,

How to Audit Payroll: Ghost Employees, Off-Cycle Payments and a Worked Engagement

Payroll is most organizations’ single largest recurring disbursement — and the one with the best natural camouflage. Every payment looks legitimate because almost every payment is: same run, same rhythm, thousands of deposits that have cleared without incident for years. That rhythm is exactly what a ghost employee, a quietly inflated rate, or a terminated employee still drawing pay hides inside. The ACFE’s 2024 Report to the Nations puts the median occupational fraud at $145,000 and a median 12 months before detection — and payroll schemes are among the most durable, because the payment machine re-commits the theft every two weeks without anyone touching it again.

This is the third flagship in our How to Audit series — after accounts payable and journal entries — and the program behind the clean payroll report we modeled in our annotated report library. The full treatment: how hire-to-pay actually works and where its trust boundaries sit, the risk map, a starter RCM, a 12-test program with the ghost-employee analytic at its center, and the findings that recur.

This guide was rewritten in September 2026 to add what the August version left out: how to size and sequence the engagement, MidState Beverage’s payroll audit test by test (the control-side complement of the analytics run in the payroll analytics catalog), how to test an outsourced payroll’s boundary controls against the provider’s SOC 1 report, and the links to the templates that carry the work. The risk map, the starter matrix, the twelve-test program and the analytics are unchanged. The ACFE’s Occupational Fraud 2026 report updates the economics quoted below: 2,402 cases, a median loss of 104,000 dollars, and a median of twelve months before detection, with payroll schemes still among the most durable because the payment machine repeats them every cycle.

In this guide

Know the terrain: hire-to-pay and the two-masters problem

The flow is simple to draw: hire → employee master setup → time capture (for non-exempt) → gross-to-net calculation → review and release → disbursement → termination and removal. The audit-relevant structure sits underneath: payroll serves two masters. HR owns who exists, what they earn, and when they leave; payroll operations owns turning that into money on time. Every classic payroll failure lives at their seam — the hire HR processed that payroll double-keyed wrong, the termination HR closed that never reached the payroll master, the comp change that arrived by email instead of through the system. In planning, map exactly which fields flow automatically between the HR system and the payroll engine and which are re-keyed by hand: the re-keyed fields are your audit, because automation carries data faithfully and humans carry it approximately.

The second structural fact is the trust boundary. Payroll teams are small, tenured, and trusted — which is precisely the profile that makes segregation matter more, not less. The person who can create an employee record, and the person who can change a bank account, and the person who can release the payment run must be different people (or the difference must be manufactured with monitoring); in a three-person payroll team that trio of capabilities frequently collapses into one login. Ask for the access model before the walkthrough and read it with the same eyes you would read AP’s vendor-create/payment-release conflict — it is the same fraud, wearing an HR badge.

The payroll risk map

#RiskWhere it livesError or fraud?
R1Ghost employees — pay flowing to a person who does not work here (never existed, or never left the file)Master setup + terminationFraud
R2Terminated employees paid past separationTermination interfaceError that ages into fraud
R3Unauthorized compensation changes — rates, salaries, allowances edited without approvalMaster maintenanceBoth
R4Bank-account redirection — pay rerouted to an account that is not the employee’sMaster maintenance / self-service takeoverFraud (BEC’s payroll cousin)
R5Time and overtime inflation — hours padded, OT self-served, buddy punchingTime capture + approvalBoth
R6Off-cycle and manual payment abuse — the run outside the runOff-cycle processBoth
R7Executive payroll bypass — senior comp handled outside normal controls “for confidentiality”Exec payroll handlingGovernance gap
R8Segregation failures — one login can create, change, and payAccess modelEnabler of R1–R6
R9Deduction, garnishment, and tax errors — wrong withholding, missed garnishment, misapplied benefitsGross-to-net engineError (compliance exposure)
R10Accrual and cutoff — bonus, PTO, and payroll accruals misstatedClose processError (or earnings management)

Prioritize like the money does: R1, R2, and R4 are the catastrophic-embarrassment risks and are all testable with full-population analytics in a week; R5 is where the recurring leakage lives; R7 is the one nobody scopes and everyone should — the audit that “couldn’t look at executive payroll” has already written its own quality-assessment finding.

