Expense Report Audit: How Do You Get From 5% Sampling to 100% Coverage?

Most finance teams audit 3-10% of expense reports, after payment. That number is set by how many hours the team has, not by risk. The result is that the other 90%+ is approved on trust and any finding arrives after the cash has gone. The fix is to invert the model: screen 100% of claims against every rule automatically before payment, and spend human audit time only on the 5-15% that fail a check. Coverage goes up, reimbursement gets faster, and audit stops being a sampling exercise.
The Number Nobody Wants to Say Out Loud
Ask a finance controller what percentage of expense reports get audited and you will usually get a pause, then a qualifier. “We review everything above S$500.” “We spot-check.” “Internal audit pulls a sample each quarter.”
All three mean the same thing: somewhere between three and ten percent of claims are genuinely examined, and the rest are paid because nobody had a reason to stop them.
This is not negligence. It is arithmetic. A 400-person company generates 600 to 1,200 expense line items a month, and a careful manual audit of one multi-line report — open the attachments, read the receipts, check each amount, confirm the category, verify the approval chain — takes eight to fifteen minutes. Auditing all of it would consume two to three full-time roles nobody has budgeted. So the team sets a threshold, samples what it can, and calls it a control.
The problem is not sampling itself. Statistical sampling is a legitimate technique, and the Institute of Internal Auditors has well-established guidance on when it applies. The problem is what the sample is being asked to do. In most T&E programmes, sampling is not measuring a population to draw an inference. It is the entire control. Nothing else is looking.
Why Approval Is Not Audit
The usual objection is that expense claims already pass through an approver, so they are already checked.
They are not, and conflating the two is the single most common design flaw in T&E control.
An approver makes a business judgement. Was this trip necessary? Was the client dinner worth having? The approver has context an auditor does not — the deal, the customer, the project.
An auditor makes an evidence check. Does the receipt exist, and does it say what the claim says? Is the date inside the claim period, the category right, the tax coding recoverable? Is the approver even in the valid chain for this cost centre?
These are different questions requiring different skills and, critically, different incentives. The approver is usually the claimant’s own manager, being asked to hold up a S$180 dinner claim from someone who just closed a quarter. Most approvers, most of the time, approve. Research from the Association of Certified Fraud Examiners consistently places expense reimbursement among the most frequent occupational fraud schemes precisely because of this dynamic — the control point is socially compromised and individual amounts feel unworthy of a confrontation.
When a manager approves a claim, what has been validated is intent. Nothing about the evidence has been tested.
What a Complete Expense Report Audit Actually Checks
Before discussing automation, it helps to be precise about what a full audit covers. Most checklists circulating online stop at “check the receipt.” A defensible programme tests eight distinct dimensions.
1. Documentation integrity. Is a receipt attached at all, is it legible, and is it a receipt rather than a booking confirmation or a card slip without merchant detail? Tax authorities are specific about valid evidence — the UK guidance on VAT invoices and record keeping sets out the minimum fields, and Singapore’s IRAS GST rules do the same for input tax. A card slip usually fails both.
2. Receipt-to-claim agreement. Does the claimed amount match the receipt? This sounds trivial and is the most frequently failed check in practice. Rounding, tip inclusion, self-chosen conversion rates and transposition all produce mismatches — and so does deliberate inflation, which hides comfortably in a population where innocent mismatches are common.
3. Timing and duplication. Is the expense date inside the claim period? Has this receipt been submitted before, or arrived through a second channel as a personal claim for something already on the corporate card statement? We cover the seven duplicate claim patterns and how to detect them separately.
4. Policy conformance. Is the amount within the limit for this category, grade and city? Is the travel class permitted? Was pre-approval obtained where required? This is where most automated tools stop — and it is one dimension of eight.
5. Coding accuracy. Is the category correct, and does it map to the right GL account, cost centre, project and legal entity? Miscoding loses no money directly. It corrupts every downstream report and makes departmental budget conversations unwinnable.
6. Tax treatment. Is input tax correctly identified and recoverable, or is the claim in a blocked category such as certain entertainment? Is there a valid tax invoice to support the reclaim? This is the dimension most often skipped entirely, and it has direct cash value — see input tax recovery on employee expenses.
7. Approval chain validity. Was the claim approved by someone with authority over this cost centre, at this amount, on this date, under a delegation that was itself valid? Approval chains break quietly during reorganisations and leave periods — see our guide to approval delegation and fallback approvers.
