Tools and providers
Part of Choosing payroll software and suppliers with HMRC evidence and scenario testing
Due diligence on a payroll vendor, from entity identity to a clean exit
Perform payroll software vendor due diligence in England across entity, product scope, PAYE, pensions, security, resilience, support, contracts and exit.
Due diligence should test whether a supplier can deliver the exact payroll service promised throughout the contract. A recognisable brand, security badge or HMRC listing answers only one part of that question.
Entity and product identity
- Record the contracting legal entity and registered details.
- Identify the exact product, plan, version and hosting model.
- Separate developer, reseller, implementer and managed-service roles.
- Check ownership, material sub-contracting and financial continuity.
- Obtain references from comparable customer contexts.
Confirm that evidence belongs to the contracting service rather than another company in the group.
PAYE scope and maintenance
- Find the exact product on HMRC's recognised software list.
- Verify the supported tax year, calculations and submission types.
- Review the supplier's rule-change and release process.
- Request test and defect evidence appropriate to the risk.
- Check support for corrections, acknowledgements and audit history.
Recognition confirms the stated online reporting capability, not HMRC endorsement of the vendor's whole operation.
Pension and workflow fit
- Map assessment, contribution, tax-relief and worker-event functions.
- Name every pension provider and exchange format required.
- Test rejection, correction and reconciliation.
- Assign communications and record-keeping responsibilities.
- Document unsupported arrangements.
Use The Pensions Regulator's payroll-software guidance to avoid reducing compatibility to one contribution field.
Personal data and security
- Determine controller, processor and sub-processor roles.
- Review processing terms, locations, transfers and retention.
- Examine access, authentication, client separation and logging.
- Obtain vulnerability, incident and assurance information.
- Check employee document delivery and support access.
The ICO's contracts guidance provides a current prompt for required controller-processor terms. Confirm that operating controls can fulfil them.
Resilience and service
- Review dependencies, backup design and tested restoration.
- Exercise a failed import, submission and pension exchange.
- Match support hours to payroll deadlines.
- Obtain service-status and customer-notification routes.
- Review past material incidents through lawful available evidence.
Ask for measurable recovery evidence, not only an availability target.
Contract, cost and exit
- Normalise all fees using a realistic employer scenario.
- Review renewal, change, suspension, liability and termination.
- Define migration and customer-input responsibilities.
- Test a complete, intelligible data export.
- Confirm post-termination access, retention and deletion.
Log every finding as verified, supplier stated, unknown or failed. Assign risk, owner and deadline, and require an authorised reviewer to accept residual risk. Do not let a sales deadline turn an unanswered material question into approval.
Implementation evidence
- Obtain a responsibility matrix for data preparation and validation.
- Agree parallel-run cases and reconciliation criteria.
- Identify who can authorise live HMRC submissions and payments.
- Document cutover, rollback and temporary-data disposal.
- Confirm training and administrator handover.
The implementation plan should identify the existing system as authoritative until acceptance. Ask how previous migrations failed and what control changed as a result.
Ongoing oversight
- Schedule tax-year, security and access reviews.
- Receive material incident and sub-processor notifications.
- Track submission errors, corrections and pension rejections.
- Reconcile contracted service levels with actual performance.
- Prepare a tested exit before a renewal decision.
Give each evidence item an expiry date. Recognition, integrations, certifications, insurance and financial information can all change during a multi-year relationship.
Summarise the decision in plain language: supported scenario, material dependencies, failed or unknown checks, required safeguards and residual risk owner. Keep source documents with the contract record. A diligence pack is useful only when operations can act on it after procurement ends.