HR and payroll workflow | Evidence checked August 29, 2026

Let AI surface payroll anomalies; make payroll prove every resolution

An AI alert is an attention signal, not a finding. Before payroll closes, freeze the pay-run state, reproduce the alert, trace the authorized source change, independently recalculate the amount, close every material exception, and require a named human release decision.

Pre-process register Independent recalculation Segregation of duties Named release gate

One-click AI pack

Run the payroll anomaly investigation

Paste this into ChatGPT, Claude, Gemini, or an enterprise-approved AI tool. Replace bracketed fields with sanitized, authorized evidence. The pack structures investigation; it does not approve payroll or interpret tax and employment law.

Payroll AI is moving into the pre-close investigation window

UKG's August 27 release describes Agentic Pay as a way for administrators to investigate pay activity in natural language, compare pay history, surface potential issues, and validate payroll before the run closes. That is a useful place for AI because the work is time-bound, repetitive, data-heavy, and consequential. It is also exactly where a plausible explanation can create false confidence.

The product announcement says payroll professionals remain in control. This guide turns that phrase into an operating record. A named reviewer needs the exact pay-run version, the complete employee population, the alert's rule or model version, the source change, the independent calculation, the disposition, the person who fixed it, and the evidence that the released run is the one reviewed.

The surrounding evidence argues for caution. UKG and KPMG surveyed more than 300 decision-makers at very large organizations and reported fragmented vendor landscapes, limited first-time-right measurement, and material payroll leakage. Because UKG sponsored the research, use the figures as vendor context, not an independent performance benchmark. The control problem is still credible without the headline numbers: payroll combines high-volume inputs, effective dates, local rules, exceptions, integrations, approvals, and a deadline that cannot wait for a vague investigation.

Current practitioner discussion is not a product endorsement. r/Payroll users discussing a UKG interface update reported confusing pay-statement editing, extra clicks, and AI features they found unhelpful. Separate threads raise support ownership and deadline pressure. Those comments do not prove the new Agentic Pay capability fails. They show why the employer needs a vendor-independent evidence trail and a manual fallback that works when the interface, explanation, or support channel does not.

The AI can prioritize the queue. Payroll must still prove the population, source, calculation, disposition, and exact released run.

An anomaly is neither an error nor a fraud finding

An anomaly means a value differs from a rule, threshold, expected pattern, peer group, or previous period. A large gross-pay increase could be an incorrect rate, but it could also be a bonus, retroactive adjustment, promotion, additional shift, leave payout, commission, or longer pay period. The first control is language: call it an alert or hypothesis until evidence establishes the cause.

Signal typeWhat it can revealWhat it cannot prove
Rule exceptionValue violates an explicit configured conditionThat the rule is current or correctly scoped
Period comparisonEmployee or population changed materiallyThat periods are comparable
Pattern outlierValue differs from learned history or peersThat the unusual value is wrong
Natural-language explanationPossible drivers and records to inspectThat every cited record is complete or authoritative
Duplicate/missing detectorPotential repeated or absent recordsThat population and lifecycle states are correct
Risk prioritySuggested investigation orderThat low-priority items are safe to ignore

Do not measure the system only by alert precision. A detector can generate few false positives while missing a systematic configuration error across the whole population. Track false negatives through independent control totals, rule fixtures, prior incidents, random samples, and post-run corrections. The AI is one detective control among several.

Freeze one pay-run state before asking why it looks wrong

Payroll evidence changes quickly. Time entries arrive, retroactive changes recalculate, interfaces retry, employee records update, and configuration can be promoted while reviewers are investigating. If the AI explanation refers to one state and the reviewer opens another, agreement is meaningless.

Create a pay-run identity containing legal entity, pay group, period, check date, environment, payroll ID, extract timestamp, pre-process version or hash, source-interface statuses, calculation/configuration versions, population count, and control totals. Every anomaly row and approval must refer to that identity.

pay_run_id: US-WEEKLY-2026-08-29
snapshot: pre-process-07
snapshot_hash: sha256:4dd8...
extracted_at: 2026-08-29T08:15:00-04:00
population:
  expected: 1842
  included: 1841
  missing: 1
control_totals:
  gross_pay: 2841976.42
  employee_taxes: 418220.17
  deductions: 291882.03
interfaces:
  time: complete
  benefits: complete
  commissions: failed
release_owner: payroll_manager_17

This example cannot be released even if every surfaced employee anomaly is explained. The missing employee and failed commission interface are population-level blockers. Investigating interesting outliers before proving completeness is a common form of control theater.

