — Terminated Vested Participants Project investigations for defined benefit plans[1][7]
- 2022-01 — cryptocurrency in 401(k) plans, now expressly rescinded[1][3]
- 2024-01 — cybersecurity guidance update[1][4]
- 2025-01 — rescission of the 2022 cryptocurrency release.[1][2]
Those documents do not perform one uniform function.
That is the first important insight.
The title Compliance Assistance Release identifies the guidance series.
The operative text identifies what the particular document actually does.
Does a CAR Carry the Force of Law?
Not merely because it carries that title.
CAR 2021-01 states expressly that its contents:
do not have the force and effect of law
and are intended to provide clarity about existing legal requirements or agency policies.[7]
That sentence is unusually useful because it describes the proper hierarchy.
A CAR can be important evidence of:
- DOL's current interpretation
- EBSA's investigation priorities
- expected compliance practices
- agency enforcement posture.
But it does not become:
- statutory text
- a Code of Federal Regulations provision
- a prohibited-transaction exemption
- a private adjudication.
A 401(k) file should therefore cite the underlying authority as well as the release.
Why Can Guidance Matter So Much If It Is Not a Regulation?
Because enforcement risk is real.
Suppose EBSA tells fiduciaries that a particular practice will receive heightened investigative attention.
The statute did not change.
The practical risk did.
A plan may now expect:
- targeted document requests
- questions about process
- requests for committee minutes
- service-provider records
- correction discussions.
The 2022 crypto release illustrates that effect directly.[3]
It announced an investigative program aimed at plans offering cryptocurrency and related products and told fiduciaries responsible for such options—or allowing crypto through brokerage windows—to expect questions about prudence and loyalty.[3]
That was not a new ERISA section.
It was still a consequential enforcement signal.
What Happened to DOL's 2022 Cryptocurrency Release?
DOL rescinded it in full on:
The rescinded release had instructed plan fiduciaries to exercise:
“extreme care”
before adding a cryptocurrency option to a 401(k) menu.[3]
It also identified concerns involving:
- volatility
- participant understanding
- custody and recordkeeping
- valuation
- evolving regulation.[3]
The 2025 release did not merely soften the wording.
It rescinded the 2022 guidance in full.[2]
That is a current-status fact every 401(k) crypto article should get right.
Why Did DOL Reject the “Extreme Care” Standard?
CAR 2025-01 states that the phrase:
is not found in ERISA
and differs from ordinary fiduciary principles under the statute.[2]
DOL said its historical practice had generally been neutral toward particular investment types and strategies.[2]
The 2025 release returned to that approach.
Under the current release, DOL neither:
- endorses
- nor disapproves
of a fiduciary simply because the fiduciary concludes cryptocurrency belongs in a plan's investment menu.[2]
The decision instead depends on:
all relevant facts and circumstances.[2]
That is a much cleaner Section 404 framework.
Does the 2025 Release Mean DOL Approves Cryptocurrency in 401(k)s?
No.
Neutral is not approval.
The 2025 release removes an asset-class-specific agency thumb on the scale.[2]
That neutral stance does not say:
- Bitcoin is prudent
- digital assets are suitable for every plan
- volatility no longer matters
- custody no longer matters
- valuation no longer matters
- participants can evaluate the risk without fiduciary oversight.
ERISA Section 404 still requires a fiduciary to act prudently and loyally for participants and beneficiaries.[9]
The investment analysis remains context-specific.[2]
That can produce different answers for different products and plans.
What Does Neutral Fiduciary Analysis Look Like?
Consider two investments both described broadly as:
digital asset exposure.
Option A
A diversified professionally managed asset-allocation vehicle:
- 3% digital-asset exposure
- daily institutional valuation
- audited custody
- broad diversification
- established liquidity controls
- transparent fees.
Option B
A single-token direct investment option:
- 100% token exposure
- high volatility
- concentrated platform custody
- weak valuation controls
- limited operational history.
A neutral asset-class policy does not require the committee to treat those products as equivalent.
Neutrality applies to the legal starting point.
Prudence applies to the actual facts.
The fiduciary can reject Option B without claiming:
“crypto is per se prohibited.”
It can also consider Option A without claiming:
“DOL approved crypto.”
That is the distinction the 2025 release restores.[2]
What Happened to the 2022 Crypto Investigative Program?
The 2022 release expressly announced an investigative program aimed at plans offering cryptocurrency and related products.[3]
Because the 2025 rescission withdrew that guidance in full, the 2022 release should not be presented as current DOL enforcement policy.[2]
A 2026 compliance memo should not say:
“DOL currently says every plan with crypto should expect a special crypto investigation.”
That statement relies on rescinded guidance.
This does not mean EBSA cannot investigate a plan that holds cryptocurrency.
EBSA can investigate fiduciary conduct under ERISA.
The difference is important:
ordinary enforcement authority remains; the special 2022 crypto posture does not remain as current guidance.
Does the Rescission Erase Historical Liability?
Do not make that leap.
Rescission tells us the 2022 release no longer represents current DOL guidance.[2]
That action does not, by itself, decide:
- whether a 2022 investment decision was prudent on its facts
- whether a historical fiduciary breach occurred
- whether an investigation was procedurally valid
- whether a participant claim exists
- how a court should evaluate historical conduct.
Those are separate legal questions.
The safe current statement is narrower:
do not use the 2022 release as today's DOL crypto standard.
Does Participant Choice Eliminate the Fiduciary Issue?
No.
A participant-directed plan does not convert menu construction into a nonfiduciary act.
ERISA Section 404 and DOL's investment rules still require prudence in fiduciary investment decisions.[9][10]
A committee cannot say:
“Participants chose it, so we did not need to evaluate it.”
That is especially clear for designated investment alternatives selected for the plan menu.
The participant chooses among options.
The fiduciary decides which options are made available.
Those are different decisions.
What About Cryptocurrency Available Only Through a Brokerage Window?
This is a separate governance question.
The rescinded 2022 release expressly mentioned crypto accessible through brokerage windows.[3]
The 2025 rescission removes that special crypto enforcement message.[2]
Nothing in the rescission establishes that a plan has zero fiduciary responsibility for:
- selecting the brokerage-window provider
- negotiating fees
- cybersecurity
- disclosures
- feature design
- contractual controls
- ongoing monitoring.
INV-135 addresses the brokerage-window boundary in detail.
A useful distinction is:
monitoring each participant-selected security
versus:
prudently governing the brokerage feature and provider.
Those questions should not be collapsed.
How Does DOL's 2026 Alternative-Investment Proposal Fit?
On March 30, 2026, DOL proposed a new regulation addressing fiduciary duties in selecting designated investment alternatives, including vehicles containing alternative assets.[11][12]
The proposal reflects a neutral asset-type premise.
Its draft language would make clear that ERISA's prudence rule does not require or prohibit any particular category of designated investment alternative merely because of the asset type.[11]
The proposal also discusses process-based safe harbors and factors such as:
That policy direction is consistent with the 2025 CAR's return to neutral fiduciary analysis.[2][11]
But the rule remains:
A proposal cannot be cited as though it already amended 29 CFR Part 2550.
Why Is the Proposed Rule an Important Update Trigger?
Because it could eventually turn part of today's policy direction into formal regulatory text.
If DOL finalizes the proposal, a future version of this article should compare:
- final text
- effective date
- available safe harbors
- treatment of alternative assets
- interaction with existing Section 404 rules
- whether the final rule changes the practical relevance of CAR 2025-01.
Until then:
current ERISA + current CFR + current CAR 2025-01
remain distinct from:
proposed 2026 rule.
What Does CAR 2024-01 Do?
The 2024 CAR addresses cybersecurity.[4]
Its purpose is narrow and important.
EBSA had issued cybersecurity guidance in April 2021.
Some health and welfare plan service providers later argued that the guidance applied only to retirement plans.[4]
The 2024 release clarified that the cybersecurity guidance generally applies to:
all ERISA plans
including:
- employee pension benefit plans
- health plans
- welfare plans.[4]
For a 401(k), the practical effect is confirmation, not expansion into a new retirement-plan rule.
401(k)s were already within the intended cybersecurity framework.
Did CAR 2024-01 Create a New Cybersecurity Fiduciary Duty?
No.
The release points fiduciaries back to ERISA responsibilities involving prudent plan administration and service-provider oversight.[4][9]
Current DOL cybersecurity materials say responsible plan fiduciaries have an obligation to ensure appropriate mitigation of cybersecurity risk.[5]
The release clarifies the reach of the agency's guidance.
It does not add a new numbered fiduciary duty to Section 404.
That is another recurring Compliance Assistance Release pattern:
existing duty first; agency guidance second.
What Cybersecurity Practices Does DOL Currently Emphasize?
DOL's current Cybersecurity Program Best Practices identifies twelve major areas.[5]
They include:
- formal documented cybersecurity program
- prudent annual risk assessments
- reliable annual independent audit of security controls
- clearly assigned information-security roles
- strong access controls
- security review of cloud and third-party assets/data
- periodic cybersecurity awareness training
- secure system-development lifecycle
- business continuity, disaster recovery and incident response
- encryption for sensitive data at rest and in transit
- strong technical controls
- appropriate response to past incidents.[5]
That list is useful because it makes vague cybersecurity oversight measurable.
A committee can ask:
What evidence do we have for each area?
Is Every Cybersecurity Best Practice a Separate ERISA Violation Test?
Do not treat the guidance that mechanically.
The statutory standard is prudence under the circumstances.[9]
DOL's cybersecurity materials help fiduciaries understand what robust current practice can look like.[5]
They are strong evidence of agency expectations.
But an audit should not automatically conclude:
“One missing bullet equals one statutory breach.”
The analysis should consider:
- risk
- plan size
- systems
- data
- provider structure
- controls
- compensating safeguards
- current threat environment.
The guidance sharpens the process.
It does not eliminate judgment.
How Can a 401(k) Committee Use the Cybersecurity Guidance?
Use it as a due-diligence framework.
For a recordkeeper, ask for evidence concerning:
- information-security framework
- independent audit reports
- penetration testing
- breach history
- insurance
- MFA
- privileged access
- encryption
- incident response
- subcontractors
- data destruction
- business continuity.[5][6]
Then document:
- what the provider supplied
- weaknesses identified
- remediation commitments
- contract protections
- monitoring frequency.
The practical standard is not:
“Vendor says it is secure.”
It is:
“The fiduciary had a reasoned basis to select and retain this provider given the actual controls and risks.”[6][13]
What Contract Terms Does DOL Emphasize for Cybersecurity?
DOL's service-provider tips recommend attention to provisions addressing:[6]
- ongoing compliance with information-security standards
- access to audit results
- confidentiality and permitted use of data
- cybersecurity incident notification
- cooperation with investigations
- compliance with privacy and security laws
- insurance coverage.
These terms matter because cybersecurity is partly a vendor-governance problem.
A perfect committee policy cannot compensate for a contract that gives the plan:
- no breach notice
- no audit information
- no control over subcontractors
- no meaningful cooperation after an incident.
The provider relationship is part of the fiduciary process.[6][13]
What Does CAR 2021-01 Reveal About the Format?
It shows that this guidance format can be directed primarily at:
EBSA investigators.[7]
The release is a memorandum to Regional Directors concerning the:
Terminated Vested Participants Project
for traditional defined benefit pension arrangements.[7]
Its purpose is to promote consistent:
- investigation processes
- case-closing practices
- voluntary compliance efforts.[7]
That is materially different from the 2025 cryptocurrency rescission.
Same document series.
Different function.
Is CAR 2021-01 a 401(k) Missing-Participant Rule?
No.
The release's stated subject is:
defined benefit plans.[7]
That detail should not be blurred merely because 401(k)s also have missing-participant problems.
DOL simultaneously issued broader:
Missing Participants — Best Practices for Pension Plans
which applies to defined benefit and defined contribution plans, including 401(k)s.[8]
The two documents work together but are not identical.
For a 401(k), the best-practices document is the more direct operational source.
For understanding EBSA's investigative method, CAR 2021-01 remains highly instructive.[7][8]
What Missing-Participant Red Flags Did EBSA Identify?
CAR 2021-01 describes problems that can signal systemic weakness.[7]
Examples include:
- missing names or dates of birth
- incomplete Social Security numbers
- placeholder dates such as 1/1/1900
- placeholder names
- returned mail
- uncashed checks
- large numbers of retirement-age participants who have not claimed benefits
- continued mailing to known bad addresses
- failure to use available search resources
- poor monitoring of outside search vendors.[7]
Those examples are defined-benefit investigation guidance.
The underlying data-quality lesson transfers readily to defined contribution administration.
A participant cannot receive a 401(k) benefit if the plan cannot:
- identify the person
- locate the person
- reconstruct the account
- prove the benefit due.
What Does the 2021 Release Say About EBSA Investigations?
The release describes the kinds of records investigators may seek, including:[7]
- plan documents
- participant census data
- actuarial/demographic information
- participant communications
- search procedures
- recordkeeper contracts
- third-party search arrangements.
It also says investigations are case-specific.[7]
That is important.
The document is not a closed checklist that guarantees no investigation if every listed item exists.
It is a window into the agency's questions.
For compliance teams, that is valuable because it allows a reverse audit:
Could we produce credible answers to the same questions before EBSA asks them?
What Does “Voluntary Compliance” Mean in CAR 2021-01?
The release describes a case-closing approach that encourages plans to correct identified problems.[7]
When EBSA finds systemic errors, investigators are instructed to discuss remedies with responsible fiduciaries.[7]
The agency can seek:
- locating affected participants
- paying benefits
- correcting records
- improving communications
- improving search policies.[7]
Where fiduciaries provide appropriate remedies and correct process failures, the release describes case-closing practices that can recognize those corrective steps without necessarily citing each individual fiduciary for a specific violation, absent more serious circumstances.[7]
That does not create immunity.
It shows how compliance assistance and enforcement can operate together.
Why Does the No-Force-of-Law Disclaimer Matter?
CAR 2021-01 ends with an explicit statement that the document:[7]
- does not itself carry legal force
- is not meant to bind the public
- is intended to clarify existing requirements or agency policies.
That is the right mental model for the whole CAR series.
A release can tell you a great deal about:
- agency expectations
- investigative priorities
- policy
- interpretation.
The legal obligation still comes from the authority the release is explaining.
How Does a CAR Compare With a Field Assistance Bulletin?
The boundary is not perfectly rigid.
INV-176 covers FABs.
A Field Assistance Bulletin is often issued by the Office of Regulations and Interpretations to enforcement leadership in response to field questions.[1]
CAR 2021-01 is also a memorandum to Regional Directors and deals directly with investigation and case closing.[7]
So do not invent a false bright line.
A better distinction is practical:
- FAB — a long-used field-guidance format often addressing interpretation or enforcement treatment
- CAR — a compliance-assistance series EBSA has used for investigative protocols, clarifications, investment guidance and rescissions.[1][7]
In either case, read the actual document.
The title alone does not determine legal effect.
How Does a CAR Compare With a Technical Release?
INV-177 covers Technical Releases.
Technical Releases have been used for:
- substantive legal interpretation
- transition enforcement
- implementation guidance
- requests for comment.
CARs likewise can span more than one function.
The difference is less important than the hierarchy:
statute/regulation/exemption first → agency guidance second.
If the documents overlap, determine:
- which is newer
- which directly addresses the issue
- whether one rescinds or supersedes another
- whether later rulemaking changed the law.
Do not assume one guidance label automatically outranks the other.
Why Is an Advisory Opinion a Different Instrument?
A Procedure 76-1 advisory opinion applies ERISA to specific facts presented by identified parties.[1]
INV-175 explains its party-specific reliance structure.
A CAR is not that process.
CAR 2025-01 does not say:
“Plan X may prudently offer Bitcoin.”
It states DOL's broader current policy toward the asset category.[2]
That is why another plan can read the release as agency guidance but cannot treat it as a private approval letter.
Why Can a CAR Not Substitute for a PTE?
A PTE changes the prohibited-transaction result when:
- transaction falls within scope
- every condition is satisfied.
A CAR does not itself provide that exemptive relief.
Suppose a crypto product involves:
- affiliated compensation
- fiduciary self-dealing
- principal transaction.
CAR 2025-01's neutral approach does not cure the conflict.
The plan still needs to analyze:
- Section 406
- statutory exemptions
- class exemptions
- individual relief where necessary.
Investment-type neutrality and prohibited-transaction legality are separate questions.
Does a CAR Control Private Litigation?
Not automatically.
A current release can be relevant agency guidance.
It can materially affect how EBSA investigates or describes its legal position.
A private ERISA case is decided under:
- statute
- valid regulations
- controlling judicial precedent
- plan documents
- evidence.
That distinction is especially important with enforcement-oriented guidance.
If EBSA says it will not pursue a particular theory, that does not necessarily mean:
no participant could ever assert a claim.
The legal theory and governing authority still need analysis.
What Does the 2022-to-2025 Crypto Reversal Teach About Guidance Maintenance?
It exposes a weakness in static compliance libraries.
Imagine a committee investment policy adopted in 2023 stating:
“DOL requires extreme care before considering cryptocurrency.”
The committee never updates the policy.
By 2026, the sentence is stale because DOL expressly rescinded the source.[2]
A good legal-content system should track:
- source date
- status
- rescinded-by
- superseded-by
- review trigger.
This is not editorial housekeeping.
It is legal accuracy.
How Should a Committee Preserve Rescinded Guidance?
Keep it for history if it helps explain past decisions.
Do not use it as current authority.
A clean file might say:
2022 decision record: committee considered then-current CAR 2022-01.
2025 update: DOL rescinded CAR 2022-01 in full through CAR 2025-01.
current policy: committee applies ordinary context-specific Section 404 analysis without a special crypto standard.[2][3][9]
That preserves chronology without pretending the old release never existed.
How Should a Committee Document a Crypto Decision Today?
Use the same disciplined process you would apply to another unusual investment.
For example:
Product structure
- direct token
- fund
- ETF
- managed allocation
- collective vehicle
- brokerage-window access.
Economics
- fees
- spreads
- custody costs
- expected return
- volatility
- liquidity.
Operations
- custody
- valuation
- trading
- recordkeeping
- reconciliation
- cyber controls.
Portfolio role
- diversification
- concentration
- correlation
- participant behavior
- rebalancing.
Legal structure
- securities/commodities treatment
- prohibited transactions
- service-provider compensation
- plan documents.
The 2025 release removes a special agency presumption.[2]
The need for analysis remains.
How Should a Committee Document Cybersecurity Oversight?
Start with DOL's current cybersecurity materials.[4][5][6]
Then convert them into evidence.
A useful annual file can include:
- risk assessment
- independent security-control report
- penetration-test summary
- open remediation items
- MFA/access-control metrics
- material incidents
- subcontractor changes
- insurance review
- incident-response test
- contract compliance
- data-retention review.
The goal is not to prove:
“We copied DOL's checklist.”
It is to prove:
“We understood the risk, obtained credible evidence, challenged weaknesses and monitored the provider.”
That is a fiduciary process.[5][6][9]
What Should a Neutral Crypto Review Actually Test?
A neutral standard is demanding because it removes the shortcut of treating the asset label as the answer.
A committee considering digital-asset exposure should build a record around the actual investment vehicle rather than the word:
crypto.
One useful review has six parts.
1. Investment thesis
Document what role the option is supposed to play.
Possible rationales include:
- diversification
- long-term return exposure
- participant demand
- access to a developing asset class.
A rationale such as:
“Participants asked for it”
is incomplete. Participant interest can explain why the committee studied the product. It does not establish prudence.
2. Vehicle quality
The fiduciary should distinguish direct ownership from a regulated fund, managed portfolio or other wrapper.
Ask about:
- custody structure
- valuation source
- audit
- liquidity
- counterparty exposure
- trading mechanics
- operational controls.
Two products with the same underlying token exposure can present very different plan risks.
3. Portfolio consequences
Evaluate how the option behaves in the menu as a whole.
A committee can model participant outcomes at allocations such as:
- 1%
- 5%
- 20%
- 50%.
The point is not to impose one universal cap.
It is to understand whether participant behavior could create concentration or volatility that the plan design makes unusually easy to assume.
4. Cost
Measure more than the stated expense ratio.
Potential economics include:
- fund fee
- custody charge
- trading spread
- platform fee
- redemption cost
- advisory compensation.
A product with a moderate headline fee can still be expensive once the full structure is mapped.
5. Participant communication
The committee should consider whether ordinary disclosure allows a reasonable participant to understand:
- what the investment owns
- how its value is determined
- key risks
- fees
- liquidity limitations.
Good disclosure does not cure an imprudent option.
Poor disclosure can make a difficult product harder to defend.
6. Monitoring
The initial decision is not the end of the process.[9][13]
Monitoring can track:
- performance against stated purpose
- volatility
- fees
- custody changes
- provider financial condition
- regulatory developments
- participant concentration
- operational incidents.
The 2025 rescission therefore removes an asset-specific presumption, not the fiduciary workflow.[2]
What Does a Policy Reversal Require From the Committee?
A major DOL reversal should trigger more than a citation update.
Suppose an investment policy adopted in 2023 says:
“Cryptocurrency is presumptively unsuitable because DOL requires extreme care.”
After CAR 2025-01, the committee should decide whether that policy still expresses its own investment judgment or merely repeats rescinded agency language.[2][3]
Three outcomes are possible.
Keep the restriction for independent reasons
The committee may conclude that direct digital assets remain inconsistent with the plan because of:
- participant demographics
- product quality
- operational limits
- fees
- volatility
- administrative burden.
That can be a legitimate fiduciary conclusion if the record supports it.
Modify the restriction
The committee might distinguish:
- direct token options
- diversified funds
- brokerage-window access
- professionally managed allocation funds.
That is often more analytically useful than one blanket category.
Remove the restriction
The committee may determine the old provision existed only because of the rescinded 2022 release.
Removing it does not require adding crypto.
It simply restores the investment policy to a neutral review standard.
The important point is ownership of the decision.
The committee should not outsource its policy first to a 2022 CAR and then to a 2025 CAR.
Agency guidance informs the process.
The fiduciary still decides under current ERISA.[9]
What Makes Cybersecurity Monitoring Evidence Credible?
Cybersecurity oversight is easy to document badly because committees often receive technical material they cannot meaningfully evaluate.
A thick SOC report is not automatically a prudent monitoring process.
A better record shows how the committee converted technical evidence into governance decisions.
For example:
| Evidence | Weak response | Stronger fiduciary response |
|---|---|---|
| Third-party audit finds high-risk access-control exception | File the report | Ask for remediation owner, due date and closure evidence |
| Provider had recent breach | Note that it happened | Review cause, affected plan data, control changes and notification performance |
| MFA is unavailable for one privileged system | Accept vendor explanation | Determine compensating control and timeline for stronger authentication |
| Penetration test finds critical issue | Accept verbal assurance | Obtain written remediation and retest result |
| Cyber insurance renewed | Check box | Review limits, exclusions, retention and whether plan-related events are covered |
DOL's current guidance gives fiduciaries a strong list of practices to interrogate.[5][6]
The committee's value comes from:
- asking what the evidence means
- escalating material weaknesses
- following remediation
- deciding whether the provider should still be retained.
That is the difference between collecting cybersecurity paperwork and monitoring cybersecurity risk.
Why Do Mergers and Acquisitions Matter to Missing-Participant Risk?
CAR 2021-01 notes that mergers, acquisitions and company-name changes can create participant-record problems.[7]
The risk is easy to underestimate.
A successor plan can inherit:
- old payroll identifiers
- disconnected HR systems
- stale beneficiary data
- duplicate participants
- incomplete vesting history
- returned mail tied to a predecessor name.
A former employee who worked for:
OldCo
may ignore a letter from:
NewHoldings Benefits Trust
because the person does not recognize the sender.
A strong transaction-integration process should therefore test more than whether assets transferred correctly.
It should reconcile:
- participant census
- addresses
- employment status
- beneficiary records
- uncashed checks
- outstanding distributions
- predecessor plan names
- data-retention obligations.
For 401(k) sponsors, the broader 2021 best-practices guidance makes the lesson direct: accurate census data, repeated communication and documented search procedures are core defenses against missing-participant problems.[8]
The acquisition closing date should not become the date historical participant data disappears.
How Should a Plan Read Any New Compliance Assistance Release?
Use a disciplined sequence.
1. Identify the underlying legal rule
What statute, regulation or exemption is the release discussing?
2. Identify the audience
Plan fiduciaries?
Service providers?
Regional Directors?
Everyone covered by ERISA?
3. Find the operative action
Is DOL:
- warning
- clarifying
- instructing investigators
- describing correction
- rescinding earlier guidance?
4. Extract exact scope
Which plans?
Which investments?
Which fiduciary acts?
5. Check current status
Does the DOL index mark it:
- rescinded
- superseded
- revised?
6. Check later law
Has Congress acted?
Has DOL finalized a regulation?
Has a court changed the legal premise?
7. Separate enforcement from substantive legality
What does the release say EBSA will do?
What does ERISA itself require?
Those questions can overlap without being identical.
The ROIStreet Compliance Assistance Release Test
Find the CAR in DOL's current index → identify whether it is current, rescinded or replaced → identify the underlying ERISA provision or regulatory issue → identify the release's audience → classify its function: investigation / clarification / enforcement messaging / rescission → extract exact operative language → distinguish agency policy from statutory duty → check later regulations, exemptions and cases → compare actual plan facts with the guidance → document independent fiduciary analysis → calendar the next review trigger
The useful question is not:
“Is there a CAR on this topic?”
It is:
“What does the current release actually change about DOL's stated interpretation or enforcement posture, what legal obligations remain underneath it, and has anything later made the release stale?”
Frequently Asked Questions
What is a DOL Compliance Assistance Release?
It is an EBSA guidance format used to communicate compliance, investigation, clarification or enforcement information. The current series includes releases addressing missing-participant investigations, cybersecurity and cryptocurrency.[1]
Is a CAR a regulation?
