
Operator's Daily is where multi-unit restaurant and hourly-workforce operators get smart, fast — practical guides and no-nonsense software comparisons across hiring, onboarding, scheduling, payroll, and compliance.
Documented data on restaurant margins, internal controls, cybersecurity, and loss prevention for multi-unit operators
Employee theft can involve cash, inventory, unauthorized discounts, loyalty accounts, time records, or company data. However, many frequently quoted restaurant theft percentages cannot be traced to current primary research.
That does not make internal loss unimportant. Restaurants operate with narrow margins, significant food and labor expenses, high transaction volumes, and frequent employee access to cash, inventory, point-of-sale systems, and customer information.
This guide focuses on statistics and incidents that can be supported by identifiable sources. It also explains how operators can use scheduling controls, inventory reconciliation, point-of-sale reporting, access management, and training to reduce opportunities for loss.
Operators Daily publishes practical guides to workforce and restaurant operations technology.
Employee theft is not limited to taking cash or food. It may include unauthorized discounts, false refunds, void manipulation, loyalty-account abuse, payroll falsification, inventory diversion, credential misuse, or unauthorized access to employee and customer data.
Reliable national restaurant-specific estimates are limited. Operators should therefore assess risk using their own exception reports, inventory variances, labor records, cash discrepancies, access logs, and documented incidents rather than relying on unsupported industry averages.
Food costs historically represented approximately 33 cents per dollar of restaurant sales. Actual ratios vary by restaurant type, menu, sales volume, purchasing practices, and accounting methods.
In 2024, food and nonalcoholic beverage costs represented a median 32.4% of sales among limited-service respondents and 32.0% among full-service respondents.
Because food represents such a large expense, small unexplained variances in high-value ingredients can materially affect results.
Labor also historically represented approximately 33 cents per dollar of sales.
Recent results vary significantly by profitability. Among limited-service respondents in 2024, labor represented a median 30.0% of sales for profitable restaurants and 34.1% for restaurants reporting a pre-tax loss.
Unauthorized early clock-ins, late clock-outs, missed-break manipulation, and inaccurate time records can therefore add meaningful costs even when no cash or inventory is taken.
The National Restaurant Association has historically placed a typical restaurant’s pre-tax margin at approximately 5% of sales.
More recent data shows substantial variation. Among full-service respondents with annual sales below $2 million, median income before taxes was 1.1% of sales in 2024. For respondents with sales of at least $2 million, the median was 4.3%.
These figures illustrate why operators should investigate recurring cash, labor, and inventory discrepancies promptly.
In the National Restaurant Association’s 2026 industry outlook, 42% of operators said their restaurant was not profitable in 2025.
This statistic does not measure theft. It shows the broader financial environment in which preventable losses occur.
Time theft may include clocking in for another employee, recording time not worked, taking unauthorized extended breaks, or remaining clocked in after work has ended.
Reliable national restaurant-specific prevalence figures are not readily available. Operators should use location-level records to identify problems.
Biometric, photo, and location controls can reduce buddy-punching opportunities, but they do not guarantee that misconduct will be eliminated.
Cash and POS misuse may involve unauthorized voids, refunds, discounts, open-drawer events, deleted items, or transactions entered after a guest has paid.
Operators can reduce these risks by reviewing exception reports and restricting sensitive functions according to job responsibility.
Exception reports are indicators, not proof of theft. Operators should investigate discrepancies before taking disciplinary action.
Inventory loss can arise from employee theft, customer theft, spoilage, portioning errors, receiving discrepancies, unrecorded waste, or administrative mistakes.
Operators should avoid automatically classifying every variance as theft.
Focused controls are generally more useful than relying on an unsupported industry-wide shrinkage percentage.
Loyalty programs and gift cards can be abused through unauthorized adjustments, false redemptions, account takeovers, or the reclassification of cash transactions.
A general manager at two Mancino’s locations was sentenced after using loyalty-program transactions to embezzle approximately $130,000.
Reporting indicated that approximately 99% of the questionable reward transactions were entered through one office computer. The case demonstrates the value of reviewing redemption rates by employee, device, location, and transaction type.
Operators should not confuse this type of internal loyalty fraud with FTC statistics about consumers who are instructed to pay scammers using gift cards. The FTC treats those incidents as payment scams, not restaurant employee-theft data.
Employees do not need malicious intent to create a data-security incident. Mistakes, phishing, weak credentials, excessive permissions, and poorly managed accounts can all expose restaurant information.
Verizon’s 2024 Data Breach Investigations Report analyzed 10,626 confirmed breaches and 30,458 security incidents.
The dataset covers multiple industries and should not be presented as restaurant-specific research.
The report found that the non-malicious human element was involved in 68% of breaches. Examples include falling for social engineering or mistakenly disclosing credentials.
This finding excludes malicious privilege misuse from the human-element calculation. It should not be described as a measure of malicious insiders.
Stolen credentials represented 24% of initial breach actions in the 2024 DBIR.
Restaurants can reduce credential-related risk by using unique user accounts, multifactor authentication, prompt offboarding, access reviews, and limits on administrator privileges.
Golden Corral reported that an unauthorized actor accessed systems between August 11 and August 15, 2023. A regulatory filing indicated that 183,272 individuals were potentially affected.
The affected information related to current and former employees and beneficiaries. Golden Corral said customer data was not affected.
The incident shows why restaurants should treat workforce data, payroll information, and employee credentials as sensitive operational assets.
Technology can improve visibility and accountability, but no product independently proves or prevents employee theft.
Useful capabilities may include:
Useful capabilities may include:
Useful capabilities may include:
Onboarding software can document policy distribution, training completion, employee acknowledgments, and role-specific access requirements.
Operators Daily provides software guides for restaurant and hourly-workforce operations.
Technology is most effective when paired with consistent management processes.
Managers should document facts objectively and avoid treating an exception report as conclusive evidence.
Clear policies should define prohibited conduct, investigation procedures, reporting channels, and potential consequences.
Operators should apply policies consistently, preserve relevant evidence, protect employee confidentiality, and consult qualified legal counsel when an investigation could lead to termination, repayment demands, insurance claims, or criminal referral.
Compensation, scheduling predictability, supervision, and workplace culture may affect employee behavior, but no single employment practice guarantees that theft will or will not occur.
Consider:
A platform should be evaluated on documented functionality and operational fit, not unsupported promises that it will eliminate theft.
No current primary source establishes one form as universally most common across all restaurants. Frequently discussed risks include cash manipulation, unauthorized discounts, inventory diversion, loyalty-account misuse, and inaccurate time records.
Start with unique POS credentials, cash reconciliation, regular counts of high-value inventory, documented waste, manager approval for sensitive transactions, and review of time-entry changes.
They can reduce the opportunity for one employee to clock in for another, but they do not guarantee prevention. Operators must also consider applicable biometric and privacy laws.
No. Commercial crime and employee-dishonesty policies vary in covered conduct, exclusions, limits, deductibles, discovery periods, and documentation requirements. Operators should review the actual policy with an insurance professional.
High-risk exceptions may require daily review. Inventory, access permissions, policies, and training should be reviewed on a recurring schedule and whenever systems, staffing, or operating procedures change.
Join multi-unit operators getting practical guides and no-nonsense software breakdowns across hiring, onboarding, scheduling, payroll, compliance, and what's shifting in the industry.
Free. One email a week. Unsubscribe anytime.


