CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Blog
PayrollComplianceHR OperationsHRMS

Payroll Audit Readiness: Controls and Checklist

How Indian employers build payroll controls that survive scrutiny: a payroll risk map, segregation of duties for small teams, a section-wise audit checklist and a 10-day self-au...

CozyHR editorial team 11 September 2026 45 min read
CozyHR Blog
Payroll Audit Readiness: Controls and Checklist

A payroll audit is no longer an event that happens to your company once a year. For Indian employers, it has become a standing condition: your statutory auditor tests employee-benefit expense, your investor's diligence team pulls three years of registers in a week, a labour inspector asks for muster rolls and wage registers in digital form, and your own board wants comfort that the largest line item on the P&L is controlled. The companies that handle this well are not the ones with the biggest finance teams. They are the ones that designed payroll controls before anyone asked for them.

This guide is about readiness, not reconciliation. If you want the mechanics of closing a payroll month, that is a separate discipline and a separate post. Here we cover how to build a payroll control environment that survives scrutiny: the risk map, the control design that works when only two people run payroll, a payroll audit checklist you can actually use, a control calendar, a ten-day self-audit sprint, and the documentation pack that keeps a diligence process from stalling. Treat every statutory reference here as a general concept, verify current rates, forms and timelines with the relevant government portals, and take professional advice on anything that touches your specific facts.

Why Payroll Audit Readiness Matters More Now

Payroll used to be judged by one question: did people get paid on time. That question still matters, but it is now the floor, not the standard. Four shifts have pushed payroll audit readiness up the priority list for Indian SMBs and startups.

The labour codes era assumes digital records

The consolidation of Indian labour legislation into a smaller set of codes has, as a direction of travel, pushed employers towards electronic registers, electronic wage slips, and standardised definitions of wages. Implementation timelines and state rules vary and continue to evolve, so verify what currently applies to your establishments and states. But the underlying expectation is clear enough to plan around: registers should be maintainable and producible in electronic form, wage components should be defined consistently, and the employer should be able to show the same numbers across payslip, register, return and bank statement.

The practical consequence is that "we have it in a spreadsheet somewhere" is a weaker answer than it used to be. An inspector or auditor asking for a wage register for a specific month at a specific location expects a document that looks like a register, not a pivot table assembled on the spot.

Wage definition changes make historical consistency visible

Whenever the definition of wages for benefit calculations shifts, the first thing anyone reviewing your payroll does is compare how you treated a component before and after. Inconsistency without a documented decision looks like error. A documented decision, even a conservative one, looks like control.

This is why the single most valuable artefact in payroll readiness is not a number. It is a dated note explaining why you compute something the way you do, who approved it, and when it changed.

Investors and acquirers now open payroll early

Payroll and statutory dues used to be a late-stage diligence item. In practice, buyers now front-load it because unpaid statutory dues, misclassified contractors and undocumented ESOP or bonus promises are the kind of liabilities that change valuation or trigger indemnities. A diligence team that finds a clean, indexed payroll pack in week one forms a different view of management quality than one that receives six unlabelled Excel files in week three.

Deal risk is asymmetric here. A well-run payroll rarely wins you a better price. A messy one reliably costs you time, escrow, or negotiating position.

Auditors focus on employee-benefit expense because it is material

For most services businesses, employee-benefit expense is the largest cost line. Auditors go where materiality is. Expect testing on headcount reconciliation, month-on-month variance explanations, cut-off around joiners and leavers, accrual completeness for bonus, leave encashment and gratuity, and agreement between statutory deductions in the books and amounts actually deposited.

None of this is exotic. It is all answerable if the underlying controls exist. It is painful if they do not.

The Three Audiences for a Payroll Audit

A common mistake is preparing for "an audit" as if there were one reviewer with one appetite. There are three, and they want different evidence in different shapes. Designing for all three at once is cheaper than retrofitting for each.

Audience 1: Statutory and internal auditors

What they want: assurance that reported numbers are complete, accurate, correctly cut off, and properly classified. They think in assertions: existence (do these employees exist), completeness (are all costs recorded), accuracy (is the arithmetic and rate right), cut-off (is it in the right period), and presentation (is it in the right GL account).

Evidence that satisfies them: a headcount-to-cost reconciliation, month-on-month movement analysis with explanations, the payroll register tied to the GL journal, statutory liability accounts tied to challans and returns, sample employee files with appointment letters and revision letters, and an accrual working with a basis you can defend.

What annoys them: journals posted to payroll accounts from outside the payroll process with no supporting schedule, and reconciling items that carry forward month after month without resolution.

Audience 2: Regulators and inspectors

What they want: statutory compliance in prescribed form. Registers maintained, wage slips issued, contributions computed on the correct base, deposits made within timelines, returns filed, and coverage applied to the right set of workers, including contract labour where applicable.

Evidence that satisfies them: registers in the prescribed or acceptable electronic format, proof of wage slip issue, challans and return acknowledgements, records for each establishment and state separately where registration is state-specific, and contractor compliance documentation where you are the principal employer.

What annoys them: inability to produce records for a specific location and month, gaps between registered establishments and actual places of work, and contractor compliance that was never collected.

Audience 3: Buyers, investors and lenders

What they want: quantified exposure. Not just "are you compliant" but "if you are not, what does it cost, and is it a one-year problem or a five-year problem". They also want to understand the shape of the cost base: attrition, joiner run-rate, variable pay commitments, notice period liabilities, and anything that changes post-transaction.

Evidence that satisfies them: a clean data room index, three years of monthly registers in machine-readable form, a statutory dues status summary per registration, a reconciliation of payroll cost to audited financials, employment contract templates plus a list of non-standard contracts, contractor and consultant arrangements with classification rationale, and a management representation on known disputes and notices.

What annoys them: reformatted data that does not tie to the audited numbers, and answers that arrive one question at a time over three weeks.

Designing for all three

The overlap is larger than the difference. If you maintain source registers, keep approvals, deposit on time, reconcile to the GL, and index the evidence, then each audience needs a different cover sheet over the same underlying files. Build the base once.

DimensionStatutory / internal auditorRegulator / inspectorBuyer / investor
Core questionAre the numbers right and completeAre the rules followed in prescribed formWhat is the exposure and the run-rate
Time horizonCurrent financial year, with comparativesPeriod under inspectionTypically multi-year lookback
Preferred formatSchedules tying to trial balanceRegisters, challans, returnsIndexed data room, machine-readable files
Fatal weaknessUnreconciled differencesMissing or unproducible recordsUnquantifiable liabilities
Best single artefactPayroll-to-GL reconciliationWage register plus challan setStatutory dues status summary

The Payroll Risk Map

You cannot design controls without naming the risks. Payroll risk in an Indian SMB clusters into seven areas. For each, the useful exercise is to write down the specific way it fails in your company, not the textbook description.

1. Master-data risk

Master data is employee identity, bank account, PAN, statutory identifiers, date of joining, designation, location, cost centre, salary structure and benefit eligibility. Everything downstream inherits errors here.

Illustrative failures: an employee's bank account is updated from a WhatsApp message with no verification, and salary goes to a wrong account. A date of joining is entered as the offer date rather than the actual joining date, so the first month is overpaid. A salary revision is keyed with an effective date of the approval month rather than the promised month, so arrears are wrong. A location code is never updated after an employee moves states, so professional tax is deducted under the wrong state.

2. Input risk (attendance, leave, variable pay)

Payroll consumes inputs that originate outside payroll: attendance, leave balances, overtime, incentives, shift allowances, reimbursements, loss of pay.

Illustrative failures: a branch sends attendance as a scanned sheet, and a manual key-in flips two digits on overtime hours. A sales incentive is paid from a working file that a manager emailed directly to the payroll executive, bypassing the approval route. Leave-without-pay is applied a month late because the leave system and payroll are reconciled only at year-end. Reimbursement claims are processed without bills because "the bills are coming".

3. Calculation risk

This is the risk that the engine or the spreadsheet computes something differently from your stated policy.

Illustrative failures: a pro-rata formula uses calendar days for some components and fixed days for others, so a mid-month joiner's payslip does not foot. A new allowance is added to the structure but excluded from the gratuity or bonus base without a documented reason. Tax projection ignores a mid-year salary revision until the last quarter, causing a large February deduction and a queue outside HR. A one-off payment is coded as a regular earning and silently repeats the next month.

4. Statutory deduction and deposit risk

The gap between deducting correctly and depositing correctly is where real money is lost.

Illustrative failures: contributions are computed correctly but deposited after the due date because the approver was travelling, attracting interest and damages. A new state of operation begins without professional tax registration, so deductions accumulate undeposited. Employees are added to the payroll but not to the statutory portal in the same month, creating a mismatch between the register and the return. TDS is deducted using declared investments that were never backed by proof, and the shortfall surfaces only at year-end.

5. Disbursement risk

The bank file is the point at which errors become irreversible.

Illustrative failures: the bank upload file is edited after approval to "fix" a rounding issue, and the edited file no longer matches the approved register. A duplicate file is uploaded after a portal timeout, and two credits go out. A returned payment is re-issued to a manually typed account number without re-verification. Off-cycle payments are made from the current account on verbal instruction and never enter the payroll system, so the register understates cost.

6. Accounting and GL risk

Payroll can be correct and still be reported wrongly.

Illustrative failures: the payroll journal maps all earnings to a single salary account, so the auditor cannot test components. Statutory liability accounts are never cleared, so old balances sit there indefinitely and nobody can say which month they relate to. Full-and-final settlements are booked as a lump sum with no split between notice pay, leave encashment and recoveries. Cost centre mapping is stale, so departmental cost reports mislead management.

7. Records and access risk

The last risk is about who can see and change what, and whether you can prove what happened.

Illustrative failures: three people share one payroll login, so no change can be attributed to an individual. Payslips are generated as editable files and emailed, so a modified payslip can circulate without detection. An exited employee's access to the payroll folder is never revoked. Salary data sits in a personal cloud drive belonging to an employee who has since left. Backups exist but have never been tested by restoring a file.

Control Design That Works in a Small Team

Most payroll control guidance assumes a department. Indian SMBs frequently run payroll with one HR executive, one finance person, and a founder who approves things on a phone. Controls still work at that size, but they have to be designed for it.

Segregation of duties when you only have two people

The principle is simple: the person who can change what is paid should not be the person who releases the money, and neither should be able to quietly alter the record afterwards. With two people, you split along that line and use the system and the bank as your third party.

A workable split:

  • Person A (Preparer, usually HR): maintains master data, processes inputs, runs the payroll, generates the register and payslips.
  • Person B (Reviewer and releaser, usually Finance): reviews the register against the prior month with variance explanations, approves, uploads and releases the bank file, and files statutory deposits.
  • System: enforces that Person A cannot release payment and Person B cannot change master data without leaving a log.
  • Founder or director: acts as second bank authoriser above a defined threshold and reviews the monthly variance summary.

If the founder is the only realistic second pair of eyes, do not ask for a full review. Ask for a focused one: new joiners and leavers this month, any payment above a threshold, any off-cycle payment, and the total movement versus last month with reasons. That takes fifteen minutes and catches most material errors.

Compensating controls when segregation is impossible

Sometimes one person genuinely does everything. Then you compensate:

  • Mandatory dual bank authorisation with a second authoriser outside payroll.
  • Monthly independent review of the payroll register by someone who does not process it, even a part-time accountant or the company secretary.
  • Exception reporting that is automatic: new bank account changes, salary changes above a percentage, employees paid after their exit date, duplicate bank accounts, duplicate PANs.
  • Periodic rotation or mandatory leave during which someone else runs a payroll cycle. Errors and manipulations usually surface when the usual operator is away.
  • Bank statement review by the founder against the payroll total each month, which takes two minutes and is surprisingly effective.

Maker-checker in practice

Maker-checker fails when the checker does not know what to check. Give the checker a defined test set rather than a vague instruction to review.

