Physical controls stop shrink from happening. Forensics figures out where it already went. Those are two different jobs, and most shops only do the first one.
If you've already tightened up your low-cost physical controls and counting cadence, you know the frustrating part: the controls slow the bleeding, but they don't tell you who or what caused the last $2,300 gap between your book value and your shelf. You just know the number is wrong, and you're staring at a variance report with no idea whether it's a receiving error, a mislabeled SKU, a mechanic pocketing chain lube, or a POS that never rang the sale.
This is a forensic problem, not a controls problem. And forensics has an order of operations. Do the cheap, high-signal pulls first. Save the awkward staff conversations for last, after the data has already told you where to look. Most owners do it backwards — they get suspicious, confront a person, poison the room, and then start pulling reports. By then the trail is cold and morale is worse.
What follows is a 7-step routine ranked roughly by return on the hour you spend. The early steps cost you 20 minutes and eliminate most false alarms. The later steps cost real time and social capital, so you only run them when the earlier steps actually point you there.
Before you start: define the gap in dollars and categories
Don't investigate "shrink." Investigate a number. A vague sense that "stuff walks out of here" leads to a witch hunt. A specific line — tubes and CO2 are down $410 against book over 90 days, everything else reconciles — leads to a fix.
-
Paper shrink — the item exists, the record is wrong (receiving miscounts, unposted returns, SKU mapping errors)
-
Process shrink — the item left without being recorded correctly (warranty swaps, comped parts, tech consumables never logged)
-
Real loss — theft, external or internal
Roughly 70% of what shops call theft turns out to be the first two. That's not optimism — it's just what the numbers show once you actually separate them. Which is exactly why you don't start with people.
The 7-step forensic routine, ranked by ROI
Step 1 — Pull the negative-on-hand and impossible-quantity report (10 minutes, highest ROI)
Never miss a sale or service appointment again.
Bicyclly helps you manage every sale, repair, and booking with ease and accuracy.
- Unified inventory and sales tracking
- Automated customer notifications
- Service appointment scheduling
No credit card required
Your first pull is the one that finds errors, not thieves. Run a report of every SKU sitting at a negative quantity, plus anything with a wildly implausible on-hand (say, 340 valve caps when you order in packs of 10).
Negatives are gold. A negative on-hand means you sold or consumed more than the system thinks you received. That's almost never theft — it's a receiving failure or a SKU where two variants got merged. Every negative you clean up shrinks your apparent loss without any drama.
A typical example: a shop shows $1,900 in unexplained shrink. The negative-on-hand report reveals a case of 32-ounce sealant was received under the 8-ounce SKU. One line fix recovers about $600 of the "loss" instantly. Nobody stole anything.
Follow-up action: for every negative, trace the last receiving event and the last three sales. Correct the mapping — don't just zero it out — or it comes back next quarter.
Step 2 — Reconcile the till and the no-sale / void log (15 minutes)
Pull the transaction exceptions from your POS: voids, returns without a receipt, manual price overrides, and no-sale drawer opens. Sort by employee and by time of day.
You're not accusing anyone yet. You're looking for pattern density. One void is nothing. Fourteen voids clustered on the same register between 5:30 and 6:00 PM, all under $40, all by the same login — that's a pattern worth a real look. Small, repeated, under a threshold nobody double-checks. That's what internal cash shrink actually looks like. It's rarely a dramatic $500 grab.
| Exception type | Low concern | Worth a closer look |
|---|---|---|
| Post-sale voids | Occasional, logged with reason | Clustered by user, no reason noted |
| No-receipt returns | Rare, manager-approved | Repeating amounts, same login |
| Price overrides | Matches promo calendar | Off-calendar, round-dollar patterns |
| No-sale drawer opens | Making change, start of shift | Multiple mid-shift, single register |
Follow-up: pull the camera timestamps (if you have them) for the top three clustered events. Don't watch hours of footage — jump to the exact minute the exception hit.
Step 3 — Audit the warranty and comp trail (20 minutes)
This is the step almost every shop skips, and it's where process shrink hides in plain sight. Warranty replacements, goodwill swaps, and "just throw a new one on for them" moments consume real parts that often never leave a proper record.
Pull every warranty and comp transaction for the period. Match each one to a supplier credit or a documented customer. If a mechanic swapped six derailleurs under warranty but you only received two credits back from the distributor, you've found four derailleurs of shrink — and it's a documentation gap, not necessarily dishonesty.
Real numbers here matter: one mid-size shop found roughly $2,800 a year in "shrink" that was actually warranty parts installed without ever filing the manufacturer claim. Parts gone, credit never collected. That's not theft. That's money left on the counter.
Follow-up: build a one-line rule — no warranty part leaves the bin without a claim number or a customer name attached to the ticket.
Step 4 — Test high-shrink categories with a targeted blind count
By now the data has narrowed things to specific categories. Don't recount the whole store. Blind-count only the top offenders — usually consumables and small high-value items: tubes, CO2, chain lube, multitools, tail lights.
Blind means the counter doesn't see the expected quantity. If staff counts against the system number, they'll unconsciously correct toward it, and you learn nothing. This is the same discipline behind a proper pre-season inventory audit that finds miscounts and high-risk SKUs fast — you're just applying it surgically to the categories the forensic trail already flagged.
Do this count twice, a week apart, on the same SKUs. A single count tells you the gap. Two counts tell you the rate. If tubes drop 11 units in seven days with only 6 sold, you now have a measured leak of about 5 units a week to explain.
When blind-counting, ensure counters don't see the expected quantity so the results aren't biased toward the system number.
