Field Notes

Shared POS logins and what auditors can still prove

“Everyone uses the same code” is the sentence we hear most on first visits. It frustrates owners who want a named person behind every void. It also frustrates auditors who cannot attribute a ticket to an individual.

What we can still show

Even with shared logins, a financial audit of point-of-sale applications can document:

  • Which privileged functions exist and who could reach them
  • Time clusters when voids spike relative to trading
  • Whether the application retains device IDs or shift IDs separate from the user name
  • Whether end-of-day close can complete without a cash count acknowledgment

That is enough to write a control finding. It is rarely enough to name a thief, and we do not pretend otherwise in the report.

What we ask clients to change first

Create distinct IDs for supervisors even if cashiers share a basic rung-up profile. Disable dormant accounts after staff turnover — a frequent gap in resort shops with seasonal hiring. Then reconsider dual approval for refunds above a threshold your margin can absorb.

A cash control walkthrough is often the right first engagement when logins are tangled; a full audit can follow once identities exist to test.

← Back to Field Notes