Oversight and Monitoring
A plan fiduciary’s oversight responsibilities do not end when the contracts are signed. Action should be taken to assess whether service providers are adhering to the agreed-upon practices for data privacy and security. In addition, agreed-upon practices should be reviewed and updated from time to time in light of the shifting and evolving threats to ensure that the service provider is keeping current with reasonable security practices.