Voids and refunds are 6% of restaurant fraud cases

Automated monitoring catches 3% of cases; tips catch 43%. Surprise audits halve how long a scheme runs — and only 44% of organizations use them.

Lucas Hartwell
10 min read
Employee theft and POS fraud in restaurants — a point-of-sale terminal showing void, discount, no-sale and refund functions restricted to authorized access, beside a theft prevention checklist covering permissions, void monitoring, refund review and cash drawer reconciliation

Almost every article about restaurant theft is about voids, comps and refunds. Mine was going to be too.

Then I looked at the numbers. The Association of Certified Fraud Examiners published Occupational Fraud 2026: A Report to the Nations in May — 2,402 cases across 143 countries, $3.4 billion in losses, with a breakout for food service and hospitality. In those cases, register disbursements — the void-and-refund family — appear in 6% of them.

Here is what the rest looks like:

SchemeShare of food-service cases
Corruption45%
Billing (fake or inflated vendor invoices)30%
Noncash (inventory, product)28%
Expense reimbursement25%
Check and payment tampering19%
Payroll19%
Skimming15%
Cash on hand11%
Cash larceny6%
Register disbursements6%

Food service leads every industry in the study on expense reimbursement at 25%, and runs at roughly double the all-industry rate on payroll. Those are back-office schemes. No POS exception report touches any of them.

One caveat before anything is built on that table, because it matters: these are cases investigated by certified fraud examiners, not a random sample of restaurants. ACFE says so directly — the distribution "reflects the distribution of the cases submitted by CFEs." It is a severity dataset, not a prevalence one. Small voids that get caught in week two never enter it. What it tells you reliably is where the expensive fraud lives, and the answer is not the POS.

Why void fraud survives: it's too small to trip anything

ACFE also measures velocity — median loss per month. Register disbursements come last:

SchemeMedian loss per month
Financial statement fraud$41,700
Corruption$12,500
Check and payment tampering$8,800
Billing$6,400
Noncash$6,300
Payroll$4,800
Skimming$3,800
Cash on hand$2,200
Expense reimbursement$1,900
Register disbursements$1,200

That single number explains more about void fraud than any amount of commentary about lazy managers. It bleeds at $1,200 a month. It does not trip a dollar threshold because it never reaches one.

The clearest documented example is a federal prosecution out of Nebraska: an area manager over three fast-food locations ran roughly 275 fraudulent credit-card refunds through the POS to eight personal cards over about seven and a half months. Total restitution: $30,075.16. That is an average of about $109 per refund.

No dollar-based alert catches $109. A count-based one does. If you take one configuration change from this post, make your void and refund exception reports rank by frequency per employee against peers, not by amount.

The scheme-to-report map, with an honest label

Below is what to look at. I want to be clear that this mapping is operational practice — it is what these reports are for — and not something with an independent measured detection rate behind it. Treat it as where to look, not as a guarantee of what you'll find.

SchemeWhat it looks like in the dataWhere it surfaces
Sweethearting / unauthorized compsComps concentrated on one server, clustered by guest or timeComps as % of net sales by employee, ranked; comp reason-code mix; comps without a manager ID
Void after paymentVoid timestamp later than tender timestampPost-tender void report; voids per server per shift ranked against peers
Refund fraudRefunds with no matching original sale; refund to a card that wasn't used originallyRefunds after close; refunds lacking an original transaction reference
Cash skimming / short-ringingSuppressed cash sales; drawer opened with no saleNo-sale drawer opens per employee; cash over/short by drawer; cash-to-card mix versus peers
Gift card fraudCash sale re-rung as a gift-card tenderGift-card issuance without matching tender; activation log against the sales journal
Order transfer abuseItems moved between checks to bury a comp or a walkoutItem-transfer log by employee; transfers immediately preceding a void
Time theftClocked in with no corresponding sales activityTime-clock hours against transactions per hour; clock-ins from off-site

Notice the last column stops at the POS boundary. Billing, payroll and expense-reimbursement fraud — which together account for the largest share of food-service case exposure — appear nowhere on it, because they happen in accounts payable and the payroll register.

Reports are not how fraud gets found

This is the finding that should reset expectations. ACFE measured how each case was first detected:

Detection methodShare of cases
Tip43%
Internal audit15%
Management review13%
Document examination5%
Account reconciliation5%
By accident4%
Automated transaction/data monitoring3%
External audit2%
Notification by law enforcement2%

Automated monitoring — the category your exception reports fall into — initiated detection in 3% of cases. Somebody telling you did it in 43%, and 55% of those tips came from employees, with another 21% from customers.

But detection method also predicts how bad it gets, and here the reports earn their keep:

Detected byMedian durationMedian loss
Surveillance / monitoring6 months$66,000
Automated data monitoring7 months$90,000
Account reconciliation8 months$150,000
Management review12 months$80,000
Tip12 months$100,000
External audit18 months$375,000
Law enforcement notification24 months$890,000

Monitoring rarely finds it, but when it does, it finds it fastest. The outside world finding it for you is the worst outcome by an order of magnitude — 24 months and $890,000 median.

One more practical note: among organizations under 100 employees, only 24% have any reporting mechanism, against 85% of larger ones. Given that tips are 43% of detections, that is the single largest control gap by organization size. And the channel has moved — web form 46%, email 34%, telephone hotline 23%. If you're planning a 1-800 line, you're building the third-most-used option.

