This checklist covers eight core HR domains: records, hiring, wage and hour, benefits, policies, performance, safety, and data privacy. Pull a random sample of personnel files and check them against the items in the checklist below. That ten-file sample is the fastest way to find out whether your organization has a paperwork problem or a real exposure problem, and it takes less than an afternoon.
TL;DR:
- Conduct an HR audit at least once a year, focusing on records, hiring, classification, benefits, policies, safety, and data privacy.
- Run targeted quarterly checks on payroll classification, I-9 compliance, and timekeeping, especially after incidents or regulatory inquiries.
- Prioritize fixing immediate legal risks within days, address contained gaps within two months, and schedule process improvements quarterly.
- Maintain accurate, secure personnel and immigration files with clear access controls, and verify I-9 forms are completed correctly and stored separately.
- Track recurring regulatory obligations, including training, filings, and notices, with a compliance calendar to prevent ongoing legal exposure.
Table of Contents
- What Is an HR Audit, and Why Does It Matter?
- When Should You Run an HR Audit?
- The Complete HR Audit Checklist by Domain
- How Do You Run an HR Audit Step by Step?
- Turning Audit Findings Into Real Action
- A Manager’s Script for Requesting Documentation
- What I Wish Every New HR Manager Knew
- How Visionova Can Help You Close the Gaps
- Where to Go for Primary Sources and Templates
- Sources
What Is an HR Audit, and Why Does It Matter?
An HR audit is a structured review of your people practices against the law and against your own written policies. It’s not a performance review of your HR person, and it’s not busywork. It’s the process of pulling files, timekeeping records, and handbooks off the shelf and asking a blunt question: does what we actually do match what we say we do, and does either one hold up under a regulator’s or a plaintiff’s attorney’s scrutiny?
Most small organizations avoid this because it sounds like a legal project. It’s really an operational one. A good audit accomplishes four things at once:
- Compliance verification. Confirms you’re meeting federal, state, and local requirements, not just the ones you remember from onboarding a decade ago.
- Risk reduction. Surfaces the gaps that turn into wage claims, discrimination complaints, or OSHA citations before a regulator finds them first.
- Record accuracy. Catches missing I-9s, expired certifications, and personnel files that would embarrass you in a Department of Labor request.
- Process improvement. Reveals where your onboarding, performance, or termination process is inconsistent manager to manager.
The consequences for skipping this are not abstract. A misclassified employee can trigger back pay, penalties, and interest under the Fair Labor Standards Act, which governs how you determine exempt versus nonexempt status. A pattern of inconsistent discipline documentation can turn a routine termination into a discrimination claim under Title VII. Missing OSHA injury logs can mean citations during an inspection you didn’t see coming. And underneath every one of those risks sits a human cost: employees who don’t trust that their pay, their leave, or their complaint will be handled fairly.
I’ve watched organizations treat an audit like a fire drill they run once and forget. The ones that actually reduce risk treat it like a physical: recurring, unglamorous, and worth doing even when nothing feels broken.
When Should You Run an HR Audit?
Frequency depends on your risk exposure, not your calendar preference. Here’s how to think about cadence:
- Run a full audit annually. Treat this as your baseline. Cover every domain: records, hiring, classification, benefits, policies, performance, safety, and data privacy.
- Run targeted quarterly checks on your highest-risk areas. Payroll classification, I-9 compliance, and timekeeping accuracy shift the fastest and cause the most expensive mistakes, so they deserve more frequent attention than your handbook does.
- Trigger an audit after any incident. A harassment complaint, a workers’ comp claim, or an employee lawsuit is a signal to check whether your documentation would hold up, not just whether the immediate issue is resolved.
- Trigger an audit before and after a merger, acquisition, or rapid hiring wave. Combining two employee populations or tripling headcount in six months almost guarantees inconsistent practices you haven’t caught yet.
- Trigger an audit when regulations change. California updates wage, leave, and harassment training rules often enough that a policy written two years ago may already be out of date.
- Trigger an audit after a regulatory visit or inquiry. If OSHA, the DOL Wage and Hour Division, or immigration enforcement has contacted your organization, assume other agencies could follow, and get your files in order immediately.
If you operate in more than one state, add a jurisdiction-mapping step before you start. California alone stacks state leave laws, local sick leave ordinances, and wage notice requirements on top of federal rules, and a policy that’s compliant in one city can fall short two counties over. Multi-state employers should keep a living map of which rules apply where, updated whenever you open a new location or hire a remote employee in a new state.
The Complete HR Audit Checklist by Domain
This is the working checklist. Go domain by domain, and resist the urge to skim. The gaps that cause real damage are almost always in the domain you assumed was fine.
Organization and Recordkeeping
Personnel files are usually the first place an auditor, a plaintiff’s attorney, or a state agency looks, and they’re often the least maintained part of an HR system.
- Confirm each personnel file contains the offer letter, signed acknowledgments, performance reviews, and disciplinary records, and that medical information is stored in a separate, restricted file.
- Verify retention schedules: personnel records generally need to be kept for a set number of years after separation, and requirements vary by document type and by state.
- Check who has access to personnel files, both physical and digital, and confirm that access is limited to people with a legitimate business need.
- Confirm I-9 forms are stored separately from personnel files, which makes them easier to produce quickly if requested and keeps sensitive immigration documentation out of a manager’s general access.
Hiring and Onboarding Practices
This is where a lot of exposure gets built in on day one, often by people who never intended to create risk.
- Pull a sample of I-9 forms and confirm Section 1 was completed by the employee’s first day of work and Section 2 by the employer within three business days of the start date, per the Epstein Becker Green HR audit checklist.
- Check that expired I-9s tied to temporary work authorization have been re-verified and that you’re not still holding I-9s for employees separated years ago past the retention window.
- Review job descriptions for accuracy: do they reflect actual duties, and do they support the exemption status you’ve assigned under the FLSA duties test?
- Confirm background check processes comply with the California Fair Chance Act, which restricts when you can ask about criminal history and requires an individualized assessment before withdrawing a conditional offer.
- Check job postings for pay range disclosures, which California requires, and scan for language that could signal age, gender, or other protected-class bias.
Classification and Wage and Hour Compliance
If your organization has one area of hidden risk, it’s almost always here.
- Re-run the duties test for every exempt employee. Job titles like “manager” or “coordinator” mean nothing to the FLSA; actual duties and independent judgment do.
- Confirm nonexempt employees are recording all hours worked, including time spent on calls, emails, or tasks outside scheduled shifts.
- Check meal and rest break compliance and confirm break waivers, where used, are documented properly under California rules.
- Verify final pay was issued on time. California requires final wages at termination immediately, and within 72 hours for employees who quit without notice.
- Sample overtime calculations for nonexempt employees who receive bonuses or shift differentials, since those payments often get left out of the overtime rate calculation.
Benefits and Leave Administration
Leave stacking is where multi-state and even single-state California employers most often trip up, because so many overlapping laws apply to the same absence.
- Confirm FMLA eligibility tracking is accurate for employers with 50 or more employees, and that designation notices go out within the required timeframe.
- Check that California’s state leave programs, including paid sick leave and the California Family Rights Act, are layered correctly with FMLA rather than treated as identical.
- Review COBRA notice timing and confirm you’re retaining proof of mailing, not just a note that a notice was “sent.”
- Confirm ACA recordkeeping is current if your organization is an applicable large employer, including offer-of-coverage documentation.
- Check that local paid sick leave ordinances, which vary by California city, are reflected in your actual accrual and usage records, not just your handbook language.
Policies, Handbooks, and Required Notices
A handbook nobody signed is not a defense. It’s a liability with a table of contents.
- Confirm every employee has a signed acknowledgment of the current handbook version, not an old one from before your last policy update.
- Check that required workplace postings are current and displayed, including wage and hour notices, safety information, and anti-discrimination postings.
- Verify harassment prevention training compliance. California requires supervisors to complete two hours of training every two years and nonsupervisory employees to complete one hour, for employers with five or more employees.
- Review your handbook for state-specific addenda if you employ people outside California, since a single national handbook rarely satisfies every jurisdiction’s requirements.
Performance, Discipline, and Offboarding
Documentation gaps in this domain are what turn a defensible termination into a costly one.
- Sample performance reviews against actual disciplinary action. If a file shows three years of “meets expectations” before a sudden termination for performance, that inconsistency is exactly what a plaintiff’s attorney looks for.
- Confirm disciplinary write-ups are specific, dated, and signed, rather than vague notes about “attitude” or “not a fit.”
