M cenaly.ru
🛠️ Касса и ККТ: вопросы и ответы

🔐 Безопасность кассы: пароли, роли, махинации кассиров

Пароли по умолчанию, роли и ПИН-коды на рискованные операции, типовые схемы злоупотреблений и как ловить их по отчётам и журналам

Documentation

POS Security: Passwords, Roles, Cashier Fraud

An online POS records every transaction for tax authorities, but this doesn't protect the owner from internal losses: fraudulent refunds, items canceled before payment, or off-the-books sales leave no trace in tax returns, but they do leave one in reports if you know where to look. We break down basic POS security — from changing the default password to what needs to be reissued after an employee leaves.


1. Default Passwords — Why You Must Change Them#

POS terminals are sold with factory default passwords for roles that are identical across the entire model line — this is not a secret, but reference information from the manufacturer's manual available to anyone. On ATOL POS terminals, default passwords for the "Administrator" (29) and "System Administrator" (30) roles are set by default — the "29/30" combination familiar to anyone who has opened out-of-the-box POS settings. A similar story applies to other manufacturers — for details on specific models and error codes when an incorrect password is entered, see the articles "ATOL POS Errors" and "SHTRIH-M POS Errors".

Until the factory password is changed, anyone who knows the POS model (and the model is visible on the casing) potentially has access to administrative functions: receipt voids, VAT rate settings, and correction receipts. The password is changed in the admin menu of the POS terminal itself or via setup software (fiscal printer driver) immediately after the first power-on — before starting work with real transactions.

Role What it gives access to Who can be trusted
Cashier Issuing standard sales receipts Frontline staff
Administrator POS settings, reports, sometimes corrections Manager / shift supervisor
System Administrator / Service Center Maintenance, fiscal memory (FN) replacement, deep settings Responsible person or service engineer only

2. Self-refunds — how to spot them in reports#

The scheme is simple: a cashier rings up a sales receipt, and after some time processes a refund for the same item, taking the cash for themselves, even though no actual return occurred from the customer. Signs in reports:

  • an unusually high proportion of refunds for a specific cashier compared to colleagues with comparable revenue;
  • refunds are concentrated at the end of the shift, before closing, rather than distributed evenly throughout the day;
  • the same item/amount is repeated in refunds more often than statistically explainable by real customer behavior;
  • the refund is processed without the customer's receipt on hand and without an explanation in the digital log (who processed the return, why).

The right to process a refund without a receipt is legal in itself (see "Advanced Refunds") — the problem is not the lack of a paper receipt, but the lack of an independent check: if a refund can be processed and approved by the same person without a second participant or a recorded reason, the scheme remains undetected until someone compares reports across employees.


3. Canceling items before closing the bill and off-the-register sales#

Canceling an item before printing the receipt (in an open order that has not yet been turned into a fiscal receipt) is a routine operation, but it also leaves a trail: the electronic POS log records that an item was added and then deleted, by whom, and when. If a cashier regularly "rings up" an item, shows the customer the total, accepts cash, and before final printing deletes some items and prints a receipt for a smaller amount—they keep the difference. Compare the count and total value of canceled items by employee: abnormally frequent cancellations by a single cashier are a reason for an internal audit.

Selling entirely off-the-books (no receipt is printed at all) leaves no trace in fiscal data—only indirect signs work: discrepancies between inventory usage in inventory management and the total printed receipts, video surveillance, and test purchases (see "How the Tax Authority Analyzes Your Cash Register"). Regular reconciliation of inventory balances with actual sales is the most reliable internal control method for this specific scheme.


4. Roles and PIN Codes: What to Restrict for Frontline Staff#

Role separation is a basic security measure that requires no additional hardware:

  1. Regular cashier — issuing sales receipts, accepting payments. Nothing else.
  2. Refunds — a separate permission or PIN of a shift supervisor/manager; a regular cashier cannot process a refund alone without confirmation.
  3. Manual discount (custom input rather than a catalog promotion) — another high-risk operation: unmonitored "friends and family" discounts reduce revenue.
  4. Correction receipt — an administrative operation accessible only to a responsible person, not to any cashier.
  5. Canceling an item in an open order — can be left to frontline staff, but with reason logging for significant volumes.

A PIN code for each operation (and not just for logging into the system) provides what a shared admin password cannot: personal accountability. You can see exactly who processed a specific refund or discount, rather than just "someone with admin rights."


5. Video Surveillance Over the POS Area#

A camera positioned to see the POS screen (or at least the cashier's hands and cash drawer) and the customer is not a mandatory legal requirement, but a practical tool for resolving disputed transactions. It is important that:

  • the recording is time-synchronized with the POS — otherwise, matching a frame with a specific receipt is difficult;
  • it is stored for a sufficient period to allow time for auditing transactions (the typical overwrite cycle for budget systems ranges from a few days to a month);
  • the field of view captures the moment the cash drawer opens and change is handed over, not just the cashier's face.

By itself, video footage does not replace fiscal data, but combined with the POS electronic log and fiscal module log, it turns suspicion into a proven fact — or clears an innocent employee of an unfounded accusation.


6. FN Log and POS Electronic Log — How to Reconcile#

These are two different sources with different levels of detail:

Source What It Shows Change Retroactively
Fiscal Storage (FN) log (via OFD/cash register portal) Every issued fiscal document: amount, time, payment attribute, cashier (if transmitted) Impossible
POS electronic log Order content, voided items, discounts, who logged into the system and when Usually impossible without leaving a trace in the log itself

If you suspect fraud, cross-check both sources for the same time window: the FN log will show which receipt was actually submitted to the tax authority, while the POS log will show what happened to the order prior to that (what was added, voided, and by whom). A discrepancy between what the customer saw on the screen and what ended up on the final receipt is the primary indicator of the schemes described in sections 2–3.


7. A dismissed employee knew passwords — what to reissue#

  1. Personal PIN code/account of the dismissed employee — block on the day of dismissal.
  2. Shared POS administrator password, if the departing employee had access to it rather than just their own PIN — change immediately (this is the same role password from Section 1).
  3. Access codes to shared devices (a POS tablet with a shared access code rather than a personal PIN code) — reissue.
  4. Login credentials for the OFD/fiscal register account, if the departing employee had direct access to them — change the password there as well.

Personal PIN codes (Section 4) eliminate part of this issue in advance: terminating a single employee does not require changing the shared administrative password — disabling their specific code is enough.


8. Example#

In a restaurant, three cashiers shared a single POS administrator password that had remained set to the factory default since purchase. After one of them was dismissed, it turned out that he knew this password and could process refunds without approval. The refund report for his last month of work showed a refund rate three times higher than his colleagues', almost all of them in the last hour of his shift. The owner changed the password that same day and switched to personal PIN codes so that such a situation would be visible immediately in the report, rather than after the fact upon dismissal.


9. How to do this in Cenaly#

  • Cashier roles and personal PIN codes: refunds, manual discounts, and correction receipts require separate permission or manager approval, leaving regular cashiers only with ringing up receipts.
  • A POS shift with expected/actual balance control highlights discrepancies upon closing, linking them to the cashier and the shift.
  • Receipt history and reports on employees/refunds — POS → Receipts (receipts): the share of refunds, corrections, and operation timestamps are visible per individual employee without manual Z-report reconciliation.
  • For physical POS terminals using Cenaly Hardware Bridge, the electronic journal is synchronized with fiscal data — reconciliation is done against a single source of truth.
  • When an employee leaves, their PIN code is disabled in the "Employees" section without changing the general POS password for everyone else.

10. Frequently Asked Questions#

Is it legally required to separate roles and set PIN codes at the POS terminal? Federal Law 54-FZ itself does not contain such a requirement — it is an internal control measure. However, without it, proving who processed a specific operation in a dispute or shortage is much harder.

How can we quickly determine if we have a problem with "self-refunds"? Compare the refund rate and processing time for each cashier with comparable revenue (Section 2) — a sharp deviation for one person is rarely a coincidence.

A cashier left a long time ago, but we haven't changed the administrator password — what should we do? Change it immediately: the risk does not decrease over time. Also, check the reports for the period between the departure and today.

Is video recording a mandatory requirement for the checkout area? No, this is not a fiscal requirement, but a security measure at the owner's discretion.

Can we identify who processed a refund if it is not visible at the register? If the PIN codes are personal — yes, through the POS log. If everyone worked under a shared admin password, it is usually impossible to trace the specific person — a strong argument in favor of personal codes.


Related articles: ATOL cash register errors · SHTRIH-M cash register errors · complex refunds · how the FTS analyzes your POS · fines under 54-FZ

The material is for informational purposes only and does not replace legal or security advice. Primary sources: Federal Law No. 54-FZ "On the Use of Cash Registers", Art. 14.5 of the Administrative Code of the Russian Federation, cash register manufacturers' manuals on role access passwords (ATOL, SHTRIH-M, etc.).