An HR audit is a structured review that tests what an organisation says about its people practices against what its records and its actual practice show. Its value comes from the gap it exposes between policy and behaviour, and it is only worth running if the findings arrive with owners, dates and enough evidence to act on.
Evidence and independence. A review asks people how things work and writes down what they say. An audit takes a stated practice, decides in advance what would count as proof that it happens, then goes and looks for that proof in records the people being reviewed did not prepare for the purpose. The difference shows immediately: a policy stating that every new manager receives training is confirmed by a review because everyone believes it, and is disconfirmed by an audit because the attendance records for the last several intakes do not exist. The discipline is not suspicion, it is refusing to accept intention as evidence of practice.
More than any single exercise should attempt. Candidate scope includes the completeness of employee files, statutory registers and filings, payroll accuracy against approved structures, leave and attendance records, policy currency, how consistently discipline is applied, the integrity of data held in [the core HR system](/hrms), access rights to sensitive records, and retention practice. Trying to cover all of it produces a document nobody reads. Choosing two or three areas where a failure would genuinely hurt, and testing those properly, produces findings someone will act on, which is the only outcome that matters.
Someone with no ownership of the result. An HR team auditing its own records is doing quality control, which is useful but is not an audit, because the person who created a gap is not well placed to score it. Internal audit, a colleague from another function, a peer from a different site, or an external specialist all supply the necessary distance. What matters more than the auditor's title is that the evidence standard is agreed before the work begins, so that findings are disputed on facts rather than on whether the reviewer was being fair.
By working backwards from consequence. List the ways the people function could actually cause serious harm to the organisation or to an individual, rank them by how bad and how plausible each would be, and audit the top few. That usually surfaces a short list: obligations where non-performance carries penalty, records that would be needed to defend a dispute, payments that could be wrong at scale, and personal data that could be exposed. It rarely surfaces the areas people expect it to, such as engagement activity, the tone of the handbook or the design of the appraisal form.
The second scoping decision is depth against breadth, and depth almost always wins. A shallow pass across everything yields observations that are true, unsurprising and unactionable, and it consumes exactly the goodwill needed to act on something real. A deep test of one area yields a specific finding with a specific cause, which is what allows a fix. If wider coverage is genuinely needed, rotate areas across successive cycles rather than diluting a single one, and keep a record of what was covered when so that the rotation is deliberate rather than a matter of who remembered what.
Records created in the ordinary course of business, not assembled for the auditor. A signed document filed at the time it was made, a system log, an approval trail, a register maintained continuously, a filing acknowledgement. Evidence produced after the request, reconstructed from memory or supplied as a summary someone typed up for the occasion, is weaker and should be recorded as such in the working papers. This distinction matters because the situations these records exist for are adversarial, and a document created in response to a dispute carries a very different weight from one that plainly predates it.
Sampling should be defined before the testing starts and described in the report, since a finding based on a handful of files chosen by the person being reviewed proves very little and will be dismissed on exactly that basis. Say how the sample was drawn, how large it was relative to the population, and what was found in it. Where a control depends on data quality, test the data rather than the control: reconciling the employee master against payroll, or against the register held in [the employee database](/employee-database-software), tends to reveal considerably more than reading the procedure that governs both.
Four things, and severity is not the most important of them. A finding needs a statement of what was tested and what was observed, the reason it matters expressed as consequence rather than as a reference to a clause number, a single named owner, and a date by which it will be addressed. Findings written as observations without an owner become a document that circulates politely and expires. Findings written as criticism of a team produce defensiveness and a debate about tone, which reliably consumes the attention that should have gone to the remedy itself.
The other discipline is separating the symptom from the cause. A set of incomplete employee files is a symptom; the cause might be that the joining checklist has no completion gate, or that a document is collected by someone with no visibility of whether it ever arrived. Fixing the files leaves the mechanism intact and the finding recurs at the next audit, which is the most common reason an organisation audits the same area repeatedly and improves slowly. A finding that names the mechanism can be closed permanently, and is worth the extra effort to write.
The part most often skipped. An audit produces value only when findings are tracked to closure by someone who was not involved in fixing them, with closure meaning evidence that the mechanism changed rather than an assurance from the owner that it did. A tracker carrying owner, date, current status and the evidence accepted at closure is sufficient for the purpose. What does not work is treating the report itself as the tracking artefact, since nobody returns to a document once it has been presented and acknowledged in a meeting.
Retesting matters as much as closure. A finding closed in one cycle should be sampled again in the next, because remediation frequently holds for a few months and then decays once attention moves elsewhere and the original owner changes role. Where an audit touches statutory obligations, the standard being tested against is set externally and is amended over time, so confirm with a qualified advisor what the current requirement is before scoring compliance against it. Auditing against a superseded understanding produces confident findings that are wrong, which damages the credibility of every other finding in the report.
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. Everything on this page — sourcing, screening, interviewing, offers — runs in one pipeline.
Free for 1 user · No credit card · Talk to a real hiring expert
Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.
Prefer to talk? Book a demo · Talk to sales · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert