Time clocks10 min read
Buddy punching: why it keeps happening, and what actually stops it

Buddy punching is the plainest problem in workforce time tracking and the one most businesses quietly give up on. Not because owners do not care, and not because staff are dishonest, but because almost every time clock ever sold can be operated by somebody standing in for somebody else. If the thing your clock asks for can be spoken, texted or lent, then your attendance record is a record of what a credential did, not of who was there.
The short version
- Buddy punching is one employee clocking in or out for another. It survives PINs, phone apps and honesty policies because each of those can be handed to a coworker without the lender going without anything.
- Most of it is not theft. Four causes account for nearly all of it, and three are process problems: somebody forgot, the clock is inconvenient, or the shift boundary is fuzzy.
- A credential stops it when it is a physical object whose absence somebody would notice. A badge or name tag qualifies; a number in somebody’s head does not.
- A badge alone is not proof of identity. A badge plus a photograph taken at the moment of the tap is: the card shows a credential was present, the photograph shows who was holding it.
What buddy punching actually is
Buddy punching is one employee clocking in or out on behalf of another. Somebody is running late, so a coworker enters their PIN at the wall tablet. Somebody leaves twenty minutes early on a slow night, and a friend clocks them out at close. The payroll file that lands two weeks later shows a full shift for a person who was not there for part of it, and nothing in the record disagrees.
It is worth being precise about the scale of this, because the industry is not. You will find articles claiming that buddy punching costs American employers a fixed percentage of payroll every year. Those figures circulate endlessly and trace back to nothing you can read. What is documented is narrower and more useful: under the Fair Labor Standards Act you are obliged to keep an accurate record of the hours each employee actually worked, and you are the one who has to produce that record if it is ever questioned. What counts as that record, and how long you keep it, is its own subject. A record that can be created by the wrong person is a weak answer to that obligation whatever the national average turns out to be.
The question is not how much buddy punching costs the average business. It is whether your record can tell you it happened.
The reasons are usually boring, and that matters
Managers tend to imagine buddy punching as theft, and occasionally it is. Far more often it is one of four ordinary situations, and knowing which one you have changes what you should do about it.
- Somebody forgot. They walked in, got straight onto the floor because there was a queue, and realised at ten past that they never clocked in. A coworker fixes it for them, meaning well.
- The clock is inconvenient. It is in the back office, up a flight of stairs, behind a door that needs a key. People solve for the distance, not for the policy.
- The shift boundary is fuzzy. Staff stay to finish a table or a prescription and clock out later in a batch, so one person tidies up the record for everyone.
- Somebody is taking time they did not work. This is the case everyone thinks of first and it is the least common of the four.
The first three are process problems wearing a fraud costume. If you respond to them with suspicion you will spend your goodwill on the wrong thing, and the underlying habit will continue. If you respond by making the honest path the easy path, most of the volume disappears before you ever have to have a difficult conversation.
Why PINs, passwords and apps do not solve it
Nearly every time and attendance product on the market answers buddy punching with a PIN. Some add a phone app. A few add a manager approval step. All three share a single flaw, which is that the credential is information rather than a thing. Information can be given away without being lost. Your coworker can use your PIN and you still have it.
A PIN on a shared wall tablet is worse than it looks, too. It is entered in front of a queue of colleagues, several times a day, for years. It is not a secret after the first week. We still support PIN entry, because a business should be able to run its clock on the day a reader breaks and because a new business should not have to buy anything to get started. What we do not do is pretend a PIN is evidence. Every PIN entry on our clock is flagged for a manager to look at, precisely because a PIN cannot prove who typed it.
Phone apps move the problem rather than fixing it. A phone can be handed over, and an app that clocks you in from anywhere within a wide radius of the building will cheerfully clock you in from the car park, the bus stop or the flat upstairs. Geofencing narrows the radius and narrows the problem to the same degree, which is to say somewhat.
Manager approval is the most expensive of the three. It works, in the sense that a person who was there signs off on what happened. It also converts a two second action into a weekly review of several hundred rows, and the reviewer very quickly starts approving in bulk. Any control that depends on sustained human attention to boring data degrades within a month.
What a credential has to do to actually work
A time clock credential stops buddy punching when it has two properties at once. It has to be a physical object rather than a piece of information, so that lending it means going without it. And its absence has to be visible to somebody, so that lending it is awkward in front of other people.
That second property is the one the industry forgets. A plain proximity card satisfies the first test and fails the second: a card lives in a wallet, and nobody notices a wallet. Ten cards can sit in one person’s pocket and the room looks completely normal.
The strongest credential for a time clock is the one the employee is already required to be wearing.
This is the idea On Post is built on, and it came out of a real problem rather than a design session. In New Jersey, pharmacy staff are required by regulation to wear a visible identification tag while working. The rule is not optional and it is not obscure. It was also routinely ignored, because the only enforcement available to the owner was noticing and saying something, every day, forever. There were printed signs next to the time clock. Signs do not work.
Putting the clock credential inside the name tag changes the economics of both problems at once. Clocking in requires the tag, so the tag comes to work. Lending the tag means working a shift without the thing you are legally required to wear, in front of colleagues and customers. The rule that was unenforceable becomes self enforcing, and the buddy punch becomes conspicuous instead of invisible.
What the badge does and does not prove
It is worth being honest about the limits here, because plenty of vendors are not. A 13.56 MHz card can be cloned by somebody who has bought the right twenty dollar device and has your card in their hand for a moment. A badge can still be handed over by two people who have decided to do that. A badge alone is not identity, and anyone telling you otherwise is selling.
What makes it strong is the pairing. The card proves a credential was present. A photograph taken at the moment of the tap proves who was standing there and whether the badge was being worn. Neither half is sufficient. Together they are the difference between a record you hope is right and a record you can hand to somebody.
Photographs, and the way they are usually wasted
Photo capture on clock in is not a new feature. It has been standard in this category for years, which is exactly why it is worth looking at how it is normally implemented.
Before building On Post we went through the stored punch photos on a real pharmacy account that had been running a well known time clock product for years. Every photograph showed a wall and some shelving. No person, no face, no badge, nobody in frame at all. The tablet was mounted at a height and angle where the camera pointed past everybody who used it, and it had been doing that for the entire life of the account. The photos were filed three levels deep behind a collapsed section. There was no review queue, no check for whether a person appeared in the frame, and no setting anywhere to configure any of it.
Nobody was ever going to find out. That is the part worth sitting with. The feature was switched on, the storage bill was being paid, the marketing page said photo verification, and the evidence was worthless.
If you are evaluating any product that captures photographs, ask four questions.
- Is the camera framing checked when the device is set up, and does setup refuse to finish if the frame is wrong?
- Is there a queue where a manager reviews flagged clock ins, or are photos only reachable one record at a time?
- How many clicks does it take to see the photograph for a specific shift? If the answer is more than two, nobody will ever look.
- Does the product do facial recognition? If it does, you have acquired a biometric privacy obligation, and you should know that before you switch it on rather than after.
On that last point we made a deliberate choice. On Post takes a photograph and shows it to a human. It derives no face geometry, matches no faces between images and runs no recognition of any kind. Illinois, Texas and Washington all regulate biometric identifiers, and Illinois law in particular has produced a long line of litigation.Photographs are excluded from the Illinois definition of a biometric identifier. A scan of face geometry taken from one is not, and what that means if you are shopping for a fingerprint clock is covered separately. That line is the whole reason the feature is built the way it is.
What to do about it this month
You do not need to buy anything to make progress on this. Four steps, in order of how much they return for the effort.
- Move the clock. Put it where people already walk, at the entrance staff use, at a height an average person can reach without stretching. Most of the informal buddy punching in a small business is a distance problem.
- Write down what happens when somebody forgets. If there is no stated way to fix a missed clock in, staff will invent one, and the one they invent is asking a coworker. A manager correction that takes fifteen seconds and leaves a trail is better than a policy nobody can follow.
- Look at your exceptions once a week. Not every record. The ones the system has flagged: PIN entries, clock ins with no photograph, shifts that ran past twelve hours, people still shown as present overnight. Ten minutes on the exceptions beats an hour on the full timesheet.
- Then change the credential. Once the process problems are gone, whatever is left is the part that needs a physical answer. Start with a QR code printed on the name tags you already issue, which costs a printer and an afternoon. Add a reader when you want the tap.
The order matters. Buying hardware first is how businesses end up with an expensive clock and the same timesheet problems, because three of the four causes were never about the credential at all.
Common questions
- Is buddy punching illegal?
- Clocking in for a coworker who is not there creates a false record of hours worked, and paying on that record is a wage and hour problem for the employer regardless of who created it. Employers are required under the Fair Labor Standards Act to keep an accurate record of hours actually worked, so the obligation to catch it sits with the business. Most employers treat it as a disciplinary matter under their own policy rather than pursuing it further.
- Does a PIN stop buddy punching?
- No. A PIN is information rather than an object, so it can be given away without being lost, and a PIN typed at a shared wall tablet in front of a queue of colleagues is not a secret after the first week. PIN entry is still worth supporting so a business can run its clock without buying hardware, but it should be treated as an exception to review rather than as evidence of who was present.
- How do you prove somebody clocked in for a coworker?
- You need something at the moment of the punch that ties it to a person rather than to a credential. A photograph captured at clock in and reviewed by a manager is the practical answer for most businesses, because it can be looked at and explained later. Check that the camera is actually framed on the person: stored punch photos frequently show a wall, because the tablet was mounted at an angle nobody ever verified.
- What does buddy punching cost a business?
- Nobody credibly knows, and the percentages circulating in this industry trace back to nothing you can read. The useful question is not the national average but whether your own records could tell you it happened. A record that can be created by the wrong person is a weak answer if the hours behind it are ever questioned.
Sources
- U.S. Department of Labor, Fact Sheet 21: Recordkeeping under the FLSA
- 29 CFR Part 516, Records to be kept by employers
- Illinois Biometric Information Privacy Act, 740 ILCS 14
- New Jersey State Board of Pharmacy regulations (N.J.A.C. 13:39)
This is general information about how these rules work, not legal advice. Wage and hour law varies by state and by industry, and your own counsel is the right place to take a specific question.
On Post is a time clock that proves who clocked in
A badge tap or a QR code on the name tag your team already wears, a framed photo on every clock in, and timesheets that are ready for payroll. Free for small teams.
Start free trial