People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Payroll Fraud Prevention and Detection Policy

Purpose

The purpose of this policy is to establish robust controls, procedures, and responsibilities to prevent, detect, investigate, and respond to payroll fraud within People Group Services Ltd (“PGS”).

This policy supports:

  • Compliance with HMRC PAYE regulations,
  • Mitigation of Joint and Several Liability (JSL) risk (Chapter 11 ITEPA),
  • Protection of clients, agencies, workers, and PGS from financial loss and reputational damage,
  • Reinforcement of PGS’s commitment to “Compliance Without Compromise”.

Scope

This policy applies to:

  • All employees, directors, and contractors of PGS,
  • All payroll operations including umbrella, PAYE, PEO, and CIS models,
  • All third-party payroll providers, agencies, MSPs, and intermediaries interacting with PGS payroll systems,
  • All systems used to process payroll, including the PGS Agency/MSP Portal.

Definition of Payroll Fraud

Payroll fraud includes, but is not limited to:

  • Creation of ghost employees or assignments,
  • Manipulation of gross pay, deductions, or net pay,
  • False or inflated hours, rates, or expenses,
  • Misappropriation of PAYE tax or National Insurance contributions,
  • Unauthorised changes to bank details,
  • Submission of falsified documentation (e.g., timesheets, KIDs, contracts),
  • Deliberate underpayment or non-payment to HMRC,
  • Collusion between internal staff and external parties.

Policy Statement

PGS operates a zero-tolerance approach to payroll fraud.

All payroll activity is subject to:

  • Full auditability,
  • Real-time verification against HMRC systems,
  • Granular reporting and transparency,
  • Segregation of duties and approval controls.

Any suspected fraud will be investigated promptly and may result in:

  • Disciplinary action (including dismissal),
  • Termination of supplier agreements,
  • Reporting to HMRC and/or law enforcement authorities.

Key Fraud Risks in Payroll

PGS recognises the following primary risk areas:

Worker & Assignment Risk

  • False identities or right-to-work fraud
  • Duplicate or fictitious workers
  • Incorrect engagement status

Pay Calculation Risk

  • Incorrect PAYE or NIC calculations
  • Manipulated payslip values
  • Incorrect application of tax codes or thresholds

Payment Risk

  • Diversion of wages to unauthorised bank accounts
  • Duplicate or unauthorised payments
  • Failure to remit PAYE/NIC to HMRC

Supply Chain Risk

  • Non-compliant umbrella providers
  • Hidden deductions or disguised remuneration schemes
  • Lack of visibility over subcontracted payroll providers

Preventative Controls

PGS implements the following controls to prevent payroll fraud:

Identity & Onboarding Controls

  • Full Right to Work checks in line with UK legislation
  • Verification of identity and bank account ownership
  • Mandatory documentation including:
    • Contracts of employment
    • Key Information Documents (KIDs)
    • Work-finding terms (where applicable)

Segregation of Duties

  • Separation between:
    • Payroll input
    • Payroll processing
    • Payroll approval
    • Payment release
  • No individual has end-to-end control of payroll transactions

System Controls

  • Role-based access to payroll systems
  • Multi-factor authentication (2FA)
  • Full audit logs of all changes and actions
  • Automated validation rules for payroll inputs

HMRC-Aligned Verification (Core PGS Control Framework)

PGS operates industry-leading controls including:

  • Payslip Validation Against HMRC Tools
    Every payslip is verified against HMRC’s own calculation tools post-payroll to ensure accuracy “to the penny”.
  • Real-Time Information (RTI) Transparency
    RTI submissions are available at:
    • Company level
    • Agency level
    • Worker level
  • Live HMRC PAYE Account Verification
    PGS provides a live HMRC PAYE account checker, enabling validation of:
    • Amounts owed vs paid
    • Payment timing
    • Full audit trail (time/date stamped)

After all, why not check against the authority that enforces the legislation?

Detection Mechanisms

PGS actively monitors for fraud using:

Automated Monitoring

  • Exception reporting (e.g., unusual pay variances)
  • Duplicate payment detection
  • Bank detail change alerts
  • Payroll reconciliation reports

Manual Oversight

  • Payroll reviews and sign-offs
  • Random sampling of payslips and assignments
  • Cross-referencing:
    • Timesheets
    • Contracts
    • KIDs
    • RTI submissions

Portal Transparency (Agency & MSP Oversight)

  • Agencies and MSPs can:
    • Review individual payslips
    • Validate calculations
    • Access RTI drilldowns
    • Confirm HMRC payments in real time

This ensures independent verification across the supply chain.

Reporting Suspected Fraud

All employees and stakeholders must report suspected payroll fraud immediately.

Reports can be made via:

  • Line management
  • Compliance team
  • Confidential reporting channels (where available)

Reports should include:

  • Nature of concern
  • Individuals involved
  • Supporting evidence (if available)

PGS operates a non-retaliation policy for whistleblowers.

Investigation Process

Upon suspicion of fraud:

  • Initial Assessment
    • Immediate risk evaluation
    • Temporary controls implemented if required
  • Formal Investigation
    • Conducted by Compliance and/or senior management
    • Review of system logs, payroll data, and documentation
  • Escalation
    • HMRC notified where required
    • Legal advisors engaged if necessary
  • Outcome & Action
    • Disciplinary action
    • Recovery of funds
    • Process improvements implemented

Third-Party & Supply Chain Assurance

PGS requires all partners to demonstrate compliance through:

  • Professional accreditation (e.g. Professional Passport, APSCo, SafeRec where applicable)
  • Evidence of:
    • PAYE compliance
    • RTI reporting
    • HMRC payment history
  • Participation in PGS transparency tools where required

Failure to comply may result in:

  • Removal from Preferred Supplier Lists (PSLs)
  • Termination of agreements

Record Keeping & Audit

PGS maintains:

  • Full payroll records in line with HMRC requirements
  • Audit trails for all payroll activities
  • Secure storage of all documentation

Internal and external audits are conducted periodically to ensure:

  • Ongoing compliance
  • Effectiveness of fraud controls

Training & Awareness

PGS ensures:

  • Staff receive regular training on:
    • Fraud risks
    • Compliance requirements
    • HMRC obligations
  • Updates are provided in line with:
    • Legislative changes (e.g., April 2026 JSL)
    • Emerging fraud trends

Policy Governance

  • Owner: Head of Compliance
  • Approved by: Board of Directors
  • Review Frequency: Annually or upon regulatory change

Related Policies

This policy should be read in conjunction with:

  • PAYE Reconciliation & HMRC Alignment Policy
  • Cybersecurity Policy
  • Data Protection & GDPR Policy
  • Contractor Onboarding Policy
  • Anti-Bribery & Anti-Corruption Policy
  • Whistleblowing Policy

Conclusion

People Group Services Ltd is committed to delivering complete transparency, HMRC-aligned verification, and industry-leading controls to eliminate payroll fraud risk.

Through a combination of:

  • Technology,
  • Process, and
  • Independent verification,

PGS ensures that every pound is accounted for, and every liability is visible, validated, and paid.

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 25th March 2026