This topic is about risk, not reporting. Policies catch rule violations. Behavior reveals fraud.
The problem
Companies process millions in employee expenses every year. Most audits still sample only 1–5% of claims.
Policy engines catch what they are built to catch: over-limit meals, missing receipts, weekend travel flags. Those are rule violations. The highest-risk transactions often look fine in isolation— until you look at how someone spends over time, against peers, and across systems.
Expense reports
Sampled claims. Policy checks. Receipts attached. Approvals complete. The report looks clean.
Expense behavior
Patterns across claims, cards, peers, vendors, and timing. The story only appears when you watch the person—not the single form.
Where money actually leaks
These patterns rarely trip a single policy gate. Together, they drive real leakage and fraud exposure.
-
01
Duplicate reimbursements — the same spend claimed more than once, or reimbursed after a card payment.
-
02
Split claims — one purchase broken into smaller reports to stay under approval limits.
-
03
Weekend spending — travel and entertainment that doesn’t align with business calendars.
-
04
Personal expenses — retail, family travel, or lifestyle spend coded as business.
-
05
Excessive mileage — distances and trips that don’t match itineraries or peer norms.
-
06
Hotel rate anomalies — rates far above market, role, or booking channel for the same city.
-
07
Meals exceeding peer averages — consistent outliers vs role, grade, and cost centre.
-
08
Claims after employee termination — spend or reimbursements that continue past exit dates.
-
09
Round-dollar patterns — repeated even amounts that suggest fabricated or padded claims.
-
10
Frequent small claims below approval limits — high volume under the radar of managers and policy caps.
Why rules fail
- Misuse adapts Once a limit or keyword is known, spend is reshaped to stay just inside the rule.
- Rules generate false positives Legitimate travel trips the same flags as misuse—so reviewers stop trusting the queue.
- Auditors cannot review every receipt Sampling and annual cycles leave most behavior unobserved between reviews.
How AI changes the approach
Instead of asking only “Does this violate policy?”, AI asks whether the behavior is unusual.
Does this violate policy?
Binary checks against limits, categories, and mandatory fields. Useful—but incomplete.
Is this risky?
Peer comparison, change detection, vendor and timing signals, and resemblance to known abuse patterns.
- Is this employee different from peers? Role, grade, and cost-centre baselines expose outliers.
- Is spending behavior changing? Sudden jumps vs the person’s own history matter more than one receipt.
- Is this vendor unusual? New or rare merchants for that role raise the priority of review.
- Is timing suspicious? Weekends, post-termination windows, and clustered submissions are signals.
- Does the pattern resemble previous fraud? Split claims, double-dips, and round-dollar runs look familiar once you’ve seen them.
Real examples
Illustrative cases based on common T&E risk patterns. Savings estimates reflect avoided leakage when behavior monitoring replaces sample-only review.
Duplicate reimbursement after card payment
An employee’s corporate card cleared a hotel stay; the same invoice was later reimbursed as out-of-pocket. Policy saw two “clean” transactions. Behavior matched card feed to claim.
Estimated impact: $8K–$25K / year in a mid-size sales org
Split meals under the approval limit
Client dinners were filed as three claims under $75 on consecutive days. No single claim breached policy. Pattern analytics flagged the cluster under one merchant and approver.
Estimated impact: $15K–$40K / year across high-travel teams
Mileage far above peer norms
A field role claimed 35% more monthly miles than peers with the same territory. Individual trips looked plausible. Peer baselines made the outlier obvious.
Estimated impact: $12K–$30K / year for a regional field force
Claims after termination
Card and reimbursement activity continued for two weeks after exit. HR and T&E systems weren’t joined in the audit sample. Continuous monitoring caught the window.
Estimated impact: $5K–$50K per incident, depending on access and role
Frequent sub-limit claims
Dozens of round-dollar “office supplies” claims stayed under manager review thresholds. Volume and vendor mix looked nothing like peers in the same cost centre.
Estimated impact: $20K–$60K / year in a large shared-services population
Continuous monitoring of expense behavior beats annual audits of expense reports. Policy still matters—but risk lives in the pattern.
How foretale.ai helps
foretale.ai turns expense and related data into behavior-led risk analytics— peer baselines, change detection, vendor and timing signals, and known abuse patterns— with explainable evidence for every finding.
Your experts review the highest-risk behavior first, instead of sampling reports and hoping the sample is lucky.
See it in action
See how Foretale monitors expense behavior—not just expense reports.
Request a demo