Talent & Workforce

HR Audit

An HR audit is a structured review that tests what an organisation says about its people practices against what its records and its actual practice show. Its value comes from the gap it exposes between policy and behaviour, and it is only worth running if the findings arrive with owners, dates and enough evidence to act on.

What distinguishes an audit from a review?

Evidence and independence. A review asks people how things work and writes down what they say. An audit takes a stated practice, decides in advance what would count as proof that it happens, then goes and looks for that proof in records the people being reviewed did not prepare for the purpose. The difference shows immediately: a policy stating that every new manager receives training is confirmed by a review because everyone believes it, and is disconfirmed by an audit because the attendance records for the last several intakes do not exist. The discipline is not suspicion, it is refusing to accept intention as evidence of practice.

What can it cover?

More than any single exercise should attempt. Candidate scope includes the completeness of employee files, statutory registers and filings, payroll accuracy against approved structures, leave and attendance records, policy currency, how consistently discipline is applied, the integrity of data held in [the core HR system](/hrms), access rights to sensitive records, and retention practice. Trying to cover all of it produces a document nobody reads. Choosing two or three areas where a failure would genuinely hurt, and testing those properly, produces findings someone will act on, which is the only outcome that matters.

Who should run it?

Someone with no ownership of the result. An HR team auditing its own records is doing quality control, which is useful but is not an audit, because the person who created a gap is not well placed to score it. Internal audit, a colleague from another function, a peer from a different site, or an external specialist all supply the necessary distance. What matters more than the auditor's title is that the evidence standard is agreed before the work begins, so that findings are disputed on facts rather than on whether the reviewer was being fair.

How is scope decided without boiling the ocean?

By working backwards from consequence. List the ways the people function could actually cause serious harm to the organisation or to an individual, rank them by how bad and how plausible each would be, and audit the top few. That usually surfaces a short list: obligations where non-performance carries penalty, records that would be needed to defend a dispute, payments that could be wrong at scale, and personal data that could be exposed. It rarely surfaces the areas people expect it to, such as engagement activity, the tone of the handbook or the design of the appraisal form.

The second scoping decision is depth against breadth, and depth almost always wins. A shallow pass across everything yields observations that are true, unsurprising and unactionable, and it consumes exactly the goodwill needed to act on something real. A deep test of one area yields a specific finding with a specific cause, which is what allows a fix. If wider coverage is genuinely needed, rotate areas across successive cycles rather than diluting a single one, and keep a record of what was covered when so that the rotation is deliberate rather than a matter of who remembered what.

What counts as evidence?

Records created in the ordinary course of business, not assembled for the auditor. A signed document filed at the time it was made, a system log, an approval trail, a register maintained continuously, a filing acknowledgement. Evidence produced after the request, reconstructed from memory or supplied as a summary someone typed up for the occasion, is weaker and should be recorded as such in the working papers. This distinction matters because the situations these records exist for are adversarial, and a document created in response to a dispute carries a very different weight from one that plainly predates it.

Sampling should be defined before the testing starts and described in the report, since a finding based on a handful of files chosen by the person being reviewed proves very little and will be dismissed on exactly that basis. Say how the sample was drawn, how large it was relative to the population, and what was found in it. Where a control depends on data quality, test the data rather than the control: reconciling the employee master against payroll, or against the register held in [the employee database](/employee-database-software), tends to reveal considerably more than reading the procedure that governs both.

What makes a finding actionable rather than decorative?

Four things, and severity is not the most important of them. A finding needs a statement of what was tested and what was observed, the reason it matters expressed as consequence rather than as a reference to a clause number, a single named owner, and a date by which it will be addressed. Findings written as observations without an owner become a document that circulates politely and expires. Findings written as criticism of a team produce defensiveness and a debate about tone, which reliably consumes the attention that should have gone to the remedy itself.

The other discipline is separating the symptom from the cause. A set of incomplete employee files is a symptom; the cause might be that the joining checklist has no completion gate, or that a document is collected by someone with no visibility of whether it ever arrived. Fixing the files leaves the mechanism intact and the finding recurs at the next audit, which is the most common reason an organisation audits the same area repeatedly and improves slowly. A finding that names the mechanism can be closed permanently, and is worth the extra effort to write.

What happens after the report?

The part most often skipped. An audit produces value only when findings are tracked to closure by someone who was not involved in fixing them, with closure meaning evidence that the mechanism changed rather than an assurance from the owner that it did. A tracker carrying owner, date, current status and the evidence accepted at closure is sufficient for the purpose. What does not work is treating the report itself as the tracking artefact, since nobody returns to a document once it has been presented and acknowledged in a meeting.

Retesting matters as much as closure. A finding closed in one cycle should be sampled again in the next, because remediation frequently holds for a few months and then decays once attention moves elsewhere and the original owner changes role. Where an audit touches statutory obligations, the standard being tested against is set externally and is amended over time, so confirm with a qualified advisor what the current requirement is before scoring compliance against it. Auditing against a superseded understanding produces confident findings that are wrong, which damages the credibility of every other finding in the report.

See how Pitch N Hire handles hr audit on your roles

FAQ

HR Audit — FAQs

How is an HR audit different from an engagement survey? +
A survey collects opinion about how things feel; an audit tests evidence about what actually happened. Both are useful and they answer different questions. An audit will tell you whether the promotion process was followed as documented; a survey will tell you whether people believe it was fair. Neither substitutes for the other.
Can an HR team audit itself? +
It can do valuable quality control, but that is not an audit, because the people who created a gap are poorly placed to assess it. Independence can come from internal audit, another function, a peer site or an external specialist. What matters most is agreeing the evidence standard before the work starts.
How wide should the scope be? +
Narrow and deep beats wide and shallow. Work backwards from consequence, pick the few areas where a failure would genuinely hurt, and test those properly. If broader coverage is needed, rotate areas across cycles and record what was covered when, rather than diluting a single audit until nothing in it is conclusive.
Why do the same findings keep reappearing? +
Usually because the symptom was fixed and the mechanism was not. Correcting a set of incomplete files without changing what allowed them to be incomplete guarantees recurrence. Findings that name the underlying mechanism, and closure that requires evidence the mechanism changed, are what break the cycle.
Pitch N Hire ATS

See how this works in a real applicant tracking system

Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. Everything on this page — sourcing, screening, interviewing, offers — runs in one pipeline.

  • One pipeline for every role, applicant, and interview stage
  • Structured scorecards so the panel compares candidates on the same criteria
  • Careers page, job posting, and candidate communication in one place

Free for 1 user · No credit card · Talk to a real hiring expert

Built for recruiters & hiring teams

See HR Audit in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · Talk to sales · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo