GuideLevel: ExpertWorking Time RegulationsUK Employment LawComplianceHMRC Record-KeepingAudit Trail

Creating Process Documentation for Time Tracking

Four parts, one document, single proof for audit compliance

7 min read · Updated on

Process documentation is the comprehensive standard operating procedure and technical record by which an organisation demonstrates exactly how a recorded working hour translates into an accounting entry in the general ledger and payroll run. Without it, an auditor or HMRC compliance officer must reconstruct this trail manually — and what cannot be traced, verified, and substantiated in writing risks being disputed or disallowed.

Why Time Tracking Is Affected

Part 1: General Description

What the process does and its operational context:

  • Purpose of time tracking and statutory legal foundations — Working Time Regulations 1998 (WTR 1998), National Minimum Wage Act 1998 (NMWA), Employment Rights Act 1996 (ERA 1996), UK GDPR / Data Protection Act 2018, and applicable sector or trade union collective agreements,
  • Scope of affected employee groups, departments, and operational sites (including hybrid and remote workers),
  • Boundaries and interfaces with adjacent systems: payroll software (e.g. RTI payroll engines), project accounting, enterprise resource planning (ERP), and physical access control systems,
  • High-level overview of the end-to-end data flow from initial clocking event to journal entry posting and HMRC RTI submission.

A process flow diagram effectively replaces several pages of text here.

Part 2: User Documentation

How day-to-day operations are conducted — the section most frequently omitted:

  • Recording methods: Hardware biometric/fob terminals, mobile applications, web portals, or paper timesheets as a documented business continuity fallback.
  • Who records what: Employee self-recording, supervisory entry on behalf of workers, or line manager batch entry for shift crews.
  • Time categories (activity types) and their exact definitions, exhaustively listed (e.g. standard hours, overtime, night work, travel time, training, on-call time, statutory annual leave, sickness absence).
  • Correction workflows: Who is authorised to adjust recorded entries, digital approval chains, and mandatory justification notes for auditability.
  • Period close approval process for each pay period or accounting cycle, including cutoff deadlines and defined operational responsibilities.
  • Exception handling: Forgotten clock-ins/outs, network or device outages, and retroactive manual logging protocols.
  • Role and access permission matrix: Precise definition of worker, line manager, HR administrator, and system administrator roles.

Part 3: Technical System Documentation

  • Software used, including specific version numbers, build levels, and release notes,
  • Deployment and hosting model: On-premises servers, private data centres, or multi-tenant SaaS cloud — including data processing locations, UK/EEA server hosting regions, and UK GDPR adequacy safeguards,
  • Core data schema and model, specifically highlighting data types subject to statutory retention obligations under UK employment and tax law,
  • Interfaces / APIs: Which datasets are transferred where, in which file format (e.g. JSON, CSV, XML), encryption standards in transit and at rest, and synchronization frequency,
  • Mapping table Time Category → Payroll Element / Wage Code (e.g. standard pay rate, 1.5x overtime multiplier, bank holiday rate, Statutory Sick Pay qualifying days) — the central element during HMRC PAYE or National Minimum Wage audits,
  • Calculation logic: Automated statutory rest break deductions, rounding rules (e.g. 5-minute or 15-minute rounding increments), night work hours computation, and working hour averaging over the 17-week reference period,
  • System logging and tamper-evident audit trail mechanisms (logging timestamps, user IDs, original values, and edited values).

Part 4: Operational Documentation

  • Access security & controls: User authentication (including Multi-Factor Authentication / MFA), role-based access control (RBAC), password policies, and defined workflows for granting, modifying, and promptly revoking user permissions upon employee departure,
  • Data backups: Backup frequency, off-site storage location, encryption protocols (AES-256), and dated restoration test logs,
  • Disaster recovery & business continuity procedures ensuring operational continuation during software downtime or power outages,
  • Retention and deletion policies: Statutory retention schedules per data category (e.g. 6 years under NMWA 1998 and TMA 1970; 3 years for statutory holiday pay records under WTR 1998; 3 years for PAYE records), automated deletion workflows adhering to UK GDPR storage limitation principles, and deletion audit logs,
  • Version history of the process documentation itself,
  • Designated responsibilities with named process owners, data protection officers (DPO), and operational payroll leads.

Versioning

Process documentation is not a one-off document. Every material change — deploying new clocking terminals, altering an approval hierarchy, updating payroll wage code mappings, or rolling out a software release that introduces updated calculation logic — requires a formal version update.

Historical versions must be retained across the entire statutory retention period (at least 6 years) so that an auditor or HMRC compliance officer can reconstruct the exact system state, business rules, and configuration that applied to any given tax year or dispute period. A current document without historical versions is inadequate for prior audit periods.

Every version requires: A sequential version number, effective validity period, summary of changes, and the approving authority with a formal sign-off date.

Document Scope and Depth

A scope of 15 to 30 pages is customary for comprehensive time tracking process documentation in mid-sized to enterprise organisations. The benchmark is not document length, but clarity, completeness, and audit trail traceability: an expert third-party auditor, HMRC compliance officer, or independent technical expert must be able to understand the entire procedure within a reasonable timeframe.

Referencing the software vendor’s technical user manuals and API documentation is permitted, but this does not replace the description of your concrete operational implementation: Which specific configurations were selected, which time categories were defined, and which business rules were activated for your workforce.

Consequences of Non-Compliance

If process documentation is missing or inadequate, tax authorities (HMRC), statutory financial auditors, or employment tribunals may challenge the formal regularity, completeness, and accuracy of your accounting and payroll records. While a documentation gap alone might not instantly trigger an assessment, any concurrent factual discrepancies, employee wage disputes, or suspected National Minimum Wage underpayments will substantially shift the burden of proof onto the employer.

In practical terms, an immediate operational consequence arises: Without clear documentation, every internal or external audit takes significantly longer, costs more in professional advisory fees, and exposes the organisation to extensive inquiries into every individual pay and time calculation.

Acts and Statutory Regulations

Additional Guidelines

Evaluation date: August 2026. This article does not constitute individual legal, tax, or payroll advice.

Frequently asked questions

Because working time data feeds directly into payroll accounting and financial bookkeeping via overtime pay, surcharges, shift allowances, and leave records. Time tracking is therefore an upstream subsystem under UK tax compliance, National Minimum Wage enforcement, and statutory electronic record-keeping frameworks (such as HMRC digital record standards, Making Tax Digital, and the Companies Act 2006).
HMRC, statutory auditors, or employment tribunal inspectors can challenge the formal compliance, accuracy, and integrity of your payroll and accounting records. In the event of discrepancies, this risks HMRC compliance investigations, discretionary tax adjustments, National Minimum Wage penalty notices, or estimated assessments.
Upon every relevant change — introducing a new software or hardware system, altering approval workflows, or implementing a new payroll interface. Previous versions must be retained throughout the statutory retention period (at least 6 years under UK tax and employment law).
Detailed enough for an expert third-party auditor or HMRC inspector to understand and verify the entire process within a reasonable timeframe. Between 15 and 30 pages is standard for enterprise time tracking systems.
Author
PlainStaff Editorial Team
HR Editorial Team
Updated on