Step 5 — Reconstruct the receiving door
If the leak is happening on inbound — and Step 1's negatives hinted at it — spend an hour on receiving. Pull three recent POs and physically match:
-
What the supplier invoice says shipped
-
What the packing slip says
-
What got received into the system
-
What's actually on the shelf right now for those lines
Discrepancies between lines 1 and 2 are supplier problems — file the claim. Discrepancies between 2 and 3 are your receiving process. Discrepancies between 3 and 4, with clean paperwork, start pointing toward post-receiving loss.
The pattern shops miss: partial shipments received as complete. A box arrives, someone scans the PO as fully received to clear the queue, the backordered items never show up, and three weeks later the shelf is short with perfect-looking records. Looks like theft. Was a receiving shortcut.
Step 6 — The structured staff conversation (only now)
You've done five steps of quiet work. You have specific numbers, specific categories, specific time windows. Now you talk to people — and you talk to everyone, not just your suspect, so it reads as process improvement rather than an interrogation.
Keep it tight and non-accusatory. The goal is information, not confession. Here's a script that actually works:
> "We're tightening up our inventory process because our counts on tubes and lube aren't matching. Not pointing fingers — I need your help figuring out where the record breaks. Walk me through what happens when you grab a tube for a repair. Do you always ring it to the ticket, or does it sometimes get skipped when it's busy?"
That last question does the work. Most process shrink surfaces the moment you make it safe to admit "yeah, when it's slammed we just grab and forget." You'll often solve the case right there without ever framing it as theft.
For the exception patterns from Step 2, if they point at one person, keep it factual and one-on-one:
> "I'm reviewing register exceptions and I'm seeing a cluster of voids on your login around closing. Help me understand what's happening at that time of day."
Let silence do its job. Don't fill it.
Step 7 — Camera and access review (highest cost, lowest frequency)
Only if Steps 1–6 point to genuine internal theft do you spend time here. Reviewing footage is expensive in hours and toxic in vibe if done fishing-style. Use it surgically: exact timestamps from the exception log, exact SKUs from the blind count, exact days from the measured leak rate.
This step is a confirmation tool, not a discovery tool. If you're using cameras to find the problem, you skipped the cheaper steps that would've told you where to point them.
A quick workflow image.
The last element here is a reminder: the order matters. Cheap data first, targeted counts next, conversations only after the numbers narrow the question.
When this full routine makes sense — and when it doesn't
Run the whole 7-step routine when: your measured variance is meaningful (more than roughly 1–1.5% of inventory value), it's recurring across multiple counts, and it's concentrated in specific categories. That combination means there's a real, repeatable cause worth chasing.
Run only Steps 1–3 when: the gap is small, occasional, and spread evenly. That's almost always paper and process shrink. The blind counts, receiving reconstruction, and camera reviews aren't worth the hours.
Do NOT jump to Steps 6 and 7 first if you value your team. The fastest way to lose a good mechanic is to accuse them of theft over what turns out to be a SKU mapping error. Every experienced shop owner has watched a suspicion sour a relationship that the data later exonerated. Order of operations isn't just efficiency — it's how you avoid burning trust on a problem your POS created.
A short real scenario
A two-bay neighborhood shop doing somewhere around $600k a year kept posting quarterly shrink of roughly $1,800–$2,200. The owner assumed it was walk-out theft from the sales floor and was close to installing more cameras.
-
Step 1 cleaned up four negative-on-hand SKUs — about $500 was pure mapping error.
-
Step 3 found roughly $900 a year in warranty tubes and a couple of cassettes installed but never claimed back from the distributor.
-
Step 4's blind counts showed tubes and CO2 genuinely leaking at a small, steady rate.
-
Step 6 cracked it
two techs admitted they grabbed tubes and CO2 mid-repair on busy Saturdays and never rang them to the ticket. No theft. Pure "we were slammed and forgot."
The fix wasn't cameras. It was a shelf-side tap-to-log step on consumables and a Saturday closing checklist. Next quarter's shrink came in under $700, and most of what remained was normal breakage and demo use. The camera budget got redirected toward a better repair-tracking setup instead.
Turning the investigation into a standing routine
A forensic pull you run once is a fire drill. A forensic pull you run every month becomes early warning. The whole point is to catch the $200 leak in week two instead of the $2,000 gap at year-end.
Recurring cadence worth locking in:
-
Weekly glance at the exception log (voids, no-receipt returns, overrides). Two minutes.
-
Monthly run negative-on-hand, blind-count your top 10 high-shrink SKUs, reconcile warranty claims to credits received.
-
Quarterly full variance split into paper / process / real, plus a receiving-door reconstruction on a random sample of POs.
This is where the right systems earn their keep quietly. If your POS and inventory platform can flag negative on-hands automatically, surface void clusters by login, and tie every warranty part to a claim number without you exporting three spreadsheets, the monthly pull drops from an afternoon to about fifteen minutes. The forensics don't change — the labor of gathering the evidence does.
But the tools are secondary to the sequence. Refusing to skip straight to accusation is the single most valuable habit here. Pull the cheap data first. Separate the errors from the losses. Talk to people only after the numbers have already narrowed the question. Do it in that order and you'll close most cases before you ever have to have a hard conversation — and the shrink that's left will actually be worth confronting.
But the tools are secondary to the sequence. Refusing to skip straight to accusation is the single most valuable habit here. Pull the cheap data first. Separate the errors from the losses. Talk to people only after the numbers have already narrowed the question. Do it in that order and you'll close most cases before you ever have to have a hard conversation — and the shrink that's left will actually be worth confronting.
Ready to revolutionize your bike shop operations?
Join hundreds of bike shops using Bicyclly to save time, increase revenue, and deliver exceptional customer service.