Expense Policy Best Practices
Clear rules on spending limits and documentation stop fraud before it starts.
An expense policy is a tax document dressed up in business-casual clothes. Most companies write it like an HR formality, then act shocked when the IRS treats it like the legal backbone it actually is. Reimbursements only stay tax-free for employees, and deductible for the business, if the policy meets the IRS's "accountable plan" rules: every expense needs an amount, a date, a place, and a business reason attached to it. IRS Publication 463 calls this "adequate accounting," which is really just a formal way of saying your receipts aren't paperwork you shove in a drawer, they're part of your tax position. Miss the 60-day submission window and that reimbursement can get reclassified as taxable income, hit with withholding and FICA, all because someone just wanted their $40 lunch back.
Zoom out and the numbers get bigger fast. Global business travel spending hit $1.48 trillion in 2024, according to the GBTA's 2025 Business Travel Index Outlook, so even a small slice of that moving through a sloppy policy adds up. Fraud isn't rare, either. The ACFE's 2024 Report to the Nations looked at nearly 2,000 cases worldwide and found expense reimbursement fraud in 13% of them, running an average of 18 months before anyone noticed, with a median loss of $50,000 per case, up $10,000 from the 2022 report. Weak internal controls showed up in close to a third of all occupational fraud in that same study. A good policy protects the company and the person filing the report, since clear rules beat guesswork for both sides.

What a complete expense policy actually contains
Most policies fail for the same three reasons: fuzzy spending limits, no real documentation standard, and an approval chain that falls apart the second headcount crosses 50.
A policy that holds up has six parts. Purpose and scope, so everyone knows who's covered (yes, contractors too, don't leave them guessing). Eligible and non-reimbursable categories, spelled out with real examples instead of some vague line about "business necessity." Spending limits with actual dollar figures attached, documentation standards that say plainly what counts as proof, and approval workflows tiered by amount and type. Then there's a reimbursement timeline written in business days, one finance is actually held to.
Drop any one of those and the failure is predictable, since no spending limits means every purchase turns into a negotiation, and no documentation standard means audits become archaeology. Scope gaps are especially common, since contractors, part-timers, and executives tend to fall into gray zones nobody bothered naming. Length matters more than people assume, too, because a policy nobody reads might as well not exist. The ones people actually read are short, sorted into categories employees recognize (travel, meals, software), and written like a person wrote them, not a law firm.
Setting spending limits that are defensible and used
"Reasonable and necessary" isn't a spending limit. It's an open invitation for every manager to make a different call on the same purchase, and that's exactly how fairness falls apart. Without actual numbers in a policy, the same purchase can get approved by one manager and rejected by another, and that inconsistency is exactly what happens once you strip out actual numbers.
So borrow numbers that already exist. The GSA's FY2026 standard CONUS rates (effective October 1, 2025) set lodging at $178 a night and meals and incidentals at $68 a day. The IRS's Notice 2025-54 high-low per diem method goes further: $319 a day for high-cost localities ($233 lodging, $86 M&IE) and $225 a day everywhere else in the continental U.S. High-cost cities like San Francisco, New York, Boston, and Washington D.C. carry seasonal lodging rates from $258 to $419 a night, so a flat national cap just falls apart the moment someone books a hotel in those markets. Mileage gets its own update, too, with the IRS standard mileage rate revised periodically, so confirm the current rate directly with IRS guidance before setting your policy number.
International travel runs on the same logic, different table. The State Department publishes monthly per diem rates by city, and London comes in at $476 a day combined as of the January 2026 tables. Point your policy at those tables instead of inventing one flat international number that'll be wrong somewhere by March.
Building private-sector defaults from nothing? A reasonable starting point: economy class for anything under six hours in the air, a daily meal per diem in the mid-double-digits in standard markets, hotel caps near $150 a night outside the named high-cost cities. GSA rates move every year and IRS mileage moves too, so put a review date on the calendar and actually keep it. Numbers frozen in place get unfair and non-compliant at the same time, and there's no version of that combination that ends well.

