New Tax Declarations and Proofs – Now Fully Inside HR Blizz for India Payroll Read the release note
HR Blizz
All resources
April 21, 2026 · 11 min read
Global Payroll

The payroll controls an auditor will actually test in a walkthrough

Auditors do not test whether your payroll was right. They test whether the control operated. What gets tested, what counts as evidence, and how to fix it.

The audit senior needs four seconds to ask her question. “Who approved the November run for Poland?”

You know the answer. Marek approved it. He opened the register on his second monitor, scrolled the variance column, saw nothing strange, and typed “looks fine, go ahead” into a Teams thread at 4:12 p.m. on the 22nd. The bank file went out the next morning. Net pay was correct to the cent.

None of that is evidence.

Payroll almost never fails loudly. It fails in a step nobody owned. A bonus file lands in the wrong period because the cutoff was a convention, not a lock. A bank detail changes on the 19th, and the person who changed it releases the payment.

Why the auditor cares about a function that reports to HR

Payroll sits in the financial statement audit because of arithmetic, not org charts. It is usually the largest expense line and the largest recurring cash outflow, and the US Bureau of Labor Statistics’ quarterly series on employer costs for employee compensation shows how much of that total sits outside base wages, in employer contributions and benefits nobody outside payroll can see. For a software or services business, that is most of the P&L moving through one system on a fixed cycle.

Anything that large gets tested twice. Once at process level: authorisation, reconciliation and segregation of duties around the compensation cycle and the accrual. Once through IT general controls, where the payroll system gets examined for logical access, change management and job scheduling, like any financially significant application.

For US issuers the statutory hook is older than SOX. Section 13(b)(2)(B) of the Exchange Act requires internal accounting controls sufficient to give reasonable assurance that transactions are executed in accordance with management’s authorisation. The SEC pursues that on its own. On 29 January 2019 it charged four public companies, Grupo Simec, Lifeway Foods, Digital Turbine and CytoDyn, with failing to maintain internal control over financial reporting across seven to ten consecutive annual reporting periods. All four settled without admitting or denying the findings, and paid penalties ranging from $35,000 to $200,000. Companies “cannot hide behind disclosures as a way to meet their ICFR obligations,” said Melissa Hodgman, then an associate director in the SEC’s Enforcement Division.

The fraud numbers are less dramatic than people expect. The ACFE’s Occupational Fraud 2024: A Report to the Nations, the current edition, analysed 1,921 cases across 138 countries and territories: median loss $145,000, median duration 12 months before detection. Payroll schemes run longer. As the Chartered Institute of Payroll Professionals and the Bonadio Group read the same report, payroll fraud appeared in 190 cases, about 10 percent of the total, median loss near $50,000, median duration 18 months. Six quarters of signed financials while a ghost employee draws net pay.

What actually gets tested, and what “tested” means

Strip away the framework language and a walkthrough covers a short list:

  • Segregation of duties across three roles: whoever changes master data, whoever runs the calculation, whoever releases the payment.
  • Authorisation at source: a new hire, a salary change or a bonus approved by someone with delegated authority before it reaches payroll, not after.
  • The master data cutoff, with proof inputs were frozen at a stated point and anything later went to the next period or an exception route.
  • Bank file integrity and dual release: the file leaving the payroll system is the file the bank receives, with a control total and two people to release it.
  • A three-way reconciliation of payroll register to general ledger to bank, reviewed by someone who did not prepare it.
  • Off-cycle and exception payment approval above the requester’s level.
  • Access reviews on the payroll system, with terminated users removed inside a stated window.
  • Change management on payroll configuration, since a pay element formula is part of the financial reporting system.

The last one is where payroll teams argue. An analyst editing a wage type formula in production has changed the calculation behind your largest expense line. If that edit in the general ledger would need a ticket, an approval and a test record, expect to be asked why payroll is different.

Segregation of duties when there are six of you

The textbook matrix assumes a payroll department with layers. You have six people covering 14 countries, one of whom is the only person who understands the Japanese social insurance table.

Pretending the conflict does not exist is the worst option, because the auditor will find it in twenty minutes by exporting role assignments. The workable answer is a documented compensating control, emphasis on documented.

Compensating controls that hold up: an after-the-fact review of all master data changes by someone outside payroll, against a system-generated change report rather than a list payroll assembled itself. Exception reporting with thresholds, so new bank details, rate rises above a set percentage and hires added inside the cutoff window surface automatically and get signed off. An independent bank reconciliation by treasury, which catches a payment that does not match an approved register even when the payroll side of the wall is compromised. Mandatory leave, so once a year someone else operates the process.

Then write the conflict into your control documentation with the compensating control attached and the residual risk stated. An auditor who finds a known conflict with a working compensating control writes a very different memo to one who finds a conflict nobody had noticed.

Nobody is auditing whether your payroll was right

This one catches good teams. Auditors are not testing the accuracy of your November run. They are testing whether a control operated. Different questions, and a perfectly accurate payroll can still produce a deficiency.

Which makes the artefact the point. A control that operated leaves three things behind: a named approver, a timestamp, and the report that person was looking at. Then a trail from the register the approver signed to the total that left the bank.

A folder of screenshots is not that. It shows a screen, not a decision, it carries the date the file was saved rather than the date of the review, and anyone can produce one afterwards. Sample five months, find four screenshots, and the test fails even if all five payrolls were right.

