Skip to content
What the Hour Is Worth

Home / The records

The Audit You Run Yourself

A one-day wage audit anybody can run with data they already hold, what it reliably finds, and why one employee is a better starting point than a sample.

The records · Reference

Start with one employee and one week rather than with a sample. A single week walked all the way through the chain — raw punch, every setting, the rate build, the threshold, the statement — finds more than a survey of four hundred payslips, because almost every error is produced by a setting and a setting shows up in any affected week.

The recordkeeping discipline in “The Audit You Run Yourself” should also apply to workforce technology. When a team evaluates view the solution in relation to does microsoft teams track your activity, it should document purpose, access, retention and deletion, then preserve the source entry, approvals and correction history needed to explain the final figure.

The exercise takes a day, needs no external help, and produces findings that apply to whole pay groups rather than to individuals.

For an independent reference relevant to “The Audit You Run Yourself”, consult the CISA insider-risk mitigation resources. Use it to test record quality, working-time definitions, access, retention and exception handling against the organisation’s real payroll process.

Choosing the week

Pick somebody with variable hours, a premium in the week, and at least one additional component — a differential, a bonus, a second rate. Simple weeks confirm that simple weeks work.

Avoid the current week, because the records are still moving, and avoid anything more than a few months old, because the detailed data may have been purged.

The order to work in

  1. Pull the raw timestamps for the week, before any rule is applied.
  2. List every setting that can change them, and what each one did.
  3. Produce the hours the system used, and reconcile them to the raw times.
  4. Rebuild the rate from its components, by hand.
  5. Check the threshold, the period it was measured over, and the multiplier.
  6. Compare everything with the statement the employee actually received.

Step two is the one that takes longest and teaches most. In most organisations nobody can name all the settings without opening the system and looking, which is itself the first finding.

What it reliably finds

  • One or two settings nobody can explain.
  • A rate that differs from the components by a small amount.
  • A statement that does not show what the employee would need to check it.
  • At least one pay code with no classification.

Those four appear in most organisations and none of them requires anything to have gone badly wrong. They are the normal state of a system that has been running for a few years without anybody walking the chain.

Who should run it

Somebody who can ask payroll and the time system owner for things and get them, who is not responsible for either, and who has a day.

Internal audit is the obvious choice where one exists. Where it does not, a finance or HR person with no stake in the answer works, provided they are given access rather than summaries.

Writing it up

Short: what was examined, what was found, what each finding implies for the wider population, and what should happen next. Two pages.

The implication column is the part that matters. "The rate excluded the shift allowance" is an observation; "this applies to everybody in pay group 3 with premium hours, approximately 40 people" is a finding.

Doing it again

Annually, on a different employee from a different group, with the previous year's findings checked for recurrence.

The second year is more valuable than the first, because it shows what was actually fixed. A finding that reappears has been corrected in the payment and not in the mechanism, which is the distinction this collection keeps returning to.

Why one employee is enough to start

A sample of four hundred payslips tests whether the system is internally consistent, which it will be, because it is a system.

Walking one week tests whether the system is doing what the organisation thinks it is doing, which is a different question and the one worth answering. If the week is clean, widen it. If it is not, there is no point sampling anything until the finding is understood.

Telling people what it is

An internal audit of somebody's pay looks, to that person, like an investigation into them. Saying what it is before it starts removes that entirely.

The framing is honest and simple: the organisation is checking that its own systems do what it thinks they do, one week has been picked as an example, and nothing about it concerns the employee. Most people are interested rather than alarmed, and several will volunteer exactly the kind of information the audit is looking for.

What to do with a finding nobody wants

Some findings are inconvenient: a setting that has been wrong for years, an arrangement that costs more than anybody realised, a population that has been underpaid.

The temptation is to narrow the scope and report the small version. That decision is itself a record, it is usually visible later, and it converts a problem the organisation found into a problem the organisation knew about and managed. The audit is only worth running if its findings are allowed to be what they are.

The thing it is really for

The audit produces findings, and it also produces the only complete description of the chain the organisation has. That description — the settings, their owners, the order they apply in — is the artefact everything else on this site depends on, and running the audit is the cheapest way to acquire one.