Expense fraud detection is the review of employee expense claims for signs that a claim is fabricated, inflated, submitted twice, or personal rather than business-related, ideally before reimbursement. Nine patterns recur in enterprise expense data. Each has a legitimate version that produces the same signal, so a red flag sets review priority rather than proving anything.
Volume is rising, the average fraudulent claim is smaller, and the median scheme still lasts a year. Detecting a familiar pattern sooner matters more than detecting a more sophisticated one.
The Association of Certified Fraud Examiners (ACFE), a professional body that studies workplace fraud, examined 2,402 occupational fraud cases for Occupational Fraud 2026. Collective losses across those cases exceeded $3.4 billion. The median loss per case was $104,000, and the median scheme lasted 12 months before detection.
The same report found a median loss of $40,000 in schemes caught within six months, against more than $1.1 million in schemes that lasted five years or longer. Loss size tracks the length of the run more closely than it tracks the sophistication of the scheme. Tips remained the most frequently used detection method at 43% of cases, which is a measure of how much discovery still happens outside the formal control process.
The submission side has changed faster than the review side. PYMNTS reported in June 2026 that AI-generated documents grew from zero percent of flagged fraudulent receipts in March 2025 to 70.8% by mid-May 2026. The average AI-generated fake was worth about $100, against $182 for the older fakes built from templates.
Employees describe the same shift. A 2026 HR Executive survey of 2,000 US and UK workers found that four in ten US employees had used AI to create a fake receipt. Nearly 20% fabricated a purchase that never happened, and about 6% used AI to replace a lost receipt for an actual expense.
A red flag is a signal rather than a verdict. Every pattern below has an innocent version, and a program that forgets this spends auditor time and employee goodwill in equal measure. A flag earns its place only where four conditions are met.
Coverage. Search for a pattern only in the 10 to 20% of reports selected for sampling and it mostly goes unexamined. Most large organizations audit about that share, and full coverage yields five to ten times more detection, as our analysis of 100% audit coverage sets out.
History. Few of these signals exist inside a single report. A duplicate needs a prior submission to match against, and a repeat offender needs several cycles. The more history a reviewer holds, the more each new report reveals.
Timing. A flag raised after reimbursement creates a recovery problem. A flag raised before payment stays a review problem.
Disposition. Every flag needs a defined next step, meaning automatic approval, manager review, a request for a receipt, or an investigation. Flags without one accumulate into a backlog.
The signal is below the image. Generated receipts show distinctive metadata, uniform fonts and spacing, and prices that do not match the merchant's real menu. Arithmetic provides a second check, because line items often fail to re-add against the stated tax and total. Our explainer on AI-generated fake receipts covers the forensic detail.
The innocent version is the employee who lost a receipt and asked a tool to replace it, which about 6% of the workers surveyed in 2026 reported doing. The document is fake while the expense is real, which makes it a policy matter rather than a fraud case.
The signal is the same charge submitted twice by two routes. A corporate card feed posts the transaction, and the employee also uploads the same receipt as an out-of-pocket claim. Duplicates that cross reporting periods are harder to catch, because a claim resubmitted three cycles later never appears beside its twin. Duplicates found grow about 700% between the first and the twelfth month of an audit program.
The innocent version is a genuine second visit. Two lunches at one restaurant, with the same party size and a similar amount two days apart, are ordinary for a salesperson working one territory.
The signal is a distribution of amounts that bunches just below a control point. Where receipts are required above $75, reviewers see many claims at $71 and $74 and almost none above the line. Splitting is the related pattern, in which a single $260 dinner appears as two $130 claims on separate reports.
The innocent version is a policy limit set close to real market prices. Where a meal allowance is close to what dinner costs in that city, clustering below the line reflects the market rather than intent.
The signal is an unusual density of clean figures. Genuine spending produces amounts such as $43.87 and $112.44. Fabricated spending produces $50.00 and $75.00 at rates that stand out against the employee's own history.
The innocent version is any category where round amounts occur naturally. Flat-rate parking, prepaid transit cards, fixed conference fees, and whole-dollar tips all produce clean numbers honestly.
The signal is a mismatch between the merchant and the category claimed. A grocery run coded as client entertainment, or a resort spa charge folded into the total of a hotel folio, are the everyday versions. A folio is the itemized bill for a stay, and most of these surface only in that itemized data, because the summary line does not show them.
The innocent version is a legitimate expense with careless coding, such as supplies bought at a big-box retailer because it was the only option near the site.
The signal is a tip percentage well outside the employee's own baseline, or a handwritten tip line that does not match the amount settled on the card. A $40 tip on a $60 check is arithmetically valid and unusual against most spending histories. Add-on padding follows the same logic, with mini-bar charges appearing at rates one traveler sustains and comparable travelers do not.
The innocent version is hospitality for a large party where a service charge has already been applied. Banquet events and markets where service is included by default produce percentages that look incorrect.
The signal is a claimed distance that does not survive a route check. It exceeds the point-to-point distance between the addresses given, or the same trip is claimed at different distances in different months.
The innocent version is a real detour. Road closures and several stops in one day both produce honest overage, and an employee claiming 40 miles for a 31-mile route has often stopped somewhere legitimate.
The signal is timing and geography that do not match an approved trip. Meals appear in a city with no travel authorization, or on the empty days between two unrelated trips. A location mismatch is clearest when one day shows charges from two distant cities.
The innocent version is ordinary work outside the standard week. Retail and field service operate on weekends, and trade shows often begin on a Sunday.
The signal is accumulation. A single flag on a single report is noise. The same employee triggering low-severity flags across six or eight consecutive cycles is a pattern. The ACFE median of 12 months is in large part a record of accumulation that nobody counted. Severity should rise with repetition, even where each flag alone would clear automatically.
The innocent version is a role that generates exceptions structurally. A field engineer with unusual travel, or a clinical liaison subject to the Sunshine Act, will trigger rules constantly and legitimately. The Sunshine Act is the US law requiring drug and device makers to report payments to physicians. Repetition should raise scrutiny of the pattern rather than suspicion of the person.
Three structural gaps recur, and none concerns the quality of the rules.
The first is sample-based coverage. Reviewing 10 to 20% of reports leaves the remainder unexamined, and fraud patterns are not distributed conveniently across the sample.
The second is post-payment review. Auditing after reimbursement converts every finding into a recovery conversation with someone who has already spent the money. The ACFE gap between a six-month median loss of $40,000 and a five-year median above $1.1 million is one measure of the cost of delay.
The third is the absence of memory. Fixed-threshold rules read one report at a time, with no view of an employee's twelve-month distribution and no way to escalate on repetition. That is why a fraudster gains most from the small, unremarkable, repeated patterns.
Our AI reads every line of every receipt on every report, before reimbursement. Our coverage is 100% of expense reports and 100% of card transactions as purchases post, in 42 languages across 97 countries. Each report is compared against the employee's own history and the organization's, which is what makes duplicate and repetition patterns visible.
Receipt authenticity is assessed through several layers, covering image provenance and metadata, pattern recognition, merchant authentication, mathematical validation, and completeness verification. More than 40 pre-built travel and expense (T&E) audit models cover policy and compliance requirements, among them the Foreign Corrupt Practices Act (FCPA), the Sunshine Act, value-added tax (VAT) rules, validation of Chinese fapiao invoices, and screening for politically exposed persons, meaning senior public officials whose payments require additional scrutiny.
Disposition keeps the flags useful. Smart Workflows route exceptions to the appropriate reviewer, and AI Agents resolve routine issues on their own. Customers reach automation rates above 80% and up to 50% lower finance operating costs, mostly by clearing clean reports rather than flagging more of them. Our Expense Audit page describes our agentic AI fits alongside an existing expense system.
Determine what share of expense reports receives review before payment, and how much submission history a reviewer can see at that point. Where that history is thin, coverage and timing will do more to reduce losses than an additional rule. Two of the nine patterns are invisible without it.
Expense fraud detection is the review of submitted employee expense claims for patterns indicating a fabricated, inflated, duplicated, or non-business expense. It works best when the review happens before reimbursement, and when each claim is compared against the submitter's own spending history.
Nine recur most often. The first group covers fabricated or AI-generated receipts, duplicate submissions across channels and periods, clustering just below a policy threshold, and round-number claims. The second covers personal spending coded as business, inflated tips, padded mileage, out-of-territory charges, and repeated low-level flags from one employee.
The ACFE Report to the Nations 2026 found a median scheme duration of 12 months before detection. Schemes caught within six months had a median loss of $40,000, while those that lasted five years or longer exceeded $1.1 million.
No, a red flag does not prove fraud. Every pattern has a legitimate version, from a real second visit at the same restaurant to a genuine detour that inflates a mileage claim. A red flag sets the priority for review, and the review determines the outcome.
A single-report review misses cross-period duplicates and repetition across cycles. Both need submission history to detect, so a control that reads one report in isolation cannot see either, however well its rules are written.