Nobody discovers a loss problem on a good day
In more than two decades of loss prevention work, I have never had an owner call me because a report looked slightly off. They call after the physical inventory comes back eleven thousand dollars short. They call after the third week of drawer shortages. They call after a long-trusted employee resigns abruptly and the refund log suddenly goes quiet. By then the money is gone, the evidence is stale, and the conversation is about damage control instead of prevention.
Here is what those cases have in common: in almost every one of them, the loss had been visible in the store's own data for months. Nobody looked. Not because the owner was careless — because nothing in the daily routine required anyone to look. A business runs on urgency, and a slow leak never feels urgent until it becomes a flood.
That is the entire purpose of an audit schedule. An audit is not an accusation and it is not an inspection. It is a scheduled moment where someone is required to look at something specific and write down what they found. That written record is what converts a hundred unrelated small events into a visible pattern.
The goal of an audit is not to catch an employee. The goal is to find the problem while it is still cheap.
Most small business losses come from five recurring sources: inventory that disappears without explanation, cash shortages nobody reconciles, margin erosion from pricing and markdown errors, receiving mistakes that were never claimed against the vendor, and employee theft that grew because the first attempt went unnoticed. An audit schedule addresses all five with the same tool — a documented, repeatable look.
Section 1 — The daily audit
Daily audits exist because some losses have a shelf life measured in hours. A delivery short six cases can still be claimed today; in ten days the vendor will decline it. A drawer shortage identified this morning can still be traced to a specific transaction; a week later it is unresolvable. Speed is the entire value of the daily tier.
Opening procedures and register assignment
The opening routine sets the accountability baseline for the entire day. Two people should be present at open whenever staffing allows, the alarm and door log should be checked for overnight activity, and safe contents should be verified against the closing count from the night before. If the safe does not match the previous close, you have found something before the store even opened — and you know exactly which shift to look at.
Register assignment matters more than most owners realize. One cashier, one drawer, one login, one shift. The moment two cashiers share a till, every shortage becomes unattributable and every investigation dies before it starts. Shared drawers are the single most common reason a legitimate theft case cannot be proven. Read our full breakdown of opening and closing procedures that reduce theft for the complete sequence.
Opening till counts
Count the starting bank in front of the cashier who is accepting it, and have both people initial the count. This takes ninety seconds and eliminates the most common excuse in retail: "the drawer was already short when I got it." Once that excuse is gone, a shortage belongs to a known shift and a known person, which is what makes coaching — or an investigation — possible.
Random high-risk merchandise counts
You cannot count everything daily. You can count the ten to twenty items that account for the majority of your theft exposure: cigarettes and tobacco, energy drinks, batteries, razors, pain relievers, baby formula, small tools, ammunition, high-value fasteners, premium spirits — whatever moves fastest and hides easiest in your format. Rotate which items you count so the pattern is unpredictable.
Use a fixed sheet with an expected on-hand figure so the counter cannot back into the "right" answer. Our free High-Risk Merchandise Tracker is built for exactly this.
Cash handling throughout the day
Enforce three things daily: drops at a defined threshold, no cash counting on the sales floor, and a documented reason for every no-sale and every register open outside a transaction. Drops are a security control and an audit control at once — a drawer holding eight hundred dollars is a robbery target and an accounting mess.
Receiving documentation
Every delivery gets checked against the invoice before the driver leaves and before product reaches the shelf. Blind receiving — where the receiver counts without seeing the expected quantity first — is dramatically more accurate than confirming a printed number. Note shortages, damages, and substitutions on the invoice, get a driver signature, and file it the same day. Undocumented shortages are not losses you can recover; they are donations. We cover this in depth in stopping inventory loss before it reaches the shelf.
Incident and damage logging
Every shoplifting event, refusal, safety issue, customer injury, equipment failure, and damaged item gets logged the day it happens — even the small ones, especially the small ones. A single broken jar is noise. Forty logged damages in a quarter, all in one department, all on one shift, is a finding. Unlogged damage becomes unexplained shrink four months later, and unexplained shrink always gets blamed on theft.
The manager walkthrough
Ten minutes, same route, different times of day. Look at what an experienced thief looks at: blind corners, fitting rooms, the back hallway, the compactor, the trash exit, stock staged near the back door, and any product concentration that does not match the planogram. Look also at what a stressed employee leaves behind: overrides taped to a monitor, a propped fire door, a pile of unfiled invoices. Both tell you something.
