Payroll and DSN checks: discrepancies caught before filing
A payroll error is almost always found too late: the payslip has gone to the employee, the return to the social security bodies, the entry to accounting. Your agent reads every payslip and every return before filing, cites the rule that grounds each discrepancy and the line that carries it, and traces recurring anomalies back to their cause rather than their symptom. Hosted in France, running locally or on an isolated resource. The payroll officer approves.
Updated on
The 9: 4 contribution bases that move with no event in the file to explain it, 3 items missing although the file's collective agreement provides for them, 1 contract closed in payroll but still open in the return, 1 contribution rate left at its previous-year value.
The other 128 are variations explained by a dated event in the file — a start, a leaver, an absence, a bonus — and are classified as such, with the event shown alongside.
Every discrepancy cites the rule that grounds it and the payslip line that carries it. The file is ready to review.
⛓ Sourced · payroll software and this month's return, 4,900 payslips, 214 client files
What that produces if the filing goes out as it stands: a feedback report after filing, and a correction to carry into the following month — Article L. 133-5-3 of the French Social Security Code requires inaccurate or incomplete data filed for earlier months to be corrected.
What I have prepared: the end-of-contract block, with the date and reason exactly as they appear in the payroll file. You approve it, it goes into the return before tomorrow's filing.
✎ Framework · Article L. 133-5-3 of the French Social Security Code — correction of filed data
A Blue Lemon Agent payroll control agent reads the month's payslips and the DSN return before filing, flags every discrepancy with the rule that grounds it and the line that carries it, spots recurring anomalies and traces them to their cause, picks up the feedback reports to prepare the corrections owed under Article L. 133-5-3 of the French Social Security Code, and keeps the history of discrepancies per file. Hosted in France, running locally or on an isolated resource, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: your pay data stays with you. The payroll officer approves.
Reference points describing our offer, not results measured at a client. The scale of the gain is confirmed by a pilot on your own portfolio.
Why payroll control is decided before filing
At month end everything goes out at once: the payslip to the employee, the return to the social security bodies, the entry to accounting. An error caught beforehand is corrected with one gesture; the same error caught afterwards ties up the payroll officer, the client and the employee, and drags on across two or three months of corrections.
! The challenge
A payroll team produces hundreds of payslips a month, across as many collective agreements and configurations, and files them against a deadline that does not move: payment falls due in the month following the work period, « le 5 de ce mois pour les employeurs dont l'effectif est d'au moins cinquante salariés et dont la paie est effectuée au cours du même mois que la période de travail », « le 15 de ce mois dans les autres cas » — Article R. 243-6 of the French Social Security Code (Légifrance — Article R. 243-6). Exhaustive checking is mechanical work, but it takes time the deadline does not leave.
✓ Our answer
The agent sifts the batch while the month is being built, not the evening before filing: consistency of each payslip against the contract and the collective agreement, reconciliation of payslips and return, comparison with the previous month, and pick-up of feedback reports to prepare the corrections required by Article L. 133-5-3 of the French Social Security Code (Légifrance — Article L. 133-5-3). The payroll officer approves: keeping a discrepancy, correcting a payslip and triggering a filing are acts that bind the firm or the employer. Local inference or an isolated resource hosted in France: pay data never leaves the house.
Pay, absences, family situations: sensitive by concentration
A batch of payslips gathers what a company knows most intimately about its staff. Here is how the architecture protects it, file after file.
Local inference
The agent can run on a machine inside the firm or the company: no payslip leaves the network, nothing passes through a foreign cloud.
Hosting in France
Otherwise, a dedicated, isolated resource hosted in France under French law — pay data: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
Architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity: the pay of your staff, or of your clients' staff, depends on a subcontracting chain and remote access documented for the configuration chosen.
Separation by client file
Each client file stays separate: a check on one never gives access to another's data, and the separation is logged.
Controlled access and retention
Encryption in transit and at rest, role-based access (RBAC), logging, and retention periods aligned on those you already apply.
AI Act: governed deployment
A strictly supporting agent; no payslip corrected and no filing triggered automatically; traceability and human supervision end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- The encryption mechanisms in transit and at rest, their components and key management are those documented for the architecture chosen.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyFerralis & Associés — accountancy firm, payroll department
- Sector
- Accountancy: the payroll department produces payroll and returns for small and mid-sized clients
- Headcount
- 48 staff, including 6 payroll officers and a head of the payroll department
- People served
- 214 client files, from 1 to 180 employees — retail, construction, catering, services
- Order of magnitude
- 4,900 payslips a month, 214 monthly returns — 23 client files due on the 5th, 191 on the 15th
- Tools in place
- The firm's payroll software, the filing platform, plus per-file settings and collective agreements
- Who decides
- The payroll officer keeps or sets aside each discrepancy, approves corrected payslips and triggers filing for their own file; the signing chartered accountant commits the firm on a closed financial year or on rework outside the engagement letter
- Room for improvement
- Over twelve months, 63 returns drew a feedback report with an anomaly, and 41 payslips were corrected after being handed to the employee
Ferralis has doubled its portfolio in four years without doubling its payroll department. Payslip checking therefore happens at month end, under deadline pressure, and by sampling: part of the batch goes out unread. The agent is connected to two systems — the payroll software and the filing platform — and works continuously; keeping a discrepancy, approving a corrected payslip and triggering a filing remain acts of the payroll officer.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
The 9:
· 4 contribution bases that move with no dated event in the file to explain it — no start, no leaver, no absence, no bonus entered this month.
· 3 items missing although the collective agreement recorded in the file provides for them.
· 1 contract closed in payroll and still open in the return — Marnaval file.
· 1 rate left at its previous-year value on a file of 62 employees.
The other 128 are explained variations, and I show it: each is set against the dated event that produces it. They call for no action — I list them so that you can contradict me, not so that you have to process them.
Every discrepancy carries two things: the rule that grounds it — statute, collective agreement or the file's own configuration — and the exact payslip line that carries it. A flag without its rule is not a check, it is a worry. payslip-check_monthly-batch.pdf137 discrepancies · 9 to settle · 128 explained
⛓ Sourced · payroll software, this month's batch: 4,900 payslips, 214 client files
The clearest case, Verdanne file, 34 employees: one employee's capped base drops to a level 12.4% below its usual value, with no absence and no change of working time in the file. Going back twelve months, I find the same swing in February and in July, each time the month following a bonus adjustment. So this is not an incident, it is a behaviour.
My reading: the adjustment is entered on an item that is not attached to the same contribution profile as the bonus itself. In the bonus month everything is correct; the following month, the pick-up happens elsewhere.
What I propose, in this order: settle this month first — I have prepared the corrected payslip —, then look at the configuration, because correcting the payslip without correcting the cause will bring the same discrepancy back in October. The attached table gives the 137 lines, filterable by file and by family.
The other two bases come from an absence reason entered after the payslip was produced: the correction is mechanical, and it is prepared. discrepancies-this-month_137-lines.csv9 to settle, 128 explained, rule cited on every line
⛓ Sourced · comparison with the previous month and 12 months of file history
Solmieux file, catering, 18 employees: the collective agreement recorded in the file provides for a seniority bonus from three years of service. Two employees crossed that threshold this month — start dates from the file, calculation done — and the item appears on neither payslip.
Verdanne file: a professional expenses item provided for by a company agreement filed in January, never activated since.
What I have prepared: the three recalculated payslips, presented line by line, before and after, with the source of each addition — the collective agreement article for the first two, the company agreement article for the third. A payslip must carry the items listed in Article R. 3243-1 of the French Labour Code, and the employer keeps a copy for five years under Article L. 3243-4: better that the copy kept is the right one from the first issue.
What is left for you: checking that the collective agreement recorded in the file really is the applicable one — that is your source, not mine — and approving. The three payslips go out corrected in tomorrow's batch. corrected-payslips_before-after.pdf3 payslips, line by line, source of each addition
✎ Framework · file's collective agreement, company agreement, Article R. 3243-1 of the French Labour Code
What I do with every input received: I tie it to a period, an employee, a contract, an establishment and an effective date. An input missing any of the five does not enter the checks — it goes back to the file as a question, with the missing field named.
This month that produced a case data entry would not have caught: the Prillac file, one exceptional bonus received twice — through the portal on the 22nd, by email on the 24th, different wording, same amount. I neither add them up nor pick one: I show you both sources and their dates, and I ask which one prevails.
And where I cannot find the rule, I stop: on the Bastenac file, the rate of one collectively agreed contribution has been missing from the file's rule set since the March agreement changed. I do not carry last month's forward and I do not infer it — a guessed rate would pass every one of my checks and would be read on an employee's payslip. The check reads "rule missing", never "passed", and it stays that way until the rate is filed.
Every rule I apply carries its version and its effective date, and that is the version cited under the discrepancy: a check replayed next January replays this month's rule, not January's. monthly-inputs_collection-and-rule-set.pdf3 channels · 1 duplicate · 1 missing rule, not guessed
⛓ Sourced · 214 client files, three collection channels, rule set versioned per file
What I compared, item by item: pay totals, declared headcount, contracts opened and closed during the month, pay blocks, consistency of employee identifiers.
