Retail loss prevention strategies that work
What the NRF shrink numbers actually say, and the floor layout, exception reporting, officer training and outside partnerships that answer retail theft.

A store loses merchandise four ways, and only one makes the news. The smash-and-grab video goes viral. The returns clerk running a credit scheme for eighteen months does not. Retail loss prevention built only for the loud threat leaves the expensive one running.
Retail shrink runs a little over one and a half percent of sales industry-wide, and roughly two-thirds of it is theft. Defending against it takes four layers: a floor laid out so merchandise can be seen, physical protection on the items that actually walk, transaction analytics that catch the internal side, and officers trained for the specific decision of when not to intervene. Outside partnerships turn apprehensions into prosecutions.
How much does retail theft actually cost?
The National Retail Federation's security survey put the average shrink rate at 1.6 percent of sales in FY2022, or $112.1 billion, up from 1.4 percent the year before. In the same survey, internal and external theft together accounted for about 65 percent of shrink. The rest is paperwork and vendor error, which is worth remembering before you buy cameras to solve an inventory count problem.
The mix is moving. NRF's 2026 study reports shoplifting incidents down 12.4 percent in 2025 against 2024, while fraud schemes climb: 69 percent of retailers report more phone scams, 51 percent more loyalty fraud, 42 percent more gift card fraud. If your program is still aimed entirely at the sales floor, it is aimed at the part that is shrinking.
Be careful with the organized retail crime numbers specifically. GAO looked at them and found that the widely quoted annual ORC loss figures came from nowhere anybody could name: "it is unclear how these estimates were developed and neither the FBI nor industry groups were able to identify the sources for these figures". That report is from 2011 and the sourcing has not improved much since. Argue your program from your own shrink numbers, not from a headline.
What are you actually defending against?
Four distinct problems that need four different answers.
Organized theft rings. Not opportunists. They scout the store first, know which items resell, and take a planned quantity in a planned window. The merchandise is listed online within days. Visible security does not deter them because they already accounted for it during the scout.
Smash-and-grab. A group comes through the door in numbers specifically so that nobody can intervene. The merchandise loss is often the smaller part. The staff who were standing there quit, and the ones who stay want to know what you are going to do about it.
Internal theft. The employee knows where the cameras point, which shift is thin, and which manager does not check the void report. Internal loss frequently exceeds external loss in dollar terms and it rarely produces an incident anybody witnesses.
Return fraud. Receipt manipulation at the simple end, and at the other end a ring converting stolen goods into store credit and then into cash. It shows up in the transaction data long before anybody sees it on the floor.
What does physical security still do?
Most of the work, and it is the cheapest layer you have.
Start with sightlines. High-value merchandise where staff and cameras can see it, fixtures laid out so there is no aisle where a person can stand unobserved for two minutes, mirrors in the corners the plan could not fix. A single funneled exit if the fire code and the format allow it. A backroom door that locks and a rule that it stays locked.
Then protect the items that actually walk out. Locked cases for the top tier, which costs you conversions and stops grab-and-go entirely. EAS tags with working pedestals, so the alarm at the door is both the deterrent and the detection. Cable locks, spider wraps and keepers for the awkward shapes. Theft-prone stock kept away from the exits.
Which items get which treatment should come off your own shrink report, refreshed quarterly. The list changes with resale value, and last year's list will be protecting things nobody wants anymore. A physical security audit is the structured version of this walk.
What does the technology add?
It extends attention, which is the thing humans run out of first.
Video analytics flag behavior worth a look, loitering in a fixed spot, concealment movements, a pattern the operator can act on in the moment instead of finding on Thursday. Tied to the point of sale, the register event and the footage of it sit side by side. How far video analytics has actually come covers what these systems do and do not detect reliably.
Exception-based reporting is the one most operations skip and the one that catches internal theft. It reads the transaction stream and flags the anomalies: a cashier whose refund volume sits four standard deviations off the store's, voids clustered at the end of a shift, discounts that match no live promotion. Link it to video and an investigator can confirm or clear a flag in ten minutes.
Traffic and heat mapping is a merchandising tool that happens to help you. Knowing which parts of the floor get walked tells you where to put the officer and where the unwatched corner really is.
Facial recognition sits in a different category. Where it is lawful it identifies known offenders at the door, and where it is not, deploying it is an expensive legal problem. Several states and cities regulate it specifically. Check your own jurisdiction and your client's tolerance before it appears in a proposal.
Uniformed officers, plain clothes, or both?
Both, doing different jobs.
The uniform deters the opportunist and reassures the staff, and reassuring the staff is half of what the client is buying after an incident. It does nothing against a crew that watched your officer's route last Tuesday.
Plain clothes investigators catch what the uniform cannot, because the deterrent effect they lack is exactly what lets them observe. The tradeoff is that apprehension carries real exposure. Detention authority, use of force, and what your officer may do off the property are set by state law and by your client's own policy, and the two often disagree. Get both in writing before anybody stops anybody.
Retail security training has to cover the specific things this post demands: recognizing a coordinated group before it commits, de-escalating a confrontation with someone who has decided to fight, collecting evidence that survives contact with a prosecutor, and the hardest one, when to let it go. Merchandise is replaceable. Building the training program covers how to structure that, and writing incident reports people read covers the documentation half.
Documentation is where most apprehensions die. A report written from memory the next morning, with no photos and no timestamps, will not support a charge. Reports filed from the floor with a photo, a GPS fix and a server timestamp will. That is the whole case for getting incident reports off paper. Descriptions of repeat offenders belong somewhere every officer on shift can read them, on a shift channel rather than in one supervisor's head.
Who do you need on the outside?
Three relationships, all of which take time to build and none of which you can build during an incident.
- Local law enforcement. A named detective who knows your stores gets you a different response than a general dispatch line. Feed them repeat offender information, plate numbers and patterns rather than only calling when you need something.
- The regional ORC task force. These exist to connect incidents across jurisdictions, which is the only level at which a ring is actually visible. One store's four thefts are a nuisance. Forty stores' incidents are a case.
- Other retailers, including competitors. The same crew is hitting all of you. Industry information sharing through a retail association is how you find out that the man in your footage was in three other stores that week.
Then follow through on prosecution. Providing the witness, the footage and the paperwork is unglamorous and it is the difference between a consequence and a release. Word travels about which chains are worth the risk.
How do you know the program worked?
Shrink rate by store, quarter over quarter, is the outcome measure. It is also slow and noisy, so pair it with things that move faster: EAS activations, apprehensions and their disposition, exception flags raised and cleared, and incidents by hour of day.
Hour of day is the one that usually pays for itself. If your losses cluster in a two-hour window, that is a staffing question, and it is a much cheaper answer than another round of hardware. Seasonal peaks work the same way, which is the subject of staffing retail through the holidays.
Key Takeaways
- Shrink averaged 1.6 percent of sales in NRF's last published survey, about 65 percent of it theft.
- Shoplifting fell in 2025 while fraud schemes rose. Point the program at both.
- Four different problems, four different answers. Building only against the visible threat misses internal theft.
- Exception-based reporting is the highest-yield tool most operations do not have.
- Measure by store and by hour of day. The staffing answer is usually cheaper than the hardware answer.
Continue Reading

Event security planning: staffing to egress
Risk assessment, a staffing number you can defend, screening throughput, crowd density and the exit plan, for concerts, festivals and corporate events.

Construction site security: threats and the plan
What gets stolen from a jobsite, how to assess the risk at each phase, and how to choose between patrol, remote monitoring and a standing guard.

Hospital security: violence, access and response
What hospital security teams plan for: workplace violence in the ED, behavioral health elopement, infant abduction drills and the privacy limits on a report.