Payroll fraud is rarely sophisticated. It is almost always the same handful of schemes, executed by someone with legitimate access, and it persists for years because it is small enough per instance that nothing prompts a look.
That combination has a useful implication: detection is a data exercise, not an investigative talent. The schemes leave statistical signatures, and the tests that reveal them can be run in an afternoon by anyone with access to a payroll register and a spreadsheet.
Ghost employees. A fictitious person, or a real former employee kept active, with payments directed to an account the perpetrator controls. The most lucrative scheme because it is recurring rather than one-time. See our ghost employee guide.
Inflated hours. A non-exempt employee reporting hours not worked, frequently with supervisor collusion or through a supervisor approving without reviewing.
Unauthorized rate changes. Someone with system access raises their own rate, or a colleague's, by an amount small enough to escape a variance threshold.
Commission and bonus manipulation. Fabricated sales, altered targets, or bonuses entered without authorization.
Expense reimbursement abuse. Duplicate submissions, personal expenses, altered receipts, or mileage that was never driven — often processed through payroll rather than accounts payable, where controls are lighter.
Diversion of legitimate pay. Changing a real employee's bank details to an attacker-controlled account. This is usually external rather than internal, but the detection overlaps. See our payroll data security guide.
Each test below is straightforward, and each targets a specific scheme. Run them quarterly.
Duplicate bank accounts. Sort every active employee by bank account and routing number and look for repeats. Legitimate matches exist — spouses, a parent and adult child — and each should be confirmed rather than assumed. An account shared by employees with no apparent relationship is the strongest single indicator of a ghost employee scheme.
Duplicate addresses. Same approach. Household members are legitimate; unrelated employees at one address warrant a look.
Employees with no deductions. A real employee almost always has something — a tax withholding, a benefit election, a garnishment. An employee with nothing but a net payment is worth examining, because a fabricated employee has no benefit elections to fabricate.
Employees who never take leave. Fraud requires presence. An employee who has taken no time off in years may be dedicated, or may be preventing anyone else from touching their work. This is the classic indicator across fraud types, not only payroll.
Missing or invalid Social Security numbers, or numbers that fail a format check.
Hours clustering at exactly the overtime threshold. Non-exempt employees consistently reporting exactly 40.0 hours suggests hours are being managed rather than recorded, in either direction.
Rate changes without a corresponding HR record. Reconcile every rate change in payroll against an approved change in the HRIS. A rate change with no upstream authorization is the whole finding.
Payments to terminated employees. Compare the payroll register against HR's termination list every cycle. This catches both fraud and the far more common process failure.
Round-number payments and manual checks issued outside the normal cycle.
Employees added and paid within the same cycle, particularly where the hire was entered by the person who released the payroll.
A supervisor whose approvals show an unusual pattern — approving instantly, approving in bulk, or approving their own subordinates' maximum hours consistently.
Headcount reconciliation. Total active employees per payroll versus per HR versus per department manager confirmation. The third source is the one that catches a ghost employee whose HR record was also fabricated.
Data tests find the scheme; these indicators direct where to look first.
The last one deserves emphasis because it is actionable. In a properly functioning department, a request for a report is routine. Resistance to a routine request is information.
Understanding the mechanism explains where to place controls.
Concentration of duties. Nearly every internal payroll fraud requires one person to both enter a change and release the payment. This is why segregation of duties is the single most effective preventive control. See our segregation of duties guide.
Amounts below thresholds. A rate inflated by 3%, or four hours added per week, clears most variance thresholds while producing meaningful cumulative value.
Recurring rather than one-time. A ghost employee paid biweekly for three years yields far more than a single fraudulent transaction, and each individual payment looks entirely normal.
Nobody owns the review. Reports exist and nobody is assigned to read them.
Trust as a control. Long-tenured, reliable, and indispensable is the profile in most cases — which is precisely why controls must be structural rather than personal.
Once you suspect fraud, the sequence matters more than the speed. Errors here have ended otherwise strong cases.
Do not confront the suspected individual. This is the most common and most damaging mistake. Confrontation destroys evidence, alerts an accomplice, and creates employment law exposure.
Escalate immediately to whoever should own it — senior management, internal audit, legal counsel, and where appropriate the insurer under a fidelity or crime policy, since notice obligations may be time-limited.
Preserve evidence before doing anything else. Suspend routine document destruction, preserve system logs and email, and image relevant data. Log files frequently have short retention windows.