The starter RCM: eight controls that carry the process

CtrlControl (condensed)Type / frequencyAnswers risk
C1Master-data changes (new hire, rate, bank, status) require system-routed approval independent of the requestor, evidenced against source documentsPreventive / each changeR1, R3, R4
C2Automated HR-to-payroll interface for hires and terminations; interface exceptions worked from a queue within SLAPreventive-detective / each eventR1, R2
C3Bank-detail changes verified with the employee via an independent channel; self-service changes trigger out-of-band confirmation and a hold on the next deposit changePreventive / each changeR4
C4Time approved by the employee’s manager before processing; no self-approval; delegation loggedPreventive / each cycleR5
C5Payroll-run variance review: period-over-period movement above threshold at cost-center and employee level investigated and dispositioned before releaseDetective / each runR1–R6
C6Off-cycle payments individually justified and approved at elevated level; volume trendedPreventive / each paymentR6
C7SoD ruleset: master-maintenance, time-approval, and run-release mutually exclusive; conflicts monitoredPreventive / continuousR8
C8Payroll bank reconciliation and GL tie-out, timely, with aged-item escalation; accruals reviewed at closeDetective / monthlyR9, R10

As with the AP starter matrix, load this into our free RCM Workbench and reshape it to the walkthrough — in a mature HRIS, C1–C3 are workflow configuration you evidence once; in a re-keying shop, they are people you sample. (For the field-by-field craft of building the matrix itself, our RCM template guide has six fully worked rows — three of them from this exact process.)

Sizing and sequencing the engagement

Payroll audits are cheaper than payables audits and more sensitive, because the data is personal and the process is run by a small trusted team who will read the report. The budget below is MidState’s, for about 1,400 employees on an outsourced platform with twelve sites keeping their own time; a single-site salaried workforce needs perhaps half the hours, and a first engagement with no analytics run behind it adds sixty to eighty hours to the analytics line. Two features of the sequence matter more than the total: the data handling arrangement is agreed with HR and counsel before any extract is taken (pseudonymised at extraction, with HR holding the key, and destroyed after the run), and the full-population analytics run before any sample is drawn, so that the samples go where the humans re-key and approve rather than where the payment machine does its faithful work.

PhaseHoursWhat happensWhat it produces
Planning and data handling30Scope agreed including executive payroll; handling arrangement for personal data signed; extracts specified (provider register, HR master, time data, bank files, AP payments to employees); provider SOC 1 obtainedPlanning memo; data agreement; population record
Walkthrough and matrix refresh20One hire, one rate change, one termination, one off-cycle payment walked through HR, the provider platform and the bank; re-keyed fields listed; prior-year matrix reconciledRefreshed RCM; the re-keyed-field list that becomes the sample frame
Analytics (or corroboration of an existing run)40 to 120Ghost, leaver, rate, overtime, off-cycle and cross-file families run or, where the function already runs them, their hits triaged with the analytics auditorCorroborated hits; judgmental selections
Master data, bank changes and compensation50Tests 3 to 5: authorisation of changes, bank-detail verification, rates to sourceThe master-data findings, usually the highest rated
Time, overtime and off-cycle50Tests 6 to 8: approvals, outliers followed into time records, the off-cycle population in fullLeakage figures; approval findings
Executive payroll, access, run release and reconciliations50Tests 9 to 12, including the SOC 1 and complementary user control review for an outsourced platformGovernance and boundary-control conclusions
Reporting and validation40Findings in five-Cs form; management responses; issue log; audit committee summary; any referral handed off under the protocolReport; issue log entries
Total280 to 360Senior auditor 160, analytics auditor 80 to 160, manager 40

The 12-test program

Sample sizes follow the standard attribute parameters (derivation in our sample-size guide; seeded selection via mySampler). Tests marked ▲ are full-population analytics — run them first; their hits become judgmental selections.