A practical checker script for a monthly payroll run:

  1. Headcount at start, plus joiners, minus leavers, equals headcount at end. Tie to the register line count.
  2. Gross payroll this month versus last month, with every variance above a set threshold explained by a named cause (joiner, leaver, revision, arrear, incentive, LOP).
  3. New joiners: offer letter on file, joining date matches, first-month pro-rata recomputed independently for at least one case.
  4. Leavers: paid up to last working day only, full-and-final either processed or accrued, access revoked.
  5. Arrears: approval reference present, effective date matches the approval document.
  6. Statutory totals: contribution bases reconcile to the earnings that should attract them.
  7. Bank file total equals net pay total in the approved register, to the rupee.
  8. Off-cycle payments during the month: listed, approved, and included in the register.

Change logs on master data

Every master-data change should answer four questions: what changed, from what to what, who changed it, and on whose authority. The first three should be system-generated. The fourth is a document reference.

The highest-risk fields deserve extra treatment. Bank account changes should require independent confirmation with the employee through a channel other than the one that requested the change, and ideally a cooling period or a next-cycle effect rather than same-day payment. Salary changes should be traceable to a signed or system-approved revision letter. Statutory identifier changes should be validated against the source document.

Approval matrices

Write down who can approve what, at what value, and keep it to one page. A simple structure:

Transaction typePrepared byApproved bySecond approval above thresholdEvidence retained
New hire and salary structureHRFunction head + HR headFounder for senior rolesOffer letter, approved requisition
Salary revision or promotionHRFunction head + HR headFounder above defined bandRevision letter, approval trail
Variable pay and incentivesBusiness owner of the schemeFinance review + HR headFounder for scheme changesScheme document, computation file
ReimbursementsEmployee claimReporting managerFinance above thresholdPolicy, bills, approval record
Loans and advancesHRFinance headFounderAgreement, recovery schedule
Off-cycle or manual paymentHR or FinanceFinance headFounder, alwaysWritten justification, register entry
Full-and-final settlementHRFinance headFounder above thresholdClearance form, computation, recovery proof
Bank file releaseFinanceBank authoriser 1Bank authoriser 2 above thresholdApproved register, upload confirmation

Adjust the names to your structure. The value is in having it written and applied consistently, not in the specific thresholds.

Bank file controls

Bank file handling deserves its own set of rules because it is the last controllable point.

  • Generate the bank file from the payroll system, not by hand, and never edit it after generation.
  • Match file control totals (record count and value) to the approved register before upload, and record the match.
  • Use a dedicated payroll bank account funded with the exact approved amount. A residual balance close to zero after disbursement is itself a control.
  • Maintain a beneficiary master at the bank where possible, so new accounts require separate addition and approval.
  • Reconcile the bank statement to the payroll file the next working day and investigate any return, reversal or unmatched debit immediately.
  • Keep the upload confirmation and the success or failure report with the payroll month file.

Off-cycle payment controls

Off-cycle payments are the most common route by which payroll records and reality diverge. Treat them as exceptions with a fixed process.

  • Every off-cycle payment requires a written reason and an approval that names the employee, amount and component.
  • Every off-cycle payment must be entered into the payroll system in the same month, even if paid outside the system, so registers, statutory bases and the GL remain complete.
  • Maintain a single off-cycle log for the year. At audit, this log is one of the first things worth producing voluntarily, because it demonstrates control rather than hiding an exception.
  • Review the log quarterly. A rising count usually means a process problem elsewhere, such as late joiner onboarding or an unworkable cut-off date.

The Payroll Control Calendar

Readiness is a rhythm, not a project. This calendar assumes an April to March financial year and a standard monthly payroll. Adjust dates to your cut-off. Verify all statutory due dates currently applicable to your registrations, because they differ by law, state and sometimes by establishment.

FrequencyActivityOwnerEvidence produced
MonthlyFreeze master-data changes at cut-off; export change log for the monthHRMaster-data change report with approvals
MonthlyLock attendance and leave inputs; sign-off from each location or managerHRSigned or system-approved input sheets
MonthlyRun payroll; generate register, payslips, statutory computation sheetsHRPayroll register, payslip batch
MonthlyMaker-checker review using the fixed checker scriptFinanceSigned review checklist with variance notes
MonthlyRelease bank file with dual authorisation; reconcile bank statement next dayFinanceUpload confirmation, bank reconciliation
MonthlyDeposit statutory dues within applicable due dates; file monthly returns where requiredFinanceChallans, return acknowledgements
MonthlyPost payroll journal; reconcile payroll cost and liabilities to GLFinancePayroll-to-GL reconciliation
MonthlyUpdate off-cycle payment log and exception report reviewFinanceOff-cycle log, exception sign-off
QuarterlyReconcile statutory registers to challans and returns for the quarterFinanceQuarterly statutory reconciliation
QuarterlyFile quarterly TDS statements; review mismatches and correctFinanceReturn acknowledgement, correction trail
QuarterlyReview user access list for payroll systems and folders; revoke stale accessHR + ITAccess review sign-off
QuarterlyTest a sample of full-and-final settlements end to endFinanceF&F test sheet with exceptions
QuarterlyReview contractor and consultant classification and compliance documentsHR + LegalContractor compliance file
Half-yearlyReview salary structure definitions against policy and current statutory interpretationHR + FinanceStructure review memo
Half-yearlyInternal self-audit sprint (see below)Internal audit or FinanceFindings report with owners and dates
AnnualCollect and verify investment proofs; finalise tax computationsHR + FinanceProof verification records
AnnualIssue annual tax certificates to employees within applicable timelinesFinanceIssued certificates, distribution log
AnnualActuarial or policy-based valuation input for gratuity and long-term benefitsFinanceValuation report and data sheet
AnnualReconcile annual payroll cost to audited financial statementsFinanceCost reconciliation schedule
AnnualReview and refresh policies: leave, reimbursement, notice, bonus, loansHRApproved policy versions with dates
AnnualRecords retention review; archive and purge per applicable requirementsHR + ITRetention log
AnnualRefresh data room payroll packFinanceIndexed diligence pack

The only way this calendar works is if each row has a named owner and a date, and if the evidence column is treated as the deliverable. An activity with no artefact did not happen, as far as any auditor is concerned.

