TL;DR
- Core decision: Decide the remediation principle, budget envelope, and communication approach before the analysis runs, not after you see the numbers.
- When doing nothing is right: Your current methodology is documented, your decision rules are written down, and your last audit is recent enough to reflect today's organisation.
- What has to be true: Legal is in the room early, finance has signed off on a range of outcomes, worker representatives understand the process, and the methodology is decided before data is touched.
- How the options split: Internal statistical work, external statistical work, or a hybrid where an adviser runs the model and you run the conversations.
- Decision rule: If you can't describe what you would do if the analysis identifies a ten per cent gap in a single job family today, you're not ready to run the analysis yet.
- Outcome to expect: A defensible gap figure, a written remediation plan, and a paper trail that holds up under internal and external scrutiny.
The Number on Your Desk, and the Conversation After
A reward lead opens a variance report on a Tuesday morning and finds that three senior engineers in the same job family, doing work assessed at the same level, are paid materially differently from their peers. The statistical work is clean. The data is defensible. She can defend the methodology to a CFO, a board, and an employment lawyer. That's the easy part. The hard part starts when she walks to the CFO's office and is asked what the company is going to do about it, for those three people, this quarter, and whether the same answer holds for everyone the analysis later identifies.
She closes the spreadsheet, opens a blank document, and types three questions. Can we afford to remediate every case the analysis finds. Do we've a written principle for who gets what. And who in the organisation needs to know before the affected employees do. None of those questions are statistical. All of them are the ones the audit actually has to answer.
So the audit you can act on isn't the one that produces the lowest defensible gap. It's the one that produces a number the organisation has already agreed, in advance, what it will do with. Most audits fail at the point of action, not the point of analysis. The analysis is a few weeks of careful work. The decision about what to do with the people the analysis identifies is a matter of months, and it's the part nobody prepares for.
Best tools for Payroll & Compensation
When You Genuinely Do Not Need to Act Yet
Your current setup is genuinely fine. A people lead in a 90-person professional services firm inherited a clean pay structure two years ago. Bands are documented, every role sits inside a band, and a promotion always triggers a band move. Her last review was a manual cohort comparison across the eight job families. It produced three small adjustments, all communicated, all closed out. She isn't behind. Running another audit this quarter would produce the same answer and consume a month of her team's time. The honest call here's to set a date for the next review, document the methodology used last time, and move on to the compensation work that actually needs attention. The trade-off she's weighing is attention: every cycle spent re-proving a known result is a cycle not spent on the hiring plan, the promotion calibration, the bonus curve, the new job family the firm just acquired. The risk of doing nothing is small because the next review is on the calendar and the methodology is reproducible without her.
You have friction but not risk. A 400-person SaaS company has run two audits using the same internal model. The model is fine for the population it was built for. Headcount has grown fast and the company has opened two new geographies. The methodology was never refreshed for the new countries and the bands were inherited from the original market. Nobody is in immediate danger. The risk is that the next audit, run on the same logic, produces a number that can't be defended in a country where the methodology doesn't fit. The right move is a methodology review before the next analysis, not another pass through the same model. The distinction matters because running the same model on a wider population produces false confidence. The number looks comparable to the last cycle. The number is not comparable because the controls weren't designed for the new mix.
You have real risk on the horizon. A 1,200-person group with operations in multiple EU member states sits inside the EU Pay Transparency Directive's reach. The transposition deadline of 7 June 2026 has passed, and only Slovakia, Italy, Lithuania and Malta met it. The first gender pay gap reports are due in June 2027 and the data collection period for those reports is running now. If a gender pay gap above five per cent is found, the Directive triggers a joint pay evaluation with worker representatives. This isn't a future problem. It's a problem for this year's planning cycle. The action isn't a new audit. The action is a written plan that names the methodology, the owner, the timeline, and the route through worker representatives that the Directive will require. Public-sector employers in late-transposing states are subject to vertical direct effect from 8 June 2026; private employers face directive-consistent interpretation, meaning national courts must read existing national law in conformity with the Directive.
The edge case where even a perfect audit doesn't help. A 60-person firm with one founder, one compensation committee, and no HR team is being pressed by an investor to publish an equity statement. There's no methodology to defend because there's no formal pay structure. Producing a number now, before the bands exist, produces a number nobody can interpret. The right move is to build the structure first, run the audit second, and tell the investor why the order matters. The investor conversation is the hard part: the investor wants the artefact for marketing reasons, and the artefact without the structure behind it is a liability, not an asset.
Five Questions You Are Asking Yourself at 11pm
Can I do this in-house or do I need external help. The honest answer is that you can do the statistical work in-house if you've someone who has done it before. The harder question is whether you can do the conversations. External help earns its keep on the second problem, not the first. The reasoning is that statistical work is reproducible from a documented methodology. The conversations with worker representatives, finance, and affected employees depend on relationships, trust, and the ability to translate a finding into a plan. If the team has the relationships and not the statistics, the hybrid is the answer. If the team has the statistics and not the relationships, external facilitation is the answer. The cost of getting it wrong is a defensible number that the organisation can't act on because nobody trusts the messenger.
Do I involve legal before or after the analysis. Before. The reason is privilege. In some jurisdictions, work product from an audit can attract legal privilege if it's run at legal's direction and for the purpose of legal advice. The shape of that protection varies by country and is the kind of detail that has to be confirmed locally with counsel. If you wait until after the analysis to bring legal in, you may have lost the chance to structure the work in a way that protects it. The cost of getting this wrong is that an internal document, written for an internal purpose, becomes discoverable in a dispute that has nothing to do with pay. The document you wrote to manage a risk becomes the document that proves the risk was known.
Do I tell the affected employees before or after I know the answer. Tell them the process is running, not the result. Employees hear "we are auditing" and read "I am about to be underpaid". Employees hear nothing and read "they're hiding it". A short, factual note that an audit is in progress, with a commitment to share outcomes with affected employees individually before any aggregate result, holds the line. The reasoning is that silence reads as concealment and disclosure reads as accusation. The position in the middle, which is process-factual and result-private, is the one that survives both legal review and the workforce conversation. The cost of getting it wrong, in either direction, is a workforce that has written its own version of the story before the company has had a chance to tell it.
Do I publish the headline number. Possibly. Publishing an aggregate gap is a signal of seriousness and it pressures the organisation to act. It also locks in a baseline. If the next audit produces a worse number, you have to explain the regression. The decision depends on whether you trust your remediation plan to close the gap before the next cycle. If you don't, publish a commitment, not a number. The reasoning is that a published number becomes a contract with the workforce, the regulator, and the media. A published commitment to a process becomes a contract you can meet. The cost of getting it wrong is a published headline the next cycle has to explain, and the explanation usually isn't kind.
What do I do if the analysis finds nothing. You document it. A clean audit, written down, dated, signed by the right people, is worth more than most of the audit work itself. It becomes the baseline against which the next cycle is judged, and it short-circuits the version of the conversation where someone, two years from now, asks why the issue was ignored. The reasoning is that a clean finding, like a positive finding, is information the organisation needs in order to make decisions. The cost of not documenting it is that the next audit, two years later, has no baseline, and the cycle of "we don't know if there's a problem" starts again from zero.
Three Honest Categories the Approaches Split Into
Internal statistical work. A reward analyst runs the model on the HRIS data, controls for role, level, tenure, and geography, and produces the adjusted gap. This is right when the company has done it before, the methodology is documented, and the team has the statistical literacy to defend the model under questioning. It fails when the model is inherited from someone who has left, when the assumptions aren't written down, and when the team can't explain to a non-statistician why a particular control was chosen. The example that fits here's a 300-person firm with a senior reward analyst who has run the same model three times. She knows the data. She knows the edge cases. She can produce a defensible number in two weeks. The trade-off is that internal-only work can read as self-interested to an outside audience. A regulator or a workforce that hears "we audited ourselves" will want to see the methodology document before they accept the number. Internal capability also concentrates the knowledge in one person, which is the failure mode that turns into the next category.
