FlowParse
Blog August 2026 19 min read

What an Auditor Checks in Your Payroll Register

A register that looks tidy on a screen isn't the same as one that survives a sample test. Ten signals that surface first in a payroll audit — and which ones are actually worth worrying about.

FlowParse
flowparse.io
flowparse.iono audio needed
0:00 / 0:00

Looking fine isn't the same as being fine

A payroll register can look perfectly in order — documents filed, totals that seem to add up — and still contain a series of signals that surface first in an audit. None of them is necessarily an error. They're deviations from an expected pattern, which is exactly why they draw a closer look.

The ten signals below recur consistently across companies of every size, from a business processing a handful of pay runs a year to one running payroll for thousands of employees monthly. None of the ten is proof of anything on its own — together, they give a reliable sense of where an auditor would look first.

FlowParse
flowparse.io

1 · Registers reconciled well outside a normal window

A register should be reconciled to the bank within a reasonable window after payday. A register reconciled weeks or even months later, without any explanation, is one of the most direct signals — it strongly suggests the document sat completely untouched before anyone actually checked it.

Look for: a reconciliation timestamp that lags weeks behind the pay date, with no note explaining the gap.

This doesn't automatically mean anything is wrong — a period of leave, a staffing change — but without a note that explains it, it stays an unexplained delay.

2 · A gross-to-net waterfall that doesn't foot

Gross pay minus every deduction category should equal net pay, exactly, on every register. A waterfall that's off by even a small amount is a direct signal that a deduction was applied incorrectly, twice, or not at all.

Look for: a register where gross pay minus the sum of all listed deductions doesn't equal the stated net pay figure.

This is usually the fastest check an auditor runs, because it requires nothing beyond the register itself — no bank statement needed to catch it.

3 · Net pay with no corresponding bank debit

A register that shows net pay disbursed should have a matching bank transaction within the payroll provider's usual clearing window. A payment shown as issued with no corresponding debit is a signal that the payment never actually cleared, or cleared somewhere unexpected.

Look for: a register line marking net pay as paid, with no bank transaction of a matching amount within a reasonable window.

This is exactly the kind of gap a systematic bank-to-register match is built to catch early, before it's an auditor finding.

4 · Tax withholding that doesn't match the jurisdiction

An employee's tax withholding should reflect the jurisdiction they actually work in, not just the one they were hired into. A withholding rate that doesn't match an employee's current work location — after a move, a remote-work change — is a signal worth checking against the personnel record.

Look for: a withholding rate on the register that doesn't correspond to the tax rate for the employee's current work jurisdiction.

This one is easy to miss because nothing about the register itself looks wrong — the amount withheld is internally consistent with the rate applied, it's just the wrong rate for where the work actually happened.

5 · Benefits deductions never remitted to the provider

Money deducted from an employee's paycheck for benefits or retirement contributions should show up as a remittance to the relevant provider within a reasonable window. A deduction that's been withheld for several periods without a matching remittance is a serious signal — it can mean the money is sitting somewhere it shouldn't be.

Look for: benefits or retirement deductions accumulated on the register with no corresponding remittance transaction to the provider.

This is one signal that genuinely warrants prompt attention rather than a routine note — a delayed remittance can carry compliance consequences beyond the reconciliation itself.

6 · A terminated employee still on the register

An employee who left the company should stop appearing on the register after their final pay run, apart from a documented severance or final-pay adjustment. Continued pay to a terminated employee, without an explicit reason on file, is a signal an auditor treats seriously, since it can indicate either a process failure or something worse.

Look for: a payment to an employee whose termination date, on file elsewhere, precedes the pay period on the register.

Most of the time this traces to a simple timing gap between when HR recorded the termination and when payroll processed that period's run — but it's exactly the kind of gap that needs a documented explanation rather than an assumption that it will sort itself out.

7 · An off-cycle payment with no documented reason

A payment issued outside the regular payroll schedule — a bonus, a correction, an advance — should carry a documented reason and an approval trail. An off-cycle payment with neither is a signal worth tracing back to its origin before an auditor has to ask.

Look for: an off-cycle register entry with no linked approval, reason code or supporting documentation.

An off-cycle payment isn't inherently a problem — corrections happen, advances happen — but one without any supporting paper trail is indistinguishable from an unauthorized payment until someone tracks down who approved it.

8 · Segregation of duties that doesn't actually exist

A payroll process where the same person can add a new employee, set their pay rate and approve the payment has no built-in check against an error or a deliberate manipulation. Auditors look specifically for whether that separation exists in practice, not just on an organizational chart.

