Payroll is most organizations’ single largest recurring disbursement — and the one with the best natural camouflage. Every payment looks legitimate because almost every payment is: same run, same rhythm, thousands of deposits that have cleared without incident for years. That rhythm is exactly what a ghost employee, a quietly inflated rate, or a terminated employee still drawing pay hides inside. The ACFE’s 2024 Report to the Nations puts the median occupational fraud at $145,000 and a median 12 months before detection — and payroll schemes are among the most durable, because the payment machine re-commits the theft every two weeks without anyone touching it again.
This is the third flagship in our How to Audit series — after accounts payable and journal entries — and the program behind the clean payroll report we modeled in our annotated report library. The full treatment: how hire-to-pay actually works and where its trust boundaries sit, the risk map, a starter RCM, a 12-test program with the ghost-employee analytic at its center, and the findings that recur.
This guide was rewritten in September 2026 to add what the August version left out: how to size and sequence the engagement, MidState Beverage’s payroll audit test by test (the control-side complement of the analytics run in the payroll analytics catalog), how to test an outsourced payroll’s boundary controls against the provider’s SOC 1 report, and the links to the templates that carry the work. The risk map, the starter matrix, the twelve-test program and the analytics are unchanged. The ACFE’s Occupational Fraud 2026 report updates the economics quoted below: 2,402 cases, a median loss of 104,000 dollars, and a median of twelve months before detection, with payroll schemes still among the most durable because the payment machine repeats them every cycle.
In this guide
- Know the terrain: hire-to-pay and the two-masters problem
- The payroll risk map
- The starter RCM: eight controls that carry the process
- Sizing and sequencing the engagement
- The 12-test program
- The analytics: ghosts, leavers, and outliers
- Worked example: MidState Beverage’s payroll audit
- The findings that recur — and wording that lands
- Scoping variants: outsourced payroll, small shops, executives
- Outsourced payroll: the boundary, and the four controls that stay yours
- Where to go next
Know the terrain: hire-to-pay and the two-masters problem
The flow is simple to draw: hire → employee master setup → time capture (for non-exempt) → gross-to-net calculation → review and release → disbursement → termination and removal. The audit-relevant structure sits underneath: payroll serves two masters. HR owns who exists, what they earn, and when they leave; payroll operations owns turning that into money on time. Every classic payroll failure lives at their seam — the hire HR processed that payroll double-keyed wrong, the termination HR closed that never reached the payroll master, the comp change that arrived by email instead of through the system. In planning, map exactly which fields flow automatically between the HR system and the payroll engine and which are re-keyed by hand: the re-keyed fields are your audit, because automation carries data faithfully and humans carry it approximately.
The second structural fact is the trust boundary. Payroll teams are small, tenured, and trusted — which is precisely the profile that makes segregation matter more, not less. The person who can create an employee record, and the person who can change a bank account, and the person who can release the payment run must be different people (or the difference must be manufactured with monitoring); in a three-person payroll team that trio of capabilities frequently collapses into one login. Ask for the access model before the walkthrough and read it with the same eyes you would read AP’s vendor-create/payment-release conflict — it is the same fraud, wearing an HR badge.
The payroll risk map
| # | Risk | Where it lives | Error or fraud? |
|---|---|---|---|
| R1 | Ghost employees — pay flowing to a person who does not work here (never existed, or never left the file) | Master setup + termination | Fraud |
| R2 | Terminated employees paid past separation | Termination interface | Error that ages into fraud |
| R3 | Unauthorized compensation changes — rates, salaries, allowances edited without approval | Master maintenance | Both |
| R4 | Bank-account redirection — pay rerouted to an account that is not the employee’s | Master maintenance / self-service takeover | Fraud (BEC’s payroll cousin) |
| R5 | Time and overtime inflation — hours padded, OT self-served, buddy punching | Time capture + approval | Both |
| R6 | Off-cycle and manual payment abuse — the run outside the run | Off-cycle process | Both |
| R7 | Executive payroll bypass — senior comp handled outside normal controls “for confidentiality” | Exec payroll handling | Governance gap |
| R8 | Segregation failures — one login can create, change, and pay | Access model | Enabler of R1–R6 |
| R9 | Deduction, garnishment, and tax errors — wrong withholding, missed garnishment, misapplied benefits | Gross-to-net engine | Error (compliance exposure) |
| R10 | Accrual and cutoff — bonus, PTO, and payroll accruals misstated | Close process | Error (or earnings management) |
Prioritize like the money does: R1, R2, and R4 are the catastrophic-embarrassment risks and are all testable with full-population analytics in a week; R5 is where the recurring leakage lives; R7 is the one nobody scopes and everyone should — the audit that “couldn’t look at executive payroll” has already written its own quality-assessment finding.
