Risk AssessmentHigh riskComparison recommended

AI Ghost Employee Investigation Playbook

A county government's internal auditor suspects payroll fraud in the public works department after an anonymous tip. The department has 214 employees. Payroll records show 11 employees who have not had PTO taken, no W-4 changes, no benefit elections, and no direct deposit changes in over 36 months.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A county government's internal auditor suspects payroll fraud in the public works department after an anonymous tip.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Ghost Employee Investigation".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • Payroll register for the past 36 months (214 employees, public works dept)
  • HR onboarding records
  • Direct deposit routing history
  • Badge access logs (entry/exit by employee ID)

Attachments: Spreadsheets (Spreadsheets)

The Prompt

You are investigating potential ghost employee fraud in a county government payroll system. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Flag all employees who show payroll activity but zero HR activity (no address changes, no benefit changes, no time-off records, no badge swipes) over any rolling 12-month window.
2. For flagged employees, identify whether their direct deposit routing number matches any other active employee—a sign of payment consolidation fraud.
3. Cross-reference supervisor approval chains: are any flagged employees approved exclusively by one supervisor?
4. Estimate total fraudulent disbursements if all flagged employees are confirmed ghosts.
5. Tell me what I need to present to the DA and what I need to preserve for chain of custody.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Ranked list of high-probability ghost employees
  • Supervisor concentration analysis
  • Estimated exposure with confidence range
  • Evidence preservation checklist

Review before you act

  • Validate this output against source files before relying on it: Flag all employees who show payroll activity but zero HR activity (no address changes, no benefit changes, no time-off records, no badge swipes) over any rolling 12-month window.
  • Validate this output against source files before relying on it: For flagged employees, identify whether their direct deposit routing number matches any other active employee—a sign of payment consolidation fraud.
  • Validate this output against source files before relying on it: Cross-reference supervisor approval chains: are any flagged employees approved exclusively by one supervisor?.
  • Validate this output against source files before relying on it: Estimate total fraudulent disbursements if all flagged employees are confirmed ghosts.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Ghost Employee Investigation, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface ranked list of high-probability ghost employees; supervisor concentration analysis; estimated exposure with confidence range; evidence preservation checklist. Those are comparison artifacts — they only exist if more than one model runs. Models often split on qualitative materiality, intent versus error, and whether a newly formed counterparty is a red flag or a legitimate intermediary. Those splits are the review queue — not noise.

Forensic AccountingOccupational FraudRisk AssessmentHighSpreadsheets

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.