Void and refund fraud: how AI video + POS checks can catch it

Void and refund fraud is cashier theft hidden behind two everyday POS functions: a paid sale is voided or deleted after the customer leaves, or a refund is rung up with no customer and nothing returned, and the cash is taken while the drawer still balances. It can be caught by checking each void and refund in the POS log against the register camera at the same moment: AI video built on vision-language models sees whether the sale was paid and handed over, and whether anyone was at the counter when the refund was entered.

What void and refund fraud is

Void and refund fraud is a group of cashier schemes that use two legitimate POS functions — the void and the refund — to make cash that really came in look as if it never came in, or as if it was paid back out. Because the POS record is changed to match the missing cash, the drawer still balances at close and over/short reports stay clean. It takes four forms.

Void after payment

A customer orders, pays cash and leaves with the goods. A few minutes later, once the counter is quiet, the cashier opens the closed ticket and voids it. In the POS the sale now never happened, so the cash it brought in is surplus in the drawer. At some point that surplus leaves with the cashier, and the drawer still balances at close. In stores this is also called a post-void.

Deleted orders

At restaurant, café and quick-service counters the same move shows up as a deleted order: the order is paid at the counter and handed over, then the ticket is deleted from the POS before the shift closes. Where the POS allows lines to be removed from a closed ticket, part of a paid sale can disappear instead of all of it.

Fake refunds with no customer

The counter is quiet. The cashier opens a return on the POS — against an old receipt, or as a no-receipt return — picks a few items and chooses a cash refund. The drawer opens and the refund is counted out, but nobody is there to take it. On paper the store gave money back for goods that came back; in reality, no customer came and nothing came back. Variations include refunding a real earlier sale to a card the employee controls, or adding items to a real return so it pays out more than the customer received.

This is different from customer return fraud, such as returning worn, stolen or counterfeit goods. There the merchandise does come back across the counter. With a fake refund by staff, the person entering the refund is the one who keeps the money, and nothing comes back at all.

Manager-code abuse

Many POS setups require a manager override for voids and refunds. That control is weaker than it looks. When a manager's code is shared, written down or entered on request without a look at the transaction, an approved void or refund says little about who decided it. And when the manager is the one running the scheme, the approval is their own.

Schemes like these fit what the Association of Certified Fraud Examiners (ACFE) calls register disbursements: false entries on a cash register that conceal the removal of cash. Its own example is an employee who "fraudulently voids a sale on a cash register and steals the cash"; a fake refund fits the same definition. The cash may leave the drawer later, during a no-sale drawer opening or at the end of the shift.

Why traditional methods miss void and refund fraud

Voids and refunds are a normal part of every shift. A customer changes their mind, an item is rung twice, the kitchen can't make an order, a real return comes in. In the transaction log an honest entry and a fraudulent one look the same: a ticket or return number, a time, an amount, an employee ID and maybe a manager override.

  • POS exception reports give a count without context. Void and refund reports show how many, how much and by whom. They can't show whether the customer was still at the counter, whether the goods came back, or whether the money had already changed hands. Because the record was changed to match the cash, the drawer reconciles, and a cashier who voids one or two paid tickets a shift rarely stands out across many registers and stores.
  • The paperwork looks right. A fake refund can reference a real earlier sale and real items, so it passes a receipt check. If the "returned" items are restocked in the system, the gap surfaces weeks later as inventory shrink, far from the register where it happened.
  • Manual CCTV review doesn't scale. To check a single void, someone has to find the right camera, the right minute and watch what happened before it. Across every register, every shift and every store, that review happens only after a loss is already suspected — if at all. The camera is usually recording; the footage is rarely watched.
  • Classic object detection sees objects, not actions. A detector can say that a person is at the counter or that an item is on it. It can't say that cash was handed over and the order went out the door, or that nothing came across the counter for a refund — and it doesn't know what the POS just recorded.

Exception reports are good at telling you where to look. They can't tell you what happened. That answer is in the video at the register, at the moment the void or refund was entered.

How vision-language models make it solvable

Primarch builds on and enhances vision-language models (VLMs): models that read video and language together. That changes what can be checked at the register. Instead of detecting objects frame by frame, the model reads a scene the way an experienced loss-prevention auditor would — and does it at every register, every hour.

  • It understands the action, not just the objects. A VLM reads a window of time, not a single frame, so the before and after of an action are read together. It can recognize that a sale was paid and the order handed over before a void, or that a refund was entered while no one was at the counter and nothing came across it.
  • It joins the video moment with the POS line. Each void and refund in the transaction log is matched with what the camera at that register shows in the same second. The log says what was recorded; the video says what happened. A camera alone produces suspicion; with the POS it produces evidence.
  • It writes the finding in plain language, with a clip. The result is not a label or a score but a sentence a manager can read — what happened, at which register, and why it doesn't match the log — with a time-stamped evidence clip and the matching transaction line.
  • It chains repeated events into patterns. Events are linked by store, register, cashier and hour into 30-day patterns. One void can be a mistake; the same pattern at the same register and hour, week after week, is worth a closer look.

For a void, the question is: was this sale paid and handed over before it was voided? For a refund: was anyone at the counter, and did anything come back? Both answers are in the video at the moment the POS entry was made.

What to look for in a solution

Whichever vendor you talk to, these are fair questions to ask about a system meant to catch void and refund fraud:

  • Works on your existing cameras. Can it connect to the IP cameras you already have, or does it need new hardware at every register?
  • Integrates with your POS transaction log. Voids, refunds and overrides live in the log; a camera-only system can't tell an honest void from a false one. Ask which POS exports it can read and how the integration is validated.
  • Produces evidence usable in HR processes. A time-stamped clip together with the matching transaction line, so a finding can be reviewed and discussed fairly — not a bare alert.
  • Respects privacy. Is there an on-premise option where footage never leaves the site? Is anonymization applied, is analysis limited to the checkout zone, and does it meet GDPR and other data-protection requirements?
  • Can be piloted on your own footage. Your registers, camera angles and POS — not a demo video.
  • Handles false alarms openly. Many voids and refunds are honest. Ask how findings are reviewed by a person, and how single events are separated from repeating patterns.
  • Gets alerts to the right role. An instant alert to the store manager, a digest for loss prevention, a dashboard for area and head-office teams — each person sees what they need to act on.

Example use cases

The walk-throughs below are illustrative examples of how a finding is built. They are not customer cases and contain no performance figures.

Example 1: a paid takeaway order voided after the customer leaves

  1. 01

    Moment

    A café counter, 14:12 on a weekday.

  2. 02

    What the camera shows

    The customer pays cash, the cashier puts it in the drawer and hands over the order. The customer leaves. At 14:19 the counter is empty; the cashier is at the terminal and nothing comes back across the counter.

  3. 03

    What the POS log shows

    Ticket closed with a cash tender at 14:12; the same ticket voided at 14:19 under the cashier's ID.

  4. 04

    The finding + evidence clip

    "The ticket was paid in cash and the order handed over at 14:12. It was voided at 14:19 with no customer at the counter and no goods returned." The clip covers payment, handover and the void, with the matching transaction lines.

  5. 05

    Who is alerted

    The store manager receives an instant alert; the finding also appears in the loss-prevention team's weekly digest.

  6. 06

    What the 30-day pattern shows

    Similar flagged voids at the same register fall in the quiet hour after lunch, on the same cashier's shifts.

Example 2: a cash refund at a boutique with no one at the counter

  1. 01

    Moment

    A fashion boutique, 16:40, between customers.

  2. 02

    What the camera shows

    No customer at the register. The cashier is at the terminal; nothing is placed on the counter and no item or bag comes across it.

  3. 03

    What the POS log shows

    A no-receipt return for two items with a cash tender at 16:40.

  4. 04

    The finding + evidence clip

    "A cash refund for two items was entered at register 1 at 16:40. No customer was at the counter and nothing was on it." The clip and the refund line are attached.

  5. 05

    Who is alerted

    The store manager, instantly; loss prevention in the periodic digest.

  6. 06

    What the 30-day pattern shows

    Asked in plain language — "show refunds flagged at register 1 in the last 30 days" — the event memory returns a short list, all on the same weekday afternoon shift.

Example 3: a deleted restaurant order approved with a manager code

  1. 01

    Moment

    A quick-service counter, 22:35, near closing.

  2. 02

    What the camera shows

    Earlier, at 22:05, a customer paid in cash and took the order away. At 22:35 the counter is empty and no order comes back.

  3. 03

    What the POS log shows

    The 22:05 ticket deleted at 22:35, with the store manager's override code on the entry.

  4. 04

    The finding + evidence clip

    "The order was paid and handed over at 22:05. The ticket was deleted at 22:35 with a manager override; no customer or returned order was present." Clip and transaction lines attached.

  5. 05

    Who is alerted

    Set up to reach the area manager's dashboard and weekly digest: when the store manager's own code is on the entry, the review belongs one level up.

  6. 06

    What the 30-day pattern shows

    Flagged deletions at this counter cluster in the last hour of the evening shift. Each comes with its clip, so the area manager can review the moment every override was entered.

Example 4: a refund at a drive-thru window

  1. 01

    Moment

    A drive-thru window with a camera that covers the window, 19:10. Drive-thru coverage depends on camera placement and is confirmed per site.

  2. 02

    What the camera shows

    No vehicle or customer at the window; nothing is handed in or out.

  3. 03

    What the POS log shows

    A refund against an earlier order with a cash tender at 19:10.

  4. 04

    The finding + evidence clip

    "A cash refund was entered at the drive-thru register at 19:10 with no customer at the window." Clip and refund line attached.

  5. 05

    Who is alerted

    The shift manager on duty, instantly.

  6. 06

    What the 30-day pattern shows

    Whether refunds with no customer at the window repeat at the same hour or on the same cashier's shifts — or stay a one-off with an innocent explanation.

How Primarch's Retail Fraud Expert helps

This section is about our product. The Retail Fraud Expert is the Primarch expert module for the checkout. It recognizes actions at the register — scan, skip, void and refund — and cross-checks each one against the POS record in the same second. For void and refund fraud it:

  • Recognizes on video that a sale was paid and handed over before it was voided — whether a ticket is voided in a store or an order is deleted at a restaurant or quick-service counter.
  • Checks whether a customer is at the counter or window when a refund is entered, and flags a return entered with nothing on the counter. At drive-thru windows this depends on camera placement and is confirmed per site.
  • Matches back-to-back voids, no-sale drawer openings and discount-key anomalies with the motion on camera.
  • Chains events by store, register, cashier and hour into 30-day patterns: single events are alerted for review, and the 30-day patterns show what repeats, so a single event isn't treated as a verdict.
  • Produces an evidence file for each finding: a time-stamped clip plus the POS record, usable in HR processes.

It works at restaurant and quick-service counters and in any store with a register — coffee shops, fashion and luxury boutiques, souvenir shops, bookshops. The same camera + POS check also applies to missed scans and sweethearting. For a sector view, see restaurant and café loss prevention and retail store loss prevention.

Putting it to work

  1. 01

    Connect

    Connect your existing RTSP cameras and the POS transaction log export; no new cameras or special hardware. It is designed to work with any common POS system that can export transaction logs; the integration is validated together during the pilot.

  2. 02

    Pilot on your own footage

    Run it on your own registers, camera angles and POS data, and review the findings together.

  3. 03

    Roll out

    Extend to more registers and stores, with central monitoring across the chain.

  • Alerts, digests and dashboards. Instant notifications, periodic digests and role-based dashboards, so each finding reaches the person who acts on it.
  • Ask the past in plain language. Findings are written into a queryable event memory: "Which refunds were flagged at register 2 last week?"
  • Evidence for HR. Every finding carries its time-stamped clip and the matching transaction line.
  • Privacy by design. With on-premise deployment, footage never leaves the facility. Analysis focuses on the checkout zone with privacy-compliant anonymization; the goal is action–transaction consistency, not tracking people.

Industry figures

There is no reliable public figure for void or refund fraud on its own. The closest published data covers register disbursement schemes as a whole — the ACFE category these schemes fit — and does not break out employee voids or refunds.

5%

of revenue lost to fraud each year, as estimated by Certified Fraud Examiners[1]

17 months

median time a register disbursement scheme runs before it is detected[1]

A scheme that keeps the drawer balanced can run for more than a year at the median. Checking each void and refund against the footage means every one can be reviewed against what actually happened at the register; repeats at the same register and hour stand out as a pattern.

Frequently asked questions

What is void and refund fraud?

It is cashier theft hidden behind voids and refunds in the POS: a paid sale is voided or deleted after the customer leaves, or a refund is entered with no customer and no returned goods, and the cash is taken. Because the POS record matches the missing cash, the drawer still balances.

Is every void after payment, or every refund without a customer, fraud?

No. Many voids and refunds are honest: a changed order, a double ring, an online or phone order, a correction to an earlier transaction. What separates fraud is the context — a paid, handed-over sale followed by a void, or a refund with no one at the counter and nothing coming back. That is why each entry has to be checked against the video and the store's own rules, and why repeated patterns matter more than a single event.

Why don't POS void and refund reports catch it?

They show counts, amounts and employee IDs, not what happened at the counter. Because the void or refund also lowers the cash the POS expects, the drawer reconciles and over/short reports stay clean.

Doesn't a manager override prevent it?

Not reliably. When codes are shared or entered on request, an approved void or refund says little about who decided it, and a manager running the scheme approves their own entries. Checking the entry against the video works the same way with or without an override.

Do we need new cameras or a new POS?

No. Primarch's Retail Fraud Expert connects to existing RTSP cameras. It is designed to work with any common POS system that can export transaction logs, and the integration is validated together during the pilot.

Does it work in restaurants and at drive-thrus?

Yes at restaurant and quick-service counters, where a paid order that is deleted is checked the same way as a voided ticket. At drive-thru windows it depends on camera placement and is confirmed per site.

Sources

  1. [1] ACFE, Occupational Fraud 2024: A Report to the Nations — accessed 2026-10-07

Related scenarios

READY?

Ready to make your cameras think?

A 15-minute live demo — with a scenario tailored to your industry.