  1. ▲ Ghost-employee sweep. The centerpiece — full employee master against independent existence evidence (details in the analytics section below). Every hit dispositioned in writing.
  2. ▲ Terminated-still-paid. HR termination file (from HR’s system, not payroll’s) joined to post-termination payments. Any pay after final-pay date beyond documented severance is an exception — and test the interface exception queue (C2) while you are there.
  3. Master-change authorization. Sample 25 changes across types (hires, rate changes, status). Attributes: source document exists and matches; approver independent and authorized; change effective-dated correctly. Weight the sample toward rate changes — that is where money moves quietly.
  4. Bank-detail changes. All changes in period if volume permits, else 25. Attributes: verification through an independent channel, before the next run; self-service changes carry out-of-band confirmation. The control’s absence is a High finding on the spot — payroll redirection fraud is an active, current threat.
  5. Compensation to source. Sample 25 employees; agree system rate/salary to the authorized comp document (offer letter, merit letter, contract). This catches both R3 and the re-keying seam.
  6. Time and overtime approval. Sample 25 timecards from non-exempt population. Attributes: manager approval precedes processing; hours agree to schedule/badge where available; no self-approval via delegation.
  7. ▲ Overtime outliers. Full-year OT by employee and cost center: top earners, employees whose OT exceeds a share of base, cost centers where OT concentrates in one approver’s team. Follow the top decile into time records.
  8. Off-cycle payments. All of them (the population is usually small). Attributes: documented justification, elevated approval, regularized in the next run, volume trend flat or explained.
  9. Executive payroll. The bypass test: walk exactly how executive comp is processed, who can see it, who approves changes, and whether the same C1–C5 disciplines exist in the confidential channel. Confidentiality justifies restricted visibility — never absent control. Sample the year’s executive comp changes to committee-approved sources.
  10. SoD and access. Pull actual access: who holds master-maintenance with run-release, or time-approval for their own team while processing payroll? For each conflict, test the monitoring that supposedly compensates.
  11. Run review and release. Sample 10 cycles: variance review performed and dispositioned (C5), totals reconciled to bank file, release under dual control, post-approval changes re-approved.
  12. Reconciliation and accruals. All 12 monthly recs plus the year-end bonus/PTO accrual: timely, reviewed, aged items escalated, accrual methodology consistent — documented to the standard of our model workpaper.

The analytics: ghosts, leavers, and outliers

AnalyticLogicWhat a hit means
Ghost-employee existence matchEmployee master vs. independent life-signs: HR status, badge swipes, network logins, benefits enrollment, time entries. Flag paid employees with zero activity across all signals in 60–90 daysGhost, long-leave data gap, or a field population problem — all three worth knowing
Shared bank accountsSame deposit account across multiple employee records; employee accounts matching vendor-master accountsGhost cluster, household edge case, or vendor-employee collusion
Shared addresses / contact detailsDuplicate addresses, phones, emergency contacts across unrelated employeesGhost tell; also catches the supervisor whose “employees” all live at his address
Post-termination payment scanPayments dated after final-pay date, netted for severance schedulesInterface failure aging into loss
OT distributionZ-scores by employee within cost center; share-of-base ratios; approver concentrationInflation, buddy-approval, or a genuinely understaffed team — the follow-up tells you which
Rate-change velocityEmployees with multiple rate changes in-year; changes effective-dated backward; round-percentage clusters outside merit cyclesUnauthorized raises; retro manipulation
Off-cycle trendOff-cycle count and dollars by month and by requestorDiscipline decay — a rising line is a finding by itself
Net-pay outliersNet pay vs. peer band for grade and locationThe blunt catch-all that finds what the elegant tests miss

Same disciplines as always: prove population completeness first (payroll register to GL to bank file), and disposition every hit in writing — the ghost analytic in our model payroll report earned its credibility by reporting 14 initial exceptions and clearing all 14, not by pretending the first pass came back empty.