Look for: one individual with system access to both create employee records and approve payroll runs, with no independent review step.

This signal is about the process, not any specific transaction — it's a structural weakness that makes every other signal on this list harder to catch reliably.

9 · A pay rate that doesn't match the personnel file

An employee's pay rate on the register should match the rate documented in their personnel file or offer letter. A discrepancy between the two — even a small one — is a signal that either the register or the file is out of date, and which one is wrong matters.

Look for: a register pay rate that differs from the rate on file in HR records, without a documented raise or correction.

A mismatch here is worth resolving quickly regardless of direction — an underpayment creates a wage claim risk, and an overpayment creates a recovery problem that only gets harder to unwind the longer it continues unnoticed.

A pattern of small, consistent discrepancies across several employees points to a systemic issue with how rate changes get entered into payroll, rather than several unrelated one-off mistakes that each need their own explanation.

10 · Headcount that drifts from the general ledger

The employee count on a payroll register should reconcile to the headcount reflected in the general ledger's payroll accrual. A drift between the two — more employees paid than accrued for, or fewer — is a signal that the accrual process and the actual payroll run have fallen out of sync.

Look for: an employee count on the register that doesn't match the headcount implied by the general ledger's payroll accrual entry.

FlowParse
flowparse.io

The pattern behind all ten

Looked at together, none of the ten signals is about a single transaction being wrong in isolation. Every one is about consistency between the register and something else that surrounds it — the bank, the personnel file, the general ledger, the prior period's pattern for the same employee.

That's precisely why a check based only on the register's own total never catches any of these ten. It takes a comparison across sources, not a sum within one, and looks like a mystery only when one side is compared to the other from memory instead of read and matched directly.

FlowParse
flowparse.io

What an unresolved signal actually costs

None of these ten sound expensive individually. A late reconciliation costs nothing but a little scrambling. A pay-rate mismatch on one employee is a quick fix once found. The real cost shows up at audit time, when an auditor finds several of these unresolved and has to widen their sample to rule out a systemic issue across the whole population.

A wider sample means more auditor hours, which means a longer audit and a larger invoice — the cost of catching these ten signals internally, every period, is almost always smaller than the cost of an auditor finding them first.

There's a slower, less visible cost too. An employee who notices, once or twice, that their pay doesn't quite match what they expected starts trusting the payroll process a little less each time — not because anyone did anything wrong, but because nobody explained where the discrepancy came from. That erosion of trust is harder to fix than the number itself.

Who inside the company should be catching this

In most companies, nobody has this as an explicit job. An HR manager runs payroll and moves to the next task. A controller sees the bank activity weeks later, disconnected from the specific pay run it came from. The gap between the two sits in nobody's specific lane — which is exactly why it goes unexplained more often than it should.

The ten-minute check described below doesn't need a dedicated internal auditor to work. It needs to sit with whoever already has the register in hand at close, with these ten signals as a concrete checklist rather than a vague instinct that something looks off.

What tends to make the difference isn't adding headcount, it's making the check specific enough that it doesn't depend on the reviewer remembering all ten signals from memory. A short, named list, checked against a document that's already in front of someone, survives a busy close in a way that a vague intention to “double-check the numbers” never does.

One signal, from flagged to explained

It's worth following one case through, because a concrete example makes more sense than a list of rules on their own.

A biweekly register closes with net pay of $58,410. The expected bank debit doesn't appear the next business day as usual. A quick check confirms the payroll run did process successfully — so the gap isn't simple provider delay, since that window has already passed.

The bank statement shows the answer two days later: the debit posted with a one-day delay because it fell on a bank holiday the payroll calendar hadn't accounted for — signal one and a timing issue at once. The transaction, once matched against the register, accounts for the full amount exactly.

What made this fast wasn't luck — it was checking the bank statement for a trace number before assuming the payment was simply missing.

A ten-minute check before you close the period

Does gross pay minus every deduction category exactly equal the stated net pay?

Has enough time passed for every register line to have actually cleared the bank?

Does the register's employee count match what's reflected in the general ledger accrual?

Is every off-cycle payment linked to a documented reason and an approval?

Does the headcount and pay-rate detail match what's on file in HR records?

Five questions, ten minutes, applied before a period gets closed or a discrepancy gets escalated. It's far cheaper than unwinding a finding an auditor surfaces months later.

FlowParse
flowparse.io

If a discrepancy already made it past close

The first step is locating the actual reconciled figure — the confirmed register and bank match, once every category is accounted for — rather than guessing at a correction.