The starter RCM: eight controls that carry the process
| Ctrl | Control (condensed) | Type / frequency | Answers risk |
|---|---|---|---|
| C1 | Master-data changes (new hire, rate, bank, status) require system-routed approval independent of the requestor, evidenced against source documents | Preventive / each change | R1, R3, R4 |
| C2 | Automated HR-to-payroll interface for hires and terminations; interface exceptions worked from a queue within SLA | Preventive-detective / each event | R1, R2 |
| C3 | Bank-detail changes verified with the employee via an independent channel; self-service changes trigger out-of-band confirmation and a hold on the next deposit change | Preventive / each change | R4 |
| C4 | Time approved by the employee’s manager before processing; no self-approval; delegation logged | Preventive / each cycle | R5 |
| C5 | Payroll-run variance review: period-over-period movement above threshold at cost-center and employee level investigated and dispositioned before release | Detective / each run | R1–R6 |
| C6 | Off-cycle payments individually justified and approved at elevated level; volume trended | Preventive / each payment | R6 |
| C7 | SoD ruleset: master-maintenance, time-approval, and run-release mutually exclusive; conflicts monitored | Preventive / continuous | R8 |
| C8 | Payroll bank reconciliation and GL tie-out, timely, with aged-item escalation; accruals reviewed at close | Detective / monthly | R9, R10 |
As with the AP starter matrix, load this into our free RCM Workbench and reshape it to the walkthrough — in a mature HRIS, C1–C3 are workflow configuration you evidence once; in a re-keying shop, they are people you sample. (For the field-by-field craft of building the matrix itself, our RCM template guide has six fully worked rows — three of them from this exact process.)
Sizing and sequencing the engagement
Payroll audits are cheaper than payables audits and more sensitive, because the data is personal and the process is run by a small trusted team who will read the report. The budget below is MidState’s, for about 1,400 employees on an outsourced platform with twelve sites keeping their own time; a single-site salaried workforce needs perhaps half the hours, and a first engagement with no analytics run behind it adds sixty to eighty hours to the analytics line. Two features of the sequence matter more than the total: the data handling arrangement is agreed with HR and counsel before any extract is taken (pseudonymised at extraction, with HR holding the key, and destroyed after the run), and the full-population analytics run before any sample is drawn, so that the samples go where the humans re-key and approve rather than where the payment machine does its faithful work.
| Phase | Hours | What happens | What it produces |
|---|---|---|---|
| Planning and data handling | 30 | Scope agreed including executive payroll; handling arrangement for personal data signed; extracts specified (provider register, HR master, time data, bank files, AP payments to employees); provider SOC 1 obtained | Planning memo; data agreement; population record |
| Walkthrough and matrix refresh | 20 | One hire, one rate change, one termination, one off-cycle payment walked through HR, the provider platform and the bank; re-keyed fields listed; prior-year matrix reconciled | Refreshed RCM; the re-keyed-field list that becomes the sample frame |
| Analytics (or corroboration of an existing run) | 40 to 120 | Ghost, leaver, rate, overtime, off-cycle and cross-file families run or, where the function already runs them, their hits triaged with the analytics auditor | Corroborated hits; judgmental selections |
| Master data, bank changes and compensation | 50 | Tests 3 to 5: authorisation of changes, bank-detail verification, rates to source | The master-data findings, usually the highest rated |
| Time, overtime and off-cycle | 50 | Tests 6 to 8: approvals, outliers followed into time records, the off-cycle population in full | Leakage figures; approval findings |
| Executive payroll, access, run release and reconciliations | 50 | Tests 9 to 12, including the SOC 1 and complementary user control review for an outsourced platform | Governance and boundary-control conclusions |
| Reporting and validation | 40 | Findings in five-Cs form; management responses; issue log; audit committee summary; any referral handed off under the protocol | Report; issue log entries |
| Total | 280 to 360 | Senior auditor 160, analytics auditor 80 to 160, manager 40 |
The 12-test program
Sample sizes follow the standard attribute parameters (derivation in our sample-size guide; seeded selection via mySampler). Tests marked ▲ are full-population analytics — run them first; their hits become judgmental selections.
- ▲ Ghost-employee sweep. The centerpiece — full employee master against independent existence evidence (details in the analytics section below). Every hit dispositioned in writing.
- ▲ Terminated-still-paid. HR termination file (from HR’s system, not payroll’s) joined to post-termination payments. Any pay after final-pay date beyond documented severance is an exception — and test the interface exception queue (C2) while you are there.
- Master-change authorization. Sample 25 changes across types (hires, rate changes, status). Attributes: source document exists and matches; approver independent and authorized; change effective-dated correctly. Weight the sample toward rate changes — that is where money moves quietly.
- Bank-detail changes. All changes in period if volume permits, else 25. Attributes: verification through an independent channel, before the next run; self-service changes carry out-of-band confirmation. The control’s absence is a High finding on the spot — payroll redirection fraud is an active, current threat.
- Compensation to source. Sample 25 employees; agree system rate/salary to the authorized comp document (offer letter, merit letter, contract). This catches both R3 and the re-keying seam.
- Time and overtime approval. Sample 25 timecards from non-exempt population. Attributes: manager approval precedes processing; hours agree to schedule/badge where available; no self-approval via delegation.
- ▲ Overtime outliers. Full-year OT by employee and cost center: top earners, employees whose OT exceeds a share of base, cost centers where OT concentrates in one approver’s team. Follow the top decile into time records.
- Off-cycle payments. All of them (the population is usually small). Attributes: documented justification, elevated approval, regularized in the next run, volume trend flat or explained.
- Executive payroll. The bypass test: walk exactly how executive comp is processed, who can see it, who approves changes, and whether the same C1–C5 disciplines exist in the confidential channel. Confidentiality justifies restricted visibility — never absent control. Sample the year’s executive comp changes to committee-approved sources.
- SoD and access. Pull actual access: who holds master-maintenance with run-release, or time-approval for their own team while processing payroll? For each conflict, test the monitoring that supposedly compensates.
- Run review and release. Sample 10 cycles: variance review performed and dispositioned (C5), totals reconciled to bank file, release under dual control, post-approval changes re-approved.
- Reconciliation and accruals. All 12 monthly recs plus the year-end bonus/PTO accrual: timely, reviewed, aged items escalated, accrual methodology consistent — documented to the standard of our model workpaper.
The analytics: ghosts, leavers, and outliers
| Analytic | Logic | What a hit means |
|---|---|---|
| Ghost-employee existence match | Employee master vs. independent life-signs: HR status, badge swipes, network logins, benefits enrollment, time entries. Flag paid employees with zero activity across all signals in 60–90 days | Ghost, long-leave data gap, or a field population problem — all three worth knowing |
| Shared bank accounts | Same deposit account across multiple employee records; employee accounts matching vendor-master accounts | Ghost cluster, household edge case, or vendor-employee collusion |
| Shared addresses / contact details | Duplicate addresses, phones, emergency contacts across unrelated employees | Ghost tell; also catches the supervisor whose “employees” all live at his address |
| Post-termination payment scan | Payments dated after final-pay date, netted for severance schedules | Interface failure aging into loss |
| OT distribution | Z-scores by employee within cost center; share-of-base ratios; approver concentration | Inflation, buddy-approval, or a genuinely understaffed team — the follow-up tells you which |
| Rate-change velocity | Employees with multiple rate changes in-year; changes effective-dated backward; round-percentage clusters outside merit cycles | Unauthorized raises; retro manipulation |
| Off-cycle trend | Off-cycle count and dollars by month and by requestor | Discipline decay — a rising line is a finding by itself |
| Net-pay outliers | Net pay vs. peer band for grade and location | The blunt catch-all that finds what the elegant tests miss |
Same disciplines as always: prove population completeness first (payroll register to GL to bank file), and disposition every hit in writing — the ghost analytic in our model payroll report earned its credibility by reporting 14 initial exceptions and clearing all 14, not by pretending the first pass came back empty.
Worked example: MidState Beverage’s payroll audit
MidState Beverage is the three-state drinks distributor used across this site: about 1,400 employees, 300 of them drivers paid on route-based hours, twelve depots with their own timekeeping practices, two acquired distributors recently migrated onto the platform, payroll processed by a cloud provider whose SOC 1 Type 2 report covers 1 October to 30 September, and a six-person internal audit function with no compliance function beside it. The analytics auditor’s first run of the catalog, on fourteen months of provider extracts and 37,800 pay records reconciled to the ledger within 900 dollars and to the bank files exactly, is written up in the payroll analytics catalog; the payroll audit that followed tested the controls the hits pointed at, and the two engagements together produced the eight findings. The table gives the twelve tests as they ran.
| Test | Population and sample | What it found | Where it went |
|---|---|---|---|
| 1. Ghost-employee sweep | Full master against HR status, route settlement activity, badge and network signals | 168 raw hits triaged to nine: six shared bank accounts, five of them married couples and one a driver paid into a depot clerk’s account for four periods as a stopgap for a lost card, reversed; 22 thin-profile seasonal hires all confirmed present at depots; no fabricated records. | Control failure on the shared-account stopgap; no ghost finding |
| 2. Terminated-still-paid | HR termination file joined to payments | Eleven employees paid after termination, 19,400 dollars, all from terminations the depots reported to HR between eight and thirty days late; nine recovered. Three termination-and-rehire cycles at one depot used to reset probation. | Finding, High: depot termination reporting; fix in the route settlement system that locks a driver’s route on the termination date |
| 3. Master-change authorisation | 25 changes weighted to rate changes | Seventeen rate changes in the period were entered and approved by the same HR administrator under a workflow that allowed it. | Finding, High: segregation in the HR workflow |
| 4. Bank-detail changes | All 71 changes in the period | Two changes made by a payroll user two days before payday and reversed after, corroborated as a diverted pay run of 4,100 dollars, recovered from a former payroll clerk; the verification control that should have caught it did not operate for changes made by payroll staff themselves. | Referred under the protocol and recovered; finding on the verification control’s scope |
| 5. Compensation to source | 25 employees | Six above-band rates, all with approved exceptions on file; two re-keyed rates differing from the offer letter by transposition, both in the employee’s favour. | Observation; corrected |
| 6. Time and overtime approval | 25 timecards from the driver population | Approval preceded processing in 23; two approved after the run by delegation. | Combined with test 7 |
| 7. Overtime outliers | Full year by employee and cost centre | Four drivers at two depots recorded hours implying more than fifteen hours a day for eleven consecutive periods, approved by a supervisor who was the brother-in-law of two of them. | Referred, then finding, High |
| 8. Off-cycle payments | All 210 in the period | Concentrated in the two acquired distributors’ first months on the platform and explained by migration errors; separately, 40 payments to employees made through accounts payable coded as awards, 31,000 dollars, bypassing withholding. | Finding, Medium: tax compliance and the AP channel |
| 9. Executive payroll | The confidential channel walked; the year’s changes sampled | Executive compensation processed by the HR director and the CFO on the same platform with restricted visibility; changes traced to board-approved sources; no bypass of the controls. | No finding; confidentiality implemented as restricted visibility, the right way |
| 10. Segregation and access | Actual platform roles | The HR administrator’s combined enter-and-approve rights (test 3); payroll staff able to change their own bank details without the verification step (test 4); provider administrator accounts held by two named MidState users and reviewed quarterly. | Findings above |
| 11. Run review and release | 10 cycles | Variance review performed and dispositioned in all ten; release under dual control; totals reconciled to the bank file. | No finding |
| 12. Reconciliations, accruals and the provider’s SOC 1 | 12 monthly reconciliations; year-end accruals; the SOC 1 Type 2 report and its complementary user controls | Reconciliations timely and reviewed; the SOC 1 report clean, but two of the four complementary user controls it assumes MidState operates (review of the provider’s output register before funding, and quarterly review of platform user access) were not being performed, as the SOC 1 review guide describes. | Finding, Medium: boundary controls |
The report carried eight findings, three High, and an overall rating of Needs Improvement, with two referrals handled under the protocol described in the CFE guide and kept out of the report’s wording. Three things generalise. The most expensive condition, the late termination reporting, was not a payroll control failure at all but a depot process gap, which is why the fix lived in the route settlement system rather than on the payroll platform; payroll audits find their causes upstream. The diverted pay run, the only fraud in the engagement, was small, caught by an analytic rather than by the control designed to catch it, and possible only because the verification control had a hole for the people who ran payroll; the finding was about the hole, not the 4,100 dollars. And the outsourced platform’s clean SOC 1 report was true and irrelevant to the two controls MidState was supposed to operate on its own side of the boundary, which nobody had read the report closely enough to notice.
