Callback
  • From a market stall to a store

  • -

  • From a store to a retail chain

  • -

  • From retail to manufacturing

Retail employee fraud: how to protect your business

Andrii Toverovskyi
Andrii Toverovskyi

Expert in tax and legal business matters

Business security

How to protect a store from staff fraud: Torgsoft settings and control rules

Torgsoft Blog Reading time: 15 min Updated: July 2026

Losses caused by staff most often arise where one person can perform an operation, change its result, and independently hide the traces. Protection begins with separation of duties, personal user accounts, action logging, and regular review of exceptions.

In Torgsoft technical support practice, there have been sales canceled after receiving money, unauthorized discounts, fictitious returns, price changes before sale, inventory manipulation, discrepancies during internal transfers, and editing of old documents. A single case does not prove intent: the cause may be an error, incorrect configuration, or misunderstanding of the process. But recurring deviations must be checked.

The program does not replace management

Torgsoft restricts dangerous actions, stores information for review, and helps find discrepancies. The program cannot determine a person’s intent, confirm the actual presence of goods on the shelf, or identify who physically used someone else’s badge.

How to build protection: three levels

LevelWhat needs to be doneWhich risk is reduced
Prevention Restrict roles, manual price and discount changes, deletion of goods from sale, editing of old documents An employee cannot single-handedly perform a dangerous operation
Personal responsibility A separate user and password for each employee, a personal badge, prohibition of shared accounts An action can be linked to a specific employee
Detection Check cancellations, manual discounts, returns, write-offs, transfer discrepancies, and document changes Deviations do not accumulate for months

If only the third level is left, the owner will constantly search for violations in a large amount of data. If only restrictions are left, employees will start using shared passwords or requesting excessive rights «for convenience». Therefore, all three levels must work simultaneously.

1. Checkout: sales cancellations, cash, and card payments

Where the risk arises

A cashier may receive money from a customer but not complete the sale; cancel individual items or the entire receipt; specify the payment method incorrectly; or process a return without proper verification. Risk indicators include frequent cancellations after scanning goods, recurring «cashier mistakes», discrepancies between Torgsoft, cash, the bank terminal report, and fiscal receipts.

What to configure in Torgsoft

  • Prohibit deletion of goods from sale for the seller role. In this mode, cancellation of an item added by mistake is performed by an administrator.
  • If a complete prohibition interferes with work, enable «Register deletion of goods from sale» with a mandatory reason and responsible person. Check the report «Warehouse → Canceled goods from sales».
  • Configure automatic receipt printing after payment. The customer must receive a document with the list of goods, prices, discounts, and a barcode for return.
  • Hide from the seller the amount that should be in the cash drawer and use a request for the actual balance at login, banknote-by-banknote verification, and the mode «Payment → Cash register totals».
  • For card payments, connect integration with a bank terminal: the amount is transferred from Torgsoft to the terminal, and the operation result is returned to the program. For the seller role, disable the right «Allowed not to use connection with the bank terminal».

What regulation is needed

  • At the beginning and end of the shift, count the cash and record the result in the program.
  • Daily reconcile cash, card payments, returns, cash collections, the PRRO or RRO Z-report, and the bank terminal.
  • Cancellations after the amount has been announced to the customer and money returns should be performed only according to a defined procedure. The operation is confirmed by another authorized employee using their own password or badge.
  • Synchronize the time on the checkout computer and the video recorder. Then an event in the report can be quickly compared with the camera recording.
What Torgsoft provides

The canceled goods report shows the time, product, quantity, price, reason, seller, and accounting center. This makes it possible to check exceptions instead of reviewing all sales in a row.

Collective responsibility does not replace personal accounting

If several people work at one checkout under a shared user, it is impossible to identify the author of the operation. Every sale, return, cancellation, and cash collection must be linked to a specific employee.

2. Discounts, bonuses, and discount cards

Where the risk arises

An employee may apply a card with a large discount to a regular purchase, use another customer’s bonuses, temporarily change loyalty parameters, or set a manual discount without approval. If the customer did not receive a receipt and does not know about the promotion, the difference is harder to notice.

What to configure in Torgsoft

  • Prohibit the seller from manually selecting a customer from the full list and from editing customer cards, discount amounts, and bonus parameters.
  • Enable «Prohibit the seller from entering the discount card number from the keyboard (scanner only)».
  • For stores with valuable bonuses or significant personal discounts, use discount card verification via SMS. The code is sent to the card owner’s phone, so having the physical card or knowing its number is not enough.
  • Leave manual discounts only to the roles that need them by position. Set an allowed limit and define cases when administrator approval is required.
  • Check «Analysis → Discount usage analysis»: manual discounts on goods and documents, percentage changes, amount adjustment, excessive discounts, sales below cost or below the price with a product discount.

What regulation is needed

  • Display promotion terms and prices so that the customer sees them before payment.
  • Issue a receipt to every customer. In the receipt, the customer sees the actual price and the applied discount.
  • Weekly compare employees by the share of manual discounts, average percentage, and sales below the established limits.
  • Assign changes to loyalty rules and cards with large bonus balances to a separate role that does not work at the checkout.
Physical card scanning does not always confirm the right to a discount

An employee may have someone else’s card. Risky operations require additional confirmation from the card owner or another control, such as phone number verification.

3. Product returns and gift certificates

Where the risk arises

A return creates a movement of goods back to the warehouse and may involve paying out money. Because of this, returns without the original sale, use of someone else’s badge, repeated payouts, return of the wrong item, and changing the payout method are dangerous. For certificates, an additional risk arises if their return, reuse, and cash payout are not regulated by one process.

What to configure in Torgsoft

  • Process returns by receipt barcode. Torgsoft opens the list of goods from the corresponding sale and allows you to select items and quantities for return.
  • Restrict roles: the cashier processes a standard return, while a non-standard return without a receipt or a change in payout requires a separate right and approval.
  • Enable the document change log and check returns together with the corresponding sale and payment.
  • For gift certificates, use unique barcodes and account for sale and redemption in Torgsoft. Distribute access to issuing, returning, and changing certificate parameters between roles.

What regulation is needed

  • Make the payout using the same method by which the purchase was paid, unless another procedure is provided by law and the approved store regulation.
  • Physically check the product, completeness, serial number, and packaging condition before confirming the return.
  • Do not leave the administrator badge near the checkout and do not pass it to other employees. Confirmation with someone else’s badge is not control.
  • Return of a certificate, restoration of its validity, or payout of funds are separate controlled operations. They should not be performed single-handedly by the seller who sold or accepted the certificate.

4. Product substitution, price changes, and sale of unrecorded goods

Where the risk arises

This group includes using the barcode of a cheaper product, short-term price changes before sale, issuing another product from the warehouse, and selling goods that are not present in incoming documents. The risk increases if the cashier can edit the product card, enter a barcode manually, change the price, and independently issue goods from the warehouse.

What to configure in Torgsoft

  • Prohibit the seller role from changing the product card, barcodes, retail price, product type, receipt, and write-off documents.
  • If possible, disable manual entry of the product barcode during sale — the product is added by scanner.
  • Enable «Keep document change log». For a suspicious sale, check the user action protocol and changes to related warehouse and financial documents.
  • Hide the warehouse quantity from roles that do not need it for work. Separately control zero and negative balances: physically available goods must be received into stock on time.
  • In trade with a separate warehouse, print an invoice or warehouse worker receipt. The warehouse employee issues goods according to a paid document, not at the cashier’s verbal request.
  • Check incoming invoices by quantity and amounts. After control, set the attribute «Control completed» to prohibit further editing of the checked invoice.

What regulation is needed

  • No product goes onto the shelf without an incoming document and the marking accepted in the store.
  • The employee who created the receipt should not check and block it single-handedly.
  • For expensive or compact product groups, conduct sudden selective counts by barcodes.
  • For separated payment and issuing, the cashier is responsible for the correct document, and the warehouse worker is responsible for the actual issued product matching the document.

5. Internal transfers between warehouse and stores

Where the risk arises

If the store independently changes the quantity during receiving, the shortage may be attributed to the sending warehouse. Without a separate check, it is impossible to establish at which stage the discrepancy occurred.

What to configure in Torgsoft

  • Process internal transfers through the «Goods in transit» mode so that sending and receiving do not merge into one uncontrolled action.
  • On the recipient side, perform «Check invoice» and enter the actual quantity. In case of discrepancies, the program offers to generate a report and creates adjustment documents during receiving.
  • Separate the rights to create a transfer, check quantity, apply results, and cancel invoice control.
  • Enable the document change log: verification results and applied changes to the internal transfer are recorded in the log.

What regulation is needed

  • The sender and the recipient count the goods independently of each other.
  • A discrepancy is not corrected by verbal agreement. It is documented in a report, and the packaging, route, video, and responsible persons at each stage are checked.
  • Transfer expensive goods with container sealing, photo recording, or serial numbers, if this corresponds to the product type.

6. Inventory without the ability to adjust the result

Where the risk arises

If an employee sees the accounting balance during counting, they may transfer this number into the actual quantity without checking the shelf. In this case, the shortage will not appear in the inventory results.

What to configure in Torgsoft

  • Enable «Restrict the inventory statement for inventory performed by a seller».
  • For the corresponding role, activate «Hide warehouse quantity for goods during inventory». The employee enters only the actual counting result.
  • Do not give the counting commission the right to close the statement and apply the results independently without verification.
  • Before inventory, complete or stop goods movement, define the moment of balance fixation, and check negative balances.

What regulation is needed

  • Use blind counting: the first employee counts, and the second checks only the positions with discrepancies.
  • Do not disclose the accounting balance until the initial count is completed.
  • Conduct both scheduled inventories and short sudden checks of risky product groups.
  • After correcting errors, close the period so that documents from the past period are not changed without controlled opening.

7. Accountant, administrator, and employees with extended rights

Where the risk arises

A user with excessive rights can change old documents, dates, payments, prices, program parameters, or open closed periods. Family ties, long tenure, or position do not replace technical access separation.

What to configure in Torgsoft

  • Create separate roles for the accountant, manager, administrator, cashier, and warehouse worker. Leave full rights only to the owner or system administrator who performs defined tasks.
  • Create a separate user with a recognizable name for each employee. Accounts such as user, test, or one password for the entire shift make personal responsibility impossible.
  • Enable «File → User action protocol», «User action protocol for edit forms», and «Document change log».
  • Close periods regularly. Grant the right to open or unlock past periods only to a defined role.
  • Prohibit employees from deleting or changing financial and warehouse documents and critical settings if this is not part of their regular duties.
  • If there is suspicion of backdated operations, compare the document date with the actual time of its creation in goods movement and protocols. In financial documents, additionally check the sequence of numbers.
Do not clear history before the check

When deleting statistics of closed periods for the corresponding period, the document change log and user action protocol are also cleared. If there is suspicion of a violation, first save a database backup and agree on the verification procedure with technical support.

What the owner should check

FrequencyControlWhat to look at
Daily Checkout, card payments, returns, cancellations Amount discrepancies, unfinished sales, many cancellations at the end of the shift, atypical returns
Weekly Discounts, write-offs, document changes, internal transfers Manual and excessive discounts, sales below the limit, recurring write-off reasons, discrepancies linked to one employee
Monthly Inventory, period closing, access rights Shortages by product groups, negative balances, excessive rights, users of dismissed employees
Quarterly Full audit of roles and regulations Temporary permissions that remained forever, shared passwords, operations without independent verification

The check should be short and regular. The owner does not need to control every action. It is necessary to define operations with increased risk, normal limits, and the person responsible for reviewing deviations.

Signs that require verification

  • Frequent cancellation of goods or sales by one employee.
  • Manual discounts, amount adjustment, sales below cost or the established limit.
  • Returns without a receipt, repeated returns, or payouts by another method.
  • Changing the price, customer card, or document shortly before or immediately after a sale.
  • Documents from past dates created later by sequence number, or repeated opening of closed periods.
  • Discrepancies in internal transfers that are systematically linked to the same shift, route, or employee.
  • Surpluses and shortages that repeat for the same goods.
  • User attempts to open prohibited forms or frequent requests for broader rights without a clear work need.
An anomaly is not proof

The same result may arise from abuse, an error in the regulation, incorrect rights, or insufficient training. A conclusion is made after comparing documents, logs, actual balances, cash, bank operations, and video.

What to do if suspicion arises

  1. Save the data. Create a database backup. Do not delete documents, logs, or statistics, and do not «correct» suspicious operations before verification.
  2. Narrow the period. Record the date, approximate time, accounting center, checkout, user, product, amount, receipt or document number.
  3. Compare sources. Check the receipt, financial and warehouse documents, action protocol, change log, bank terminal, PRRO or RRO, and video.
  4. Limit the risk without destroying traces. Temporarily remove excessive rights or access to the risky operation. Do not give the suspected employee the owner’s password to «correct» the situation.
  5. Record the explanation. Ask the employee to describe the actions step by step. Compare the explanation with the time and program records.
  6. Contact Torgsoft technical support. Provide specific identifiers and the time interval. The specialist will help restore the sequence of events in the database, but the management or legal decision is made by the owner.

Basic configuration checklist

  • Each employee has a personal user, password, and, if needed, badge.
  • The role corresponds to the position; unnecessary menus, forms, columns, and actions are closed.
  • Dismissed employees do not have active access.
  • The seller cannot delete goods from sale, or each deletion is registered with a reason and responsible person.
  • A receipt is printed after every payment.
  • Manual customer selection, discount card entry, and changes to loyalty rules are restricted.
  • Manual discounts and price changes are available only to authorized roles.
  • Card payment is transferred to the integrated terminal; the seller cannot disable the connection.
  • Returns are processed by receipt and checked separately.
  • Incoming invoices are checked by an employee other than the one who created them.
  • Internal transfers go through «Goods in transit» and independent counting by the recipient.
  • Inventory for the counting commission does not show the accounting balance.
  • User action protocol and document change log are enabled.
  • Periods are closed regularly; their opening is controlled.
  • Daily, weekly, and monthly checks have responsible persons and recorded results.
  • The time in Torgsoft, at the checkout, terminal, and video recorder is synchronized.
  • Backups are created automatically, and the possibility of restoration is checked.

Torgsoft instructions for configuring control

  1. Role settings — access to program menus, forms, and actions.
  2. Access settings — restrictions for the seller, checkout, discount cards, and inventory.
  3. Canceled goods from sales — registration of the reason, responsible person, and report for the owner.
  4. User action protocol and Document change log.
  5. Goods in transit — checking internal transfer and processing discrepancies.
  6. Inventory using a computer — hiding the accounting quantity from the employee who counts goods.
  7. Product return by receipt — selecting goods from the corresponding sale.