Time fraud is an insider threat in which a worker is paid for work they are not actually performing. It often involves giving another person control of a device or session while keeping the appearance of normal activity. The security concern is misuse of authorized access, not simple timekeeping error.
Expanded Definition
Time fraud is not a payroll typo or a generic attendance issue. It is a misuse of authorised access in which someone creates the appearance of active work while another person, or a non-authorised workflow, is actually doing the task or holding the session. The practical boundary matters: if the core problem is falsified presence backed by legitimate access, the security lens is insider abuse rather than record-keeping error.
In security terms, the issue sits between workforce misconduct and access misuse. The worker may remain the nominal account owner, but the real control of the device, session, or assigned task is no longer aligned with that identity. That distinction affects investigation, evidence handling, and policy ownership. For a control baseline on monitoring and access accountability, NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is the clearest authority among the supplied sources.
Examples and Use Cases
- A remote worker signs in at the start of the shift, then leaves a device connected while someone else continues the apparent activity.
- An employee delegates keyboard and mouse control to another person during paid hours, preserving the normal session trail while disengaging from the actual work.
- A contractor keeps a system online and responsive enough to look active, but the expected assigned task is being performed by a different individual or not performed at all.
- A manager relies on attendance logs alone and misses the gap between login presence and actual task execution, which is why time fraud is often discovered through productivity anomalies rather than a single alert.
The common implementation tradeoff is surveillance versus trust. Organisations need enough visibility to detect misuse of paid time, but they should avoid treating every idle period as suspicious because legitimate pauses, meetings, and offline work are normal in many roles.
Security Implications
When time fraud is ignored, the direct loss is not just wage leakage. It weakens assurance that authorised access is being used by the assigned worker for the intended purpose, which can mask broader insider risk. A session that appears legitimate can become a cover for unreviewed access, poor segregation of duties, or unapproved delegation.
Operationally, the failure mode is poor alignment between identity, session, and activity. If managers only check login timestamps, they may miss patterns such as repeated inactivity, shared control, or suspiciously consistent output from an account that is supposedly active. That creates a governance gap: the organisation cannot reliably tell whether the named worker is actually accountable for the work performed.
The practical consequence is diluted control confidence. If an insider can preserve appearances while transferring the work to another person, then attendance evidence, work logs, and basic access records stop being dependable indicators of performance or trustworthiness.
Domain and Governance Relevance
Time fraud matters in workforce governance, insider-threat management, and access accountability because it tests whether an organisation can link a paid role to actual human execution. The subject is not mainly about identity proofing or credential compromise, but it does affect how much trust should be placed in a named user’s session and whether supervision is sufficient.
Where the work is digital, the governance question becomes whether the organisation can distinguish authorised presence from authorised performance. That matters in environments that depend on audited activity, regulated processing, or customer-impacting tasks. The best controls usually combine policy clarity, manager oversight, and evidence that the assigned worker is the one actually carrying out the work.
For NHIMG’s identity-security lens, the useful distinction is that this is a people-and-access integrity problem rather than a pure timekeeping concern. The identity element becomes material only when the named user’s session is being used to conceal who is really doing the work.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | Time fraud creates insider-risk and accountability exposure that belongs in enterprise risk governance. |
| Recommendation — Treat time fraud as an insider-risk issue and track it in your workforce risk governance process. | ||
| CIS Controls v8 | 5 — Account Management | Shared control or delegated session use undermines user accountability and access ownership. |
| 8 — Audit Log Management | Detection often depends on correlating login, activity, and inactivity evidence across logs. | |
| Recommendation — Review account ownership and remove informal shared access that obscures who performed the work. Correlate logs and activity signals to spot paid sessions with little or no real work. | ||
| NIST SP 800-63 | 6 — Authenticator and Lifecycle Management | The term touches session legitimacy and the question of whether the authenticated user remained the real operator. |
| Recommendation — Bind authenticated sessions to the expected user and investigate when control appears to shift during a shift. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Time fraud can rely on legitimate accounts whose apparent activity masks misuse by another person. |
| Recommendation — Hunt for valid-account misuse when a legitimate session shows activity inconsistent with the assigned worker. | ||
Related resources from NHI Mgmt Group
- Why do AI-powered fraud campaigns weaken one-time verification?
- Why do multi-surface identity programmes reduce fraud and support burden at the same time?
- What breaks when fraud controls stop at onboarding and ignore payout time?
- Why do real-time commerce flows make legacy fraud systems less effective?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org