Who Can Change a Salary, and Who Would Know?
Payroll is the one process in most companies where a single person can create a payee, set an amount, approve it and send the file. The controls that would prevent that are cheap, standard and almost never configured, because payroll is implemented under deadline by whoever can make it run.
· 6 min read · Written by Faceela Research & Editorial Team
In a large number of mid-sized companies, one person can add an employee, set their bank details, set their wage, run the payroll, approve it and produce the bank file. Nobody has decided this. It is the residue of an implementation done under time pressure by whoever could make the thing work, and it survives because payroll runs correctly every month and nothing ever draws attention to it.
The payroll controls that close it are neither exotic nor expensive. Four separations, four pre-run checks and one monthly reconciliation, all of them standard capability in any competent system: the person who changes a wage is not the person who approves the run; the person who changes bank details is not the person who pays; every change to a payee's standing data is logged with a before and an after; and the run is compared against the previous one before the file leaves the building. What makes this worth writing about is not the controls, which are obvious, but the reason they are absent — and the reason is always the same, which is that payroll is configured last, by one person, against a deadline.
That is the answer. The rest of this article is the four checks, the reconciliation nobody runs, and what the current statutory deadline does to all of it.
The four pre-run checks
Each takes minutes and each catches a different class of error. Run them in this order, before the file is produced rather than after.
The variance run. Compare this payroll to the last one, employee by employee, and list every difference above a threshold. Most will be explainable — a joiner, a leaver, overtime, a genuine increase. The value is in the two or three that nobody expected. This one check catches more real errors than the other three together, and it is a report.
The exception list. New payees, changed bank details, payees with no attendance record, negative or zero net pay, unusually high net pay, and duplicated bank accounts across employees. Each of these has an innocent explanation most of the time, which is exactly why each needs an explanation recorded rather than assumed.
The reconciliation to headcount. Number of payees on the run against number of active employees in the master, with the difference itemised. A payee who is not an employee is the single most important thing this list can find.
The gross-to-net proof. Total gross, total deductions, total net, tying to the ledger and to the file amount. Three totals that must agree, and a discrepancy that must be explained rather than adjusted.
The point of running them before rather than after is not pedantry. A correction after the file has gone is a reversal, a re-run, a conversation with a bank and, where the amount is wrong in an employee's favour, a recovery problem nobody enjoys.
The four separations
Standing data and approval. Whoever can change a wage, a bank account or a payee cannot be the person who approves the run. This is the single most important one and the most commonly missing.
Approval and payment. Whoever approves the payroll does not release the file to the bank. In many companies this one exists already for supplier payments and has simply never been applied to payroll.
Change logging. Every change to a payee's standing data carries who, when, before, after and — ideally — why. Notice that the "why" turns a log into something readable a year later. A log nobody can interpret is a log nobody reads.
Someone outside the process looks. Periodically, and unannounced: a sample of changes traced back to authorisation. Not because fraud is expected, but because a control nobody has ever tested is a control nobody knows works.
One point deserves emphasis because it is where these controls are usually defeated. If the access model gives an administrator the ability to change anything and the payroll administrator holds an administrator role, the separations above exist on the screen and not in reality. The general treatment of that problem is access control and segregation of duties, and payroll is the process where the consequences are most direct — it is the only one that moves money to individuals on a standing instruction.
The reconciliation nobody runs
There is a four-way reconciliation that almost no mid-sized company performs, and it is where errors that survive every check above come to light: the payroll register, the general ledger, the bank file and the employee master should all agree, every month, with every difference explained.
They diverge quietly. A leaver removed from the master and not from the payroll. A journal posted to the wrong account. A file amended manually after the run — which happens more often than anybody admits, and which is the single most dangerous habit in the whole process. A joiner paid from the wrong cost centre, which nobody notices because the total is right.
The discipline is simple and monthly: four totals, one page, every difference named. It takes an hour and it is the only test that covers the whole chain end to end rather than one link of it.
The deadline makes all of this harder
The UAE wage protection framework changed in 2026 and the operational effect is that the grace period gave way to a single unified due date — the instrument, its date and the specifics are stated with their source in the statutory side of UAE payroll, with its source, and should be read from the Ministry rather than from any summary.
Two consequences for controls. First, the time available to run the checks has shrunk, which creates pressure to skip them — and a control skipped under deadline pressure is a control that does not exist in the month it was most needed. Second, the upstream inputs have to arrive earlier, which puts weight on the attendance bridge and on whoever resolves its exceptions, as set out in why the clock-to-payslip handover is usually a person rather than a system.
So the checks have to be automated enough to run in minutes. A variance report that takes an afternoon to prepare will not be prepared in the month it matters.
What to do this month
- List who can do what today. Not the policy — the actual permissions, read out of the system. Most companies are surprised at this stage and the surprise is the finding.
- Implement the variance run, even as a spreadsheet comparison, and run it this month before the file goes.
- Separate standing-data changes from run approval, which is usually a permission change rather than a project.
- Start the four-way reconciliation and keep the page.
- Then test one control by tracing five changes back to their authorisation.
Step five is the one people skip and it is the one that tells you whether any of the rest is real. A control that has never been tested is a belief, and payroll is the process where the difference between a belief and a control is measured in money leaving the company on a standing instruction every month. Where nobody inside the business has the independence to run that test, it is a short piece of work for an independent read of the systems, and a much better one to commission in a quiet quarter than after a finding.