No. CAR 2021-01 expressly says the memorandum is nonbinding guidance intended to clarify existing requirements or agency policies.[7]
Is every Compliance Assistance Release an enforcement safe harbor?
No. The current releases perform different functions.[1][2][4][7]
What did CAR 2025-01 change?
The May 28, 2025 DOL release that rescinded the 2022 cryptocurrency guidance in full and restored DOL's neutral approach toward investment types.[2][14]
Is “extreme care” still DOL's current crypto standard?
No. The 2025 release says that standard is not found in ERISA and rescinded the release that used it.[2]
Does DOL now endorse crypto for 401(k)s?
No. The 2025 release expressly restores a neutral position that neither endorses nor disapproves of a fiduciary conclusion merely because the investment is cryptocurrency.[2]
What standard applies instead?
Ordinary ERISA fiduciary principles, including context-specific prudence and loyalty based on all relevant facts and circumstances.[2][9]
Is CAR 2022-01 still online?
Yes, but DOL marks it as rescinded by CAR 2025-01.[1][3]
Can I still cite CAR 2022-01 as current DOL policy?
No. It can be cited as historical guidance, but not as the Department's current crypto position after full rescission.[2][3]
Did the rescission invalidate every historical crypto investigation?
The release does not make that broad determination. Historical liability and investigation issues depend on the law and facts applicable to the period involved.
What about crypto in a brokerage window?
The special 2022 crypto investigative language was rescinded, but ordinary fiduciary duties concerning the brokerage feature, service provider, fees, cybersecurity and plan administration remain separate questions.[2][3][13]
Is DOL's 2026 alternative-investment rule final?
No. The March 2026 designated-investment-alternative rule remains a proposal as of August 30, 2026.[11][12]
Why is that proposal relevant?
Its neutral treatment of investment categories is consistent with the policy direction reflected in CAR 2025-01, but proposed regulatory text is not current final law.[2][11]
What does CAR 2024-01 clarify?
A cybersecurity guidance update confirming that EBSA's existing cybersecurity guidance applies to all ERISA plans, including pension, health and welfare plans.[4]
Did CAR 2024-01 create a new cybersecurity statute?
No. It clarifies the scope of DOL guidance; the fiduciary duty remains grounded in ERISA.[4][9]
What cybersecurity practices does DOL emphasize?
Among other controls: a formal cybersecurity program, annual risk assessment, independent audit, access controls, third-party oversight, training, secure development, resiliency, encryption, strong technical controls and incident response.[5]
What should a plan ask a recordkeeper about cybersecurity?
DOL recommends reviewing security standards, independent validation, breach history, insurance, audit rights, confidentiality, incident notification and related contract protections.[6]
What does CAR 2021-01 address?
An EBSA memorandum establishing consistent investigation and case-closing practices for the Terminated Vested Participants Project involving the defined benefit TVPP population.[7]
Does CAR 2021-01 directly govern 401(k) missing-participant audits?
Its stated TVPP scope is defined benefit plans. DOL's companion missing-participant best-practices guidance expressly reaches defined contribution plans such as 401(k)s.[7][8]
Why is CAR 2021-01 still useful to a 401(k) committee?
It provides a detailed view of the records, red flags, search practices and corrective approach EBSA uses when examining missing-participant problems.[7]
Does a CAR give party-specific reliance like an advisory opinion?
No. Procedure 76-1 advisory opinions have a separate reliance framework for identified parties and facts. A CAR is broader agency guidance.
Can a CAR create a prohibited-transaction exemption?
No. Exemptive relief requires applicable statutory or administrative exemption authority.
How do CARs and Field Assistance Bulletins differ?
Both can address enforcement and interpretation, and their functions can overlap. A FAB is a long-used field-guidance format; CARs are a separate compliance-assistance series. The actual operative text matters more than the label.[1][7]
How do CARs and Technical Releases differ?
Technical Releases are another DOL guidance format and can serve interpretive, transition, enforcement or proposal functions. Neither label automatically outranks the other; current authority and document status control.
Can a favorable CAR prove fiduciary prudence?
No. Section 404 prudence and loyalty still depend on the plan's actual facts, process and decision.[9][13]
What is the most important check before citing a CAR?