External statistical work. A specialist provider runs the analysis, writes the report, and presents the findings. This is right when there's no internal capability, when the analysis needs to be defensible to an external audience, and when the company wants a clean separation between the people who run the analysis and the people who act on it. It fails when the provider is given free rein on methodology and the company can't interrogate the choices. A defensible external report depends on the company being able to defend the methodology, which means understanding it well enough to challenge it. The example that fits here's a 1,000-person company with no senior reward analyst and a board that has asked for an independent audit. The external report carries credibility the internal version wouldn't. The cost of getting it wrong is paying for a number the company can't explain when the regulator or the workforce asks how the controls were chosen.
The hybrid. An external specialist runs the statistical model. An internal reward lead runs the conversations with finance, legal, worker representatives, and affected employees. This is right when the company needs external credibility on the numbers and internal credibility on the actions. It fails when the two sides don't communicate and the internal team ends up defending a model it doesn't understand. The example that fits here's a 1,500-person group with a small reward team that has the relationships but not the technical depth. The external partner provides the number, the internal team provides the route through the organisation. The trade-off is that two vendors, even when one is internal, create two failure modes: a number the company can't defend and a conversation the number can't reach. The hybrid only works if the internal team is in every methodology conversation, not just every remediation meeting.
Five Diagnostic Questions to Self-Assess Against
Do you've written decision rules for what you'll do if the analysis finds a gap. If not, write them before you run the audit. If yes, the audit has a customer for its output. To answer this for your own organisation, look at the last time a compensation decision was challenged. Was there a written rule the decision-maker pointed to, or was there a judgement call that survived because nobody pushed back. If the answer is the second, the rules aren't written. The rules have to cover which gaps trigger action, what the action is, who funds it, and who signs off. A rule that says "we'll figure it out" isn't a rule.
Can your finance team name, today, the budget envelope they would accept for remediation. If not, the audit will produce a number that finance can't absorb and reward can't fund. Get finance to a yes or a no on a range of outcomes before data is touched. To answer this for your own organisation, ask finance what they would say if the audit identified a gap requiring adjustments equal to a defined share of payroll. If the answer is "I'd have to come back to you", the envelope isn't agreed. The envelope has to be a range, not a number, because the audit hasn't produced a number yet. But it has to be a range with a yes or a no behind it.
Do you've a documented methodology from the last audit, and can someone other than the author run it again. If not, you don't have a methodology. You have a spreadsheet. The audit is the wrong place to discover this. To answer this for your own organisation, ask a colleague who wasn't the author to walk through the last audit's model and explain each control. If they can, the methodology is documented. If they can't, the methodology lives in one person's head, which is the failure mode the next audit will inherit.
Have you agreed with legal, in writing, how the audit will be structured to maximise any available privilege. If not, involve counsel now. The shape of legal protection varies by jurisdiction and has to be confirmed locally. To answer this for your own organisation, ask legal counsel for a written note on the privilege structure for an internal pay equity audit, with the jurisdiction named. If the answer is "we can do that", privilege is on the agenda. If the answer is "what do you mean", the conversation hasn't happened.
Have you agreed with worker representatives how the process will be communicated and how individual findings will be handled. If you're inside the Directive's reach and a gender pay gap above five per cent is found, a joint pay evaluation with worker representatives is required. Even outside the Directive, worker representatives who hear about the audit from an employee are a worse starting point than worker representatives who heard about it from you. To answer this for your own organisation, ask who would brief the worker representative body and on what date. If the answer is "we'll see what the audit finds", the route hasn't been agreed and the audit will produce the briefing by accident.
Five Ways to Cut the Analysis, Reviewed
Raw or Unadjusted Gap by Headcount
The raw gap compares average pay across the whole company or across a defined group, with no controls. It's the number most often quoted in media coverage and the number that produces the strongest reaction in a leadership meeting. It earns a place because it's the easiest to explain and the hardest to dismiss as a starting point. It's also the number that almost never survives contact with the actual organisation, because it ignores every structural feature of the workforce that the company didn't design to disadvantage anyone.
The weakness is specific. A raw gap conflates composition with pay. If a job family is weighted toward early-career employees and that family is paid less than another family weighted toward late-career employees, the raw gap reports that as a pay equity problem when it's a workforce shape problem. A leadership team that acts on a raw gap will spend the remediation budget on the wrong people. A regulator that's shown a raw gap will ask for the adjusted version. A workforce that hears a raw gap will assume the worst. The raw gap earns its place as the headline and as the entry point to the conversation. It doesn't earn a place as the basis for action.
Adjusted Gap Controlling for Role and Level
The adjusted gap holds role and level constant and asks whether people in the same role at the same level are paid differently in a way the model can't explain. It earns a place because it's the number that survives scrutiny. The controls isolate pay from structure and force the conversation toward the part the organisation actually controls, the part inside the level and the part the company decides when it makes an offer or a counter-offer.
The weakness is real. The model is only as good as the controls. A level that's itself inequitable will hide gaps inside it. A role that's under-graded relative to the work will absorb people who are paid fairly for the work and underpaid for the role. An adjusted gap that controls for a flawed structure will produce a number that looks clean and conceals the issue one level up. The audit needs to test the levels before it trusts the gap. The most common version of this failure is the band structure that was built from a job evaluation ten years ago and never refreshed for the work the organisation actually does today.
Cohort Comparison Within Job Families
Cohort comparison takes a single job family and asks whether people inside it are paid consistently. It earns a place because it produces findings that are immediately actionable. The unit of analysis is the people the company can adjust. The conversation that follows is concrete. It also surfaces issues that whole-population regression averages out, including the experience of long-tenured employees whose starting pay has drifted away from the band.
The weakness is that cohort comparison is local. It doesn't see patterns that cross job families. A company with consistent underpayment of a particular demographic inside every job family will produce a clean cohort comparison inside each family and a meaningful gap across families. Cohort comparison on its own will miss this. It needs the whole-population view as a partner, not a substitute. The failure mode is the audit report that shows clean cohorts and a clean average, and a regulator who asks the question cohort comparison can't answer.
Regression Across the Whole Population
Regression takes the full population, includes controls for role, level, tenure, geography, and any other variable the methodology supports, and asks whether the variable of interest, pay as it relates to a protected characteristic, explains residual variance after the controls. It earns a place because it's the most defensible single number. It's also the number that employment lawyers and regulators expect to see.
The weakness is that a regression output is only as good as the variable list. Omit a variable that matters and the model assigns its effect to the variable of interest. Include a variable that's itself a product of bias and the model absorbs the bias into the control. The choice of variables is a methodological choice and a defensible audit has to be able to defend each one. A regression run by someone who can't explain the variable list isn't a defensible audit. The most common version of this failure is the model that controls for performance rating, where the rating itself is the product of the bias the audit is trying to find.
Outlier Review by Individual
Outlier review identifies individuals whose pay falls outside what the model expects and asks whether each case has a documented reason. It earns a place because it's the only method that looks at the actual people. Every other method averages. Outlier review is where the company sees Maria in engineering, who was hired above band for a counter-offer that was never written down, and James in sales, whose pay has drifted below band over four years without anyone noticing.
The weakness is scale. Outlier review doesn't scale to a 5,000-person organisation without becoming a people decision masquerading as an analysis. It requires a human in the loop for every flagged case, which is the part of the work that consumes the time and that can't be outsourced to a model. The right place for outlier review is the second pass, after the regression has narrowed the population, not the first. The failure mode is the audit that produces a thousand flagged cases and a reward team that has to triage them with no agreed principle for what to do with each one.
