
Loyalty Fraud
Part of Loyalty fraud and abuse
Reviewing employee access to member balances
Audit who can view or change loyalty balances, review sensitive actions and remove permissions that staff no longer need.
List every role that can view a member balance, change it or issue a reward. Check whether each permission is still needed. Balance changes need tighter control than viewing. Every sensitive action should be attributable and explainable.
Map permissions to tasks
A store associate may need to check reward availability. A support agent may need transaction history to resolve a complaint. A programme administrator may need to correct a balance after an approved case. These tasks do not automatically require the same access.
| Action | Review question |
|---|---|
| View balance or history | Is the view needed for this role and limited to relevant records? |
| Add or remove points | Is a case reason required, and can the operator approve their own adjustment? |
| Issue, cancel or restore a reward | Can a reviewer trace the resulting member and ledger record? |
| Export member data | Who can request, create and receive the file? |
Include temporary and agency staff, service accounts, vendor access and shared till logins. A shared login that cannot identify the operator weakens the audit trail. Check which permissions the actual platform and identity provider can separate; systems vary.
Revalidate access
Compare user accounts with current staff duties. Remove access left after a transfer or departure. Recheck elevated access regularly and after role changes.
Use individually attributable accounts and multi-factor authentication for sensitive staff access where the platform or identity provider supports it. Where the platform allows it, keep privileged access separate from ordinary user accounts and tie it to authorised duties.
For rare corrections, use a defined approval route and a separate privileged account where applicable. Keep an emergency process with a later independent review. Avoid giving an ordinary user account broad privileges simply for convenience.
Review what staff did
Sample manual credits and debits, reward issues, exports and unusual member-record views. Match each action to a case, operator, time and outcome. Repeated adjustments or a cluster of actions under one account warrant a check, but can also reflect legitimate incident work.
Preserve original ledger entries and post a separate correction when needed. If a review suggests unauthorised access to personal information, involve the privacy or security response owner. Entities with obligations under the Privacy Act must comply with the Notifiable Data Breaches scheme; the OAIC provides guidance to help assess whether a data breach needs to be notified.
End the review with owners for permission changes, known platform limits and follow-up dates.
Key compliance and security metrics
- Audit frequency
- Quarterly
- Mandatory breach notification threshold
- If likely to result in serious harm
- Multi-factor authentication requirement
- For all privileged access
- Shared login risk
- High – weakens audit trail



