Compliance checklist for shift teams
Check the basics before publishing rosters, approving timesheets or turning on clock-in with evidence.
Points to review
Status
3 of 8 points covered.
This checklist is not legal advice. It helps you catch common operational gaps before using clock-in, payroll or time-record data.
Set up compliance in ShiftCal
Legal working-time record, signatures, tamper-evident seals and audit log — inspection-ready.
Compliance in shift operations is a process, not paperwork. A roster or time record can look perfectly tidy on screen and still fall apart the moment someone asks how a number was produced, who approved it, or what changed after the fact. What actually protects a business is the way records are created, reviewed and corrected day after day — not the existence of a document.
This checklist covers the operational basics that shift teams most often miss: complete clock-in and clock-out records with daily totals per employee, manager review of incidents before approval, signatures or seals that lock a closed period, an audit log for every change, informing staff before enabling GPS, selfie or kiosk evidence, configured rest and maximum working-day rules, reviewing holidays and premiums before payroll export, and removing access when someone leaves. Requirements vary by country; this checklist is general information, not legal advice.
What does a defensible working-time record need?
At minimum, a record you can stand behind shows every clock-in and clock-out per employee and a daily total derived from them. Totals matter as much as the raw punches: totals are what feed payroll and what get questioned, so they should be computed visibly from the entries rather than typed in separately.
It also needs a review step. Forgotten punches, swapped shifts and mid-shift incidents are normal; what matters is that a manager resolves them before approving the period, not silently afterwards. Finally, records have to be kept and retrievable: a record you cannot reproduce months later, exactly as it was approved, is barely better than no record at all.
Why should corrections be traceable instead of deleted?
Every real operation produces errors — a cook who forgets to clock out, a punch on the wrong shift. The wrong response is typing over the original value, because that destroys the record’s history. A corrected entry that preserves the original value, the new value, the date and the person who made the change tells a story of good faith. A silently edited one looks like manipulation, even when it was innocent.
This is why signatures or seals on a closed period, combined with an audit log, are so powerful together: the seal makes ordinary edits impossible after approval, and the log proves that any change that did happen was deliberate, dated and attributable. Credibility does not come from a record never changing — it comes from every change being explainable.
What transparency do employees deserve?
Most disputes about hours come from surprise, not bad faith. Employees should know their schedule in advance, be able to see their own recorded hours, and understand how corrections to their record were handled. In many places these are formal duties; everywhere, they are simply good practice.
Transparency also changes the tone of an inspection or a disagreement. When an employee can check their own totals at any time and sees the same numbers the company sees, the record becomes a shared fact instead of the employer’s claim. A time record that only management can read invites exactly the kind of conflict it was supposed to prevent.
How should GPS or selfie evidence be handled?
Evidence like geolocation, a selfie at clock-in or a shared kiosk can protect both sides — but only when it is proportionate and transparent. Proportionate means collecting the minimum needed for the purpose: a location captured at the moment of the punch is very different from continuous tracking, and one photo at clock-in is very different from ongoing surveillance.
Transparent means informing staff before enabling anything: what is captured, when, why, and where it is stored. Rolling out evidence quietly, or turning everything on by default just because the software allows it, converts a legitimate control into a source of distrust and potential liability. If the purpose can be achieved with a less intrusive method, use the less intrusive method.
A 12-person restaurant walks the checklist
- The owner and the head chef go down the eight points together one afternoon, marking only what is genuinely in place today. Five points pass; three do not.
- Gap 1 — untraceable corrections: forgotten punches were being fixed by typing over the original time. They switch to corrections that keep the original value, the new value, the date and the author, and agree that the manager reviews all incidents before approving each week.
- Gap 2 — silent evidence: the kitchen tablet captured location and a photo at clock-in, but nobody had been told what was collected or why. They write a short notice, explain it in a staff meeting, answer questions and keep a record that everyone was informed.
- Gap 3 — stale access: two former employees still had active accounts. Access is revoked the same day and “remove access” is added to the standard leaver routine.
Result: The restaurant went from 5 of 8 to 8 of 8 points in a single afternoon. None of the fixes required new hardware or outside help — only making the existing process reviewable, transparent to the team, and properly closed off when people leave.
Frequently asked questions
Is completing this checklist enough to be compliant?
No. It covers common operational gaps that apply almost everywhere, but the specific obligations — what to record, how long to keep it, what to inform — vary by country and sector. Use it to find weak spots, then confirm the specifics with a local advisor.
Why does the checklist care so much about who changed what?
Because a record’s credibility rests on its history. Numbers that can be silently rewritten prove nothing, in either direction. An attributable, dated trail of changes is what turns a spreadsheet of hours into evidence.
Do we need daily totals if we already store every clock-in and clock-out?
Yes. Totals are what payroll, employees and inspectors actually look at. Deriving them visibly from the punches, once, prevents the classic dispute where raw entries and paid hours quietly diverge.
Can we just enable GPS and selfie evidence for everyone by default?
You should not. Evidence collection should be proportionate to a real need and always preceded by informing staff. Blanket collection adds risk and erodes trust without making the record more credible.
What happens to records when someone leaves the company?
Their access should be revoked promptly, but their time records should be retained according to your retention obligations. Departure ends a person’s access to the system, not the company’s duty to keep the history.
How often should we walk through the checklist?
Not just once. Repeat it whenever the process changes — a new site, a new evidence type, a new payroll flow — and on a regular rhythm, for example once a quarter, so drift gets caught early.
