GOSI and WPS are the two payroll-compliance frameworks where Saudi employers most often fall foul of regulators, and where Western HRIS platforms consistently fail. The General Organization for Social Insurance (GOSI) requires per-pay-run contribution calculations split between Saudi and non-Saudi employees, with the SANED unemployment-insurance component added for Saudis; the Wage Protection System (WPS), filed through Mudad, requires a strictly-structured SIF file with IBAN validation, bank-code mapping, and contract-salary-to-net-pay matching. Late or rejected submissions trigger wage-protection violations on the MHRSD portal, which can block government services and labour-file renewals. This guide walks through how U HR handles both frameworks natively — from Earnings & Deduction Rules configuration through WPS SIF file generation, monthly reporting, and the audit trail that an MHRSD or GOSI auditor expects. The goal is a repeatable monthly cycle that produces audit-ready evidence without manual Excel cleanup, and the configuration choices that make that cycle stable from month one.
The two pillars of Saudi payroll compliance #
GOSI and WPS are often confused as a single 'payroll compliance' requirement, but they are two distinct frameworks with different submission cadences, different data structures, and different failure modes. GOSI is a social-insurance framework: every Saudi employer contributes a percentage of each Saudi employee's salary (9% employee + 9% employer for pension and disability, plus 1% each for the SANED unemployment component) and a smaller percentage for non-Saudi employees (2% employer-only for occupational-hazard coverage). WPS is a wage-disbursement framework: every employer must submit a monthly SIF file through Mudad listing each employee's bank, IBAN, contract salary, and actual disbursement, so that MHRSD can verify wages are paid in full and on time. The two frameworks share the same source data — employee salary components and bank details — but they ask different questions of that data. U HR treats them as two outputs of a single configured payroll engine, so that the GOSI contributions on each payslip reconcile exactly with the WPS disbursement lines in the SIF file.
GOSI contribution calculation in U HR #
GOSI calculation in U HR begins in the Earnings & Deduction Rules module, where the HR Manager defines two GOSI rules: one for Saudi employees (9% employee social insurance + 9% employer + 1% employee SANED + 1% employer SANED, totalling 22% for Saudis under the standard scheme) and one for non-Saudi employees (2% employer-only occupational hazard). Each rule carries a calculation type (percentage-of-base), an effective date, and a Saudi-or-non-Saudi flag. Working & Finance Info flags each employee as Saudi or non-Saudi, and payslip generation applies the correct rule automatically — eliminating the manual lookup that produces the most common GOSI error (applying the Saudi rate to a non-Saudi, or vice versa). The GOSI establishment code entered at the Company level drives the contribution schedule that the e-GOSI portal expects, and the monthly GOSI report can be generated from the U HR Manager app in the format the portal accepts. For multi-entity holdings, GOSI is computed per Company — each legal entity has its own establishment code and its own contribution schedule — so the group's total GOSI liability is the sum of per-entity schedules, not a blended calculation.
WPS file generation via Mudad SIF #
The WPS SIF file is the single most-rejected artefact in Saudi payroll compliance, and the rejection reasons are remarkably consistent: IBAN validation failures, bank-code mismatches, contract salary not matching the WPS base salary line, and total disbursement not matching the sum of approved payslips. U HR's WPS file generation is designed to eliminate these rejections at the source. After a payslip batch is approved, the system generates the Mudad-compatible SIF file by pulling each employee's bank details from Working & Finance Info, validating the IBAN against the bank-code mapping, placing the contract salary as the first line of each employee's record, and summing the net disbursements to a header total that must match the file's footer. The HR Manager reviews the file before submission — a thirty-second scan of the totals and the per-employee variance flags — and uploads it to Mudad through the standard portal. U HR does not submit directly to Mudad on the employer's behalf, because the submission requires authenticated Mudad credentials that the employer controls, but the file itself is ready for upload without manual reformatting.
Monthly compliance reporting #
Beyond the per-cycle SIF and GOSI submissions, Saudi employers need monthly compliance reports that consolidate payroll activity for internal review and external audit. U HR's reporting layer produces three core reports each cycle: a GOSI contribution report (per-entity, with Saudi and non-Saudi splits), a WPS submission report (file generation timestamp, total disbursement, per-employee breakdown), and an exceptions report (payslips that varied from the previous cycle by more than the configured threshold, IBAN validation failures, GOSI rate mismatches). These reports are generated from the Employee Manager app and can be scoped per Company or rolled up to the group level. The reports also feed the MHRSD-expected audit pack — payslip samples, GOSI evidence, WPS submission history, and the approval-chain stamps that show who approved each cycle. For a Saudi employer under a routine MHRSD audit, producing this pack in minutes rather than days is the difference between a clean audit and a finding, and for a multi-entity group, the per-entity reporting is what surfaces a subsidiary that is drifting toward non-compliance before it triggers a regulatory action.
Audit trails and MHRSD evidence #
MHRSD audits of Saudi employers increasingly focus on the audit trail behind each payroll cycle — who configured the rules, who generated the batch, who approved it, when it was distributed, and how employees accessed it. U HR captures this trail natively: every Earnings & Deduction Rule change carries an editor stamp and timestamp; every payslip batch carries a generator, an approver, and a distribution timestamp; every employee payslip access is logged. The audit trail is read-only — it cannot be edited or deleted — which is what an MHRSD auditor expects from a regulated HR system. For multi-entity groups, the audit trail is scoped per Company, so the auditor of a single subsidiary sees only that subsidiary's records unless explicitly granted group-level access. This scoping matters because NDMO treats employee payroll data as personal data subject to access controls, and an auditor who can see all subsidiaries' payroll by default is an access-control failure in itself. The combination of complete capture and scoped visibility is what makes U HR's audit trail admissible in MHRSD and GOSI audit contexts.
Common compliance failures and how to prevent them #
Most Saudi payroll compliance failures fall into a small number of patterns, all of which U HR is designed to prevent. The first is GOSI rate misapplication — applying the Saudi rate to a non-Saudi or vice versa — which U HR prevents by flagging each employee's nationality in Working & Finance Info and applying the correct rule automatically. The second is IBAN validation failure on the WPS file — which U HR prevents by validating IBANs against bank-code mappings at upload time, not at submission time. The third is contract-salary mismatch — the WPS base salary line not matching the contract salary registered with MHRSD — which U HR prevents by treating the contract salary as the single source of truth, propagated from Working & Finance Info to both the payslip and the SIF file. The fourth is late submission — which U HR prevents through the monthly reporting layer that surfaces upcoming deadlines. The fifth is missing audit trail — which U HR prevents by capturing every action with a stamp that cannot be edited.