Featured Image

Expense auditing at enterprise financial institutions still relies heavily on manual review. It is an operating model that is losing viability as AI agents prove they can autonomously handle transaction controls, and catch AI-generated fakes that fool the human eye, with governance and a complete audit trail.

But finance leaders in banking and financial services (FinServ) must hold expense audit solutions to the same standards they apply to every other control, prompting important questions about expense audit tools and platforms: Is AI the best solution for travel and expense (T&E) audits? Can it flag the increasingly prevalent AI-generated receipts that finance teams are struggling to catch? Can the work done by AI agents withstand the scrutiny of an external audit in highly regulated institutions? These are the questions any provider of an agentic expense auditing tool must be able to clearly answer.

Is expense audit the “last manual operation standing” in financial services?

For most banks and financial services firms, yes. Regulators require documented human judgment across a wide set of financial controls, creating heavy compliance workloads. Most of these firms have automated their invoice processing and payments. Expense audit falls outside the manual review mandate, yet auditors still review reports by hand. This increases the likelihood of errors and slows reimbursements. And that assumes full review at all. Many businesses still spot-check 10–20% of reports, leaving the rest to surface after payment, when money has already left the company.

Investment banking, wealth management, insurance, credit card processing, tax services, and accounting are all dense with manual finance and risk controls. Anti-money laundering (AML) alert reviews, Sarbanes-Oxley (SOX) control testing, journal entry reviews, account reconciliations, and more all consume analyst hours. Scaling the business means increasing headcount or outsourcing the work, both of which add cost.

Why is expense fraud suddenly so easy?

A templated fake receipt takes effort to build and reuse. Generative AI has eliminated both the effort and the skill that forgery once required, making a convincing fake cheap and fast to produce. According to our data, in March 2025, AI-generated receipts accounted for 0% of the fraudulent receipts flagged by our customers. That same month, TechCrunch reported that ChatGPT’s image generation had improved enough to be convincing to the naked eye. With the right text prompt, an AI image generator could produce a photorealistic receipt in seconds.

In April 2026, we observed the number of AI-generated fakes caught by our platform overtaking template-based fakes. By mid-May, they made up 70.8% of the fraudulent receipts flagged for review. In 14 months, a previously marginal receipt-faking method replaced the dominant one.

Expense fraud · AppZen platform data

AI-generated fakes overtook template forgeries in 14 months

Share of flagged fraudulent receipts that were AI-generated

0% 20% 40% 60% April 2026: AI fakes overtake template fakes 70.8% Mar 2025 Apr May Jun Jul Aug Sep Oct Nov Dec Jan 2026 Feb Mar Apr May*

March 2025–mid-May 2026. AI-generated fakes overtook template-based forgeries in April 2026. *May 2026 reflects a partial month through mid-May. Source: AppZen platform data, reported by Forbes (2026).

These manufactured reimbursement requests also tend to fall below review thresholds. AI-generated fakes discovered by our platform averaged roughly $100 per receipt, while template-based fakes averaged just over $180. Both amounts are well under common auto-approval thresholds. And small amounts avoid scrutiny.

Expense fraud detection has not kept pace

In a June 2026 survey of 2,000 U.S. and U.K. workers reported by Accounting Today, 32% of finance professionals said they could not recognize an AI-generated fake receipt. Fraudsters have also learned to strip images of some visual and metadata cues. The same survey found the problem extends to peers. Some 42% of finance professionals have suspected a colleague of submitting a fake or altered receipt, and 34% have felt pressured to approve a questionable expense.

Receipt fraud used to be an art. Today, it’s just a prompt. Here’s how to use AI to catch AI.

Read the blog →

Practitioners increasingly treat AI-generated receipts as their own operational risk. The Institute of Chartered Accountants in England and Wales (ICAEW) published member guidance on spotting AI fake receipts in November 2025. The Internal Audit Collective convened roundtables on T&E audits in the AI era. Inc. documented practitioner alarm spreading through finance communities online. Even the AP Professionals Group named AI-driven document fraud a priority risk area for FY26.

Data from the Association of Certified Fraud Examiners (ACFE) offers no evidence that expense fraud itself is surging. In fact, median losses per case have declined over the past decade. What changed is the method. Forgeries that human reviewers once caught can now pass visual inspection.

Two legacy expense audit models, one shared blind spot

Nearly every expense audit program at a financial institution descends from one of two operating models. The first reviews a sample of reports and accepts risk on the rest. The second manually reviews every report, whether in-house or through an outsourced provider, and accepts the cost. Hybrid programs that layer rules-based automation onto sampling fare no better. Rules-based systems are inflexible, cannot interpret the context within a receipt or document, and flag high volumes of exceptions, which returns the work to human reviewers. All of these models predate AI-generated documents, and all fail the same test: reliably detecting AI-generated fake receipts before payment.

The sampling model

Sampling concentrates review effort on a fraction of submitted reports, selected by threshold, category, or random draw. Everything outside the sample is paid without examination. Across enterprise audit programs observed on our platform, sampling programs typically review 10% to 20% of expense reports.

According to the ACFE’s 2026 Report to the Nations, recent expense reimbursement fraud schemes continued a median of 18 months before detection, versus 12 months for occupational fraud overall. That is longer than any other scheme type except financial statement fraud. Individual amounts are trending lower, but the ACFE estimates the median loss of an expense reimbursement scheme at $1,900 per month. Every month a scheme remains unreviewed is a month of paid, unrecovered loss. Sustained for the median year and a half, even a small monthly leak compounds into tens of thousands of dollars. Tips uncovered 40% of fraud, more than internal audit and management review combined. A control model that relies on someone volunteering information does not provide provable coverage.

The full manual review model

Large financial institutions often reject sampling and audit every report through manual review. Coverage improves, at the cost of speed, labor, and control. Offshoring audit labor or running it through a business process outsourcing (BPO) provider is the profession’s default. These examples from a global bank illustrate the challenges:

Speed. A global bank with 90,000 employees and roughly 250,000 annual reports ran its T&E audit through an outsourced provider. Its prepayment audit cycle took four days for electronic receipts and up to 22 days for paper. Employees wait for reimbursement for the length of that cycle, every cycle.

Labor. Those 250,000 reports a year required 20 minutes of review per report, for a total of roughly 83,000 hours. That is the workload of about 40 full-time reviewers. Headcount grows in proportion to report volume, which is the opposite of how institutions should scale control functions.

Control. The loss here applies specifically to the outsourced variant. The same bank’s audits were scripted checks applied across dozens of countries and languages, without regard for context.

Reduced visibility and oversight are common drawbacks when moving finance functions to an outside provider. And regulators still hold the hiring institution accountable for the control, regardless of who performs the work.

 Agentic AI is reversing 20 years of strategic outsourcing. Read the white paper to learn how.

 

Where both models converge

AI-generated receipts have highlighted the problems inherent in both sampling, which misses them by design, and manual review, which fails on detection at any coverage level. One in three finance professionals concedes they could not recognize an AI-generated fake, and the remainder rely on visual inspection cues that photorealistic output removes. For AI-generated fakes, reviewing 100% of reports by hand offers little advantage over reviewing 15%.

Traditional automation using rules-based techniques is the most widely deployed form of anti-fraud analytics. Among these programs, 51% use exception reporting and 48% use automated red flags. Yet only 34% of organizations use unstructured data in their anti-fraud analytics, and a receipt image is unstructured data. Roughly two-thirds of anti-fraud programs never examine the document itself. Their rules validate the fields typed into the expense system, and an AI-generated fake with plausible fields passes every rule by definition.

The evidence of AI-generated fraud is building

Single-method document checks fail, too. ICAEW notes in its guidance that metadata analysis is defeated the moment a fake is photographed or screenshotted. The header in ICAEW’s guidance, “Use AI to catch AI,” is an increasingly common refrain, and for good reason.

The pattern extends beyond expense receipts. The Financial Crimes Enforcement Network (FinCEN) issued an alert to financial institutions in November 2024 on the rise of suspicious activity reports related to deepfake media. Although the alert singled out fraudulent identity documents that were circumventing verification rather than receipts, it was early regulatory recognition that document authenticity now requires more than field validation.

Deloitte’s Center for Financial Services projects that generative AI will push U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023. Its diagnosis is that legacy fraud systems built on business rules and decision trees are eroding as AI-enabled fraud tools become widely available. Closing the AI-generated fraud gap requires a reviewer that examines the document itself, reasons about its context, and operates at full population scale.

What does 100% prepayment audit coverage look like?

The alternative to sampling and manual full review is a control that examines every report before payment, documents every decision, and scales without headcount. Banks already run other controls in this manner. Payment screening examines every transaction it processes. Expense auditing has been late to adopt the same standard.

100% prepayment audit coverage is the new standard for T&E. The difference between rules-based automation and agentic AI performing the review is what the reviewer examines. Rules validate typed fields. Our AI Agents examine the document itself and reason about its context.

Agentic control checks four things on every report:

Verify receipt authenticity. Our AI reads every line of every receipt and examines the image and its metadata. It then cross-references the claim against corporate card transaction data, the traveler’s itinerary, and merchant records to confirm the transaction is legitimately for business. A plausible fake with clean fields fails the cross-reference even when it passes visual inspection.

Detect duplicates across reports, submitters, and time periods, the cross-checking that defeats resubmission schemes spanning reporting cycles.

Enforce policy on every line item, touchlessly, and in real time, including international receipt types such as fapiao and value-added tax (VAT) receipts, which manual reviewers validate inconsistently.

Flag behavioral patterns over time, the repeated under-threshold claims that no single-report review detects.

How AI expense auditing protects financial institutions

Agentic AI expense auditing provides the needed control, with 100% prepayment audit coverage performed by governed AI. Agentic solutions built for regulation-bound industries plan and complete multi-step review work autonomously, based on the policies and guardrails that finance teams define. They review every report before payment, in minutes rather than days, and record every decision for audit.

Case study

Real ROI for banking and financial institutions

One global bank replaced an outsourced audit cycle that took up to 22 days with our AI-powered review model that achieved 100% prepayment coverage. With 76% of its roughly 250,000 annual reports auto-approved, the remainder that required human review took only 0.83 days to complete. The work previously sent to a BPO returned in-house to a small internal team, with increased control and direct dashboard access to their own audit data. The bank’s team went on to build five customized AI models. Coverage, speed, cost, and control all improved.

Next, the team deployed AppZen AI Agents. These Agents handle routine reviews and approve standard claims autonomously, so auditors could stop reviewing every receipt and start managing exceptions and audit strategy. Volume growth, new regions, and multi-currency compliance no longer require proportional headcount adjustments.

< 24 hrs
average manual audit, down from 22 days
76%
of reports AI audited and approved
250K
annual reports, now audited in-house

The importance of governed agentic AI expense audit for regulated institutions

AI fraud requires AI defense. But banks cannot deploy AI that cannot be audited. The resolution is agentic AI governed to the same standard as the control it performs. As a whole, agentic AI for finance has not yet reached that standard. Benchmarking data reported by the ACFE and SAS indicate that 82% of anti-fraud professionals consider explainability or auditability important when adopting generative AI. Yet only 6% feel completely confident explaining how their AI or machine learning models make anti-fraud decisions. Only 18% of organizations test their AI models for bias.

Adoption is proceeding anyway. EY’s global financial services regulatory outlook reports that more than 70% of banking firms use agentic AI to some degree. Regulators’ opinions diverge across jurisdictions, and boards make AI oversight a standing agenda item. Gartner reports that 57% of finance teams are implementing or planning to implement agentic AI. It also warns that over 40% of agentic AI projects will be canceled by the end of 2027. Ungoverned deployment is how a project joins the canceled 40%.

What are the requirements for a governed agentic AI expense audit?

Governance in an audit context means every decision is reviewable. Our platform records a decision-level audit trail for every action an AI Agent takes, enforces policies that humans define and change, and produces explainable outcomes for every report. It is designed for enterprises that process highly sensitive financial data. Documentation is organized, and compliance issues are flagged as transactions occur, rather than reconstructed at month-end. The control produces its own evidence of oversight, which is what examiners and regulators look for.

Institutions evaluating vendors should insist AI-driven expense auditing software provide:

Decision-level audit trails covering every autonomous action, retrievable per report.

