Internal audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Payroll is usually a company's largest recurring payment, and it is run on personal data, approvals and monthly deadlines. A weak control here means ghost employees, wrong deductions, unrecovered advances or an unpaid exit settlement. An internal audit of payroll and HR checks the chain from hiring to exit. This guide gives an illustrative programme that HR and finance teams can use before an audit.
There is no standard on internal audit specific to payroll. The approach rests on SIA 120 (internal controls), SIA 130 (risk-based audit), SIA 310 (planning) and SIA 320 (evidence), with SIA 150 (compliance with laws and regulations), all from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. The checklists below are TaxClue's own and are illustrative; nothing in them is mandatory unless a cited standard or a linked law post says so. Check current versions on internalaudit.icai.org.
Audit payroll from the risk assessment: test who is on the master, whether pay follows attendance and approvals, whether deductions and settlements are computed under the applicable rules and whether no one person can create, approve and pay. Under SIA 150 the auditor evaluates the compliance framework; it does not take over the compliance function.
How the SIAs shape the audit
SIA 130 (paragraph 5.1) and SIA 310 (paragraph 3.4) ask for risk-based planning; SIA 120 (paragraphs 5.2 and 5.3) for tests of design and operating effectiveness of key controls linked to risks; SIA 320 (paragraph 3.1) for sufficient and appropriate evidence. SIA 150 adds the compliance angle. Where a formal compliance framework exists, the auditor evaluates its design, implementation and operating effectiveness (paragraph 5.1); where none exists, the auditor highlights exposures and recommends improvements (paragraph 5.2); and the auditor does not act as the compliance officer or deal directly with regulators (paragraph 5.5). Our guide to SIA 110, 130, 140 and 150 explains these paragraphs. A statutory compliance review of payroll is also available through our payroll compliance audit service.
Payroll and HR: an illustrative control and test map
| Area | Illustrative risk | Illustrative key control | Illustrative test |
|---|---|---|---|
| Master data | Ghost or duplicate employee; unapproved pay change | Joining form and approval before creation; change log reviewed by HR head | Match master to appointment letters and ID; review pay changes in the period |
| Bank details | Salary paid to a wrong or shared account | Bank detail change needs written request and verification | Test duplicate bank accounts across employees; review changes |
| Attendance and leave | Pay for days not worked; leave balances wrong | Attendance system feeds payroll; leave approved by manager | Compare payroll days with attendance and leave records |
| Payroll processing | Calculation errors; unauthorised components | Input sheet approved; payroll run reviewed against previous month | Re-compute a sample; compare month-to-month variance by employee |
| Statutory deductions | Wrong or late deductions and deposits | Deduction rules set up and reviewed by a person other than the processor; deposit checklist | Re-compute deductions; compare payment dates with due dates |
| Advances and loans | Advances never recovered | Approval limits; recovery schedule | Test recoveries against schedule; review old balances |
| Payment | Payment file altered after approval | Approval of the bank file; separate payer | Compare payroll register, bank file and bank debit |
| Exits and final settlement | Dues paid late or wrongly; access not removed | Exit checklist with HR, finance and IT sign-offs; settlement review | Test leavers: last day, settlement calculation, timeliness, access removal |
Labour law governs several of these areas. This guide does not set out rates or ceilings; for the wage codes and their rules, read our posts on the four labour codes and on the wage slip, composition and nomination forms, and have the auditor compare the company's practice with the version that applies in your State.
Segregation of duties
SIA 120 lists segregation of duty as a typical control activity (paragraph 3.1). In payroll the aim is that no single person can add an employee, change pay, run payroll and release payment. A simple illustrative matrix:
| Task | Should not also do |
|---|---|
| Create or change employee master | Approve payroll; release payment |
| Process payroll | Approve master changes; release payment |
| Approve payroll | Create employees; process the run |
| Release bank payment | Create or change master data |
Small businesses often cannot split every task. The auditor then looks for a compensating control, such as an owner's review of the payroll variance report and bank file, and records it.
Analytics that suit payroll
Using the approach of SIA 6, paragraph 5 (relationships between financial and non-financial data such as payroll cost and number of employees), illustrative tests are: headcount and payroll cost by month; duplicate bank accounts, phone numbers or addresses on the master; employees paid with no attendance; payments after the last working day; pay components that change without a documented decision; and overtime by supervisor. Where analytics suggest possible fraud, see our article on fraud risk and red flags.
Reporting
Each finding states the observation, the control or rule it is measured against, the evidence and extent, the risk, a recommendation and management's response with owner and date. A written draft goes to HR and finance before the report is final (SIA 370, paragraph 3.3). Because payroll data is confidential, the report goes only to those who engaged the auditor (Basic Principles, paragraph 3.4); our article on SIA 360, 370 and 390 covers reporting.
Illustrative example
Illustrative: Shreyas Hospital Pvt Ltd has 420 staff on monthly payroll. The internal auditor compares the master to attendance and finds 11 employees paid for months with no attendance; nine had left, and the exit checklist was not shared with payroll. Two bank accounts appear against two employee names each. The final settlements of 14 leavers were paid on average 70 days after the last working day. The auditor reports the exit process and the bank-account duplicate check as design gaps, and the unmatched attendance as operating failures. Management recovers the amounts, adds a payroll hold on any employee without a joining or exit record and agrees owners and dates. Related review of a hospital's accounts is covered in our article on audit of educational institutions and hospitals.
Common lapses
- Testing a payroll register without checking it against the master and attendance.
- No exit checklist reaching payroll and IT.
- A single person running payroll end to end with no review.
- Reading deductions only against the previous month and not against the rule.
Need help with a payroll review?
If you want your payroll controls and statutory deductions reviewed, or a ghost employee test run on your master data, our team can help through payroll compliance audit.
Key takeaways
- Start from a risk assessment; test design and operation of controls (SIA 120, paragraphs 5.2 and 5.3).
- Check master data against attendance, bank accounts and appointment records.
- Segregate creating employees, running payroll, approving and paying, or add a compensating control.
- Under SIA 150 the auditor evaluates the compliance framework and does not run it.
- Labour law specifics come from the linked posts; the checklists here are illustrative.
Read next
- SIA 110, 130, 140 and 150: assurance, risk, governance and compliance
- Internal audit of procurement and inventory
- Internal audit of treasury and related party transactions
- Audit of educational institutions and hospitals
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
