River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Payroll Audit Checklist Template

Two documents and three sheets that diff two payroll periods and catch the change nobody approved, not just the error someone happened to notice.

Free download  ·  No account needed

A payroll audit checklist usually asks someone to sample transactions and confirm that classifications, hours and tax withholdings look right, the same list whether or not anything actually changed. It catches an error a reviewer happens to look at directly. It does not catch a change: a rate, a deduction, a direct-deposit account, different this period than last for a reason nobody approved. Payroll schemes run a median 18 months before detection and account for 10 percent of occupational fraud cases studied by the Association of Certified Fraud Examiners (ACFE, 2024 Report to the Nations).

At Marloe Logistics, 240 employees, this period's register differs from last period's in 34 rows. Cross-checking each against the approved change log explains 31: merit increases, a benefit tier change, a new dependent. Three do not match anything on file. Owen McAllister's raise, sized against his compensation band, was approved at $33.00 an hour; the register shows $34.50, a $120 keying error. Farrukh Islam's rate rose to $31.50 with no raise on file anywhere, $280 this period. Bianca Souza's direct-deposit account changed with no request logged, putting $2,150 at risk.

The pack opens with the Audit Procedure and Correction Guidance, then the Change Register listing every row that differs between two periods. Exception Flags carries the three unexplained rows forward, priced and prioritized. The Correction Log records what each turned out to be: Owen's was corrected, Bianca's was legitimate, Farrukh's is still open, feeding a total rewards statement only as trustworthy as the register beneath it. A state auditor's fraud alert advises reviewing the system's own change log for unauthorized changes, not just the amounts (Arizona Auditor General).

34 rows differ. 31 are explained. Three are not

The Change Register's diffs against the approved change log, and the Exception Flags they produce.

Change Register: two consecutive periods

Illustrative example. Marloe Logistics, fictional warehouse software company, 240 employees, 34 of 240 rows differ.

EmployeeChange typePriorCurrentMatched to change log?
Owen McAllisterRate$31.00/hr$34.50/hrNo, amount mismatch
Bianca SouzaDirect deposit...4821...7013No, nothing on file
Farrukh IslamRate$28.00/hr$31.50/hrNo, nothing on file
Grace OkaforRate$29.00/hr$30.50/hrYes, merit increase
Liam BergstromDeduction$145.00$162.00Yes, benefit tier change
31 of 34 rows match an approved change log entry. 3 do not.

Exception Flags

The 3 rows with no matching approved change, sorted by priority.

EmployeeExceptionThis periodAnnualized if uncaughtPriority
Bianca SouzaDirect deposit changed, no request on file$2,150 at riskn/aHighest
Farrukh IslamRate increased, no approval on file$280$7,280Highest
Owen McAllisterApproved raise entered at the wrong amount$120$3,120High

Owen's turned out to be a keying error, now corrected. Bianca's was legitimate, a portal outage skipped the log entry. Farrukh's is still open.

What is in the pack

01

Audit Procedure

The repeatable sequence run before every payroll cycle funds: pull two registers, diff them, pull the change log, flag exceptions, review.

02

Correction Guidance

How to fix a processing error going forward, how to handle a retroactive correction carefully, and when to escalate instead of closing.

03

Change Register

Every row that differs between two consecutive payroll periods: rate, deduction or direct-deposit changes, matched against the approved log.

04

Exception Flags

The rows with no matching approval, prioritized by type and priced both for this period and annualized if the change recurs uncaught.

05

Correction Log

What each exception turned out to be, a processing error, a late-filed approval, or an open investigation, dated and signed off.

How it works

  1. 1

    Send two payroll registers

    The prior period's final register and the current period's draft, at row level: rate, hours, deductions and direct-deposit reference.

  2. 2

    Get the Change Register

    Every row that differs between the two periods, with the type of change and both values shown side by side for review.

  3. 3

    Send the approved change log

    Your HRIS's record of approved raises, promotions, benefit elections and direct-deposit change requests for the same window.

  4. 4

    Get Exception Flags before you fund the run

    Every diff with no matching approval, priced and prioritized, so it can be reviewed before the payroll run releases, not after.

Frequently asked questions

Is this template free?

Yes. The whole pack, the Audit Procedure and Correction Guidance, plus all three sheets, downloads as real files with no signup. Edit with AI is a separate, optional path that creates a free account and installs the same pack as a private workspace.

How is this different from a normal payroll audit checklist?

Every payroll audit checklist we reviewed asks someone to sample transactions and confirm classifications, hours and withholdings look right, the same steps whether or not anything actually changed. This pack diffs two consecutive registers and checks every difference against what was actually approved.

What counts as a match to the change log?

The same person, the same type of change, and an amount and effective date consistent with what the register shows. A raise approved for $2.00 an hour that shows up as $3.50 an hour in the register is still an exception. Presence alone is not enough; the amounts have to reconcile.

Does this replace a full compliance-focused payroll audit?

No. Classification, overtime and tax-withholding compliance checks still matter and this pack does not replace them. It adds the check those audits typically skip, whether every payroll change actually happened for a reason someone approved, which a compliance-focused checklist is not built to catch.

What happens when an exception turns out to be unapproved?

The pack documents it, prices it and hands it to whoever owns internal controls or personnel matters. It does not decide what happens to the person who made the change. Its job stops at confirming what changed and whether an approval exists for it anywhere in the record.

Why do so many exceptions cluster around open enrollment?

Because that is when the most legitimate payroll changes happen at once: new elections, tier changes, dependent additions, all logged in an open enrollment communication template's completion tracker. A high change-log match rate right after enrollment is expected; a low one is the signal worth investigating.

What format are the downloaded files?

Word documents for the Audit Procedure and Correction Guidance, and CSV spreadsheets for the Change Register, Exception Flags and Correction Log. All open natively in Word, Google Docs, Excel or Sheets, so nobody has to convert anything before reading it.

Stop checking whether numbers look right and start checking whether they changed

Send two consecutive payroll registers and your approved change log for the same window. The Change Register comes back first, then Exception Flags for whatever does not match, priced and prioritized before the run funds.

Audit my next payroll run