Expense Report Fraud: The Four Schemes and How to Design Against Them

Expense reimbursement fraud comes in four scheme types — mischaracterised, overstated, fictitious, and multiple reimbursements — and each defeats a different control. Documentation checks miss mischaracterisation because the receipt is genuine. Policy limits miss overstatement because the claim stays under the cap. What makes these schemes expensive is not size but duration: they run for years because no single claim is big enough to trigger anyone’s threshold. The design answer is uniform automated screening on every claim plus pattern analysis across the full population.
The Scheme That Survives Because Nobody Cares Enough
Expense fraud is unusual among financial crimes in that almost everyone involved knows roughly what is happening and nobody acts.
The manager who approves a slightly generous dinner claim suspects it included a spouse. The finance clerk who processes a taxi claim for a route that makes no sense notices. The colleague who was at the same conference knows their teammate did not take that airport transfer. In each case the amount is forty dollars, or eighty, and the social cost of raising it exceeds the value recovered.
This is precisely the economics that makes the category durable. Research from the Association of Certified Fraud Examiners has long placed expense reimbursement among the most common occupational fraud schemes, and the reason is not that people who claim expenses are unusually dishonest. It is that the control environment around small, frequent, socially-adjudicated transactions is structurally weak.
What makes it costly is duration. A scheme running at a hundred dollars a month for six years is a five-figure loss discovered, if at all, by accident. The distribution of expense fraud cost is driven almost entirely by time-to-detection, not by transaction size — which means the controls worth building are the ones that shorten detection time, not the ones that catch big claims.
The Four Schemes
Fraud examiners generally classify expense reimbursement schemes into four types. The distinction matters operationally, because each defeats a different control and each requires a different detection approach.
1. Mischaracterised expenses
A genuine purchase, with a genuine receipt, claimed under a business category it does not belong to.
A family dinner submitted as client entertainment. A personal weekend appended to the end of a business trip and claimed as accommodation. A flight booked for a relative under a business booking reference. Everything about the documentation is authentic — merchant, date, amount and receipt all agree perfectly.
This is the hardest scheme to detect, because every documentation control passes. The claim only looks wrong in context: who the attendees were, what the trip was for, whether the dates extend past the business purpose.
What catches it: mandatory attendee capture on entertainment categories, trip date validation against the approved travel request, and pattern analysis on claimants whose entertainment ratio diverges sharply from peers in comparable roles.
2. Overstated expenses
A real expense, inflated. The taxi cost S$28 and the claim says S$48. The meal receipt is genuine and the claimed amount is not.
Two variants exist. In the simpler version the claimant relies on nobody comparing the claim against the receipt — which, without extraction, nobody does. In the more deliberate version the receipt itself is altered before submission.
What catches it: automated extraction of the amount from the receipt image and comparison against the claimed amount, with a tolerance band. This is a single check and it eliminates the entire scheme category, but it only works if extraction is accurate enough to trust — which is why receipt extraction quality is a control question, not just a convenience question.
3. Fictitious expenses
The expense never happened. A fabricated receipt, a downloaded template, a duplicated image from a previous trip, or increasingly a generated one.
Historically this required effort and produced artefacts a careful reviewer could spot. That is no longer reliable — plausible receipt images are now trivially producible, which makes visual inspection an obsolete control and shifts the burden onto corroboration.
What catches it: cross-referencing against independent records. Does the claimed taxi exist on a day the claimant was travelling per the approved request? Does the hotel night overlap a card transaction at a different hotel? Is the receipt image a reuse of one submitted previously? Reuse detection — hashing submitted images and comparing against history — is cheap and effective, and it is the single control most organisations lack entirely.
4. Multiple reimbursements
One real expense claimed more than once. The same receipt submitted twice, or an expense paid on a corporate card and also claimed out of pocket, or two attendees at the same dinner both claiming the full amount.
This is the most mechanically detectable scheme and the one that most often goes undetected anyway, because detection requires comparing across claims, across time and across channels — which manual review, operating one claim at a time, structurally cannot do. The mechanics of catching each variant are worth their own treatment, and we cover the seven duplicate claim patterns and the detection technique for each separately.
| Scheme | Receipt genuine? | Amount matches receipt? | Defeats which control | Primary detection |
|---|---|---|---|---|
| Mischaracterised | Yes | Yes | Documentation, limits | Attendee capture, trip date validation, peer comparison |
| Overstated | Usually | No | Documentation, approval | Extraction vs claim comparison |
| Fictitious | No | Yes (both fabricated) | Documentation, visual review | Corroboration, image reuse detection |
| Multiple reimbursement | Yes | Yes | Single-claim review | Cross-claim and cross-channel matching |
Read the third column. Every scheme passes at least one control that organisations rely on heavily, and two of the four pass documentation checks entirely. A control programme built only on “did they attach a receipt” catches one scheme out of four, and only the clumsy version of it.
Why Approval Does Not Function as a Fraud Control
Most organisations, asked where expense fraud would be caught, point at the approver. This is misplaced for three structural reasons.
The approver is socially compromised. They manage the claimant. They will work with them tomorrow. Challenging a S$60 discrepancy carries a relationship cost that exceeds the amount in dispute, and both parties know it.
The approver has no evidence. Approvers rarely open receipt attachments. Even when they do, they are comparing a photograph against a number, by eye, at volume, usually on a phone. The comparison that catches overstatement is not one a human performs reliably.
The approver sees one claim. Fraud patterns live across claims — the drift toward the cap, the merchant that recurs, the deadline-day submission habit. No individual approver holds that view, and no sequence of individually reasonable approvals will ever surface it. This is why the Institute of Internal Auditors treats independence from the transaction as a defining property of an assurance activity: a control performed by someone inside the relationship is not assurance.
This is the same structural point that applies to expense control generally: approval validates business intent, not evidence. Treating it as a fraud control means the organisation’s fraud defence is the person with the strongest incentive not to look.
Designing a Programme That Actually Deters
The prevention literature is consistent on one point: what deters fraud is the perceived probability of detection, far more than the severity of consequence. That has a direct design implication — controls must be visible and uniform, not severe and selective. Professional ethics guidance from IFAC makes a related argument about tone: controls applied evenly signal that the organisation expects integrity from everyone, while selective scrutiny signals that it suspects some people.
Make the screening universal
Every claim, every rule, before payment. Not a sample, not a threshold. The deterrent value of a check that applies to 5% of claims is roughly 5% of the deterrent value of one that applies to all of them, and the detection-time improvement is what drives the loss reduction. Moving from sampled post-payment review to full pre-payment screening is the single highest-leverage change available, and we set out the mechanics of getting to full coverage in detail.
Add the three checks most programmes lack
Most organisations already validate policy limits. The three that are usually missing are the ones that catch the schemes limits cannot:
- Extracted amount versus claimed amount, with tolerance. Eliminates overstatement.
- Receipt image reuse detection across the claimant’s own history and, where feasible, across the organisation. Catches the laziest and most common fictitious and duplicate variants.
- Cross-channel matching between reimbursement claims and imported corporate card statements. Catches the double-dip that neither system sees alone — which is one reason card statement reconciliation belongs inside the same platform as claims rather than beside it.
Watch behaviour, not just transactions
Threshold rules catch the claim that breaches a cap. They are blind to the claimant whose average has drifted from 40% of the cap to 96% over two years without a single breach — which is what a long-running scheme actually looks like.
Population-level signals worth monitoring: clustering just below approval or receipt thresholds, round-number amounts, habitual deadline-day submission, merchants shared across employees with no business reason to overlap, and category ratios that diverge from role peers. None of these is evidence on its own. Together, and over time, they are where the serious cases surface — and the analytical framing the Institute of Management Accountants applies to continuous monitoring works directly here: monitor the distribution, investigate the outlier, never the reverse.
Separate fraud from policy violation
An over-limit meal submitted openly as an over-limit meal is a policy violation. The same meal disguised as a client dinner is fraud. The detection control is often identical; the response should not be.
Conflating them produces one of two failures: treating every breach as suspected fraud, which poisons the culture and gets controls switched off, or treating everything as an administrative slip, which means deliberate misstatement carries no consequence. Define the escalation path for each separately, and state it in the expense policy rather than improvising it when the first case arrives.
Keep the trail
Every rule result, every exception, every clearance with its stated reason, every approval and delegation — immutable and reconstructable per claim. Investigating a suspected scheme means reassembling eighteen months of decisions, and if that reconstruction depends on asking people what they remember, the investigation will not reach a defensible conclusion. Control frameworks including COSO treat the evidence of a control operating as inseparable from the control itself.
How Peakflo Helps
Peakflo’s travel and expense management module runs the full check set against every claim before payment rather than sampling after it. AI-powered extraction reads merchant, date, currency, gross and tax amounts from the receipt image, which makes the amount-versus-claim comparison possible — the single check that removes overstatement as a viable scheme.
Submitted receipt images are fingerprinted and tested against the claimant’s history to catch reuse, and claims are matched across channels against imported corporate card statements so the out-of-pocket double-dip surfaces automatically. Attendee capture on entertainment categories, trip date validation against the approved travel request, and category-versus-merchant consistency checks address the mischaracterisation schemes that documentation controls pass. Because the full claim population is held as structured data, behavioural signals — drift toward the cap, deadline-day clustering, merchants recurring across unrelated employees — are reportable rather than invisible, and every rule result and clearance is written to an immutable trail that supports a real investigation.
To see which of the four schemes your current checks would catch, request a demo and bring a sample of your claim history.
Our Verdict: How Much Should You Invest Here?
Treat this as a priority if:
- You have no check comparing extracted receipt amounts against claimed amounts — this is the largest single gap in most programmes
- Corporate card spend and reimbursement claims are reconciled in separate systems, leaving the double-dip channel open
- Your fraud defence is effectively manager approval
- You have had a case, or a near-miss, and could not reconstruct the history without interviewing people
- Claim volume is high enough that no realistic manual review covers a meaningful share
Lower priority if:
- Volume is small enough for genuine full manual review, and someone is actually doing it
- Your T&E spend is immaterial against total addressable spend, where AP-side fraud controls will return more per unit of effort
- You have screening in place and the real gap is policy clarity, in which case fix the rules themselves first
One caution on framing. Building this programme as an anti-fraud initiative tends to generate resistance disproportionate to the actual change, because it implies a suspicion most employees have not earned. The same controls framed as consistent validation — everyone gets the same checks, you see immediately what failed and why, clean claims pay faster — deliver identical detection with none of the cultural cost. The deterrent works because the checks are visible, not because they are announced as fraud controls.
Conclusion
Expense fraud persists not because it is sophisticated but because the control environment around small, frequent, manager-adjudicated transactions is weak in a predictable way. Four schemes, each defeating a different control, each too small individually to trigger anyone’s threshold, each running for years.
The schemes that pass documentation checks — mischaracterisation and the competent version of overstatement — are the ones worth designing against, and neither is addressed by asking for a receipt. What addresses them is reading the receipt as data, comparing it to the claim, corroborating against independent records, and looking at the population rather than the transaction.
None of that requires an investigator. It requires the checks to run on everything, every time, and to be visible to the people they apply to. Detection probability is the deterrent; uniformity is what makes it credible.
Frequently Asked Questions
What are the main types of expense report fraud?
Four schemes account for nearly all of it: mischaracterised expenses, where personal spend is claimed as business; overstated expenses, where a real expense is inflated; fictitious expenses, where the expense never happened; and multiple reimbursements, where one real expense is claimed more than once.
Why is expense reimbursement fraud so hard to detect?
Individual amounts are small enough to sit below review thresholds and below the level anyone wants to challenge socially. The approver is usually the claimant’s own manager, the evidence is an image nobody reads closely, and the pattern only becomes visible across many claims, which sampling never assembles.
How do you detect fraudulent receipts?
Compare extracted receipt data against the claim rather than eyeballing the image. Check merchant, date, currency and amount agreement, look for reused receipt images across claims, test whether the merchant category matches the claimed category, and flag receipts whose image metadata or formatting is inconsistent with the claimed merchant.
What is a mischaracterised expense?
A genuine purchase, with a genuine receipt, claimed under a business category it does not belong to — a family dinner submitted as client entertainment, or a weekend hotel night appended to a business trip. Everything about the documentation is authentic, which is why documentation checks alone never catch it.
How can you prevent expense fraud without treating employees as suspects?
Apply the same automated checks to every claim and show claimants which check failed and why. Uniform, visible, pre-payment validation reads as a system behaving consistently. Selective investigation and silent post-payment clawbacks are what damage trust, because they single people out after the fact.
What is the difference between expense fraud and policy violation?
A policy violation is spending outside the rules openly — an over-limit meal submitted as an over-limit meal. Fraud involves misrepresentation: disguising what the spend was, inflating what it cost, or claiming it twice. The same control catches both, but the consequence and the escalation path should differ.
Does corporate card spend reduce expense fraud risk?
It reduces fictitious expenses, because the transaction must actually exist, but it increases mischaracterisation risk and creates a second channel for double claiming. Card spend needs receipt matching and category validation just as reimbursement claims do, plus cross-channel duplicate checks.
What behavioural signals indicate possible expense fraud?
Claims clustering just below approval or receipt thresholds, round-number amounts, consistent submission on the policy deadline, merchants appearing across employees with no business overlap, and a claimant whose average against the cap drifts steadily upward over months without ever breaching it.
How much does expense fraud typically cost an organisation?
Individual instances are small, often under a few hundred dollars, but duration is what drives cost. Expense schemes typically run for years before detection because no single claim is large enough to trigger review, so the cumulative figure is a function of time undetected rather than transaction size.
Can AI detect expense claim fraud?
Yes, for the patterns fixed rules miss. AI extracts receipt data so claims become testable, identifies reused or manipulated receipt images, and compares each claim against the claimant’s own history and peer behaviour — surfacing gradual drift and cross-employee merchant overlaps that threshold checks cannot see.