- Check your separation checklist: final pay timing, COBRA notice, return of company property, and a release form reviewed by counsel where appropriate.
- Verify exit interview documentation is being collected and actually reviewed, not just filed.
Workplace Safety and OSHA Requirements
- Confirm OSHA Forms 300, 300A, and 301 are current where your organization is required to maintain them, and that the 300A summary was posted during the required February through April window.
- Check that any incidents requiring reporting within OSHA’s timeframes were reported, not just logged internally.
- Review your injury and illness prevention program, which California requires of virtually all employers regardless of size.
HR Technology and Data Privacy
- Confirm access controls on your HRIS match your personnel file access rules. If everyone in the office can see salary data, that’s a finding, not a footnote.
- Check retention settings in your HR software against your actual legal retention requirements, since default settings in off-the-shelf platforms rarely match state law.
- Review your data handling against CCPA/CPRA obligations if you collect employee personal information as a California employer, particularly around what you disclose to employees about data use.
Pro Tip: Run this checklist twice. First, pull a random sample of ten personnel files across departments and tenure lengths and score them against every item above. If more than two or three files show the same gap, stop sampling and check the entire population for that specific item, because you’ve likely found a systemic issue, not an isolated mistake.
How Do You Run an HR Audit Step by Step?
A checklist tells you what to look for. A runbook tells you how to look for it without losing a week to disorganization.
- Define scope, owner, and jurisdiction map. Decide whether this is a full audit or a targeted one, name a single owner responsible for pulling records, and list every state and city whose rules apply to your workforce.
- Assemble documents and HRIS pulls. Export personnel file indexes, timekeeping data, I-9 lists, and leave records before you start reviewing, so you’re not hunting for documents mid-review.
- Run a 10-file random sample first. Pull ten files spanning different departments, managers, and tenure, and check each against the domain checklist above. Practical audit runbooks recommend this exact sequence: sample first to surface patterns quickly, then expand only where you find them.
- Score practice against policy. For each item, mark it compliant, partially compliant, or noncompliant, and note whether the gap is a paperwork issue or a genuine practice problem.
- Document findings and rank risk. Write down exactly what you found, in which files, and why it matters, using specific language rather than vague notes.
- Assign remediation and deadlines. Every finding gets an owner and a date. A finding with no deadline just becomes next year’s finding again.
- Follow up and monitor. Schedule a check-in thirty to sixty days out to confirm remediation actually happened, not just that it was assigned.
Name your evidence files consistently as you go. Something like “2026_Audit_WageHour_Sample_01” beats a folder full of files named “Copy of Copy of timesheet.” When a regulator or an attorney asks for proof of your process later, a clean naming convention is the difference between producing evidence in an afternoon and reconstructing it from memory.
One structural note worth building into how you present findings, especially if you’re summarizing them for a board or leadership team in writing: put your headline finding and recommended action first, then the supporting detail. Readers and reviewers alike absorb the first portion of any document far more than the middle, so don’t bury your most urgent finding on page four of an audit report.
Turning Audit Findings Into Real Action
An audit that produces a report nobody acts on is worse than no audit at all, because now you have it in writing that you knew about the problem.
Rank every finding into one of three tiers. Immediate covers anything with active legal exposure: missing I-9s, active misclassification, an unreported injury. Fix these within days, not weeks. Short-term covers gaps that are real but not actively bleeding: outdated handbook language, inconsistent training records. Give these thirty to sixty days. Long-term covers process improvements that make the next audit easier: better file organization, an HRIS upgrade, a training rotation. These belong on a quarterly roadmap, not a fire-drill list.
Once you’ve ranked findings, build them into a compliance calendar rather than a one-time to-do list. A working calendar tracks recurring obligations: annual EEO reporting where applicable, harassment training renewal dates, I-9 re-verification deadlines, and OSHA posting windows. Recent guidance on HR compliance frames this as spanning eight ongoing domains, hiring, payroll, benefits, leave, safety, records, data privacy, and termination, each with its own recurring deadlines rather than a single annual deadline. A firm like Aibarra CPA can help if your payroll tax compliance needs a specialist’s eye alongside your HR review.
Know when to bring in counsel. If a finding involves active litigation risk, a pattern of discrimination complaints, or a classification issue affecting a large group of employees, that’s not a DIY remediation project anymore. Preserve every remediation document you produce, dated and specific, because regulators and auditors expect proof of corrective action, not a promise that it happened.
