Field Notes
Shared POS logins and what auditors can still prove
“Everyone uses the same code” is the sentence we hear most on first visits. It frustrates owners who want a named person behind every void. It also frustrates auditors who cannot attribute a ticket to an individual.
What we can still show
Even with shared logins, a financial audit of point-of-sale applications can document:
- Which privileged functions exist and who could reach them
- Time clusters when voids spike relative to trading
- Whether the application retains device IDs or shift IDs separate from the user name
- Whether end-of-day close can complete without a cash count acknowledgment
That is enough to write a control finding. It is rarely enough to name a thief, and we do not pretend otherwise in the report.
What we ask clients to change first
Create distinct IDs for supervisors even if cashiers share a basic rung-up profile. Disable dormant accounts after staff turnover — a frequent gap in resort shops with seasonal hiring. Then reconsider dual approval for refunds above a threshold your margin can absorb.
A cash control walkthrough is often the right first engagement when logins are tangled; a full audit can follow once identities exist to test.