Clocking in for a friend is the oldest fraud in the building
Every time clock ever built identifies a credential, a device, or a body part in a database. None of them identify a person who is standing there and meant to start work. That gap is why buddy punching outlived the punch card, the badge reader, and the fingerprint scanner.
Six fifty seven in the morning, and the line is forty deep
Picture the entrance to a distribution centre at shift change. Two doors, one clock terminal at each, and a queue that forms hard between 06:50 and 07:00 because nobody wants to be marked late and nobody wants to arrive early enough to stand around for fifteen minutes unpaid. The terminal takes a four digit code. It beeps. The line moves at roughly one person every three seconds, which is the only performance requirement anyone in the building actually cares about.
Somewhere in that line, a worker types two codes. Their own, and one belonging to a colleague who is eight minutes away and stuck behind a level crossing. This is not a heist. It is a favour, of the kind that has been exchanged in workplaces since the first mechanical clock was bolted to a wall in the 1890s. The colleague will do the same next week. Neither of them thinks of it as theft, and if you asked them whether they were defrauding their employer they would be genuinely offended.
Now scale that. In a building with eight hundred hourly staff, the favour is not an anomaly, it is a norm with a distribution. Most people never do it. Some do it occasionally. A small number do it systematically, and a much smaller number have worked out that nobody reconciles badge-in events against door sensors, camera timestamps, or the moment their scanner gun first registers a pick. For that last group it stops being a favour and becomes a salary supplement.
The manager knows. The manager has always known. What the manager does not have is any way to tell, for any specific punch, whether a human was there. The clock recorded a credential. That is the whole of the evidence.
Short answer: buddy punching persists because time clocks verify a credential (a PIN, a badge, a phone, a stored fingerprint template) rather than a present human. You can stop it without a biometric database by requiring each punch to be signed on the worker's own enrolled device with an on-device face match, so nothing biometric is stored anywhere and a colleague cannot produce the signature.
What does buddy punching actually cost?
Here is where most articles on this subject reach for a large number, and here is where this one is going to disappoint you on purpose.
The figure you will see everywhere, usually attributed to the American Payroll Association, is that buddy punching costs United States employers around 373 million dollars a year. You will also see the identical claim, with the identical attribution, rendered as 373 billion dollars. That is a thousand-fold spread on the same sentence, which is a reliable sign that nobody repeating it has traced it. A second figure, that time theft costs between 450 and 550 billion dollars annually, circulates with the same attribution and no locatable primary publication, no survey instrument, no sample, and no year.
We are not going to cite any of them. Not because the underlying problem is imaginary, but because a control that has to be justified with a number that varies by three orders of magnitude is a control being sold rather than a problem being measured. If you take one thing from this section, take this: when a vendor opens with the 373 figure, ask which one, and watch what happens.
The arithmetic you can actually do
You do not need a national estimate. You need your own, and the formula has four terms, three of which you already know.
annual_phantom_cost =
workers
× shifts_per_worker_per_year
× p # fraction of shifts carrying phantom time
× (m / 60) # phantom minutes per affected shift
× loaded_hourly_rate
# Worked example, mid-size distribution operation
800 workers × 240 shifts × 0.03 × (15/60) × $22 = $31,680 / year
Thirty one thousand dollars. For a lot of operations that is real money and not a crisis, and it would be dishonest to pretend otherwise. But look at what happens when the two unknown terms move, because they are the entire story:
| Workers | p (affected shifts) | m (phantom minutes) | Annual cost at $22 loaded |
|---|---|---|---|
| 800 | 3% | 15 | $31,680 |
| 800 | 10% | 25 | $176,000 |
| 5,000 | 3% | 15 | $198,000 |
| 5,000 | 10% | 25 | $1,100,000 |
The same operation, the same wage, the same formula, and the answer ranges from a rounding error to over a million dollars a year depending entirely on two rates that almost nobody has measured at their own site. That is the honest state of this problem. Anyone who tells you the number without asking about your p and your m is guessing.
So measure them. You can approximate p in an afternoon by reconciling clock-in timestamps against the first independent activity signal each worker generates: first badge swipe at an interior door, first scanner login, first till open, first vehicle key draw. The gap distribution will tell you more about your building than any industry survey, and it costs one analyst one day.
The second cost bucket nobody counts
Phantom hours are the visible loss. The invisible one is that unprovable hours are expensive even when they are completely genuine.
Under the Fair Labor Standards Act, the employer carries the recordkeeping obligation (US Department of Labor, Fact Sheet 21). When an employer's records are found inadequate in a wage dispute, courts have long applied the burden-shifting framework from Anderson v. Mt. Clemens Pottery Co., 328 U.S. 680 (1946): an employee who shows they performed uncompensated work may carry their burden by producing sufficient evidence to support a just and reasonable inference of the amount, at which point the burden shifts to the employer to negate it. Weak timekeeping does not merely fail to catch fraud. It weakens your position in every hours dispute you will ever have, including the ones where you are entirely in the right.
Government contractors feel this most sharply. Defence contract timekeeping is audited on the premise that the person recording the time is the person who worked it, and certified payroll under prevailing wage rules asks you to attest to hours you can only evidence with the same credential-based records that a colleague can trigger from the next terminal along. Contractors do not lose money on buddy punching so much as on the cost of proving the absence of it.
Why does every time clock fail in the same way?
Run the list. Each technology has a different defeat, and the defeats are all instances of one structural fact.
PIN and badge
A PIN proves knowledge of four digits. A badge proves possession of a plastic rectangle. Both transfer perfectly, instantly, and without any residue. This is not a flaw in the implementation, it is the specification working as designed: the clock was built to identify an employee number.
GPS-fenced mobile punch
A location-fenced punch from a phone proves that a phone reported coordinates inside a polygon. It does not prove the phone's owner was holding it, and location can be simulated on both major mobile platforms with tooling that requires no particular expertise. It also introduces a genuine privacy problem, because you have now built a system whose natural extension is knowing where your staff are at other times, and everyone in the building understands that immediately.
Photo on punch
This one is interesting because it works, and it does not scale. A photo captured at punch time is real evidence, right up to the moment you ask who is going to look at it. An eight hundred person site generates around 3,200 punch photos a week. Nobody reviews 3,200 photos. In practice the photos are stored, never examined, and consulted only after a dispute has already cost more than the control would have saved. It is evidence with no reader.
Fingerprint and hand geometry clocks
These do bind a punch to a body, and they are the only widely deployed control that actually does. They are also the reason a large number of employers have spent the last decade in litigation, which we should treat seriously rather than as a footnote.
The structural fact
Every one of these systems answers the question "which employee record should I attribute this event to". None of them answers "was a specific human present and did they intend to start their shift". Those are different questions, and the industry has spent a century building progressively more sophisticated answers to the first one while the second remains unasked. It is the same failure this blog has traced through activity monitoring for knowledge workers, through electronic visit verification in home care, and through gig platform account rental. Same shape, different building.
Is a fingerprint time clock legal, and what does it actually cost?
This deserves more than a warning label, because biometric clocks are the incumbent answer to buddy punching and they carry a specific, documented, expensive legal exposure that most operations directors have never had explained to them properly.
The Illinois Biometric Information Privacy Act (740 ILCS 14), enacted in 2008, regulates the collection of biometric identifiers including fingerprints, hand geometry, and face geometry. It requires written notice of the collection and its purpose, a written release from the subject, and a published retention and destruction schedule. What makes it different from most privacy statutes is the enforcement design: it provides a private right of action with liquidated statutory damages of 1,000 dollars per negligent violation and 5,000 dollars per intentional or reckless violation.
Two decisions turned that design into a live commercial risk. In Rosenbach v. Six Flags Entertainment Corp. (2019 IL 123186), the Illinois Supreme Court held that a person need not plead an injury beyond the statutory violation itself to be aggrieved and bring suit. In Cothron v. White Castle System, Inc. (2023 IL 128004), the same court held that a claim accrues with each scan or transmission rather than only the first. Cothron arose from a fingerprint timekeeping system, which is worth sitting with: the leading case defining the outer edge of biometric privacy liability in the United States is a time clock case. White Castle argued that per-scan accrual exposed it to damages running into the billions, a figure the court discussed in the context of the legislature's ability to address the consequences.
The legislature did address it. An amendment enacted in August 2024 limited recovery to a single claim per person per method of collection, which substantially reduced the tail risk that Cothron created. That is a genuine improvement in the employer's position and any fair account has to say so. It did not remove the private right of action, the consent requirements, or the statutory damages. It made the exposure finite rather than existential.
Illinois is not alone in regulating this, though it remains the only one with a broad private right of action of this kind. Texas addresses biometric identifiers under its Capture or Use of Biometric Identifier Act, enforced by the Attorney General, and Washington enacted its own biometric statute in 2017. Several states have considered BIPA-style bills with private enforcement in recent sessions.
The practical consequence for a buying decision is this. A fingerprint clock creates a permanent asset in your infrastructure: a database of body-part templates belonging to people who will eventually leave, whose consent must be documented and whose retention schedule must be honoured, in a category of data with dedicated statutes and a plaintiff bar that specialises in it. You are taking on a durable liability to solve a problem whose size you have not measured. That may still be the right call. It should at least be a conscious one.
| Method | What it proves | How it is defeated | Biometric statute exposure | Worker acceptance |
|---|---|---|---|---|
| PIN | Knowledge of a code | Tell someone the code | None | High |
| Badge | Possession of a card | Hand over the card | None | High |
| GPS mobile punch | A phone was in a polygon | Location simulation, lend the phone | None | Low, reads as tracking |
| Photo on punch | A face was at the terminal | Nobody reviews the photos | Moderate if stored and matched | Medium |
| Fingerprint or hand geometry | A body was at the terminal | Rarely defeated at scale | High, direct statutory target | Low, common grievance subject |
| Signed presence receipt | An enrolled human authorised this punch | Enrollment fraud, handing over an unlocked device | Low, no template retained | Medium to high when receipts are worker-held |
How do you prove presence without storing biometrics?
Here is the move, and it is smaller than people expect.
Separate two things that every biometric clock fuses: the comparison and the storage. A fingerprint clock compares a live finger to a stored template, and the storage is what creates the liability. But the comparison does not have to happen in your infrastructure, and the template does not have to exist in it.
Think of it like a door key. A biometric clock is a system where the building keeps a mould of every employee's key, compares your key to the mould, and accepts you if they match. The moulds are the problem. They can be stolen, they must be destroyed on a schedule, they are regulated, and they exist forever in backups. The alternative is that each worker keeps their own key, the building keeps only the shape of the lock it opens, and possession of a working key is the proof. Nobody needs a mould.
Concretely: the worker enrols once on their own phone. A face match runs entirely on the device to unlock a private key held in that device's secure hardware. What leaves the phone is a signature, not an image, not a template, not a measurement. The employer's system stores a public key and a stream of signed events. There is no biometric vault because there is no biometric anywhere except momentarily in the worker's own hand.
A punch becomes a small signed statement:
{
"type": "presence.punch",
"event": "shift_start",
"worker_key": "mk_7f3a91c4e8b25d10",
"employer": "org_44921",
"site": "dc_04_north_gate",
"schedule_ref": "sched_2026w39_A",
"occurred_at": "2026-09-24T06:57:14Z",
"continuity": "glance",
"location_class": "trusted_site"
}
The worker's device signs the hash of that object. The result is a receipt: the payload, the signature, and the key identifier. Verification is a pure function with no callback to anyone:
from nacl.signing import VerifyKey
def verify_punch(receipt, published_key_bytes):
vk = VerifyKey(published_key_bytes)
vk.verify(receipt.canonical_payload, receipt.signature) # raises on failure
assert receipt.payload["employer"] == EXPECTED_ORG
assert receipt.payload["site"] in AUTHORISED_SITES
assert within_shift_window(receipt.payload["occurred_at"],
receipt.payload["schedule_ref"])
return receipt.payload["worker_key"]
Note what the verifier does not do. It does not phone a server, it does not look up a face, and it does not consult a score of any kind. It checks a signature against a published key and checks that the claims are consistent with the schedule. That is why it works in a warehouse with poor signal, and it is the same offline verification property discussed in verifying a credential without contacting the issuer.
Three modes, because 06:57 is not the time for a ceremony
A single interaction design will not survive a real shift change. Three tiers do:
- Trusted place. Known device, known site, inside the scheduled window: a single tap. This is the overwhelming majority of punches and it must be under two seconds or the queue eats you.
