A supervisor notices the same three names hitting a suspiciously exact 7:00 a.m. every single day, on a site with 40 hourly workers and two shift leads who cannot watch every gate at once.
Nobody has caught anyone in the act. The timesheets just look a little too clean.
That instinct is usually right, and it has a name. Buddy punching is when an employee clocks in or out for a coworker who isn't actually at work, most often to hide a late arrival, an early exit, or a full missed shift.
It survives at most companies not because nobody is watching, but because the tools meant to stop it, shared PIN codes, swipe cards, even a photo snapped at the time clock, do not actually confirm that the person standing at the clock is the person the system thinks it is.
That is the gap this article covers: what buddy punching actually costs, how to spot it in a normal week, and why identity verification at the point of clock-in, not a photo reviewed after the fact, is what closes it for good.
TL;DR
- Buddy punching is when one employee clocks in or out for a coworker who isn't actually there, usually to cover lateness or an early exit.
- It typically costs employers around $1,560 per employee per year, and most do not catch it until they audit for it.
- Shared PINs and swipe cards offer no identity check at all.
- A photo on clock-in only creates a picture to review later. It does not verify anyone in real time.
- GPS tracking proves a phone was on-site. It does not prove the right person was holding it.
- The fix that actually closes the gap is identity verification at the moment of the clock-in, not after it.
- Truein is an AI-powered time and attendance platform for hourly and multi-site workforces that works as a face recognition time clock on any Android or iOS device, verifying identity at clock-in with face recognition paired with GPS, with no dedicated hardware required.
Buddy Punching Is One Employee Clocking In for a Coworker Who Isn't There

Buddy punching happens when a worker asks, or lets, a coworker clock them in or out while they are not at the job site. It is sometimes called buddy clocking, and it shows up in three common forms on job sites and facility crews.
- Covering a late arrival: A crew member running behind has a coworker clocks them in at the scheduled start time, so the record shows they were on time.
- Covering an early exit. A crew member leaves before the shift ends and has someone punch them out later, at the official close of shift.
- Covering a full missed shift. A crew member does not show up at all, and a coworker clocks them in and out for the entire day.
Every one of these looks small in isolation. A supervisor waves it off as somebody helping a friend out of a jam. The problem is that time theft, unpaid wages an employer covers for hours nobody actually worked, does not stay small once it becomes routine across a crew.
It is one of the more common forms of time theft, alongside padded timesheets and unauthorized overtime claims, and the same weak clock-in process usually lets more than one type through at once.
Buddy Punching vs. Time Theft: What's The Difference?
Time theft is the umbrella term for any paid hours that were not actually worked, padded timesheets, long unrecorded breaks, buddy punching.
Buddy punching is specifically the version where a second person, not the absent worker, performs the fraudulent clock-in or clock-out.
That distinction matters for policy writing: a timesheet-padding policy and a buddy punching policy need different language, because buddy punching always involves two employees, not one, and most attendance policies that only address the first person miss the second.
Buddy Punching Adds Up to Real Money, One Small Favor at a Time
The dollar figure is where most managers get surprised. Time theft is not a rounding error once you add it up across a full crew for a full year.
A 2024 study Biometrics and Beyond, published in the Human Resource and Leadership Journal, modeled what buddy punching costs U.S. businesses and arrived at an average cost of $1,560 per employee per year.
On a 100-person crew, that works out to roughly $156,000 a year in wages paid for hours nobody actually worked, and the number scales up directly with headcount from there.
The Number: Asure Software's 2025 HR Benchmark Report found that 46% of small and mid-sized businesses had caught at least one instance of time theft or falsified timesheets in the past 12 months, and fewer than half of them had a system in place to catch it before it happened. That gap, catching it after the fact instead of preventing it at the clock-in, is exactly where the cost comes from.
What This Looks Like on a Real Timesheet
Picture a five-day week for a 12-person crew. One crew member is consistently 15 minutes late but shows a clean 7:00 a.m. clock-in every day. Another leaves early for an appointment but the record shows a full shift.
Neither incident trips a payroll flag on its own. Multiplied across 50 weeks and a dozen workers doing small versions of the same thing, that is the difference between a clean payroll cycle and a quiet, compounding payroll leak nobody budgeted for.