The Payroll Audit Checklist

This is the working payroll audit checklist. Use it as a self-assessment before anyone external asks. For each line, the evidence noted is what you should be able to produce within a day.

Section A: Master data

  • [ ] Employee master list agrees to the HR headcount report and to the last month's register. Evidence: headcount reconciliation with joiner and leaver movement.
  • [ ] Every active employee has a signed appointment letter or contract on file. Evidence: employee file index with completeness status.
  • [ ] Every salary revision in the period is supported by an approved revision letter with an effective date. Evidence: revision letters mapped to payroll effective dates.
  • [ ] No duplicate PAN, duplicate bank account, or duplicate employee ID exists. Evidence: duplicate check report, with explanations for genuine cases.
  • [ ] Bank account changes in the period were independently verified before payment. Evidence: change log with verification record.
  • [ ] Statutory identifiers (PF, ESI, UAN and equivalents) are captured and validated where applicable. Evidence: identifier completeness report.
  • [ ] Location, state and establishment mapping is current for every employee. Evidence: location-wise headcount tie to registrations.
  • [ ] Dates of joining and dates of exit in the master match HR records and settlement files. Evidence: joiner and leaver register with source documents.
  • [ ] Master-data changes in the period are all traceable to an approver. Evidence: system change log export.

Section B: Time and attendance inputs

  • [ ] Attendance for every location is locked and signed off before payroll processing. Evidence: sign-off records per location.
  • [ ] Leave balances used in payroll agree to the leave system at the cut-off date. Evidence: leave balance extract at cut-off.
  • [ ] Loss-of-pay days in payroll agree to attendance and leave records. Evidence: LOP report with supporting attendance.
  • [ ] Overtime is computed on the approved base and supported by approved hours. Evidence: overtime approvals and computation basis.
  • [ ] Shift, night and location allowances are supported by roster or eligibility data. Evidence: roster extract and eligibility rules.
  • [ ] Late input corrections are logged as exceptions rather than silently absorbed. Evidence: input exception log.

Section C: Earnings and deductions

  • [ ] Each earning and deduction component has a documented definition, taxability treatment and statutory inclusion or exclusion. Evidence: component master document with approval date.
  • [ ] Pro-rata logic for joiners, leavers and mid-month changes is documented and applied consistently. Evidence: policy note plus recomputation of sample cases.
  • [ ] Variable pay and incentives trace to an approved scheme and an approved computation. Evidence: scheme document, computation file, approval.
  • [ ] Arrears are supported by approval and the effective date matches the approval. Evidence: arrear working with document references.
  • [ ] Reimbursements are supported by policy-compliant bills and approvals. Evidence: claim files or system records with attachments.
  • [ ] Loans and advances have signed agreements and recovery schedules that tie to deductions. Evidence: loan register reconciled to payroll recoveries.
  • [ ] Recoveries on exit (notice shortfall, asset, advances) are documented and approved. Evidence: clearance form and settlement working.
  • [ ] Bonus, gratuity, leave encashment and similar accruals have a documented basis. Evidence: accrual workings with assumptions stated.

Section D: Statutory

  • [ ] The set of registrations held matches the set of states and establishments where you actually employ people. Evidence: registration certificates mapped to location headcount.
  • [ ] Contribution bases for each statutory deduction are computed on the components documented in your policy. Evidence: base computation sheet per component.
  • [ ] Employee coverage and eligibility rules are applied consistently, including for employees crossing thresholds mid-year. Evidence: eligibility logic note and exception list.
  • [ ] All deposits for the period were made within applicable due dates, or late payments are identified with interest or damages quantified. Evidence: challan set with date comparison.
  • [ ] Returns and statements for the period are filed and acknowledged. Evidence: acknowledgements filed by period.
  • [ ] Register totals reconcile to challan totals and to return totals for each period. Evidence: three-way statutory reconciliation.
  • [ ] TDS on salary is supported by declarations at the start and verified proofs at the end, with the treatment of unverified declarations documented. Evidence: declaration and proof verification records.
  • [ ] Mismatches flagged on statutory portals are tracked to closure. Evidence: mismatch tracker with resolution dates.
  • [ ] Contract labour compliance documentation is collected from contractors where you are the principal employer. Evidence: contractor compliance file per month.
  • [ ] Professional tax and any state-specific levies are applied per the employee's actual work state. Evidence: state-wise deduction summary.

Verify current rates, thresholds, forms and due dates directly with the relevant authority or your advisor before relying on any internal note. These change, and an internal document that was right two years ago is a liability if it is still being followed blindly.

Section E: Disbursement

  • [ ] Bank file total ties exactly to the approved register net pay total. Evidence: control total match record.
  • [ ] The bank file was generated by the system and not modified after approval. Evidence: file hash, generation log or system audit trail.
  • [ ] Dual authorisation was applied per the approval matrix. Evidence: bank authorisation record.
  • [ ] Bank statement is reconciled to payroll disbursement with all returns and reversals investigated. Evidence: disbursement reconciliation.
  • [ ] No payments were made to employees after their exit date without approval. Evidence: post-exit payment exception report.
  • [ ] Off-cycle payments are logged, approved and recorded in the payroll system. Evidence: off-cycle log with approvals.
  • [ ] Payments to non-employees (consultants, interns, contractors) are routed through the correct process, not through payroll by default. Evidence: classification note and payment route mapping.

Section F: Accounting and GL

  • [ ] The payroll journal is generated from the payroll system with a component-level mapping. Evidence: journal with mapping table.
  • [ ] Payroll cost in the GL agrees to the payroll register for each month. Evidence: monthly payroll-to-GL reconciliation.
  • [ ] Statutory liability accounts are cleared in the following period and aged balances are explained. Evidence: liability ageing schedule.
  • [ ] Accruals for bonus, leave and gratuity are supported and reversed or adjusted appropriately. Evidence: accrual schedule with movement.
  • [ ] Cost centre and department mapping is current and agrees to the org structure. Evidence: cost centre mapping review.
  • [ ] Manual journals to payroll accounts are rare, approved and supported. Evidence: manual journal log with approvals.
  • [ ] Annual payroll cost reconciles to the employee-benefit expense in the financial statements. Evidence: annual reconciliation schedule.

