Receipt fraud is any attempt to obtain money using a receipt that misrepresents a purchase. In a corporate setting it takes four forms, namely forged documents, altered documents, the same cost submitted more than once, and real receipts attached to a false business purpose. Detection now depends on checks a document generator cannot satisfy.
Two years ago most corporate receipt fraud was clumsy enough to catch by eye. Generative artificial intelligence (AI) means software that produces new images and text on request. It has since made convincing documents cheap to produce. The four types below now behave differently in enterprise expense data, and the defenses that worked against the previous generation no longer catch them.
The term covers two different problems, and search results mix them freely.
Retail receipt fraud happens at the returns counter, where someone presents a fabricated or reused receipt to obtain a refund, store credit, or a rebate on goods they did not buy. Loss prevention teams inside retailers own that problem.
Corporate receipt fraud happens inside the expense system. An employee attaches a document to a reimbursement claim, and the document does not represent a real business purchase at the stated amount. Finance departments and internal auditors own it, and it is the version described here.
The two share a technique and little else. Retail fraud is a single transaction against a store. Corporate receipt fraud occurs inside an approval workflow with policy rules, a feed of corporate card transactions, an approver, and an audit trail, so it leaves far more evidence and is still detected far less often.
Producing a convincing forgery once required effort and skill. A generative model now produces a plausible restaurant receipt, with a real-looking merchant, a coherent tax line, and correct local formatting, in roughly the time it takes to type the request.
PYMNTS reported enterprise expense data in June 2026. It shows AI-generated documents rising from zero percent of flagged fraudulent receipts in March 2025 to 70.8 percent by mid-May 2026. The sample covered 1,471 fake receipts from 745 employees across 174 companies, worth $148,143 in claims.
Two details in that data matter more than the headline figure. The first is average value. AI-generated fakes averaged about $100 each, against $182 for the template-built fakes that preceded them. Those claims are priced to clear the thresholds below which reports are approved automatically, rather than to maximize a single payout. The second is the size of the population. Seven hundred and forty-five employees is not a handful of bad actors. HR Executive reported a survey of 2,000 workers in the United States and the United Kingdom in July 2026. Four in ten US employees had used AI to create a fake receipt, with nearly 20 percent fabricating a purchase outright and about 15 percent inflating a real one.
A control does not catch frequent, small, casual fraud when it was designed to catch rare, large, deliberate fraud. That is the shift.
The receipt describes a purchase that never happened. Generated images now pass visual inspection reliably, so detection now depends on the things a generator cannot fake consistently. Those are whether the merchant exists and trades at that address, whether it sells that item, whether the line items and tax actually sum to the total, and whether the document matches other receipts genuinely issued by that vendor.
An employee edits a real receipt. The amount changes, a personal line item is removed, the date is moved into an open reporting period, or an attendee count is trimmed. These are harder to detect than pure forgeries, because the merchant checks out and only the arithmetic or the internal consistency of the document gives it away.
An employee claims the same cost more than once, across reporting periods, across employees, or once as a receipt and again as a corporate card line. Most duplicates are honest mistakes, which is precisely why deliberate duplicate claiming is so hard to distinguish from them. Detection depends on how widely claims are compared with one another rather than on analysis of any single document, and the mechanics appear in our explainer on duplicate expense detection.
The document is real, unaltered, and correctly claimed, and the business purpose attached to it is false. A hotel folio, the itemized bill for a stay, lists a pet boarding charge described as lodging. A restaurant bill covers a family dinner logged as a client meeting. Nothing about the receipt is wrong. Finding it takes a line-by-line reading of the document against the stated purpose.
Most programs relied on three defenses until recently, and all three have weakened.
Image metadata analysis. Metadata is the hidden record a camera or program stores inside an image file. EXIF (Exchangeable Image File Format) data can contain the signatures left by receipt generators. Checking it worked while employees submitted fakes as downloaded files. Employees now capture a screenshot of the image or photograph it off a second screen, both of which strip that record. Metadata is still worth reading, and it is no longer a primary signal.
Visual inspection. Misaligned columns, wrong fonts, and impossible date formats were the classic tells. Generated documents no longer make those mistakes, and asking reviewers to spot them trains people to trust documents that look tidy.
Sampling. Manual programs review 10 to 20 percent of expense transactions, a gap examined in our analysis of 100 percent audit coverage. At an average fake value near $100, most fraudulent claims are below the dollar thresholds that trigger review, so the sample is aimed at the wrong part of the distribution.
The time a scheme lasts before discovery is what makes it expensive. The Association of Certified Fraud Examiners studied 2,402 cases for Occupational Fraud 2026 and found a median scheme length of 12 months and a median loss of $104,000 per case. Schemes caught inside six months had a median loss of $40,000. Small claims that nobody reviews go undetected for a long time.
Detection is the part vendors describe. A document fails a check, and what happens next decides whether the program changes any employee's behavior. In most organizations that part is unwritten. The governing principle is that a flagged receipt is evidence that a document failed a check, not proof of intent. A workable response follows a fixed sequence.
Some programs find the same behavior from the same people every quarter. Those programs produce reports rather than change conduct.
Expense platforms improved capture and approval and left verification largely alone. What survives in most enterprises is a rules engine checking amounts against thresholds, plus a human sample.
Both assume the receipt is a reliable artifact. The document itself can now be manufactured on demand. A control that reads amounts and dates off that document checks the forgery against itself. Approval is also not verification. An approver looks at a $94 dinner receipt from a real-sounding restaurant. They have no way to know the restaurant does not exist, and no time to find out.
Our AI reads every line of every receipt on every report, before reimbursement rather than after. The platform runs several independent checks in one pass, covering whether the merchant is real, where the image came from, whether the line items and tax reconcile with the total, and how the claim compares against the employee's history, other employees' reports, and posted card transactions.
The independence of those checks is the point. A generated receipt may survive image analysis. It still has to survive a merchant that does not exist, a tax line that does not sum, or a colleague who claimed the same dinner. Exceptions are then sorted by risk and value, so reviewers spend their time on the findings with the most money at stake. Our fake receipt detection explainer describes the individual layers.
What such a system does not do is read intent. It reports that a document failed a specific check and shows the evidence for that conclusion. The judgment remains with the review team.
Compare the value distribution of the claims your program actually reviews against the roughly $100 average of an AI-generated fake receipt. Where sampling rules are triggered by dollar thresholds well above that figure, receipt fraud is concentrated in the part of the ledger that receives no review. Our overview of expense report auditing describes how that gap closes before payment.
Receipt fraud is the use of a receipt that misrepresents a purchase to obtain money. In a corporate setting it covers forged documents, altered documents, the same cost claimed twice, and real receipts attached to a false business purpose.
Submitting a fabricated or altered receipt for reimbursement is generally treated as fraud, and employers commonly handle it as a policy and employment matter first. Consequences depend on jurisdiction, value, and intent, so legal counsel should be involved before a finding is characterized.
Yes, though not by examining the image alone. Reliable detection combines document analysis with checks a generator cannot satisfy, including whether the merchant exists and trades where claimed, whether the totals reconcile, and whether the same charge appears elsewhere in the organization's data.
Metadata identifies files produced by known receipt generators, and it disappears when an employee captures a screenshot of the image or photographs it from another screen. It remains a useful signal, and it no longer works as the primary one.
A survey of 2,000 US and UK workers was reported in July 2026. Four in ten US employees had used AI to create a fake receipt for an expense report. Enterprise platform data reported the same year showed AI-generated documents making up 70.8 percent of flagged fraudulent receipts by May 2026.