ADP Payroll Security and Audit 1 — Questions and Answers
Question 1: What is the principle of 'segregation of duties' in payroll and why is it important?
- Dividing payroll tasks among multiple employees so that no single person can both initiate and approve a transaction, reducing the risk of fraud or error (Correct answer)
- Assigning all payroll functions to a certified payroll specialist to ensure accuracy
- Separating payroll from HR so each department has independent data access
- Dividing payroll responsibilities between the employer and ADP
Correct answer: Dividing payroll tasks among multiple employees so that no single person can both initiate and approve a transaction, reducing the risk of fraud or error
Segregation of duties prevents payroll fraud and error by ensuring no one person controls an entire payroll transaction from setup through approval and payment.
Question 2: In ADP, what feature allows administrators to restrict which payroll actions each user can perform?
- Role-Based Access Control (RBAC) within ADP's security settings (Correct answer)
- Employee Self-Service permission groups
- ADP SmartCompliance user hierarchy
- ADP Time & Attendance supervisor codes
Correct answer: Role-Based Access Control (RBAC) within ADP's security settings
ADP's Role-Based Access Control assigns specific permissions to user roles so each individual can only access and perform the payroll functions appropriate to their job responsibility.
Question 3: What is a 'ghost employee' scheme in payroll fraud and how can ADP controls help prevent it?
- A ghost employee is a fictitious or terminated employee left on the payroll to divert paychecks; ADP prevents this through user access controls, approval workflows, and regular audits of the employee master file (Correct answer)
- A ghost employee is an employee whose direct deposit failed and whose check was cashed fraudulently
- Ghost employees are employees misclassified as contractors to avoid payroll taxes
- A ghost employee scheme involves duplicating a real employee's payroll record
Correct answer: A ghost employee is a fictitious or terminated employee left on the payroll to divert paychecks; ADP prevents this through user access controls, approval workflows, and regular audits of the employee master file
Ghost employee fraud involves adding fictitious payees or keeping terminated employees active; ADP mitigates this risk through access controls on employee setup and regular system audits.
Question 4: How often should payroll audit reports be reviewed to detect unauthorized changes in ADP?
- Each pay period, or at a minimum monthly, and before each payroll is processed (Correct answer)
- Annually during the year-end W-2 preparation process
- Only when an employee raises a complaint about their pay
- Quarterly, aligned with Form 941 filing deadlines
Correct answer: Each pay period, or at a minimum monthly, and before each payroll is processed
Best practices require reviewing ADP audit trail reports before each payroll run and at least monthly to catch unauthorized changes before they result in incorrect payments.
Question 5: What is the purpose of ADP's Audit Trail Report?
- To log all changes made to employee records, pay rates, deductions, and payroll configurations, including who made the change and when (Correct answer)
- To summarize total payroll costs by department for budget review
- To list all direct deposit transactions processed in a pay period
- To document employee time and attendance exceptions
Correct answer: To log all changes made to employee records, pay rates, deductions, and payroll configurations, including who made the change and when
ADP's Audit Trail Report creates a time-stamped log of every change made to the payroll system, recording the user, date, and nature of each modification for compliance and fraud detection.
Question 6: Which payroll data elements should be treated as highly sensitive and protected under data privacy regulations?
- Social Security numbers, bank account details, compensation amounts, and tax withholding information (Correct answer)
- Employee names and department codes only
- Job titles and hire dates
- PTO balances and performance review scores
Correct answer: Social Security numbers, bank account details, compensation amounts, and tax withholding information
Payroll data including SSNs, bank account numbers, wages, and tax information are classified as sensitive personal and financial data requiring encryption, access controls, and compliance with privacy laws.
What is the principle of 'segregation of duties' in payroll and why is it important?