September 8, 2026

How to prepare your company for a labour audit: guide and checklist

Spain's Labour Inspectorate can walk in unannounced and ask for four years of time records, contracts, payslips and your risk prevention plan. Here is what the ITSS Strategic Plan 2025-2027 targets, the documents you must produce, fines from €751 to €983,736, and a checklist to be ready.

How to prepare your company for a labour audit: guide and checklist

A labour audit almost never arrives at a convenient moment. It may start with an employee complaint, with a planned campaign under the Strategic Plan of Spain's Labour and Social Security Inspectorate (ITSS) 2025-2027 or, increasingly, with an automated data cross-check between the Social Security system, the tax agency and the public employment service that flags an inconsistency in your company. In all three cases the outcome depends on the same thing: whether you can put the documentation on the table within minutes, or whether you have to reconstruct it.

And the context leaves little room for improvising. The ITSS has reinforced its staff with more than 500 inspectors and deputy inspectors and has prioritised exactly the areas where most companies fall short: working time, pay equality, psychosocial risks and bogus self-employment. Getting ready is no longer a job for your external adviser: it is a job of internal organisation.

The essentials in one minute

  • An inspector may enter without prior notice at any workplace (article 13 of Law 23/2015).
  • Time records must be kept for 4 years and be available at the workplace itself.
  • Not having them is a serious offence: €751 to €7,500, applicable per workplace.
  • In occupational risk prevention, very serious offences reach €983,736.
  • Once an infringement report is issued you have 15 working days to respond.
  • Employment offences have a 3-year limitation period: the Inspectorate can look back.

A labour audit and an inspection are not the same thing

It is worth separating two things that often get confused. A preventive labour audit is voluntary: the company itself commissions it — from its advisers, a law firm or its own HR department — to find breaches before anyone else does. It carries no sanctions, and that is precisely where its value lies.

An inspection is something else: it is carried out by the Labour and Social Security Inspectorate exercising public authority, and it can end in a formal requirement, an infringement report or an assessment for unpaid social security contributions. The preparation is identical in both cases; what changes is who knocks on the door and what happens if the paperwork does not appear.

How the Inspectorate reaches your company

The three ways it starts

  • A complaint: from an employee, from the workers' legal representatives or from a trade union. This is the most common origin and it usually follows a difficult exit or an overtime claim.
  • A planned campaign: actions programmed by sector, company size or region under the ITSS Strategic Plan. There is nothing personal here: your company profile puts you on the list.
  • Data cross-checking: the Inspectorate mines information held by the Social Security Treasury, the tax agency and the public employment service. Part-time hours declared with inconsistent contributions, or turnover that does not match the registered headcount, trigger an alert without anyone filing a complaint.

And a warning about 'prior notice': there often is none. Law 23/2015, governing Spain's Labour and Social Security Inspection System, is explicit about an inspector's powers.

To enter freely at any time and without prior notice any workplace, establishment or place subject to inspection, and to remain there.

Article 13.1 of Spain's Law 23/2015 on the Labour and Social Security Inspection System

What the Inspectorate is looking at in 2026

The ITSS Strategic Plan 2025-2027 concentrates its effort on five fronts. Knowing which ones lets you audit yourself where the inspector will actually look, instead of reviewing everything equally.

The five priorities

  • Working time: time records, overtime that is neither paid nor declared for contributions, rest periods between shifts, and the hours of part-time contracts.
  • Equality: equality plans, pay registers, pay audits and protocols against sexual harassment and harassment on grounds of sex.
  • Psychosocial risks: assessment of mental load and work pace, mental health, and the digital disconnection policy.
  • Workplace algorithms: bias and lack of transparency in automated systems for recruitment, task allocation and performance evaluation.
  • Undeclared work: bogus self-employment, fraudulent temporary contracts, and hours worked beyond those contracted.

The pay register is not just for large companies

This is a very common misunderstanding. An equality plan is mandatory from 50 employees upwards (Royal Decree 901/2020), but the pay register is required by Royal Decree 902/2020 of every company, whatever its size, showing average values for salaries, supplements and non-wage payments broken down by sex and professional group. A company of eight people needs one too.

The documents you will be asked for

This is the list that appears, with few variations, in any inspection. Note the retention period for each block: it matters as much as having the document at all.

Mandatory documentation and retention periods

  • Daily time records for the last 4 years, with specific start and end times per person (article 34.9 of the Workers' Statute).
  • Employment contracts, signed and in force, with their extensions and annexes, plus proof of notification to the public employment service within 10 working days of signing.
  • Basic copy of contracts delivered to the workers' legal representatives, where they exist.
  • Payslips and proof of payment, together with the social security contribution documents (RLC and RNT) for the previous 4 years.
  • Occupational risk prevention plan, risk assessment — psychosocial risks included — preventive activity planning, and proof of health and safety training and information.
  • Medical check-ups offered, and health surveillance documentation.
  • Pay register (all companies) and equality plan with pay audit filed with the REGCON registry (from 50 employees).
  • Anti-harassment protocol covering sexual harassment and harassment on grounds of sex, plus the LGBTI protocol for companies with more than 50 employees.
  • Internal whistleblowing channel and its management policy, mandatory under Law 2/2023 for companies with 50 or more employees.
  • Digital disconnection policy, drawn up after consulting the workers' legal representatives (article 88 of the LOPDGDD).
  • Information given to employees about monitoring systems — clocking in, geolocation, video surveillance — and the GDPR record of processing activities.
  • Proof of mandatory training, including the 20 hours of annual paid training leave where it applies.

Time records: the single biggest source of infringement reports

If there is one document an inspector always asks for, it is the time record. It allows working hours, overtime, rest periods and consistency with payslips and contributions to be checked in one go. It is also the easiest one to fail, because many companies still hold it together with spreadsheets.

The company shall guarantee the daily record of working time, which must include the specific start and end time of each worker's working day.

Article 34.9 of Spain's Workers' Statute

The provision adds that records must remain available to employees, their legal representatives and the Labour Inspectorate for four years. 'Available' means at the workplace itself and accessible at the moment of the visit: promising to email them next week does not count. We go into this in our article on the fines for failing to keep time records.

Common failings an audit uncovers

The mistakes that come up again and again

  • Scattered documentation: contracts in a manager's inbox, payslips in a shared folder, clock-ins in a spreadsheet and protocols in a PDF nobody can confirm is the latest version.
  • Time records filled in after the fact: identical every day, no breaks and no trace of who changed what. They do not evidence real working time, and an inspector spots it immediately.
  • Discrepancies between recorded hours and payslips: overtime that appears in the record but is neither paid nor declared for contributions. That is the direct route to a contributions assessment.
  • Documents signed without an audit trail: with no timestamp and no evidence of the signing process, the company cannot prove when a document was delivered or who actually signed it.
  • Not informing staff about the monitoring system, a requirement of both the GDPR and article 20.3 of the Workers' Statute.
  • Outdated policies: harassment protocols predating the latest reform, expired equality plans, or pay registers untouched for two years.
  • Nobody knows where anything is: the person who managed the paperwork has left and no one else holds the access.

What happens on the day of the visit

The inspector identifies themselves, states the purpose of the action, and may require the employer to attend, interview employees in private and examine the documentation. The company has a duty to cooperate: denying access, concealing documents or deliberately delaying delivery amounts to obstruction of the inspection, a standalone offence penalised on top of whatever is found.

An inspection can end in three ways: with no consequences, with a formal requirement to put things right within a set deadline, or with an infringement report. If the report arrives, you have 15 working days from notification to file your submissions with the competent body. That window is short, and it is used far better when the documentation is already in order.

A requirement is not a fine, but the clock is running

If the inspector issues a requirement and the company fails to fix things within the stated deadline, the action almost certainly becomes an infringement report, and the breach is then treated as deliberate. A requirement is the best opportunity you will get: treat it as a real deadline, not an informal reminder.

Fines: what being unprepared costs

Current amounts under the LISOS

  • Time records (serious offence): €751 to €1,500 at the minimum degree, €1,501 to €3,750 at the medium degree and €3,751 to €7,500 at the maximum degree, applicable per workplace and graded by the number of employees affected.
  • Occupational risk prevention: serious offences from €2,451 to €49,180 and very serious offences from €49,181 to €983,736.
  • Bogus self-employment and improper registrations (very serious in social security terms): €7,501 to €225,018, plus assessment of the unpaid contributions with a surcharge.
  • Equality breaches: failing to draw up or apply the equality plan is a serious offence, and it can bring loss of grants and rebates plus a ban on public-sector contracting.
  • Whistleblowing channel: Law 2/2023 provides for fines of up to €1,000,000 for very serious offences.
  • Obstructing the inspection: a serious offence in its own right, added on top of everything else.

Bear in mind, too, that employment offences carry a three-year limitation period — five years for very serious prevention offences — so the Inspectorate is not limited to what is happening today. You can estimate your company's specific exposure with our penalty calculator.

Checklist to prepare for the audit

Ten things to verify before anyone knocks

  • Digital, traceable time records, marked in real time and showing who changed each entry and when.
  • Guaranteed 4-year retention and immediate export in a format the inspector can read.
  • Consistency between clock-ins, payslips and contributions: check that recorded overtime is actually paid and declared.
  • Contracts and annexes signed electronically with a timestamp and evidence of the signing process.
  • A single document repository with version control, where the current version of each policy is unambiguous.
  • Role-based permissions: who can see which document, with restricted access to sensitive information and health data.
  • An up-to-date pay register and, if you have 50 or more employees, a filed equality plan and pay audit.
  • A working whistleblowing channel with its management policy documented, if you are above 50 employees.
  • A current risk assessment, psychosocial risks included, plus proof of the health and safety training each person has received.
  • Proof of delivery and information: acknowledgements of receipt for the policies communicated to staff, including the one covering the time tracking system.

How to prepare for a labour audit with Horalia

The difference between an audit resolved in a morning and one that ends in an infringement report is rarely underlying compliance: it is being able to prove it. That is why the centrepiece is Horalia's document manager, which centralises in one place the documents and policies your company is required to hold and makes them immediately available in the event of an inspection.

What the document manager solves

  • A single repository for contracts, annexes, payslips, protocols, plans and internal policies: no more hunting for the latest version across three folders and an inbox.
  • Immediate availability: when the inspector asks for a specific document, it is found and downloaded there and then, from the workplace itself.
  • Advanced electronic signature with process evidence and a timestamp, so you can prove who signed, what they signed and when. We cover it in depth in our article on document management and electronic signature.
  • Bulk distribution of policies to the whole workforce with acknowledgement of receipt — the proof you will be asked for that the information actually reached each person.
  • Version control and full history for every document, evidencing since when each protocol has been in force.
  • Role-based permissions and data hosted in the European Union, in compliance with the GDPR and the LOPDGDD.

Around it, the rest of the platform covers the other fronts of an audit: time tracking with a tamper-evident history and 4-year retention, absence and holiday management, schedules and calendars, shift planning and the whistleblowing channel required by Law 2/2023. You can discover Horalia or try it for free and reach your next audit with the work already done.

Conclusion

Preparing for a labour audit is not about complying on the day of the visit: it is about being able to prove you have been complying for years. The Inspectorate can enter unannounced, look back three years and ask for four years of time records, and fines run from the €751 of a time-tracking breach to the €983,736 of a very serious prevention offence. A company whose clock-ins, absences and documentation are centralised and traceable answers in minutes; one whose records are scattered starts losing from the first question.

© 2026 Horalia Software S.L.