CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Blog
PayrollInternal ControlsPayroll FraudCompliance

Payroll Fraud Prevention: Spot Ghost Employees & Fix Gaps

How to detect and prevent ghost employees, bank detail tampering and unauthorised payroll changes with practical internal controls for Indian SMBs.

CozyHR editorial team 07 October 2026 32 min read
CozyHR Blog
Payroll Fraud Prevention: Spot Ghost Employees & Fix Gaps

Payroll is the one process in a growing company where money leaves the bank account on a fixed date, every month, in large amounts, and mostly on trust. That is exactly why payroll fraud prevention deserves a place on the agenda of every founder, HR head and finance lead in India, not just those running large enterprises. A 40-person startup in Pune and a 400-person manufacturer in Coimbatore face the same basic exposure: a spreadsheet or software system that decides who gets paid, how much, and into which account, usually operated by a very small number of people.

The uncomfortable truth is that most payroll fraud in small and mid-sized businesses is not sophisticated. It is not hacking. It is a salary that kept running after someone left, a bank account number changed on the last working day before payroll, a reimbursement claim backed by a bill that was never real, or a "temporary" access given to one person that nobody ever revoked. These are control failures, not technology failures, and they are fixable with process, discipline and sensible tooling.

This guide walks through the main fraud patterns, shows how to spot them, and then builds a practical internal control framework you can implement in stages in 2026, whether you run payroll on a spreadsheet, a legacy desktop package or a modern HRMS. Where statutory points come up (PF, ESI, TDS, labour code compliance and so on), we keep the guidance general. Rules and thresholds change, so always verify current requirements with your auditor, a practising professional or the official government portals before you act.

Why payroll is a fraud magnet in Indian SMBs

Before looking at controls, it helps to understand why payroll attracts fraud in the first place. Several features of the Indian SMB environment make it especially exposed.

Concentration of duties. In many companies one person collects attendance, calculates salary, prepares the bank upload file and sometimes even uploads it to the bank. When a single person controls the whole chain, nobody else is positioned to notice an anomaly.

Cash-heavy and informal workforces. Contract labour, daily wagers, site staff and field teams often come and go quickly. Records are patchy, KYC may be incomplete, and headcount is fluid. Fraudsters thrive where the baseline is unclear.

Rapid growth. Hiring fast means onboarding shortcuts. Documents get collected "later", approvals happen over chat, and the employee master data becomes a mix of verified and unverified records.

Trust culture. In founder-led businesses, the payroll executive may be a long-serving, well-liked person. Trust is valuable, but a control environment that depends on trust alone fails the day trust is misplaced, or the day a trusted person's email is compromised by an outsider.

Spreadsheet dependence. Excel files are easy to edit silently. There is often no audit trail, no version history that anyone reviews, and no separation between the person who edits and the person who approves.

Salary through bank transfer files. Most Indian employers pay through bulk upload (NEFT/RTGS/IMPS files or bank portal formats). Once the file is uploaded and authorised, the money moves quickly and recovery becomes difficult.

None of this means your people are dishonest. It means your system makes dishonesty cheap and detection slow. Good payroll internal controls flip this: they make fraud expensive and detection fast, and, just as importantly, they protect honest employees from false suspicion.

The four big payroll fraud patterns

Most payroll fraud falls into a handful of patterns. Understanding the mechanics of each makes the controls in later sections feel logical rather than bureaucratic.

1. Ghost employees

A ghost employee is a person on the payroll who does not actually work for the company. Variants include:

  • Fictitious person. A record created from scratch, with an invented name and a bank account controlled by the fraudster or an accomplice.
  • Departed employee still being paid. The person resigned or was terminated, but the record stays active and the salary continues to be credited, either to the original account or, worse, to a quietly modified one.
  • Duplicate record. A real employee entered twice, with different employee codes, so that a second salary is routed elsewhere.
  • Inflated headcount at sites. Common with contract and muster-roll labour, where supervisors add names that do not exist and pocket the wages.

Ghost employees persist because nobody looks at the full list with fresh eyes. Payroll teams compare this month to last month at the total level ("payroll is up two percent, fine") and never inspect individual lines.

