Almost everything written about time theft relies on projection. Industry studies estimate what buddy punching costs. Benchmark reports estimate how many businesses are affected. The figures are useful, but they are modeled rather than measured.
So it is worth paying attention when a large employer overhauls its timekeeping controls and an independent watchdog reports the result. That is what happened recently at a major US public sector employer, where overtime spending fell from nearly $18 million in the first half of one year to $9.6 million in the same period the next. That is a reduction of $8.3 million, or roughly 45%, in six months.
The details of how it happened are more instructive than the headline number.
What Went Wrong First
Before the improvement came the diagnosis. An Inspector General’s review found a set of failures that will sound familiar to anyone who has looked closely at a credential-based timekeeping process.
Payroll login credentials were shared, which meant employees were able to approve their own time using a supervisor’s credentials. Overtime was entered in block chunks rather than the minutes worked. Oversight of whether staff had shown up for the shifts they claimed was inconsistent. Investigators reported instances of people being paid while at home during hours their timesheets showed as worked.
The conclusion was that weak oversight had created an environment open to abuse. Not that every employee was exploiting it, but that the system made exploitation straightforward and detection difficult.
What Changed
The response was a package of measures, not a single fix. The organization put biometric time clocks at the locations where staff report for duty and stopped anyone approving their own time through a shared supervisor login. Timekeeping accounts were reset, spot checks introduced, and non-compliance acted on.
Six months later, the watchdog credited those changes with the reduction and publicly commended the improvement in timekeeping practices.
Being Straight About the Numbers
It would be easy to present this as proof that installing time clocks saves millions. That would overstate it, and anyone examining the case would spot the gap.
Several changes were made at once, so the outcome reflects a combination of measures rather than any single control. The organization also made separate budget decisions during the same period, including workforce reductions, and its operational demands shifted. Attributing the entire figure to one intervention would not survive scrutiny.
What the case does demonstrate is more useful: when an employer closes the gap between claimed hours and verified hours, the financial effect can be substantial and measurable. The direction and the scale are the story, not a precise causal split.
It is also worth noting that observers close to the situation caution the underlying problem is not fully resolved. Controls reduce opportunity, but they do not end the need for oversight.
Credentials Verify Credentials, Not People
The single most transferable lesson here is the credential failure.
A shared login, a borrowed badge, a disclosed PIN: each of these confirms that someone had access to a credential. None of them confirms who was actually standing there. When credentials can be passed around, the record produced is a record of the credential, not of the person.
That is the vulnerability at the center of this case. Staff approving their own time using a supervisor’s credentials is the same weakness as one employee clocking in for another, applied to the approval layer instead of the capture layer. In both cases, the system recorded what it was told rather than what it verified.
Tying each entry to the individual is what closes that gap. Whether through a badge, a PIN or biometric verification, the goal is the same: the record should reflect the person, not whoever held the credential.
Capture and Approval Are Separate Controls
The second lesson is one that vendors in this space rarely emphasize, because it points beyond the hardware.
Recording time accurately and approving it appropriately are two distinct controls, and this case failed at both. Even a well-designed clock will not help if the approval workflow above it allows the same person to record and sign off their own hours. Equally, a rigorous approval process cannot fix data that was entered in blocks after the fact rather than captured when the work happened.
Accurate capture at the source and separation of duties in approval are complementary. Organizations reviewing their own setup are better served checking both than assuming either alone is sufficient.
Not a Public Sector Problem
Public bodies attract this kind of scrutiny because their spending is public and independent watchdogs review it. That visibility is the only real difference.
The conditions that produced these losses exist in any organization with shift work, overtime, multiple sites and credential-based timekeeping. Most private employers simply have no Inspector General publishing the numbers.
GT Clocks: Built for This
This is the standard our hardware is designed to meet. The GT4, GT8 and GT10 capture time at the point where the workday begins and ends, with verification options, biometric among them, that confirm the right person is clocking in. Records are created as the work happens rather than reconstructed later.
Through GTConnect, that data flows into the payroll and workforce management systems an organization already runs, without manual re-keying.
Verified hours, captured at the source, feeding systems you can defend in an audit.
The question worth asking isn’t whether your people are honest, it’s whether your records could prove it.