Skip to main content
POS anomaly detection for jewelers: rule set, weekly triage and investigation logs to spot internal fraud

POS anomaly detection for jewelers: rule set, weekly triage and investigation logs to spot internal fraud

A tight playbook for catching voids, discount abuse, rapid returns and the ring-void combo before they bleed your margin

Most jewelry theft doesn't look like a smash-and-grab. It looks like a clean receipt. A void here, a "friends and family" discount there, a return processed at close when nobody's watching the register. Individually, each transaction passes the sniff test. Stacked over a quarter, they add up to a number that would make you sick if you saw it on one line.

Jewelry POS data is noisy by nature — legitimate voids from fat-fingered SKUs, real discounts on aged inventory, genuine returns from cold-feet grooms. Fraud hides inside that noise. The trick isn't spotting one bad transaction. It's building rules that flag patterns worth a second look, then having a repeatable way to investigate without turning into a paranoid manager who accuses everyone.

This is about that system: the specific exception rules that matter for jewelry, a weekly triage rhythm you can actually maintain, and sample investigation logs so you're not making it up as you go.

Why jewelry POS fraud is different from retail generally

A convenience store loses $4 to a bad void. You lose $1,400. The ticket sizes mean a jeweler doesn't need volume fraud to get hurt — a handful of well-placed exceptions a month does real damage.

There's also the appraisal-and-return dynamic that's almost unique to this business. An employee can sell a ring, process a "return" of an identical SKU that never actually came back, and pocket the difference. Because you carry near-identical stones and settings, the physical inventory can look fine on a quick glance. The paper trail is the only place the crime is visible, which is exactly why POS anomaly detection matters more here than in almost any other small-retail category.

The last wrinkle is trust. Jewelry teams are small and often long-tenured. The person most capable of quiet fraud is usually the one you'd least suspect, because they know the blind spots. That's uncomfortable, but it's the reality the rule set has to account for.

The exception categories that actually matter

Not every anomaly is worth your attention. Flag everything and you'll effectively flag nothing, because you'll stop looking. These are the categories worth building rules around, ranked roughly by how often they turn into something real.

Voids — especially post-tender voids

A void before payment is usually a mistake. A void after a transaction was tendered — or one that shows up minutes after a completed sale — is the one to watch. The classic pattern: a ring is sold and paid in cash, the sale is voided after the customer walks out, and the cash goes in a pocket. The item shows as still in stock, so nothing looks off until a physical count months later.

Discounts that drift

Manager-approved discounts are fine. The problem is discount authority that quietly expands. An employee allowed 10% starts applying it to almost everything, or applies it and then processes the difference as a separate cash "adjustment." Also watch round-number discounts applied right at the item's cost — someone who knows the margins can zero out profit while keeping the sale looking normal.

Rapid returns

A return processed within a short window of the original sale — same day, or within a day or two — deserves a look, particularly if it's cash and particularly if the same employee handled both the sale and the return. Legitimate rapid returns happen (buyer's remorse is real in this business), but they're also the cleanest way to reverse a fake sale or launder a cash grab.

The ring-void combo

This is the one that gets missed most often. A sale is completed, then partially voided — a ring sells with a warranty and a cleaning kit, and only the ring line gets voided after tender while the customer keeps everything. Or a multi-line sale where one high-value line is voided post-payment and the item leaves the store. Because the transaction still shows activity and a nonzero total, it doesn't trip a simple "voided sale" filter. You have to look at line-level voids inside otherwise-normal transactions.

A weekly rule set you can maintain

These are thresholds to start with — tune them to your volume and ticket sizes after a month of watching what's normal for your store.

RuleTrigger thresholdPriorityTypical false-positive cause
Post-tender void (cash)Any single occurrenceHighGenuine customer change-of-mind at counter
Line-level void inside completed saleAny void on a line over $500HighItem swap not re-rung correctly
Rapid return (same employee, cash)Return within 48h of saleHighReal buyer's remorse
Void clustering by employee>3 voids/week above store averageMediumNew/untrained staff
Discount above authorityAny discount exceeding role limitMediumManager override not logged
Discount at/near item costMargin under 5% on a non-clearance itemMediumLegit negotiated bridal deal
Voids at open/close windowVoid within 20 min of open or closeLow-MediumRegister setup/reconciliation
Repeat identical-SKU returnsSame SKU returned 2+ times/month by one associateHighGenuinely defective batch

The point of the priority column is triage. You will not investigate everything. High-priority flags get looked at every week without exception. Medium flags get looked at when they cluster — one is noise, three on the same person in a month is a pattern.

The weekly triage: 30 minutes, same day every week

Consistency beats intensity here. A manager who reviews flags for 30 minutes every Monday catches more than one who does a heroic four-hour audit twice a year, because patterns show up in the rhythm.

The process:

  1. Pull the week's exception report. All voids, returns, and discounts above your set thresholds, grouped by employee — not by date. Grouping by employee is the whole game. Fraud clusters on people, not on days.
  2. Scan the high-priority flags first. Every post-tender cash void and every rapid same-employee cash return gets an eyeball this week, no matter what.
  3. Check the medium flags for clustering. Is the same name showing up across categories? Someone with slightly elevated voids and slightly high discounts and one rapid return is more interesting than someone with five voids and nothing else.
  4. Cross-reference against the schedule. Were the flagged transactions during that person's solo shifts? Solo-shift concentration is one of the strongest signals there is.
  5. Match a sample to physical reality. Pick one or two flagged high-value voids or returns and physically confirm the item is where the system says it is. This is where a tight jewelry inventory lifecycle pays off — if your counts are trustworthy, a five-minute check settles it. If your inventory is already a mess, you can't use it as a control at all.
  6. Log everything, even the clean ones. The log is what turns a hunch into a case.

Once you run this a few weeks in a row, you start developing a feel for what's normal on your team. That baseline is what makes the outliers actually visible.

What clustering actually looks like

A single flag means almost nothing. Real internal fraud rarely shows up as one dramatic red flag — it shows up as a person who's mildly elevated across three or four categories at once, almost always on the shifts where they're alone at the register.

A typical example: an associate whose void rate is only slightly above average, whose discount usage looks a touch generous, who processes returns more often than peers, and whose flagged transactions almost all happen between 6:30 and 7:00 pm on Tuesdays when they close solo. No single number screams. The overlap does.

That's why grouping by employee and cross-referencing the schedule matter more than any individual threshold. You're building a picture, not catching one transaction.

Sample investigation logs

When a flag turns into an actual look, write it down — both to build a case if it's real and to protect yourself and the employee if it isn't. Vague suspicion is a lawsuit waiting to happen. A dated, factual log is a defensible record.

Investigation Log — Entry Format

  1. Date logged / Reviewer

    who looked and when

  2. Trigger

    which rule fired

  3. Transaction detail

    date, register, employee, ticket #, SKU, amount

  4. What was checked

    inventory match, schedule cross-ref, receipt/signature, camera timestamp

  5. Finding

    explained / unexplained / needs follow-up

  6. Action

    none / coaching / escalate / monitor

Keep it boring and factual. Here's the format:

> Oct 14, reviewed by DM. Trigger: post-tender cash void, $1,290 pendant, ticket 4471, associate JR. Checked: item physically present in case 3, matches SKU. Customer had changed to a card sale — separate card transaction 4472 for same amount found same minute. Finding: explained. Action: none. Note — coach JR to re-ring rather than void when switching tender.

> Oct 21, reviewed by DM. Trigger: rapid same-employee cash return, $840 earrings, ticket 4610 sold 10/20 6:52pm, returned 10/21 6:44pm, associate TM both times, TM closing solo both nights. Checked: item NOT located in expected case; no return signature on file; no matching camera event at return timestamp. Finding: unexplained. Action: escalate to owner, pull 30-day history for TM, preserve camera footage.

Notice the cleared entry is just as detailed as the escalated one. That's intentional. If you only document the suspicious cases, your logs look like a witch hunt. Document the process evenly and they look like a control.

When to escalate — and when to let it go

Not every unexplained flag is fraud. People make mistakes, POS systems glitch, and honest employees sometimes look bad on a report through pure bad luck of scheduling.

Escalate when you get repetition + concentration + no explanation: the same person, the same category, across their solo shifts, with the physical or paper trail not backing up the transaction. That combination is when you pull broader history and preserve footage before saying a word.

Let it go — or handle it with a coaching conversation — when there's a plausible operational explanation, when it's a one-off, or when the flag is clearly a training issue. A new hire voiding a lot because they haven't learned the re-ring flow isn't fraud — coaching them early actually reduces your future noise, which makes real fraud easier to see.

The mistake to avoid is confronting someone off a single flag. You'll either tip off a genuine thief before you have evidence, or you'll damage trust with an innocent employee who now knows you're watching and resents it. Build the case quietly first.

When this system is overkill

If you're a solo owner-operator ringing every sale yourself, formal anomaly rules are wasted effort — you are the control. Same goes for a two-person shop where you personally see every high-value transaction.

This earns its keep the moment you have staff processing transactions on shifts you're not physically watching, especially solo closing shifts. Three or more people touching the register, or any regular solo coverage, and you want the rules running.

Worth being honest about one thing: anomaly detection is a paper-trail control, not a physical one. It works best alongside basic store controls — camera coverage on registers, dual-control for high-value case access, and the setup steps covered in the store security controls playbook. The POS rules tell you where to look. The physical controls give you something to look at.

Making the weekly review actually happen

The single biggest failure point isn't the rules — it's that nobody runs them. The Monday review gets skipped during busy bridal season, then skipped again, and three months later you're back to flying blind.

Make the exception report a scheduled, recurring pull so it lands in your inbox grouped by employee and becomes a five-minute review, not a manual data-mining chore.

Two things keep it alive. First, make the exception report a scheduled pull rather than something you build by hand each week. If it lands in your inbox already grouped by employee, you'll actually read it. Modern jewelry POS and operations platforms can generate these exception summaries automatically and flag clustering patterns across categories — which turns a manual data-mining exercise into a five-minute scan. That's the difference between a control that runs for a month and one that runs for years.

Second, tie it to a fixed time. Same day, same 30 minutes, calendar block that doesn't move. The rhythm is what catches the drift, because internal fraud almost always escalates slowly. The person who takes $840 this month took $300 six months ago and got comfortable.

A simple process flow for the weekly review

The triage works best when it follows the same order every time. Here's how the steps connect:

Pull exception report (grouped by employee) ↓ Review all High-priority flags ↓ Check Medium flags for cross-category clustering ↓ Cross-reference flagged transactions against schedule ↓ Physical spot-check on 1–2 flagged high-value items ↓ Log findings (cleared, coaching, or escalate) ↓ Preserve footage / pull extended history if escalating

Process diagram

Run the steps in this order each week so your effort lands where it most often finds real patterns.

Where this leaves you

You don't need to become a forensic accountant to protect your store. You need a short list of the exceptions that actually matter for jewelry — post-tender cash voids, rapid same-employee returns, discount drift, and the line-level ring-void combo — a weekly rhythm to look at them grouped by person, and a plain-language log so a real pattern becomes a defensible case instead of a gut feeling.

Start with the high-priority rules, run the Monday review for a month, and tune your thresholds to what's normal for your volume. Most stores find that just having the review — and having staff know exceptions get looked at — quietly shrinks the numbers on its own. The visibility is the deterrent. The logs are the backup for the rare times it isn't.

Start with the high-priority rules, run the Monday review for a month, and tune your thresholds to what's normal for your volume. Most stores find that just having the review — and having staff know exceptions get looked at — quietly shrinks the numbers on its own. The visibility is the deterrent. The logs are the backup for the rare times it isn't.

Built for Jewelers Tailored to jewelry retail workflows and inventory needs
Save Time Simplify order tracking, inventory management & customer communications
Delight Clients Faster order fulfillment and personalized customer experiences
Grow Revenue Maximize sales opportunities and optimize stock levels