Typical warning signs:

  • An employee with no attendance or leave history, no email activity, no assets issued and no manager who can describe their work.
  • Two employees sharing a bank account number, PAN, phone number or address.
  • Employee records created and paid in the same cycle without a matching offer letter or onboarding checklist.
  • Salary continuing after a last working day recorded in the exit tracker.
  • Bank accounts that belong to a name different from the employee name.

2. Unauthorised changes to pay

This is the quiet cousin of ghost employees: real employees, but with altered pay. It includes:

  • Increasing a friend's or relative's salary, or one's own, outside the appraisal cycle.
  • Adding unapproved allowances, special bonuses or arrears.
  • Reducing deductions such as loan EMIs, advance recoveries or professional tax.
  • Manipulating attendance or loss-of-pay days so that deductions do not apply.
  • Overstating overtime or shift allowances.
  • Changing tax declarations or regimes without proof, which affects TDS and can create compliance exposure later.

The root cause is almost always the same: the person who has access to change data also has the power to process payroll, and no independent person compares the final payroll against approved inputs.

3. Bank detail tampering

Bank detail tampering happens in two flavours. The first is internal: someone with payroll access changes an employee's bank account to one they control, pays the salary, and changes it back. Because the change is reverted, a casual review of the master data shows nothing wrong.

The second is external: a fraudster impersonates an employee over email or a messaging app and asks HR to "update my bank account, my old one is frozen". Sometimes this follows a genuine email compromise or a leaked employee list. If HR updates the account on the strength of a message, the next salary lands with the impersonator.

Both are driven by the same weakness: bank details can be changed without independent verification, and nobody reviews bank-change logs before payment.

4. Fake and inflated reimbursements

Reimbursements are the most common everyday leak, because the amounts are small enough to escape attention and the volume is large. Patterns include:

  • Fabricated bills, edited invoices or bills generated from template websites.
  • The same bill submitted twice, once to the company and once to a client, or twice in different months.
  • Personal expenses claimed as business travel, fuel or client entertainment.
  • Inflated amounts with real but lower-value receipts.
  • Claims splitting, where a large expense is broken into smaller claims below an approval threshold.
  • Collusion between an employee and an approving manager.

Because reimbursements often flow through payroll in India (travel, fuel, phone, internet, medical, LTA-type components, and so on), they deserve the same discipline as salary.

What fraud looks like in numbers: three illustrative scenarios

The following examples use invented figures purely for illustration. They are not drawn from real cases or statistics.

Scenario A: the ghost who survived four months (illustrative)

A 120-person services company has a monthly net payroll of about Rs 62 lakh. An operations executive resigns and serves notice. The exit is communicated verbally; the HR coordinator forgets to mark the record inactive. The payroll executive, who prepares the bank file, notices that the employee is still in the list, quietly updates the bank account to a personal one, and continues paying a net salary of Rs 38,000 each month.

Over four months the leakage is Rs 1.52 lakh. Total payroll moved by less than one percent each month, so the monthly "is this reasonable?" check never flagged it. It was discovered only when the statutory auditor asked for the exit list to be reconciled with the paid list.

The lesson: a total-level review is not a control. A line-level reconciliation of joiners, leavers and bank changes is.

Scenario B: the quiet bank account switch (illustrative)

An HR administrator receives a WhatsApp message from a number saved as a senior sales manager: "My salary account has a problem, please update to this new account before this month's payroll." The administrator updates the record. The message was from a person who had obtained the manager's name and designation from a public professional profile. The salary of Rs 1.1 lakh went to the wrong account before the real manager complained.

The lesson: a change request received on a casual channel must never be actioned without verification through a known, independent channel.

Scenario C: split reimbursements (illustrative)

A company requires manager approval for claims above Rs 5,000 and finance approval above Rs 25,000. A sales executive submits fuel and client-meeting claims of Rs 4,800 to Rs 4,950, several times a month, some with near-identical bill formats. Over a quarter this adds up to roughly Rs 1.2 lakh, and only a few were ever examined.

The lesson: thresholds without aggregation rules invite structuring. Controls must look at totals per employee per period, not only at single claims.

Principles behind strong payroll internal controls

Before we get into step-by-step implementation, five principles underpin everything that follows. If you remember nothing else, remember these.

