An expense audit is a review of submitted employee expense reports that confirms every charge is legitimate, documented, and compliant with company policy before reimbursement. Auditors match each line item to a receipt, test that receipt for authenticity, check the claim against policy thresholds and tax rules, and search for duplicates already reimbursed elsewhere.
For two decades, finance teams treated expense review as a sampling exercise. They pulled a slice of reports, checked those by hand, and reimbursed the rest on trust. Two changes have made that arrangement harder to defend. Measured fraud losses climb with the time a scheme runs undetected, and generative AI has cut the cost of a forged receipt to almost nothing.
An expense audit verifies that a submitted employee expense report is accurate, supported by valid documentation, and aligned with the organization’s reimbursement policy. An auditor matches each line item to its receipt, confirms the expense served a business purpose, and flags anything that breaks a rule or fails an authenticity test.
Three activities share vocabulary, and finance teams often blur them together. Expense reconciliation matches recorded transactions, such as corporate card charges, against statements and the general ledger, so it confirms the books balance. A financial statement audit is a far broader independent examination that an external firm ordinarily performs once a year. An expense audit polices the claims employees submit, which makes it the only one of the three that examines an individual claim before money leaves the company.
Every expense audit moves through the same six stages. Our stage-by-stage walkthrough sets out each stage, the condition it tests, and the trigger that releases a report to the next one.
Expense audit matters more in 2026 than it did five years ago because two trends raised the cost of leaving spend unexamined: fraud losses scale the longer a scheme runs, and forged receipts became cheap to manufacture using free, easy-to-use generative AI tools.
The Association of Certified Fraud Examiners (ACFE) is a professional body that studies workplace fraud. It examined 2,402 real cases across 143 countries for Occupational Fraud 2026. The report records a median loss of $104,000 per case and a median scheme length of 12 months before discovery. Schemes caught within six months carried a median loss of $40,000. Schemes that ran five years or longer passed $1.1 million. Asset misappropriation, the category that includes inflated and fabricated expense reports, appeared in 90% of cases. Duration determines cost, and sampling extends duration by design.
Generative AI has since cut the effort a forgery takes to about 30 seconds. PYMNTS reported an analysis of AppZen enterprise expense data in June 2026. AI-generated documents rose from 0% of flagged fraudulent receipts in March 2025 to 70.8% by mid-May 2026. That covers 1,471 fake receipts submitted by 745 employees at 174 companies. HR Executive reported a July 2026 survey of 2,000 workers in the US and the UK. Four in ten US employees admitted using AI to create a fake receipt. An employee now produces a fraudulent claim faster than a reviewer can examine one.
An expense audit tests five things about a claim. It checks whether the receipt is genuine, and whether the same charge already reached reimbursement. It then checks whether the item sits inside policy, whether foreign and regulated spend carries the right documentation, and whether the card record agrees with the report.
Authenticity work goes past optical character recognition (OCR), the conversion of an image into machine-readable text. Detection examines image metadata, meaning the hidden file information stored inside the document. That metadata sometimes carries signatures receipt generator sites leave behind. Detection also confirms that line items and tax sum to the stated total. It checks that the merchant trades at the claimed location, and compares the document against known receipts from the same vendor. Forged documents usually fail on arithmetic or merchant reality before they fail on appearance.
Three guides cover this layer. Our explainer on fake receipt detection describes what finance teams face. The detection playbook gives the controls that catch a forgery. Our breakdown of receipt fraud separates the four types a reviewer encounters.
Duplicates are the highest-volume category of expense leakage and the least deliberate. The same dinner arrives once as an itemized restaurant receipt and again as a card statement line. A conference fee appears on a manager’s report and on the attendee’s. Matching on amount, date, and merchant catches the obvious cases and misses the rest. Reading the receipt image catches submissions that arrive months apart or through different systems. Our answer page on duplicate expense names the five ways a duplicate reaches reimbursement.
Policy checks cover per diem limits, meaning the fixed daily allowance an organization sets for travel costs. They also cover alcohol rules, class of travel, personal items, attendee counts on meals, and spend an employee splits across several claims to stay under an approval threshold. Splitting is the pattern manual reviewers miss most often, because each claim looks compliant on its own. A policy only works when reviewers can enforce it. Our guides cover expense policy writing and enforceable travel policy design.
