, ,

How to Audit Travel and Expense: Policy, Fraud, Analytics and a Worked Engagement

Travel and expense is the smallest money most audit functions will ever chase and the richest signal they will ever get. The dollars rarely justify the fieldwork on recovery grounds alone — a padded dinner here, a duplicated taxi there. What justifies the audit is everything else T&E tells you: it is a complete, digital, name-attached record of how every employee in the organization behaves when they believe nobody is checking, and how every manager behaves when asked to check. Expense abuse is the classic culture bellwether — small integrity failures that predict larger ones, tolerated exceptions that map your real tone-at-the-middle — and T&E data is the best analytics training ground in audit: clean populations, obvious patterns, fast feedback.

This guide — the fourth flagship in our How to Audit series, after accounts payable, journal entries, and payroll — covers the audit in its natural order: the policy design review most programs skip, approval integrity, the full analytics catalog, and the discipline that separates a respected T&E audit from a resented one: proportionality. Most exceptions are sloppiness, not fraud, and a report that cannot tell the difference damages the function more than the exceptions damage the company.

This guide was rewritten in September 2026 to add what the August version left out: a starter risk and control matrix for the process, how to size and sequence the engagement, MidState Beverage’s travel and expense audit test by test, and the links to the templates that carry the work. The policy-design review, the approval tests, the scheme catalog, the analytics catalog and the proportionality doctrine are unchanged. The ACFE’s Occupational Fraud 2026 report, which supersedes the 2024 figures quoted below, leaves the two numbers that matter here where they were: tips remain the largest detection source at 43 percent of its 2,402 cases and the median scheme still runs for twelve months before detection, with internal audit credited with 15 percent of detections. Expense data is the place where that 15 percent is easiest to earn.

In this guide

Start with the policy: audit the design before the compliance

Most T&E audits test compliance with the policy and never test the policy — which is backwards, because in T&E the policy is the control system, and badly designed policies manufacture their own violations. Four design questions before any sampling:

  1. Where is the receipt threshold, and what does it teach? A $75 threshold tells every employee that $74 is invisible — and your amounts histogram will show exactly how well they learned it. The threshold is a cost-benefit choice, not a virtue; the design question is whether anything monitors the space below it (aggregate analytics), or whether below-threshold is genuinely unwatched.
  2. Per diems or actuals? Per diems eliminate receipt games and shrink the audit surface at the cost of over- or under-paying reality; actuals invite the games this article catalogs. Mixed regimes (per diem meals, actual lodging) are fine — undocumented regional inconsistency is not, and finding three different effective policies across divisions is a finding about governance, not travel.
  3. Is the corporate card mandated? Card-mandated programs give you a second, independent data stream (the card feed) to reconcile against expense claims — the single most powerful structural control in T&E, because cash claims are unverifiable stories while card transactions are records. A program that reimburses significant cash spend has chosen weaker evidence on purpose; say so.
  4. Do the rules fit how people actually travel? Policies written in 2015 meeting 2026 travel — rideshare, home-sharing, remote-work trips, blended personal-business travel — generate technical violations that train everyone to ignore the policy. High violation rates concentrated in a few rules usually indict the rule.

Deliverable from this section: a short policy-design assessment alongside the compliance results. It is frequently the most valuable page in the report, and it is the page that makes the compliance findings feel fair.

The policy-design assessment: a one-page template

The design assessment is short, sits in front of the compliance results, and is written so that a committee member who reads nothing else understands why the exceptions look the way they do. The template below is the one MidState’s report used; each numbered line is a sentence or two, and the whole page rarely runs past 300 words.

Travel and expense policy: design assessment. 1. Policies in force: the number of effective policies, the population each applies to, the date each was last reviewed and by whom. 2. Evidence standard: the receipt threshold by entity, the share of spend claimed in cash rather than on the corporate card, and whether anything monitors spend below the threshold. 3. Regime: per diems, actuals or mixed, by category and entity, and whether the differences are documented decisions or accidents of history. 4. Fit with actual travel: the three rules with the highest violation rates and whether each violation rate indicts the traveler or the rule. 5. Approval design: how approvers are assigned, which self-approval costumes the configuration blocks, and who reviews the executives. 6. Monitoring: what management sees monthly, and what happened the last time a metric moved. 7. Assessment: whether the policy as designed can be complied with by the people it governs, in one sentence, followed by the design changes recommended before any compliance remediation is asked of anyone.

Line 7 is the one that makes the compliance findings feel fair. When it says the policy cannot be complied with, the rest of the report is read as evidence for that sentence rather than as a list of people who broke rules, which is the reading a T&E report needs if it is going to change anything.

Approval integrity: the control that is usually theater

Every expense report is “approved.” The audit question is whether approval is a control or a click. Four tests cut to it. Self-approval and its costumes: direct self-approval is usually blocked by configuration — so test the costumes: delegate arrangements where the approver’s assistant (who reports to them) approves their reports; circular pairs who approve each other; approvals by subordinates of the submitter. Pull the approval graph and look at it as a graph. Approval velocity: timestamp analytics — the manager who approves 40 reports in three minutes at 11pm is acknowledging, not reviewing; measure median seconds-per-report by approver and rank them. Seniority inversion: who approves the executives? The CEO’s expenses approved by the CFO’s admin is a real pattern with a real name in the working papers. Executive T&E deserves the same explicit scoping decision as executive payroll: restricted visibility, never absent control. Escalation reality: when the system flags a violation, what happens? Sample flagged-then-approved items — if 96% of policy flags are approved through with no comment, the exception process is a speed bump, and that is the finding.

The starter RCM: seven controls that carry the process

The sibling guides in this series each open their testing with a starter risk and control matrix, and the August version of this one did not, partly because T&E has so few controls that the omission seemed harmless. It is not harmless: an audit that tests the policy and the approvals without a matrix tends to write findings about people, because people are what the data shows, whereas a matrix forces every exception back to the control that should have stopped it. The seven controls below carry the process in most organizations. Build them into the risk and control matrix template before fieldwork, mark which ones exist at your organization, and test the ones that exist; the ones that do not exist are design findings before a single claim is examined.

ControlTypeWhat it prevents or detectsHow to test it
One policy, owned, reviewed annually, applied to every entity and every grade including executivesEntity-level, preventiveFragmented rules across divisions and acquisitions; executive carve-outs; rules that no longer fit how people travelObtain every policy version in force; map which population each applies to; compare thresholds and rules; confirm the annual review happened and who signed it
Corporate card mandated for travel spend, with the card feed loaded into the expense systemPreventive and detectiveUnverifiable cash claims; duplicate reimbursement of card spend; fictitious claims supported by generated receipt imagesMeasure the cash share of spend by entity and grade; confirm the feed loads daily and that unmatched card transactions age out to a report someone reads
System-enforced rules: receipt thresholds, category limits, blocked merchant categories, mandatory fields, with flagged exceptions routed to the approverAutomated preventiveOut-of-policy claims that pass because nobody noticed; missing business purpose and attendee fieldsInspect the configuration; submit test claims in a non-production environment where possible; reconcile the flag log to the approval log
Approver assignment from the HR hierarchy, with self, subordinate, delegate-to-subordinate and circular approvals blockedPreventiveApproval theater; the assistant approving the executive; two managers approving each otherPull the approval graph for the year and test it as a graph; confirm the assignment rule is system-enforced rather than a policy sentence
Independent pre-payment review of flagged and high-scored reports by a reviewer who is not the approverDetective, before paymentApproved exceptions reaching payment; receipt-image fraud; policy-washed gifts and entertainmentSample 25 reviewed reports; confirm the reviewer saw the card record and the receipt, challenged the flags, and that rejections were actually reversed
Automated duplicate detection across card feed, cash claims and employees, with a hold on payment until clearedAutomated detectiveDouble reimbursement; the shared dinner claimed by both attendees; the rejected claim resubmittedRe-perform the match on the year’s data with your own logic and compare the hit list to the system’s; the gap is the finding
Monthly monitoring analytics reported to management, with executive T&E reviewed by someone senior to or independent of the executivesDetective, entity-levelSerial grazing; approver velocity; executive exception rates with no reviewerObtain twelve months of the monitoring pack; test that a metric that moved produced an action; confirm who reviews the chief executive’s claims and whether they can say no

Two of the seven decide the shape of the audit. If the card is mandated and the feed is loaded, most of the analytics catalog runs on records rather than stories and the audit is largely a data exercise. If it is not, the audit has a structural design finding on page one, and the cash population has to be tested with the receipt in one hand and the knowledge that receipt images are now the weakest evidence class you hold in the other.

Sizing and sequencing the engagement

A T&E audit is cheap by the standards of the disbursement series because the population is clean and digital, and expensive in one place that first-time planners miss: the joins. The expense lines, the card feed, the HR hierarchy, the absence calendar, the travel bookings and the approval log come from five systems in most organizations, and reconciling them into one table with a reliable employee key is where the first week goes. The hours below assume a mid-sized organization with a few hundred submitters, a card program, and an analytics-capable auditor on the team; they are a planning range, not a quote, and the sampling memo should record why the program landed where it did.

PhaseWhat happensHours
Planning and policy-design reviewEvery policy version mapped to its population; thresholds compared; the design assessment drafted before any data is pulled30
Data acquisition and joinsFive datasets extracted with completeness proofs; employee key reconciled; card feed matched to the expense system at the transaction level40 to 60
Analytics run and triageThe full catalog run on the year; hits scored and grouped into the three populations before anyone reads a receipt50 to 80
Approval graph and velocityThe approver network drawn, costumes of self-approval identified, seconds-per-report ranked20
Layered testingLayer one categorical sets in full; layer two receipt-and-purpose testing of the scored tail; layer three seeded random sample80 to 120
Compliance-sensitive hitsGifts, entertainment and government-adjacent items walked with legal or compliance under their protocols, not the audit’s20
Reporting and the base ratesFindings written at program level with denominators; people-level items routed off-report; management conversations40
Total 280 to 370

Sequence matters more than in most audits. The policy review goes first because it changes how every later exception is read: a threshold-hugging pattern against a badly chosen threshold is a design finding, not a submitter finding. The analytics go before any manual testing because the categorical sets and the scored tail are what the manual testing is for. And the compliance-sensitive hits go to legal or compliance the day they are found, not at the end, because a gift to a customer’s buyer or a payment near a public official carries obligations that do not wait for the draft report; the first 48 hours protocol covers what changes the moment a hit stops being a policy exception and starts being a possible offense.

The scheme catalog: how T&E actually leaks

SchemeMechanicsPrimary detection
Duplicate reimbursementSame spend claimed twice: card + cash claim, two months apart, or split across two employees at the same dinnerCard-feed reconciliation; cross-employee same-merchant-date-amount matching
Personal spend as businessVacation-adjacent hotel nights, family meals, personal purchases on the corporate card coded as businessPTO-calendar overlap; weekend/holiday patterns; merchant category screens
Threshold gamesClaims engineered below receipt or approval thresholds; one dinner split into two claimsAmounts histogram; same-day same-merchant splits
Mileage inflationPersonal-car mileage padded per trip — small, constant, and almost never checkedClaimed miles vs. mapped route distance for recurring trips
Fictitious expensesClaims for spend that never happened, supported by altered or generated receiptsReceipt forensics on the scored tail; merchant validation; the modern wrinkle — AI-generated receipt images — makes independent card evidence more valuable than image inspection
Gift, entertainment, and policy-washingAlcohol, gifts, or entertainment for government officials or clients coded as “meals — other” to dodge compliance limitsKeyword and merchant screens; this is where T&E crosses into anti-corruption exposure, and where a small claim can carry regulatory consequence far beyond its amount
Serial grazingNo single egregious claim — a persistent pattern of maximum-allowable everything, every tripPer-employee spend-per-travel-day ranking against peer norms

Note what the catalog implies: almost every scheme is invisible in a random sample of 25 reports and obvious in a full-population analytic. T&E is the process where the ACFE’s detection findings — tips at 43%, frauds running a median 12 months (2024 Report to the Nations) — should embarrass nobody, because the data to find these patterns in week one has been sitting in the expense system all along.

The analytics goldmine: the full test catalog

Run these across the full year’s population — expense lines, card feed, HR calendar, and approval log joined — before selecting a single report for manual review. Logic stated plainly enough to build in SQL or Excel:

AnalyticLogicWhat a hit means
Card-vs-claim duplicatesCorporate-card feed matched to cash claims on amount + merchant + ±days; exact then fuzzyDouble reimbursement — the highest-yield test in T&E
Cross-employee duplicatesSame merchant + date + amount across employees (the shared dinner claimed by both attendees)Double reimbursement or copy-paste claims
Resubmission scanSame employee, same amount + merchant, 30–120 days apartThe rejected-then-resubmitted or claim-it-twice pattern
Threshold huggingHistogram of claim amounts; density spike just under receipt and approval thresholds, ranked by employeeLearned invisibility; split claims
PTO and calendar overlapExpense dates joined to HR absence calendar and travel bookingsVacation spend coded as business; ghost trips
Weekend and holiday spendNon-travel-day weekend charges by category, netted for legitimate weekend travelersPersonal spend on the card
Keyword and merchant screensDescription and merchant text: gift, cash, gc, spa, golf, jewelry, tuition, government-adjacent entertainment terms; MCC codes for prohibited categoriesPolicy-washing; compliance exposure (route these hits to compliance protocols, not the routine findings pile)
Mileage vs. mapRecurring origin-destination pairs: claimed miles vs. routed distanceSystematic inflation — small per trip, meaningful per year
Round-amount concentrationShare of claims at round tens/hundreds by employee vs. population base rateEstimated (unreceipted) claiming as habit
Spend-per-travel-day rankingTotal T&E normalized by travel days, ranked within role bandSerial grazing; also finds the legitimately misclassified road warrior
Approver velocity and flag pass-throughMedian seconds per approval by approver; % of policy-flagged items approved unchangedApproval theater — a control finding, not a person finding

