Cash Collected in the Field That Never Reaches the Office: A Decision Tree

Why this matters

Every other loss in this group leaves a hole. Stock goes missing and the count is short. Hours go missing and the ratio moves. Field cash is different, and the difference is the whole card: when a technician takes a payment at a customer's door and nobody else ever learns it happened, there is no hole. The customer paid and went away satisfied. Your system shows an invoice with a balance on it, which is a perfectly ordinary thing for an invoice to show.

That is why a shop can run this leak for years without a single alarm. Nothing is missing, because nothing was ever recorded as present.

Why this one is structurally different

Every control you own is built on comparing two records. Bank against ledger, count against system, hours against jobs. A field cash payment defeats that by existing outside your records entirely between the customer's hand and your deposit slip. There is exactly one moment at which it can be brought inside, and that moment is the collection itself.

Three ways the same event gets closed out, none of which looks wrong from the office:

  • The invoice is simply left open and ages into the collections pile, where it sits with the genuinely unpaid ones.
  • The invoice is voided or written off under a small-balance rule, which most shops delegate precisely because chasing small balances is not worth an owner's time.
  • The invoice is adjusted downward to the amount that was banked, so the deposit reconciles perfectly.

The third is why daily reconciliation of the deposit alone will not find this. The deposit matches. It matches because the record was moved to fit it.

The signals, and what each narrows to

Branch 1: customers who say they paid. The single highest-value signal you will get, and it arrives by accident, in a collections call, in a tone of mild annoyance. Treat one instance as a real possibility of an office error and check it properly. Treat three in a quarter, all cash, all the same person, as a pattern. What narrows it: was the payment cash or a cheque? A cheque leaves a cleared image at the customer's bank with an endorsement on the back, which is the cheapest hard evidence available anywhere in this article, and you can ask the customer for it without saying why.

Branch 2: voids, write-offs and adjustments clustered on one person. Look at the rate, not the amount. Small-balance write-offs are small by construction, so the money in any one of them is trivial and the signal is entirely in who is named on them. A technician running a fifth of the jobs and carrying most of the small-balance adjustments is a fact that wants an explanation, and there are innocent explanations, including that he works the job type where partial payment is normal.

Branch 3: the cash share of collections falling with no mix explanation. Payment mix moves for real reasons over time, and the card-share card owns that trend. What you are testing here is narrower: when cash falls, did something else rise to meet it? If cash drops and card and cheque are flat, the money did not move to another method. It moved somewhere your report cannot see.

Branch 4: no signal at all. This is the normal state, and it is the reason this card exists. The absence of a hole is the defining property of the loss, so a detective control cannot be your primary defence. The controls below are preventive on purpose. A shop waiting for a signal on field cash is waiting for the customer complaint that only arrives once the pattern is large.

A worked case

A five-truck shop, about 900 invoices a quarter, offline payments running around 18 percent of collections by count of payments.

The trend test. In the most recent quarter, cash drops from 11 percent of collections by payment count to 4 percent. That is a fall of 7 points of payment count. Over the same quarter, card rises by 1 point and cheque is flat. If customers had migrated to card, card should have absorbed most of the 7 points; it absorbed 1. So 6 points of payment count are unexplained by mix, on the same base, in the same unit. Note what this does not yet say: it says the explanation the owner reached for first is wrong, not that anything was stolen. A change in which techs run which routes would also do this.

The complaints. Three customers in the quarter said they had paid at the door against invoices showing a balance. Against about 900 invoices, three is not a rate worth reading on its own. What makes it a signal is that all three were cash, all three were the same technician, and two of the three still had the paper receipt he had written by hand.

The adjustment log. In the same quarter the shop recorded 14 small-balance write-offs. The same technician is named on 9 of them, which is 64 percent of the write-offs, while he runs about 20 percent of the jobs. Both of those are shares of their own base and both are counts, so they are comparable: he carries roughly three times the share of write-offs that his share of the work would predict.

Stop here. Three independent signals point the same way, which is more than most owners ever get, and it is still not the same thing as proof. The correct next move is not a conversation. It is preservation: the write-off log, the payment history and the invoice audit trail all live in a system he can reach, and the first thing a tipped-off person does is tidy up. Pull them, or have your software's audit history exported, before anyone knows you are looking. Then work the sequencing card, which owns the detection-to-confrontation ordering for this entire group.