Worked example: MidState Beverage’s payroll audit

MidState Beverage is the three-state drinks distributor used across this site: about 1,400 employees, 300 of them drivers paid on route-based hours, twelve depots with their own timekeeping practices, two acquired distributors recently migrated onto the platform, payroll processed by a cloud provider whose SOC 1 Type 2 report covers 1 October to 30 September, and a six-person internal audit function with no compliance function beside it. The analytics auditor’s first run of the catalog, on fourteen months of provider extracts and 37,800 pay records reconciled to the ledger within 900 dollars and to the bank files exactly, is written up in the payroll analytics catalog; the payroll audit that followed tested the controls the hits pointed at, and the two engagements together produced the eight findings. The table gives the twelve tests as they ran.

TestPopulation and sampleWhat it foundWhere it went
1. Ghost-employee sweepFull master against HR status, route settlement activity, badge and network signals168 raw hits triaged to nine: six shared bank accounts, five of them married couples and one a driver paid into a depot clerk’s account for four periods as a stopgap for a lost card, reversed; 22 thin-profile seasonal hires all confirmed present at depots; no fabricated records.Control failure on the shared-account stopgap; no ghost finding
2. Terminated-still-paidHR termination file joined to paymentsEleven employees paid after termination, 19,400 dollars, all from terminations the depots reported to HR between eight and thirty days late; nine recovered. Three termination-and-rehire cycles at one depot used to reset probation.Finding, High: depot termination reporting; fix in the route settlement system that locks a driver’s route on the termination date
3. Master-change authorisation25 changes weighted to rate changesSeventeen rate changes in the period were entered and approved by the same HR administrator under a workflow that allowed it.Finding, High: segregation in the HR workflow
4. Bank-detail changesAll 71 changes in the periodTwo changes made by a payroll user two days before payday and reversed after, corroborated as a diverted pay run of 4,100 dollars, recovered from a former payroll clerk; the verification control that should have caught it did not operate for changes made by payroll staff themselves.Referred under the protocol and recovered; finding on the verification control’s scope
5. Compensation to source25 employeesSix above-band rates, all with approved exceptions on file; two re-keyed rates differing from the offer letter by transposition, both in the employee’s favour.Observation; corrected
6. Time and overtime approval25 timecards from the driver populationApproval preceded processing in 23; two approved after the run by delegation.Combined with test 7
7. Overtime outliersFull year by employee and cost centreFour drivers at two depots recorded hours implying more than fifteen hours a day for eleven consecutive periods, approved by a supervisor who was the brother-in-law of two of them.Referred, then finding, High
8. Off-cycle paymentsAll 210 in the periodConcentrated in the two acquired distributors’ first months on the platform and explained by migration errors; separately, 40 payments to employees made through accounts payable coded as awards, 31,000 dollars, bypassing withholding.Finding, Medium: tax compliance and the AP channel
9. Executive payrollThe confidential channel walked; the year’s changes sampledExecutive compensation processed by the HR director and the CFO on the same platform with restricted visibility; changes traced to board-approved sources; no bypass of the controls.No finding; confidentiality implemented as restricted visibility, the right way
10. Segregation and accessActual platform rolesThe HR administrator’s combined enter-and-approve rights (test 3); payroll staff able to change their own bank details without the verification step (test 4); provider administrator accounts held by two named MidState users and reviewed quarterly.Findings above
11. Run review and release10 cyclesVariance review performed and dispositioned in all ten; release under dual control; totals reconciled to the bank file.No finding
12. Reconciliations, accruals and the provider’s SOC 112 monthly reconciliations; year-end accruals; the SOC 1 Type 2 report and its complementary user controlsReconciliations timely and reviewed; the SOC 1 report clean, but two of the four complementary user controls it assumes MidState operates (review of the provider’s output register before funding, and quarterly review of platform user access) were not being performed, as the SOC 1 review guide describes.Finding, Medium: boundary controls