Confirm its current status on DOL's site. CAR 2022-01 demonstrates why: it remains publicly available but is expressly marked rescinded.[1][2][3]
Sources & References
- U.S. Department of Labor — Employee Benefits Security Administration: Compliance Assistance Releases — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/compliance-assistance-releases
- U.S. Department of Labor — Employee Benefits Security Administration: Compliance Assistance Release 2025-01 — 401(k) Plan Investments in Cryptocurrencies — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/compliance-assistance-releases/2025-01
- U.S. Department of Labor — Employee Benefits Security Administration: Compliance Assistance Release 2022-01 — 401(k) Plan Investments in Cryptocurrencies — Rescinded — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/compliance-assistance-releases/2022-01
- U.S. Department of Labor — Employee Benefits Security Administration: Compliance Assistance Release 2024-01 — Cybersecurity Guidance Update — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/compliance-assistance-releases/2024-01
- U.S. Department of Labor — Employee Benefits Security Administration: Cybersecurity Program Best Practices — https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/best-practices
- U.S. Department of Labor — Employee Benefits Security Administration: Tips for Hiring a Service Provider with Strong Cybersecurity Practices — https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/tips-for-hiring-a-service-provider-with-strong-security-practices
- U.S. Department of Labor — Employee Benefits Security Administration: Compliance Assistance Release 2021-01 — Terminated Vested Participants Project — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/compliance-assistance-releases/2021-01
- U.S. Department of Labor — Employee Benefits Security Administration: Missing Participants — Best Practices for Pension Plans — https://www.dol.gov/agencies/ebsa/employers-and-advisers/plan-administration-and-compliance/retirement/missing-participants-guidance/best-practices-for-pension-plans
- Legal Information Institute / U.S. Code: 29 U.S.C. §1104 — Fiduciary Duties — https://www.law.cornell.edu/uscode/text/29/1104
- Electronic Code of Federal Regulations / Legal Information Institute: 29 CFR §2550.404a-1 — Investment Duties — https://www.law.cornell.edu/cfr/text/29/2550.404a-1
- U.S. Department of Labor — Employee Benefits Security Administration: Fiduciary Duties in Selecting Designated Investment Alternatives — Proposed Rule — https://www.dol.gov/sites/dolgov/files/ebsa/laws-and-regulations/laws/erisa/fiduciary-duties-in-selecting-designated-investment-alternatives.pdf
- U.S. Department of Labor: DOL Proposes Rule on Alternative Investments in 401(k) Plans — March 30, 2026 — https://www.dol.gov/newsroom/releases/ebsa/ebsa20260330
- U.S. Department of Labor — Employee Benefits Security Administration: Meeting Your Fiduciary Responsibilities — https://www.dol.gov/agencies/ebsa/about-ebsa/our-activities/resource-center/publications/meeting-your-fiduciary-responsibilities
- U.S. Department of Labor: DOL Rescinds 2022 Cryptocurrency Guidance — May 28, 2025 — https://www.dol.gov/newsroom/releases/ebsa/ebsa20250528
Educational Disclaimer
ROIStreet publishes educational content about 401(k) fiduciary duties, plan administration and Department of Labor guidance. This article is not legal, fiduciary, tax, investment, cybersecurity, regulatory or plan-administration advice. Compliance Assistance Releases can be revised, rescinded, superseded or affected by later statutes, regulations, court decisions and other DOL guidance. A release may describe EBSA's investigative or enforcement position without changing the underlying legal duty or the rights of other parties. Cryptocurrency, alternative investments, cybersecurity and missing-participant issues are fact-specific. Current primary authority and the current status of any cited guidance should be checked before a plan relies on it.
The ROIStreet Reader Promise
We strive to explain before we evaluate, present evidence before opinions, discuss risks alongside potential benefits, distinguish facts from analysis, and correct material errors transparently.
Our purpose is to help readers better understand investing—not to tell them what to do.
Definitions used in this guide
- Risk
- Investment risk is the uncertainty surrounding future investment outcomes, including the possibility of losing income, purchasing power, liquidity, or some or all of the capital invested.
- Return
- Investment return is the gain or loss produced by an investment over a period, including changes in value and applicable income such as interest, dividends or distributions.
- Liquidity
- Liquidity describes how readily an investment can be converted to cash without substantial delay, transaction cost or adverse price impact. Liquidity can change with market conditions.
- Volatility
- Volatility describes the magnitude and frequency of price changes over time. It is an important measure of market uncertainty, but it does not capture every form of investment risk.
We may earn a commission if you open an account through links on this page. Our editorial analysis is independent and is never influenced by commercial partnerships. Full disclosure.