End-of-day reconciliation
Reconcile each drawer independently against its own sales, not as a combined store total. A store that nets to zero can easily contain a hundred-dollar overage on one register and a hundred-dollar shortage on another — which is a very different story than "we balanced." Record every variance, even two dollars. Variance history is the raw material for every investigation you will ever run.
- 1Open · 6 minAlarm log, safe verification, till issue, register assignment
Two-person count, both initial. Confirms accountability before the first sale.
- 2Mid-morning · 4 minHigh-risk spot count + receiving check
Rotate SKUs. Blind count every delivery against the invoice before the driver leaves.
- 3Afternoon · 8 minManager walkthrough + incident/damage logging
Same route, varied timing. Log every event, however small.
- 4Close · 4 minPer-drawer reconciliation and safe count
Record variance by register and by cashier. No blended totals.
- Two-person opening safe verification
- One cashier per drawer, no exceptions
- Four rotating high-risk SKU counts
- Blind receiving on every delivery
- Per-register end-of-day variance log
- Blended store totals hiding offsetting variances
- Receiving signed without counting
- Damage discarded instead of logged
- Walkthroughs at the same time every day
- Cash counted in view of the sales floor
Section 2 — The weekly audit
Daily audits find events. Weekly audits find patterns. This is the tier most small businesses skip entirely, and it is the tier where nearly every internal theft case is actually discovered — not through video, not through a tip, but through exception data reviewed on a schedule.
Random till audits
Pull a drawer mid-shift, unannounced, and reconcile it against sales to that moment. Random timing is the entire mechanism: a cashier who knows the count happens at close can manage the drawer to close. Aim for two to four random audits per week distributed across cashiers and dayparts, and do them on your best performers too — an audit program applied only to suspects is a bias program. The step-by-step method is in our random till audit guide.
Refund, void, and discount trends
Rank employees by refund count, refund dollars, void count, no-sale count, and discount usage as a percentage of their own transactions. You are not looking for a big number — you are looking for an outlier relative to peers doing the same job in the same daypart.
| Exception | Normal pattern | Investigate when… |
|---|---|---|
| Refunds | Spread across staff; most tied to a receipt and an original sale | One employee owns a disproportionate share, or no-receipt refunds cluster on one login |
| Voids | Occasional, mid-transaction, corrective | Post-tender voids, end-of-shift clustering, or voids on cash sales only |
| No-sales | Change-making, minor corrections | Repeated no-sales without a matching transaction, or spikes in low-traffic hours |
| Discounts | Consistent with published policy and approvals | Employee discount used near the same customers repeatedly, or manual price overrides on high-margin items |
| Returns to gift card | Rare, policy-driven | Recurring on one operator — a classic conversion route for refund fraud |
Discount abuse deserves specific attention because it rarely feels like theft to the person doing it. A cashier applying an employee discount to a friend's purchase is committing sweethearting — and in most stores it costs more annually than shoplifting does.
Cycle counts
Pick one department or category per week and count it fully. Over a quarter you will have touched the whole store without ever shutting it down. Cycle counts do something a single annual inventory cannot: they tell you when the variance happened, which narrows the window from a year to seven days.
Receiving review and inventory adjustments
Review the week's invoices against what was actually received and what was entered into inventory. Then review every manual inventory adjustment — who made it, why, and whether it was approved. Unrestricted adjustment rights are the quiet back door in most small retail systems: a person who can move product on paper can move product in reality and reconcile the difference themselves.
Security equipment and camera review
Verify weekly that cameras are recording, angles are correct, retention is intact, and register overhead views actually show the drawer and the scan bed. Cameras discovered to be broken during an investigation are worse than no cameras, because you believed you were covered. Spend fifteen minutes reviewing two or three random high-risk moments — a large refund, a late-night close, a big delivery.
Store condition and repeat operational failures
Track failures, not just fixes. If the back door was propped three times this week, the finding is not "someone propped the door" — it is that your receiving workflow requires propping the door. Fix the workflow. Repeat failures are the highest-value signal in the weekly tier because they identify systems that are set up to fail rather than people who failed once.
Section 3 — The monthly audit
The monthly tier is where you stop reacting and start steering. This is analysis, not counting — the questions here are about direction, cause, and cost.
Shrink analysis and inventory variance
Calculate shrink as a percentage of sales, by category, and compare it to the previous month and the same month last year. A raw dollar figure is meaningless without that context; a $4,000 shrink month during your peak season may be excellent, while $1,200 in a slow month may be alarming.
| Metric | How to calculate | What it tells you |
|---|---|---|
| Shrink % | (Book inventory − physical inventory) ÷ net sales | Overall control health; compare month over month and year over year |
| Category variance | Variance by department in dollars and units | Where the loss actually lives — usually two or three categories carry most of it |
| Unit vs. dollar variance | Compare unit shortage to dollar shortage | High units/low dollars suggests operational error; low units/high dollars suggests targeted theft |
| Adjustment volume | Count and total of manual inventory adjustments | Whether inventory is being 'corrected' rather than reconciled |
| Receiving discrepancy rate | Discrepant deliveries ÷ total deliveries per vendor | Vendor reliability and dock-door exposure |
High-loss departments and category analysis
Rank departments by shrink dollars and by shrink percentage — they will not produce the same order. Then ask a specific question of the top two: is this category losing product, losing margin, or losing accuracy? Product loss points to theft or receiving. Margin loss points to markdowns, pricing, and discounts. Accuracy loss points to counting and system entry.
Vendor performance and receiving discrepancies
Score every vendor monthly on discrepancy rate, credit turnaround, damage rate, and substitution frequency. Two things happen when you present a vendor with three months of documented discrepancy data: the discrepancies decrease, and the ones that remain get credited. Vendors correct for the customers who count.
Training deficiencies and policy compliance
Map every finding back to a policy. If the policy exists and was not followed, that is accountability. If the policy does not exist, that is your failure, not theirs. If the policy exists but nobody can find it, it does not exist. Track who has been trained on what, and when — our LP Academy exists specifically so small teams have documented, role-appropriate training records without building a curriculum from scratch.
Corrective action plans and operational trends
Every monthly audit should end with no more than three corrective actions, each with a named owner, a specific action, a due date, and a verification date. Three actions completed beat fifteen actions listed. Then plot four to six months of your key metrics. Direction matters more than any single month — a store improving from 3.1% to 2.4% shrink is being managed well even if 2.4% is still above target.
Section 4 — How to investigate an exception
An audit finding is not a conclusion. It is a question. What separates a professional investigation from an expensive mistake is the order of operations — and almost every owner who has gotten this wrong got it wrong by talking to someone too early.
- Verify the data. Recount. Confirm the opening balance, the deposit, the system entry, and the date range. A meaningful share of "shortages" are arithmetic, timing, or a deposit that posted the next morning. Never proceed on an unverified number.
- Identify access. Who could have caused this? Not who would — who could. Build the list from schedules, logins, key assignments, and override rights. If the list is everyone, your first finding is a control problem.
- Determine the timeline. Establish the earliest moment the item or money was verified present and the earliest moment it was confirmed missing. Everything you investigate lives between those two timestamps.
- Preserve evidence immediately. Export video before it overwrites — most small systems retain 14 to 30 days. Save transaction detail, not summaries. Photograph physical evidence. Secure original paperwork. Evidence you meant to pull is evidence you do not have.
- Review transactions. Pull the operator's full transaction history for the window, not just the flagged items. Context is what distinguishes a pattern from a bad day.
- Review video against the transaction record. Match timestamps to specific transactions. Video without data shows activity; video with data shows intent.
- Interview only after the facts are assembled. Ask open questions, listen more than you speak, never accuse, never promise leniency, and never conduct the conversation alone or behind a locked door. Document what was said in the person's own words.
- Document findings objectively. Facts, dates, amounts, sources. No adjectives, no theories, no characterizations. Write it as though it will be read by an attorney, an insurer, and a judge — occasionally it will be. See our incident report template.
- Take corrective action. Coaching, retraining, procedural change, termination, restitution, or referral — but always paired with the control change that prevents recurrence. Removing a person without fixing the gap simply reassigns the opportunity.
- Follow up on a date you set now. Re-audit the same control in 14 and 30 days. Unverified corrective action is a wish.
For the behavioral side of this work — what actually precedes a case and what those signals do and do not prove — see 10 behavioral warning signs of employee theft.
Section 5 — Theft or operational failure?
This is the most consequential judgment an owner makes, and most get it backward. Industry experience consistently shows that a large share of what small retailers call theft is actually process failure — receiving errors, unlogged damage, pricing mistakes, spoilage, and untracked markdowns. Treating a process failure as theft costs you a good employee. Treating theft as a process failure costs you money indefinitely.
| Signal | Points toward operational failure | Points toward theft |
|---|---|---|
| Timing | Random across shifts, days, and people | Clusters on specific shifts, dates, or a single operator |
| Direction of variance | Both overages and shortages appear | Shortages only, rarely offset by overages |
| Product profile | Bulky, low-value, high-turn, damage-prone | Small, high-value, easily resold, concealable |
| Documentation | Missing or incomplete paperwork throughout | Paperwork complete and clean — but reality does not match it |
| Response to training | Variance drops after retraining | Variance drops briefly, then returns or changes method |
| Spread | Occurs across many employees performing the task | Follows one person across tasks, registers, or departments |
| Scale | Small, consistent, proportional to volume | Escalating over time |
Six causes explain nearly all of it: poor training (the employee never learned the correct method), poor procedures (the correct method does not exist or cannot be followed during a rush), vendor shortages (you paid for product that never arrived), administrative mistakes (price files, markdowns, unit-of-measure errors, duplicate receiving), employee theft, and external theft. Work them in that order. The first four are cheaper to fix and more common — and if you rule them out honestly, what remains is a much stronger case.
Treat as a pattern. Preserve data, review transactions and video for those shifts before any conversation.
Look at the procedure itself. A variance that follows the task, not the person, is a training or process defect.
Verify compliance. Was the step performed, skipped, or performed incorrectly? Coach and re-verify in 14 days.
You found a control gap, not a bad employee. Write the procedure before you assign blame.
Compare paperwork against physical count and system entry. The gap tells you where in the chain it broke.
Missing documentation is the finding. Nothing can be investigated until documentation is restored.
Section 6 — Building an audit system that survives December
Any owner can run a great audit week. The businesses that actually reduce loss are the ones still auditing during their busiest month, after a manager quits, in the middle of a remodel. Sustainability is a design problem, and it comes down to six things.
Consistency beats intensity
A ten-minute daily audit performed 300 times a year produces vastly more usable intelligence than a two-hour audit performed six times. Design the smallest program you will genuinely sustain in your worst week, and treat that as the floor. Expand only after 90 days of full compliance.
Documentation is the product
An audit that is performed but not recorded did not happen. There is no trend line, no accountability, and no defense if a decision is ever challenged. Same form, same fields, same place, every time — so a number from March can sit next to a number from September without translation.
Management accountability runs both directions
Managers audit employees; the owner audits the managers. Verify that the audits were actually performed and that findings turned into action. Unverified delegation is how audit programs quietly become paperwork rituals — sheets filled out at the end of the week from memory.
Trend analysis, not snapshots
One data point is trivia. Six months of the same measurement is management information. Keep a single running sheet of five numbers — shrink %, cash variance total, receiving discrepancy rate, exception outlier count, and open corrective actions — and review the line, not the dot.
Use the data to make decisions
Audit data should change something: a schedule, a layout, a vendor, a policy, an approval threshold, a training assignment. If six months of audits have not changed a single operating decision, you are collecting, not managing.
Continuous improvement
Review the audit program itself twice a year. Retire checks that never find anything, add checks where losses actually occurred, and adjust for seasonality, new products, and new staff. A static audit program eventually audits last year's business.
Section 7 — Where technology actually helps
Everything above can be done with paper, a binder, and discipline. I built my early career that way, and if paper is what you will actually use, use paper. But there are four places where the manual version reliably breaks down for a one-owner business, and those are the places where software earns its keep.
The first is recall. Paper stores information; it does not surface it. Nobody flips through nine months of till sheets to notice that one cashier's variances cluster on Sunday closes. The second is aggregation — connecting a receiving discrepancy to an inventory variance to an incident report requires those three records to live in the same place. The third is consistency across people and locations, where forms drift and standards quietly diverge. The fourth is follow-up, because corrective actions without automated reminders are the most-skipped step in loss prevention.
That is the specific gap My LP Portal was built to close for independent retailers. Scheduled audits and checklists that timestamp who completed what. Incident management that keeps documentation consistent and searchable. High-risk merchandise tracking that turns spot counts into trend lines. Receiving Intelligence that reads invoices, runs blind counts, and scores vendor reliability at the dock door. Heat maps that show where loss concentrates by location, department, and daypart. LP Academy for documented staff training. And Collin, an AI assistant that reviews your data, flags what looks unusual, and walks you through documenting an incident or structuring an investigation.
None of that replaces the judgment of the person who owns the store. It removes the clerical weight that causes audit programs to die in month three. Start with the schedule. Add the tooling when the schedule is real.