The report carried eight findings, three High, and an overall rating of Needs Improvement, with two referrals handled under the protocol described in the CFE guide and kept out of the report’s wording. Three things generalise. The most expensive condition, the late termination reporting, was not a payroll control failure at all but a depot process gap, which is why the fix lived in the route settlement system rather than on the payroll platform; payroll audits find their causes upstream. The diverted pay run, the only fraud in the engagement, was small, caught by an analytic rather than by the control designed to catch it, and possible only because the verification control had a hole for the people who ran payroll; the finding was about the hole, not the 4,100 dollars. And the outsourced platform’s clean SOC 1 report was true and irrelevant to the two controls MidState was supposed to operate on its own side of the boundary, which nobody had read the report closely enough to notice.

The findings that recur — and wording that lands

Four findings write most payroll reports. Termination-interface failure (“11 of 214 terminations were not reflected in payroll within one cycle; 4 employees received pay after separation totaling $23,400, of which $9,100 is recovered to date — the exception queue designed to catch interface failures has had no assigned owner since March”). Unverified bank changes (“63 of 71 employee bank-detail changes were made through self-service with no out-of-band confirmation; the configuration to require it exists and is disabled”). Executive bypass (“compensation changes for the 9 executives are processed manually outside the HRIS workflow; 3 of 7 in-period changes had no documented source approval available to payroll — confidentiality has been implemented as absence of control rather than restriction of visibility”). OT approval theater (“the top-decile overtime population shows 84% of approvals logged within 90 seconds of batch submission, concentrated in two supervisors — review is occurring as bulk acknowledgment, not examination”). Each follows the 5 C’s chain: numerators, denominators, named causes, consequences in dollars and exposure-days.

Scoping variants: outsourced payroll, small shops, executives

Outsourced payroll (the majority case): the processor calculates; your organization still owns the inputs and the outputs. Your audit shifts to the boundary controls — master-data authorization before transmission, output variance review before funding, bank-file reconciliation after — plus reliance discipline over the provider: what its SOC 1 actually covers, which complementary user-entity controls it assumes you operate (test those — they are yours), and, from September 2026, the program-level baseline of the IIA’s Third-Party Topical Requirement. Small organizations: SoD collapses, so the owner’s review becomes the control — test that the reviewer receives a complete register (not one filtered by the preparer) and actually engages with it; run the ghost and terminated-pay analytics yourself across everything, because nobody else ever has. Executive payroll is a scoping decision everywhere: put it in scope explicitly, negotiate visibility with the CHRO and audit committee chair if needed — and treat “you can’t look at that” as a governance data point worth reporting in its own right.

Outsourced payroll: the boundary, and the four controls that stay yours

Most organizations no longer run payroll; they run a payroll provider. The calculation engine, the tax tables, the statutory filings and the payment file live with the processor, and the processor’s SOC 1 Type 2 report describes controls over those things. What the report does not describe, except in a section most readers skip, is the set of controls the provider assumes its customers operate on their own side of the line: the complementary user entity controls. Every processor lists them, usually four to eight, and every one of them is a control your organization has in effect signed up to perform. If nobody performs them, the provider’s clean opinion covers a process with a hole in it, and the hole is on your side. The SOC 1 review method walks through how to read a report as a user entity; what follows is the payroll-specific version.

The four controls below appear, in one wording or another, in almost every payroll processor’s report. Treat them as in scope for the audit whether or not the SOC 1 itself is, because they are the controls that decide whether a wrong input becomes a wrong payment.