8. Behavioural pattern. Does this claim look like this claimant’s normal behaviour, or their peer group’s? Fixed thresholds catch the claim that exceeds a cap. They do not catch the claimant whose average meal claim has drifted from 40% to 96% of the cap over eighteen months, never once breaching it.
| Audit dimension | Typically checked manually? | Automatable? | Cash impact if missed |
|---|---|---|---|
| Documentation integrity | Sometimes | Yes — image analysis | Failed tax reclaim, audit finding |
| Receipt-to-claim agreement | Rarely at scale | Yes — extraction + compare | Direct overpayment |
| Timing and duplication | Rarely | Yes — cross-channel matching | Direct double payment |
| Policy conformance | Usually | Yes — rules engine | Overspend against budget |
| Coding accuracy | Sometimes | Yes — AI classification | Corrupted reporting |
| Tax treatment | Rarely | Yes — category + evidence rules | Unrecovered input tax |
| Approval chain validity | Rarely | Yes — workflow validation | Control failure, audit finding |
| Behavioural pattern | Almost never | Yes — anomaly detection | Sustained, undetected leakage |
Read down the third column. Every one of these is automatable. Read down the second column. Most of them are not, in practice, being done.
The Real Cost of Post-Payment Audit
A second design flaw compounds the coverage problem: most audit happens after the money has moved. Quarterly internal reviews, year-end sampling and external testing are post-payment by definition — and so is much of the “everything above S$500” screening, because in practice the review happens in a batch after the payment run is prepared.
Every finding from a post-payment audit converts into a recovery problem:
- Payroll deduction. Legally constrained in many jurisdictions, administratively painful everywhere, and guaranteed to produce a difficult conversation.
- Employee repayment request. Low success rate, high relationship cost, often abandoned below a few hundred dollars.
- Write-off. The default outcome. The finding is documented, the money is gone, and the control is recorded as effective because it “detected” the issue.
Compare this to a pre-payment exception. The claim is held, the employee is asked for a legible receipt or an explanation, and they provide it or amend the claim. No cash has moved and nothing was taken back — it was simply never paid. Moving the audit point from post-payment to pre-payment converts a recovery workflow into a clarification workflow, and recovery workflows complete far below 100% while clarification workflows approach it.
How Do You Screen 100% Without Hiring Auditors?
The answer is to stop treating audit as a single activity and split it into two: screening, which is mechanical and should be exhaustive, and investigation, which is judgemental and should be selective.
Step 1: Turn receipts into data
Nothing can be tested while the evidence is a JPEG. The first requirement is extraction — reading merchant, date, currency, gross and tax amounts and line items off the image accurately enough to compare against the claim. This is where legacy OCR programmes stall: template-based engines handle structured invoices reasonably well and collapse on crumpled thermal receipts photographed at an angle in bad light. We have written separately about why legacy OCR fails on expense receipts and what changes with agentic extraction. Extraction accuracy sets the ceiling for everything downstream — a rules engine testing bad data produces confident nonsense.
Step 2: Encode every rule, not the convenient ones
Most implementations encode policy limits and stop, because limits are easiest to express. All eight dimensions above should become testable rules:
- Receipt present for any claim above the documentation threshold
- Extracted amount within tolerance of the claimed amount, and extracted date within the claim period
- Extracted merchant consistent with the claimed category
- Claim not matching a previously submitted receipt, or a line on an imported card statement
- Amount within grade-and-city limit, with a pre-approval reference where required
- GL and cost centre valid for the claiming entity, tax treatment consistent with category and evidence
- Approver within the valid chain for this amount and cost centre
Each rule produces a pass, a fail or a flag. Rules are cheap to run: the marginal cost of testing the eleventh rule on the ten-thousandth claim is effectively zero, which is exactly why the sampling logic that governs human review does not apply here.
Step 3: Separate hard stops from soft flags
Not every failure should block payment. Blocking everything recreates the bottleneck in a new place and trains people to treat the system as broken.
Hard stops — the claim does not proceed: no receipt where one is mandatory, amount mismatch beyond tolerance, exact duplicate, invalid approver, claim outside the submission window.
Soft flags — the claim proceeds with a recorded note and enters a review queue: near-limit amount, unusual merchant category, pattern anomaly, uncertain tax treatment.
The split determines the size of the human queue. Tuned well, hard stops land on 2-5% of claims and soft flags on another 5-10%, leaving 85-90% to pay straight through.
Step 4: Give the exception back to the claimant, not the auditor
When a hard stop fires, the fastest resolution path is almost always the person who submitted the claim. They have the receipt, they remember the dinner, they can explain the date. Routing every exception into a finance queue makes finance the bottleneck for information it does not have. Returning it to the claimant with a specific, plain-language reason — “the receipt shows S$142.00 but the claim is for S$152.00” — resolves most exceptions without a finance touch. Finance then sees only what the claimant cannot or should not resolve: suspected duplicates, pattern anomalies, and anything carrying a fraud signature.
Step 5: Audit the behaviour, not just the transaction
The eighth dimension — behavioural pattern — only becomes possible once you hold 100% of claims as structured data. With a full population you can ask questions a 5% sample cannot answer: which claimants cluster consistently just under the limit, which cost centres have seen category spend shift without a business change, which approvers have never once rejected a claim, and which merchants appear across employees with no business reason to overlap.
That last question finds the genuinely serious cases, and no sampling regime will ever surface it, because the signal exists only in the aggregate.
What Changes in the Numbers
Moving from sampled post-payment audit to full pre-payment screening changes four metrics.
Coverage goes from single-digit percentages to 100% of claims screened — the metric that matters to internal audit and to external auditors testing control design.
Human review volume typically falls, because the 5-15% exception queue is smaller than the “everything above threshold” queue it replaces, and exceptions arrive with the failed rule attached rather than requiring discovery.
Reimbursement cycle time falls, usually substantially. This is counterintuitive and the point most worth making internally. Under sampling, a clean claim waits behind review capacity; under screening, it is paid on the next run. Employees experience full coverage as faster reimbursement, which removes the political objection before it is raised.
Recovered value shows up in three places that business cases often miss: prevented overpayments, recovered input tax on claims that would have been coded non-recoverable, and avoided duplicate payments across the claim and card channels.
The Institute of Management Accountants frames control effectiveness as prevention versus detection. Sampled post-payment audit is purely detective, and weakly so. Full pre-payment screening is preventive — the higher-value category in every control framework, including COSO.
Where Implementations Go Wrong
Four failure modes recur often enough to name.
Encoding the policy you wish you had. Teams write rules against the formal policy document, which has often never been written in testable form and has drifted from practice over years of quiet exceptions. Week one then produces a 60% exception rate and the project is declared broken. Run the rules in observation mode against three months of history first, and reconcile written policy against lived practice before anything blocks.
Treating every rule as a hard stop. The most common cause of user revolt in month one.
Ignoring the master data. Rules validating cost centres, entities and approver authority are only as good as the underlying records. Stale employee, grade, entity or budget data will reject valid claims and pass invalid ones — see keeping employee and budget master data in sync across ERP and HCM.
Building the screen without the trail. A rule cleared by a finance user with no recorded reason is worse than no rule: it creates the appearance of control with none of the substance. Every clearance needs an actor, a timestamp and a justification, stored immutably.
How Peakflo Helps
Peakflo’s travel and expense management module is built around pre-payment screening rather than post-payment sampling. Receipts submitted from mobile or email are read by AI-powered capture that extracts merchant, date, gross and tax amounts and line-level detail, turning the attachment into testable data at the moment of submission.
Every claim is then run against the full rule set — documentation, amount agreement, duplication across both claims and imported card statements, category and GL coding, tax treatment, policy limits by grade and location, and approver authority — with hard stops and soft flags configured separately so that clean claims route straight to payment while only genuine exceptions reach a human. Exceptions are returned to the claimant with the specific failed check in plain language, and every rule result, clearance and approval step is written to an immutable audit trail that can be replayed per claim.
Because the full population is captured as structured data, pattern-level questions — claimants clustering under limits, approvers who never reject, merchants shared across unrelated teams — become reportable rather than invisible. If you want to see what full-coverage screening looks like against your own claim history, request a demo.
Our Verdict: Is Full-Coverage Audit Worth Building?
Prioritise this if:
- You process more than roughly 300 claims a month and your audit coverage is a threshold rather than a risk assessment
- Findings arrive after payment and most convert to write-offs
- You operate across entities or jurisdictions where tax treatment and limits differ
- You have had an audit observation on T&E controls, or expect one
- Reimbursement cycle time is already a complaint — the fix improves both problems at once
Lower priority if:
- Claim volume is under about 100 a month, where genuine 100% manual review is feasible and cheaper than configuration
- T&E is a rounding error against addressable spend and control effort belongs on tail spend or AP instead
- Your master data is unreliable — fix that first, or the rules will produce noise
The honest test: if someone asked how many claims you paid last quarter that would have failed a rule you have already written down, could you answer? If not, the control you have is a sampling exercise wearing an audit’s clothes.
Conclusion
Expense report audit has been constrained by a false premise — that reviewing a claim requires a person to open it. That was true when the evidence was a photograph and policy lived in a PDF. It is no longer true.
Once receipts become structured data and policy becomes executable rules, coverage stops being a budget decision. The marginal cost of the ten-thousandth check is zero, so there is no principled reason to check five percent.
What remains scarce is judgement, and judgement should be spent on exceptions the machine cannot resolve: the pattern that looks wrong, the explanation that does not hold, the behaviour that has drifted. Organisations that make this shift get better control, faster reimbursement, cleaner cost reporting, recovered input tax, and an audit trail that survives external scrutiny without anyone reconstructing decisions from memory.
Frequently Asked Questions
What is an expense report audit?
An expense report audit is a structured review of submitted employee claims to confirm the expense was incurred, was business-related, complied with policy, was supported by valid documentation, and was coded and taxed correctly. It differs from approval: an approver judges business justification, while an audit verifies evidence and policy conformance independently.
What percentage of expense reports should be audited?
Manual programmes typically sample 3-10% of reports, chosen by value threshold or random selection. That coverage is a budget constraint, not a risk decision. With automated rule-based review the correct target is 100% of reports screened against every rule, with human auditors reviewing only the exceptions the screen raises — usually 5-15% of volume.
What should be on an expense report audit checklist?
A complete checklist covers eight areas: receipt presence and legibility, receipt-to-claim data agreement, date and duplication checks, policy limit conformance, category and GL coding accuracy, tax treatment and reclaim eligibility, approval chain validity including delegation, and out-of-pattern behaviour relative to the claimant’s own history.
Should expense audits happen before or after payment?
Before payment wherever possible. Post-payment audit finds problems after the cash has left, converting every finding into a recovery action — payroll deduction, employee conversation or write-off. Pre-payment audit prevents the payment. Automated screening makes pre-payment review feasible because it adds minutes, not days, to the cycle.
How does AI improve expense report auditing?
AI reads the receipt image and extracts merchant, date, amount, tax and line items, which converts an unstructured attachment into data that rules can test. It also compares the claim against the employee’s own history and peer patterns, surfacing anomalies that fixed thresholds miss, such as a steady drift toward the policy cap.
What is the difference between expense approval and expense audit?
Approval is a business judgement made by a manager who knows the context: was this trip worth taking? Audit is an evidence check made independently of that judgement: does the receipt support the amount, does the claim meet policy, is the coding right? Approval without audit means policy is enforced by whoever is least likely to say no.
How do you build an audit trail for expense claims?
Record every state change with actor, timestamp and reason: submission, each rule result, each exception raised, who cleared it and on what grounds, every approval and delegation, and the payment reference. The trail must be immutable and reconstructable per claim, so an external auditor can replay the decision without interviewing staff.
What are the most common expense report audit findings?
The recurring findings are missing or illegible receipts, amounts that do not match the receipt, claims submitted after the policy deadline, personal items inside a business claim, incorrect tax coding that blocks GST or VAT reclaim, duplicate submission across a claim and a corporate card, and approvals granted by someone outside the valid chain.
Does 100% audit coverage slow down employee reimbursement?
It speeds it up. Under sampling, clean claims still wait in a queue behind manual review capacity. Under automated screening, claims that pass every rule route straight to payment within minutes, while only flagged claims wait. Reimbursement cycle time typically falls even as coverage rises from single digits to full population.
How do you audit expenses without damaging employee trust?
Make the rules visible and apply them uniformly. When employees can see which check failed and why at submission time, an audit reads as a system behaving consistently rather than a manager singling them out. Silent post-payment clawbacks are what damage trust, not transparent pre-payment validation.