Run a restaurant

The 11 restaurant scams, and how owners catch them

The 11 ways staff skim from Indian restaurants, voided bills, ghost KOTs, stock walking out, and the controls that catch every one.

CountStand Team · Restaurant operations researchUpdated 2026-07-1213 min readDraft pending CA review, verify specifics with your advisorHow we research
The short answer

Industry rules of thumb put unchecked staff theft and pilferage at 2–5% of an Indian restaurant's revenue, ₹1–2.5 lakh a year on a ₹50L outlet. The 11 scams below range from cancelled-KOT cash pocketing to the offline-bill memory wipe, and every one is catchable by the same loop: attributed audit trails plus weekly ingredient-level variance against sales.

How much is theft actually costing you?

Start with the arithmetic, because it is worse than it feels. The industry rule of thumb, repeated by auditors, consultants and every honest operator who has measured it, is that un-instrumented leakage runs 2–5% of revenue. On a ₹50 lakh-a-year outlet that is ₹1–2.5 lakh, every year, invisibly. On margins where a well-run restaurant nets single digits, the leak can be a third of your profit.

Two things make it invisible. First, it is rarely one villain, it is many small mechanisms, each too small to notice: a cancelled KOT here, a shaved portion there, an inflated invoice monthly. Second, the person best positioned to steal is usually the person you rely on most, and suspicion without measurement poisons the whole team.

So say the honest thing up front: most staff do not steal. Systems exist to protect the honest majority as much as to catch the rest, because when ₹40,000 goes missing and there is no data, everyone is a suspect. If you already track food cost and variance, you have half the machinery; this guide adds the other half.

What are the 11 scams, and how do you catch each one?

The lift-and-keep version first. Every scam below follows the same anatomy: a gap between what happened and what got recorded.

#ScamThe tellThe control
1Cancelled-KOT pocketingCancellations spike on one cashier or shiftCancels need approval, attributed log, daily report
2Void-after-paymentVoids cluster after settlementSettled bills immutable; voids need reason + PIN
3Offline-bill memory wipeRepeated "internet down" shifts with soft salesSequence-numbered offline outbox that survives sync
4Reprint resaleHigh reprint counts per cashierReprints watermarked, logged, attributed
5Free plates for friendsIngredient use exceeds billed salesNo KOT, no food, staff meals included
6Under-ring / over-chargePrice overrides, open items, handwritten billsLocked menu prices; printed bill for every sale
7Portion skimmingPlates run light; usage drifts from recipesWeighed portions, random plate audits
8Raw-material walkoutsVariance on high-value SKUsWeekly counts of top-value items, goods-out register
9Vendor collusionRate creep, invoice vs delivered quantity gapsDual quotes, goods-received checks, rate cards
10Bottle swapping at the barSales per opened bottle drops on certain shiftsMeasured pours, marked bottles, per-peg variance
11Discount-code abuseDiscounts cluster on one user, on cash billsDiscount caps, approvals, day-close report by user

Now each one properly.

1. Cancelled-KOT pocketing

How it works: the order is taken, the KOT fires, the kitchen cooks, the customer pays cash, then the cashier cancels the order in the system. The food went out, the money came in, the record disappeared. The tell: cancellation counts by user and by shift. An honest operation cancels rarely and randomly; this scam cancels often and in a pattern, usually after the food was fired. The control: cancellations after firing require a manager PIN and a reason, and land in an attributed daily report. Good KOT software makes the cancel trail impossible to avoid.

2. Void-after-payment

How it works: the bill is settled in cash, and later, end of shift, quiet hour, it is voided or edited down. Cash drawer matches the doctored record. The tell: voids clustered after settlement time, or a drawer that reconciles too perfectly, night after night. The control: a settled bill becomes immutable; any void creates a new attributed event with a reason, and the day-close lists every one, by user, with amounts.

3. The offline-bill memory wipe

This one deserves depth, because it defeats most POS systems in India as they are actually deployed.

How it works: the staff member disconnects the internet, router switched off, cable pulled, hotspot exhausted, whatever looks plausible. The POS keeps billing in offline mode, as it should. Orders are punched, food is served, cash is collected. Then, before reconnecting, the offline bills are destroyed: app data cleared, local cache wiped, sometimes the terminal simply restarted on systems that hold offline bills only in memory. When the connection returns, there is nothing to sync. The kitchen cooked all evening; the record shows a dead shift. The internet outage even provides its own alibi.

The tell: repeated connectivity failures on the same shifts or under the same staff; recorded sales that dip on exactly those windows while purchase and prep levels stay normal; a paper KOT trail (if you have one) that outruns the billed total; and, on systems that number bills, gaps or resets in the bill sequence.

The control: this scam cannot be fixed with vigilance, because it attacks the record itself. It has to be fixed in architecture. CountStand was built offline-first precisely for Indian connectivity, and the design closes this hole: every bill is written to a durable local outbox with a monotonic sequence number the moment it is created, attributed to the logged-in user and device. The KOT event, the kitchen-display ticket, the inventory deduction and the bill all share one order ID. Erase the bills and you have not erased the evidence, you have created it: the server flags the hole in the sequence at next sync, the day-close refuses to reconcile, and the orphaned kitchen and inventory events point at exactly the window that "disappeared," with a name attached. A wipe that used to make sales vanish now produces an alert that says who, when and roughly how much.

4. Reprint resale

How it works: one bill is printed twice and presented to two different cash-paying customers; one payment reaches the register, one reaches a pocket. The tell: reprint counts by cashier, legitimate reprints are rare. The control: every reprint is watermarked DUPLICATE, logged and attributed, and shows in the day-close.

5. Free plates for friends

How it works: food leaves the kitchen with no KOT at all, friends, family, or a side arrangement. The tell: you cannot see it in billing, because it never touched billing. You see it in variance: ingredients consumed exceed what sales say should have been consumed. The control: an absolute no-KOT-no-food rule, including staff meals, which get their own coded (free) KOT so they are visible instead of invisible.

6. Under-ring and over-charge

How it works: two flavours. Under-ring: the customer pays for the biryani, the system rings a soft drink; the difference is pocketed. Over-charge: the customer pays above menu price on a handwritten or verbal total. The tell: price overrides and open-item usage in the logs; handwritten bills existing at all. The control: menu prices locked in the POS, open items disabled or approval-gated, and a printed, numbered bill for every sale, no exceptions, which is also, not coincidentally, what GST compliance expects (see the GST guide).

7. Portion skimming for resale

How it works: the kitchen plates 20% light all evening; the skimmed surplus goes home or out the back. Customers get shorted, and stock records look almost normal. The tell: recipe compliance drifting, plates that weigh light on spot checks, complaint patterns on portion size, usage that undercuts recipes and then corrects suspiciously. The control: gram-level recipe cards, portion tools sized to them, and random plate weighs. Weekly ingredient-level variance closes the loop: surplus that walks out shows up as usage the sales cannot explain.

8. Raw-material walkouts

How it works: the oldest one, paneer, chicken, ghee, oil and liquor leaving in bags. The tell: variance concentrated on the highest-value SKUs, and purchase frequency rising while sales stay flat. The control: weekly (not monthly) counts of your top ten value items, a goods-out register, and an inventory system that deducts stock at the moment of sale so the count has an honest baseline.

9. Vendor collusion and invoice inflation

How it works: the purchase manager and a supplier agree on inflated rates or billed-but-undelivered quantity, and split the difference. This is often the largest single leak, and it never touches the POS. The tell: rate creep against market prices, one supplier quietly winning everything, invoice quantities that do not match what the kitchen received. The control: dual quotes on the top-spend ingredients, a goods-received check against every invoice line, rate cards maintained in the inventory system, and rotating who receives deliveries.

10. Bottle swapping at the bar

How it works: staff bring their own bottle, pour it as house liquor, and pocket the sales; your stock is untouched while your revenue is served to customers. The tell: sales per opened bottle dropping on particular shifts; peg counts that do not reconcile with bottle depletion. The control: measured pours, sealed and marked bottles checked at shift change, and per-peg variance run weekly like any other ingredient.

11. Discount-code abuse

How it works: real discounts applied to full-paying customers, the guest pays ₹500, the system records a 20% "loyalty" bill, the difference is pocketed. The tell: discount percentage by cashier, discounts clustering on cash payments and near shift-end. The control: discount caps per role, approval above a threshold, and a day-close report listing every discount by user and reason.

Why do cameras alone fail?

Cameras earn their keep against walkouts and back-door traffic. But look back at the list: at least seven of the eleven scams look completely normal on camera. A cancelled KOT is a person tapping a screen. An under-ring is a smiling transaction. The memory wipe looks like a staff member restarting a hung terminal. Nobody reviews twelve hours of footage a day, and staff learn the blind spots within a month anyway. Cameras answer "what happened in this incident"; they cannot answer "is something happening", that question is only answerable in data.

How does the variance method catch what cameras miss?

The loop is the same one that controls food cost, pointed at a different suspect:

  1. Recipes define what each sold dish should consume, at gram level.
  2. Deduction at sale turns every bill into a theoretical stock movement, automatically.
  3. Weekly ingredient-level variance compares theoretical against physical counts, in rupees, per ingredient.
  4. Attributed exception reports, cancels, voids, reprints, discounts, offline windows, land in the day-close with names.

A typical variance flag reads like this: week 2, chicken, 2.3 kg unaccounted against sales; check Friday and Saturday dinner shifts. Notice what that flag does: it names the ingredient, sizes the leak in something you can price, and narrows the window before you have asked a single person a single question. Most scams on the list survive exactly as long as nobody is looking at this number; they end the week it exists.

This loop is precisely what CountStand automates rather than asks you to run by hand. CountStand is an AI-native restaurant operating system for India, offline-first billing, KDS, inventory, GST & compliance, and an autonomous AI manager, in one platform, from ₹999/mo per outlet. Recipes deduct stock at billing, the variance report prices every gap weekly, every cancel, void, reprint and discount carries a name and a timestamp in the day-close, and the offline outbox described above makes the memory-wipe scam structurally impossible rather than merely risky. Put your own numbers through the food cost calculator to see what a 2–5% leak means on your revenue, then decide whether measuring it weekly is worth fifteen minutes.

How do you build controls in 2026 without destroying trust?

The failure mode of anti-theft work is a paranoid owner and a demoralised team, which costs more than the theft did. What experienced operators do differently:

  • Announce the system, openly. Controls installed in secret read as accusation; controls announced read as professionalism. "Every bill is numbered, every void is logged, variance runs weekly", said once, to everyone, on day one.
  • Let the data ask the questions. Never accuse from a hunch. A variance flag is a question ("help me understand Friday"), not a verdict.
  • Make the honest path easy. Official, coded staff meals. A real process for genuine cancellations. Fair wages paid on time, underpaid and resentful is how rationalisation starts.
  • Close the loop publicly on clean weeks. A zero-variance week is worth saying out loud.
  • When you do catch someone, act on evidence, calmly. Attributed logs and priced variance make the conversation short and factual. For anything beyond dismissal, take proper legal advice rather than improvising.

The weekly 15-minute audit checklist

Run this once a week, same day, every week, the consistency is the deterrent:

  1. Cancels and voids by user, anything clustering?
  2. Reprints and discounts by user, same question.
  3. Offline windows, when, which terminal, do billed sales during them look normal?
  4. Bill sequence, continuous, no gaps or resets?
  5. Variance on your top ten value ingredients, in rupees.
  6. Sales per opened bottle, if you pour liquor.
  7. Purchase rates on the five biggest spend lines vs last month.
  8. One random plate weighed against its recipe card.

Fifteen minutes, because the system did the collection for you. If your current setup makes any of these eight take longer than two minutes each, that is a tooling problem, see it working in a demo.

How do I know if my restaurant staff are stealing?

You do not know from instinct, you know from gaps: ingredient-level variance between what sales say you used and what stock counts show, cancels and voids clustered on specific users or shifts, sales dips during internet-down windows, and purchase costs creeping while sales stay flat.

What percentage of revenue do restaurants lose to theft?

The industry rule of thumb is 2–5% of revenue for outlets without audit trails and variance tracking, roughly ₹1–2.5 lakh a year on a ₹50 lakh outlet. Instrumented restaurants run far lower; cash-heavy outlets without controls can exceed it.

Can CCTV alone stop restaurant theft?

No. Cameras deter physical walkouts, but most theft happens inside the billing system, cancelled KOTs, voids, under-rings, discount abuse, and looks completely normal on video. The working combination is cameras plus attributed POS logs plus weekly variance.

What is the offline bill wipe scam?

Staff disconnect the internet, bill in offline mode, collect cash, then clear the system memory before reconnecting, the offline bills never sync and the sales never existed. The fix is architectural: durable, sequence-numbered offline storage with attributed sync, where a wiped bill leaves a visible gap instead of a clean shift.

Should I confront an employee I suspect of stealing?

Not on suspicion alone. Gather attributed evidence first, logs, variance, dates and amounts, then have a calm, factual conversation. For termination or recovery beyond dismissal, take proper legal advice for your state.

Suspicion is not a system

CountStand’s variance reports and attributed audit trails catch every one of the 11, with names and amounts.

30-day free trial · No card · From ₹999/mo per outlet