Control the SOC 1 assumes you operateWhat it stopsHow to test itMidState’s result
Master-data changes (hires, terminations, rate and bank changes) are authorized before transmission to the providerUnauthorized or fictitious changes flowing straight into the pay run; the provider processes whatever it receivesSample 25 changes from the provider’s change log, not from HR’s; trace each to an approval that predates transmission and comes from someone other than the person who keyed itOperated; the exceptions in tests 3 and 4 were holes in the approval rule’s design, not skipped approvals
The provider’s pre-funding output register is reviewed against expected totals and variance thresholds before the run is releasedA wrong run being funded: a diverted bank account, a doubled rate, a migration error paid to hundreds of peopleObtain the register and the review evidence for 12 periods; confirm the reviewer received the full register, that variances beyond threshold were explained, and that the review predates fundingNot performed; the register arrived every period and nobody was assigned to review it, which is how the diverted run in test 4 reached the bank
Provider platform user access is recertified periodically and leavers are removed promptlyFormer payroll staff, HR administrators, depot timekeepers and provider support accounts keeping the ability to change data or release runsPull the current user list from the provider, not from HR; compare it to the active employee list; walk the last two recertifications and confirm the removals actually happenedPerformed only for the two provider administrator accounts; the wider population of HR and depot users had never been recertified
Funding and the returned bank file are reconciled to the approved register after each runMoney leaving the bank that differs from what was approved, and rejected or returned payments quietly re-sent to new accountsRe-perform three reconciliations; trace returned items to their resolution and confirm that re-sent payments went through the bank-change verification controlOperated and timely; returned items were resolved by the payroll clerk alone, noted as an improvement point rather than a finding

Three further points about the report itself. First, the period. MidState’s provider reports on a year ending 30 September, which left a gap between the end of the reporting period and MidState’s own year-end; a bridge letter from the provider covers the gap for reliance purposes, and where there is no letter the auditor has to decide how much of the year is uncovered and whether that matters for the reliance being placed. Second, subservice organizations. Payroll processors routinely carve out the bank or clearing house that actually moves the money, which leaves the payment leg covered by nobody’s report unless you obtain the subservice provider’s own report or test the payment controls yourself; the payment operations guide covers what to test at the bank interface. Third, exceptions. A clean opinion can sit above a testing section that lists deviations in exactly the controls you rely on; read the testing section, not just the opinion page, and ask the provider what changed as a result.

Since 15 September 2026 this reliance work has had a program-level baseline. The IIA’s Third-Party Topical Requirement sets out what an internal audit function is expected to cover when it assesses how the organization manages its third parties, and a provider that calculates and pays the workforce sits near the top of any criticality ranking. For the payroll audit that means documenting who owns the provider relationship, whether the provider is in the third-party inventory with a risk tier, whether the contract gives audit rights and a right to the SOC 1 report, and whether the complementary user controls are assigned to named owners. The last point is the one that failed at MidState: the controls were listed in a report nobody at the company had read past the opinion page, and assigned to no one. Assigning them was most of the remediation.

Where to go next

Payroll rewards the auditor who respects its rhythm. The process is well run in most organizations, which is exactly why the failures that do exist, the ghost in the master, the leaver still paid, the executive channel with no controls, the redirected deposit, survive for so long. Run the full-population analytics first, put your samples where humans re-key and approve, refuse the executive carve-out, test the four controls the provider’s report assumes you operate, and document to the model-workpaper standard. Then, when the file comes back clean, write the clean report the way Report A in the report library does, showing the work, because a payroll audit that earns its Satisfactory is one of the more reassuring documents a committee reads all year. When it does not come back clean, as MidState’s did not, the first 48 hours protocol keeps the referral out of the audit file and the audit on schedule.

Next in the process series: travel and expense, where the dollars are smaller and the signals are richer, then procurement and the vendor master file, which share a fraud population with payroll and, at MidState, the same twelve depots.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading