Travel and expense is the smallest money most audit functions will ever chase and the richest signal they will ever get. The dollars rarely justify the fieldwork on recovery grounds alone — a padded dinner here, a duplicated taxi there. What justifies the audit is everything else T&E tells you: it is a complete, digital, name-attached record of how every employee in the organization behaves when they believe nobody is checking, and how every manager behaves when asked to check. Expense abuse is the classic culture bellwether — small integrity failures that predict larger ones, tolerated exceptions that map your real tone-at-the-middle — and T&E data is the best analytics training ground in audit: clean populations, obvious patterns, fast feedback.
This guide — the fourth flagship in our How to Audit series, after accounts payable, journal entries, and payroll — covers the audit in its natural order: the policy design review most programs skip, approval integrity, the full analytics catalog, and the discipline that separates a respected T&E audit from a resented one: proportionality. Most exceptions are sloppiness, not fraud, and a report that cannot tell the difference damages the function more than the exceptions damage the company.
This guide was rewritten in September 2026 to add what the August version left out: a starter risk and control matrix for the process, how to size and sequence the engagement, MidState Beverage’s travel and expense audit test by test, and the links to the templates that carry the work. The policy-design review, the approval tests, the scheme catalog, the analytics catalog and the proportionality doctrine are unchanged. The ACFE’s Occupational Fraud 2026 report, which supersedes the 2024 figures quoted below, leaves the two numbers that matter here where they were: tips remain the largest detection source at 43 percent of its 2,402 cases and the median scheme still runs for twelve months before detection, with internal audit credited with 15 percent of detections. Expense data is the place where that 15 percent is easiest to earn.
In this guide
- Start with the policy: audit the design before the compliance
- The policy-design assessment: a one-page template
- Approval integrity: the control that is usually theater
- The starter RCM: seven controls that carry the process
- Sizing and sequencing the engagement
- The scheme catalog: how T&E actually leaks
- The analytics goldmine: the full test catalog
- From analytics to testing: the three-layer approach
- The proportionality doctrine: findings without witch hunts
- Worked example: MidState Beverage’s travel and expense audit
- The findings that recur — and wording that lands
- Where to go next
Start with the policy: audit the design before the compliance
Most T&E audits test compliance with the policy and never test the policy — which is backwards, because in T&E the policy is the control system, and badly designed policies manufacture their own violations. Four design questions before any sampling:
- Where is the receipt threshold, and what does it teach? A $75 threshold tells every employee that $74 is invisible — and your amounts histogram will show exactly how well they learned it. The threshold is a cost-benefit choice, not a virtue; the design question is whether anything monitors the space below it (aggregate analytics), or whether below-threshold is genuinely unwatched.
- Per diems or actuals? Per diems eliminate receipt games and shrink the audit surface at the cost of over- or under-paying reality; actuals invite the games this article catalogs. Mixed regimes (per diem meals, actual lodging) are fine — undocumented regional inconsistency is not, and finding three different effective policies across divisions is a finding about governance, not travel.
- Is the corporate card mandated? Card-mandated programs give you a second, independent data stream (the card feed) to reconcile against expense claims — the single most powerful structural control in T&E, because cash claims are unverifiable stories while card transactions are records. A program that reimburses significant cash spend has chosen weaker evidence on purpose; say so.
- Do the rules fit how people actually travel? Policies written in 2015 meeting 2026 travel — rideshare, home-sharing, remote-work trips, blended personal-business travel — generate technical violations that train everyone to ignore the policy. High violation rates concentrated in a few rules usually indict the rule.
Deliverable from this section: a short policy-design assessment alongside the compliance results. It is frequently the most valuable page in the report, and it is the page that makes the compliance findings feel fair.
The policy-design assessment: a one-page template
The design assessment is short, sits in front of the compliance results, and is written so that a committee member who reads nothing else understands why the exceptions look the way they do. The template below is the one MidState’s report used; each numbered line is a sentence or two, and the whole page rarely runs past 300 words.
