Employer Recordkeeping Requirements
February 25, 2022
Employer Recordkeeping Requirements

Federal laws, such as the Federal Insurance Contribution Act, the Fair Labor Standards Act (FLSA), the Equal Pay Act and the Civil Rights Act, impose recordkeeping duties on employers. Recordkeeping duties include creating, updating and preserving information.

 

State law also imposes several recordkeeping requirements on employers. These laws operate in addition to, or in conjunction with, federal requirements. This Employment Law Summary provides an overview of various New York recordkeeping requirements that generally apply to all employers in the state. Additional requirements may apply for employers in certain industries.

 

APPRENTICESHIPS

Employers that sponsor apprenticeship programs must make and keep all records necessary to prove that their apprenticeship programs comply with all federal and state laws. These records must also be used to periodically evaluate each apprentice’s progress.

 

An apprenticeship program sponsor’s records must include:

 

•   The apprentice-to-journey-worker ratio;

•   A certification of compliance with applicable federal, state and local health and safety standards;

•   A description of the probationary apprenticeship period;

•   Apprenticeship program modification requests submitted to the New York Department of Labor (NYDOL), if applicable; and

•   Information on program processes, such as procedures to authorize wage increases, transferring apprentices to other programs or notifying apprentices of adverse actions.

 

For each apprentice, the sponsor’s records must also show:

 

•   The training provided (must be at least 144 hours per year provided by qualified training personnel);

•   The apprentice’s age (must be at least 16 years of age);

•   The skills apprentices are expected to and have actually learned (must be verified and signed at least monthly by the apprentice’s supervisor);

•   The amount of time required in each work process or rotation;

•   The placement and registration with the program;

•   Evidence of program completion (if applicable); and

•   A signed copy of the Apprenticeship Agreement (which must also be filed with the NYDOL).


 

CHILD LABOR

New York allows employers to hire minors between 16 and 17 years old to work in occupations for which they have completed an approved work training program. For these minors, employers must maintain records showing:

 

•   The name, address and age of the minor;

•   The date the minor entered and the minor’s attendance record for the approved work training program;

•   The number of hours the minor participated in the work training program;

•   The number of hours the minor received specific training in safety; and

•   The occupation and work processes for which a certificate of completion was issued.

 

In addition, employers must maintain accurate records of each minor’s employment-related injuries and illnesses, unless the injuries were minor and required only first aid treatment.

 

Additional recordkeeping requirements apply for employers that work with child performers.

 

UNEMPLOYMENT COMPENSATION

Employers must keep a true and accurate record of each employee’s:

 

•   Name and Social Security number;

•   The amount of wages paid per payroll period;

•   The beginning and ending dates of each payroll period; and

•   The total amount of employee wages subject to unemployment compensation contributions under state law.

 

These records must be maintained for at least three years.

 

WAGE AND HOUR

New York employers must create and maintain contemporaneous, true and accurate payroll records for

at least six years. For each employee, these records must show:

 

•   The number of hours worked each week;

•   The regular and overtime wage rates and how they are calculated (hour, salary, piece or other, unless exempt from overtime compensation);

•   The number of regular and overtime hours worked (unless exempt from overtime compensation);

•   The amount of gross wages paid;

•   An itemized list of deductions;

•   An itemized list of allowances claimed as part of the employee’s wage (if any);

•   The amount of net wages paid; and

•   The employee’s student classification, if applicable.


 

Personnel records for student-employees must include a statement from the employee’s school indicating whether the student-employee is:

 

•   Participating in an instruction program that will lead to a degree, diploma or certificate (or is completing residence requirements for a degree); and

•   Required to obtain supervised and directed vocational experience to fulfill curriculum requirements.

 

For employees who are paid a piece rate, payroll records must include the applicable piece rate (or rates) of pay and the number of pieces completed at each piece rate.

 

Employers are subject to misdemeanor charges if they fail to keep or falsify payroll records or hinder the NYDOL’s access to these records during an investigation. Potential penalties for a first offense include a fine of between $500 and $5,000 or imprisonment for up to one year. For second or subsequent offenses within a six-year period from the first offense, employers may face felony charges punishable by a fine of between $500 and $20,000, imprisonment for up to 366 days or both. Each date an employer fails to comply with these recordkeeping requirements is considered a separate offense.

 

Additional recordkeeping requirements may apply for:

 

•   The farming industry;

•   Domestic workers and household employees;

•   The hospitality industry;

•   Employers that allow their employees to participate in tip pooling; and

•   The building service industry.

 

WORKERS' COMPENSATION

Employers subject to the state’s workers’ compensation laws must keep the following true and accurate records.

 

IDENTITY, ORGANIZATIONAL AND OCCUPATIONAL RECORDS

•   Federal Employer Identification Number;

•   Business name (including certificates of assumed business names);

•   Business form (such as corporation, limited liability company or partnership);

•   Articles of incorporation or organization (including amendments to the articles, occupational license, trade licenses or certifications); and

•   A current list of the officers, partners or principals of the business.

 

EMPLOYMENT RECORDS

•   The number of employees;

•   Each employee’s name, Social Security number or other identifying number;

•   Each day, month, year or pay period worked by each employee;

•   Each employee’s classification;

•   A description of each employee’s general duties (must provide enough information for a proper employee classification);

•   The amount of wages paid or owed to each employee;

•   The method of payment used to calculate each employee’s wages;

•   Wage payment records;

•   The value of credits and allowanced claimed for each employee’s wages (tips, employer-provided meals, lodging or similar benefits);

•   Annual wage or earnings statements for each employee (including IRS Forms 1099 and W-2);

•   Any written contracts or agreements that describe the terms of employment;

•   Documentation of all and any employee accidents and injuries;

•   Tax records (federal, state and the New York State Department of Labor filings);

•   Financial account records (general ledgers and monthly, quarterly or annual statements of all opened or closed business accounts); and

•   Insurance coverage and eligibility records.

 

PENALTIES

Employers that violate these recordkeeping requirements may face criminal and administrative penalties. Criminal penalties include misdemeanor charges and fines of between $5,000 and $10,000 for failing to keep or falsifying these records. Second and subsequent violations can lead to class E felony charges and fines of between $10,000 and $25,000. Administrative penalties include a $1,000 fine for every ten-day period of non-compliance or a fine equal to twice the cost of compensation for the employer’s payroll for the period when the violation takes place.

 

In general, employers must maintain these records for a period of at least four calendar years.

 

EMPLOYEE INJURIES

Employers must record every injury and illness employees suffer in the course of employment on a form prescribed by the New York State Workers’ Compensation Board. This injury record must be kept for at least 18 years. The Workers’ Compensation Board does not require employers to file an injury or illness report, unless the injury or illness causes the employee to:

 

•   Miss a day of work beyond the shift or day when the injury or illness took place; or

•   Receive medical treatment beyond ordinary first aid or more than two treatments by a person rendering first aid.

 

Employers that refuse or neglect to keep employee injury and illness records may be charged with a misdemeanor, punishable by a fine of up to $1,000 and an additional administrative fine (imposed by the Workers’ Compensation Board) of up to $2,000.

Sign up for our newsletter.