- Glance. New device, unusual site, outside the window, or a flagged pattern: a fresh on-device face match with a liveness challenge before the key will sign. A couple of seconds more, applied to a small minority of punches.
- Handoff. Shared kiosk or no personal device in hand: the terminal displays a rotating pattern, the worker's phone claims it, and the punch is signed on the phone. The kiosk never holds anything sensitive.
The design principle is that the friction is proportional to the doubt, and the doubt is usually zero.
Does this survive an actual shift floor?
Most workforce technology is designed in an office and dies in a building. The constraints are not edge cases, they are Tuesday.
Gloves
Cold storage, food handling, and much of manufacturing mean gloved hands for the entire shift. This is where fingerprint clocks quietly fail and where operations teams end up with a glove-removal step they do not advertise. A face match plus a tap through a capacitive-friendly interaction is materially better here, and where gloves are heavy the trusted-place single tap can be triggered from a lanyard-mounted device without fine motor control.
No personal phone on the floor
Cleanrooms, secure facilities, some clinical areas, and plenty of sites with a no-phones policy for good safety reasons. Be honest about this one: if the worker cannot carry a device, a worker-held key on that device cannot sign at the moment of the punch. The workable pattern is a supervised enrollment station and a site-issued device held at the gate, which recovers most of the benefit and loses the portability. It is a genuine constraint, not a solved problem.
Shared and low-end devices
A workforce does not all carry recent hardware. The handoff mode covers shared kiosks. For workers without a suitable personal device, a site-issued device bound to that worker for the shift is the fallback, and it should be treated as a first-class path rather than an exception, because designing for the median phone excludes the people most likely to be paid hourly.
No connectivity
Loading docks, basements, remote sites. Because verification is a signature check against a published key, punches queue locally and verify later without any loss of evidential value. This is the practical advantage of offline verification over any system that must call a service at the moment of the punch.
Forty people at 06:57
The single hardest requirement in the entire problem. If the median punch is not roughly as fast as typing a PIN, the system will be worked around within a fortnight, and the workaround will be worse than what you replaced. Budget for the trusted-place tap to be the overwhelming default and treat every glance-mode punch as a cost you must justify.
Why would a union agree to this?
Because the receipt is the worker's, and that changes what the technology is for.
Under a biometric clock, the employer holds a template of the worker's body and a record the employer authored. In a dispute over hours, the worker's evidence is their memory against the employer's database. Recall the burden-shifting framework from Mt. Clemens: it exists precisely because employees historically had no records of their own.
A signed presence receipt inverts that. The worker holds a copy in their own wallet, signed by their own key, that the employer cannot silently edit or delete. If payroll drops a shift, the worker has an independently verifiable artifact showing they were there and signed for it. That is not a concession offered to make surveillance palatable. It is a straightforwardly better evidential position than hourly workers have ever had, and it is the argument that turns a works council conversation from adversarial into negotiable.
It also gives a plain answer to the question every representative will ask first, which is what the employer learns that they did not know before. The answer is: that a punch happened, signed by an enrolled worker, at a site, at a time. Not where anyone was between punches. Not how fast they worked. Not what their phone was doing. The receipt is deliberately small, and small is the security property.
Honest limits
This control has four failure modes and pretending otherwise would be exactly the vendor behaviour criticised earlier in this piece.
- Enrollment is the trust bottleneck. If the person who enrolls is not the person who was hired, everything downstream is a beautifully signed lie. Enrollment must be supervised and bound to the same identity thread as onboarding, which is the problem covered in identity continuity from hire to offboarding.
- A handed-over unlocked device still signs. Liveness at glance-mode raises the cost, because the colleague must now be present with the worker's unlocked phone and pass a face challenge as them, which is a materially harder favour to ask than reading out four digits. It is not impossible. It is expensive enough to change the norm, which is the realistic goal.
- It says nothing about work. A signed punch proves presence and intent to start, not effort, output, or whether anyone did anything for the next eight hours. If your actual problem is productivity, this is the wrong instrument and no identity technology is the right one.
- Location class is device-reported. A stronger geofence attestation, cryptographically bound to a site rather than asserted by the device, is not something we ship today. Where site binding genuinely matters, pair the receipt with an independent site signal you already own, such as a door controller event.
What to do this week
- Measure your p and your m. Reconcile clock-in timestamps against the first independent activity signal per worker for two pay periods. One analyst, one day, and you will never need an industry statistic again.
- Price your own loss with the four-term formula above, and put the range in front of whoever approves the budget rather than a single number.
- Inventory your biometric holdings. If you operate fingerprint or hand geometry clocks anywhere, confirm you have written consents, a published retention schedule, and a destruction process that actually runs. In Illinois in particular, treat this as an urgent question rather than an administrative one.
- Count your unreviewed photos. If you run photo-on-punch, find out how many images were looked at last quarter. The answer is usually zero and it usefully ends the debate about whether it is a control.
- Time the queue. Measure your current median punch duration. That number is your latency budget for anything you replace it with, and it is non-negotiable.
- Ask about the certified payroll case. If you have prevailing wage or defence timekeeping obligations, ask your compliance lead what evidence they would produce today for a challenged hour, and how long it would take.
- Talk to the representatives before selecting, not after. Lead with worker-held receipts and the wage dispute argument. The conversation is entirely different when the workforce keeps a copy.
- Try the flow. The phantom shift demo runs the punch and receipt path end to end, and the developer docs cover the signing and verification calls.
Frequently asked questions
How do you stop buddy punching without a biometric time clock? Require each punch to be signed on the worker's own enrolled device, with an on-device face match unlocking the signing key. Nothing biometric leaves the phone and no template is stored by the employer, so there is no database to regulate or breach. A colleague cannot produce the signature because they do not have the device or the face that unlocks it.
Is a fingerprint time clock legal in Illinois? It is not prohibited, but it falls under the Biometric Information Privacy Act (740 ILCS 14), which requires written notice, a written release, and a published retention schedule, and provides a private right of action with statutory damages. A 2024 amendment limited recovery to a single claim per person per collection method. Employers operating such clocks should confirm their consent and retention practices with counsel.
What does buddy punching cost per employee? There is no credible national figure. The most repeated estimate circulates as both 373 million and 373 billion dollars with the same attribution, which tells you it has not been traced. Calculate your own: workers, multiplied by shifts, multiplied by the fraction of shifts with phantom time, multiplied by phantom minutes over sixty, multiplied by your loaded hourly rate.
Can GPS time clocks be spoofed? Yes. Location can be simulated on both major mobile platforms without specialist skill, and even an unspoofed location only proves a phone was in an area, not that its owner was holding it. Location fencing is a useful supporting signal and a poor primary control.
Does a signed punch prove the worker actually did the work? No. It proves an enrolled human authorised a shift start at a time and place. Effort, output, and whether the shift was worked are separate questions that no identity control answers, and any vendor claiming otherwise is overselling.
What happens if a worker does not have a smartphone? A site-issued device bound to that worker for the shift, or a supervised kiosk handoff, should be treated as a normal path rather than an exception. Designing only for staff with recent personal hardware excludes exactly the people most likely to be paid hourly.
Can the worker keep their own attendance records? Yes, and this is the main reason worker representatives support the design. The receipt sits in the worker's wallet, signed by their own key, and the employer cannot alter or delete their copy. In a disputed hours claim the worker holds independently verifiable evidence rather than only a recollection.
Sources
- Illinois Biometric Information Privacy Act, 740 ILCS 14. Illinois General Assembly
- Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, and Cothron v. White Castle System, Inc., 2023 IL 128004. Illinois Courts opinion archive
- Texas Capture or Use of Biometric Identifier Act, Business and Commerce Code Chapter 503. Texas Statutes
- Anderson v. Mt. Clemens Pottery Co., 328 U.S. 680 (1946). Justia
- US Department of Labor, Fact Sheet 21: Recordkeeping Requirements under the Fair Labor Standards Act. DOL Wage and Hour Division
- Defense Contract Audit Agency, timekeeping and labour audit guidance. DCAA
- W3C Web Authentication (WebAuthn) Level 3 specification. W3C
A time clock that identifies a credential will always accept a favour. A punch the worker signs is the first record in a century that both sides can rely on.