Travel and expense policy: design assessment. 1. Policies in force: the number of effective policies, the population each applies to, the date each was last reviewed and by whom. 2. Evidence standard: the receipt threshold by entity, the share of spend claimed in cash rather than on the corporate card, and whether anything monitors spend below the threshold. 3. Regime: per diems, actuals or mixed, by category and entity, and whether the differences are documented decisions or accidents of history. 4. Fit with actual travel: the three rules with the highest violation rates and whether each violation rate indicts the traveler or the rule. 5. Approval design: how approvers are assigned, which self-approval costumes the configuration blocks, and who reviews the executives. 6. Monitoring: what management sees monthly, and what happened the last time a metric moved. 7. Assessment: whether the policy as designed can be complied with by the people it governs, in one sentence, followed by the design changes recommended before any compliance remediation is asked of anyone.
Line 7 is the one that makes the compliance findings feel fair. When it says the policy cannot be complied with, the rest of the report is read as evidence for that sentence rather than as a list of people who broke rules, which is the reading a T&E report needs if it is going to change anything.
Approval integrity: the control that is usually theater
Every expense report is “approved.” The audit question is whether approval is a control or a click. Four tests cut to it. Self-approval and its costumes: direct self-approval is usually blocked by configuration — so test the costumes: delegate arrangements where the approver’s assistant (who reports to them) approves their reports; circular pairs who approve each other; approvals by subordinates of the submitter. Pull the approval graph and look at it as a graph. Approval velocity: timestamp analytics — the manager who approves 40 reports in three minutes at 11pm is acknowledging, not reviewing; measure median seconds-per-report by approver and rank them. Seniority inversion: who approves the executives? The CEO’s expenses approved by the CFO’s admin is a real pattern with a real name in the working papers. Executive T&E deserves the same explicit scoping decision as executive payroll: restricted visibility, never absent control. Escalation reality: when the system flags a violation, what happens? Sample flagged-then-approved items — if 96% of policy flags are approved through with no comment, the exception process is a speed bump, and that is the finding.
The starter RCM: seven controls that carry the process
The sibling guides in this series each open their testing with a starter risk and control matrix, and the August version of this one did not, partly because T&E has so few controls that the omission seemed harmless. It is not harmless: an audit that tests the policy and the approvals without a matrix tends to write findings about people, because people are what the data shows, whereas a matrix forces every exception back to the control that should have stopped it. The seven controls below carry the process in most organizations. Build them into the risk and control matrix template before fieldwork, mark which ones exist at your organization, and test the ones that exist; the ones that do not exist are design findings before a single claim is examined.
| Control | Type | What it prevents or detects | How to test it |
|---|---|---|---|
| One policy, owned, reviewed annually, applied to every entity and every grade including executives | Entity-level, preventive | Fragmented rules across divisions and acquisitions; executive carve-outs; rules that no longer fit how people travel | Obtain every policy version in force; map which population each applies to; compare thresholds and rules; confirm the annual review happened and who signed it |
| Corporate card mandated for travel spend, with the card feed loaded into the expense system | Preventive and detective | Unverifiable cash claims; duplicate reimbursement of card spend; fictitious claims supported by generated receipt images | Measure the cash share of spend by entity and grade; confirm the feed loads daily and that unmatched card transactions age out to a report someone reads |
| System-enforced rules: receipt thresholds, category limits, blocked merchant categories, mandatory fields, with flagged exceptions routed to the approver | Automated preventive | Out-of-policy claims that pass because nobody noticed; missing business purpose and attendee fields | Inspect the configuration; submit test claims in a non-production environment where possible; reconcile the flag log to the approval log |
| Approver assignment from the HR hierarchy, with self, subordinate, delegate-to-subordinate and circular approvals blocked | Preventive | Approval theater; the assistant approving the executive; two managers approving each other | Pull the approval graph for the year and test it as a graph; confirm the assignment rule is system-enforced rather than a policy sentence |
| Independent pre-payment review of flagged and high-scored reports by a reviewer who is not the approver | Detective, before payment | Approved exceptions reaching payment; receipt-image fraud; policy-washed gifts and entertainment | Sample 25 reviewed reports; confirm the reviewer saw the card record and the receipt, challenged the flags, and that rejections were actually reversed |
| Automated duplicate detection across card feed, cash claims and employees, with a hold on payment until cleared | Automated detective | Double reimbursement; the shared dinner claimed by both attendees; the rejected claim resubmitted | Re-perform the match on the year’s data with your own logic and compare the hit list to the system’s; the gap is the finding |
| Monthly monitoring analytics reported to management, with executive T&E reviewed by someone senior to or independent of the executives | Detective, entity-level | Serial grazing; approver velocity; executive exception rates with no reviewer | Obtain twelve months of the monitoring pack; test that a metric that moved produced an action; confirm who reviews the chief executive’s claims and whether they can say no |
Two of the seven decide the shape of the audit. If the card is mandated and the feed is loaded, most of the analytics catalog runs on records rather than stories and the audit is largely a data exercise. If it is not, the audit has a structural design finding on page one, and the cash population has to be tested with the receipt in one hand and the knowledge that receipt images are now the weakest evidence class you hold in the other.