If your timesheets already look too clean for a crew this size, that pattern alone is worth a closer look, and it connects directly to timesheet fraud more broadly, since buddy punching is one of the most common ways timesheets get falsified without anyone editing a single number.
Three Ways Employees Clock in for Each Other

Buddy punching is not one behavior. It is three different mechanisms, and each demands a slightly different way of catching it.
1. Shared Credential Punching
Shared credential punching happens when workers use a common PIN, badge, or login that anyone on the crew can enter on someone else's behalf. This is the easiest version to pull off, because the system has no way of knowing who actually typed the code.
2. Physical Badge or Card Punching
Physical badge or card punching happens when a worker hands their badge or swipe card to a coworker before leaving. The clock-in event is technically real. The person behind it is not, and a badge scan only ties the record to a credential, never to the person holding it.
3. Remote or Shared-Device Punching
Remote or shared-device punching happens on crews using a mobile app or a shared tablet kiosk, where one worker enters login details for another who is not physically present.
This is exactly why any face-matching software worth using has to catch not just whether a face was shown to the camera, but whether that face belongs to the account being clocked-in.
Face matching itself blocks an unauthorized clock-in on the spot when the face does not match the enrolled worker. A separate backend layer is what flags subtler spoofing patterns, like a static photo held up to a camera, and that backend review can happen after the clock-in depending on how the account is configured.
Those are two different safeguards doing two different jobs, not one guarantee that catches every fraudulent attempt the instant it happens.
None of the three mechanisms above are mutually exclusive on a given crew. A site running shared tablets often has shared-credential risk and remote-clock-in risk stacked on top of each other, which is why fixing one clock-in method rarely closes the gap by itself.
The Warning Signs That Show Up Before You Catch Anyone in the Act
You do not need new software to start noticing buddy punching. You need to know what to look for in the data you already have.
- Identical clock-in times, day-after-day, for the same crew member. A genuinely on-time crew varies by a minute or two. A suspiciously exact 9:00:00 a.m. every single day, for months, is a red flag.
- Frequent manual corrections tied to the same names. If a handful of workers need their timesheet "fixed" almost every week, that is worth a second look.
- Crew members marked “present” who supervisors cannot recall seeing. A name shows a full eight hours but nobody on the crew remembers that person being around.
- Multiple clock-ins from the same device within seconds of each other. This usually points to one phone or kiosk being used for more than one worker's clock-in.
- Complaints from honest workers about coworkers "never being around" despite full hours on record. Your own crew usually notices before management does.
A quick weekly scan for these patterns is the cheapest fix on this list, and it costs nothing but a manager's attention.
How many of these apply to your crew right now:
A Photo at Clock-In Does Not Stop Buddy Punching. It Just Gives You Something to Review After the Fact.

This is the part most attendance guides get wrong, and it is worth being direct about it.
Photo-on-clock-in is a common feature across time-tracking apps: the system snaps a picture of whoever taps the clock-in button, and a manager can review it later if something looks off. That is a real deterrent. But it is a documentation tool, not a verification tool.
Nobody is checking that photo in real-time. If a coworker holds up the right person's phone or logs into a shared kiosk, and the picture that gets snapped is grainy or simply never reviewed, the clock-in goes through exactly as if it were legitimate. The photo exists. The fraud still happened.
There is a real distinction between three tiers of clock-in security, and almost none of the generic advice online draws it clearly.
- Shared credential (PIN, badge, login): No identity check of any kind. Anyone who has the code can clock-in.
- Photo-on-clock-in: A picture is captured for a manager to review later, if they review it at all. Detection after the fact, not prevention at the moment.
- Automated identity verification at the clock-in: The system checks, in the moment, whether the face at the camera matches the enrolled worker, and blocks the clock-in if it does not.
Only the third tier prevents the clock-in from going through in the first place. The first two just make fraud slightly more annoying to commit, or slightly easier to spot after the money is already gone.
A photo at clock-in does not stop buddy punching. It just gives you a picture to review after the shift is already paid.
GPS Proves the Phone Was There. It Doesn't Prove Who Was Holding It.