Section G: Documentation, access and retention

  • [ ] Payroll system access is role-based, individually attributed, and reviewed at least quarterly. Evidence: access list with review sign-off.
  • [ ] Exited employees' access to payroll systems, folders and shared drives is revoked promptly. Evidence: exit checklist with IT confirmation.
  • [ ] Payslips are issued in a tamper-evident form and issue is logged. Evidence: payslip distribution log.
  • [ ] Registers required for your establishments are maintained and producible in the applicable format. Evidence: register set per establishment per month.
  • [ ] Policies referenced by payroll are versioned with effective dates and approvals. Evidence: policy register.
  • [ ] Payroll data is backed up, and restoration has been tested at least once in the year. Evidence: backup log and restore test record.
  • [ ] Sensitive payroll data is not stored in personal drives or unmanaged spreadsheets. Evidence: data location inventory.
  • [ ] Retention periods are defined per record type in line with applicable statutes and reviewed periodically. Evidence: retention policy with legal review date.

Common Audit Findings and How to Fix Them

The same findings recur across Indian SMB payrolls. Knowing the root cause matters more than knowing the finding, because the fix belongs at the cause.

FindingTypical root causeFix that holds
Ghost employees or employees paid after exitExit information reaches payroll after the cut-off; no automated exit-date validationMake exit date a hard stop in the system; run a post-exit payment exception report every cycle; tie IT access revocation and payroll exit to one checklist
Unsupported reimbursementsClaims approved on trust; bills promised later and never collectedRequire attachment at claim submission; auto-reject claims without attachments; monthly ageing of pending-proof claims with recovery if unresolved
Arrears paid without approval referenceVerbal revisions and back-dated promisesNo arrear entry without a linked approval document ID; reconcile arrear register to revision letters quarterly
Challan totals do not match register totalsManual adjustment between computation and deposit; late additions of employeesThree-way reconciliation (register, challan, return) every period, with differences explained at employee level, not in total
Salary revisions applied from the wrong dateApproval date and effective date conflated during data entryTwo separate mandatory fields, with a system warning when they differ by more than a set period; sample test each cycle
Full-and-final settlements unreconciledNo standard settlement template; recoveries tracked outside payrollOne settlement template with mandatory sections for leave, notice, recoveries and statutory; settlement liability aged monthly until cleared
Undocumented loans and advancesFounder-approved advances paid from the current accountEvery advance requires a written agreement and a recovery schedule entered in payroll on the day of payment; monthly loan register reconciliation
Statutory deposits made lateSingle approver dependency and no calendar reminderTwo authorised signatories; a compliance calendar with reminders set before the due date; escalation if unapproved by a defined buffer day
Contractor workers treated as out of scopePrincipal employer obligations not understoodMonthly contractor compliance collection as a payment precondition; classification review with legal input
Inconsistent component treatment across yearsUndocumented decisions by successive payroll ownersComponent master document with a change history and approval per change
Payroll numbers do not tie to financialsManual journals and incomplete off-cycle captureSystem-generated journals only; off-cycle payments must be entered in payroll before release
One person can do everythingTeam size, inertiaCompensating controls: dual bank authorisation, independent register review, mandatory leave cover, exception reporting

Working a finding properly

A finding that is closed with "corrected" is not closed. Use a four-part closure standard:

  1. Correct the instance. Fix the specific error, including any statutory or employee impact.
  2. Quantify the population. Determine whether the same error exists in other months or other employees. A single-instance claim needs evidence.
  3. Change the control. Describe what will now prevent recurrence, with a named owner and an implementation date.
  4. Test the fix. Re-test after one or two cycles and record the result.

Auditors read closure notes carefully. A note that shows population testing and a control change is treated very differently from a note that says the error was rectified.

Document Retention and Audit Trail

Retention is where readiness quietly fails. Records exist during the year and disappear when the laptop is replaced, the folder is reorganised, or the person leaves.

What to keep

Think in categories rather than files:

  • Employment records: appointment letters, revision letters, role change records, policy acknowledgements, exit documents, settlement files.
  • Payroll outputs: monthly registers, payslips, component-level computation sheets, arrear workings, reimbursement records.
  • Statutory records: registers required for your establishments, challans, returns and acknowledgements, portal correspondence, registration certificates, inspection records.
  • Financial records: payroll journals, GL reconciliations, accrual workings, bank files and confirmations, bank reconciliations.
  • Control evidence: approval matrices, maker-checker sign-offs, access review records, exception logs, off-cycle logs, self-audit reports.
  • Third-party records: contractor compliance documents, consultant agreements, vendor payroll service agreements and their control reports if applicable.

In what form

Electronic is acceptable and increasingly expected, but form matters.

  • Store final outputs as non-editable files where possible. An editable payslip is weak evidence.
  • Keep an original and a working copy separately. Never overwrite an original register with a corrected version; issue a revised version with a version number and a reason.
  • Preserve system audit trails, not just outputs. An audit log that shows who approved what, when, is often more persuasive than the document itself.
  • Maintain a consistent folder and naming convention: entity, year, month, record type. Anyone should be able to find a specific register without asking.
  • If you migrate payroll systems, export historical registers and audit logs in a readable format before decommissioning. This is the single most common cause of an unanswerable diligence question.

For how long

Retention periods for employment, wage, statutory and tax records are prescribed by the applicable statutes and, in several cases, by state rules, and they differ by record type. Do not rely on a rule of thumb. Set retention per record type as required by the applicable statute or state rules, confirm the current requirements with your advisor, and document the basis you have adopted.

Two practical points regardless of the specific periods. First, when a dispute, notice, inspection or investigation is live or reasonably anticipated, suspend routine deletion for the affected records. Second, retention is a floor for compliance but not a ceiling for prudence: diligence processes routinely look back further than the minimum statutory period, and a buyer asking for records you have lawfully destroyed still creates friction. Decide deliberately where you will keep more than the minimum.

Audit trail hygiene

An audit trail is only useful if it is complete, attributed and preserved.

  • Individual logins, always. Shared credentials destroy attribution and are the fastest way to turn a small error into an unexplainable one.
  • Logs should cover master-data changes, payroll runs and re-runs, approvals, payslip generation and release, report exports of sensitive data, and access changes.
  • Logs should be retained at least as long as the underlying records and should be exportable.
  • Test the trail occasionally: pick a change from three months ago and see whether you can reconstruct who made it and on what authority. If you cannot, the trail is decorative.

How to Run a Self-Audit: A Ten-Working-Day Sprint

An internal payroll audit does not need a consultant or a quarter. A focused two-week sprint, run twice a year, will find most of what an external reviewer would find, at a point where you can still fix it quietly.

Before you start

Fix three things: the period under review, the scope, and who signs the report. A typical first sprint reviews the last six months, covers all entities and locations, and reports to the founder or the audit committee. Decide up front that the output is a findings report with owners and dates, not a conversation.

Day 1: Scoping and data pull

Request and receive:

  • Payroll registers for each month in scope, in spreadsheet form.
  • Employee master with all fields, plus the master-data change log for the period.
  • Joiner and leaver lists with dates.
  • Attendance and leave extracts.
  • Challans, returns and acknowledgements for each statutory head.
  • Bank files, upload confirmations and bank statements for the payroll account.
  • Payroll journals and GL extracts for payroll accounts.
  • Policies: leave, reimbursement, notice, loans, variable pay.
  • Approval matrix and current system access list.

If a request takes more than two days to fulfil, that delay is itself a finding. Record it.

Day 2: Analytics on the full population

Before sampling, run tests on 100 percent of the data. These are cheap and catch the highest-value issues.

  • Duplicate bank accounts, PANs, employee IDs, and identical names with different IDs.
  • Employees paid after their exit date, or paid before their joining date.
  • Net pay of zero, negative net pay, or net pay above a defined threshold.
  • Salary increases above a defined percentage between consecutive months.
  • Employees with no statutory deduction where eligibility suggests there should be one.
  • Bank accounts shared across employees.
  • Employees not present in any attendance record but paid a full month.
  • Components paid to only one or two employees (often the location of one-off errors).
  • Round-number payments that recur (a soft indicator of manual entries).

Day 3: Control walkthroughs

Sit with the preparer and walk one full cycle end to end, screen by screen. Do not read the documented process; watch the actual one. Note every point where a control is described but not evidenced, and every workaround people have built because the official process is inconvenient. Workarounds are where risk lives.

Document the walkthrough as a flow with control points marked, and confirm it in writing with the process owner.

Day 4: Sampling design

Use a mix of judgemental and random selection. A workable approach for an SMB:

  • New joiners: pick a sample across the period, weighted towards months with high hiring. A reasonable starting point is 10 to 15 cases or all of them if fewer.
  • Leavers and full-and-final settlements: test at least 10 cases, and all settlements above a value threshold.
  • Salary revisions and arrears: test 10 to 15 cases, including every revision above a defined percentage.
  • Reimbursements: test 20 to 25 claims across categories, weighted to high-value and high-frequency claimants.
  • Regular payroll recomputation: recompute full payslips for 10 to 15 employees across grades, locations and joining patterns.
  • Statutory: test every month for deposit timeliness, and reconcile register to challan to return for at least three months in detail.
  • Bank disbursement: test every month for control total match, and trace three months of bank statements line by line.

Scale the numbers to your headcount. For a company under 100 employees, these samples are a substantial share of the population and that is fine. For a company over 500, increase sample sizes and stratify by location and grade. Document the sampling basis in the report so a later reviewer can assess coverage.

Days 5 to 7: Test execution

Run the tests. For each sample item, record the test performed, the evidence examined, the result, and the file reference. Keep the working papers, not just the conclusions.

Core test steps worth scripting:

  1. Existence: for a sample of paid employees, trace to appointment letter, ID proof, and independent confirmation of engagement from the reporting manager.
  2. Accuracy: recompute gross, each component, statutory deductions and net pay independently from the master and inputs. Compare to the payslip to the rupee.
  3. Authorisation: for each salary change and arrear, trace to an approval document that predates the payment and matches the effective date.
  4. Cut-off: for joiners and leavers near month boundaries, verify the number of paid days against the actual joining and last working dates.
  5. Completeness: agree register totals to the GL and to the bank disbursement for each month, and investigate every difference.
  6. Statutory timeliness: compare deposit dates to applicable due dates for each month and head, and quantify any interest or damages exposure.
  7. Disbursement integrity: match bank file control totals to the approved register and trace credits to the bank statement.
  8. Settlement: recompute full-and-final cases including leave encashment, notice adjustment and recoveries, and verify clearance sign-offs.
  9. Access: compare the current payroll system user list to the active employee list and to the approved role matrix.

Day 8: Root cause and quantification

Convert observations into findings. For each, determine the root cause, the population affected, the financial exposure if any, and the control that failed. A finding without a root cause produces a fix that does not last.

Quantify carefully. Distinguish between confirmed exposure (a computed amount), potential exposure (a range based on the population), and control weakness with no current exposure. Auditors and boards respond very differently to each, and blurring them damages credibility.

Day 9: Draft report and management response

Circulate a draft to the process owners. Their job is to correct factual errors and propose the fix with a date. Your job is to resist fixes that are really promises. "We will be more careful" is not a fix. "The system will block payment where exit date is before pay period end, effective next cycle" is.

Day 10: Finalise, rate and schedule follow-up

Rate findings so attention goes to the right place. A simple three-level rating works: high (financial exposure, statutory breach, or a control that allows undetected payment), medium (control weakness with limited exposure), low (process or documentation improvement).

Set follow-up dates and put them in the control calendar. Findings without follow-up dates reopen at the next audit, unchanged.