The second step is comparing that figure to what was actually recorded in the books, and correcting the entry rather than trying to force the original figures to match through a workaround, which rarely holds up under a closer look.

The third step, once resolved, is asking whether the same source — a manual entry instead of a reconciled figure — will cause the same problem next period, and fixing the process rather than just this one instance.

FlowParse
flowparse.io

An eleventh signal, less common but worth knowing

Beyond the ten regular patterns, an eleventh shows up occasionally at companies with contractors paid alongside employees: a worker classified as a contractor who appears on the payroll register with deductions typically reserved for employees — tax withholding, benefits — which is inconsistent with their classification.

It's uncommon enough that most period-end reconciliations never encounter it, which is exactly why it's worth naming separately — a classification mismatch like this carries its own compliance exposure well beyond a simple reconciliation gap.

How to actually respond to an auditor's question

An answer like “the numbers usually work out” gets a follow-up request for more testing. An answer like “register 4471 for the March 14th pay period shows net pay of $58,410, matched to a bank debit on March 17th with trace number ending 2291, here's the reconciliation sheet” gets accepted, often without further questions.

The difference is entirely in the specificity of the answer, and the specificity is only possible once the register and bank have already been matched — which is the whole point of doing the reconciliation before, not after, the audit request arrives.

It also matters how the answer is delivered. A response that comes with the register reference, the expected amount and the actual amount already laid out reads as a company that has its process under control — which tends to narrow an auditor's sample rather than widen it, simply because the auditor doesn't have to spend time gathering information that was already provided.

When the same signal shows up period after period

A signal explained once by a known timing issue is unremarkable. The same unexplained signal, showing up period after period, is a different situation — it usually means one of the ten patterns is present but not being accounted for consistently, rather than a new problem each time.

A recurring signal is worth tracing back to its source once, carefully, rather than re-investigating it fresh every single period. Once identified — a benefits provider that always batches monthly, say — the explanation applies going forward without needing to be rediscovered each time.

A signal that recurs but changes shape period to period is a different case again — usually a process gap rather than a fixed, predictable timing pattern.

Does this apply to smaller companies too?

Every company that runs payroll, regardless of size, produces some version of these ten signals — a five-person startup, a two-hundred-person mid-market company. What changes with size isn't whether the signals apply, but how much volume sits behind each one and how much a single unresolved signal can compound before someone notices.

A five-person company can usually spot a pay-rate mismatch by eye, because it involves one employee out of five. A two-hundred-person company can't rely on the same eyeballing — the same mismatch is one line out of hundreds, and needs a systematic check rather than familiarity with every individual employee to catch it.

What a new controller usually gets wrong first

A controller new to overseeing payroll almost always makes the same first mistake: treating a register that's internally consistent — gross minus deductions equals net — as fully reconciled, without ever checking it against the bank or the general ledger.

The fix isn't a long training document — it's walking through one real period's reconciliation, seeing an actual signal surface and get resolved, so the process stops looking like a formality and starts looking like the genuine cross-check it actually is.

A second common mistake follows close behind the first: once a new controller learns to check the bank, they sometimes stop checking headcount and personnel-file consistency entirely — which is how a pay-rate or classification issue slips past unnoticed for a full audit cycle.

What actually makes this easier

None of these ten signals require specialized software to understand — a payroll register and a bank statement, read side by side, are enough to catch most of them. What's genuinely tedious is doing that side-by-side read consistently, period after period, across every register a company closes.

A document reader that pulls the relevant figures from both sides automatically — gross pay, net pay, tax withholding, bank transactions — removes exactly that tedium, leaving the actual judgment call, when there is one, to a person instead of a spreadsheet full of manually retyped numbers.

The full step-by-step routine, including how often to check and what to do with an unexplained signal once one turns up, is in how to reconcile a payroll register to the bank — this article covers the why, that guide covers the how.

Either way, the goal is the same: a signal that's explained the first time it's noticed, not re-investigated from scratch every time it resurfaces, period after period, by whoever happens to be closing that month.

What this article isn't

This isn't accounting, legal or audit advice, and it isn't a guarantee that every signal you encounter falls into one of these ten categories. It describes patterns that come up often, not an exhaustive list covering every company's specific circumstances.

A signal that doesn't match any of these ten explanations after a genuine check is worth raising with your auditor or controller directly — that's a real discrepancy, not a timing difference waiting to resolve itself.

The step-by-step routine to check this on a regular cadence, rather than only when something looks off, is in how to reconcile a payroll register to the bank.

Frequently asked questions

Check your own register

Upload a payroll register and a bank statement and see exactly what reconciles and what needs a second look.

Keep reading