The findings that recur — and wording that lands
Four findings write most payroll reports. Termination-interface failure (“11 of 214 terminations were not reflected in payroll within one cycle; 4 employees received pay after separation totaling $23,400, of which $9,100 is recovered to date — the exception queue designed to catch interface failures has had no assigned owner since March”). Unverified bank changes (“63 of 71 employee bank-detail changes were made through self-service with no out-of-band confirmation; the configuration to require it exists and is disabled”). Executive bypass (“compensation changes for the 9 executives are processed manually outside the HRIS workflow; 3 of 7 in-period changes had no documented source approval available to payroll — confidentiality has been implemented as absence of control rather than restriction of visibility”). OT approval theater (“the top-decile overtime population shows 84% of approvals logged within 90 seconds of batch submission, concentrated in two supervisors — review is occurring as bulk acknowledgment, not examination”). Each follows the 5 C’s chain: numerators, denominators, named causes, consequences in dollars and exposure-days.
Scoping variants: outsourced payroll, small shops, executives
Outsourced payroll (the majority case): the processor calculates; your organization still owns the inputs and the outputs. Your audit shifts to the boundary controls — master-data authorization before transmission, output variance review before funding, bank-file reconciliation after — plus reliance discipline over the provider: what its SOC 1 actually covers, which complementary user-entity controls it assumes you operate (test those — they are yours), and, from September 2026, the program-level baseline of the IIA’s Third-Party Topical Requirement. Small organizations: SoD collapses, so the owner’s review becomes the control — test that the reviewer receives a complete register (not one filtered by the preparer) and actually engages with it; run the ghost and terminated-pay analytics yourself across everything, because nobody else ever has. Executive payroll is a scoping decision everywhere: put it in scope explicitly, negotiate visibility with the CHRO and audit committee chair if needed — and treat “you can’t look at that” as a governance data point worth reporting in its own right.
Outsourced payroll: the boundary, and the four controls that stay yours
Most organizations no longer run payroll; they run a payroll provider. The calculation engine, the tax tables, the statutory filings and the payment file live with the processor, and the processor’s SOC 1 Type 2 report describes controls over those things. What the report does not describe, except in a section most readers skip, is the set of controls the provider assumes its customers operate on their own side of the line: the complementary user entity controls. Every processor lists them, usually four to eight, and every one of them is a control your organization has in effect signed up to perform. If nobody performs them, the provider’s clean opinion covers a process with a hole in it, and the hole is on your side. The SOC 1 review method walks through how to read a report as a user entity; what follows is the payroll-specific version.
The four controls below appear, in one wording or another, in almost every payroll processor’s report. Treat them as in scope for the audit whether or not the SOC 1 itself is, because they are the controls that decide whether a wrong input becomes a wrong payment.
| Control the SOC 1 assumes you operate | What it stops | How to test it | MidState’s result |
|---|---|---|---|
| Master-data changes (hires, terminations, rate and bank changes) are authorized before transmission to the provider | Unauthorized or fictitious changes flowing straight into the pay run; the provider processes whatever it receives | Sample 25 changes from the provider’s change log, not from HR’s; trace each to an approval that predates transmission and comes from someone other than the person who keyed it | Operated; the exceptions in tests 3 and 4 were holes in the approval rule’s design, not skipped approvals |
| The provider’s pre-funding output register is reviewed against expected totals and variance thresholds before the run is released | A wrong run being funded: a diverted bank account, a doubled rate, a migration error paid to hundreds of people | Obtain the register and the review evidence for 12 periods; confirm the reviewer received the full register, that variances beyond threshold were explained, and that the review predates funding | Not performed; the register arrived every period and nobody was assigned to review it, which is how the diverted run in test 4 reached the bank |
| Provider platform user access is recertified periodically and leavers are removed promptly | Former payroll staff, HR administrators, depot timekeepers and provider support accounts keeping the ability to change data or release runs | Pull the current user list from the provider, not from HR; compare it to the active employee list; walk the last two recertifications and confirm the removals actually happened | Performed only for the two provider administrator accounts; the wider population of HR and depot users had never been recertified |
| Funding and the returned bank file are reconciled to the approved register after each run | Money leaving the bank that differs from what was approved, and rejected or returned payments quietly re-sent to new accounts | Re-perform three reconciliations; trace returned items to their resolution and confirm that re-sent payments went through the bank-change verification control | Operated and timely; returned items were resolved by the payroll clerk alone, noted as an improvement point rather than a finding |
Three further points about the report itself. First, the period. MidState’s provider reports on a year ending 30 September, which left a gap between the end of the reporting period and MidState’s own year-end; a bridge letter from the provider covers the gap for reliance purposes, and where there is no letter the auditor has to decide how much of the year is uncovered and whether that matters for the reliance being placed. Second, subservice organizations. Payroll processors routinely carve out the bank or clearing house that actually moves the money, which leaves the payment leg covered by nobody’s report unless you obtain the subservice provider’s own report or test the payment controls yourself; the payment operations guide covers what to test at the bank interface. Third, exceptions. A clean opinion can sit above a testing section that lists deviations in exactly the controls you rely on; read the testing section, not just the opinion page, and ask the provider what changed as a result.
Since 15 September 2026 this reliance work has had a program-level baseline. The IIA’s Third-Party Topical Requirement sets out what an internal audit function is expected to cover when it assesses how the organization manages its third parties, and a provider that calculates and pays the workforce sits near the top of any criticality ranking. For the payroll audit that means documenting who owns the provider relationship, whether the provider is in the third-party inventory with a risk tier, whether the contract gives audit rights and a right to the SOC 1 report, and whether the complementary user controls are assigned to named owners. The last point is the one that failed at MidState: the controls were listed in a report nobody at the company had read past the opinion page, and assigned to no one. Assigning them was most of the remediation.
Where to go next
Payroll rewards the auditor who respects its rhythm. The process is well run in most organizations, which is exactly why the failures that do exist, the ghost in the master, the leaver still paid, the executive channel with no controls, the redirected deposit, survive for so long. Run the full-population analytics first, put your samples where humans re-key and approve, refuse the executive carve-out, test the four controls the provider’s report assumes you operate, and document to the model-workpaper standard. Then, when the file comes back clean, write the clean report the way Report A in the report library does, showing the work, because a payroll audit that earns its Satisfactory is one of the more reassuring documents a committee reads all year. When it does not come back clean, as MidState’s did not, the first 48 hours protocol keeps the referral out of the audit file and the audit on schedule.
Next in the process series: travel and expense, where the dollars are smaller and the signals are richer, then procurement and the vendor master file, which share a fraud population with payroll and, at MidState, the same twelve depots.
Related guides
- The payroll analytics catalog — all 30 tests with their logic, thresholds and MidState’s first run in full
- How to review a SOC 1 report — the user-entity method behind the four boundary controls above
- The Third-Party Topical Requirement — the baseline for provider oversight in effect since 15 September 2026
- How to audit accounts payable — the sister guide, with the MidState AP run and a 14-test program
- How to audit accounts receivable — the other side of the cash cycle, with Brightwater’s worked example
- How to audit cash management and bank reconciliations — where the pay run meets the bank statement
- How to audit payment operations and wire transfers — the payment leg that most payroll SOC 1 reports carve out
- Segregation of duties beyond the ERP — the framework behind tests 3, 4 and 10
- How to perform a user access review — the recertification MidState was doing for two accounts instead of all of them
- Audit sample sizes demystified — why the program uses 25, 40 and full populations where it does
- The sampling memo template — documenting the selection decisions behind each test
- Annotated workpaper examples — the model testing file the program is documented to
- The fraud red flags library — the payroll cycle’s indicators, organized for triage
- The ACFE fraud tree explained — ghost employees, falsified wages and commission schemes in context
- When internal audit finds fraud: the first 48 hours — the protocol MidState’s two referrals followed
- The 5 C’s of audit findings — how the eight findings were written
- The finding and issue log template — tracking the remediation of boundary controls with named owners
- How to audit travel and expense — the next guide in the process series
- Fieldwork and testing guides and fraud risk guides — the full collections
Leave a Reply