Skills / Audit and assurance

Expense and T&E policy testing

What it does

Tests an expense, T&E, or corporate card population against the client's own written policy across fourteen exception types, and organises the result by person and by approver before it organises anything by transaction.

Expense testing is worth doing because the findings are behavioural rather than random. One person submits the same receipt twice. One manager approves everything without looking. One department has discovered that two transactions of $2,400 avoid the approval that one of $4,800 would trigger. The output follows the order in which anything actually gets fixed — an approver whose exception rate is far above peers is approving without reading, and that explains the other findings.

It is also the area where the client's own policy is the standard. There is no external threshold to apply: if the policy says receipts are required above a stated amount, that is the test. Which makes the first question whether a written policy exists at all.

What it proves

Four conditions before a clean workpaper:

  • The population ties to the GL — you supply the expense total for the accounts in scope. A filtered card extract proves nothing about the expense line.
  • Every transaction receives a disposition — compliant, or a named exception. Compliant plus exceptions must equal the population in count and in value.
  • The policy rules are stated, not assumed — approval thresholds, receipt thresholds, prohibited categories, and per-diem limits come from the written policy and are recorded on the workpaper.
  • No transaction is tested twice under a rule that would double-count its value.

If there is no written policy, that is the headline finding. It runs at zero thresholds, says explicitly that it did, and reports the absence as a control matter — an expense programme with no written policy has no standard to test against and no basis for discipline.

Split transactions engineered to stay under an approval threshold are detected as a pattern, not as individual items.

What you get

Six tabs:

  1. Summary — population proof, policy rules applied, exception counts and values by type, concentration, recovery opportunity, and control observations.
  2. Population Proof — compliant plus exceptions equals the population, in count and value, plus the tie to the GL.
  3. By Employee and By Approver — the rollups that make the behaviour visible.
  4. Exception Detail — every exception with the transaction, the rule breached, the policy reference, and columns for investigation and disposition.
  5. Splits and Duplicates — grouped, with the pattern that caught each and the amount at risk.
  6. Compliant Detail — for re-performance.

Where it stops

An expense finding lands on an individual rather than on a process, so the language matters more here than almost anywhere else in an engagement. It describes what the record shows, quantifies it, and stops.

Repeated split transactions by the same person, an approver with a very high exception rate or one approving their own claims, claims submitted after a termination date, the same receipt claimed by two employees, a reimbursement paid to a bank account matching an AP vendor, unreconciled cash advances, personal spend patterns on a corporate card: each is stated as a fact with amounts and references. Intent is not characterised — management and HR handle it through their own process.