The Decision Table
| Situation | Scale | Setup | Primary Pain | Recommended Starting Point |
|---|---|---|---|---|
| Existing documented methodology, recent clean audit | Under 500 | Reward team in place | Time spent on work that adds nothing | Set the next review date and move on |
| Multiple audits, model needs refresh | 200 to 800 | Reward team in place | Methodology inherited and not defended | Methodology review before next analysis |
| EU operations, first gender pay gap report due June 2027 | Any | Operations in EU member states | Joint pay evaluation requirement above 5 per cent gap | Written plan naming owner, methodology, worker representative route |
| Inherited pay structure, no formal bands | Under 100 | Founder-led, no HR | Number nobody can interpret | Build structure first, audit second |
| Investor or board pressure to publish | 100 to 500 | Reward team in place | Headline number without remediation plan | Publish a commitment, not a number |
| Dispersed geographies, model built for one market | 500 to 2,000 | Reward team in place | Methodology that does not fit new markets | External methodology review before next cycle |
| No internal statistical capability | Any | Reward generalists only | Cannot defend methodology | External specialist on the model, internal on the conversations |
| Disputes or complaints already in progress | Any | Reward team in place | Audit results become evidence | Counsel-led process with structured work product |
Deciding What You Will Do Before You Know the Answer
The conversation that has to happen before the analysis is the conversation about the principle. Not the principle as a slogan. The principle as an operational rule that survives contact with a real case. A reward lead who walks into the audit knowing that the company will close any adjusted gap above zero, for every identified employee, in the next compensation cycle, has a different meeting than one who knows the company will close gaps above a defined threshold, in defined job families, within a budget envelope agreed with finance. Both can be defensible. Neither is the default. The default is the one the company has not decided.
The second conversation is the budget envelope. Finance has to be in the room before the analysis, not after. The envelope doesn't have to be a number. It can be a range and a set of constraints: can't exceed a defined percentage of payroll, can't trigger a rebanding outside the current cycle, can't change the headline variable pay pool. What finance has to be able to say is yes or no to a range of outcomes, so that when the number arrives, the conversation is about whether the outcome fits the envelope, not about whether the envelope exists.
The third conversation is the communication approach. Worker representatives, managers, affected employees, and the wider workforce each need a different version of the same truth. Worker representatives need to know the methodology, the timeline, and the route through any joint pay evaluation the Directive may require. Managers need a script for the conversations they will have with their teams. Affected employees need an individual conversation before any aggregate result. The wider workforce needs a single factual statement that doesn't pre-empt the individual conversations.
| Decision | Owner | Timing | Constraint to surface |
|---|---|---|---|
| Remediation principle | Reward lead with CFO sign-off | Before analysis runs | Cannot promise to close every gap |
| Budget envelope | Finance | Before analysis runs | Defined as a range, not a number |
| Communication script | Reward lead with legal review | Before analysis runs | Individual conversations before aggregate |
| Worker representative route | Reward lead with legal | Before analysis runs | Joint pay evaluation if Directive applies |
| Affected employee script | People lead with legal review | Before individual meetings | States outcome, not method |
Who Needs to Be in the Room
The legal seat exists for two reasons. The first is privilege, and the shape of privilege varies by jurisdiction and has to be confirmed locally with counsel. The second is the framing of the work as legal work product, which is the framing that protects the audit from becoming evidence in a dispute that has nothing to do with pay. Legal also has to sign off on the communication scripts, because the script that gets an individual conversation wrong is the script that creates the claim.
The finance seat exists to convert principle into envelope. Finance doesn't need to understand the statistical model. Finance needs to be able to say yes or no to a range of outcomes, with a clear sense of how remediation interacts with the variable pay pool, the hiring plan, and the next compensation cycle. The number that arrives without a finance sign-off is a number that lands on someone's desk with no home.
The reward seat owns the methodology, the data, the analysis, and the conversations. Reward is the function that has to be able to defend the model under questioning and to translate the findings into a plan the organisation can execute. Reward also owns the relationship with worker representatives and the script for affected employees.
