Skip to main content
Category: Fraud Risk Management

Payroll Scheme

Also known as: Payroll Fraud, Payroll Fraud Scheme
Simply put

A payroll scheme is a type of fraud in which someone manipulates a company's payroll system to cause the employer to pay compensation that is improper or not actually owed. One common example is a ghost employee scheme, where a fake or inactive person is kept on the payroll so that wages can be diverted. These schemes are generally treated as a form of asset misappropriation, meaning company assets are stolen or misused.

Formal definition

A payroll scheme is a fraudulent distribution scheme, generally classified within the asset misappropriation category of occupational fraud, in which a perpetrator causes an employer to issue compensation payments that are improper or unauthorized. Recognized variants include ghost employee schemes, in which a fictitious or inactive individual is added to or retained on the payroll system so that salary payments can be misdirected. Such schemes typically exploit weaknesses in payroll processing, authorization, and reconciliation controls, and their prevalence and specific manifestations vary by organization, control environment, and jurisdiction. This entry is educational and does not constitute legal, audit, or compliance advice; the evidence provided does not enumerate all scheme types or associated statistics, and detection and prevention measures depend on facts and professional judgment.

Why it matters

Payroll is often one of the largest recurring cash outflows an organization processes, which makes it an attractive target for internal fraud. Because payroll schemes generally fall within the asset misappropriation category of occupational fraud, they involve the theft or misuse of company assets by insiders who understand and can exploit weaknesses in payroll processing, authorization, and reconciliation controls. Left undetected, these schemes can recur over many pay periods, compounding losses and eroding the reliability of financial reporting.

Beyond the direct financial loss, payroll schemes raise governance and control-environment concerns. They frequently signal gaps in segregation of duties, weak authorization over changes to master payroll data, and inadequate independent reconciliation. A ghost employee scheme, for example, depends on the ability of a single individual to add or retain a fictitious or inactive person on the payroll and to redirect the resulting payments. Where such conditions exist, the same weaknesses may expose the organization to other forms of misappropriation as well.

The prevalence, specific manifestations, and appropriate detection and prevention measures for payroll schemes vary by organization, control environment, and jurisdiction. This entry is educational and does not constitute legal, audit, or compliance advice; the sources here do not enumerate all scheme types or associated statistics, and any assessment depends on the facts and the professional judgment of those responsible.

Who it's relevant to

Chief Compliance and Financial Crime Officers
Payroll schemes fall within occupational fraud and asset misappropriation, so they are relevant to those responsible for fraud risk assessment and anti-fraud programs. Their focus is typically on identifying where payroll control weaknesses could allow improper payments and ensuring appropriate response protocols exist, though specific measures depend on the organization and its risk profile.
Internal Auditors and Assurance Functions
Internal audit generally provides independent assurance over the design and operating effectiveness of payroll controls, including authorization over changes to payroll data and reconciliation of personnel records to actual disbursements. Testing for indicators of ghost employees or improper compensation is a common part of this work, but audit does not own the operation of the controls themselves.
Management and Payroll Process Owners
Management typically owns the operation of payroll processing and the controls that prevent and detect improper payments, such as segregation of duties and authorization requirements. Process owners are generally accountable for maintaining the integrity of payroll master data and for the accuracy of wage calculation and distribution.
Boards and Audit Committees
The board and its audit committee generally exercise oversight of the organization's fraud risk and control environment rather than operating controls directly. Their interest in payroll schemes typically centers on whether management has established adequate controls and whether assurance functions are appropriately identifying and reporting on related risks.

Inside Payroll Scheme

Ghost Employee Payments
A common form of payroll scheme in which a perpetrator adds a fictitious or terminated individual to the payroll and diverts the resulting wages, typically exploiting weak controls over employee onboarding and master file changes.
Falsified Hours or Rates
Manipulation of recorded time, overtime, or pay rates so that an employee receives compensation exceeding what was earned; this generally depends on inadequate supervisory review or approval controls over time records.
Commission or Bonus Manipulation
Inflation of sales figures, commission calculations, or bonus entitlements to trigger unearned payments, often where the underlying performance data is not independently verified.
Master File Access Controls
The permissions and segregation of duties governing who can create, amend, or approve changes to payroll records; a concentration of these duties in one person typically increases scheme risk.
Ownership and Accountability
Payroll schemes generally sit at the intersection of several functions: management owns the design and operation of preventive and detective controls, internal audit or other assurance functions provide independent evaluation, and the board or audit committee holds oversight responsibility. These roles should not be conflated.

Common questions

Answers to the questions practitioners most commonly ask about Payroll Scheme.

Is a payroll scheme the same as a payroll processing error?
No. A payroll scheme generally refers to an intentional fraud in which an individual causes an organization to issue improper payments through the payroll function, such as ghost employees, falsified hours, or unauthorized rate changes. A processing error is unintentional and lacks the element of deliberate deception. The distinction matters because the two call for different responses: errors are typically addressed through process correction and reconciliation, while suspected schemes may trigger investigation, disciplinary, and potentially legal considerations. Whether a given event is fraud rather than error is a fact-specific determination that often depends on evidence of intent and concealment, and this entry is educational rather than a substitute for professional judgment.
Does detecting and preventing payroll schemes fall to the board or to internal audit alone?
Neither owns it exclusively, and the responsibilities are distinct. Management typically owns the design and operation of the payroll controls that prevent and detect improper payments as part of its day-to-day accountability. Internal audit or a comparable assurance function generally provides independent evaluation of whether those controls are designed and operating effectively, but does not own the controls themselves. The board, often through an audit committee, typically exercises oversight, reviewing management's anti-fraud arrangements and assurance results rather than performing operational monitoring. Conflating these roles risks leaving accountability gaps. The specific allocation can vary by jurisdiction, entity type, and an organization's governance structure.
What controls do organizations typically use to reduce payroll scheme risk?
Common controls include segregation of duties so that no single person can add an employee, approve changes, and release payment; independent approval and periodic review of new hires, terminations, and rate or bank-detail changes; reconciliation of payroll registers to authorized headcount and to the general ledger; and periodic verification of employee existence. The appropriate mix depends on the organization's size, systems, and risk assessment. These are examples of control activities, and their presence does not by itself demonstrate operating effectiveness, which must be tested separately. This entry is educational and not audit or compliance advice.
How does an organization distinguish inherent from residual payroll scheme risk when assessing it?
Inherent risk generally refers to the exposure to payroll scheme loss before considering the effect of controls, driven by factors such as transaction volume, workforce dispersion, and system complexity. Residual risk is the exposure that remains after accounting for the controls in place and their effectiveness. Keeping these distinct helps management and assurance functions focus effort where residual risk exceeds the organization's stated risk appetite or tolerance. The assessment is judgment-based and specific to the entity's facts, and different frameworks may describe the assessment steps differently.
What is the practical difference between testing control design and testing operating effectiveness for payroll controls?
Assessing control design typically asks whether a control, if it works as intended, would prevent or detect the scheme in question, for example whether an approval step is capable of catching an unauthorized bank-detail change. Testing operating effectiveness asks whether the control actually functioned as designed over a period, often by examining a sample of transactions or evidence of approvals. A control can be well designed yet fail in operation, or operate consistently yet be poorly designed. Both dimensions generally need to be evaluated, and the specific testing approach depends on the assurance provider's methodology and professional judgment.
How might red flags of a payroll scheme be surfaced through monitoring?
Monitoring approaches often include analytic reviews that compare payroll data against expectations, for example identifying multiple employees sharing a bank account or address, employees with no deductions, payments to terminated staff, or unusual overtime patterns. Exception reporting and periodic reconciliations can also surface anomalies. Such indicators are typically starting points for inquiry rather than proof of fraud, and any follow-up should preserve appropriate confidentiality and, where relevant, be coordinated with legal counsel and investigation protocols. The suitability of specific monitoring techniques depends on the organization's systems, resources, and applicable data-protection and employment law requirements, which vary by jurisdiction.

Common misconceptions

Payroll fraud is solely a finance or payroll department problem to detect and resolve.
Detection and prevention are typically a management (first line) responsibility, but assurance over control effectiveness generally falls to internal audit or a similar function (third line), while overall oversight rests with the board or audit committee. Treating this as a single function's issue conflates distinct lines of accountability.
Having anti-fraud controls documented means they are working.
Control design and operating effectiveness are separate concepts. A well-designed segregation-of-duties or approval control may still fail in operation if it is not consistently performed. Evaluating both dimensions is generally necessary to gain assurance.
Reducing the inherent risk of payroll fraud eliminates the exposure.
Controls act on inherent risk to produce a residual risk that generally cannot be reduced to zero. Some residual exposure typically remains, and whether that level is acceptable depends on the organization's stated risk appetite and tolerance, and on management judgment.

Best practices

Enforce segregation of duties so that no single individual can add an employee to the master file, approve pay changes, and disburse payments without independent review.
Implement independent, periodic reconciliations of the payroll master file against active-employee and HR records to identify ghost or terminated employees.
Require supervisory approval of time records, overtime, commissions, and bonuses by someone independent of the person entering or benefiting from the data.
Restrict and log access to payroll systems and master file changes, and review those logs for unauthorized or unusual amendments.
Clarify accountability across the three lines, management ownership of controls, independent assurance from internal audit, and board or audit committee oversight, so responsibilities are not blurred.
Assess both the design and the operating effectiveness of anti-fraud controls, and evaluate whether the residual risk that remains is consistent with the organization's risk appetite.