The 6:
· Marnaval file — a contract closed in payroll, still open in the return. Departure recorded on 28 July, final payslip issued, final settlement made: the end-of-contract block was not carried over.
· 2 files where the declared headcount is one higher than the payslip headcount — two employees who left on the last day of the month.
· 2 incomplete identifiers for employees who started this month.
· 1 pay block whose total differs from the sum of the file's payslips by 0.3%, on an adjustment.
Why this is worth doing tonight rather than next month: Article L. 133-5-3 of the French Social Security Code requires inaccurate or incomplete data filed for earlier months to be corrected. An anomaly that is filed does not go away: it comes back as a correction.
The 6 blocks are prepared, each with the payroll-file data it is drawn from. You approve, and filing goes out tomorrow on the deadline. return-check_before-filing.pdf208 without reservation · 6 blocks prepared
⛓ Sourced · 214 returns and 4,900 payslips from the same month, reconciled item by item
I keep the rejection exactly as it arrives — code, wording, timestamp — without rephrasing it. A rewritten rejection is one you can no longer hold up to anyone.
What I read in it: a block whose cardinality did not match the technical specification in force — two occurrences where it expects one. The structure check now runs before sending, against the edition of the specification you file with me: your document prevails, never my memory.
Compliance is declared by the body that receives the batch — and I hand you its proof: I record that body's receipt exactly as it reaches me and tie it to the batch, with the time and the code it carries. Until the receipt is there, the batch reads "filed, no receipt" — never "successful". That document is the one that stands up in front of a client, and it is yours in one click.
On deadlines, your batch carries two, and I sort it accordingly: in France the payment falls due on the 5th of the following month for employers with at least fifty employees whose pay is settled within the same month as the work period, and on the 15th in every other case (article R. 243-6 of the social security code). Of your 214 client files, 23 fall on the 5th and 191 on the 15th: I run the 23 first, five days earlier, and you see two waves instead of one scramble.
Outside that monthly rhythm: an end of contract or a sick leave is reported within a period set by ministerial order that may not exceed five working days (article R. 133-14 of the same code). I raise those as they come, file by file, without waiting for the batch. batch-rejection_what-changed.pdfRejection kept verbatim · 23 files on the 5th, 191 on the 15th
✎ Framework · articles R. 243-6 and R. 133-14 of the French social security code; technical specification filed with the agent
How they break down:
· 29 concerned incomplete or unrecognised employee identifiers. All corrected, and the check that prevents them now runs before filing: zero reports of that family for four months.
· 18 concerned missing end-of-contract blocks — the family of the Marnaval file a moment ago.
· 11 concerned base discrepancies between the return and the payslips, including the 11 still open: they need a decision I cannot take, because it means choosing between correcting the month of origin and adjusting in the current month.
· 5 concerned rates.
What I have prepared for the 11: for each one, the month of origin, the line concerned, the two correction routes with what each produces, and my recommendation. Nine can be adjusted in the current month with no effect on the employee; two touch a contribution base of a closed year and deserve a word to the client first.
You settle the 11, and the queue is empty for the first time in a year. feedback-reports_63-over-12-months.csv52 cleared · 11 awaiting a decision
⛓ Sourced · 63 feedback reports received over twelve months, tied file by file
What the history shows: the « meal allowance » item is attached, in the firm's configuration, to a single contribution profile. Yet your 9 files apply two different regimes depending on whether the meal is provided or not — 4 files in one case, 5 in the other. A single configuration therefore produces a discrepancy on 5 files, every month, mechanically. This is not a data-entry error: it is a rule that is missing.
What I have written: two distinct profiles, attached to the file rather than to the item, with the condition that separates them written in plain French.
What that gives when run over the last twelve months: 6 flags instead of 214. The 6 are exactly the ones your officers had confirmed — genuinely faulty entries. The other 208 disappear, because they should never have existed.
What that gives you back: over twelve months, 208 flags handled by hand, at three minutes each, come to more than ten hours — and above all, a family of flags that no longer cries wolf.
The signature stays with the firm: a configuration only takes effect once you approve it. That is what lets you answer for it in front of a client. root-cause_meal-allowance.pdf214 → 6 flags · 2 profiles written, ready to approve
⛓ Sourced · 12 months of history, 9 files, 214 flags and what became of them
A recent example, and it does not flatter me. You asked me for a check on overtime: flag any employee whose volume exceeds the previous month. Run over twelve months: 312 flags, 11 confirmed by your officers. One useful flag in twenty-eight. I advised you not to put it into service, and I was right to: a check with that much noise teaches your team to click without reading, and it damages the checks that are sound as well.
What I proposed instead: the same check, narrowed to three cumulative conditions — more than 30% above the employee's usual volume, on a file whose collective agreement caps the quota, and outside months of high activity declared in the file. Run over the same twelve months: 34 flags, 10 of the 11 confirmed cases found again. One useful flag in three, and a single case lost — which I showed you, because it is part of the bargain.
The protocol applies to every future check: I run it, I publish the noise and the confirmations, you decide on figures. And a check in service is re-measured every quarter: one that drifts is narrowed or withdrawn.
✎ Framework · no check goes into service without first being run over twelve months of history
What was produced: 389 discrepancies flagged, of which 147 kept by your officers and corrected before issue; 63 feedback reports picked up and tied to their line; 2 configurations rewritten and approved.
What changed on the indicators that bothered you: 0 payslips corrected after being handed to the employee over the quarter, against 41 over the previous twelve months. 4 returns with an anomaly report, against a quarterly average of 15.
The time given back, as I count it: 154 hours over the quarter, which is more than four weeks on a 35-hour basis — reading, reconciliation and shaping. Decision time has not fallen, and that is intended: it is the one place where your officers' judgement cannot be replaced.
The figure that does not flatter me: of the 389 discrepancies flagged, 242 were set aside by your officers. Two families account for 180 of them: base variations linked to paid leave on construction files, and the standby items of the Kerviel file. In both cases the cause is mine — I was reading a general configuration where the file carries its own. Both rules were fixed on 4 August; over the following three weeks those families produced 7 flags, of which 5 were kept. dashboard_quarter.pdf154 h given back · 389 flagged, 147 kept · 2 families fixed
⛓ Sourced · check log from 1 June to 31 August: 14,700 payslips, 642 returns
What the per-file history says, over three months:
· The Kerviel file, 27 employees, produced 61 discrepancies kept. The Marnaval file, 180 employees, produced 9. Seven times more discrepancies for seven times fewer employees.
· Five files account for 58% of the discrepancies kept and represent 11% of the payslips.
· What they have in common: company agreements that depart from the collective agreement, and variable items entered late.
What I propose, file by file: for three of them, a configuration of their own to write — I have quantified it as I did the meal allowance, each time with what it would have produced over twelve months. For the other two, the problem is not technical: variable items arrive after the payslip has been produced. I have prepared the dated log of the client's submissions over six months — that is the document that makes the conversation possible without it turning into a reproach.
What management does with it is theirs: revisit an engagement letter, adjust a calendar, or change nothing. The attached table gives all 214 files, sortable. discrepancy-history_214-files.csvFlagged, kept, set aside — per client file
⛓ Sourced · history of discrepancies per file, 1 June to 31 August, 214 files
What happens if the indicator becomes individual: the number of discrepancies kept per officer becomes a target. A target distorts what it measures: an officer who hesitates over a discrepancy now has an interest in settling it quickly, and one who has doubts stops telling me so. I then lose the very information I use to correct my own rules — which is exactly how this quarter's 242 set-aside discrepancies could be traced back to their cause. The instrument of control disappears at the moment it becomes an instrument of appraisal.
That said, this is not my choice to make, and I will not hide behind a prohibition that does not exist: the employer's right to monitor work is recognised. If you ask for the individual indicator, I produce it, and I bring the three conditions to be met: proportionality to the aim pursued (Article L. 1121-1 of the French Labour Code), prior information of the people concerned (Article L. 1222-4), and consultation of the works council before implementation, from fifty employees upwards — your firm has 48 today, so the threshold is worth watching.
What I do without asking, and what a single word undoes: I open the check on a batch as soon as payroll is produced; I raise an alert 3 days before any filing deadline; I tie an incoming feedback report to its file and its line. Three acts, none of which writes into payroll or files anything. The rest waits for your decision, and the attached document says exactly what. who-decides-what_payroll-control.pdf3 automatic acts · 4 acts reserved to the payroll officer
✎ Framework · Articles L. 1121-1 and L. 1222-4 of the French Labour Code; reversible automatic acts
The payroll officer keeps or sets aside a discrepancy, approves a corrected payslip and triggers the filing for the client file they handle. The signing chartered accountant commits the firm: they settle a correction touching a closed financial year, a regularisation that moves a base already declared, or any rework outside the engagement letter. The two acts are distinct in the log — name, time, and what was approved.
What that rules out, deliberately: there is no single action that files all 214 client files at once. Each file carries its own decision, its own approver and its own receipt. A firm that files in one click can no longer tell a client who approved what.
Segregation follows the same rule: a document in the Verdanne file does not open from the Marnaval file, even for an officer who handles both — the attempt is refused and logged. That log is what you will show the day a client asks.
On this point I have no automatic action at all, and that is precisely what makes the other three acceptable. who-decides-what_payroll-control.pdf3 automatic actions · 4 reserved acts · 2 distinct signatures
✎ Framework · segregation of duties between payroll officer and signing chartered accountant; segregation per client file
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
The checks the agent runs, month after month
Each use corresponds to a family of checks. All of them work in support: the payroll officer approves.
Payroll input collection
The month's variable items are gathered and set against their source: period, employee, contract, establishment and effective date. An input received twice is flagged as a duplicate, never added up.
Versioned payroll rule set
The file's collective agreements, company agreements, pay items and rates are kept with their effective date and their version, and that version is what each discrepancy cites. A missing rule is reported as missing: the agent invents none and fills in no missing rate.
Payslip consistency
Items expected under the contract and the collective agreement, ceilings, rates, contribution bases, the month's variable items.
Comparison with the previous month
Variations that no dated event in the file explains are flagged with the gap quantified.
Contracts and events of the month
Arrivals, departures, sick leave, absences, changes in working time and retroactive items are matched against the payslips and the declared blocks. An event present on one side and absent from the other is raised with its date.
Structure of the return
Blocks, cardinalities and types are checked against the technical specification you supply for the French monthly social return (DSN), and a rejected batch is kept in the form in which it reaches you. Compliance of the return is established by the body that receives it, never by the agent.
Payslip / return reconciliation
Totals, headcount, contracts opened and closed, pay blocks, consistency of identifiers — before filing.
Feedback reports and corrections
Reports received after filing are tied to their line, and the following month's correction is prepared.
Recurring anomalies
What comes back every month is traced to its cause: a configuration setting, a wrongly attached item, a badly chosen contract profile.
Draft correction
Every discrepancy that is kept becomes a draft readable line by line, before and after, with the file data it is drawn from. It stays a draft until the payroll manager has approved it.
Approval circuit before filing
The batch goes through the checks, then through the named approval of an authorised person; the receipt issued by the filing system is recorded exactly as received. The agent triggers no filing and never manufactures a receipt.
History of discrepancies per file
What was flagged, kept, set aside and by whom — enough to answer at last, with figures, on what a client file really costs.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
Accounting agent
For entries, matching and accounting anomalies beyond payroll, a dedicated agent completes the set.
Accounting agent (summaries, anomalies) from 781 € excl. VAT / month Accounting agent →HR documents
To file, retrieve and produce personnel documents, an HR document agent completes the arrangement.
HR document management agent from 710 € excl. VAT / month HR document management →In 15 minutes we identify the most relevant agent — without oversizing the project.
Where a payroll team's time goes, and where it comes back
By taking on exhaustive reading and reconciliation, the effort moves towards settling the cases that deserve it. The scale of the gain depends on the number of payslips, the number of collective agreements covered and the state of the configurations.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
A payroll control agent, installed and operated for you
An L2 agent: payslip checks, reconciliation with the return, recurring anomalies and the history of discrepancies, with the connectors and monthly maintenance of that level. Prices excluding VAT — annual subscription, the time it takes for the gains to settle in.
Setup + controlled subscription
- Installation, configuration and training for your teams
- Operation, human oversight, updates and support
- Sovereign hosting in France, a dedicated and isolated resource
All inclusive, no setup fee
- Setup included (installation, configuration, training)
- Operation, human oversight, updates and support
- Sovereign hosting in France, managed end to end
On site, you own it
- Hardware installed on your premises (you own it)
- French / European AI models run locally
- Secure remote maintenance (Pro support included)
Four guarantees that matter to a payroll team
Related resources
Your questions, our answers
Does the agent run payroll?
Does the agent file the return?
What does it do with the feedback reports received after filing?
How does the agent version the rules it applies?
Can the agent serve several companies or several client files?
How does it avoid burying the payroll officer in flags?
How does it handle different collective agreements from one file to the next?
Does it measure the payroll officers' work?
How many systems does the agent connect to?
Is our payroll data protected?
How long does it take to deploy the agent?
Other agents for the payroll team and the firm
Let us estimate the potential on your payroll batch
15 minutes to scope your volumes, your collective agreements and your deadlines — hosted in France, supervised, with no commitment.