Findings template

FieldContent
Finding IDSequential reference for tracking
AreaMaster data / inputs / calculation / statutory / disbursement / accounting / records
ObservationWhat was found, with sample references and dates
Population testedSample size, selection basis, period covered
ExposureConfirmed amount, estimated range, or none identified
Root causeWhy it happened, at the process or system level
Risk ratingHigh / Medium / Low with rationale
RecommendationSpecific control change, not a behaviour request
Management responseAgreed / partially agreed / not agreed, with reasoning
OwnerNamed individual, not a department
Target dateSpecific date
Re-test date and resultFilled after verification

Preparing a Data Room Payroll Pack

When a funding round, acquisition or lender review starts, the payroll pack is usually requested in the first tranche. Preparing it in advance converts a three-week scramble into a one-day upload.

What goes in

Organise by category with a clear index. A workable structure:

1. Organisation and headcount - Headcount by month for the lookback period, split by function, location and employment type. - Current employee list with joining date, designation, location, cost to company and notice period. - Joiner and leaver movement with attrition by month. - Org chart and reporting lines for key roles.

2. Compensation framework - Salary structure and component definitions, with effective dates for any change. - Grade or band structure if one exists. - Variable pay schemes with eligibility, computation and payout history. - Any deferred, retention or long-term incentive commitments, and their documentation. - ESOP scheme documents, grant register, vesting schedule and accounting treatment, if applicable.

3. Payroll records - Monthly payroll registers for the lookback period, in spreadsheet form. - Annual payroll cost reconciled to audited financial statements for each year. - Off-cycle payment log. - Loans and advances register with outstanding balances.

4. Statutory compliance - List of registrations by law, state and establishment, with certificates. - Status summary per registration: deposits current, returns filed, any defaults with quantified exposure. - Challans and return acknowledgements for the lookback period, filed by period. - Any notices, inspections, assessments or proceedings, with current status and management assessment. - Contractor compliance documentation and the list of contractors engaged.

5. Contracts and policies - Standard employment contract template. - List and copies of non-standard contracts (founders, senior hires, fixed-term, retention agreements). - Consultant and contractor agreements with classification rationale. - Current HR policies with approval dates.

6. Controls and governance - Approval matrix. - Description of the payroll process and systems used. - Access control list and review records. - Most recent internal payroll audit report and status of open findings.

How to present it

  • One index file listing every document, the period it covers, and where it sits. Buyers judge organisation quality within the first hour.
  • Machine-readable where possible. Registers as spreadsheets, not scanned PDFs. Diligence teams run their own analytics and will ask for source data anyway.
  • Consistent naming. Entity, period, document type. Avoid file names that only make sense to the person who created them.
  • A short covering memo that explains the payroll process, the systems, the headcount trend, any known issues and what has been done about them. Disclosing a known issue with a quantified exposure and a remediation plan is far better than having it discovered.
  • A single point of contact who can answer questions and knows where everything is.

The disclosure judgement

Founders often ask whether to disclose a compliance gap proactively. The general pattern is that issues found by the buyer cost more than issues disclosed by the seller, because discovery raises questions about what else is undisclosed. Discuss specific disclosure decisions with your legal and financial advisors, since the right answer depends on materiality, contractual terms and the deal structure. But as a default operating posture, know your own gaps before anyone else does.

How Payroll Software Changes the Control Picture

Software does not create controls by itself. A badly configured system with everyone on an admin role is weaker than a careful spreadsheet process run by a disciplined person. But the right system changes what is possible, particularly on the three things that are genuinely hard to do manually: attribution, immutability and consistency.

What software does well

Attribution. Individual logins and automatic change logs answer "who changed this and when" without anyone having to remember. In a manual process, this information simply does not exist after the fact. This is the single biggest audit advantage, because most audit disputes are about what happened, not about what the rule was.

Immutability of outputs. System-generated payslips and registers that cannot be edited after generation remove an entire class of doubt. When a payslip can be regenerated identically from the system at any time, it becomes evidence rather than a document someone produced.

Role-based access. Enforcing that the preparer cannot approve and the approver cannot change master data is straightforward in a system and nearly impossible in a shared folder. For small teams, this is how you get segregation of duties without extra headcount.

Consistency of calculation. A configured rule applies the same way to every employee every month. Spreadsheet formulas drift: a row is inserted, a range is not extended, a copy-paste breaks a reference. Consistency is also what makes year-on-year comparison meaningful for auditors.

Automated registers and returns. Generating statutory registers and return-ready files from the same data that produced the payslip eliminates the reconciliation gap between what you paid and what you reported. That gap is the source of a large share of statutory findings.

Exception reporting as standard. Post-exit payments, duplicate accounts, abnormal variances and missing statutory identifiers can be surfaced every cycle automatically rather than discovered at audit.

What software does not fix

  • Bad inputs. If attendance is unreliable, automation makes wrong payments faster and more consistently.
  • Undocumented policy. A system encodes decisions; it does not make them. If nobody has decided how a component is treated, the configuration will encode someone's guess.
  • Approval theatre. A workflow with one person holding all roles is a workflow in name only.
  • Missing history. A system implemented last year does not produce audit trails for the two years before that. Migrate historical data deliberately.
  • Configuration drift. Rules changed mid-year without documentation create exactly the inconsistency you were trying to avoid. Treat configuration changes as change-managed events with approval and a record.

Questions worth asking about any payroll system

If you are evaluating software with audit readiness in mind, the useful questions are not about features but about evidence:

  1. Can I export a complete master-data change log for any period, showing old value, new value, user and timestamp?
  2. Can a payslip or register be edited after generation, and if a correction is needed, does the system preserve the original?
  3. Can roles be configured so the person who processes payroll cannot approve or release payment?
  4. Are statutory registers generated from the same data as payslips, or maintained separately?
  5. Can I reproduce a payroll run from three years ago exactly as it was, including the rules in force then?
  6. What happens to my data and audit logs if I stop using the product, and in what format can I export them?
  7. Does the system log report exports of sensitive data, and can I see who downloaded salary data and when?

The answers to questions 1, 2 and 5 tell you most of what you need to know about whether the product was built with audit in mind.

FAQ

How often should an SMB run an internal payroll audit?

Twice a year is a reasonable default for a company with stable operations, with a lighter quarterly review of high-risk areas such as statutory deposit timeliness, post-exit payments and off-cycle payments. Run an additional sprint when something structural changes: a new payroll system, a new state of operation, an acquisition, a change in the payroll owner, or a period of rapid hiring. If the payroll team has turned over, audit before the outgoing person's knowledge leaves with them.

We have only two people in HR and finance. Is real segregation of duties possible?

Yes, in a reduced form. Split preparation from release: one person processes payroll and cannot move money, the other reviews and releases and cannot change master data. Add dual bank authorisation with a founder or director as second authoriser, and give that person a short, defined review rather than a vague one. Where a single person genuinely does everything, compensating controls carry the load: automated exception reports, an independent monthly review of the register by someone outside payroll, mandatory leave during which another person runs a cycle, and a founder-level check of the bank statement against the payroll total.

What is the fastest way to find ghost employees?

Run three tests on the full population rather than sampling. First, match every paid employee to an active entry in an independent system such as email, access control or the attendance system, and investigate anyone paid but absent from all of them. Second, look for shared bank accounts and duplicate PANs. Third, compare the paid list against the joiner and leaver register, flagging anyone paid after their exit date or before their joining date. Then have reporting managers confirm their team lists in writing, ideally without seeing the payroll list first. The written confirmation is what turns an analytic result into audit evidence.

An auditor asked for our payroll-to-GL reconciliation and we do not have one. What do we do now?

Build it for the current year first, month by month: total earnings, total deductions, net pay, employer statutory contributions, each mapped to specific GL accounts. Then reconcile each month's payroll register totals to the GL movement, listing every difference and its cause. Common causes are manual journals, off-cycle payments recorded only in the bank, provisions posted outside payroll, and cost centre reclassifications. Once you have the current year, work backwards if the auditor's scope requires it. Going forward, generate the journal from the payroll system so the reconciliation becomes a check rather than an investigation.

How do we handle a statutory deposit that was made late?

Identify the specific periods and heads affected, compute the delay in days, and quantify the interest or damages that may apply under the relevant law, confirming the current computation basis with your advisor. Make good the deposit and the additional amounts where required. Record the event in an exception log with the root cause. Then fix the cause, which is usually approver dependency or the absence of a reminder with a buffer before the due date. For the audit file, a documented, quantified, remediated late deposit is a manageable finding. An undocumented one that the auditor discovers is a much larger conversation about control.

What payroll records does a buyer typically ask for first in due diligence?

Usually headcount by month with joiners and leavers, current employee list with compensation, monthly payroll registers for the lookback period in spreadsheet form, a statutory compliance status summary per registration, copies of challans and return acknowledgements, standard and non-standard employment contracts, consultant and contractor arrangements with classification rationale, and disclosure of any notices or proceedings. Expect them to reconcile payroll cost to your audited financials and to test classification of contractors. Having these assembled and indexed before the process starts is the difference between diligence taking days and taking weeks.

How long should we keep payroll records?

Retention periods are set by the applicable statutes and, for several record types, by state rules, and they vary by the type of record. Set your retention schedule per record type against the current requirements applicable to your establishments, and confirm with your advisor rather than adopting a single blanket period. Two practical rules apply regardless: suspend routine deletion for any records connected to a live or reasonably anticipated dispute, notice or inspection, and consider keeping certain records longer than the statutory minimum because diligence processes routinely look further back than the law requires.

Should we get an external payroll audit or is a self-audit enough?

A well-run self-audit finds most issues and costs far less, so start there and run it seriously with a written report and tracked findings. Bring in an external reviewer in specific situations: before a fundraise or sale, after discovering a material issue, when entering new states or engaging contract labour at scale, when the payroll owner changes, or when the board wants independent assurance. External reviewers also add value on classification questions and statutory interpretation, which is where internal teams are most likely to have an unexamined assumption.

Does outsourcing payroll to a vendor transfer the compliance risk?

No. Outsourcing transfers work, not accountability. The employer generally remains responsible for statutory compliance regardless of who processes the payroll. Treat the vendor relationship as a controlled process: define responsibilities in the contract, require timely delivery of registers, challans and acknowledgements, review their output with your own maker-checker script, retain copies of all records in your own systems, and confirm you can extract your full historical data if you change vendors. Ask whether the vendor can produce audit trails at the level of individual changes, because "the vendor did it" is not an answer an auditor accepts.

Putting It Together

Payroll audit readiness is not a binder you produce once. It is a small set of habits that make evidence a by-product of normal work: named owners for each control, approvals that exist before the payment rather than after the question, records that are generated by a system rather than assembled from memory, and a twice-yearly self-audit that finds your problems before someone else does.

Start with the three moves that give the most coverage for the least effort. Run the full-population analytics from Day 2 of the sprint on your last six months of payroll data this week. Write the one-page approval matrix and get it signed. Put the control calendar into whatever tracker your team already uses, with owners and dates. Those three take a few days and will tell you honestly how ready you are.

Then work down the payroll audit checklist section by section, fixing the evidence gaps rather than the symptoms. The checklist is deliberately written around evidence because that is what an audit consumes. A control you cannot evidence is a control you do not have.

If your payroll currently runs across spreadsheets, email approvals and a shared login, the hardest gaps to close are attribution and immutability, and those are the ones software genuinely solves. CozyHR keeps master-data change logs with user and timestamp, generates payslips and statutory registers from the same run so they cannot drift apart, enforces role-based access so the person who processes payroll is not the person who releases it, and produces the registers and exception reports that make up most of a payroll audit file. If you want to see what your next audit file would look like coming out of a system rather than out of a folder, run one month of your payroll in CozyHR alongside your current process and compare the evidence each one produces.

This article is general guidance for Indian employers and is not legal, tax or accounting advice. Statutory rates, thresholds, forms, due dates and retention requirements change and vary by state and establishment. Verify current requirements with the relevant authorities and take professional advice on your specific facts.