Inside the Invisible Payroll: How Fictitious Employees and Duplicate Records Are Draining British Businesses Dry
The Fraud Nobody Sees Coming
It rarely announces itself. There is no ransomware notice, no dramatic confrontation, no sudden disappearance of funds from a central account. Payroll fraud — specifically the manipulation of employee records to generate payments to fictitious or duplicated individuals — tends to operate in silence, accumulating losses over months or years before a routine query or staff departure brings it into the light.
For British businesses, the scale of the problem is sobering. The Association of Certified Fraud Examiners estimates that organisations globally lose approximately five per cent of annual revenue to occupational fraud, with payroll schemes among the most common categories. Extrapolated across the UK's private sector, that figure represents tens of billions of pounds in avoidable financial leakage each year — much of it undetected by standard audit procedures.
Understanding precisely how these schemes operate, and why conventional controls so frequently fail to catch them, is the first step toward building a genuinely resilient payroll environment.
How Ghost Employees Enter the System
A ghost employee is, at its simplest, a name on the payroll that corresponds to no legitimate, active member of staff. The mechanisms by which such records are created vary considerably in sophistication.
In smaller organisations, the most common route is straightforward: a payroll administrator with insufficient oversight retains a departing employee on the system after their leaving date, redirecting payments to a personal account or a mule account they control. In larger enterprises, the scheme tends to be more elaborate — fictitious identities are constructed using plausible National Insurance numbers, bank account details, and employment histories, sometimes inserted during periods of rapid headcount growth when individual records attract less scrutiny.
A variant that receives less attention is the duplicate record. Here, a legitimate employee appears in the system under two slightly different identifiers — a middle name included in one record but not another, a minor discrepancy in a date of birth, or an old payroll reference number that was never properly retired. Each iteration generates its own payment run. The employee receives their correct salary; the duplicate generates a second payment that flows elsewhere.
What makes both schemes particularly insidious is that they exploit the natural trust placed in established systems. Once a record exists and has processed payments without incident for several cycles, it acquires a kind of institutional legitimacy that can deter scrutiny.
Why Standard Audits So Frequently Miss the Signs
Traditional audit approaches focus heavily on transactional accuracy — verifying that payments correspond to approved figures, that tax deductions have been correctly calculated, and that bank account details match those on file. These checks are valuable, but they are largely backward-looking and rely on the integrity of the underlying records.
The critical weakness is that most audit frameworks do not routinely cross-reference payroll data against independent sources of organisational truth. A ghost employee record may be entirely consistent with all internal payroll documentation while bearing no relationship whatsoever to the HR database, the physical access control system, or the corporate email directory.
Furthermore, payroll teams in many British organisations operate under significant administrative pressure, particularly following the expansion of Real Time Information (RTI) reporting obligations under HMRC. The emphasis on compliance with submission deadlines can inadvertently crowd out the kind of reflective analysis needed to identify structural anomalies in the underlying data.
Building a Detection Framework: Practical Steps for UK Finance Teams
Addressing this vulnerability does not require a wholesale overhaul of existing systems. A structured, layered approach to data reconciliation can surface anomalies effectively without disrupting normal payroll operations.
Cross-system reconciliation as standard practice. The payroll register should be reconciled against the HR information system on at least a quarterly basis, with particular attention paid to employees whose records exist in one system but not the other. Any discrepancy should trigger a mandatory verification process before the next payment cycle runs.
National Insurance number deduplication. Every individual employed in the UK is assigned a unique National Insurance number. Running a deduplication check across all payroll records using NI numbers as the primary key will, in most cases, immediately expose any duplicated identities. Organisations that have undergone mergers, acquisitions, or system migrations should treat this as an urgent priority, as legacy data transfers are a common source of undetected duplicates.
Bank account mapping. Where multiple employees share a single bank account or sort code and account number combination, the likelihood of legitimate coincidence is extremely low. Automated flagging of shared banking details is a relatively simple control to implement and has a strong track record of surfacing both ghost employee schemes and instances of accommodation fraud.
Leaver protocols and system access termination. One of the most reliable indicators of a ghost employee scheme is a payroll record for an individual whose system access — email, building entry, software licences — has been terminated. Formalising a joined-up leaver process that simultaneously updates HR records, payroll, IT access management, and facilities is among the most cost-effective preventative measures available.
Analytical profiling of payment patterns. Payroll analytics tools can flag statistical outliers: employees whose payment history shows unusual regularity of adjustments, those who have never taken annual leave (and therefore never triggered absence management crosschecks), or those whose bank account details were changed immediately prior to a period of elevated pay. These patterns do not confirm fraud, but they warrant investigation.
The Cultural Dimension: Oversight Without Paranoia
It is worth acknowledging that robust payroll controls carry a reputational dimension within organisations. Finance leaders implementing new verification procedures must communicate their purpose clearly — protecting the business and its legitimate employees — rather than allowing them to be perceived as expressions of distrust toward the workforce.
Segregation of duties remains the cornerstone of effective payroll governance. The individual who creates or amends employee records should not be the same person who approves payment runs. In smaller businesses where this separation is structurally difficult, a designated independent reviewer — even if that role is fulfilled by a part-time finance director or a trusted external adviser — provides meaningful additional protection.
Whistleblowing channels, discussed elsewhere in UKAC Business Hub's editorial coverage, also play a significant role here. Colleagues are frequently the first to notice that a departed team member's name continues to appear on internal communications or that an unfamiliar individual is listed on a shared departmental roster. A culture in which such observations can be reported without professional risk is a material fraud deterrent.
The Cost of Inaction
Payroll fraud schemes, once established, tend to persist. The average duration of an occupational fraud case before detection is eighteen months, according to global research data — and payroll schemes, precisely because they mimic legitimate transactions, often run considerably longer. By the time the loss is quantified, the damage to cash flow, to team morale, and in some cases to the organisation's relationship with HMRC can be substantial.
For British businesses operating in an environment of sustained cost pressure, the case for investing in payroll integrity is straightforward: the controls are not expensive, the detection frameworks are not technically complex, and the alternative — continuing to fund an invisible payroll that serves no one but the fraudster — is simply not acceptable.