• What is the track record of the service provider? What are its resources?
• How will the service provider use the personal information?
• Where will the personal information be stored and processed?
• Does the service provider itself intend to use subcontractors, including its affiliates, and where are they located?
• What security does the service provider apply to personal information?
• Will the service provider provide the security that the plan fiduciary requires based on its own obligations?
• What reporting does the service provider provide?
• What auditing is done (i.e., Service Organization Controls (SOC) 1 and SOC 2 reports)?