The worker representative seat exists where the Directive's joint pay evaluation requirement applies and where local representation is the route through which the audit is communicated. The conversation with worker representatives is the one that goes worst if it happens after the audit. Worker representatives who hear about the audit from a press release are a worse starting point than worker representatives who were briefed before the data was touched.
| Role | What they need from the audit | When they enter |
|---|---|---|
| Legal | Privilege structure, script sign-off, regulatory framing | Before data is touched |
| Finance | Range of outcomes with envelope sign-off | Before data is touched |
| Reward | Methodology, data, analysis, conversations | Throughout |
| Worker representatives | Process, timeline, route through joint evaluation | Before data is touched, where the Directive applies |
What to Put in Writing
The artefacts that turn a good decision into a defensible one aren't the artefacts that get the most attention. The headline number gets the attention. The methodology document is what holds up under questioning six months later when the author has moved on and the new reward lead is asked to explain the model.
The remediation plan is the artefact that closes the loop. It has to name the affected employees, the adjustment, the effective date, the source of the funding, and the person who approved it. A remediation plan that lives in someone's head is a remediation plan that won't survive a change of staff.
The communication artefacts are the ones that get used. The script for individual conversations, the note for managers, the statement for the wider workforce. Each one is a document that has to be written before the conversation and reviewed by legal. A script written after the conversation is a post-hoc rationalisation and is treated as such.
| Artefact | Who owns it | When it is written | What it prevents |
|---|---|---|---|
| Methodology document | Reward lead | Before data is touched | Future questions about model choices |
| Remediation plan | Reward lead with CFO | After analysis, before adjustments | Adjustments that cannot be defended |
| Communication scripts | Reward lead with legal | Before conversations | Individual conversations that create claims |
| Worker representative brief | Reward lead | Before data is touched | Worker representatives hearing it from employees |
| Decision log | Reward lead | Throughout | Re-litigation of decisions already made |
| Privilege structure | Legal | Before data is touched | Work product that loses protection |
| Data inventory | Reward lead | Before data is touched | Use of data that has not been agreed |
Questions to Ask Before You Commit
Methodology. Ask the person who will run the analysis to describe the variable list and to defend each variable. A bad answer is "the variables are standard". The variable list is a methodological choice and has to be defended as one.
Scope. Ask which populations the audit covers and which it excludes. A bad answer is "the whole company" without a discussion of contractors, contingent workers, and recent hires. Each exclusion is a choice with consequences.
Privilege. Ask how the work will be structured to maximise any available privilege. The shape of privilege varies by jurisdiction and has to be confirmed locally. A bad answer is a confident statement about what privilege covers in a country the speaker has not practised in.
Remediation. Ask what happens if the analysis identifies a gap that exceeds the budget envelope. A bad answer is "we will figure it out". A good answer names the principle that applies and the decision-maker who applies it.
Worker representatives. Ask how worker representatives will be briefed and at what point in the process. A bad answer is "we will tell them when we've a result". A good answer names the briefing date and the route through any joint pay evaluation the Directive may require.
Communication. Ask to see the script for the individual conversation with an affected employee. A bad answer is "we will personalise it". A good answer is a draft that has been reviewed by legal.
Cadence. Ask when the next audit will run and what will trigger an out-of-cycle audit. A bad answer is "we will see". A good answer names a date and a trigger.
Defensibility. Ask who in the organisation will be able to defend the methodology in twelve months, when the author has moved on. A bad answer is the name of one person. A good answer is a documented methodology and a named successor.
The Cost of Getting This Wrong
A defensible audit costs the organisation a few weeks of focused work and a written plan. A bad audit costs more than the remediation, because the remediation is the part that was always going to happen. The second-order costs are the ones that arrive eighteen months later. The regulator that asks for the methodology and finds it was never written down. The employee who hears about the audit from a colleague and asks for the individual result the company never planned to give. The new reward lead who inherits a number and a process they can't defend.
So the cost of getting this wrong isn't the cost of the audit. The cost is the cost of the audit the company has to run again, in public, with legal in the room, while the original number is still on the website. The cost is the cost of the workforce conversation that happens when the gap is published before the remediation is committed. The cost is the cost of the script that gets the individual conversation wrong and produces a claim that didn't need to exist.
The right question isn't what the audit costs. The right question is what the audit costs the organisation if it produces a number the company has not agreed, in advance, what it will do with.
When You Are Ready to Go Further
HROpsLab publishes independent comparison work on reward, payroll, and compliance tools. We don't sell software, we don't provide payroll services, and we don't provide legal advice. We test the tools, we talk to the people who use them, and we publish what we find. If the next step is a tool decision, the comparison work is the place to start.
If the next step is a methodology decision, our guides on pay equity methodology and on the EU Pay Transparency Directive are the place to look. They're written for the reward lead who has to make the call, not for the vendor who has to make the sale.
If the next step is a conversation with a peer who has done this before, the case studies are the place to start. They're written by the reward leads who ran the audit and lived with the result.
Frequently Asked Questions
What does an adjusted gap actually control for?
An adjusted gap controls for the variables the methodology says matter and which aren't themselves the subject of the audit: typically role, level, tenure, and geography. The residual variance is what the model can't explain and is the part the audit treats as a pay equity question. The choice of controls is a methodological choice and has to be defended. A model that controls for the wrong variables will hide the issue. A model that omits a relevant variable will assign its effect to the variable of interest. A defensible adjusted gap is one where the variable list has been argued through, not assumed.
Should we involve legal before the analysis runs?
Yes. Legal needs to be in the room before data is touched for two reasons. The first is the structure of any available privilege, and the shape of that protection varies by jurisdiction and has to be confirmed locally with counsel. The second is the framing of the work as legal work product, which is the framing that protects the audit from becoming evidence in a dispute. A late legal review is a review of a structure that has already been built without legal input.
What do we do when the analysis finds something?
The analysis is the easy part. The conversation that follows is the part that has to have been prepared. Remediation principle, budget envelope, communication scripts, and worker representative route all have to be in place before the number arrives. The audit's job is to produce a defensible finding. The organisation's job is to have agreed, in advance, what it will do with the finding.
Should we publish the result?
It depends on whether the organisation trusts its remediation plan to close the gap before the next cycle. Publishing a number commits the organisation to a trajectory. Publishing a commitment to a process and a timeline signals seriousness without locking in a baseline that may not survive the next audit. If the audit won't be repeated for two years and the remediation plan will close the gap in one, publish the number. If not, publish the commitment.
How often should we run one?
The cadence depends on the organisation. A company in active hiring, in active restructuring, or inside the Directive's reach needs a more frequent audit than a stable workforce in a single market. The right cadence is the one that reflects the rate at which the organisation changes. The wrong cadence is the one that reflects the rate at which the reward team has bandwidth.
What counts as a comparable role?
A comparable role is a role that the organisation has assessed at the same level using a documented methodology. The bands are the company's answer to the question. Two roles in different bands aren't comparable. Two roles in the same band are comparable even if the titles differ. The audit's ability to defend its findings depends on the organisation's ability to defend its bands. A bad band structure produces a bad audit, no matter how good the model.
Does running an audit create evidence against us?
An audit can be structured to maximise any available privilege, and the shape of that protection varies by jurisdiction and has to be confirmed locally with counsel. A late-transposing state inside the Directive's reach has a different exposure profile than a fully transposing state. Public-sector employers in late-transposing states face vertical direct effect from 8 June 2026. Private employers face directive-consistent interpretation. The point is that the answer depends on jurisdiction, on the structure of the work, and on whether legal was in the room early. The question to put to counsel isn't whether to run the audit. The question is how to structure the audit to protect it.
HROpsLab is an independent review publication for reward, payroll, and compliance leaders. We test the tools, we talk to the people who use them, and we publish what we find. We sell nothing.