The Small Business Retail Loss Prevention Audit Manual
This article gives you the schedule. The manual gives you the entire system — expanded training material, real investigation walkthroughs, coaching scripts, decision trees, and 21 printable worksheets your managers can start using on their next shift.
- · How to build daily, weekly, and monthly audit routines that survive a busy season
- · How to investigate a shortage without accusing the wrong person
- · How to separate theft from operational failure using data
- · How to coach, document, and follow up defensibly
- · A 30-day implementation plan, week by week
- · Daily, Weekly & Monthly Audit Worksheets
- · Cash, Receiving & Inventory Audit Forms
- · Investigation Checklist & Evidence Collection Form
- · Corrective Action & Manager Review Forms
- · Shrink Analysis, Vendor Tracker, Annual Audit Planner
Completely free. One click. No email gate, no sales call, no trial required.
Once you know how to audit manually, the next question is who keeps track of it all
Every process in this guide works on paper. The hard part was never performing the audit — it was remembering the pattern six months later, connecting a receiving shortage to an inventory variance, and making sure the corrective action from March actually got verified. That is bookkeeping for your controls, and it is the part a single owner realistically cannot carry alongside everything else.
My LP Portal keeps that record for you: audits and checklists, incident management, high-risk merchandise tracking, Receiving Intelligence, loss heat maps, LP Academy training, and Collin, your AI loss prevention assistant. Built for independent retailers who never had a loss prevention department and were never supposed to fight this alone.
Frequently asked questions
What is a retail loss prevention audit?+
A loss prevention audit is a scheduled, documented review of the controls that protect cash, inventory, and information inside a store. It verifies that procedures are actually being followed — opening and closing steps, till counts, receiving checks, refund approvals, high-risk product counts — rather than assuming they are. The audit produces a record, and that record is what makes patterns visible over time.
How often should a small retail business run audits?+
Use three tiers. Daily audits cover cash, receiving, and store condition — the fast-moving items where a loss can occur and disappear within hours. Weekly audits cover exception data such as refunds, voids, and discounts, plus cycle counts on high-risk merchandise. Monthly audits cover shrink analysis, category variance, vendor performance, policy compliance, and corrective action follow-up.
How long should a daily store audit take?+
A well-designed daily audit takes 15 to 25 minutes total, spread across the day: five minutes at open, five to ten minutes during a manager walkthrough, and ten minutes at close. If your daily audit takes an hour, it is not a daily audit — it is a monthly audit you are trying to run every day, and it will be abandoned within two weeks.
What is the difference between shrink and operational loss?+
Shrink is the gap between what your records say you own and what you physically have. Operational loss is one of its causes — damage that never got logged, receiving shortages that were never claimed, markdowns entered incorrectly, spoilage, and pricing errors. Theft is another cause. Most small businesses assume shrink is theft when the majority of it is usually process failure that nobody documented.
Should I tell employees I am running audits?+
Yes. Announce the audit program, not the audit schedule. Employees should know that till counts, cycle counts, and receiving checks happen regularly and randomly. That knowledge alone removes opportunity. What should never be predictable is the timing — a Tuesday-at-2 p.m. audit protects nothing.
What should I do when an audit turns up a shortage?+
Verify the data before you act. Recount, confirm the starting balance, check for a missed transaction, a misplaced deposit, or a manager override. Only after the number survives verification do you look at access, timeline, and transaction history. Most first-time shortages resolve into an operational explanation, and a manager who accuses before verifying loses the room permanently.
Can one person run a loss prevention audit program?+
Yes — that is exactly who these schedules are built for. The constraint is not staffing, it is consistency. A ten-minute audit performed every day for a year produces more usable intelligence than a four-hour audit performed twice. Build the smallest program you will genuinely sustain, then expand it.
Do audits mean I do not trust my employees?+
No. Audits protect honest employees more than anyone else. Without documentation, a shortage becomes a guessing game and suspicion lands on whoever people already dislike. With a documented audit trail, the record shows who had access, what happened, and when — which is how good employees get cleared and how real problems get identified without a witch hunt.
Related reading
- Retail Store Daily Audit Checklist Template
- How to Conduct a Random Till Audit
- How to Identify Cash Register Theft
- 10 Behavioral Warning Signs of Employee Theft
- Sweethearting: The Complete Guide
- Coaching & Documenting Operational Errors
- Opening & Closing Procedures That Reduce Theft
- Receiving Intelligence: Stop Loss at the Dock Door
Run all of this inside one place
My LP Portal turns checklists, audits, incidents, and trackers into a single working system — built for small business owners. Free to start.
