# POS Discrepancy Deep Dive Analysis

**Event:** Mohamed Abdo NYE 2025
**Analysis Date:** 6 January 2026
**Methodology:** POS Orders vs Orphaned Revolut Payments Pattern Matching

---

## EXECUTIVE SUMMARY

### Reconciliation Results

| Category | Count | Amount |
|----------|-------|--------|
| **POS Card Orders** | 76 | £189,550 |
| **Orphaned Revolut (event days)** | 96 | £138,511 |
| **Matched (time+amount)** | 33 pairs | £70,250 |
| **Unmatched POS** | 43 orders | £119,300 |
| **Unmatched Revolut** | 63 payments | £68,261 |

### Two-Way Mismatch

| Issue | Amount | Explanation |
|-------|--------|-------------|
| **DB ONLY** (no Rev at amount) | £87,350 | Different terminal or never charged |
| **REV ONLY** (no POS at amount) | £32,510 | Door sales without orders |
| **DB Excess** (more DB than Rev) | £11,250 | Some matched, some not |
| **REV Excess** (more Rev than DB) | £15,000 | 15 extra £1,000 payments |
| **NET DISCREPANCY** | £51,090 | DB higher than Revolut |

---

## KEY FINDINGS

### 1. Amount-Based Mismatch Analysis

**DB-ONLY Amounts** (exist in DB but NOT in Revolut at all):
- £7,800 x 1 = £7,800
- £6,650 x 1 = £6,650
- £5,550 x 2 = £11,100
- £4,350 x 4 = £17,400
- £3,700 x 6 = £22,200
- £1,850 x 5 = £9,250
- £1,100 x 4 = £4,400
- £550 x 1 = £550
- **TOTAL: £79,350**

**REV-ONLY Amounts** (exist in Revolut but NOT in DB at all):
- £4,200, £2,950, £2,100 (x3), £1,700, £1,400 (x2), £1,200
- £950, £700 (x5), £690, £600 (x2), £500 (x11)
- £450, £400, £310, £300, £60
- **TOTAL: ~£32,500**

### 2. Multi-Payment Clusters

Found 14 clusters of Revolut payments within 3-minute windows:

| Cluster | Payments | Total | Pattern |
|---------|----------|-------|---------|
| 4x £700 | 4 | £2,800 | 4 taps in 65 seconds |
| 3x £500 | 3 | £1,500 | 3 taps in 61 seconds |
| £1,400 + £4,200 | 2 | £5,600 | Near £5,550 order? |
| £1,000 + £500 + £500 | 3 | £2,000 | 3 taps in 149 seconds |

**Insight**: Staff may have been charging individual tickets instead of order totals.

### 3. Pricing Variations (NOT Errors)

BROWN tier was intentionally priced at £1,450 (vs template £550) for high demand.
- 17 BROWN tickets at £1,450 across 8 orders
- Metadata shows `tier_price: 1450.00` - template was updated for dynamic pricing
- **This is intentional, not overcharging**

Note: No `price_override` flag exists - future improvement to track standard vs custom pricing.

---

## UNMATCHED POS ORDERS (43 orders, £119,300)

### Amounts That Don't Exist in Revolut

| Order | Amount | Customer | Date | Issue |
|-------|--------|----------|------|-------|
| 724 | £7,800 | Lama Almusallam | 12-30 17:28 | 4x VVIP - NO Revolut match |
| 752 | £6,650 | Ahmed Abuobaid | 12-30 22:24 | Mixed - NO Revolut match |
| 729 | £5,550 | maryam al kuwari | 12-30 18:46 | 3x VIP - NO Revolut match |
| 744 | £5,550 | atheer | 12-30 21:26 | 3x VIP - NO Revolut match |
| 675 | £4,350 | Manal Zaid | 12-29 16:55 | 3x BROWN@1450 - NO Rev |
| 679 | £4,350 | aalaa khelaidi | 12-29 17:37 | 3x BROWN@1450 - NO Rev |
| 688 | £4,350 | homood almutairi | 12-29 19:04 | 3x BROWN@1450 - NO Rev |
| 691 | £4,350 | Mohammed Alothman | 12-29 19:40 | 3x BROWN@1450 - NO Rev |

### £3,700 Orders (6 orders = £22,200)

All 2x VIP @ £1,850 = £3,700, but Revolut only has 1 payment at £3,700.

| Order | Customer | Date |
|-------|----------|------|
| 656 | Turkey Mohamed | 12-28 18:37 |
| 657 | awatif alsabah | 12-28 18:49 |
| 702 | Mohamed Bader | 12-29 23:16 |
| 745 | muteb alotaibi | 12-30 21:33 |
| 747 | tamim alabdulla | 12-30 21:41 |
| 753 | Ahmed Abuobaid | 12-30 22:28 |

---

## UNMATCHED REVOLUT PAYMENTS (63+ payments, £68,261+)

### Amounts That Don't Exist in DB

| Amount | Count | Total | Likely Explanation |
|--------|-------|-------|-------------------|
| £1,000 | +15 excess | £15,000 | Door sales without orders |
| £500 | 11 | £5,500 | Standard tickets not entered |
| £700 | 5 | £3,500 | Custom amount on Reader |
| £2,100 | 3 | £6,300 | Multiple tickets? |
| £600 | 2 | £1,200 | Custom amount |

### Door Sales Without Orders

~£32,500 in Revolut payments have no corresponding DB order at that exact amount.
These are likely:
1. Customers paid at door but staff didn't create order
2. Custom amounts typed on Revolut Reader
3. Multi-tap payments (3x £700 instead of 1x £2,100)

---

## HYPOTHESES FOR INVESTIGATION

### Hypothesis A: Different Terminal
Some POS orders were charged on a terminal other than Revolut Reader.
- Check: Were there other card machines in use?
- Check: MBS terminal report shows ~£250k but Revolut only £224k

### Hypothesis B: Orders Never Actually Charged
Some orders were marked as "credit_card" and "completed" but payment never taken.
- Check: Were these customers admitted to event?
- Check: Any declined transactions in terminal logs?

### Hypothesis C: Amount Mismatch
Staff charged different amounts on Revolut Reader than the order total.
- Evidence: 4x £700 cluster at 18:56-18:57 (£2,800) but no £2,800 order
- Evidence: 3x £500 cluster at 21:24-21:25 (£1,500) but no £1,500 order
- Possible: Staff charged per-ticket instead of per-order

### Hypothesis D: Untracked Door Sales
Staff used Revolut Reader "Custom Amount" without creating orders.
- Evidence: 11 x £500 payments with NO £500 orders
- Evidence: 5 x £700 payments with NO £700 orders
- Total: ~£32,500 in confirmed payments without orders

---

## RECOMMENDED ACTIONS

### Immediate
1. [ ] Review the 43 unmatched DB orders - were customers actually charged?
2. [ ] Cross-reference with MBS terminal report for secondary terminal transactions
3. [ ] Contact staff about door procedures on Dec 28-30

### Data Corrections
1. [ ] If orders were never charged, mark as `cancelled` or `payment_failed`
2. [ ] If found matching Revolut by different criteria, link with `revolut_payment_id`

### Process Improvements
1. [ ] Disable "Custom Amount" on Revolut Reader
2. [ ] Require order creation BEFORE payment
3. [ ] Add price_override tracking to line items
4. [ ] Real-time reconciliation alerts

---

## FILES GENERATED

| File | Location | Purpose |
|------|----------|---------|
| `POS_DISCREPANCY_ANALYSIS_2026-01-06.md` | Local | This analysis |
| `pos_orders_detailed.json` | Server | All POS orders with details |
| `orphaned_with_cardholders.json` | Server | Orphaned Revolut payments |

---

*Analysis performed 6 January 2026*
*Continuation of forensic audit session from 5 January 2026*