April 1, 2025
April Fools' Day is often the perfect opportunity for some lighthearted fun at the office. Whether it's a harmless prank, a funny email, or a playful desk setup, these moments of levity can help break up the monotony of the workday and bring smiles to your team. However, as many HR professionals know, it’s essential to strike a balance between fun and professionalism. While the intention behind pranks is typically harmless, they can sometimes cross boundaries and lead to uncomfortable situations, or worse, legal risks. Recently, an example came to light where one employee thought it would be funny to place a suggestive image on a coworker's desk. The issue arose when another employee saw the image and was offended, leading to a formal complaint. This scenario highlights the importance of knowing where to draw the line between lighthearted fun and inappropriate behavior. A Fine Line: When Fun Turns into Harassment Even if a prank isn't directly targeted at the offended person, it can still create a hostile work environment, especially if it makes someone uncomfortable. As an employer, it's crucial to ensure that your workplace remains respectful and free from harassment. If a prank results in a complaint, it's essential to follow your company's policies to investigate and address the situation. Proper documentation of your investigation and the actions taken is vital to demonstrate that you've fulfilled your obligations as an employer and to protect the organization in case of any future disputes. Setting Clear Expectations To avoid similar issues in the future, it's a good idea to review and clarify your company's stance on pranks and personal conduct in the workplace. Setting expectations starts with having a clear written policy that outlines what is and isn’t acceptable behavior, especially regarding pranks. Consider creating a set of guidelines that all employees can refer to, and be sure these expectations are communicated effectively to everyone. Here are a few tips to guide you: Establish a Formal Policy: Clearly define the boundaries of acceptable humor in your workplace. The policy should cover both pranks and jokes, specifying that while fun is encouraged, it should not come at the expense of respect, inclusion, or professionalism. Communicate Expectations Clearly: Include these guidelines in your employee handbooks or conduct policies, and ensure they’re reviewed during onboarding. Hold periodic team meetings to remind everyone about the importance of maintaining a respectful environment and reinforcing your stance on pranks. Set the Tone from Leadership: Managers and leaders should set an example when it comes to humor in the workplace. They should demonstrate the type of jokes or pranks that are acceptable and ensure their actions align with company policy. Employees are more likely to follow suit when they see their leaders taking these matters seriously. Encourage Open Communication: Foster a culture where employees feel comfortable speaking up if they feel a joke or prank crosses the line. Providing a safe outlet to discuss concerns without fear of retribution will help create an open, transparent environment where everyone feels heard. Categories of Pranks and Jokes That Cross the Line While there’s no one-size-fits-all approach, there are certain categories of pranks and jokes that should generally be off limits in the workplace . These pranks have the potential to cause harm, create discomfort, or violate company policies. By categorizing these behaviors, you can help employees better understand where to draw the line. Sexual or Gender-Based Humor : Avoid pranks with suggestive content, gestures, or language that can create a hostile work environment or be considered harassment. Discriminatory Jokes : Refrain from jokes targeting someone's race, religion, gender, sexual orientation, or other protected characteristics, as they can be harmful and illegal.  Invasive Pranks : Don’t tamper with personal belongings or invade others' personal space, as this undermines comfort and respect. Work Disruptions : Pranks that interfere with productivity or damage equipment should be avoided, as they can hurt overall efficiency. Aggressive or Harmful Pranks : Any prank that causes physical harm or emotional distress, including pranks involving physical touch or intimidation, is off-limits. Creating a Culture of Respect and Fun The key to managing pranks and other fun activities is to cultivate a workplace culture where employees feel comfortable, respected, and empowered. Rather than banning all pranks, focus on fostering a professional environment where employees understand the line between harmless fun and actions that could potentially harm or offend others. Encourage employees to engage in team-building activities and moments of levity that unite them in a positive and inclusive way, without crossing into territory that could lead to complaints or workplace tensions. As April Fools' Day passes, it’s important to remember that while pranks can provide a bit of comic relief, they should never come at the expense of respect or professionalism. By setting clear boundaries, encouraging open communication, and ensuring all employees understand your policies, you can create a workplace where everyone feels comfortable—whether they're laughing at a harmless joke or focusing on their next big project. Have fun in the workplace—but always ensure that a good laugh never comes at the expense of respect or professionalism!
March 24, 2025
The future of work is changing fast, and HR leaders are taking notice. More than half of companies are planning to switch their HCM platform this year—but not just for any solution. They’re looking for intelligent, scalable, and AI-driven technology that doesn’t just process payroll but actively enhances business operations. The days of rigid, outdated systems are over. Now, businesses need platforms that adapt, automate, and evolve alongside them. At Simco, we’re passionate about delivering the most advanced, transformative solutions to our clients. That’s why we’ve partnered with isolved, a recognized leader in the HCM space, to provide our clients with a powerful, AI-enabled platform that makes workforce management effortless. With a focus on automation, predictive analytics, and employee experience, isolved is changing the game for small and mid-sized businesses—and we’re here to help you make the most of it. Why isolved Stands Out in the HCM Market For the second consecutive year, Nucleus Research has named isolved a leader in its HCM Value Matrix for Small and Medium-Sized Businesses (SMBs). The firm’s analysis highlights isolved’s enterprise-grade functionality, designed specifically for SMBs looking to streamline operations, enhance compliance, and leverage AI to drive efficiency. isolved’s adaptability ensures it evolves alongside customer needs. Whether an organization’s HR function matures or its priorities shift, isolved is uniquely positioned to support its success through continuous innovation. In 2024, the company launched 480+ product enhancements directly driven by direct customer feedback. Nucleus Research’s report also highlights several key updates, including: isolved's Candidate Match Tool , an AI-powered feature that evaluates and ranks candidates, streamlining the hiring process. Enhanced Talent Acquisition Services , including recruitment process outsourcing (RPO), job placement assistance, and comprehensive hiring solutions