Skip to main content

Risk Management in Payroll

What are the risks in a payroll department?   There are many variations of the three below, but it all comes down to them.
  1. Fraud
  2. Error
  3. Confidentiality
Good processes and governance go a long way to preventing all of them, and, of course, the positive effect of getting it right the first time, is so much better than having to constantly correct problems.   Payroll errors have a very negative impact on morale.

Fraud   

From ghost employees to duplicate bank accounts, payroll fraud is wide ranging and yet we are frequently told that payroll administrators manage the full process from data entry to EFT without anybody else checking the output.   While it is clearly not good governance, it is also quite simply putting temptation on the table.

Another concern is that there are many repeat offenders out there, protected by the employer who chooses to not take action, and by the companies who do not insist on full background checks when hiring into such a sensitive role.

Errors

Payroll departments work under extreme pressure, and deadlines are not always adhered to by the rest of the company.   This increases the opportunities for errors of omission, unclear communication or a lack of understanding of the requirements.

The majority of people operating in payroll departments have grown up in the position, ie they have no formal training in payroll administration, are trained on the job, and their skill set is often deep knowledge of a particular payroll software package.

We have also noticed that there is very little formal training in spreadsheet products which can be very valuable for controls.

The risk of an underpayment not being reported is low, but overpayments and incorrect calculations are frequently unreported.

Confidentiality

With the PoPi bill on its way, keeping people information confidential has never been more important, and yet there is significant risk in many payroll departments.   Some of the main areas of concern are:
  • Designing security levels that allow only the relevant people access to the information
  • Setting up firewalls correctly
  • Understanding whether the IT department has access to the encrypted data, and ensuring that there is full signed contractual confidentiality.   For convenience, in larger IT departments, the access is spread quite broadly, and it is in the interests of companies to confirm who should and shouldn't have access.
Governance and controls need to be in place.   The way the payroll is checked each month should also be standardised.   Variance reports are particularly useful as a first step, so that it is easy to see where the differences are, month on month.   Line management need to sign off on their direct reports, and should have a check list to work through eg
  • Employees who are in their last month of work
  • Employees terminated in the previous month
  • New employees
  • Increases given
  • Bonuses given
  • Savings and loans
  • Commissions
  • Travel claims
  • Reimbursements
This checking by line management subjects the payroll to an external review process, and reduces risk immediately.  Terminations and new hires should be checked with the employment contract at hand.   Audit reports should also be checked each month to confirm that all changes in the system are valid.

No matter what systems are in place, it is possible to commit fraud, make errors and break confidentiality, particularly as processes often become less tight over time.   It is advisable to ensure that payroll departments are regularly submitted to an external risk management /health check process, which confirms best practice, as well as process flows and reporting models that highlight anomalies.

Risk Management
e-Mail: support@accsys.co.za
Enquiry: Contact Form 

Payroll Training
Payroll Administration Diploma


Comments

Popular posts from this blog

Its all about the numbers - retirement age

Weight, height, age, dress size, shoe size, all numbers that we (and the media) use to define people. I was fascinated by an article from the Leicester Mercury where the age of each witness to a bus crash in January were carefully listed. Sue Kellett, 56, whose front garden is bordered by the wall, was one of the first at the scene. Read more: http://www.leicestermercury.co.uk/Bus-driver-airlifted-hospital-collision-tractor/story-20512289-detail/story.html#ixzz31lXUuyZg Read more at http://www.leicestermercury.co.uk/Bus-driver-airlifted-hospital-collision-tractor/story-20512289-detail/story.html#9cHShVptF30lJw4X.99 Sue Kellett, 56, whose front garden is bordered by the wall, was one of the first at the scene. Read more: http://www.leicestermercury.co.uk/Bus-driver-airlifted-hospital-collision-tractor/story-20512289-detail/story.html#ixzz31lXUuyZg Read more at http://www.leicestermercury.co.uk/Bus-driver-airlifted-hospital-collision-tractor/story-20512289-detail/story.htm...

Feeding the Right Wolf

Feeding the Right Wolf This Cherokee story resonated with me (see below).     Like many business people, I get caught up in managing details, instead of focusing on strategy and growth.   Measuring myself against the Good Wolf concept has become a way of thinking for me. Feeding the good wolf - focusing on the right stuff! In a previous article on this topic, I commented that the message is simple, the wolf you feed is the one that grows. The good wolf attributes in a business are where we ideally should spend our time, that good old 80 – 20 rule focusing on our   engaged employees, improving client experience and quality of product,   to name a few. Creating a Good Wolf Environment While we have many different tools – appraisals, customer and employee surveys – to try and understand the temperature and levels of entropy in our businesses – the truth is that it is really difficult to explain to people that they are not seen as feeding the good wo...

Is the employee toxic or simply disengaged?

Is the employee toxic or simply disengaged?  And how to tell? Dissecting Employee Behaviour We spend hours of management time dissecting employee behaviour to ensure that not only is each employee delivering to a minimum expectation, he or she is not actively undermining the effectiveness of the business. We design KPAs (or KPIs, or whatever we want to call them), we run regular appraisals, we discuss career paths and succession plans, and  as long as toxic employees are delivering on their job description, we keep them! It’s only after they leave, when you hear the collective deep breath of relief from colleagues and management, that you can be absolutely sure of the negative impact. Underperformance vs Undermining My view has changed – rather an underperformer, than an underminer. So what to do? Once you have firmly established that undermining is the problem, the first step is to tell them that you are onto them! Never an easy task, because very few p...