Excel doesn't fail at payroll processing because it's bad. It fails because it's too good at hiding errors — until the day the Tax Authority requests the corrected DMR for three months. The premise of this article is uncomfortable: most Portuguese industrial SMEs don't use Excel because it's the best tool for the job. They use it because the person who set up the file eight years ago is still there. When that person leaves — and in 2023 the average voluntary turnover in Portugal was 10.6%, with 52% of companies admitting difficulty in retaining talent (Mercer, 2023) — what remains is a file that nobody can explain to the auditor. The decision between Excel and integrated software is not a matter of budget. It's a matter of when the risk becomes unbearable.

What to confirm before comparing tools

Before opening any software proposal, carry out this internal review. If you fall short on two or more points, the decision has already been made — Excel isn't enough.

  • Exact number of active employees, including fixed-term contracts, freelancers and seconded workers.
  • Complete listing of allowances and deductions in use: allowances, overtime, justified absences, garnishments, exemptions from fixed working hours.
  • Confirmation of who signs the DMR to the Tax Authority and Social Security — and whether a designated substitute exists.
  • Version of the withholding tax table in force in the current file (updated annually by the Tax Authority).
  • Record of how many retroactive corrections were made in the last 12 months and for what reason.
  • Clarity about who accesses the payroll file and whether that access is logged — a direct obligation under the GDPR.
  • Integration with the time and attendance system: manual, by import or automatic.

Payroll processing in Portugal is not a calculation. It's a regulated process with fixed dates, mandatory formats and immediate tax consequences. The Monthly Remuneration Declaration must reach the Tax Authority by the 10th of the following month; the report to Social Security follows its own schedule. Any error generates interest, fines and, in the event of repeat offences, blocking of certificates — which in an industrial SME can paralyse a PT2030 funding application at the worst possible moment.

Excel doesn't have a compliance engine. It has formulas that someone wrote — and that nobody updates automatically when the income tax table changes in January or when a new contribution rate comes into effect. In a technical assessment we conducted at a garment company with 65 employees in the Vale do Ave, the withholding table had been out of date for 11 months. The error per employee was negligible. The accumulated tax exposure was not.

Here's the detail the manuals don't mention: the Tax Authority publishes interim ordinances throughout the year — not just the January table. A company that updates the file once a year may be out of date for weeks without knowing it. Integrated software receives these updates via the supplier; the responsibility for applying them is contractual, not personal. Always audit whether the update is automatic or manual — and who is responsible for applying it.

  • Check the date of the last income tax table update in your file.
  • Confirm whether the DMR file is generated automatically or built by hand.
  • Document who validates the file before sending and by what formal criterion.

Dimension 2 — Dependence on tacit knowledge: the risk that doesn't appear on the balance sheet

Excel doesn't have institutional memory. It has cells. When the person who filled them in leaves, the logic goes with them — and the auditor is left with a file they can't explain.

With voluntary turnover of 10.6% in Portugal (Mercer, 2023), in an industrial SME with two HR staff there is a real probability of losing, in a single year, the person who knows why column AJ has an IF(AND(...)) nested four levels deep. The replacement doesn't inherit the knowledge — they inherit the file. And the file doesn't talk.

We see this repeatedly in textile and footwear companies in the North: the payroll file is between six and twelve years old, it was built by someone who has since changed role or left, and nobody in the company can explain all the rules encapsulated in the formulas. It works — until it stops working. And when it does, it's always on the 9th of the month.

Integrated software encapsulates the rules in the engine. The person leaves; the process stays. It's not comfort — it's operational continuity with real legal and tax consequences.

  • Identify who is the sole holder of the knowledge of the payroll file.
  • Document all the business rules that exist only in that person's head.
  • Calculate the cost of rebuilding the file if that person left tomorrow.

Dimension 3 — Integration with time and attendance and production: where the error is born

In a textile factory with rotating shifts and variable overtime, payroll processing starts on the shop floor — not in HR's Excel. Attendance data arrives on paper, by email or by manual export from a time clock. Each of these steps is a transcription. And transcription is an error with a fixed date.

The typical scenario we find: the time clock exports a CSV at 5pm on the last day of the month. The HR staff member copies the totals into Excel. Does a visual check line by line. Detects three discrepancies. Corrects two. The third gets through. The payslip goes out wrong. The employee complains on the 20th. The retroactive correction goes into the following month's DMR. The Tax Authority requests clarification.

Integrated software — such as pplPortal with the pplCore module connected to time and attendance — eliminates that transcription step. Clocking data enters the calculation engine directly. The HR staff member validates; they don't transcribe. To understand how real-time data capture changes operations beyond HR, the logic is the same as that described in KORA Productivity: real-time shop floor control.

  • Map all the data entry points in payroll processing: time clock, job sheets, rosters, exemptions.
  • Count how many manual steps exist between clocking and the payslip.
  • Calculate the average processing time per employee and multiply by 12.

Decision matrix: Excel vs. integrated software

Criterion Excel Integrated software Weight for industrial SME
Automatic tax update No — manual, risk of omission Yes — via supplier High
Generation of DMR and Tax Authority/Social Security files Manual export or fragile macro Native, validated format High
Integration with time and attendance None or by manual import Direct, no transcription High
Traceability of changes (GDPR) Non-existent or by file versions Automatic audit log High
Scalability (more employees) Linear performance degradation No operational impact Medium
Start-up cost Zero or close to zero Real initial investment Medium
Dependence on key person Critical Low High
Support for complex shifts and rosters Very limited Native in vertical solutions High (industry)
Secure remote access File sharing — security risk Hybrid cloud with access control Medium-high

Dimension 4 — GDPR and traceability: the evidence the auditor will request

The payroll file is, by definition, sensitive personal data. The GDPR and Law 58/2019 require the company to know who accessed it, when and what they changed. An Excel file shared over the network — or sent by email between HR and accounting, as happens in more companies than is admitted — has no audit log. It has version history if someone remembered to enable change tracking. Rarely does anyone remember. And even when they do, Excel's history doesn't distinguish between a legitimate correction and an unauthorised change.

Integrated software records each change with user, timestamp and previous value. In a CNPD inspection or a labour dispute, that traceability is not an extra — it's the difference between having evidence and not having it. For companies with 50 or more employees, Law 93/2021 also adds the obligation of a whistleblowing channel, which makes the traceability of internal processes even more critical.

  • Check whether there is a record of who accessed the payroll file in the last month.
  • Confirm that retroactive changes are documented with formal justification.
  • Assess whether the file-sharing method meets the minimum GDPR requirements.

Implementation errors the manuals don't mention

Out-of-date income tax table: updating in January isn't enough. The Tax Authority publishes interim ordinances — for specific categories, for disability situations, for non-residents. Set a monthly verification schedule and assign a named person responsible, not "HR".

Formulas that work for 40 employees and break with 80: test the file with double the records before considering it stable. If the recalculation takes more than three minutes, the file is already at its limit. The problem isn't the speed — it's that a slow file invites shortcuts: calculating only the changed rows, skipping the final check, accepting the first result.

Payslips generated manually from the file: any discrepancy between the calculation file and the payslip delivered to the employee is an immediate labour risk. Automate the generation or implement a mandatory formal check with validation signature. Without this, the company has two documents with different values and doesn't know which prevails.

Homemade connectors between the time clock and Excel: some companies build scripts that export data from the clock directly into the file. When the clock changes model or the export format changes — and it does, typically when the supplier makes a firmware update — the script breaks silently. Nobody notices until the end of the month. This is the kind of failure that always appears on a Saturday night.

Absence of a substitution plan: if the only person who knows how to process payroll is on sick leave on the 8th of the month, the company has a problem with a date and time attached. Document the process step by step — not as a 40-page manual, but as a one-page operational checklist — and train at least one second person, even if they only process once a year in a simulation.

When Excel still makes sense — and when it stops making sense

There are contexts where Excel is defensible: a company with fewer than 15 employees, simple contracts, no rotating shifts, with an experienced and stable HR staff member, and an external accountant who does the DMR. In that scenario, the cost of transitioning to integrated software may not be justified immediately.

The tipping point comes when any of these conditions changes: the company grows to 30 or 40 employees, the contracts diversify, shifts or exemptions from fixed working hours come into play, the HR staff member changes, or the company takes on additional obligations such as the whistleblowing channel under Law 93/2021. Most Portuguese industrial SMEs have already passed that point — and continue to use Excel because the transition seems costly. What they don't calculate is the accumulated cost of maintaining the risk.

pplPortal was designed for Portuguese industrial companies that need to integrate time and attendance, payroll processing and people management without replacing everything at once. Phased adoption — pplCore first, then pplAdvanced for rosters and competencies, pplTalent for recruitment, pplEvolution for appraisal — allows you to start with the module that solves the most immediate pain and grow without rework. To understand how process automation changes operations beyond HR, the article Process automation in Portuguese industry: an operational guide develops the logic with shop floor examples.

Sources

  • Mercer, Global Talent Trends 2023 — voluntary turnover and talent retention in Portugal (10.6% and 52%).
  • Tax and Customs Authority (AT) — Monthly Remuneration Declaration (DMR): obligations, deadlines and file format. Available at portaldasfinancas.gov.pt.
  • Social Security Institute, I.P. — Remuneration Declaration to Social Security: schedule and reporting rules. Available at seg-social.pt.
  • Regulation (EU) 2016/679 (GDPR) and Law No. 58/2019 of 8 August — national implementation of the GDPR, including obligations for processing records and traceability of access to personal data.
  • Law No. 93/2021 of 20 December — general regime for the protection of whistleblowers, with the obligation of an internal channel for organisations with 50 or more workers.

Frequently asked questions

Is Excel really unsuitable for processing payroll in an SME?

It's not unsuitable because it's bad — it's unsuitable because it hides errors until the audit. The real problem is the dependence on a person who knows the formulas. When that person leaves (turnover in Portugal is 10.6% a year), what remains is a file that nobody can explain to the Tax Authority. The risk is not technical; it's operational and fiscal.

How much does it cost to correct an out-of-date income tax table in Excel?

The Tax Authority publishes interim ordinances during the year, not just in January. A company that updates once a year may be out of date for weeks without knowing it. The error per employee is negligible, but the accumulated tax exposure is real. Integrated software receives updates automatically; the responsibility is contractual, not personal.

How do I know if my payroll file is a legal risk?

Carry out this review: can you explain all the formulas? Do you have an updated income tax table? Who signs the DMR? Have you recorded the retroactive corrections of the last 12 months? If you fall short on two or more points, Excel isn't enough. The decision is not budgetary — it's when the risk becomes unbearable.

What is the real cost of losing the person who manages payroll?

It's not just training a replacement. It's rebuilding a file six to twelve years old, where the rules are encapsulated in formulas that only the previous person understood. In an industrial SME with two HR staff, the probability of losing that knowledge in a year is real. Integrated software encapsulates the rules in the engine; the person leaves, the process stays.

Why does integration with time and attendance matter in payroll processing?

Because the error is born on the shop floor, not in Excel. Attendance data arrives on paper, by email or by manual export. Each transcription is a point of failure. Integrated software eliminates that transcription — clocking data enters the calculation engine directly. The staff member validates; they don't transcribe. Fewer steps, fewer retroactive errors.

Does an out-of-date DMR generate immediate fines?

Not immediate, but inevitable. Any error generates interest, fines and, on repeat offences, blocking of certificates. In an industrial SME, this can paralyse a PT2030 funding application at the worst moment. The exposure is not visible until the audit — which is why the risk is underestimated.

Is integrated software mandatory for companies with fewer than 50 employees?

Legally, no. But the operational risk is the same. A garment company with 65 employees had the withholding table out of date for 11 months — the error per employee was negligible, the accumulated exposure was not. The decision doesn't depend on size; it depends on how many people know the file and how long you can go without updating.