- Immediate tier: active legal exposure, fixed within days.
- Short-term tier: real but contained gaps, fixed within thirty to sixty days.
- Long-term tier: process upgrades, scheduled on a quarterly roadmap.
- Compliance calendar: recurring filings, training renewals, and posting deadlines tracked year-round, not just at audit time.
A Manager’s Script for Requesting Documentation
Twenty years of doing this work has taught me that most audit friction isn’t about the law. It’s about how the request lands on the person being asked.
When a manager needs to request missing documentation or hold a corrective conversation after an audit finding, tone matters as much as content. Here’s language I coach managers to use:
That framing matters because employees who feel targeted by a “routine” request stop trusting the process, and that erodes the goodwill that makes future compliance easier to enforce.
Visionova HR Consulting has spent more than twenty years helping small businesses and nonprofits navigate exactly this kind of documentation and workplace risk, with particular depth in California employment law. If an audit finding turns into a termination decision, our guide to high-risk terminations walks through the legal and human considerations before you act. For organizations building a longer-term compliance strategy, our SHRM session on workplace peacekeeping covers the practical side of managing conflict during policy enforcement.
This article provides general guidance and isn’t legal advice; consult qualified employment counsel for decisions specific to your organization.
What I Wish Every New HR Manager Knew
Here’s the scenario I see constantly: someone gets handed HR duties on top of their real job, usually because they’re organized and nobody else volunteered. Six months in, they realize nobody’s checked the I-9s since the last person left, half the personnel files are missing signed handbook acknowledgments, and they have no idea if anyone’s exempt classification would survive a duties test.
If that’s you, do two things this week, not this quarter. First, secure your I-9s: confirm every current employee has one on file, completed correctly, and stored separately from other records. That single document category carries some of the steepest per-violation penalties in HR, and it’s also the fastest to fix once you know where the gaps are. Second, run the ten-file sample from this checklist. You’ll know within a day whether you’re dealing with a filing problem or a real exposure problem.
If that sample turns up wage and hour issues, classification questions, or anything involving an active complaint, that’s the point to call in help rather than guess your way through it. Not because you’re not capable. Because some findings carry legal weight that deserves a second set of eyes before you act on them.
— Bernadette
How Visionova Can Help You Close the Gaps
Visionova is the alternative to hiring a full-time HR director for organizations that need expert eyes on their compliance risk without the overhead of a permanent hire. Where a generic checklist stops at “here’s what to look for,” an audit engagement with our team goes further: we run the file sampling, score your findings against California-specific requirements, and hand you a prioritized remediation plan with actual deadlines instead of a spreadsheet of vague warnings.
A typical audit engagement runs through document collection, the sampling process, and a findings report within a few weeks, not months, so you’re not left waiting on a critical compliance gap while it stays exposed. If the audit surfaces handbook or policy gaps, we offer handbook update packages to bring your written policies in line with current California requirements. And if you’d rather not run this process alone next year, our monthly HR support subscription keeps someone with two decades of California employment experience on call for exactly these questions.
If you’re ready to find out what your files would show a regulator today, start with a session on how we approach workplace compliance and culture to see how an engagement with Visionova works.
Where to Go for Primary Sources and Templates
The checklist above draws on the same statutes and agency guidance any qualified auditor would reference. Keep these bookmarked for when you need the primary source, not a summary of it.
- Title VII of the Civil Rights Act | EEOC: the federal statute behind every anti-discrimination policy and posting requirement in your handbook.
- Wage and Hour Division (FLSA) | U.S. Department of Labor: the governing rules for exempt versus nonexempt classification and overtime.
- OSHA: recordkeeping forms, posting requirements, and incident reporting timeframes for workplace safety.
- HR Checklists | SHRM: practical, ready-made forms if you need a template beyond what’s outlined here.
- HR Audit Checklist (Epstein Becker Green): a detailed legal checklist PDF with granular I-9 and recordkeeping items worth cross-referencing.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Title VII of the Civil Rights Act of 1964 | EEOC
- Wage and Hour Division (FLSA) | U.S. Department of Labor
- Occupational Safety and Health Administration (OSHA)
Recommended
Note: This article is for general informational purposes only and is not legal advice. Employment decisions depend on the facts, applicable law, and jurisdiction. Consult qualified employment counsel for guidance on your specific situation.