  1. Segregation of duties. The person who creates or edits data must not be the person who approves it, and neither should be the person who releases the money.
  2. Least privilege. Every user gets only the access their role needs, for only as long as they need it.
  3. Independent verification. Sensitive changes (bank, salary, joiners, leavers) are confirmed through a channel the requester does not control.
  4. Audit trail. Every change is logged with who, what, when, old value and new value, and somebody actually reviews the log.
  5. Detective back-ups for preventive controls. Assume a preventive control will occasionally fail, so layer in reports and reconciliations that would catch the failure within one pay cycle.

A useful framing is the prevent, detect, respond triad. Prevent means making fraud hard. Detect means making it visible quickly. Respond means knowing exactly what you will do when something looks wrong. Most SMBs invest only in the first, partially, and ignore the other two.

Step 1: Map your payroll process and its risk points

You cannot protect a process you have not drawn. Spend an hour with HR, finance and the payroll team and write down each stage, who owns it, and what could go wrong.

A typical monthly payroll runs through these stages:

  1. Employee master data (joiners, leavers, bank details, tax details)
  2. Attendance, leave and overtime inputs
  3. Salary revisions, bonuses, arrears and one-time payments
  4. Reimbursement and expense claims
  5. Payroll computation and review
  6. Approval and bank file generation
  7. Payment release
  8. Statutory filings and payslips
  9. Post-payment reconciliation and records

For each stage, ask three questions: who can change data here, who checks their work, and what evidence remains afterwards? The answers will immediately reveal your weakest points. Many companies find that stages 1, 3 and 6 are controlled by the same person.

Sample risk map

Payroll stageKey fraud riskTypical weak controlStronger control
Employee masterGhost or duplicate employeesAnyone in HR can add recordsJoiner needs approved requisition and documents; second person activates
Bank detailsAccount swapped to fraudster accountChange accepted on email or chatCall-back verification, cooling-off period, change report reviewed before payment
AttendanceLOP days suppressed, overtime inflatedManual sheet edited by payrollAttendance locked by managers; edits after lock need approval
Salary revisionsUnapproved raisesPayroll executive keys values from a mailRevisions approved in-system by HR head and finance; effective-date logged
ReimbursementsFake or duplicate billsScanned bills reviewed by one managerMandatory attachments, duplicate checks, aggregation limits, sample audit
Bank fileFile altered after approvalFile edited in Excel before uploadSystem-generated file with checksum; approver sees totals and variances
ExitDeparted employee still paidExit tracked in a separate sheetFull and final settlement triggers automatic deactivation

Keep this map. It becomes the backbone of your control documentation and is the first thing an auditor or investor will want to see.

Step 2: Lock down employee master data

The employee master is the foundation. If it is clean and well governed, every later stage is safer.

Controls for joiners

  • No payroll record without an approved requisition and signed offer. The record in payroll should always trace back to a hiring approval.
  • Collect KYC at onboarding, not "later". Identity proof, address proof, PAN, bank proof (cancelled cheque or bank statement page showing name and account number), and statutory identifiers as applicable. Verify current document requirements with your advisor.
  • Name match. The bank account holder name should match the employee's legal name. Mismatches need written explanation.
  • Uniqueness checks. The system should flag duplicate PAN, bank account, mobile number or email.
  • Two-person activation. One person creates the record; a different person, ideally outside the payroll team, approves it.
  • First-day confirmation. The reporting manager confirms that the person joined. No confirmation, no first salary.

Controls for leavers

Leavers are the single most important area for ghost-employee prevention.

  • Tie the last working day to an exit workflow that triggers automatically from resignation approval.
  • Require sign-off from IT (access removed), admin (assets returned), finance (dues cleared) and the manager before final settlement.
  • On the last working day, the system should stop further salary computation unless full-and-final is open.
  • Run a monthly leaver reconciliation: list everyone who exited in the last 90 days and confirm none appears in the salary register after their last working day.

Controls for contract and site labour

  • Maintain a separate, supervisor-certified muster for each site and period.
  • Require periodic physical or biometric headcount verification by someone outside the site supervisor's reporting line.
  • Pay contractor workers through the contractor's invoice where the law and your contract structure allow, and confirm the contractor's compliance filings. Verify applicable contract labour requirements with your legal advisor.

Quarterly headcount confirmation

Once a quarter, send each department head the list of people paid under their cost centre and ask them to confirm, in writing, that each person is working. It is a simple exercise and it is surprisingly effective at flushing out stale records.

Step 3: Protect bank details like cash

Bank detail changes deserve their own procedure because the consequences of a single mistake are immediate and hard to reverse.

