Pay Run Lab

Tools and providers

Part of Choosing payroll software and suppliers with HMRC evidence and scenario testing

Due diligence on a payroll vendor, from entity identity to a clean exit

Perform payroll software vendor due diligence in England across entity, product scope, PAYE, pensions, security, resilience, support, contracts and exit.

Due diligence should test whether a supplier can deliver the exact payroll service promised throughout the contract. A recognisable brand, security badge or HMRC listing answers only one part of that question.

Entity and product identity

  • Record the contracting legal entity and registered details.
  • Identify the exact product, plan, version and hosting model.
  • Separate developer, reseller, implementer and managed-service roles.
  • Check ownership, material sub-contracting and financial continuity.
  • Obtain references from comparable customer contexts.

Confirm that evidence belongs to the contracting service rather than another company in the group.

PAYE scope and maintenance

  • Find the exact product on HMRC's recognised software list.
  • Verify the supported tax year, calculations and submission types.
  • Review the supplier's rule-change and release process.
  • Request test and defect evidence appropriate to the risk.
  • Check support for corrections, acknowledgements and audit history.

Recognition confirms the stated online reporting capability, not HMRC endorsement of the vendor's whole operation.

Pension and workflow fit

  • Map assessment, contribution, tax-relief and worker-event functions.
  • Name every pension provider and exchange format required.
  • Test rejection, correction and reconciliation.
  • Assign communications and record-keeping responsibilities.
  • Document unsupported arrangements.

Use The Pensions Regulator's payroll-software guidance to avoid reducing compatibility to one contribution field.

Personal data and security

  • Determine controller, processor and sub-processor roles.
  • Review processing terms, locations, transfers and retention.
  • Examine access, authentication, client separation and logging.
  • Obtain vulnerability, incident and assurance information.
  • Check employee document delivery and support access.

The ICO's contracts guidance provides a current prompt for required controller-processor terms. Confirm that operating controls can fulfil them.

Resilience and service

  • Review dependencies, backup design and tested restoration.
  • Exercise a failed import, submission and pension exchange.
  • Match support hours to payroll deadlines.
  • Obtain service-status and customer-notification routes.
  • Review past material incidents through lawful available evidence.

Ask for measurable recovery evidence, not only an availability target.

Contract, cost and exit

  • Normalise all fees using a realistic employer scenario.
  • Review renewal, change, suspension, liability and termination.
  • Define migration and customer-input responsibilities.
  • Test a complete, intelligible data export.
  • Confirm post-termination access, retention and deletion.

Log every finding as verified, supplier stated, unknown or failed. Assign risk, owner and deadline, and require an authorised reviewer to accept residual risk. Do not let a sales deadline turn an unanswered material question into approval.

Implementation evidence

  • Obtain a responsibility matrix for data preparation and validation.
  • Agree parallel-run cases and reconciliation criteria.
  • Identify who can authorise live HMRC submissions and payments.
  • Document cutover, rollback and temporary-data disposal.
  • Confirm training and administrator handover.

The implementation plan should identify the existing system as authoritative until acceptance. Ask how previous migrations failed and what control changed as a result.

Ongoing oversight

  • Schedule tax-year, security and access reviews.
  • Receive material incident and sub-processor notifications.
  • Track submission errors, corrections and pension rejections.
  • Reconcile contracted service levels with actual performance.
  • Prepare a tested exit before a renewal decision.

Give each evidence item an expiry date. Recognition, integrations, certifications, insurance and financial information can all change during a multi-year relationship.

Summarise the decision in plain language: supported scenario, material dependencies, failed or unknown checks, required safeguards and residual risk owner. Keep source documents with the contract record. A diligence pack is useful only when operations can act on it after procurement ends.

More in Tools and providers

Tools and providers

Choosing payroll software and suppliers with HMRC evidence and scenario testing

Select payroll software and suppliers for an England employer in 2027 through current HMRC evidence, scenario testing, due diligence and controlled implementation.

Tools and providers

From HMRC Basic PAYE Tools to QuickBooks, payroll starting points with their use-case limits

Review six payroll software starting points for England using HMRC and first-party sources, with use-case limits instead of an unsupported best-product ranking.

Tools and providers

Write the employer scenario first, then let payroll software prove it can handle it

Select payroll software for an England employer by testing PAYE, pensions, pay patterns, migration, data controls, support, exit and full cost.

Tools and providers

Comparing payroll suppliers on one scenario, current HMRC status and full cost

Compare payroll software suppliers for England with one scenario, current HMRC status, product-level evidence, controlled testing and full-cost analysis.