Labour, Payroll & Social Security

Payroll Compliance Calendar: Salary, EPF, ESIC and Records

Payroll Compliance Calendar: Salary, EPF, ESIC and Records
CA Nikhil Gupta·June 2026·3 min readCorporate Finance

A payroll control covering employee master, attendance, salary, deductions, EPF, ESIC, tax, bank file, payslip and evidence.

A payroll control covering employee master, attendance, salary, deductions, EPF, ESIC, tax, bank file, payslip and evidence. The purpose is to turn an operational issue into a measurable exposure, reconciled evidence, an accountable owner and a dated closure.

Primary metric

Payroll begins with approved employee, wage, attendance, leave, incentive and bank-master data.

Evidence test

EPF and ESIC eligibility should be assessed under the applicable establishment, employee and wage rules rather than one salary shorthand.

Cash or compliance risk

ESIC currently states a ₹21,000 monthly wage ceiling for coverage and ₹25,000 for persons with disability, subject to statutory rules.

Management control

Temporary, casual, part-time and contract employees can be covered where establishment and employee conditions apply.

What management should understand

Related Calculator
EPF Establishment and Employee Coverage Checker
Open Calculator →

The five-point control review

ReviewManagement test
ScopeEntity, process, period and accountable owner.
SourceContract, invoice, payroll, portal, bank or operational record.
ReconciliationBook amount, external record and explained difference.
DecisionApproval, exception threshold and corrective action.
ClosureLive-system result, evidence, date and next review.

Practical example

An employee crosses the ESIC wage threshold mid-period and payroll removes coverage immediately without applying continuity rules or reviewing wage components.

Implementation workflow

1. Define the transaction and the decision

State precisely what is being measured or approved: a month-end balance, customer order, product cost, purchase, tax credit, payroll run, bank payment, investment or export document. Set the period, legal entity, business owner, reviewer and materiality. A control cannot work when the team is reviewing different transactions or dates.

2. Lock the source evidence

Collect the signed contract, approved master data, invoice, receipt, timesheet, inventory record, payroll file, portal statement, bank transaction or system log. Preserve the original version and document subsequent amendments. Official portals are important external records, but they do not replace the underlying commercial evidence or the books.

3. Reconcile value, quantity, date and identity

Match legal names, PAN or GSTIN where relevant, document numbers, quantity, amount, tax, due date, payment account and approval. Separate timing differences from errors and suspected fraud. An unexplained difference should remain open with an owner; it should not be forced into a suspense or miscellaneous account merely to complete the close.

4. Assess tax, payroll, cyber and contract boundaries

GST registration thresholds are not one universal number: the threshold for suppliers of goods can differ from services, and specified States can have lower limits. Compulsory-registration provisions, e-invoice history, e-way-bill rules, EPF or ESIC coverage and contract terms require separate analysis. Where insurance, guarantees or cyber cover are involved, the actual policy wording or instrument terms control the outcome.

5. Quantify the cash effect

Show the immediate payment or receipt, working-capital days, tax timing, finance cost and downside exposure. A transaction can be profitable in the accounts and still create a cash deficit. Use a base case and at least one stress case before accepting a large order, changing price, buying equipment or releasing a disputed payment.

6. Approve, execute and verify

The preparer should not be the only approver where master data, payment or statutory exposure is involved. Record the decision, exception reason and expiry. After execution, verify the live result in the bank, GST portal, payroll return, vendor master, inventory record or management report. A submitted request is not completion.

Action checklist

Evidence to keep

Warning signs

  • Ghost employee
  • Bank change before payroll
  • Coverage removed automatically
  • Challan differs from payroll
  • Manual salary outside payroll

Finin2min takeaway

Strong MSME controls do not require bureaucracy. They require clean source records, segregation for high-risk actions, fast reconciliation and visible exception ownership.

Frequently Asked Questions

Does an MSME need an ERP before implementing this control? â–¼
No. A documented process, restricted access, reconciled evidence and reviewer sign-off can begin before automation.
Should portal data replace the books? â–¼
No. Portal data is an external record to reconcile with contracts, invoices, receipts, payroll and the general ledger.
How should GST registration thresholds be assessed? â–¼
Goods and services thresholds are different, specified States can have lower thresholds, and compulsory-registration situations require separate analysis.
What proves that an exception is closed? â–¼
The corrected live record, accounting entry, bank movement or statutory acknowledgement—not a verbal promise.

Source and review trail

Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.

Primary category
Labour, Payroll & Social Security
Official starting point
labour.gov.in
Editorial review date
2026-07-19
Content status
Finin2min explanation; official source controls where facts, law, rates, forms or procedures can change.

Page source links

Home / Insights / Corporate & Company Law
More on Corporate & Company Law
Browse all Corporate & Company Law articles →
Related Articles
Contract Labour and Principal Employer Risk: EPF Evidence Checklist Founder and Employee Expense Policy: Preventing Personal Spend from Entering Books Bank Reconciliation and Maker-Checker Payments: The MSME Anti-Fraud Routine Vendor Bank-Detail Change Fraud: Callback and Verification Protocol Ransomware and Backup Readiness for MSMEs: Finance Continuity Checklist