The same logic applies to geofencing, a virtual GPS boundary drawn around a job site so that a clock-in only registers when the device is physically inside that boundary.
Geofencing stops someone from clocking in from their couch while claiming to be on-site. What it cannot do is confirm which human being is holding the phone inside that boundary.
If a worker leaves their phone with a coworker who is legitimately on-site, the GPS location checks out perfectly while the actual person the shift is being paid to is somewhere else entirely.
Ask any time tracking software whether identity is verified at the clock-in or only reviewed from a photo afterward. If the honest answer is photo-review, that software will slow buddy punching down. It will not stop it.
Location data and identity verification answer two different questions, and a software that only answers one of them leaves the other wide open.
This holds regardless of which vendor's software is running underneath it. The question to ask is not what brand the software is, it is whether identity gets checked at the moment of the clock-in or only reviewed afterward.
How to Build a Buddy Punching Policy That Actually Gets Enforced

Technology closes the mechanical gap. A written policy closes the accountability gap, and most companies either skip this step or write one so vague it does nothing.
A policy that holds up has three parts:
- First, define buddy punching in plain language, with examples, so nobody can claim they misunderstood.
- Second, state explicitly that it is treated as falsification of time records, not a minor infraction, since that framing matters if disciplinary action is ever challenged.
- Third, spell out consequences clearly: a documented warning for a first instance, up to termination for repeated or deliberate cases, and note that both the worker who was clocked in and the coworker who did the clocking can face the same consequence.
The policy only works if it gets covered during onboarding and referenced again during a real incident, instead of being filed away and forgotten. A policy nobody remembers signing is not much better than no policy at all.
Is Buddy Punching Illegal?
Buddy punching itself is not typically prosecuted as a standalone crime, but it falls under time theft and falsified recordkeeping, and the Fair Labor Standards Act requires employers to maintain accurate records of hours worked.
That puts employers in a difficult spot: even when the fault clearly sits with the employees involved, regulators still expect reasonable controls in place.
Falsified records tied to buddy punching can expose a company to back-pay disputes, wage-and-hour audits, and, in serious or repeated cases, termination for the workers involved under most attendance policies.
None of this functions as a legal guarantee. What a well-built software does is give managers a documented, consistently applied rule set designed to support compliance with recordkeeping expectations, rather than leaving it to informal judgment calls on the floor.
For companies with workers in California specifically, there is an added layer worth knowing about. Since January 2023, the employee exemption under the California Consumer Privacy Act and its follow-on, the CPRA, expired. California employees now have full rights, including notice, access, and deletion rights, over biometric data collected at work, which includes face-recognition time tracking softwares.
That does not make face recognition risky to use. It means California employers specifically need consent-first enrollment and clear notice before rolling it out, which is how a well-built software should already be operating anyway.
Beyond California, the compliance picture is a patchwork. Illinois' Biometric Information Privacy Act is the one state law that carries a private right of action, meaning individuals can sue directly over violations, which is why standalone face recognition claims deserve extra care in Illinois-specific contexts. Texas, Colorado, and Washington have their own, narrower biometric statutes covering workplace data.
If buddy punching or falsified timesheets ever surface in a formal wage dispute, they tend to travel alongside broader payroll fraud concerns, since inflated hours and manipulated records often get scrutinized together once an audit starts.
Disclaimer: This section is for general informational purposes only and does not constitute legal advice. Biometric privacy laws vary by state and change over time; the information above reflects publicly available sources as of the article's publish date and may not reflect subsequent legal developments in your jurisdiction. Before deploying biometric attendance technology, consult a licensed attorney familiar with the applicable state and local requirements.
Identity Verification at the Point of Clock-in Is What Actually Closes the Gap

Everything above points to the same conclusion: the fix that works verifies who is standing at the clock, at the moment they clock in, not a software that documents the moment for someone to review three weeks later.
Truein is an AI-powered time tracking software for hourly and multi-site workforces that verifies identity at clock-in using face recognition paired with GPS, on any Android or iOS phone or tablet, with no dedicated hardware required.
A phone or tablet the site already owns becomes the face recognition time clock, which matters for crews used to scanners or wall-mounted kiosks breaking down mid-project.
