Every operator who has run a multi-unit group long enough has had the same moment. The inventory does not tie to sales. The cash deposits are $200 short three Fridays in a row. Nobody stole anything obvious, and yet the P&L is bleeding. Then a year later somebody quits and the shrinkage goes away and you realize what was happening the whole time.
The good news is that every modern POS logs the pattern for free. The bad news is that almost nobody pulls the reports until after the fact. This is how to run the audit as a monthly hygiene practice, so that the patterns show up early and the response is data-driven instead of dramatic.
Why the pattern matters more than the number
A single void is nothing. A single comp is nothing. A single no-sale open is nothing. Every restaurant runs all three of these every day for entirely legitimate reasons. Voids happen when a server keys the wrong item. Comps happen when a guest gets a bad experience. No-sale opens happen when someone needs to make change.
What you are looking for is not the transaction. It is the concentration. When one employee's void count is 4x the peer average, or when comps are always issued between 10:45pm and 11:00pm on the same closing shift, or when no-sale opens spike on Sundays after the doors are locked, the individual transactions might each look defensible. The pattern is not defensible. The pattern is the signal.
Fig. 1 · The four patterns each show up differently in the data.
Signature 1: Void clustering on one server or cashier
The report to pull: voids by employee, count and dollar amount, last four weeks.
The math to run: for each employee, calculate voids per shift and voided dollars per shift. Then calculate the peer group average (all employees in similar roles at the same unit). Flag anyone whose per-shift number is more than 2 standard deviations above the average.
Why this matters: a void that removes an item from a check can also remove the cash equivalent from the drawer if it happens after the guest pays cash. The server takes payment, delivers the food, then voids the item from the check, pockets the cash, and the ticket looks like a customer walkout or a comp. Every POS logs the void with a timestamp. The pattern shows up in four weeks of data if it is happening.
What normal looks like: 1 to 3 voids per shift per server in a typical full-service casual restaurant, mostly small-dollar item corrections in the first 20 minutes of the shift when the server is still learning the menu specials.
What outlier looks like: 6 to 10 voids per shift on one server while the rest of the team runs 1 to 3, with a disproportionate share of voids landing in the last hour of service. That is the pattern.
Signature 2: Comp percentage above 3
The report to pull: comps as a percent of gross sales, weekly, by unit and by shift.
Healthy ranges:
- Full-service casual: under 2 percent of gross sales
- Fast-casual: under 1.5 percent
- QSR: under 1 percent
Above 3 percent, and something is off. Either the comp authority is too loose, the service recovery discipline is weak, or the comps are being used to zero out tickets that were paid in cash. All three problems have the same fix: tighten authority thresholds and audit the pattern monthly.
What to look for inside the number: concentration and timing. Comps concentrated on one shift, one server, one day of the week, or one item category are far more concerning than comps spread evenly across the team. A shift where the same $18 pasta comps five times in a month while nobody else comps that item at all is a specific pattern worth a specific conversation.
Comps are not the problem. Comp concentration is. When the same person comps the same item on the same shift week after week, the pattern is telling you something the individual transactions cannot.
Signature 3: No-sale opens after close
The report to pull: no-sale drawer opens with timestamp, employee, and terminal ID, last four weeks.
A no-sale open is when the cash drawer opens without a sale being rung. Legitimate reasons: making change, correcting a cash tip, opening the drawer for shift change, opening to add a bank at the start of the shift. All fine, all should be timestamped during business hours with a clear operational reason.
Illegitimate patterns:
- No-sale opens after the doors are locked and the closing checklist has started.
- No-sale opens during periods with zero customer traffic (2:30pm on a Tuesday for a dinner-only concept).
- No-sale opens by an employee not assigned to that terminal for the shift.
The single strongest single indicator of cash-drawer manipulation is no-sale opens after close. Every POS logs them and almost nobody pulls the report. Twenty minutes a month.
Signature 4: Refund concentration
The report to pull: refunds by employee, count and dollar, last four weeks, with day of week and time of day.
Refunds are one of the easier avenues for cash removal because the refund is issued after the original sale and the cash exits the drawer without a matching customer at the counter. If one cashier is issuing 40 percent of the refunds while working 20 percent of the shifts, that is refund concentration and it belongs on the audit list.
The specific pattern I have seen most often: refunds on small credit card transactions that never actually go back to a customer's card. The refund is processed but the cash gets pulled from the drawer under the same "refund" event in the closing cash count. If your refund report and your card processor's refund report do not match line for line, that is a signal.
The monthly audit, start to finish
Thirty minutes a month, per unit, once the system is running. The first month will take a couple of hours because you are setting up the reports and calibrating the peer averages.
Step 1: Pull the four reports
Voids, comps, no-sale opens, refunds. Four weeks of data. Every POS (Toast, Square, Aloha, Micros, R365 POS, Revel) can export these directly.
Step 2: Calculate the outliers
For each report, calculate the per-employee peer average and standard deviation. Flag anyone more than 2 standard deviations above the mean.
Step 3: Cross-check timestamps
For each flagged employee, look at the timestamps of the flagged transactions. Are they clustered late in the shift? Do they cluster after close? Do they cluster on specific days of the week?
Step 4: Sit with the pattern before you sit with the person
This part matters. Do not walk up to an employee with a single data point and an accusation. That is unfair to the employee and it destroys trust across the whole team even if you are right. Bring four weeks of data, sit with the pattern for a day yourself, and then have a conversation that starts with "I want to walk you through what I am seeing and get your read on it." Most of the time you learn about a training gap, a POS habit, or a service recovery decision the person did not know to log properly. Sometimes you learn about something else.
What the numbers look like on a real unit
A five-unit full-service group I worked with pulled the audit for the first time and found:
Unit A comp %: 4.1% (bench <2%) → concentration on Sunday brunch Unit B voids/shift: avg 2.4, outlier server at 8.7 per shift Unit C no-sale opens: 34 events, 11 after close on Fridays Unit D refunds: 76% of refunds on one cashier, 22% of shifts Unit E comp %: 1.6% (in range, no flag) Rough annualized dollar impact of the four flagged patterns: $180K Time to run the audit that surfaced them: 2 hours across five units
Not all of that $180K was theft. About half of it turned out to be training gaps and loose comp authority. The other half was harder to explain, and the pattern audit gave the operator the standing to install real controls without accusing anyone specific.
What the audit does for the team, not just the P&L
The best argument for running the monthly audit is not the money it recovers. It is what it does to the culture of the unit. When the team knows the reports get pulled every month, and knows that the pattern review is a routine hygiene practice, three things change.
First, the good employees stop feeling like they are the only ones being scrutinized. The audit is universal. Everyone's data goes through the same filter. That is fairer than the alternative, which is a manager who watches one employee closely because of a hunch and misses the actual pattern elsewhere.
Second, the ambiguous cases get resolved instead of festering. Most flagged patterns are training gaps or misunderstood procedures. Bringing the data to the person on a monthly cadence surfaces those gaps early and fixes them with training, before anyone builds a story that they are being singled out.
Third, the small-percentage of people who are actually manipulating the system get uncomfortable and self-select out. In several units I have run, the audit itself (announced and installed as a monthly practice, not a secret investigation) caused two or three resignations in the first quarter without a single accusation being made. The pattern goes away because the person who was creating it decides the environment is not for them.
What separates a real audit from a paranoid one
There is a version of this that goes wrong. The version where the operator becomes obsessed with catching people, brings suspicion to every conversation, and turns the unit into an environment where nobody feels trusted. That environment loses good employees fast and creates the exact culture that hides real problems.
The line between a real audit and a paranoid one comes down to three things:
- The audit is universal, not targeted. Everyone's data goes through the same filter every month. No individual is watched more closely than the peer average unless the peer average puts them there.
- The response is data first, conversation second. Never confront on one data point. Always bring four weeks of pattern to any conversation, and always start with "walk me through what happened here" rather than "why did you do this."
- The controls are visible, not hidden. The team should know that voids above $25 require a manager PIN, that no-sale opens are logged, that refunds are reconciled to the card processor. Hidden surveillance breeds paranoia. Visible controls breed accountability.
The controls to install alongside the audit
The audit tells you what happened last month. Controls prevent the next month.
- Manager PIN for voids and comps above $25. Every one. No exceptions.
- Next-day review for any void or comp above $100. The general manager reads the reason, signs off, and initials the log.
- Two-person cash count at open and close. Manager plus one hourly, both sign, no exceptions.
- Deposit reconciliation within 24 hours. POS sales versus deposit slips versus bank statement, matched by day.
- Refund report cross-check monthly. POS refunds versus card processor refunds, matched line by line.
None of this is expensive. All of it is boring. The boring stuff is what actually protects the P&L.
The point
Theft in a restaurant is almost never a dramatic event. It is a slow, patient pattern that shows up in POS data long before it shows up in inventory or in cash. The four signatures (void clustering, comp concentration above 3 percent, post-close no-sale opens, refund concentration) are already sitting in your POS reports. Nobody is pulling them.
Thirty minutes a month per unit. Bring the pattern to the person, not the accusation. Install the boring controls alongside the audit. That is how you keep the leaks small and the team's trust intact at the same time.
Authority without audit is where the money goes. Audit without accusation is how you get it back.