Use a six-record investigation, not a chat transcript

1. Population recordExpected, included, missing, duplicate, lifecycle, off-cycle, and totals.
2. Alert recordOriginal signal, rule/model version, basis, threshold, population, and priority.
3. Source recordAuthoritative field, original/new value, effective date, ticket, approver, and interface.
4. Calculation recordIndependent formula, units, rates, bases, caps, rounding, and tie-out.
5. Exception recordClassification, impact, owner, containment, correction, retest, and closure.
6. Release recordExact snapshot, open items, segregation, totals, named decision, and timestamp.

First reproduce the alert. If an AI says gross pay is 38% above the prior period, recompute the percentage from the frozen registers and confirm that the periods have the same length and comparable employment status. If it cites a changed hourly rate, open the authoritative compensation record and its approved effective date. Do not accept a generated explanation as a source.

Next independently recalculate. Use the documented payroll rule rather than asking the same AI to check its own answer. Show regular hours, overtime hours, eligible rate, multiplier, differentials, taxable basis, caps, proration, rounding, and currency. For tax or legal interpretation, route the question to the qualified owner and keep the anomaly open until a documented decision is returned.

Then classify and close. Useful classes include valid expected change, valid unusual payment, source-data error, interface failure, configuration defect, calculation defect, duplicate, missing payment, unauthorized change, possible fraud indicator, tax/legal question, false positive, and unresolved. “Explained by AI” is not a class.

PCAOB guidance makes an important point about exception reports: the human review depends on both the quality of the review and the accuracy of the computer-produced information. Validate report completeness, parameters, period, population, filters, and source totals before treating the exception list as the universe of risk.

Worked example: overtime outlier with a valid source change

An alert flags employee E-1042 because gross pay is 46% above the previous weekly period. The explanation attributes the difference to overtime. The investigation begins by reproducing the comparison: current gross is $2,146.00 and prior gross is $1,470.00, a $676.00 increase. The comparison is arithmetically correct but not yet resolved.

The source trace shows 40 regular hours, 12 overtime hours, a $28.00 hourly rate, and an approved shift differential of $2.50 per hour for eight overtime hours. The timecard is approved by the supervisor, the rate is effective before the period, and the differential configuration matches the assigned shift.

regular = 40 × $28.00                         = $1,120.00
overtime_base = 12 × $28.00 × 1.5            =   $504.00
shift_differential = 8 × $2.50 × 1.5         =    $30.00
other approved earnings                      =   $492.00
independent expected gross                    = $2,146.00
pre-process register gross                    = $2,146.00
difference                                    =     $0.00

The correct disposition is valid unusual payment, not “false positive.” The alert did useful routing: a large change deserved review. Close it only after attaching time approval, rate and differential authority, the independent calculation, reviewer identity, and the related-population check showing the differential rule did not misapply to other employees.

Now change one fact: the shift differential interface failed and the AI explanation inferred the differential from history. The same total might accidentally tie, but the source authority is absent. Hold the item, restore the interface or obtain approved source evidence, recalculate the affected population, and retest. Numerical agreement is not proof of authorization.

Keep AI inside the existing payroll control environment

RiskPreventive controlDetective controlRelease evidence
Incomplete populationInterface and lifecycle cutoffsExpected-to-included reconciliationCounts, missing/duplicate disposition
Unauthorized master changeRole-based access and approvalChange report and source traceTicket, approver, effective date
Wrong calculationVersioned configuration and testingIndependent recalculation and control totalsFormula, fixture, tie-out
Missed systematic errorDeterministic rules and interface controlsPopulation tests and random sampleCoverage and false-negative record
Rubber-stamped alertReviewer training and workload limitsQuality sample and override reviewNamed rationale and evidence links
Same person prepares and releasesSegregation-of-duties matrixAccess/event reviewIndependent signature or compensating control
Wrong version releasedImmutable release candidateSnapshot/hash comparisonApproved and processed hash match
Post-run rejectionPayment-file validationBank, register, GL, and reject reconciliationNamed post-run close record

Public audit guidance supports independent review before processing and documented signature/date. State Department payroll controls also emphasize written or electronic approval for corrections, an audit trail of original and new data, and segregation between authorization, preparation, and related payroll duties. Adapt these principles to the organization's policy, jurisdictions, and systems; this page is not a substitute for legal, tax, audit, or payroll advice.

Failure modes to test before relying on AI alerts

FailureWhat happensRequired response
Wrong comparison periodHoliday, bonus, or longer period looks anomalousNormalize basis and rerun
Incomplete interfaceMissing data appears normal or lowBlock population control and restore source
Explanation hallucinationPlausible cause has no source recordMark unexplained; trace authority independently
Threshold blindnessMany small errors stay below alert levelAggregate by rule, location, owner, and population
Outlier biasValid bonuses consume review while systematic errors passBalance alert review with controls and samples
Privacy spillSensitive payroll data enters an unapproved modelContain, preserve evidence, and follow incident procedure
Vendor support gapAlert cannot be explained before deadlineUse documented manual fallback and hold rule
Version driftReviewer approves a snapshot different from processingHash exact candidate and compare after run

A deadline is not evidence. Define in advance which unresolved conditions require hold, which immaterial exceptions may be documented under policy, who can approve an emergency path, how employees are protected from delayed or incorrect pay, and how the organization returns to standard controls after the event.

A 30-day pilot should run in shadow mode first

  1. Days 1-4: choose one pay group; document systems, data classes, jurisdictions, authority, segregation, materiality, service levels, stop rules, and fallback.
  2. Days 5-8: create the frozen pay-run identity, population reconciliation, source/interface register, control totals, and approval evidence model.
  3. Days 9-12: build representative fixtures for bonuses, overtime, retroactivity, new hires, terminations, leave, deductions, failed interfaces, duplicates, missing pay, and valid no-alert cases.
  4. Days 13-18: run AI alerts without changing payroll decisions. Reproduce each signal, independently calculate, classify, time the review, and sample cases the AI did not flag.
  5. Days 19-22: measure alert precision, qualified misses, population coverage, investigation time, evidence completeness, false closure, reviewer disagreement, and correction latency.
  6. Days 23-25: test unavailable AI, unavailable vendor support, stale explanations, version change, interface failure, privacy incident, approver absence, and last-minute source correction.
  7. Days 26-28: remediate controls, rerun fixtures, verify segregation, train reviewers, confirm manual fallback, and rehearse hold/release communication.
  8. Days 29-30: approve a limited monitored use, approve with conditions, hold, or stop. Record scope, owners, metrics, change triggers, rollback, and reapproval date.

Measure first-time-right payroll, post-run corrections, employee-impact incidents, unresolved exception age, review time, and false-negative discoveries. Do not count alerts generated or explanations accepted as success. The outcome is accurate, timely pay supported by a reviewable control record.

Frequently asked questions

Can AI approve a payroll run?

No. AI can route attention and assemble evidence, but an authorized human must decide whether the exact pay-run candidate can be released under the organization's control framework.

Does an anomaly prove payroll is wrong?

No. It proves a condition or comparison deserves review. Preserve the alert, reproduce it, trace the source, calculate independently, and assign a supported disposition.

What if the AI cannot explain its alert?

Do not invent a reason or silently dismiss it. Mark the alert unexplained, run deterministic checks, inspect source and configuration evidence, use vendor escalation if available, and apply the predefined hold or manual-review rule.

Should payroll data go into ChatGPT or another public tool?

Use only employer-approved tools, authorized integrations, and minimum necessary data. Payroll records can contain identity, bank, tax, benefits, leave, garnishment, and other sensitive information that requires strict access and retention controls.

Is this workflow specific to UKG?

No. UKG's August release is the current trigger and example. The controls apply to AI-assisted anomaly review in other payroll systems, data warehouses, BI tools, or approved internal models.

Sources and reference points

Public sources were checked on August 29, 2026. Product behavior, controls, and obligations can change. Confirm local payroll, tax, employment, privacy, security, audit, and records requirements with qualified owners.

Related playbooks