The innocent version, which you must test with the same energy. The two receipts the customers kept are handwritten, on a pad with no numbers on it. It is entirely possible that a technician with poor paperwork habits banked every cent and recorded none of it. That produces the same three signals. The way you tell the difference is the deposit record on the days those three payments were taken, and that is a comparison you can run without talking to him.

The customers are the witnesses, which creates a second problem

Bounding how far back to look is the sequencing card's step. What is specific to field cash is that the record you need does not exist in your shop, so the only witness to each event is the customer who paid. That has two consequences an owner rarely thinks through before starting.

The first is practical. Your look-back is a list of aged open invoices on that technician's jobs where cash was the expected method, and confirming any one of them means asking a customer whether they paid, months later, about an amount they have long since stopped thinking about. Expect a meaningful share of honest people to be unsure. The ones who remember clearly, or who kept a receipt, are your evidence; the rest are not proof of anything in either direction, and you must not treat a vague answer as confirmation because it points the way you already believe.

The second is commercial, and it arrives before the investigation ends. Somewhere in your ageing pile are customers being chased for money they already paid, and that is a churn event and a public review waiting to happen. Close those invoices as paid on the customer's word, immediately, without making them prove it, and apologise for the chasing rather than explaining the internal reason. You are not conceding anything you will need later: a customer's statement that they paid is the same evidence whether the invoice is open or closed, and the goodwill is worth more than the balance. Stop the dunning on that list on day one.

The controls that actually close it at four people

The recurring problem with published cash controls is that they assume a cashier, a supervisor and a safe. These work at your size.

  1. An independent record created at the moment of collection, by the system rather than by the collector. A payment recorded on the tech's device that immediately sends the customer a receipt by text or email is the whole control in one step, because it writes a record the tech cannot delete into a place the tech does not control: the customer's phone. The paper equivalent is a pre-numbered two-part receipt book where the customer keeps the top copy and the shop holds the carbon.
  2. Numbered books issued and returned, voids returned intact. If you are on paper, the numbering is the control and nothing else is. Log which book went to whom. A missing number is the finding, and a voided receipt has to come back with all its parts.
  3. Daily reconciliation of collections to deposits, by day. Monthly netting hides lapping, which is the practice of covering one day's shortfall with the next day's takings. A day-by-day comparison breaks it, because lapping requires the days to stay blended.
  4. Nobody voids, writes off or adjusts their own collection. Above a stated threshold it goes to a second person. Below it, the write-off list still gets read monthly by the owner, in full, with names on it. The reason is in the worked case: the useful signal was a rate, and a rate is invisible unless somebody reads the whole list.
  5. The rule that the invoice closes, not the cash. A tech's job at the door is to record the payment against the invoice on the device. If the device is the only way a payment can be recorded, the paper problem disappears.

The structural answer: get off field cash

Every control above is friction you are adding to keep a risk manageable. The alternative is to remove the risk, and for most shops it is now genuinely available.

Card on file, a payment link the customer opens themselves, a portal payment, or a card taken on the technician's device all share one property: the money never exists in a form a person can put in a pocket, and the record is created by the processor rather than by anyone in your shop. That single change closes this branch entirely, and it closes the disputed-payment argument with it, because the processor's record is neutral.

What changes the answer. Some customer segments will not move: older residential customers, certain commercial accounts that pay by cheque on their own cycle, jobs in areas with poor signal where a device cannot take a card at the door. So the realistic target is not zero, it is small and named. Decide which customers may pay cash, write it down, and put every other job on an electronic method by default. The smaller the cash population, the more effective every control above becomes, because a signal that would vanish in the noise at 18 percent of payments is loud at 2 percent.

And the honest trade: card processing costs a percentage of the ticket. Compare that to a loss with no hole in it, which can run for years and which you will discover, if you ever do, from a customer who is annoyed at being chased for money they already paid.

References

  • See related: What Share of Collections Arrives by Card, which owns the payment-mix trend and its legitimate causes
  • See related: Before You Accuse Anyone: The Sequence, which owns evidence preservation and the order of the conversation
  • See related: Separating Duties in a Shop With Four People, which owns the receive-and-record rule this card depends on
  • See related: The Past Due Collections SOP; Deposits and Prepaids: Money You Haven't Earned Yet