Policy controls defined by you with changes taking effect without vendor intervention.

Explainable outcomes that any reviewer can understand.

Prepayment operations so violations stop before funds leave the institution.

Visibility to your in-house team with direct access to audit data and models.

A vendor that fails these evaluation criteria reproduces the outsourcing problem in a new form. It simply replaces an offshore or BPO team that the institution cannot see into with a black box AI model that still provides little or no visibility.

Where to start with agentic AI expense auditing

The following four steps will help you establish the case for agentic AI expense auditing internally by producing the measurements that CFOs require.

1. Measure current exposure. Compare your program’s detection duration and loss profile against the ACFE benchmarks for expense reimbursement schemes: a median duration of 18 months and damage velocity of $1,900 per month.

2. Quantify the unreviewed population. Count the reports paid without examination in the last 12 months. Consider including everything under auto-approval thresholds, where AI-generated receipts and fraud schemes may be hiding.

3. Pilot one category or region. Run 100% prepayment coverage on a defined subset of your program, such as a single expense category, business unit, or region, and measure auto-approval rate, audit cycle time, and violations caught before payment against your current baseline.

4. Evaluate the results. Review against the requirements for a governed agentic AI expense audit listed above. Measure cost per report, audit cycle time, violations stopped before payment, and the share of reports with documented review.

The bottom line: A governed AI expense audit for banking and FinServ

Expense audit modernization raises T&E to the standard that the institution applies to its other transaction controls. Every report is reviewed, documented, and audited before payment. Finance leaders reduce structural cost and gain audit-ready operations that scale without headcount. Audit teams gain coverage they can document for every transaction, freeing time for the professional judgment calls they were hired to apply. Employees are reimbursed in days rather than weeks, removing the financial pressure and stress that slow cycles create.

Financial institutions that have modernized are converging on the same answer to AI-generated fraud: 100% prepayment audit coverage with governed, auditable AI. This closes the gaps left by legacy approaches, keeping control in-house.

How AppZen helps financial institutions today

We built AppZen Expense Audit around this control model. Expense Audit reviews 100% of expense reports before payment. Our AI Agents read every line of every receipt, cross-reference each claim against transaction and travel data, and enforce the policies your team defines, in real time. Every action an Agent takes is recorded in a decision-level audit trail, and your team keeps direct access to the audit data, dashboards, and models.

Fortune 500 companies, including global financial institutions, use AppZen to reach automation rates of 80% or more and reduce finance operating costs by up to 50%. The global bank described above operates its entire T&E audit this way, in-house. To measure the model against your current audit baseline, contact us today to request a demonstration of AppZen Expense Audit.

Ready to build your hybrid finance team? Check out the finance leader’s guide to evaluating AI agents.

 

Frequently asked questions about e-invoicing compliance

What is an AI expense audit?

AI expense audit uses artificial intelligence to review expense reports for fraud, duplicates, and policy violations. Rules-based tools validate typed fields, while agentic AI examines receipt images, cross-references transaction data, and reasons about context, covering 100% of reports before payment.

How is 100% prepayment audit coverage different from sampling?

Sampling reviews a fraction of reports after selection by threshold or random draw, leaving the rest unexamined. 100% prepayment coverage reviews every report before money leaves the institution, so violations are prevented rather than recovered.

Why do manual reviewers miss AI-generated fake receipts?

AI image generators produce photorealistic receipts that 32% of finance professionals say they could not recognize as fake. Detection now requires examining image data, metadata, and cross-referenced transaction records, which human review does not perform at scale.

How does prepayment fraud prevention differ from post-payment detection?

Prepayment fraud prevention audits every expense report before reimbursement, stopping fraudulent claims and out-of-policy spend before money leaves the institution. Post-payment detection identifies violations after payment, increasing the likelihood of expense schemes running longer. ACFE data indicate such schemes run a median of 18 months, at $1,900 per month, before detection.

Does agentic AI replace expense auditors?

No. AI Agents handle routine reviews and approve standard claims, and auditors manage exceptions, tune policies, and direct audit strategy. One global bank brought its audit in-house to a small internal team after adopting this model.