Audit trails fail the same way. A log recording “record updated by jkowalski, 19/11/2025 14:32” tells the auditor nothing. Updated from what to what? A salary moving from 8,400 to 9,400 and a corrected IBAN look identical there. The trail has to carry old value, new value and source, so you can tell a manual edit from an HRIS feed from an import file.

Here a system either helps or does not. HR Blizz runs every period as a 13-step cycle with a named approver on each gate and a master data cutoff that locks the run once inputs are signed off, so the frozen population is a system state rather than an email convention. Corrections run as their own controlled off-cycle run and merge back without breaking the trail, because the alternative, editing a closed period, is what auditors go looking for. Underneath sits a 30-column audit trail recording every change with old value, new value and source. None of that makes payroll correct. It makes the control testable, which is the separate thing being asked.

The SOC report on your provider’s website is probably the wrong one

Outsourcing does not move the control. It moves the evidence to a third party.

The distinction gets blurred in sales conversations. A SOC 1 Type II covers controls at the service organisation relevant to user entities’ internal control over financial reporting, tested over a period, and it is written for your auditor. A SOC 2 Type II covers the Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy. Only the first answers your financial auditor’s question. Outside the US, ISAE 3402 is the equivalent for controls relevant to financial reporting, with ISAE 3000 for broader subject matter. A provider handing over a SOC 2 has answered a different question.

Then read the section everyone skips. Complementary user entity controls are the ones the report explicitly assumes you perform. Typical payroll CUECs: the user entity approves the payroll register before authorising payment, reviews its own users’ access, reconciles reported payroll to its general ledger, and notifies the provider of terminations promptly. Skip that list and you are relying on a report whose conclusions are conditional on controls you are not running.

Two traps. A SOC 1 covering 1 October to 30 September leaves three uncovered months against a December year end, so you need a bridge letter. And if the provider carved out a local partner or a hosting vendor, those controls sit outside the report in your hand.

The same control, evidenced fourteen times

Multi-country is where this gets expensive. The design is one control. The evidence is fourteen.

Local statutory audits ask their own questions, often with an auditor who wants local records rather than your group control matrix. Several jurisdictions attach personal certification to filings, so a named individual attests that the return matches the books. Run 14 countries through 14 providers and you collect 14 SOC 1 or ISAE 3402 reports with 14 period ends, 14 CUEC lists and 14 ideas of what counts as an approval. Somebody maps that to one control description, every year.

The cheapest structural answer is fewer control boundaries. The cost driver is the number of places evidence has to be gathered from, not the number of countries you pay in.

What to fix before the walkthrough

The five findings that come up most, in the order worth fixing them.

1. No independent review of the payroll register before payment. Name a reviewer outside payroll operations, give them a variance report against the prior period, and record the approval in the system, not in chat.

2. Master data changes without documented authorisation. Export the change log for the last three periods and count the changes with no approval behind them. That number is the finding.

3. Users holding both master data and payment release rights. Export role assignments today, and where you cannot split them, write the compensating control down.

4. Terminated employees still active in the payroll system. Reconcile the HRIS leaver list against active payroll users and active payees, then set a removal window and measure against it.

5. Off-cycle payments approved by the person who requested them. Route every off-cycle to an approver one level above the requester, with no exception for urgency, since urgency is how every off-cycle gets described.

Then do the thing nobody enjoys. Pick one month and one country and walk it yourself, approved input to bank confirmation, using only what is in the system. If you have to open your email to finish the chain, that is the finding, and you found it first.

See how HR Blizz handles the controlled payroll cycle, from named approvals at each gate to a 30-column audit trail with old value, new value and source.

Treat the statutory and reporting requirements described here as general information rather than legal or audit advice. Your own auditors set the standard you get tested against.

FAQ

Q: Is a SOC 2 Type II report enough for my financial auditor to rely on my payroll provider?

No. A SOC 2 Type II reports on the Trust Services Criteria, which are security, availability, processing integrity, confidentiality and privacy. Your financial auditor needs a SOC 1 Type II, or an ISAE 3402 report outside the US, because those cover controls at the service organisation that are relevant to user entities’ internal control over financial reporting.

Q: What are complementary user entity controls in a payroll SOC 1 report?

They are the controls the report assumes you perform yourself, and the provider’s conclusions are conditional on them. Common payroll examples include reviewing and approving the payroll register before authorising payment, restricting and reviewing your own users’ access, reconciling reported payroll to the general ledger, and notifying the provider of terminations promptly.

Q: How do you handle payroll segregation of duties in a team too small to split the roles?

Document the conflict and attach a compensating control rather than leaving it undisclosed. Workable compensating controls include an after-the-fact review of system-generated master data change reports by someone outside payroll, threshold-based exception reporting on bank detail and pay rate changes, an independent bank reconciliation performed by finance or treasury, and mandatory leave so a second person operates the process at least once a year.

Q: Why is a folder of screenshots not accepted as payroll control evidence?

A screenshot shows a screen rather than a decision, carries the date the file was saved rather than the date the review took place, and can be produced after the fact. Auditors are testing whether the control operated, so the evidence needs a named approver, a timestamp, the report that was reviewed, and a trail linking the approved figure to the amount actually paid.