1. User roles and permissions on the POS
Most modern POS systems support role-based logins. If every employee shares one login or one PIN, there is no way to know who did what, which makes every other control on this list weaker.
Individual logins
Every employee has a unique login or PIN β never a shared one β so actions are attributable to a person.
Role-based permissions
Cashiers, shift leads and managers have different permission levels for discounts, voids, refunds and price overrides.
Remove access promptly
Disable a former employee's login the same day they leave, not at the next system review.
Review admin accounts
Confirm only the people who should have full administrative access still have it.
2. Void, refund and discount controls
These three actions are the most common vector for internal loss because each one moves money or inventory without a corresponding sale.
Manager approval on voids and refunds
Require a manager PIN or approval step above a set threshold, and for any refund without a matching original sale.
Discount limits by role
Cap the discount percentage a cashier can apply without escalation.
Reason codes
Require a reason to be selected for voids and refunds so patterns can be reviewed later, not just totals.
Same-day review
Have a manager glance at the day's voids and refunds before close, not just at month end.
3. Cash-drawer and no-sale monitoring
Cash-adjacent activity on the POS β no-sale openings, drawer counts, paid-outs β is worth watching even in a mostly card-based business, since patterns here often reveal broader process gaps.
No-sale tracking
Review how often and by whom the drawer is opened without a sale attached.
Drawer counts at shift change
Count and log the drawer at every shift change, not just at open and close.
Paid-out approval
Require manager approval for any cash paid out of the drawer.
4. Receipt and descriptor hygiene
A clear, recognizable receipt and billing descriptor reduces both customer confusion and the number of avoidable disputes that start as a simple 'I don't recognize this charge.'
Recognizable descriptor
Confirm the name on the customer's card statement clearly matches your business name and location.
Complete receipts
Include the business name, date, amount, last four digits of the card and a support contact.
Duplicate copies
Keep an accessible transaction record so a receipt can be reissued if a customer disputes an unrecognized charge.
5. Device tampering and skimming inspection
Physical tampering with a terminal or card reader is less common than online fraud but can go undetected for a long time in a busy, high-traffic location.
Daily visual check
At open, check that terminals match their usual appearance β no added attachments, loose seams or extra cables.
Tamper-evident seals
Where supported by the device, check any tamper seals and note the serial number periodically.
Secure mounting
Bolt or cable-lock countertop devices so they cannot be swapped out unnoticed during a busy shift.
Report immediately
Any sign of tampering should be reported to your processor and hardware provider right away, and the device taken out of service.
6. Staff onboarding and offboarding
Most POS-related risk enters or exits with staff turnover. A short, repeatable process at both ends closes the most common gap.
Onboarding
Assign the correct role and permissions on day one, and walk through void, refund and discount procedures before their first shift alone.
Offboarding
Disable POS access, change shared safe or drawer codes if any exist, and confirm no lingering admin sessions on shared devices.
7. Periodic report reviews
None of the controls above matter if nobody looks at the reports they generate. Set a recurring cadence β weekly is reasonable for most small businesses β to review the numbers, not just react when something feels off.
Voids, refunds and discounts by employee
Look for outliers, not just totals β one person repeatedly near a threshold is worth a conversation.
No-sale and paid-out activity
Compare week to week for unexplained increases.
Chargeback and dispute volume
Track trends over time, not just individual cases, to catch a process problem early.
Frequently asked questions
What is the single most impactful control on this list?
Individual staff logins with role-based permissions. Nearly every other control depends on being able to attribute a void, refund or discount to a specific person.
How often should we review POS reports?
Weekly is a reasonable cadence for most small businesses, with a lighter daily glance at voids and refunds before closing out.
Do we need this checklist if we rarely handle cash?
Yes. Void, refund, discount and permission controls matter regardless of tender mix, and device tampering checks apply to any physical terminal.
What should we do if we find a tampered terminal?
Take the device out of service immediately and contact your processor and hardware provider. Do not attempt to use or move the device further until it has been assessed.
Can our POS reporting help with chargeback responses too?
Often yes. Clean records of transactions, refunds and staff activity support both fraud monitoring and any evidence you may need to submit for a dispute.
Where can I see what reporting tools are available for my POS?
BSV Solution can walk through the reporting available on your current or a new POS setup, including role permissions and activity tracking, as part of an account review.
Want a second opinion on your setup?
Tell us how you take payments today and a BSV Solution specialist will walk through the options with you. Eligibility and processor selection are reviewed individually, subject to underwriting approval.