Ask who approves payroll at a company of 60 people and the answer is often a name, singular. The same person builds the run, checks it and submits it. Nobody designed that. It is what happens when a process grows out of one competent individual.

It works right up until it does not, and the failure is expensive in a specific way: payroll errors reach every employee at once, they are visible, and they arrive with tax and filing consequences attached.

The fix is not more software. It is separating two jobs that should never have been one.


Prepare and approve are different people

The control that matters most is the cheapest one to implement. Whoever assembles the run does not release it.

That is it. Everything else on this page is detail.

The person preparing enters changes, resolves exceptions and produces a draft register. A second person compares that register against the prior period, asks about anything that moved, and releases. Neither role needs to be senior. They need to be different.

At 25 to 250 employees the usual objection is that there is only one person who understands payroll. That is the finding, not the obstacle. A process only one person can check is a process nobody is checking, and it is also a single point of failure the week that person is on holiday or leaves.

The approver does not need to run payroll. They need to be able to read a variance report and ask a question.


The close calendar

Work backwards from the pay date, and put the dates in a shared calendar rather than in somebody's head.

Stage Who What has to be true
Input cutoff Managers and HR Timesheets in, approvals done, new hires and leavers entered
Preparation Payroll preparer Changes applied, exceptions resolved, draft register produced
Variance review Approver Every difference against last period explained
Release Approver Funding confirmed, submission made
Post-close Payroll and finance Register filed, journal posted, exceptions logged

The input cutoff is the stage most companies skip formalising, and it is the reason so many runs need corrections. A change that arrives after the cutoff goes into the next period or into a documented off-cycle. It does not go into the run quietly.


What the approver actually checks

Not every line. Four comparisons against the previous period, which catch most of what goes wrong:

  • Headcount. Number of people paid, with joiners and leavers accounted for by name.
  • Gross total. Any movement beyond expected joiners, leavers and known increases needs a reason.
  • Anyone whose net pay moved materially. A change in one person's pay is either explained or it is an error.
  • New or missing deduction and tax codes. A code appearing for the first time, or disappearing, is usually a configuration change nobody announced.

That review takes about twenty minutes on a stable run. It is the cheapest twenty minutes in the finance calendar.


Off-cycle payments

Off-cycles are where controls quietly lapse, because they are urgent by definition and the whole point is speed.

Give them the same two-person rule and a lower ceremony version of the same trail: who requested it, why, who approved it, what it cost including employer taxes. A missed commission or a termination payment that has to go out today is a legitimate reason to run one. Convenience is not, and an off-cycle habit is usually a symptom of an input cutoff nobody enforces.


The trail, and who eventually asks for it

Keep, per period: the final register, evidence of who approved it and when, the variance explanations, the funding confirmation, and the filings with their confirmations.

Produce it from the system rather than by assembling it later. The difference matters because the people who ask for this material ask on their timetable, not yours: an auditor, a buyer's diligence team, or an employee's lawyer. Reconstructing approvals after the fact is possible and it looks exactly like what it is.

Two conditions make this urgent rather than good practice. If you have taken institutional investment, payroll controls appear in diligence. And if one person can both change their own compensation record and release the payroll containing it, you have a segregation gap that any auditor will write up.


On one page

  1. The person who prepares does not release.
  2. Publish a close calendar and enforce the input cutoff.
  3. Approver checks headcount, gross, individual net movements, new codes.
  4. Off-cycles get the same two people and a written reason.
  5. Keep the register, the approval, the variances and the filings, generated rather than assembled.
  6. Nobody approves a run containing a change to their own pay.

Most of this is configuration rather than headcount, and it can usually be set up inside the system you already run. If you want the calendar and the approval chains built against your own pay cycle, book a 20-minute call.

Download this guide

Take it with you

Take the whole thing with you.

The whole guide as one PDF you can send to your team. We email it over.

One email, with the PDF attached. Nothing else.

Common questions

Can one person run payroll end to end?

They can, and it is the most common segregation gap we find. Preparation and release should sit with different people, and neither role has to be senior. The approver needs to read a variance report and ask a question, not run payroll.

What should be checked before every submit?

Four comparisons against the previous period: headcount with joiners and leavers named, gross total, any individual whose net pay moved materially, and any deduction or tax code appearing or disappearing for the first time. On a stable run that takes about twenty minutes.

How should we handle off-cycle payments?

The same two people, plus a written reason and the full cost including employer taxes. A termination payment or a missed commission is a legitimate off-cycle. Convenience is not, and a habit of them usually means the input cutoff is not being enforced.

On your own setupTwenty minutes with someone who runs these builds. We will tell you which parts of this apply to you, and which do not.