Author: David Jenkins, NZPPA CEO
- Making the provider accountable while protecting the employer
Your business remains responsible for paying employees correctly, even when it relies on a payroll provider’s software and advice. Choosing a system is only the beginning. Businesses need to understand what it delivers, question its limitations and hold their provider accountable for its performance.
This article is part of a series I will publish as we move towards implementing the Employment Leave Act. My aim is to give businesses and payroll practitioners the knowledge and confidence to take control of their provider relationship: to ask the right questions, challenge unsupported claims and insist on evidence that their system can meet New Zealand payroll requirements.
NZPPA has repeatedly called on government to strengthen payroll provider accountability. Those calls have yet to deliver the protections employers need. Businesses remain exposed when a system is promoted as compliant but fails to calculate and pay employees correctly. A provider’s assurance offers little comfort when the employer is left to resolve errors, meet remediation costs and rebuild employee trust.
Taking control means setting clear expectations, requiring meaningful testing, understanding system limitations and demanding effective support when problems arise. With significant legislative change ahead, businesses and payroll practitioners must be active, informed customers. They need a payroll system—and a provider relationship—they can rely on.
Payroll software does not transfer payroll accountability
For many businesses, the payroll provider is one of the most important third parties they use. Its software may calculate gross-to-net pay, maintain leave balances, produce payroll reports, submit employment information to Inland Revenue and hold years of sensitive employee data. Because the system performs so much of the payroll process, it can be easy to assume that if the software produces a result, the result must be compliant.
That assumption creates risk. The employer employs the employee, agrees the terms and conditions, holds the employment records and must meet statutory obligations. Employment New Zealand states that employers must keep complete and accurate wage, time and leave records and, even where payroll software is used, must check that the payroll system accurately records changes to employees’ hours and pay. Inland Revenue places payday-filing obligations on employers. The Office of the Privacy Commissioner states that an organisation remains responsible for personal information sent to a third-party provider.
The provider relationship should therefore be managed as a compliance, operational and third-party risk relationship, not merely as a software subscription. The payroll practitioner has a central role: translating employment terms and legislation into requirements, challenging system outcomes, leading testing, recording decisions and ensuring provider assurances are backed by evidence.
A level playing field: evidence, not assurances
A provider saying its product is “compliant” should never be the end of the discussion. Compliance depends on the legislation, the employee’s circumstances, the employment agreement, the data supplied, configuration choices and the calculation or process performed. The employer needs evidence of what the system does, what assumptions it makes, what remains the employer’s responsibility and what limitations or manual processes exist.
The following controls should form part of the employer’s provider governance framework and, where appropriate, the contract, statement of work, implementation plan, service schedule and ongoing review process.
- Service-level agreements (SLAs)
An SLA should define measurable availability, support hours, response and resolution targets, severity levels, planned maintenance, payroll-critical periods, escalation and reporting. Payroll deadlines make timing important: an outage immediately before the bank file is released has a different impact from an outage at a quiet time. The employer should review SLA performance regularly. Service credits are a contractual remedy, but they do not compensate for employees being paid incorrectly or late.
- Employer–provider responsibilities
Maintain a written responsibility matrix for configuration, legislative updates, employee data, tax, leave, interfaces, calculations, filing, security, backups, testing and corrections. This removes the dangerous gap where each party assumes the other owns a task. Review the matrix whenever the system, legislation, contract or operating model changes.
- Contractual protections
The contract should cover scope, compliance-related commitments, implementation deliverables, data ownership, confidentiality, security, subcontractors, audit rights, liability, insurance, termination, extraction and transition assistance. Payroll should ensure the operational wording reflects how the service actually works. Distinguish standard statutory product maintenance from chargeable employer-specific customisation.
- Legislative and regulatory updates
Require a documented process to identify, analyse, design, build, test and release legislative changes. For each material change the provider should explain the effective date, affected calculations/processes, required customer action, configuration dependencies, known limitations and testing completed. The payroll practitioner should assess the release against the organisation’s workforce and agreements. Provider deployment should not automatically equal employer acceptance.
- Implementation and ongoing updates
Treat a new payroll implementation as a compliance project, not simply an IT project. Document requirements before configuration, covering the employee lifecycle, pay rules, leave, tax, KiwiSaver, deductions, interfaces, reporting, security and records. Retain a requirements-to-configuration record and reconcile migrated data. Apply similar discipline to major upgrades, including impact assessment and regression testing.
- Support and access to expertise
Define where help can be sought, available channels, support hours, key contacts and escalation. Separate technical help from payroll or legislative expertise. A helpdesk that resets passwords may not be qualified to explain a statutory calculation. Maintain payroll-critical escalation contacts and enough internal expertise to challenge answers that do not resolve the compliance issue.
- Testing and sign-off
The provider should test the product, but the employer should independently test the configured system. Include normal and exception scenarios: starters, terminations, variable hours, leave, public holidays, allowances, deductions, KiwiSaver, tax, backpay and organisation-specific rules. Retain expected results, actual results, defects, retests and formal sign-off against defined acceptance criteria.
- Change requests
Document how changes are requested, assessed, prioritised, priced, approved, developed, tested and released. Establish timeframes and authority to approve cost. Critically, distinguish an employer enhancement from a defect or a change necessary for legislative compliance. Keep a change register showing owner, reason, impact, cost, approval, test evidence and implementation date.
- Incident management
Define how payroll incidents are reported, categorised and escalated. Severity should reflect payroll impact, not merely technical impact. Set acknowledgement targets, update frequency, workaround expectations and resolution targets. Significant incidents should result in root-cause analysis identifying what happened, affected users, why controls failed, corrective action and prevention measures.
- Provider assurance
Assess whether the provider can continue to support the service: staffing, key-person dependency, architecture, development capability, legislative expertise, support capacity, security, backups, disaster recovery, financial resilience and ownership changes. Understand dependencies on cloud platforms and other suppliers. Repeat assurance reviews periodically rather than only at procurement.
- Release notes
Treat release notes as a control document. They should identify legislative and calculation changes, defect corrections, affected modules, effective dates, configuration requirements, customer actions, known issues, interface changes and testing implications. For defect fixes, ask whether historical payrolls could have been affected. Maintain a release register recording review, actions, testing and acceptance.
- Audit evidence and independent assurance
Ask what internal or external assurance exists over the provider. Establish who performed it, the period, systems and controls in scope, exclusions, exceptions and remediation. Security certification alone does not prove that New Zealand payroll calculations have been audited for legislative compliance. Where full reports cannot be shared, request an appropriate assurance summary with scope and limitations.
- Business continuity and disaster recovery
Payroll has a fixed delivery deadline. Understand backup frequency, recovery processes, recovery time and recovery point objectives, alternate infrastructure, cyber-response arrangements and disaster-recovery testing. The employer also needs its own contingency plan for provider outages, internet failure, banking failure or unavailable payroll staff, including an emergency payment process and later reconciliation.
- Exit plan
Understand the exit before signing the contract. Identify notice periods, minimum terms, termination charges, data-extraction fees, transition assistance, post-termination access and required actions. Confirm how long data remains available, when copies are deleted, how deletion is confirmed and how the provider will assist migration to a replacement system.
- Data ownership and portability
The contract should clearly state the employer’s rights to its payroll data and complete usable exports. Periodically test whether data can actually be extracted in structured form. This reduces vendor lock-in and supports audit, remediation, business continuity and future migration.
- Privacy, security and breach management
Payroll contains highly sensitive personal and financial information. Assess multifactor authentication, privileged access, encryption, logging, data location, retention, vulnerability management and breach notification. The employer should know how quickly it will be told of a suspected breach and who manages regulatory and employee communications. Review user access regularly.
- Configuration ownership and documentation
A compliant product can produce a non-compliant payroll if configured incorrectly. Maintain an effective-dated configuration register for pay elements, tax treatment, leave settings, rates, rules and interfaces. Changes should be authorised. Where the provider changes configuration, require evidence of the change and test the resulting payroll outcome.
- Integration and interface controls
Document every interface into and out of payroll: time and attendance, HR, rostering, banking, general ledger and government filing. Define ownership, frequency, validation, rejected-record handling and reconciliation. A successful file transfer does not prove that the data was complete or correct.
- Performance reporting and governance meetings
Use a provider scorecard covering system availability, SLA performance, incidents, defects, change backlog, support performance, security matters, releases and upcoming legislation. Hold scheduled governance meetings with decisions, actions, owners and due dates. This turns provider management into an ongoing control rather than an annual contract discussion.
- Record retention and auditability
Ensure historical transactions, calculations, configuration and change history remain accessible for statutory retention, employee queries, audits and disputes. The Employment Leave Act 2026 requires leave-record information to be retained for at least six years after entry. The system and contract need to support the employer in meeting these obligations.
- Employment Leave Act 2026 readiness
The Employment Leave Act takes effect on 6 August 2028. Employment New Zealand is telling providers to identify gaps, design and test changes, and support customers through transition. Employers should require a documented roadmap covering standard, additional and casual hours; notional rosters; multiple roles; hours-based leave; leave compensation payments; leave pay; pay statements; records; data conversion and testing. Ask what is complete, what remains unresolved, what depends on future guidance and how the employer will be able to test and sign off the final solution.
Questions every employer should be asking its payroll provider
Exactly which New Zealand legislative requirements does the product support, and what remains the employer’s responsibility?
- What evidence can you provide that material calculations and legislative changes have been tested?
- What known limitations, workarounds or manual processes exist?
- Who owns each configuration decision and how are changes authorised and recorded?
- If a provider-controlled defect causes incorrect pay, what is the remediation and support process?
- How quickly will payroll-critical incidents be escalated and who is the senior contact?
- What data can we extract, in what format, at what cost, and how quickly?
- What happens if your service is unavailable on payroll processing or payment day?
- What third parties do you rely on to deliver our payroll service?
- What is your roadmap and testing approach for the Employment Leave Act 2026 transition?
The payroll practitioner’s role
The payroll practitioner should not be reduced to the person who enters data into the provider’s system. The practitioner should be the employer’s informed payroll representative: defining requirements, questioning assumptions, validating calculations, identifying risk, maintaining evidence, coordinating testing and escalating unresolved compliance issues.
This does not mean the practitioner must personally be a lawyer, tax specialist, cybersecurity specialist or software developer. It means payroll should know when specialist input is needed and should be able to translate that advice into an operational payroll requirement and test whether the system delivers it.
Conclusion: manage the provider, do not surrender control
A payroll provider can be an essential partner, but partnership does not mean unquestioned reliance. The employer needs clear contractual obligations, measurable service standards, transparent change processes, evidence of testing, accessible support, strong data protections and an exit route. The provider should be accountable for the service and product it supplies; the employer should retain governance and informed control.
The strongest position is created when the business and its payroll practitioners can demonstrate not merely that they purchased a reputable payroll system, but that they understood its responsibilities and limitations, tested the outcomes, monitored the service and retained evidence of the decisions made. That is how provider accountability becomes part of payroll compliance and professional best practice.