A recommended bank-change procedure

  1. Request through the employee's authenticated self-service login only. No changes on email, chat or phone. If an employee cannot log in, HR raises a ticket after verifying identity in person or on a video call.
  2. Proof upload. The employee uploads a cancelled cheque or a bank statement or passbook page that shows name, account number and IFSC.
  3. Automated validation. Check IFSC format and, where your bank offers it, run a penny-drop or name-verification check so that the account holder name is confirmed by the bank.
  4. Independent approval. A person outside payroll approves the change. For senior roles or large salaries, the approver is a finance head.
  5. Call-back verification. Someone calls the employee on the phone number already on file (not a number supplied in the request) and confirms the change.
  6. Cooling-off rule. A changed account is not used for the very next payroll unless approved by two people; if the change falls within a few days of payroll cut-off, pay by the old account or hold the amount for a short, defined period.
  7. Notification. The system sends a message to the employee's previous registered email and mobile saying the bank account has been changed, and how to report it if they did not do it.
  8. Review before release. The payroll approver receives a "bank changes this cycle" report and signs it off.

Bank-change report: what to review

ColumnWhy it matters
Employee and codeIdentify who is affected
Old and new account (masked)Show what changed without exposing full numbers
Changed by and approved byConfirms segregation of duties
Date and time of changeLate-night or last-minute changes are red flags
Proof attachedConfirms evidence exists
Verification statusPenny-drop or call-back outcome
Employee notifiedConfirms the alert went out

Extra checks on the payment file

  • Compare the number of accounts in the bank file with the number of payable employees.
  • Flag any account number that appears more than once.
  • Flag payments to accounts where the bank-returned beneficiary name differs materially from the employee name.
  • Reconcile the file's total with the approved payroll register before upload. Any difference must be explained.
  • Keep the upload and the authorisation separate, using the bank's maker-checker feature. One person uploads (maker), another authorises (checker). Never share bank portal credentials.

Guarding against impersonation

Train HR and payroll staff to recognise social-engineering patterns: urgency ("I need this before payroll today"), unusual channels, new phone numbers, or a senior person asking for an exception. A one-line policy helps enormously: "We never change bank details on a message. Ever." Make it a rule everyone, including the founder, is expected to follow.

Step 4: Control salary changes and payroll inputs

Pay changes should flow through a structured approval chain, not through whoever happens to have edit rights.

Salary revision workflow

  1. The line manager proposes a revision with justification.
  2. HR validates against grade, band and budget.
  3. The HR head or CHRO approves; for amounts above a threshold, finance or the founder also approves.
  4. The approval is attached to the record in the system.
  5. A person other than the approver and the payroll processor enters or imports it.
  6. The change becomes effective from the stated date, with the old value retained in history.

Rules for one-time payments

Bonuses, spot awards, arrears, settlement amounts and incentives are favourite channels for abuse. Insist on:

  • A written approval before the payment is entered.
  • A reason code (for example, "performance bonus Q2", "notice pay recovery waiver").
  • A limit above which two approvals are needed.
  • A review of all one-time payments for the month in a single report.

Attendance and overtime

  • Managers approve attendance and overtime in the system. Payroll should not be able to alter either.
  • Lock attendance on a cut-off date. Edits after cut-off need a documented exception.
  • Compare overtime against shift rosters and biometric or access logs.
  • Report the top overtime earners every month and check that the pattern is plausible.

Tax declarations and deductions

  • Investment declarations and regime choices should be done by the employee in self-service, not keyed in by payroll.
  • Proof verification should be done by someone other than the person processing payroll, where practical.
  • Loan and advance recoveries should be set up with approval, and any change to an EMI schedule should show in an exception report.

Tax rules and regime defaults are updated regularly in India. Confirm the current position with your tax advisor or official sources and make sure your system configuration reflects it.

Step 5: Tighten reimbursement controls

Reimbursements need to be tied to policy and evidence, with checks that scale.

Build a clear policy

A good reimbursement policy answers these questions in plain language:

  • Which expenses are allowed, and what are the category-wise limits?
  • What proof is needed? (Original invoice, payment proof, travel tickets, mileage log.)
  • Within how many days of the expense must the claim be submitted?
  • Who approves and at what threshold?
  • What happens if the claim is found to be false? (Recovery, disciplinary action.)

Many companies discover that most disputes arise because the policy never said what "reasonable" means. Spell it out with numbers.

Practical controls

  • Mandatory attachments. The claim cannot be submitted without a document.
  • Duplicate detection. Flag claims with the same date, amount, vendor and invoice number, even across different employees.
  • Aggregation rules. Apply thresholds on monthly and quarterly totals per person and per category, not just per claim.
  • Approver independence. A manager cannot approve their own claims, and approvals for a manager's claims go to their superior or finance.
  • Vendor and invoice validation. For high-value claims, verify the vendor details and tax invoice information (for example, GST details where the claim is meant to carry them). Check current GST invoice requirements with your advisor.
  • Round-number and pattern analysis. Many claims ending in round numbers or just below a threshold deserve a look.
  • Random sample audit. Each month, finance pulls a random sample of approved claims and calls vendors or verifies originals.
  • Time and place sense-check. A fuel claim in a city the employee was not in, or a hotel bill dated while they were on leave, should be caught by comparing claims with attendance and travel records.

Worked example: threshold design (illustrative)

Suppose the policy allows a monthly phone and internet reimbursement of up to Rs 1,500, a fuel claim of up to Rs 6,000 for field staff, and client-entertainment claims with pre-approval above Rs 3,000.

ObservationPossible readingSuggested action
Employee claims Rs 1,499 phone reimbursement every month, all different vendorsLikely pattern worth checking; invoices may be templatedRequest original statements for a sample month
Fuel claim Rs 5,950 across 30 days, including weekends and leave daysCross-check with attendance and locationAsk for log and explanation
Three client-lunch claims of Rs 2,950 each in one weekPossible splitting below pre-approval limitAggregate and apply pre-approval rule
Same invoice number appears in two employees' claimsPossible duplicate or collusionReject both; escalate to finance

The goal is not to treat every claim as suspicious. It is to make careless or dishonest claiming riskier than honest claiming, while keeping the honest majority's experience smooth.

Step 6: Design roles, access and approvals (segregation of duties)

Now bring the above together into a role design. For a typical 50 to 300 person Indian company, a sensible split looks like this.

RoleCan doCannot do
HR operationsCreate joiner records, update personal data, manage exitsApprove their own entries, change salary, release payments
Payroll executiveProcess payroll, prepare registers and filesAdd or edit employees, change bank details or salary structures, approve payroll
HR headApprove joiners, salary changes, exitsProcess payroll, authorise bank payments
Finance managerReview payroll variances, approve payroll, authorise bank paymentEdit employee master or attendance
Reporting managerApprove attendance, leave, overtime, reimbursementsEdit payroll or bank details
Employee (self-service)View payslips, submit declarations and claims, request bank changeChange anything that bypasses approval
Auditor / read-onlyView reports and audit logsChange any data

Practical rules for access

  • Named accounts only. No shared logins, ever.
  • Multi-factor authentication for all payroll and bank users.
  • Joiner-mover-leaver reviews for system access, so that a person who changes roles does not keep their old powers.
  • Quarterly access review. The HR head lists every user with payroll-related permissions, and signs off or removes them.
  • Emergency access. If one person is on leave, delegate formally and time-box it, rather than sharing a password.
  • Small teams. If you have only one payroll person, you cannot get full segregation, so compensate with a monthly review by a senior finance person or an external professional who checks the exception reports.

Step 7: Build a monthly detective routine

Preventive controls fail sometimes. A detective routine, run every cycle before payment is released, makes sure failures are short-lived. Here is a checklist you can adopt as-is.

The pre-payment review checklist

  1. Headcount bridge. Opening headcount + joiners - leavers = closing headcount. Tie it to the number of payslips.
  2. Joiner list. Each joiner has an approved requisition, offer letter, KYC and manager confirmation.
  3. Leaver list. Each leaver has a last working day and no salary beyond the permitted full-and-final.
  4. Bank-change report. Reviewed and signed off, as described above.
  5. Salary-change report. Every change matches an approval.
  6. One-time payments. Every item matches an approval and reason code.
  7. Variance analysis. Compare each employee's net pay with the last month, and investigate those above a threshold such as 10 percent unless explained by an approved change.
  8. Zero and negative pay. Check for unexpected zero or negative net pay, which can indicate a manipulated deduction or a missing component.
  9. Duplicates. No duplicate bank accounts, PAN, mobile or email.
  10. Statutory reasonableness. PF, ESI, professional tax and TDS amounts look consistent with salary levels and applicable rules. Verify current rates and thresholds with official sources.
  11. Bank file total. Matches the approved payroll register.
  12. Sign-offs. Prepared by, reviewed by, approved by, with date and time.

A worked variance example (illustrative)

Imagine the reviewer sees this extract:

EmployeeLast month net (Rs)This month net (Rs)ChangeApproved change on file?
A54,20054,2000 percentNot needed
B71,00071,0000 percentNot needed
C38,50052,900+37 percentNo
D46,80046,8000 percentNot needed
E62,30041,000-34 percentYes, LOP of 9 days

Row C is the one to investigate: a jump of Rs 14,400 without an approval. It might be an honest data-entry error, an unapproved arrears payment, or an inflated allowance. In every case the correct action is the same, hold payment for that line, ask the originator for the approval, and release only after the answer is documented. Row E is a decrease, but there is a recorded reason, so the reviewer only needs to confirm the LOP aligns with attendance.

Analytics that catch what eyes miss

Even simple spreadsheet or system reports reveal anomalies:

  • Employees paid with no attendance or leave records in the month.
  • Employees with salary above their grade band.
  • Employees whose only login or activity is the payroll module.
  • Accounts credited with salaries from two different employee codes.
  • Reimbursement totals concentrated among a few approvers.
  • Payments released outside the normal date or time window.
  • Sudden growth in contract or temporary staff without a matching approval.

Review these quarterly even if you do nothing else, and every month if your headcount is above a few hundred.

Step 8: Create an audit trail that people really review

An audit trail is only useful if it is complete, tamper-resistant and read. Make sure your system, or your spreadsheet process, records:

  • Who made each change (a named user, not a shared one).
  • What was changed: field, old value, new value.
  • When it happened, with date and time.
  • Why it happened: a reason or an approval reference.
  • Who approved it and when.

Then define who reviews what, and how often:

Log or reportReviewerFrequency
Bank-detail change logFinance managerEvery payroll cycle
Salary and allowance change logHR headEvery payroll cycle
New joiners and leaversHR head and financeEvery payroll cycle
User access and role changesIT / HR headQuarterly
Reimbursement exceptionsFinanceMonthly
Failed or reversed paymentsFinanceEvery payroll cycle
Payroll-file edits after approvalFinance head or founderEvery payroll cycle

If your payroll lives in Excel, protect files with passwords and version control, store them in a restricted shared location rather than on personal drives, disable editing after approval, and keep the approved version in a read-only format. Understand that this is weaker than a system-enforced audit trail, which is one of the strongest arguments for moving to a purpose-built HRMS as you grow.

Step 9: Strengthen the technology and data-protection layer

Payroll data includes identity documents, bank accounts, salaries and tax information. In India, handling of personal data is increasingly governed by data-protection law. The specifics and the compliance timelines continue to evolve, so check the current position with a qualified professional. Regardless of the legal detail, good practice includes:

  • Role-based access and multi-factor authentication.
  • Encryption of data at rest and in transit.
  • Masked display of sensitive fields, such as showing only the last four digits of an account number.
  • Secure sharing. Never send payroll files or payslips as plain email attachments to personal addresses, and avoid forwarding them over messaging apps.
  • Backups and recovery tested periodically.
  • Vendor diligence. If you use a cloud HRMS or an outsourced payroll provider, ask about their access controls, logging, incident handling and data location, and put the key expectations in the contract.
  • Device hygiene. Payroll staff should use managed devices with updated software and without unnecessary browser extensions.
  • Phishing awareness. Run short, regular training sessions with realistic examples of salary-related scams, such as fake payslip links or "update your bank details to receive salary" messages.

Step 10: Prepare an incident response plan

Even good controls cannot promise zero fraud. What distinguishes mature companies is how they respond. Write a one-page plan and keep it where the right people can find it.

When you suspect payroll fraud

  1. Contain. Stop the next payment run for the affected record. If a payment has been initiated, contact your bank immediately and ask about recall or hold options. Speed matters; do not wait for certainty.
  2. Preserve evidence. Take a copy of logs, emails, bank files and the relevant database entries. Restrict access to those who need it. Do not let the suspect person clean up.
  3. Limit knowledge. Share details only with a small group: founder, HR head, finance head, legal counsel.
  4. Investigate fairly. Gather facts before drawing conclusions. Involve HR and, where appropriate, an independent investigator. Follow your disciplinary policy and principles of natural justice.
  5. Recover. Evaluate recovery through settlement, deductions (only where lawful and consented, so check applicable wage and labour rules) or legal remedies.
  6. Report where required. Depending on the nature and amount, you may need to inform your bank, your auditors, your board or investors, and, for criminal matters, the police or cyber-crime authorities. Take advice from your legal counsel on what applies to you.
  7. Fix the control. Every incident should end with a short root-cause note and a change in process.
  8. Communicate carefully. Staff generally need to know that a control was strengthened, not the details of the person involved.

Do not accuse, dismiss or publicly shame anyone before the facts are established. A wrongful accusation can cause more damage than the fraud itself.

A 30-60-90 day implementation roadmap

If this feels like a lot, sequence it. Here is a pragmatic plan for a company starting from a weak baseline.

First 30 days: stop the biggest leaks

  • Write the one-line policy: no bank changes on messages.
  • Run a full list reconciliation: active employees vs HR records vs managers' confirmation.
  • Remove or deactivate stale employees and shared logins.
  • Separate the bank "maker" and "checker" roles.
  • Start the pre-payment checklist, even in a spreadsheet.
  • Add duplicate checks on bank account, PAN and mobile.

Days 31 to 60: build the process

  • Document the payroll process map and risk table.
  • Implement approval workflows for joiners, leavers, salary changes and bank changes.
  • Publish the reimbursement policy and thresholds with aggregation rules.
  • Set up the monthly reports for changes, exceptions and one-time payments.
  • Train HR, payroll and finance teams on the new procedures and on social-engineering red flags.

Days 61 to 90: embed and test

  • Run the first quarterly access review and headcount confirmation.
  • Perform a sample audit of reimbursements and a test of the bank-change procedure, for example by having a trusted colleague attempt a simulated unverified change.
  • Review the incident response plan with a tabletop exercise.
  • Decide whether your current tools can enforce these controls, and plan any migration.

What to measure

Track a few simple indicators, quarter on quarter:

MetricWhat a healthy trend looks like
Bank changes approved with full verificationClose to 100 percent
Payroll corrections after releaseFalling
Days between exit and system deactivationFalling towards zero
Reimbursement claims rejected or amended on reviewStable or modestly falling as policy awareness grows
Exceptions closed within the cycleClose to 100 percent
Users with payroll permissionsStable, with every user justified

Do not turn these into a target that people game. Use them to see where your process needs attention.

Common mistakes to avoid

  • Treating payroll controls as an auditor's problem. Auditors test controls once a year. Fraud happens every month.
  • Relying only on trust or tenure. Long-serving staff are often the ones with the broadest access and the least supervision.
  • Reviewing totals, not lines. Total payroll can stay flat while individual lines are manipulated.
  • Over-engineering for a small team. A 25-person company does not need a ten-step committee. It needs three or four well-chosen controls done consistently.
  • Leaving exit processes informal. Most ghost employees begin life as exits that were never closed.
  • Ignoring the human side. Controls feel adversarial when explained badly. Present them as protecting everyone, including honest payroll staff who would otherwise carry the suspicion in any incident.
  • No consequence framework. A policy that is never enforced is ignored. Make the consequences clear and apply them consistently.
  • Forgetting managers. Managers approve attendance, overtime and reimbursements. If they click "approve all" without reading, the control is empty. Brief them on their responsibility.

How a modern HRMS supports payroll fraud prevention

Everything above can be done on spreadsheets with discipline, but the discipline is expensive and easy to erode. A purpose-built HRMS and payroll platform converts many manual controls into default behaviour. When evaluating tools, look for capabilities such as:

  • Configurable approval workflows for joiners, exits, salary revisions, bank changes and reimbursements, with multi-level routing.
  • Granular roles and permissions that enforce segregation of duties automatically.
  • Employee self-service so that sensitive data is entered and changed by the employee, with verification, rather than relayed through intermediaries.
  • Complete audit logs showing old and new values, user and time, which cannot be edited by payroll users.
  • Automated validations such as duplicate bank account, PAN or mobile checks, and IFSC checks.
  • Exit-linked deactivation so that a closed full-and-final removes the employee from the next payroll run.
  • Variance and exception reports generated before payment, not after.
  • Reimbursement controls such as mandatory attachments, policy limits and duplicate flags.
  • System-generated bank files with maker-checker steps, avoiding hand edits.
  • Alerts and notifications to employees when sensitive details change.
  • Integrated attendance and leave, so that pay is computed from the same source managers approve.

CozyHR is built around these ideas for Indian SMBs: approval workflows, role-based access, self-service and audit trails sit alongside payroll, attendance, leave and statutory support, so that the controls described in this guide are part of how payroll runs rather than a separate burden. Whatever tool you pick, test it against your own risk map from Step 1 and ask the vendor to demonstrate each control in a live session, not a slide.

Frequently asked questions

1. What is the most common form of payroll fraud in small Indian companies?

There is no reliable single figure, and we would not want to quote one without a source. In practice, the patterns HR and finance teams most often describe are departed employees who stay on payroll, unauthorised bank detail changes, and inflated or duplicate reimbursement claims. These share a root cause: weak approvals and no independent review of changes. Fixing those two things addresses most of the exposure.

2. We only have one payroll person. How can we get segregation of duties?

Full segregation is hard with a single processor, so compensate with oversight. Have a senior person, such as the finance head or founder, approve payroll and authorise the bank payment separately from the person who prepares it. Remove the payroll executive's ability to edit bank details and salary structures, and have someone else review the change reports each month. If no internal person is available, consider a periodic review by an external accountant or a payroll compliance professional.

3. How do we handle an employee who genuinely needs to change their bank account urgently?

Use the same verified process, just run it faster. The employee requests the change through authenticated self-service or, if that fails, in person or on a video call with HR. Proof is uploaded, an independent approver reviews it, and a call-back is made to the number on file. If the change is too close to payroll cut-off to be verified properly, consider paying the amount separately after verification rather than skipping steps. A short delay is far cheaper than a misdirected salary.

4. Can we recover salary that was paid to a ghost employee or the wrong account?

Sometimes, but speed is critical. Contact your bank as soon as you find the issue and ask about the options available for the specific payment mode. Recovery from an employee involved in the fraud may involve settlement or legal action, and deductions from wages are subject to labour and wage rules. Take advice from a lawyer on what is permitted in your situation rather than recovering informally.

5. Are payroll controls a legal requirement in India?

Statutes require accurate wage payment, records and statutory filings, and companies of certain types and sizes have obligations around internal financial controls and audit. The details depend on your entity type, size and sector and they change over time, so confirm what applies to you with your auditor or company secretary. Even where no rule demands a specific control, an unreliable payroll process can lead to wrong deductions, incorrect filings and penalties, which is reason enough to put the controls in place.

6. How often should we audit payroll?

Run the pre-payment review every cycle, a sample-based reimbursement review every month, a headcount confirmation and access review every quarter, and an independent review by your internal or external auditor at least annually. Increase the frequency if you are growing fast, have many contract workers or have recently changed systems.

7. Will these controls slow down payroll and annoy employees?

Done well, they add minutes, not days, to each cycle, because most checks are system-driven exception reports rather than manual hunts. Employees mostly notice only the bank-change verification and the reimbursement attachment requirement. Explain why they exist, make the self-service experience smooth, and most people will accept them readily, since the controls also protect their own salaries from tampering.

Conclusion

Payroll fraud prevention is not about suspecting your team. It is about designing a process in which no single person can quietly move money, in which every sensitive change leaves a trail, and in which someone independent looks at the exceptions before the bank file goes out. The core moves are simple: clean and govern your employee master, treat bank details as sensitive, route pay changes and reimbursements through real approvals, separate who prepares from who approves and who pays, and review exceptions every cycle. Add a practical incident plan and a 90-day rollout, and you will already be ahead of most businesses your size.

You do not have to build all of it on spreadsheets and goodwill. If you would like these controls to be part of the way payroll runs every month, from approval workflows and role-based access to audit logs and reimbursement checks, take a look at CozyHR and try it with your own payroll process. Start by mapping your risk points using the table in Step 1, and see how much of it a system can enforce for you.

This article is general information for educational purposes and is not legal, tax or audit advice. Statutory rules, thresholds and data-protection requirements change, so verify current requirements with the official sources or a qualified professional before acting.