
Prevention rests on three levers working together: clear policy and visible leadership, internal controls that remove easy opportunity, and proportionate detection with lawful evidence preservation if something does go wrong. Get the first two right and most theft never starts. The sections below cover hiring checks, operational controls, investigation steps and the legal boundaries you need to respect along the way.
TL;DR:
- Implement layered controls by segregating financial duties and requiring dual approvals to significantly reduce opportunities for theft.
- Conduct risk-based pre-employment screening for roles involving financial access, including police checks and verification of references, to prevent hiring at high theft risk.
- Use daily cash counts, exception reporting, and audit logs to detect discrepancies early and limit concealment by potential thieves.
- Follow procedural fairness with documented investigations, evidence preservation, and legal advice before employee termination for theft allegations.
- Combine physical security measures, such as CCTV, access control, and regular site patrols, with employee awareness programs and a positive workplace culture to deter theft.
Table of Contents
- Employee theft prevention: policy and cultural foundations
- How do you screen for theft risk before you hire?
- What operational controls actually reduce opportunity?
- What are the red flags of employee theft and how do you investigate?
- Legal and privacy limits when you respond to theft
- How ABCO Security turns policy into daily practice
- Employee training and awareness programs to prevent theft
- Creating a positive workplace culture to reduce theft risk
- Regular audits and continuous monitoring strategies
- Recovery and restitution processes after theft incidents
- Balancing trust with controls: a short perspective
- Managed security is the direct route to fewer gaps
- Sources
- FAQ
Employee theft prevention: policy and cultural foundations
Every effective theft-prevention program starts with a written policy, not a hunch about who looks trustworthy. A code of conduct that spells out what counts as theft (till skimming, inventory diversion, expense fraud, time theft), the consequences, and the reporting process gives you something concrete to act on when things go wrong. Vague warnings in a staff handbook don’t hold up in a dismissal dispute.
Leadership sets the tone before any policy document does. ICAC NSW points to visible, consistent adherence by owners and managers as the single strongest factor in reducing a permissive culture. If the boss expenses personal items or waves through unexplained stock variances, staff notice, and the policy becomes decoration.
Practical steps that turn policy into practice:
- Put the theft policy and consequences in the employee handbook and induction pack, not just a poster in the lunchroom.
- Set up an anonymous reporting channel or whistleblower hotline, and put a non-retaliation clause in writing.
- Mandate annual leave rather than letting it accrue. Someone masking a fraud often avoids time off because a replacement might spot it.
- Rotate staff through high-trust roles like purchasing, banking and payroll reconciliation.
- Require a second person to cross-check high-value transactions before they’re finalised.
CPA Australia’s guidance on employee fraud frames whistleblowing and segregation of duties as core controls precisely because they raise the cost of concealment, not just the cost of getting caught.
Pro Tip: Review your theft policy every time you update your point-of-sale or accounting software. Old policies written for cash registers rarely cover digital refund fraud or gift-card manipulation.
How do you screen for theft risk before you hire?
A police check isn’t a universal requirement in Australia, and running one on every applicant regardless of role invites a discrimination complaint. The smarter approach is risk-based: match the depth of screening to what the role can access.
- Identify roles that touch cash, banking, supply chain or financial systems, and apply enhanced screening, including a National Police Check where the role warrants it.
- Get written consent before running any check. The Privacy Act 1988 and anti-discrimination rules apply regardless of company size.
- Verify referees, identity documents and employment history directly rather than relying on a candidate’s summary.
- Only request criminal-record information when it’s genuinely relevant to the job, and document why you assessed it the way you did.
- Where a check is still pending, issue a conditional offer rather than delaying the whole process.
For roles carrying ongoing financial trust, don’t treat screening as a one-off. AUSTRAC’s guidance on employee due diligence recommends prescreening at intervals or after a role change, since risk shifts as someone gains more access over time.
What operational controls actually reduce opportunity?
Segregating duties is the cheapest control you’ll ever install, and it’s often the one businesses skip because “everyone wears multiple hats.” Splitting sales, refunds, banking and reconciliation across different people, or requiring two sign offs on high-risk actions, severely limits how a single employee can hide a discrepancy, a point CPA Australia’s fraud guidance makes directly.
Beyond that structural fix, a handful of daily habits close most remaining gaps:
- Count the till at the start and end of every shift, not just at closing.
- Generate exception reports for refunds and voids and review them weekly, not quarterly.
- Set role-based permissions in your POS and accounting systems so junior staff can’t approve their own discounts.
- Keep audit logs that record who did what, and when, without the option to edit history after the fact.
- Run cycle counts on stock rather than one exhausting annual count nobody trusts.