for quick-service restaurants (QSRs). A Broadened Content Library, now with over 95,000 courses designed for employee training, compliance, and professional development. A Next-Gen Time Clock , featuring advanced facial recognition and remote access for secure and accurate time tracking. The Power of Partnership: Simco + isolved While technology is the foundation, the real value comes from how it’s applied. At Simco, we don’t just provide software—we offer a full-service HCM and advisory solution, ensuring that all aspects of workforce management integrate seamlessly. Our clients benefit from: A Dedicated Client Success Manager – Your go-to resource who oversees your relationship with Simco, ensuring that every service—HCM, HR advisory, benefits, insurance, and retirement—works together without gaps. A Fully Integrated HCM & Advisory Solution – No need to juggle multiple vendors for payroll, HR advisory, employee benefits, commercial insurance, and 401(k)/retirement plans. Simco is your one-stop shop for all workforce solutions. Strategic Guidance & Ongoing Optimization – We help businesses maximize their investment in HCM technology while aligning it with compliance, employee engagement, and long-term growth goals. As businesses evolve, so do their workforce management needs. By combining isolved’s leading-edge technology with Simco’s hands-on service and industry expertise, we help businesses stay ahead of change, improve efficiency, and create better employee experiences. Ready to explore the future of HCM? Contact us today to learn more about how we can transform your workforce operations!
March 3, 2025
Cybercriminals continue to evolve their tactics, making phishing attacks more sophisticated and harder to detect. Every day, countless phishing emails reach inboxes, often with the intent to steal sensitive information or spread malware. Unfortunately, many of these attacks succeed in just a matter of seconds— the median time for users to fall for phishing emails is less than 60 seconds according to the 2024 Verizon Data Breach Investigations Report . With stolen credentials being one of the most popular methods of attack, businesses face increasing risks as these types of cyber threats become more complex and dangerous. How Phishing and Spoofed Domains Work Phishing attacks aim to trick employees into revealing sensitive information, often through: Fraudulent Email Links – These emails appear to be from trusted sources but contain malicious links that install malware or steal login credentials. Look-Alike Domains – Hackers create fake websites that resemble real business portals, altering a single character in the domain (e.g., “micr0soft.com” instead of “microsoft.com”). Credential Theft – Once hackers obtain login credentials, they sell them on the dark web, leading to widespread data breaches. Red Flags: How to Identify a Phishing Email Unusual Sender Addresses – Cybercriminals often spoof email addresses to look like trusted sources. Carefully inspect the sender's domain name for typos, extra characters, or strange formatting. A genuine email from "paypal.com" could be faked as "paypall.com" or "paypal-support.com." Urgent or Threatening Language – Many phishing emails attempt to create a sense of urgency, claiming that an account will be suspended, a payment has failed, or legal action is imminent. If an email pressures you into immediate action, be suspicious. Unexpected Attachments or Links – Hover over hyperlinks before clicking to see the actual URL destination. If the web address looks unfamiliar or mismatched with the sender's identity, do not click. Similarly, attachments that appear out of context—especially ZIP files, PDFs, or Word documents—could contain malware. Requests for Sensitive Information – Legitimate organizations will never ask for passwords, Social Security numbers, or banking details via email. If an email requests confidential information, verify with the company directly using a trusted phone number. Generic Greetings or Poor Grammar – Emails that start with “Dear Customer” instead of your name, or those containing awkward phrasing and misspellings, often indicate phishing attempts. Many cybercriminals operate internationally and use machine translations, leading to unnatural wording. Best Practices to Protect Your Business Train Employees Regularly – Frequent security awareness training helps employees recognize phishing attempts. Past studies by Proofpoint show that companies with ongoing cybersecurity training reduce phishing-related breaches by up to 60%. Implement simulated phishing tests to reinforce learning. Enable Multi-Factor Authentication (MFA) – MFA significantly decreases the chances of an account being compromised, even if login credentials are stolen. Microsoft reports that MFA can block over 99% of automated cyberattacks . Ensure all employees activate MFA for business accounts. Verify Requests Independently – If an email asks for sensitive actions (e.g., wire transfers, login changes, or software downloads), confirm the request through a known and trusted contact method. Never use the phone number or link provided in the email —instead, visit the company's official website or call using a verified number. Monitor and Filter Emails – Implement robust email security tools that automatically flag suspicious messages. Advanced filtering systems, like those offered by Barracuda Networks, can block over 90% of phishing emails before they reach inboxes. Encourage a Report-First Culture – Employees should feel empowered to report suspicious emails even if they are unsure. IT teams can analyze these reports to strengthen cybersecurity measures. Early detection prevents widespread damage. Use a Password Manager – Employees often reuse passwords across multiple accounts, increasing security risks. Encourage the use of password managers like 1Password or LastPass to generate and store complex passwords securely. New Tactic: The Rise of QR Code Phishing ("Quishing") QR code phishing, or "quishing," is a new phishing tactic gaining momentum as attackers exploit the widespread use of QR codes. Unlike traditional phishing, which relies on malicious email links, quishing uses QR codes to redirect users to fake websites designed to steal login credentials. Several factors contribute to quishing's success: Ubiquity : QR codes are now commonly used for payments, tickets, and documents, reducing suspicion when they appear in emails. Minimal Text : Unlike traditional phishing emails, quishing messages often contain little text, making them harder for security systems to flag. Mobile Vulnerability : QR codes are scanned on personal devices, which typically lack the protection of corporate systems. According to Abnormal Security , 90% of quishing attacks involve credential phishing , where users are tricked into entering sensitive data. Another common tactic is using fraudulent MFA alerts, which account for 27% of attacks , while 21% involve fake document-signing requests . Final Thoughts At the end of the day, protecting your company from phishing and cyber threats requires more than just technology—it’s about the people behind it. By fostering a culture of awareness and encouraging open communication, you empower your employees to be the first line of defense. Together, with vigilance and the right tools in place, you can ensure the safety of your sensitive data and build a more secure future for your business.

Have a question? Get in touch.

Share by: