River
Y CombinatorBacked by Y Combinator

Finance & AccountingFree

Payroll Change Report Register Audit

The change log lists what somebody edited. The register diff shows what came out different, including the field that should have moved and did not.

Start here

Payroll change control is usually one artifact: the change report the payroll system produces, initialled by whoever is senior enough to initial it, filed with the run. It is a reasonable control and it has one structural blind spot. That report is the system's account of its own edits. It lists what somebody changed. It cannot list what nobody changed, which is where the largest payroll errors live, because a termination that was never entered produces no row.

So this ignores the change report and diffs the two registers directly, field by field. The field set is not a preference. 29 CFR 516.2(a) names twelve items a payroll record has to carry for every employee. Among them: the regular hourly rate and the basis of pay, hours worked each workday and each workweek, straight-time earnings, premium overtime pay, every addition and deduction with its nature, total wages, and the date of payment. Diff all twelve, then diff the payment destination too, which the rules do not require.

Then every delta gets priced at its annualized run rate with employer burden on top, and the list is ranked by that number rather than by the per-period amount. The ranking is the useful part, because it reorders the findings away from the field everybody watches. Sibling checks work the same way: the filing reconciliation ties the register to what was actually remitted, and the journal and accrual pack carries the posting side. A name arriving on the register for the first time is a classification question rather than a pay change.

Where the money actually was

Thistledown Mills, a fictional 46-employee millwork shop on biweekly payroll, diffed the register for the period ending 14 June against the one before it. Nineteen field-level changes. Twelve had approval evidence behind them and seven did not. Three of the seven were recurring: a standard-hours field moved from 72 to 80 at 31.20 an hour, an employee health premium share of 186.50 went to zero, and an hourly rate went from 24.60 to 26.45.

Those three add up to 584.10 on a register with 104,298.74 of gross pay, so fifty-six hundredths of one percent. Nobody stops a payroll for that, which is exactly why they clear. Annualized over 26 periods with the 7.65 percent employer social security and Medicare on the wage items, the same three lines are 15,977.43, or 27.4 times the figure anybody eyeballed. The per-period view is not a smaller version of the annual view. It is a different decision.

The largest finding was the one where nothing changed. A salaried employee terminated 29 May was still on the 14 June register at 2,600.00, plus 198.90 of employer tax. Fourteen periods remained in the year, so the run rate was 39,184.60. The change report had no row for him because no field was edited. Ranked by annualized exposure, the unapproved hourly rate change, the one field every review diffs, came fourth. Three people run that finance department, so segregating the payroll duties was never on the table.

How it works

  1. Load both registers

    Two consecutive periods, at employee and earnings-code level rather than the summary totals page

  2. Diff every field

    Rate, basis, hours, earnings, additions, deductions, total wages, payment date and destination, per employee

  3. Test the absences

    Roster movement, approved increases and new earnings codes each imply a field that had to move this period

  4. Price and rank

    Each delta annualized with employer burden, sorted by exposure, split by whether approval evidence exists

What it checks

  • Diffs all twelve fields 29 CFR 516.2(a) requires, not the three a change report usually shows
  • Prices each delta at its annualized run rate with employer social security and Medicare added on top
  • Holds an expectation per employee, so it reports the field that should have moved and did not
  • Flags a payment destination change, and flags it harder when the address moved in the same period
  • Checks the regular hourly rate against new earnings codes, because a non-discretionary bonus has to enter it
  • Separates the deltas carrying approval evidence from the ones that need it before the run is released

Common questions

Why not just review the change report the payroll system already produces?

Because it is the system's record of edits, and the costly errors are usually omissions. A termination nobody entered, an approved raise nobody applied, a regular rate that did not move when a bonus appeared: none of those is an edit, so none appears on a change report. Diffing the registers finds them because it compares outcomes rather than actions.

Our controller already signs off on the register every period. Is this different?

Sign-off is review of a total. This is a field-level comparison against a stated expectation, which is a different kind of evidence. PCAOB AS 2201 draws the line between preventive controls, which stop an error happening, and detective ones, which find it afterward. A register diff run before release is detective in design and preventive in timing.

We have three people in finance. We cannot segregate payroll duties properly.

The standard anticipates that. AS 2201 notes that a smaller, less complex company may have fewer people in the accounting function, limiting opportunities to segregate duties, and will implement alternative controls to reach the same objective. A diff somebody other than the preparer reviews is one of those alternatives, and it leaves a testable artifact.

How far back do we need to keep the registers for this to work?

Longer than most people assume. 29 CFR 516.5(a) requires payroll records for three years from the last date of entry, and IRS Publication 15 requires employment tax records for at least four. Four years is binding, and a premium audit response reads the same span, since a class code error predates the audited year. Keep the diffs too: the register alone never shows what a field held before.

Does the annualized number overstate things? Most of these get fixed next period.

Some do. The run rate is not a forecast, it is a materiality scale, and its job is to stop a 148 dollar line from being dismissed as 148 dollars. Every finding carries both figures so the reviewer sees the period cost and the exposure if it runs unchecked. Fixed items get closed with the date and the evidence.

What counts as approval evidence?

Something written, dated before the effective date, from somebody with the authority to grant it. An offer letter, a signed change form, an approved requisition, a board or compensation committee minute. An email confirming a change already made is not approval, and the review says so rather than accepting it, because that distinction is the whole point of the artifact.

Can this catch payroll diversion, or is it only errors?

It catches the pattern. Diversion needs the payment destination changed, and the durable version changes the address or contact details too so the employee stops receiving statements. Those are separate fields nobody diffs together. The duplicate payment scan applies the same joined-field idea to vendor banking.

Payroll Change Report Register Audit

Fill in the form and your workspace opens with the work already underway.