The mechanism is the tier-three protection described above. Face recognition checks the live face at the camera against the enrolled worker's profile in real-time, working even with masks, beards, or a changed hairstyle, and blocks an unmatched face from completing the clock-in on-site rather than flagging it for a manager to notice a week later.
Truein’s AI TimeGuard is a built-in anomaly detection module that continuously scans attendance data in the background for subtler spoofing patterns and unusual timing sequences, surfacing those as flagged exceptions rather than requiring anyone to comb through every timesheet by hand.
Those are two different safeguards working together, not one system that catches everything the instant it happens.
GPS geofencing sits alongside face verification rather than replacing it, so a clock-in has to be both the right person and the right place to go through clean. For crews spread across sites with patchy signals, offline capture stores the clock-in on the device and syncs automatically once connectivity returns, so a dead signal never turns into a missing day of records.
Offline clock-ins show up in the dashboard once they sync, not the instant they happen.
Truein’s mobile-based time tracking app is designed to run equally well on a worker's own phone, a shared tablet at a site entrance, or a supervisor-assisted device, and it complements the payroll and HRMS systems already in place rather than replacing them.
For crews mixing in-house staff with subcontractor agencies, Truein’s face-based contract labor attendance software gives each agency supervisor a scoped dashboard limited to their own workers, with headcount caps and document-expiry tracking built in, which matters most where subcontractor accountability is already a point of friction with clients.
This is not hypothetical for the crews already running it. Walker Engineering, an electrical contracting firm, and Hallmark Housekeeping Services, a facility-services company managing crews across multiple client sites, are among the companies using Truein today, alongside more than 500 clients across 25 countries and 500,000-plus users overall.
Truein holds a 4.8 out of 5 rating on G2 and Capterra as of this writing, a reasonable proxy for how the product holds up once teams are using it daily, not just piloting it.
Watch out for: Attendance apps marketed as mobile-first. That framing usually signals a lightweight consumer tool rather than a platform built for multi-site operations. What you actually want is dedicated-hardware-free: enterprise-grade software that happens to run on devices your sites already own, be it Android or iOS phones the crew already owns, or a shared tablet owned by the site. For sites that don’t own a tablet and are looking to set up a shared kiosk, the only exception is acquiring a basic tablet.
A Quick Look at How the Three Clock-in Methods Stack Up
If your current software falls in either of the first two rows, treat that as your actual exposure, not a solved problem.
Decision rule: If you cannot answer, in real time, whether the face at the camera matches the enrolled worker, your time tracking software is documenting buddy punching, not preventing it. The gap is not hypothetical. It is the exact mechanism buddy punching relies on.
A Quick Note for Teams in GCC and India
Buddy punching is not a U.S.-only problem, though the framing shifts once you leave American labor law behind.
In the GCC, attendance integrity connects directly to Wage Protection System compliance and accurate manpower headcount reporting, which drives adoption there more than U.S.-style privacy law ever does.
In India, the same underlying mechanism, verifying identity at the punch rather than relying on a shared credential, is usually searched under terms like biometric punching machine prevention, and it is worth being clear that this is software running on a phone or tablet, not a dedicated hardware device, with data handling governed by India's Digital Personal Data Protection Act rather than any U.S. consent statute.
Neither region maps onto the other, and neither maps onto U.S. compliance language.
Two things matter more in these regions than anywhere else. First, offline capture: large infrastructure sites, basements, and tier-2 and tier-3 locations often have patchy or zero connectivity, so time clock software that only works online leaves gaps exactly where the workforce is largest. Second, the shortlist question does not change: whatever time clock software you evaluate, ask whether it verifies identity at the punch or only records that a punch happened.
The Bottom Line
Buddy punching survives on most crews for one reason: the common fixes people reach for first, a shared badge, a photo at the clock, a GPS check, all create a record to review later.
None of them verify, in the moment, that the person clocking in is the person who is supposed to be there. That is the actual gap, and it is a fixable one.
If your attendance still runs on a system that cannot answer "was that really them, right now" with a straight yes or no, that is the specific thing worth fixing before the next payroll cycle, not after the next incident.
