Empty dark office desk at night — ghost commission
Payroll Operations

Terminated Employees Keep Getting Paid. It's Not Fraud. It's Drift.

Every ghost-employee article blames a bad actor. Most overpayments don't have one.

Ken Lannon · Founder, OrgDrift | 20 years in global sales compensation·June 16, 2026·9 min read
DRIFT FILESPayroll OperationsKen Lannon · Founder, OrgDrift | 20 years in global sales compensation·June 16, 2026·9 min read

I've been in the room for this one more times than I can count, and it always opens the same way.

Someone finds an overpayment. A former employee got a commission check after their last day, there's a ticket open with Internal Audit, and a VP somewhere wants a name. Who missed this. Who screwed up.

I understand the instinct. It's almost never right.

Twenty years running sales comp for global companies teaches you a few things, and this is one of them. When a terminated employee keeps getting paid, the cause is hardly ever a person. I've watched it happen through acquisitions, reorgs, headcounts that moved faster than any system trying to track them. Dozens of times. And in nearly every case, nobody did a thing wrong. HR processed the termination correctly. The comp team ran their month-end checks. Payroll closed on schedule. Everybody did their job.

The problem is that none of those systems ever stopped to confirm the same fact with each other at the one moment that actually mattered, which was when the calculation ran.

Why everybody reaches for "fraud" first

Go search "terminated employee still on payroll" and look at the language. Ghost employees. Phantom workers. Payroll fraud. Every result assumes a villain, some manager or payroll admin who kept a dead name on the books on purpose.

That framing isn't crazy. It's just old. Back when payroll lived in one system and the only real risk was a human gaming that one system, "go find the person who did it" was a perfectly good investigation. I started my career in something close to that world.

It's gone, and it isn't coming back.

A mid-size company today runs its pay across an HRIS, a commissions platform (ICM), a benefits admin, a payroll processor, and usually a CRM bolted on the side. The simple question of who's eligible to get paid gets answered in four or five places at once, and those places don't always agree. The space between them, where two systems are holding two different versions of the same person, is where the overpayment is born.

Not fraud. Drift.

What month-end actually looks like from the inside

Before anyone blames the people, I want you to see what those people are actually doing, because it looks nothing like the policy-deck version.

At most SaaS companies commission payroll runs once a month, and it's a grind. The comp team is usually tiny and absurdly experienced, and they work it in stages. An HRIS snapshot around Day 4 to anchor the accrual. Another pull around Day 10 to 12 to catch whatever moved. By Day 13 or 14 they hand the final file to payroll, and at that point payroll has hours, not days, to reconcile it against the HRIS before the run goes out the door. And commissions isn't the only thing they're touching that week, either. A global org can run 19 or more payroll cycles in a single month. This is just one of them.

None of it is passive. These are seasoned pros. They check between systems, they flag exceptions, they'll hold a file when something smells off. Nobody's asleep at the wheel. What they're doing, and I've called it this for years, is data Olympics. Pulling files out of five source systems, reformatting them, joining everything on employee ID, comparing line by line, chasing some HR rep to confirm one termination date, rerunning the check, then writing the whole thing up in a spreadsheet so there's a record of it. Done properly, that's 20 to 30 hours a cycle. And even then it only holds if every source system happened to be completely current at the exact second the comp team pulled from it.

That's the catch. It was never about whether the team covered the work. It's cost, and it's timing.

83%
of companies fail to pay commissions accurately, with errors clustering around employee transitions: role changes, territory shifts, and departures
Source: Xactly Fierce Competition Report

Walk one termination all the way through

Let me trace a real one. Not the policy version. The version that actually happens.

A rep leaves at month-end, on a Friday, because people always seem to leave on Fridays. HR enters the termination in the HRIS. Status flips, badge dies, the manager's headcount updates. Textbook. HR did it right.

But they entered it after the comp team had already pulled the Day 13 snapshot. So the termination is real, it's sitting right there in the HRIS, and it is completely invisible to the file the comp team is working from.

Meanwhile the ICM is off doing its own thing. It calculates against its own participant data, and its picture of who's active is only as fresh as the last import it got from the HRIS. Maybe that import runs on a schedule. Maybe somebody has to trigger it. At crunch time, maybe it hasn't run since the Day 10 pull. So when the ICM does the math at month-end, the rep is still flagged eligible. The deals are real, the rate is right, the calculation completes without a single error.

Nobody committed fraud. The termination was on time. Every system followed its own logic, and every system was correct about what it knew. They just never knew the same thing at the same moment. That's the whole of it, and it's so much more boring than fraud.

Diagram showing how a ghost commission occurs: the HRIS records a termination correctly, but the ICM's last import predates the change, so the eligibility check runs on stale data

Every system did its job correctly. The timing between them is where the money went.

So what's a ghost commission?

The fraud world already has a clean term for a person fraudulently kept on the books. A ghost employee. Good term. It names a problem that requires somebody to intend it.

I needed a different word for the thing I just walked you through, because it's a different animal, so I started calling it a ghost commission.

A ghost commission is a real payment that goes to someone whose employment had already ended. Not because anyone schemed to keep them active, but because the ICM and the HRIS were holding two different versions of the truth on the day the numbers ran.

That difference isn't word games. It decides everything you do next.

If it's actual ghost-employee fraud, you investigate, you revoke access, you escalate, you file the report. If it's a ghost commission, the job is completely different. You find the timing gap between the HRIS and the ICM, you run an honest cross-system eligibility check, you claw back what went out, and you close the window so next month doesn't do it again.

Confuse the two and you'll burn weeks hunting a bad actor who doesn't exist, while the actual gap, the one that caused all of it, sits wide open for the next cycle.

The four doors the error walks in through

Ghost commissions aren't random. They come in through the same handful of doors every month.

There's HRIS entry lag. HR processes the termination, but it doesn't hit the HRIS until after the comp team's snapshot. Termination on Day 13, file locked on Day 12, and the change just isn't in there.

There's the between-snapshot change. Something moves between the Day 10 pull and the Day 13 final. Comp checked on the 10th. The thing happened on the 11th. By the 14th, when payroll fires the run, neither team can see what shifted in the window between their two check dates.

There are retroactive effective dates, which I hold a personal grudge against. The HRIS books a termination with an effective date in the past, totally normal when HR is digging out of a backlog, and as far as the ICM is concerned that rep was active the entire period it just finished calculating.

And there are cross-entity gaps, which are the nastiest of the bunch. A rep moves from one legal entity to another. Different country, different payroll jurisdiction, sometimes a different HR system entirely. The old entity marks them inactive, the new one marks them active, and if the comp system can't see both records at the same time, it might pay from both. Or neither. Or the wrong amount from one and call it done.

The thread running through all four is that not one of them is a mistake by a person. They're gaps between when a system gets updated and when a calculation runs. Pure timing.

The seam nobody owns

Here's the part that took me a while to really sit with. Comp checks inside the ICM. Payroll checks inside the payroll register. Internal Audit runs its terminated-employee test. Everybody is genuinely doing their job, and doing it well.

But checking inside a system and checking between systems are not the same activity, and only one of them catches this.

A payroll register audit proves the amounts match what got calculated. It does not prove the payee was still active in the HRIS the day that calculation ran. A commission spot-check proves the deal was real and the rate was right. It does not cross-reference whether that person's status in the HRIS matched their status in the ICM when the thing fired. A terminated-employee test confirms departing folks got their final base paychecks, and then it usually stops, without ever reaching into a whole separate system to pull the commission ledger and look for activity that shouldn't be there.

Everybody's checking their own lane. The seam between the lanes is exactly where ghost commissions live, and in twenty years I've never once seen it land on somebody's responsibility matrix.

The systems aren't wrong. They just don't agree with each other at the exact moment the calculation runs. That disagreement is the finding. — Ken Lannon, OrgDrift

80%
of payroll errors are found by the employee, not the system, meaning most catches happen after the check has already gone out
Source: G2 / Paycom payroll accuracy research

The overpayment is the cheap part

The direct hit from a ghost commission is honestly the easy part. You spot it, you claw it back, you close the file.

It's the indirect cost that compounds, and that's the part that should bother you.

Start with the boring math. A typical org makes around 15 payroll corrections a pay period, at roughly $291 each just in administrative cleanup. That's north of $4,300 a cycle before you've touched a single downstream consequence. And since 80% of payroll errors get caught by the employee instead of the system, the first sign you're wrong is usually a phone call. Somebody who got a check that's too big, or didn't get one at all. Not a great way to find out.

Then there's the audit side, which is where this stops being an annoyance and becomes a real problem. In FY2024, 8% of public companies disclosed a material weakness in their internal controls. Of those, 56% pointed at IT or system-integration failures as a root cause, up from 31% in 2021. That line is moving the wrong way, fast. And 98% of them had documentation gaps, meaning no trail showing how the data moved between systems or whether anyone actually verified it on the way through.

That gap is the punchline, because it's exactly what 20 to 30 hours of heroic manual comparison produces. Work product. Not independent evidence. Your spreadsheet proves your team ran the check. It does not prove the check was independent of the team that ran it. So when the external auditor asks who verified the comp data was accurate before payroll went out, "the same team that runs comp" is not an answer that lands.

And since December 2023 this reaches all the way up the building. SEC Rule 10D-1 requires every NYSE- and NASDAQ-listed company to keep a clawback policy on incentive comp. If an accrual error caused by cross-system drift ends up forcing a restatement, executive incentive pay from that period is on the hook for recovery, fault or no fault, and the board's comp committee has to go get it. That whole chain, from one missed termination to an executive clawback, is documented and real. I'm not speculating.

It gets worse every time the org changes

Drift isn't a fixed thing you patch once. Every time the company changes shape, fresh gaps tear open.

A reorg shuffles territories, and Sales Ops updates the CRM that same day because Q1 pipeline can't wait on anybody. Legal, meanwhile, takes another week to finalize quota letters before the ICM gets touched. For those seven days, any deal that closes can land on the wrong territory, the wrong rep, the wrong rate.

An acquisition drops a second HRIS into the stack and integration drags on for months. The whole time, two HRIS instances are live, and the comp system can usually only see one of them. The person who transferred over from the acquired company exists, active, in both. Comp pays from whichever one it can see.

A RIF terminates hundreds of people in a week. The HRIS handles all of them. The sync to the ICM is batched, so some terminations land in 24 hours, some land after the next monthly run, and some don't surface until a commission dispute drags them into the light.

Every one of those is a ghost commission with the fuse already lit.

Three questions worth asking this week

If you own payroll, or sales comp, or internal controls, sit with these three before the next period closes.

When a termination gets processed in your HRIS, how long until your commission platform actually reflects it? If your honest answer is "not sure," or "depends when the sync runs," you've already got an open gap.

Who is responsible for verifying a commission payee was still active in the HRIS on the day the calculation ran? If the answer is some version of "I assume the systems handle that," then nobody is, and the cross-system check simply isn't happening.

When your auditor asks for evidence that your eligibility verification was independently reviewed, what do you actually hand them? If it's a spreadsheet your own team built, you've got the verification. You don't have the proof.

None of those are hard questions. They've just never been anyone's job to answer, because cross-system verification was never written into a single role. The controls got designed for a world where one system owned the data. Then the world moved to four systems, and the controls stayed right where they were.

Yes, I know you're going to ask about AI

So, can AI fix this? If the whole problem is timing and sync between systems, can't you just automate the gap shut?

You can, and you should try. AI and automation are genuinely remaking SOX work right now, and I'm not the least bit nostalgic about the manual version. KPMG put out guidance in 2025 openly pushing companies to use AI agents for evidence collection, walkthrough documentation, controls testing. I'm for all of it.

But here's the wall every one of these frameworks runs into, and they all hit it in the same spot. COSO's February 2026 guidance on generative AI, the PCAOB's Technology-Assisted Analysis standard that took effect December 2025, the SEC Investor Advisory Committee's December 2025 recommendations. Every one of them puts the same thing dead center: independent oversight of whatever the AI does. COSO says it about as plainly as a standards body ever will, "GenAI cannot be controlled with a 'set it and forget it' mindset." KPMG's own guidance says the future needs "employees carefully overseeing AI activities to verify quality and mitigate risk."

Which means the moment you build internal AI to verify your comp, your external auditor now has to independently test that tool. Its logic, its access controls, its change management, whether its output is actually complete. That's IT General Controls, and the team that built it cannot be the team that certifies it. Segregation of duties doesn't care that it's AI.

So the AI doesn't make the independent-verification requirement go away. It hands you a brand new one. The ghost commission I walked you through happens just as cleanly in a fully automated shop as a manual one, because the ICM calculated perfectly off what it knew. This was never a manual-process problem. It's an independence problem. And no internal system, human or machine, can independently verify its own data. That's a logical impossibility, not a tooling gap.

The actual point

The ghost-employee fraud story was written for a world where payroll was a sealed box and the only danger was somebody tampering with it. That world still exists in the corners. It just isn't the main event anymore.

The real exposure now is quieter and a lot bigger. Your HRIS, your ICM, your CRM, and your payroll processor are all walking around with slightly different pictures of your workforce, and the differences pile up in silence, pay period after pay period, until a commission dispute or an audit finding or a material-weakness disclosure finally drags one of them into daylight.

That's not fraud. It's drift. And the reason the distinction matters so much is that if you call it fraud, you'll investigate it wrong, fix it wrong, and leave the real gap open for next month to find again.

Ghost commissions are completely preventable. But only if you know to look at the seams between the systems, instead of staring harder inside any one of them.

98%
reduction in time spent on cross-system eligibility verification, after replacing manual file comparison with a systematic cross-system check
Source: OrgDrift internal, SUFA recon methodology deployment

One of our beta members runs three separate HR and payroll systems, and they told me they'd been spending something like 30 hours a month just keeping the three roughly in line. Not perfectly. Roughly, their word. We ran a cross-system check across the seams, and the finding they'd never caught doing it by hand showed up almost immediately.

Their entire response was one word. "WOW."

Not because the finding itself was exotic. Anybody who's run this kind of check has seen this kind of finding. It got to them because their team had been running clean audits inside every individual system for years. Every internal check came back green. Every single one.

It only appeared when somebody finally looked between the systems instead of inside them. That's really the whole thing.


Ready to see whether your systems agree on who's eligible right now? Run a Drift Scan →

Or view a sample Control Execution Record, the independent evidence artifact that shows exactly where your systems diverge, in a format built for auditors.

Ready to Check Your Org?

See your drift before it costs you.

Drop in a CSV export from your HRIS, CRM, or comp system. Get your ODIS in minutes. Your data never leaves your browser.

Scan my data →

No IT ticket. No OAuth. No data upload to any server.

Get Drift Notes

Short, sharp field notes on data propagation, control risk, and audit pain.

OrgDriftOrgDrift

The verification layer between your systems and your auditors.

“Your org changed. Nobody told your data.”

Product
Company
Security
SHA-256 Hashed

Every record sealed with a tamper-evident hash

Browser-Only Processing

Your data never leaves your browser

SOC 2 Roadmap

Enterprise compliance certification in progress

Read our privacy commitment →
© 2026 OrgDrift, LLC. All rights reserved.·Beta session replay in use
orgdrift.com