From analytics to testing: the three-layer approach

Structure selection exactly like journal-entry testing: layer one, 100% review of the categorical sets (all executive T&E, all compliance-keyword hits, every employee in the top decile of composite analytic score); layer two, manual receipt-and-business-purpose testing of the scored tail — verify against the card record first, the receipt image second, remembering that receipt images are now the weakest evidence class you hold; layer three, a small seeded random sample of ordinary reports (sizing per the sampling guide, selection via mySampler) so the program is not perfectly predictable and so you can say something statistical about the boring middle. Document dispositions hit-by-hit in the grid format of our model workpaper — in T&E more than anywhere, the file must show which hits were cleared and why, because the population is people, not invoices.

The proportionality doctrine: findings without witch hunts

T&E is the audit most likely to damage the function if reported badly, because every exception has a name attached and most names belong to careless people, not corrupt ones. The doctrine has four planks. Report programs, not people: findings describe control and policy failures with aggregate numbers; individual cases route to management or investigation channels, never to a distributed audit report. Separate the three populations your analytics will surface — sloppiness (duplicate submissions from bad memory, missing receipts), policy abuse (threshold games, serial grazing), and potential fraud (fictitious claims, forged receipts) — and treat them differently: the first is a training-and-design story, the second a management-action story, the third exits the audit into your fraud protocol (see the fraud risk guide) with chain-of-custody discipline from that moment. Mind the seniority asymmetry: the intern’s $40 duplicate and the SVP’s pattern of policy-flag overrides are not the same finding, and a report that hammers the first while soft-pedaling the second will — correctly — destroy the audit’s credibility; executive exceptions carry the tone-at-the-top weight and get reported with it. Give the base rate: “$61,000 of exceptions” alarms; “$61,000 of exceptions on $9.4M of spend — 0.65%, concentrated in 14 of 1,900 submitters” informs. Proportionality is not softness; it is precision about magnitude, which is what makes the severe findings believable when you have them.

Worked example: MidState Beverage’s travel and expense audit

MidState Beverage, the three-state drinks distributor used across this site, has about 1,400 employees, twelve depots, two acquired distributors integrated for revenue but not for controls, a 2013 ERP with a cloud expense system bolted on, and a six-person internal audit function with no compliance function beside it. Its drivers do not claim expenses; its 412 submitters are sales representatives, merchandisers, depot managers and head-office staff, and in the year audited they filed 21,400 expense lines worth 2.6 million dollars. The corporate card is mandated at head office and the ten legacy depots. The two acquired distributors, about 90 submitters between them, were still claiming cash against scanned paper receipts, because nobody had migrated their card program. The engagement ran in the sequence above and took 310 hours, most of the overrun in the joins, where the acquired distributors’ employees turned out to carry different identifiers in HR, the expense system and the card feed.

Test or analyticPopulationWhat it foundDisposition
1. Policy designEvery policy version in forceThree effective policies: a 75-dollar receipt threshold and actuals at legacy MidState; a 25-dollar threshold at one acquired distributor; no threshold and a meal per diem at the other. No annual review of any of them since 2022.Finding, High: governance of the policy, not travel
2. Card mandate and feedSpend by entity and gradeCash claims were 4 percent of legacy spend and 100 percent of the acquired distributors’ spend; the card feed loaded weekly rather than daily and unmatched transactions aged out to nobody.Part of finding 1, including the feed cadence
3. Approval graphAll 38 approvers, 21,400 linesSix approvers handled 44 percent of volume at a median of six seconds per report; 94 percent of policy-flagged items approved without comment; two depot managers approved each other’s reports for fourteen months; the CFO’s reports were approved by the controller, who reports to the CFO.Finding, High: the approval workflow operates as acknowledgment
4. Executive T&EAll nine executives, in fullFlagged-item rate 2.1 times the company average with a 100 percent approval pass-through; no reviewer independent of the executive team for anyone but the chief executive, whose claims the audit committee chair reviews twice a year.Reported inside finding 3 with the tone-at-the-top weight it carries
5. Card-versus-claim and cross-employee duplicatesCard feed against cash claims; all lines across employees14,800 dollars claimed both on card and as cash reimbursement across 33 employees; 2,900 dollars of shared dinners claimed by both attendees in eleven pairs; six resubmissions of previously paid claims, 1,100 dollars.Finding, Medium: no automated match; 88 percent recoverable
6. Threshold huggingAmounts histogram by submitterClaims between 70 and 74.99 dollars at 2.7 times expected density, concentrated in seventeen submitters, nine of them in one sales region under one of the six-second approvers.Design and training item inside finding 1; region routed to sales management
7. Calendar overlapExpense dates against the absence calendar and bookings61 lines on leave days, 6,200 dollars; forty explained by travel bookended by leave; 21 lines, 2,400 dollars, were personal spend on the card.Finding, Low; recoveries handled by management
8. Keyword and merchant screensDescriptions, merchants and category codes23 hits, fourteen of them gifts to retail customers’ store managers coded as other meals, 3,100 dollars, against a gifts rule that was a single sentence in the policy.Walked with outside counsel under their protocol; finding, Medium, on the absence of a gifts and entertainment policy
9. Mileage against mapped routes24 recurring origin-destination pairsClaimed miles averaged 18 percent above routed distance; five merchandisers accounted for most of it, about 4,700 dollars a year.Finding, Medium; mileage moved to app-captured routes
10. Spend per travel dayTotal spend normalized by travel days, ranked within role bandTwo sales representatives at three times the peer median: one with a territory spanning two states and a legitimate explanation; one with maximum-allowable everything on every trip.Management action for the second; no finding
11. Receipt forensics on the scored tailTop decile by composite score, cash claims firstThree receipts from one cash-claiming submitter at an acquired distributor with identical fonts and totals that did not foot, 1,900 dollars; the merchant confirmed no such transactions.Referred under the protocol on day nine; substantiated as generated images; kept out of the report
12. MonitoringTwelve months of management reportingNo monitoring pack existed; the analytics above had never been run by anyone.Finding, Low, with the monthly pack as the remediation

The report carried seven findings, two High, three Medium and two Low, an overall rating of Needs Improvement, and one referral handled outside it. The base rate went on the first page: 30,900 dollars of quantified exceptions on 2.6 million dollars of spend, 1.2 percent, with 60 percent of the amount attributable to nineteen submitters. That sentence is what made the two High findings land, because it told the audit committee at once that the money was small and the control failures were not. Three things about the engagement are worth carrying to your own. The most expensive finding was the one with no dollars attached: three policies and no card program at the acquired distributors were the reason most of the other exceptions existed, and the fix, one policy and one card program, cost less than the audit. The fraud, the only one in the engagement, was small, sat in the cash population the card mandate had never reached, and was found by the forensic work the guide describes rather than by any control; the expense reimbursement branch of the fraud tree predicts exactly that. And the approval finding was written about six seconds and 94 percent, not about the six approvers, whose names went to their managers through the channel the issue log tracks and never into a distributed document.

The findings that recur — and wording that lands

Four findings cover most T&E reports. Duplicate-detection gap (“card-feed reconciliation identified $38,200 claimed both on card and as cash reimbursement across 61 employees over the year; no automated match exists between the card feed and the expense system — 0.4% of spend, 92% of it recoverable”). Approval theater (“the 11 approvers handling 40% of report volume show median review times under 8 seconds; 96% of policy-flagged items were approved without comment — the approval workflow operates as acknowledgment”). Threshold clustering (“claims between $70 and $74.99 occur at 3.1× the expected density against the $75 receipt threshold, concentrated in 23 submitters — the threshold functions as a target”). Executive exception rate (“flagged-item rates for the executive population run 2.4× the company average with a 100% approval pass-through — reported here as the tone indicator it is”). Each is a program-level statement built on the 5 C’s chain, with the people-level follow-ups routed off-report.

Where to go next

Audit T&E for what it is: a low-dollar process wired directly into the organization’s integrity signal. Review the policy design before prosecuting compliance with it, build the seven-control matrix so that every exception has a control to point at, test the approvers harder than the submitters, run the full analytics catalog before touching a single receipt, and hold the proportionality line: programs in the report, people through the right channels, base rates on every number. Done that way, as MidState’s engagement was, the T&E audit produces the thing committees quietly value most, an honest reading of everyday integrity with the data to back it, and it does so in three hundred hours.

The series continues across the disbursement universe with accounts payable, payroll and journal entries, and into the buying side with procurement and the vendor master file. The reporting craft that carries the results lives in the findings masterclass and the model report library.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading