Gartner® report CFO Guide to Governing Agentic AI Read now

How an expense report audit works, stage by stage

An expense report audit is the review of submitted employee expense claims against company policy, tax requirements, and supporting receipts, performed either before reimbursement or after. It is a chain of handoffs across four roles rather than a single step, and most of what goes wrong happens in the gaps between those roles.

Key takeaways

  • Four roles share the process, namely the submitter, the approver, the auditor, and the controller. Write the boundaries down, or the auditor absorbs whatever decisions the other three roles leave unclaimed.
  • The most common failure is a shared assumption. Approvers believe finance verifies receipts, auditors believe the approver confirmed the business purpose, and when both beliefs stand at once nobody has checked the report.
  • Stage 3, selection, is set by auditor capacity in most programs rather than by risk. A clean sample then gets reported as a clean population.
  • Fix a disposition list at stage 6. Teams without one accumulate findings that are neither paid nor closed, and those become the evidence problem at year end.

The audit is often described as a single step between manager approval and payment. In practice it is seven stages and four owners.

Why the handoffs matter more than the individual stages

A report passes through at least four sets of hands. The submitter builds it, the approver signs off on the business justification, the auditor tests the detail against policy, and the controller owns the outcome for the financial close, meaning the period-end process of finalizing the books. Each handoff rests on an assumption, and the assumptions are where bad reports get paid.

The most common assumption is that someone else has already looked. Approvers tend to believe finance verifies receipts line by line. Auditors tend to believe the approver confirmed the business purpose, since the approver knows the trip and the auditor does not. Both beliefs are reasonable on their own. When both stand at the same time, nobody has checked the report.

The chain costs money even when it works as intended. GBTA research from 2015 remains the most cited benchmark, putting the cost of a single report covering one night's hotel stay at $58 and 20 minutes. The same research found that 19 percent of reports contain errors or missing information, and that correcting one costs a further $52 and 18 minutes. Those figures are a decade old and best treated as directional, though the ratio has stayed stable. Rework costs roughly as much as the original processing.

The cost of late detection is larger still. The Association of Certified Fraud Examiners studied 2,402 cases for Occupational Fraud 2026 and found that the median scheme lasted 12 months before detection. Cases found within six months had a median loss of $40,000, while cases that lasted five years or longer exceeded $1.1 million. Tips remained the leading detection method at 43 percent of cases, an indication of how much discovery still happens outside the formal control process.

Role ownership and the timing of the expense report audit

Two design choices define a program, namely which role owns each decision and whether the review happens before or after money leaves the organization.

Four roles share the process.

  • The submitter assembles the report, attaches documentation, and certifies the business purpose. This role owns accuracy, and it holds the only first-hand knowledge of what took place.
  • The approver confirms that the spending was necessary and within the limit the organization has delegated to that manager. This role owns the business justification rather than the receipt arithmetic.
  • The auditor tests individual line items against policy, documentation standards, and tax rules. This role owns the finding.
  • The controller sets the risk tolerance, owns the rules for closing findings out, and answers to the external auditors.

Write those boundaries down. Without a documented split, the auditor absorbs everything left over, including business purpose judgments the auditor is not positioned to make.

The timing choice is the sharper of the two. A pre-payment audit tests the report before reimbursement, so a violation becomes a correction rather than a recovery. A post-payment audit tests after the money has moved, usually on a sample, and turns every finding into a recovery conversation with a current employee. Post-payment review still has work to do, since it catches patterns across periods that a single report cannot show on its own. The failure mode is running it alone, which is the default at most companies because reimbursement speed is the measure employees complain about.

A third timing factor is easily forgotten. Corporate card transactions post on the card network's schedule rather than the employee's, so nobody reviews card spending until a reconciliation deadline passes. That gap warrants its own stage in the design of the program.

The expense report audit lifecycle, stage by stage

Seven stages follow, in the order a finance team runs them, each with the role that owns it.

Stage 1, submission and the completeness gate

The submitter builds the report and attaches documentation. The completeness gate is a system check rather than a human one. Confirm that required fields are populated, that receipts are attached above the stated threshold, and that dates fall inside an open accounting period. Confirm also that the report is not a resubmission of something already paid. Return failed reports immediately, before anyone spends review time on them. A weak gate here causes most of the rework cost described above.

Stage 2, manager approval

The approver confirms the business purpose and their own authority to approve the amount. Keep this role's job narrow. Ask an approver to verify receipts, check tax arithmetic, and validate policy limits and they will do none of the three well, because they have neither the tooling nor the time. Ask one question instead, namely whether the spending was necessary and within the approver's own limit.

Stage 3, selection and routing

Someone decides which reports are audited. In a sample-based program that decision is a percentage, usually set by available capacity rather than by risk. In a risk-based program it is a scored queue that routes high-value reports, repeat exception filers, and unusual merchant categories to a human reviewer. Record the selection logic. A documented risk model is a stronger answer to an external auditor than a statement that 10 percent of reports were sampled.

Stage 4, the audit review

The auditor works through the report. Reconciliation of receipts to line items, merchant plausibility, tax arithmetic, proximity to policy thresholds, cross-period history, and validation of listed attendees all happen here. Order and judgment both matter, which is why the technique for auditing expense reports is a discipline of its own. For the lifecycle view, the output is what counts. The auditor closes each report with a status and, where something is wrong, a written finding tied to a specific line item and a specific policy clause.

Stage 5, exception handling and employee response

The submitter receives the finding and responds. Set a response window in days and a default action for the point at which it expires. Keep the exchange inside the system rather than in email, because the thread forms part of the audit trail. Most findings resolve at this stage, and they resolve faster when the finding cites the policy clause by number. A vague expense policy costs real time here, since a rule asking only for spending to be reasonable gives the employee nothing specific to concede to.

Stage 6, disposition and the payment decision

Every finding closes into one of five dispositions, meaning outcomes that end the review. Approve as submitted. Approve with the disputed amount removed. Return for correction and resubmission. Escalate to the controller for a judgment call. Refer to human resources or investigations where documentation appears falsified. Define these in advance and require every finding to end in one of them. Teams without a fixed list accumulate findings that are neither paid nor closed.

Stage 7, post-payment review and trend analysis

After payment, the controller reviews patterns rather than individual reports, covering repeat exception filers, category drift against budget, approval bottlenecks, and duplicate claims that surface only across two periods. Feed what emerges back into the routing at stage 3 and into the policy itself. A program that never closes this loop keeps catching the same things and missing the same things.

Where expense report audit programs fall short

The structural weakness in most programs is that stage 3 is set by capacity rather than by risk. Teams review 10 to 20 percent of expense transactions, and the sample size fits the auditors available rather than the places where the loss actually occurs.

That produces a second problem at stage 4. Auditors spend their attention on low-risk reports that happened to fall into the sample, which leaves less attention for the reports that warrant it. A clean sample then gets reported as a clean population.

The handoff between stage 2 and stage 4 fails for a related reason. Approvers see a queue and a deadline, so approval becomes a throughput task rather than a control. Training alone rarely corrects this, because the incentive rests on speed. The more durable response is to narrow what approval means and to move detail testing into a stage designed for it.

How we approach the expense report audit

We treat the audit as a pre-payment stage rather than a post-payment sample. Our AI reads every line of every receipt on every report before reimbursement, which puts 100 percent of expense reports and 100 percent of card transactions through the same tests as purchases post. Stage 3 changes accordingly, because selection stops being a capacity decision and becomes a routing decision about which exceptions need a person.

Stages 4 and 5 change with it. Smart Workflows route exceptions to the appropriate reviewer, with the finding already written against a specific line item. AI Agents resolve routine issues without a person touching the report. Team Insights gives managers the trend view that ordinarily appears only at stage 7. Customers running this way reach auto-approval rates above 75 percent and eliminate 80 to 90 percent of manual audits, so auditors spend their time on the reports with real money at risk. You can read more in our overview of AI expense audit.

The bottom line

An expense report audit works when each role has a single job and each handoff has a defined output. Document the four roles, place a genuine completeness gate at stage 1, fix a disposition list at stage 6, and move as much testing as possible ahead of payment. Map your own process against the seven stages and mark the handoffs where no role owns the decision. That map explains rework cost more fully than any error-rate metric.

Frequently asked questions

What is an expense report audit?

An expense report audit is the review of employee expense reports against company policy, tax requirements, and supporting receipts. It confirms that each claim is accurate and legitimate, either before the employee is reimbursed or afterward.

Who performs an expense report audit?

Four roles share it. The submitter certifies accuracy, the approver confirms business purpose and authority, the auditor tests line items against policy, and the controller owns the risk tolerance and the rules that close findings out.

What is the difference between a pre-payment and a post-payment expense report audit?

A pre-payment audit tests the report before reimbursement, so a violation is corrected rather than recovered. A post-payment audit tests after the money has moved, usually on a sample, and any finding becomes a recovery conversation with a current employee.

How long does an expense report audit take?

The time required depends on coverage and automation. GBTA research from 2015 put the processing of a single report covering one night's hotel stay at 20 minutes and $58. Correcting one of the 19 percent of reports submitted with errors took a further 18 minutes and $52.

How are expense report audit findings resolved?

Findings resolve through a fixed list of outcomes. A report is approved as submitted, approved with the disputed amount removed, returned for correction, escalated to the controller for a judgment call, or referred for investigation where documentation appears falsified.