Do not restrict the individual's access abruptly without a plan. It signals the investigation and may prompt evidence destruction. Access management should be coordinated as part of the plan, not as a first reaction.
Involve counsel early, particularly regarding privilege, interview procedures, and any potential referral to law enforcement.
Document contemporaneously — what was found, when, by whom, and what was done. Reconstructed chronologies are weak.
Quantify carefully. Establish the actual loss with documentation rather than estimating. Insurance recovery and any restitution depend on it.
Consider whether reporting obligations exist — insurer notice, auditor communication, and in regulated industries potentially a regulatory report.
Fix the control gap, not only the instance. A scheme that ran for three years reveals a structural weakness that a termination does not close.
Our How to Prevent Payroll Fraud session covers the control framework, and Online Internal Investigation Training & Certification Course covers investigation procedure.
That mandatory-vacation item is worth more than it appears. Requiring payroll staff to be absent while someone else runs the cycle is one of the few controls that surfaces a scheme without anyone looking for it.
Understanding how frauds are found in practice should shape where you invest, and the answer is not flattering to control frameworks.
Tips are the leading source. A substantial share of occupational frauds are discovered because someone reported them — a coworker who noticed a name they did not recognize, a manager who saw an employee they had never met on a departmental cost report, a bank employee who found a pattern odd. This is why an anonymous reporting channel is not a compliance formality but a genuine detection mechanism, and why it should be publicised rather than merely available.
Management review comes second, and it is the category most within your control — the variance report actually read, the reconciliation actually performed, the headcount actually confirmed.
Internal audit finds a meaningful share, particularly where audit performs the data tests described above rather than only testing controls.
Accident accounts for more discoveries than anyone would design for — a returned piece of mail, a duplicate address noticed by chance, a payroll clerk covering for an absent colleague and finding something odd. This last route is the argument for mandatory vacation as a control: it manufactures the accident deliberately.
External audit finds comparatively few payroll frauds, because a financial statement audit is scoped to material misstatement rather than to schemes sized below that threshold.
Two implications worth acting on. First, invest in the reporting channel — publicise it, make it genuinely anonymous, and respond to reports credibly, because a channel that produced no action once will produce no reports thereafter. Second, do not rely on the external audit. A clean audit opinion is not evidence that payroll fraud is absent, and treating it as such is a common and expensive misreading.
Ghost employees — a fictitious or terminated person kept active with payments directed to a controlled account; inflated hours reported by non-exempt employees, often with supervisor collusion or unreviewed approval; unauthorized rate changes below variance thresholds; commission and bonus manipulation; expense reimbursement abuse processed through payroll; and diversion of a legitimate employee's pay through altered bank details.
The strongest single test is sorting active employees by bank account and routing number to find duplicates — legitimate matches exist among household members and should be confirmed individually, but an account shared by unrelated employees is a serious indicator. Supplement with duplicate address tests, reports of employees with no deductions or no leave usage, and a headcount reconciliation comparing payroll against HR against department manager confirmation.
In the data: shared bank accounts or addresses, employees with no deductions, employees who never take leave, hours clustering at exactly 40.0, rate changes with no corresponding HR authorization, and payments to terminated employees. In behavior: one person controlling the entire cycle, resistance to cross-training or documentation, reluctance to take vacation, and — notably — resistance to a routine request for records.
Because it is small per instance and recurring. A rate inflated by a few percent or four hours added weekly clears most variance thresholds while accumulating meaningful value, and each individual payment looks normal. Nearly every internal scheme also requires one person to both enter a change and release the payment, which is why concentration of duties is the enabling condition rather than sophistication.
Do not confront the individual — that is the most damaging common mistake, destroying evidence, alerting accomplices, and creating employment law exposure. Escalate to senior management, counsel, and where applicable your insurer, since notice obligations may be time-limited. Preserve evidence immediately, including system logs with short retention windows, and coordinate any access changes as part of a plan rather than as a first reaction.
It is one of the few controls that surfaces a scheme without anyone looking for one. Requiring payroll staff to be absent while a colleague runs the cycle means a second person necessarily encounters the records — which is why reluctance to take leave is such a consistent indicator across fraud types. It costs nothing beyond scheduling and provides cross-training as a secondary benefit.
Run the data tests on a schedule and document the results. Involve counsel before investigating, and address the control gap rather than only the individual — a scheme that ran for years reveals a structural weakness a termination does not close.
Recommended Online Training Courses
Recommended Course(s)

1-770-410-1219
support@PayrollTrainingCenter.com