Sizing and sequencing the engagement
A T&E audit is cheap by the standards of the disbursement series because the population is clean and digital, and expensive in one place that first-time planners miss: the joins. The expense lines, the card feed, the HR hierarchy, the absence calendar, the travel bookings and the approval log come from five systems in most organizations, and reconciling them into one table with a reliable employee key is where the first week goes. The hours below assume a mid-sized organization with a few hundred submitters, a card program, and an analytics-capable auditor on the team; they are a planning range, not a quote, and the sampling memo should record why the program landed where it did.
| Phase | What happens | Hours |
|---|---|---|
| Planning and policy-design review | Every policy version mapped to its population; thresholds compared; the design assessment drafted before any data is pulled | 30 |
| Data acquisition and joins | Five datasets extracted with completeness proofs; employee key reconciled; card feed matched to the expense system at the transaction level | 40 to 60 |
| Analytics run and triage | The full catalog run on the year; hits scored and grouped into the three populations before anyone reads a receipt | 50 to 80 |
| Approval graph and velocity | The approver network drawn, costumes of self-approval identified, seconds-per-report ranked | 20 |
| Layered testing | Layer one categorical sets in full; layer two receipt-and-purpose testing of the scored tail; layer three seeded random sample | 80 to 120 |
| Compliance-sensitive hits | Gifts, entertainment and government-adjacent items walked with legal or compliance under their protocols, not the audit’s | 20 |
| Reporting and the base rates | Findings written at program level with denominators; people-level items routed off-report; management conversations | 40 |
| Total | 280 to 370 |
Sequence matters more than in most audits. The policy review goes first because it changes how every later exception is read: a threshold-hugging pattern against a badly chosen threshold is a design finding, not a submitter finding. The analytics go before any manual testing because the categorical sets and the scored tail are what the manual testing is for. And the compliance-sensitive hits go to legal or compliance the day they are found, not at the end, because a gift to a customer’s buyer or a payment near a public official carries obligations that do not wait for the draft report; the first 48 hours protocol covers what changes the moment a hit stops being a policy exception and starts being a possible offense.
The scheme catalog: how T&E actually leaks
| Scheme | Mechanics | Primary detection |
|---|---|---|
| Duplicate reimbursement | Same spend claimed twice: card + cash claim, two months apart, or split across two employees at the same dinner | Card-feed reconciliation; cross-employee same-merchant-date-amount matching |
| Personal spend as business | Vacation-adjacent hotel nights, family meals, personal purchases on the corporate card coded as business | PTO-calendar overlap; weekend/holiday patterns; merchant category screens |
| Threshold games | Claims engineered below receipt or approval thresholds; one dinner split into two claims | Amounts histogram; same-day same-merchant splits |
| Mileage inflation | Personal-car mileage padded per trip — small, constant, and almost never checked | Claimed miles vs. mapped route distance for recurring trips |
| Fictitious expenses | Claims for spend that never happened, supported by altered or generated receipts | Receipt forensics on the scored tail; merchant validation; the modern wrinkle — AI-generated receipt images — makes independent card evidence more valuable than image inspection |
| Gift, entertainment, and policy-washing | Alcohol, gifts, or entertainment for government officials or clients coded as “meals — other” to dodge compliance limits | Keyword and merchant screens; this is where T&E crosses into anti-corruption exposure, and where a small claim can carry regulatory consequence far beyond its amount |
| Serial grazing | No single egregious claim — a persistent pattern of maximum-allowable everything, every trip | Per-employee spend-per-travel-day ranking against peer norms |
Note what the catalog implies: almost every scheme is invisible in a random sample of 25 reports and obvious in a full-population analytic. T&E is the process where the ACFE’s detection findings — tips at 43%, frauds running a median 12 months (2024 Report to the Nations) — should embarrass nobody, because the data to find these patterns in week one has been sitting in the expense system all along.