The manager problem, with numbers

The standard control is a manager approval threshold on voids and comps. ACFE's collusion data explains why that fails more often than it should:

PerpetratorsShare of casesMedian lossMedian velocity
One51%$55,000$4,600/month
Two18%$125,000$10,400/month
Three or more31%$324,000$27,000/month

Nearly half of all cases involve more than one person, and three-or-more-person schemes bleed almost six times faster than solo ones. ACFE reports that more than half of register-disbursement cases specifically involved two or more people — meaning void fraud is majority-collusive. The server ringing the void and the manager approving it are frequently the same scheme.

The loss also scales with rank. Employees: $50,000 median. Managers: $125,000. Owners and executives: $475,000 — and owner-level cases are 16% of the total.

So what actually works against a scheme the approver is part of? ACFE measured eighteen controls. The four with the best return:

ControlAdoptionLoss reductionDuration reduction
Management review71%55%44%
Proactive data monitoring49%53%44%
Surprise audits44%50%50% (16 mo → 8 mo)
Job rotation / mandatory vacation27%49%33%

Surprise audits produce the largest duration effect of any control measured, and job rotation or mandatory vacation cuts losses nearly in half. Both are near the bottom on adoption. Both work for the same structural reason: they defeat a scheme that requires one person to control one process continuously.

For a restaurant that means something concrete — a manager who never takes a week off is a control failure, not a hero. Have someone else run the close for that week and reconcile it.

Worth reporting the counterexample too: rewards for whistleblowers produced a 7% loss reduction — the weakest control in the study. Not everything sold as an anti-fraud measure performs.

You find it. Now what? Three things most operators assume are available are not.

You almost certainly cannot deduct it from their pay. Under the FLSA, deductions for cash shortages are unlawful to the extent they cut wages below the federal minimum — and a written, voluntary repayment agreement doesn't fix that. The federal tipped cash wage is still $2.13 an hour, so a tipped employee has zero lawful deduction headroom before the deduction even starts. There is a narrow exception for shortages provably caused by that specific employee's theft, and the burden of proof is on you. California is stricter still: losses from mistakes or ordinary negligence are a cost of doing business, deduction requires proving dishonesty or a willful act, and a wrongful deduction adds waiting-time penalties on top of the wages.

You cannot take it out of tips. Since the 2018 amendment, an employer may not keep employee tips for any purpose, whether or not a tip credit is taken, and civil penalties attach without any need to show the violation was willful or repeated.

You cannot polygraph them. The Employee Polygraph Protection Act allows it only under a narrow ongoing-investigation exemption requiring documented economic loss, employee access, articulated reasonable suspicion, and a signed written statement given to the employee beforehand setting out the specific incident with particularity — kept for three years.

The practical path is discipline, termination, and restitution through the criminal or civil process. Which brings up the last set of numbers.

What actually happens afterward

56% of victim organizations recovered nothing. 29% recovered part. Only 15% got everything back.

46% never referred the case to law enforcement. The stated reasons: internal discipline judged sufficient 51%, fear of bad publicity 35%, private settlement 20%, too costly 19%.

And the belief driving a lot of that — that prosecutors won't take a restaurant theft case — is mostly wrong. Of cases that were referred, 48% pleaded guilty or no contest, 24% were convicted at trial, prosecutors declined 14%, and only 2% were acquitted.

Statistics I refuse to repeat

You will encounter these constantly, and I could not find a primary source for any of them:

  • "Employee theft costs restaurants 3–4% of sales" (7% in QSR)
  • "75% of restaurant inventory shortage is employee theft"
  • "$20 billion a year in restaurant employee theft"
  • "Buddy punching costs US employers $373 million a year"
  • "Sweethearting is 35% of retail shrinkage"

The first three are universally attributed to the National Restaurant Association, and I could not locate an NRA publication containing any of them. The buddy-punching figure is attributed variously to the American Payroll Association, BLS, and two private studies — four incompatible attributions for one number. The retail internal-theft percentages still in circulation come from a survey the National Retail Federation discontinued in 2024, so "current" figures are recycled 2022 data.

There is one real piece of sweethearting research: a 2012 Journal of Marketing study using paired data from 171 service employees and 610 of their customers. Its most useful finding is counterintuitive — sweethearting inflates satisfaction, loyalty and word-of-mouth scores by up to 9%, with the goodwill attached to the employee rather than the business. Your most-liked server and your most expensive one can be the same person, and the guest survey will defend them.

What I'd actually do

Rank voids, comps and refunds by count per employee against peers, not by dollars. Look at the post-tender void report specifically. Then — because that only addresses 6% of the expensive cases — pull the vendor master list and check for addresses matching employee addresses, run the payroll register against the active roster, and sample expense receipts. Put in a web-based reporting channel, because that is where 43% of detections come from and 24% of small operators have one. And schedule a surprise audit and a mandatory week off for whoever runs your close.

Disclosure: I work at Katalyst and exception reporting is something we build and sell. Which is exactly why I'll say plainly that the honest version of the pitch is narrow: reporting finds 3% of cases, and cuts median duration from twelve months to seven when it does. That is worth having. It is not a fraud program, and anyone selling it to you as one is selling you coverage for six percent of the problem.

Related Katalyst products

Ready to switch?

See how Katalyst handles your service style

A 30-minute walkthrough of the platform, tuned to how your restaurant actually runs.