CCTV and access control help, but only when deployed lawfully. Victoria Police recommends visible signage, staff notification, and footage retention procedures as standard practice, and cameras belong in work areas, never in change rooms or bathrooms.
| Control | What it stops | Effort to implement |
|---|---|---|
| Segregation of duties | Concealed skimming or fake refunds | Low, mostly a rostering change |
| Daily till reconciliation | Cash shortages going unnoticed | Low, five minutes per shift |
| Role-based system permissions | Unauthorised discounts or voids | Medium, needs IT setup |
| CCTV with signage | Opportunistic theft, disputed incidents | Medium to high |
| External stocktake audit | Long-term inventory shrinkage | Medium, periodic cost |
What are the red flags of employee theft and how do you investigate?
Shrinkage that doesn’t match sales data, an employee who repeatedly processes their own refunds, unexplained after-hours system access, or someone who never takes leave and resists having anyone cover their role. Each is a prompt to look closer, not a verdict.
- Secure your systems immediately. Export POS logs, accounting records and CCTV footage before anything can be overwritten.
- Log every action you take, with timestamps, so your evidence trail holds up later.
- Limit who knows about the investigation early on, to avoid tipping off the person involved or triggering gossip that taints witness accounts.
- Give the employee a chance to respond before any decision (a show-cause process), and document that response.
- Bring in police or a lawyer once you have enough documented evidence to justify the step.
Sprintlaw’s guidance on workplace theft flags a common and costly mistake: editing or overwriting digital logs before exporting the raw files, which can compromise the evidence chain entirely.
The stakes are real even for a single incident. A 2022 retail crime study across Australia and New Zealand found the average value per internal-theft incident sat around $1,200, which is enough to justify a proper investigation rather than a quiet word and a shrug.
Legal and privacy limits when you respond to theft
Procedural fairness isn’t optional. A documented show-cause process, where the employee gets to respond to specific allegations before you act, is what protects you from an unfair-dismissal claim later.
Resist the urge to simply deduct wages for suspected theft. Doing so without clear legal authority or the employee’s written agreement can itself breach workplace law. Consider a repayment deed instead, or lodge an insurer claim where your policy covers internal theft.
- Notify staff about surveillance where workplace surveillance laws require it, and never record audio without meeting consent requirements.
- Preserve the original evidence exactly as captured, with no edits, as Sprintlaw notes in its guidance on legal steps for employers.
- Check whether your business insurance covers employee theft before assuming a police report is your only recovery path.
- Get legal advice before terminating for theft. Yes, an employee can be terminated for theft, but only when you can show the process was fair and the evidence solid.
How ABCO Security turns policy into daily practice
Written policy only works if the physical environment backs it up. On construction sites, that means locked tool storage, a formal check in and check out process, and tagged equipment so nobody can quietly walk gear off site unnoticed.
An integrated setup, CCTV monitoring paired with mobile patrols and access control, supports the internal controls covered above and gives you a faster response when something looks wrong, rather than discovering it days later.
Before engaging any provider, ask about service-level commitments, relevant ISO certifications, monitoring arrangements, and exactly how evidence is captured and handed over if you ever need it for a police report.
Pro Tip: Ask a prospective security provider for a sample incident report before signing anything. If it’s vague on timestamps and evidence handling, your future investigations will be too.
Employee training and awareness programs to prevent theft
A policy nobody reads is a policy that doesn’t exist. Training turns the written rules into something staff actually understand, and it needs to happen at induction, not buried in a slideshow six months in.
Cover what counts as theft in plain terms: taking stock home “just this once,” processing a friend’s refund without a receipt, clocking in for a mate who’s running late. These feel minor to the person doing them, which is exactly why they need to be named directly rather than left implied.
Run refresher sessions annually, and tie them to real (anonymised) examples where possible. Staff remember a story about a colleague who lost their job over a $40 discrepancy more than they remember a policy clause.
Train managers separately on how to spot red flags and escalate concerns without jumping straight to accusation. A manager who panics and confronts an employee publicly can destroy evidence and expose the business to a bullying complaint in the same conversation.
Make the anonymous reporting channel part of the training, not a footnote. Staff need to know it exists, how to use it, and that using it won’t cost them their job. Combine this with cash-handling training for anyone touching money. Clear procedures reduce genuine mistakes as well as deliberate misconduct, and a well-run cash handling procedure makes both easier to audit later.
Creating a positive workplace culture to reduce theft risk
Theft correlates strongly with how employees feel treated, not just how tightly they’re watched. Staff who feel undervalued, underpaid relative to peers, or ignored when they raise concerns are statistically more likely to rationalise taking something back.
Recognition costs little and does real work here. Victoria Police’s prevention guidance lists staff recognition alongside CCTV and stock counts as a genuine deterrent, not a soft add-on.
Fair rostering, transparent pay structures, and clear promotion pathways all reduce the sense of grievance that often precedes theft. This doesn’t mean going soft on controls. It means explaining why the controls exist, so honest staff don’t feel accused every time they clock in.
Open two-way communication matters more than most managers assume. An employee who can flag a broken process, a supplier discrepancy, or a colleague’s odd behaviour without fear of being dismissed as a troublemaker gives you an early-warning system no camera can replicate.
Exit interviews are an underused tool here. Departing staff will often tell you things they never would have raised while employed, including where the controls are weakest.
Regular audits and continuous monitoring strategies
A single annual stocktake catches theft that’s been running for months, sometimes years. Cycle counts, run weekly or monthly on rotating sections of inventory, catch it while it’s still small enough to investigate cleanly.
Reconciliations matter more than surveillance for most small and medium businesses. Sprintlaw’s guidance on preventing employee theft notes that many businesses see bigger gains from tightening reconciliations and exception reporting than from adding intrusive monitoring.
Build a simple audit calendar: weekly exception report reviews, monthly stock cycle counts, quarterly reconciliation of supplier invoices against banking records, and an annual external audit for anything involving significant cash flow. Vary the timing occasionally so audits don’t become predictable enough to work around.
Continuous monitoring doesn’t mean watching every camera feed all day. It means setting sensible thresholds, a refund over a certain value, a stock variance beyond a set percentage, and having those exceptions flagged automatically rather than discovered by accident three months later.
Document every audit finding, even the clean ones. A consistent paper trail of “checked, no issues found” is what protects you if a dispute ever ends up in front of Fair Work or a court.
Recovery and restitution processes after theft incidents
Once theft is confirmed, recovery options depend heavily on documentation quality. A repayment deed, an agreement where the employee acknowledges the debt and commits to structured repayment, is often faster and cheaper than litigation, provided it’s drafted properly and signed voluntarily.
Insurance is the other lever many businesses forget to check until it’s too late. Review your policy for internal-theft or fidelity cover before assuming a police report is your only path to recovery.
A police report matters for two reasons beyond the criminal process itself: it creates an official record that supports an insurance claim, and it can support a civil claim if you pursue one separately. Keep the exported logs, CCTV footage and investigation notes from earlier in the process, since you’ll need them again here.
Civil claims for restitution are possible but often slow and costly relative to the amount recovered, particularly for smaller thefts. Weigh the legal cost against the recovery amount before committing to that path.
Whatever the outcome, close the loop internally. Review which control failed, update the relevant policy or procedure, and communicate the change (without naming individuals) so staff understand the business learned something from the incident rather than just punished someone for it.
Balancing trust with controls: a short perspective
Controls exist to protect honest staff as much as the business. When you explain why a second sign off or a stock count exists, most employees see it as fairness, not suspicion. Treat every incident as a chance to improve the system, not just close a file.
— Abco
Managed security is the direct route to fewer gaps
Reading a policy checklist is one thing. Having someone actually patrol the site, monitor the cameras overnight, and respond when an alarm fires at 2am is another. Abcosecurity exists for the gap between the two, delivering the operational side of everything covered above rather than leaving it to a part-time manager checking footage between other jobs.
Abcosecurity provides licensed security guarding for staffed deterrence, A1 CCTV & Alarm Monitoring for round-the-clock evidence capture, mobile patrol services for irregular site checks, and dedicated construction site security for tool and materials protection. Backed by ISO 9001 and ISO 30000 aligned processes and over 15 years in the industry, the approach favours proactive coverage over waiting for an incident report.
For a straightforward entry point, the Night Owl monitoring plans start from $5.45 a day and cover after-hours monitoring without a full guarding contract. The simplest next step is to request a security risk assessment through Abcosecurity and get a proposal scoped to your site, your roles and your actual exposure, not a generic package.
Sources
- New retail crime stats reveal employee theft, customer aggression and fraud (Griffith University news)
- Theft by employees (Victoria Police)
- Employee fraud (CPA Australia guidance)
- Theft in the workplace: legal steps for employers in Australia (Sprintlaw)
- Employee due diligence (AUSTRAC)
FAQ
How Do You Deal With an Employee Who Steals?
Secure your evidence first: export POS logs, accounting records and CCTV footage before confronting anyone. Then run a documented show-cause process that lets the employee respond, and only decide on termination or police involvement once you’ve reviewed their response against the evidence.
Can an Employee Be Terminated for Theft?
Yes, theft is generally recognised as valid grounds for termination, but you need a fair, documented process to avoid an unfair-dismissal claim. Give the employee a genuine chance to respond to specific allegations before you make a final decision.
What Is an Example of Employee Theft?
Common examples include skimming cash from the till, processing fake refunds to a personal account, taking stock home without paying, and inflating expense claims. Time theft, like buddy-punching timesheets, is also a recognised form.
What Are Five Ways to Prevent Theft?
Write a clear theft policy with visible leadership enforcement, segregate financial duties so no single person controls a transaction end to end, run regular stocktakes and reconciliations, set up an anonymous reporting channel, and use CCTV and access control lawfully with proper staff notification, as Victoria Police recommends.
How Much Does Employee Theft Actually Cost a Business?
Costs vary by incident, but a 2022 retail crime study put the average value per internal-theft incident at around $1,200 across Australia and New Zealand. That figure covers a single incident, not cumulative losses from undetected, ongoing theft.