The analytics goldmine: the full test catalog
Run these across the full year’s population — expense lines, card feed, HR calendar, and approval log joined — before selecting a single report for manual review. Logic stated plainly enough to build in SQL or Excel:
| Analytic | Logic | What a hit means |
|---|---|---|
| Card-vs-claim duplicates | Corporate-card feed matched to cash claims on amount + merchant + ±days; exact then fuzzy | Double reimbursement — the highest-yield test in T&E |
| Cross-employee duplicates | Same merchant + date + amount across employees (the shared dinner claimed by both attendees) | Double reimbursement or copy-paste claims |
| Resubmission scan | Same employee, same amount + merchant, 30–120 days apart | The rejected-then-resubmitted or claim-it-twice pattern |
| Threshold hugging | Histogram of claim amounts; density spike just under receipt and approval thresholds, ranked by employee | Learned invisibility; split claims |
| PTO and calendar overlap | Expense dates joined to HR absence calendar and travel bookings | Vacation spend coded as business; ghost trips |
| Weekend and holiday spend | Non-travel-day weekend charges by category, netted for legitimate weekend travelers | Personal spend on the card |
| Keyword and merchant screens | Description and merchant text: gift, cash, gc, spa, golf, jewelry, tuition, government-adjacent entertainment terms; MCC codes for prohibited categories | Policy-washing; compliance exposure (route these hits to compliance protocols, not the routine findings pile) |
| Mileage vs. map | Recurring origin-destination pairs: claimed miles vs. routed distance | Systematic inflation — small per trip, meaningful per year |
| Round-amount concentration | Share of claims at round tens/hundreds by employee vs. population base rate | Estimated (unreceipted) claiming as habit |
| Spend-per-travel-day ranking | Total T&E normalized by travel days, ranked within role band | Serial grazing; also finds the legitimately misclassified road warrior |
| Approver velocity and flag pass-through | Median seconds per approval by approver; % of policy-flagged items approved unchanged | Approval theater — a control finding, not a person finding |
From analytics to testing: the three-layer approach
Structure selection exactly like journal-entry testing: layer one, 100% review of the categorical sets (all executive T&E, all compliance-keyword hits, every employee in the top decile of composite analytic score); layer two, manual receipt-and-business-purpose testing of the scored tail — verify against the card record first, the receipt image second, remembering that receipt images are now the weakest evidence class you hold; layer three, a small seeded random sample of ordinary reports (sizing per the sampling guide, selection via mySampler) so the program is not perfectly predictable and so you can say something statistical about the boring middle. Document dispositions hit-by-hit in the grid format of our model workpaper — in T&E more than anywhere, the file must show which hits were cleared and why, because the population is people, not invoices.
The proportionality doctrine: findings without witch hunts
T&E is the audit most likely to damage the function if reported badly, because every exception has a name attached and most names belong to careless people, not corrupt ones. The doctrine has four planks. Report programs, not people: findings describe control and policy failures with aggregate numbers; individual cases route to management or investigation channels, never to a distributed audit report. Separate the three populations your analytics will surface — sloppiness (duplicate submissions from bad memory, missing receipts), policy abuse (threshold games, serial grazing), and potential fraud (fictitious claims, forged receipts) — and treat them differently: the first is a training-and-design story, the second a management-action story, the third exits the audit into your fraud protocol (see the fraud risk guide) with chain-of-custody discipline from that moment. Mind the seniority asymmetry: the intern’s $40 duplicate and the SVP’s pattern of policy-flag overrides are not the same finding, and a report that hammers the first while soft-pedaling the second will — correctly — destroy the audit’s credibility; executive exceptions carry the tone-at-the-top weight and get reported with it. Give the base rate: “$61,000 of exceptions” alarms; “$61,000 of exceptions on $9.4M of spend — 0.65%, concentrated in 14 of 1,900 submitters” informs. Proportionality is not softness; it is precision about magnitude, which is what makes the severe findings believable when you have them.
Worked example: MidState Beverage’s travel and expense audit
MidState Beverage, the three-state drinks distributor used across this site, has about 1,400 employees, twelve depots, two acquired distributors integrated for revenue but not for controls, a 2013 ERP with a cloud expense system bolted on, and a six-person internal audit function with no compliance function beside it. Its drivers do not claim expenses; its 412 submitters are sales representatives, merchandisers, depot managers and head-office staff, and in the year audited they filed 21,400 expense lines worth 2.6 million dollars. The corporate card is mandated at head office and the ten legacy depots. The two acquired distributors, about 90 submitters between them, were still claiming cash against scanned paper receipts, because nobody had migrated their card program. The engagement ran in the sequence above and took 310 hours, most of the overrun in the joins, where the acquired distributors’ employees turned out to carry different identifiers in HR, the expense system and the card feed.
| Test or analytic | Population | What it found | Disposition |
|---|---|---|---|
| 1. Policy design | Every policy version in force | Three effective policies: a 75-dollar receipt threshold and actuals at legacy MidState; a 25-dollar threshold at one acquired distributor; no threshold and a meal per diem at the other. No annual review of any of them since 2022. | Finding, High: governance of the policy, not travel |
| 2. Card mandate and feed | Spend by entity and grade | Cash claims were 4 percent of legacy spend and 100 percent of the acquired distributors’ spend; the card feed loaded weekly rather than daily and unmatched transactions aged out to nobody. | Part of finding 1, including the feed cadence |
| 3. Approval graph | All 38 approvers, 21,400 lines | Six approvers handled 44 percent of volume at a median of six seconds per report; 94 percent of policy-flagged items approved without comment; two depot managers approved each other’s reports for fourteen months; the CFO’s reports were approved by the controller, who reports to the CFO. | Finding, High: the approval workflow operates as acknowledgment |
| 4. Executive T&E | All nine executives, in full | Flagged-item rate 2.1 times the company average with a 100 percent approval pass-through; no reviewer independent of the executive team for anyone but the chief executive, whose claims the audit committee chair reviews twice a year. | Reported inside finding 3 with the tone-at-the-top weight it carries |
| 5. Card-versus-claim and cross-employee duplicates | Card feed against cash claims; all lines across employees | 14,800 dollars claimed both on card and as cash reimbursement across 33 employees; 2,900 dollars of shared dinners claimed by both attendees in eleven pairs; six resubmissions of previously paid claims, 1,100 dollars. | Finding, Medium: no automated match; 88 percent recoverable |
| 6. Threshold hugging | Amounts histogram by submitter | Claims between 70 and 74.99 dollars at 2.7 times expected density, concentrated in seventeen submitters, nine of them in one sales region under one of the six-second approvers. | Design and training item inside finding 1; region routed to sales management |
| 7. Calendar overlap | Expense dates against the absence calendar and bookings | 61 lines on leave days, 6,200 dollars; forty explained by travel bookended by leave; 21 lines, 2,400 dollars, were personal spend on the card. | Finding, Low; recoveries handled by management |
| 8. Keyword and merchant screens | Descriptions, merchants and category codes | 23 hits, fourteen of them gifts to retail customers’ store managers coded as other meals, 3,100 dollars, against a gifts rule that was a single sentence in the policy. | Walked with outside counsel under their protocol; finding, Medium, on the absence of a gifts and entertainment policy |
| 9. Mileage against mapped routes | 24 recurring origin-destination pairs | Claimed miles averaged 18 percent above routed distance; five merchandisers accounted for most of it, about 4,700 dollars a year. | Finding, Medium; mileage moved to app-captured routes |
| 10. Spend per travel day | Total spend normalized by travel days, ranked within role band | Two sales representatives at three times the peer median: one with a territory spanning two states and a legitimate explanation; one with maximum-allowable everything on every trip. | Management action for the second; no finding |
| 11. Receipt forensics on the scored tail | Top decile by composite score, cash claims first | Three receipts from one cash-claiming submitter at an acquired distributor with identical fonts and totals that did not foot, 1,900 dollars; the merchant confirmed no such transactions. | Referred under the protocol on day nine; substantiated as generated images; kept out of the report |
| 12. Monitoring | Twelve months of management reporting | No monitoring pack existed; the analytics above had never been run by anyone. | Finding, Low, with the monthly pack as the remediation |
The report carried seven findings, two High, three Medium and two Low, an overall rating of Needs Improvement, and one referral handled outside it. The base rate went on the first page: 30,900 dollars of quantified exceptions on 2.6 million dollars of spend, 1.2 percent, with 60 percent of the amount attributable to nineteen submitters. That sentence is what made the two High findings land, because it told the audit committee at once that the money was small and the control failures were not. Three things about the engagement are worth carrying to your own. The most expensive finding was the one with no dollars attached: three policies and no card program at the acquired distributors were the reason most of the other exceptions existed, and the fix, one policy and one card program, cost less than the audit. The fraud, the only one in the engagement, was small, sat in the cash population the card mandate had never reached, and was found by the forensic work the guide describes rather than by any control; the expense reimbursement branch of the fraud tree predicts exactly that. And the approval finding was written about six seconds and 94 percent, not about the six approvers, whose names went to their managers through the channel the issue log tracks and never into a distributed document.
The findings that recur — and wording that lands
Four findings cover most T&E reports. Duplicate-detection gap (“card-feed reconciliation identified $38,200 claimed both on card and as cash reimbursement across 61 employees over the year; no automated match exists between the card feed and the expense system — 0.4% of spend, 92% of it recoverable”). Approval theater (“the 11 approvers handling 40% of report volume show median review times under 8 seconds; 96% of policy-flagged items were approved without comment — the approval workflow operates as acknowledgment”). Threshold clustering (“claims between $70 and $74.99 occur at 3.1× the expected density against the $75 receipt threshold, concentrated in 23 submitters — the threshold functions as a target”). Executive exception rate (“flagged-item rates for the executive population run 2.4× the company average with a 100% approval pass-through — reported here as the tone indicator it is”). Each is a program-level statement built on the 5 C’s chain, with the people-level follow-ups routed off-report.
Where to go next
Audit T&E for what it is: a low-dollar process wired directly into the organization’s integrity signal. Review the policy design before prosecuting compliance with it, build the seven-control matrix so that every exception has a control to point at, test the approvers harder than the submitters, run the full analytics catalog before touching a single receipt, and hold the proportionality line: programs in the report, people through the right channels, base rates on every number. Done that way, as MidState’s engagement was, the T&E audit produces the thing committees quietly value most, an honest reading of everyday integrity with the data to back it, and it does so in three hundred hours.
The series continues across the disbursement universe with accounts payable, payroll and journal entries, and into the buying side with procurement and the vendor master file. The reporting craft that carries the results lives in the findings masterclass and the model report library.
Related guides
- How to audit accounts payable — the first guide in the series, with MidState’s AP run and a 14-test program
- How to audit payroll — the sister process, with MidState’s payroll engagement test by test
- How to audit journal entries — the three-layer selection method this guide borrows
- How to audit procurement — where gifts and entertainment hits usually lead
- Procure-to-pay analytics for collusion — the multi-table joins the T&E joins are modeled on
- The risk and control matrix template — where the seven-control starter matrix lives
- How to run a fraud risk assessment — where expense reimbursement sits in the scheme catalog, beside MidState’s 41-scenario register
- The ACFE fraud tree explained — the expense reimbursement branch, with its controls and analytics
- When internal audit finds fraud: the first 48 hours — the protocol the generated-receipt referral followed
- The fraud red flags library — the expense cycle’s indicators, organized for triage
- Audit sample sizes demystified — sizing the seeded random sample in layer three
- The sampling memo template — documenting why the program landed where it did
- Annotated workpaper examples — the disposition grid the hits are recorded in
- Segregation of duties beyond the ERP — the approval-assignment rule as a segregation control
- The 5 C’s of audit findings — how the seven findings were written
- Internal audit report examples — the model report the base rate sentence comes from
- The finding and issue log template — tracking people-level follow-ups off-report
- Fieldwork and testing guides, data analytics guides and fraud risk guides — the full collections
Leave a Reply