For most businesses, payroll represents the single largest operational expense. Because payroll runs are frequent, highly automated, and massive in volume, they are the perfect hiding place for occupational fraud.
At the heart of the most devastating payroll schemes—such as the creation of “Ghost Employees”—is a classic failure in Segregation of Duties (SoD).
The Anatomy of a Ghost Employee
A ghost employee is a fictitious person on your company’s payroll. It might be a completely made-up identity, or an actual employee who has recently left the company but was never removed from the system.
For this scam to work, an internal bad actor needs a specific, toxic combination of access rights within your ERP or HR system:
- Access to Employee Master Data: The ability to create a new employee profile or alter the banking details of an existing/terminated employee.
- Access to Payroll Processing: The ability to authorize or execute the weekly/monthly payroll run.
If one person holds both keys, they can simply route the “ghost’s” salary directly into their own bank account. Because the system recognizes the employee as active, the direct deposit goes through smoothly, buried in a batch of hundreds of other legitimate payments.
Drawing the Line
Preventing payroll fraud requires a hard, non-negotiable line between Human Resources and Finance.
- HR’s Job: Creating employee records, managing salaries, and updating bank accounts.
- Finance’s Job: Reviewing the payroll register, ensuring it matches the approved budget, and executing the actual transfer of funds.
Under no circumstances should these roles overlap. As companies grow and ERP environments become more complex, it is easy for a trusted payroll manager to accidentally accumulate both permissions.
Automated SoD monitoring platforms scan your ERP for these exact conflicts. By immediately flagging any user holding this toxic combination, you can close the loop on payroll fraud before a single fraudulent paycheck is issued.