Documentation standards that create a real audit trail
The IRS sets minimum documentation thresholds for business expenses, but most practitioners set the bar higher: require a receipt for everything, every time, yes, even the $6 coffee. Small purchases quietly pile up into real money when nobody's tracking them, and a blanket rule takes the guesswork off the approver entirely.
A receipt that actually counts shows the vendor name, the date, the amount, and an itemized breakdown, not just one lump credit card total. That last part trips people up constantly, because a card statement is not a receipt, no matter how official it looks.
Then there's the newer headache: AI-generated receipts. Software now exists that fakes the layout, fonts, and formatting of a real receipt well enough to slide past a tired human glance, and most companies still lean on manual review or basic OCR, neither of which was built to catch a fake that convincing. Name the acceptable formats in the policy, and say plainly that software-level verification is part of the review process, not some just-in-case backstop nobody actually runs.
Submission mechanics matter more than people give them credit for, too. Name the acceptable channels (email, a mobile photo, an upload into whatever expense platform you're on) and attach a real deadline. Research consistently finds that most rejected expense claims come down to vagueness or missing information, not fraud. Blame lands on the policy here, not the people, since it never told anyone what "complete" actually looks like.
Approval workflows that scale without creating bottlenecks
Good workflows control spending at three separate moments, not one. Before the money moves: pre-approval above a set threshold, commonly in the few-hundred-dollar range, so a manager signs off before the employee commits company cash. During the spend: corporate or virtual cards with limits and category controls built in, instead of hoping a post-hoc review catches whatever slips through. After the spend: submission channels with no friction, so people file as they go rather than dumping three months of receipts on finance the week before quarter close.
Tiering keeps every expense from landing on the same overworked desk. Routine items under the threshold get manager approval and move on, while bigger single-ticket items, airfare, conference passes, equipment, go to a department head or finance for pre-approval. Exceptions get a named escalation path, not a scattered email thread six people reply-all to until it dies quietly.
Industry practitioners commonly cite significant error rates in expense reports. A tiered structure catches those errors at the right level instead of routing everything, mistakes included, straight to an overloaded finance desk. Approvers who don't actually understand the rules they're enforcing undercut all of this structure, since an untrained approver is the weakest link in the chain, especially on judgment calls like client meals or entertainment spend. Overrides deserve real scrutiny too: the ACFE's 2024 report found control overrides showing up in roughly one in five occupational fraud cases. The fix isn't banning overrides outright, it's making every single one visible and logged, not something that happens quietly and gets forgotten by Friday.
Reimbursement timelines and why slow payment is itself a risk
Slow reimbursement isn't just annoying, it's a measurable risk. Slow approval cycles are a documented problem, with a meaningful share of expense claims taking 30 days or more to get approved, a lag that doesn't just frustrate employees but wrecks cash flow forecasting on the company's side too.
The human cost runs worse than mild inconvenience. A YouGov survey run for Emburse, covering over 1,000 workers, found 40% had racked up overdraft or late fees on business expenses charged to personal cards, and 19% paid credit card interest directly because reimbursement showed up late, according to the Emburse/YouGov survey. Here's the part that should worry finance leaders more than any of that: 24% of employees admitted to expensing personal items as business expenses, and another 15% said they'd thought about it, with financial strain from delayed reimbursement named as a driver. Slow payment doesn't just cost goodwill, it nudges honest people toward shortcuts they wouldn't otherwise take.
Finance best practices point to a short, clearly defined window from submission to payment as the target worth hitting. Payment method matters here, too: companies moving off paper checks toward direct deposit cut out a manual step slowing the whole cycle down for no real reason. Whatever number you land on, write it into the policy in business days, because "promptly" isn't a commitment, it's a shrug. And put the IRS's 60-day submission limit in plain language right there in the document, so nobody finds out about the tax consequences after it's too late to do anything about them.

Fraud patterns a policy must be designed to catch
Expense fraud cost businesses over $3 billion in 2024, and it doesn't land evenly across company size. The ACFE's 2024 Report to the Nations found 20% of small businesses (under 100 employees) hit by expense fraud, against 12% of larger companies, a gap that tracks pretty closely with thinner controls and smaller finance teams.
The patterns repeat often enough that a well-built policy can be built around them directly. Duplicate submissions: the same receipt filed twice, sometimes across different reporting periods, betting nobody cross-checks. Split transactions: a purchase broken into smaller pieces specifically to duck under an approval or receipt threshold. Round-number clustering: repeated claims at suspiciously clean amounts, which usually means someone's estimating instead of reporting what actually happened. Personal expenses quietly reclassified as business ones, which the Emburse data suggests gets rationalized more often than it gets planned, meaning a clearer policy genuinely shrinks the temptation rather than just punishing it after the fact. And now, AI-generated receipts, which need a direct answer in the policy text: name the acceptable formats, and say plainly that automated verification is part of the process.
Scale tells the real story here. In November 2024, a Macy's employee was found to have hidden over $150 million in falsified expenses across roughly three years. An Amazon employee pulled in over $350,000 in fraudulent meal expenses tied to a virtual event where, notably, no meals were involved at all. Reviewing every report by hand won't catch that kind of scheme, which is exactly why risk-based sampling makes more sense: audit a random 10 to 20% of reports monthly, checked against the patterns above. Give people a real, named channel to flag something that looks off, since practitioners recommend this constantly, and the policy should point to it by name, not bury it in a footnote nobody reads.
Keeping the policy current and actually enforced
Policies rarely die at launch. They die slowly, at the revision stage, or more precisely, at the revision stage that never happens, since GSA rates update every year, IRS mileage rates move, and travel patterns shift right along with them. A policy stuck on last year's numbers manages to become non-compliant and unfair in the same breath.
Set real triggers for review. An annual pass tied to the GSA and IRS rate cycles (GSA's fiscal year starts October 1) covers the routine update. Add triggered reviews for anything bigger: a new office opening, a hiring surge, new expense categories like remote work stipends or AI tool subscriptions, or a sudden spike in rejected claims and audit flags.
Distribution counts as enforcement too, and it's the part companies skip most. An employee who never read the policy isn't committing fraud, they're just uninformed, and that one's fixable: onboarding coverage, an annual acknowledgment, a searchable digital copy that isn't buried nine folders deep on the intranet. The Expense Management Trends Report 2025 found 87% of CFOs putting money into expense automation specifically to improve accuracy and compliance, since software can stop a bad claim the moment someone tries to submit it, rather than waiting for an approver to catch it three weeks later.
A policy that's actually working shows up in the numbers: rejected claim rates, late submission rates, audit exceptions, tracked over time instead of eyeballed once a year around budget season. Capture Expense's 2025 report found 70% of finance teams naming real-time expense visibility their top priority. The policy sets the rules, while the platform is what lets anyone check, in real time, whether those rules are actually holding.