A walkthrough of how Truein verifies identity at the point of punch, without adding dedicated hardware to sites that do not already have it, is a reasonable next step if that question has been nagging at you.
You can schedule a demo to see the mechanism against your own site setup.
Frequently Asked Questions
1. How much does buddy punching actually cost a small business?
A 2024 ‘Biometrics and Beyond’ study published in the Human Resource and Leadership Journal worked out an assumption on how much buddy punching can cost businesses, and found that buddy punching can cost U.S. employers an average of $1,560 per employee per year. On a 50-person crew, that works out to about $78,000 a year in wages paid for hours nobody worked.
The number scales directly with headcount, so a larger crew loses more in absolute terms even at the same per-employee rate. Most owners are surprised by the total once they run the math on their own payroll, rather than assuming it is a handful of harmless minutes here and there.
2. Can I fire an employee for buddy punching?
Yes, in most cases, as long as the termination is backed by a documented policy, consistent enforcement, and clear evidence, such as timestamp records, GPS logs, or an admission during an investigation. Falsified time records are generally treated as legitimate grounds for discipline or termination, since they constitute time theft.
Both the worker who was clocked in and the coworker who did the clocking can typically face the same consequence under a well-written policy. Document the incident, follow your existing disciplinary process exactly, and apply it the same way for every employee caught in the same situation.
3. Does a photo clock-in actually stop buddy punching?
Not fully. A photo captured at the moment of clock-in creates a record a manager can review later, which does raise the effort required to cheat the system, but nobody is checking that photo in real time as the clock-in happens. If the picture is grainy or simply never reviewed, an unauthorized clock-in goes through exactly as if it were legitimate.
Photo-on-clock-in is a detection tool, not a prevention tool. If stopping the fraudulent clock-in before it registers matters to you, look for a software that checks identity live against an enrolled worker, not one that just documents whoever showed up to the camera.
4. What's the difference between GPS tracking and face verification for attendance?
GPS tracking, including geofencing, confirms that a device was physically located within a defined boundary around a job site when a clock-in occurred. It says nothing about who was holding that device. Face verification checks, in real time, whether the person at the camera matches the enrolled worker's profile, a completely different question.
The two work best together: GPS confirms the right location, face verification confirms the right person. A software that only checks one of them leaves the other wide open to buddy punching.
5. How do I know if buddy punching is happening on my team?
Look for identical clock-in times for the same worker across many days, frequent manual corrections tied to specific names, workers marked present who supervisors do not recall seeing on-site, and multiple clock-ins from the same device within seconds of each other.
Honest coworkers often notice the pattern before management does, so an anonymous way for staff to flag it is worth having. A quick weekly scan of these patterns costs nothing and is the fastest way to confirm whether it is happening before you invest in new tools to stop it.
6. What is the best time clock software to stop buddy punching??
The best time clock software to stop buddy punching is one that verifies identity at the moment of the clock-in, not just afterward. Truein is built specifically around this identity-first approach for hourly and multi-site workforces, using face recognition paired with GPS on any Android or iOS device, with no dedicated hardware required.
Whichever platform you evaluate, look for four things: real-time identity matching (not just a photo saved for later review), GPS or geofencing that confirms location alongside identity rather than instead of it, offline support if your crews work at sites without reliable connectivity, and a software that fits how your workforce actually operates, hourly or multi-site, rather than a desk-based tool retrofitted for the field. The same test applies across the board: can it answer, in real time, whether the person clocking in is who the software expects, or does it only give you something to review after the fact.
7. What is the best face recognition time clock software to stop buddy punching?
The best face recognition time clock software is one that matches the live face against the enrolled worker at the moment of the clock-in and blocks the clock-in when it does not match, rather than saving a photo for someone to review later. Truein turns any Android or iOS phone or tablet into a face recognition time clock, pairing live face verification with GPS geofencing so a clock-in has to be both the right person and the right place, with no dedicated hardware to buy or maintain. The only possible cost is acquiring a basic tablet if a site does not already have one for a kiosk setup
Many tools marketed as face recognition time clocks only capture a photo at the clock-in. That is documentation, not verification. If the vendor cannot confirm that an unmatched face gets blocked in real time, the software will slow buddy punching down, but it will not stop it.