Cross-border programs add tax documents that need local validation, including the fapiao, the official receipt issued under Chinese tax law, and value-added tax (VAT) receipts across Europe. Life sciences companies also report spend under the Sunshine Act, the US law requiring disclosure of payments to physicians. Any organization operating overseas carries Foreign Corrupt Practices Act (FCPA) exposure on gifts, travel, and hospitality for government officials. A general reviewer cannot apply these rules consistently at volume. Our guide to AI travel expense audit works through hotel folios, per diems, and multi-country trips.
Card programs put a second record beside the expense report, and the two disagree more often than finance teams expect. A reviewer who reads only the report never sees a charge the employee never reported. Our guide on corporate card management covers what happens after the swipe. Our listicle on corporate credit card fraud names seven patterns, and our corporate travel card buyer guide sets out what to ask a provider.
Expense audits differ on three axes, namely who performs the audit, when the audit happens, and how the auditor selects reports. Each axis changes what the program can prevent rather than merely record.
By who performs it. An internal audit team enforces policy and catches waste inside the organization. An external firm examines controls as part of broader assurance work. The Internal Revenue Service (IRS) tests whether reimbursements followed tax rules. The accountable plan rules in IRS Publication 463 set three conditions for tax-free reimbursement. The plan must show a business connection. The employee must account for the expense within 60 days, and return any excess within 120 days.
By timing. A pre-payment audit reviews reports before reimbursement, so finance stops a bad claim before money leaves the company. A post-payment audit turns a control into a collections exercise, and recovery rates are poor once the pay cycle closes.
By selection method. Random sampling pulls an arbitrary subset of reports. Risk-based sampling targets reports showing suspicious signals such as high amounts, round numbers, or repeat offenders, and it finds more per hour spent. Full coverage examines every line of every report. Risk-based sampling still leaves unexamined every report the rule set never scored as risky, which is exactly where a new fraud pattern hides. Our listicle on expense fraud detection works through nine red flags, and our guide on auditing expense reports sets out what to check and in what order.
Finance teams commonly judge a program by the number of violations it found last quarter. That figure reflects what reviewers examined rather than what employees submitted. Four variables determine whether a program works.
Coverage is the share of reports and line items that receive a real review. A 15% sample gives finance a 15% view of the underlying risk, and nothing about the other 85%.
Timing decides whether the program prevents a loss or pursues one. Pre-payment review stops the payment. Post-payment review opens a recovery case.
Evidence depth separates a fake receipt from a true one. Confirming an attachment is present is not the same as confirming that the merchant trades at that address, sold that item, and charged that tax.
Disposition is what happens after a flag. A program that routes every exception to one queue builds a backlog and teaches reviewers to approve quickly. Exceptions need sorting by risk and dollar value, with explicit rules for automatic approval, employee query, and escalation.
Five measures support that assessment. Track the audit coverage rate. Record the share of exceptions caught before payment. Measure auditor hours spent on reports that turn out clean. Monitor average days to reimbursement. Track the repeat violation rate by employee as a measure of deterrence. A program that reports the same violation from the same person every quarter is reporting rather than controlling. Our benchmark guide to T&E spend explains how to size each measure against peers.
Sampling fails at enterprise volume because auditor capacity, rather than risk, sets the sample size. A human auditor needs roughly 20 minutes to open a report, match line items to receipts, check merchant details, and confirm policy thresholds. That arithmetic forces a choice, and most finance teams settle on 10% to 20% of expense transactions. Employees submitting the reports understand the odds, and the 12-month median scheme length ACFE reported in 2026 has a long runway inside a program that examines one report in five. Our analysis of 100% audit coverage works through the cost argument that used to justify the compromise.
Scale compounds the problem. A global organization operates multiple legal entities, settles in dozens of currencies, and receives reports in many languages. Tax rules differ by country, from VAT recovery in Europe to fapiao requirements in China. One reviewer in one time zone cannot apply every local rule at speed. Our framework on expense management automation tests whether verification should stay manual, and our guide to travel and expense management names the verifications teams most often skip.
Most expense audit programs fall short because the organization bolted audit onto the end of a submission workflow as a configurable rules engine. Expense platforms improved the submission experience considerably, since receipt capture works, mileage tracking works, and card feeds arrive clean. Audit remained an afterthought.
Rules engines fail in two specific ways. They catch only the violations someone anticipated and encoded, so a new fraud pattern stays invisible until a person notices a trend. They also generate volume without judgment, so teams tune thresholds down until the queue becomes manageable, and coverage quietly falls again. A program can report a high flag count and still pass the forged receipt, because no rule asks whether a $65 omelet is a real price at that restaurant.
Vendor claims deserve the same scrutiny, because a vendor that reports a coverage percentage without naming the denominator has told the buyer nothing. Our five-test framework for evaluating AI spend management separates a real claim from a marketing number.
Our AI reads every line of every receipt on every report before reimbursement, rather than scoring a sample after the fact. We train our models on millions of real and fraudulent receipts. They check merchant reality, image provenance, mathematical consistency, and cross-report history in a single pass. AppZen Expense Audit covers 42 languages and 97 countries. Its named checks include credit card activity, allowable alcohol, blocklisted merchants, conflicting expenses, duplicate expenses across reports, Sunshine Act payments, personal expense detection, and fapiao validation.
AI Agents then act on the exception according to the organization’s standard operating procedures (SOPs). Every Agent action is governed and leaves a full explanation behind, so a reviewer can see what the Agent did and why. Anything requiring human judgment routes to an auditor. Merin Schrinel, Manager of Global Travel, Expense and Corporate Cards at Owens Corning, described the result: “On average, over 70 percent of our expense reports are auto-approved, so they are truly able to do that targeted audit that looks at the highest-risk items that helped them spend less time reviewing what we would call clean transactions.”
That changes how a travel and expense (T&E) team spends the day. Clean reports clear without human attention, and auditors work only the exceptions that carry real exposure. Enterprises reach automation rates of up to 80% and reduce finance operating costs by up to 50% when they run expense report auditing at full pre-payment coverage. Our breakdown of what AI expense audit does shows each check in sequence, and our guide to expense reports at scale explains how agentic AI handles the volume. Card spend follows the same model through corporate card expense management, audited as transactions post.
Nineteen published guides cover the expense audit process in detail, grouped by what a finance team is deciding.
Process and method. Start with how an audit works stage by stage, then the practitioner sequence in auditing expense reports, then the volume question in expense reports at scale.
Fraud, receipts, and duplicates. Five guides cover the evidence layer. Read fake receipt detection for what teams face, the fake receipts playbook for the controls, receipt fraud for the four types, and expense fraud detection for the nine red flags. Duplicates get their own treatment in duplicate expense.
Policy. Two guides cover the rules an audit enforces. Use expense policy for the general case, and travel and expense policy where travel rules need enforcement built in.
Cards. Three guides cover the second spend record. Read corporate card management for the program view, corporate credit card fraud for the seven patterns, and the corporate travel card buyer guide when selecting a provider.
Travel. Read travel and expense management for the verifications teams miss, and AI travel expense audit for the hardest review cases.
Automation and evaluation. Four guides support a buying decision. Read what AI expense audit does for the mechanics, and expense management automation for the manual-versus-automated question. Use evaluating AI spend management for the five vendor tests, and T&E spend for the benchmarks.
Finance leaders should determine what share of expense spend currently receives a real review before payment. Where that share sits near the 10% to 20% norm of manual programs, coverage is the largest control gap in the function. Every other improvement matters less than closing it. Our overview of AI expense audit describes how full pre-payment coverage works at enterprise volume.
An expense audit is a review of submitted employee expense reports against company policy, tax requirements, and supporting receipts. It confirms that each claim is accurate and legitimate before reimbursement. It examines the receipt, the policy rules that apply to the item, and any duplicate of the same charge already in the system.
Manual programs typically review 10% to 20% of transactions, because auditor capacity sets the limit rather than risk. An audit performed by AI before payment removes that constraint and reviews 100% of transactions, which is the standard enterprises now target.
A pre-payment audit reviews claims before money leaves the company, so finance prevents the violation rather than recording it. A post-payment audit converts every finding into a recovery effort. Recovery rates on reimbursed employee spend are low once the pay cycle closes, so the same finding is worth less after payment.
Detection combines analysis of image metadata, verification that the merchant trades at the claimed location, and mathematical validation of line items against the stated total. It also checks required fields such as tax identification numbers and compares the document against known receipts from the same vendor. Forgeries tend to fail these checks before they fail visual inspection.
The most common findings are duplicate submissions, out-of-policy items, split claims that stay under an approval threshold, personal expenses claimed as business costs, and forged or altered receipts. Duplicates usually produce the highest volume, and forged receipts the highest loss per case.
Yes. The accountable plan rules in IRS Publication 463 keep reimbursements tax-free only under three conditions. The plan shows a business connection, the employee accounts for the expense within 60 days, and the employee returns any excess within 120 days. Section 404 of the Sarbanes-Oxley Act requires management at public companies to assess internal control over financial reporting. T&E controls sit inside that framework, so a weak expense audit weakens the control environment the assessment describes.