Expense Approval Process: How to Design a Chain That Scales
- What is an expense approval process, and what is it supposed to catch?
- What checks should an approver perform before approving an expense claim?
- How should you set approval thresholds and escalation rules?
- How do you move approvals out of email without slowing the team down?
- Enforce your expense policy where the spend happens, with Corpay
An expense approval process is the sequence of reviews an employee expense claim passes through before it's paid, with each step checking something specific and each approver holding defined authority. Almost every finance team has one. Far fewer have one that catches what it was built to catch.
The common failure is approvals that live in email, stall on unresponsive approvers, and check the wrong things, rather than an absence of approvals altogether. That combination produces a process that feels slow to employees while still missing the spend it exists to stop. Both symptoms come from the same root, which is a chain that was never designed, only accumulated.
Key Takeaways
Four roles cover most approval chains, and the value comes from each one checking something different rather than each one looking at everything.
The federal substantiation floor requires documentary evidence for lodging and above a set dollar amount, and internal thresholds are usually set lower for control reasons.
Every approval level adds control and adds days, so a third level has to earn its cost against a specific risk.
Expense reimbursement schemes run about a year before detection, which says more about review quality than about review frequency.
Multi-entity teams need entity-level queues and routing rules, not a single chain with more people in it.
Approval and card controls are complementary layers, and tightening the card side reduces how much needs approving at all.
What is an expense approval process, and what is it supposed to catch?
An expense approval process is the defined sequence of reviews an employee expense report passes through between submission and payment, with named approvers, authority thresholds, and a recorded decision at each step. It exists to catch three specific things.
Policy violations, where the spend happened but breaks a rule about amount, category, or circumstance. Coding errors, where the spend is legitimate but charged to the wrong account, cost center, or project. And unauthorized spend, where the purchase should never have been made at all. Those are different failures requiring different checks, which is why a single approver asked to catch all three catches none of them reliably.
This is employee-expense approval specifically, and it's a different discipline from approving a supplier invoice. The invoice approval workflow tests an invoice against a purchase order and a receipt, with the supplier as the counterparty. Expense approval tests a claim against a policy, with your own employee as the counterparty, which changes both the checks and the conversation when something is wrong.
Who owns each step, and what does each role actually do?
Four roles cover most chains. The point of separating them is that each one checks something the others can't.
Role | What they check | What they can't reasonably check |
Submitter | That the claim is complete, coded, and has receipts attached | Whether the coding matches how finance defines the account |
Manager | That the spend happened, was necessary, and belongs to their budget | Policy edge cases and tax substantiation rules |
Finance reviewer | Policy compliance, coding accuracy, receipt adequacy, and duplicates | Whether the business purpose was genuine |
Final approver | That total spend is within delegated authority for the amount | Line-level detail, at any realistic volume |
A chain where two roles perform the same check is a chain with a redundant step.
The manager's check is the one that can't be delegated to a rule and the one most often treated as a rubber stamp. Only the manager knows whether the client dinner happened and whether it was worth having. A finance reviewer can verify that a $340 restaurant charge has a receipt, attendees, and a valid account code, and has no way to know whether the meeting was real.
How is this different from approving a supplier invoice?
Expense approval tests policy compliance and receipt substantiation; invoice approval tests a three-way match between the invoice, the purchase order, and the goods receipt. Same discipline, different object and different evidence.
The practical consequence is that the two shouldn't share a workflow even where they share a tool. An invoice queue optimized for matching exceptions will handle expense claims badly, and an expense queue optimized for policy checking has no concept of a purchase order. The evidence each one produces also gets tested differently, as the accounts payable audit walkthrough shows.
What checks should an approver perform before approving an expense claim?
Work down eight checks, in this order, which takes under a minute per report once it's habitual.
Confirm the expense date falls in a period the employee was actually working and traveling.
Confirm a receipt is attached wherever policy or tax rules require one.
Confirm the business purpose is specific enough to mean something, with attendees named for meals and entertainment.
Confirm the amount is within the policy limit for that category.
Confirm the GL account and cost center match the nature of the expense.
Check for duplicates against recent claims from the same employee.
Check whether the same expense may have been charged to a company card and also claimed as reimbursement.
Confirm the total is within your own delegated approval authority before signing.
Check seven is the one that catches real money and almost nobody performs. An employee who pays for a hotel on a corporate card and then submits the folio as a reimbursement claim gets paid twice, and neither the card reconciliation nor the expense review sees the other half. The mechanics of catching this class of error are covered in duplicate payment.
Which receipts are actually required?
Federal tax regulation requires documentary evidence for any lodging expenditure while traveling away from home, and for any other expenditure of $75 or more, under 26 CFR 1.274-5. That's the floor rather than the target.
Most companies set a lower internal threshold, and the tradeoff is worth thinking about rather than inheriting. A lower threshold catches more and costs more, since chasing a $20 receipt consumes the same administrative effort as chasing a $200 one. A threshold at the federal floor is defensible and leaves a band of small spend unsubstantiated, which is a reasonable risk decision as long as it's a decision.
Retention is a separate question with its own answer. The IRS instructs businesses to keep records for three years in the general case, six years where unreported income exceeds 25% of gross income shown on the return, and indefinitely where no return was filed.
What are the most common red flags in a submitted report?
Four patterns account for most of what a careful reviewer finds. Round-number claims where the amount ends in zeros too often to be genuine. Weekend or holiday dates on expenses claimed as business travel. Transactions split just under an approval or receipt threshold. And personal spend coded to a plausible business category, which is the hardest to spot and the most common.
Duration is the argument for taking these seriously. The ACFE's Occupational Fraud 2024: A Report to the Nations found expense reimbursement fraud runs an average of 12 months before detection, with organizations losing an estimated 5% of revenue to occupational fraud annually. That study analyzed 1,921 cases across 138 countries with total losses exceeding $3.1 billion and an average loss above $1.5 million per case. A scheme running twelve months isn't evading review, it's passing review, which is a comment on what the review is checking.
Broader payment-side exposure sits alongside this. AFP's 2026 Payments Fraud and Control Survey Report found 76% of US organizations experienced attempted or actual payments fraud in 2025, with paper checks the most-targeted method at 58% against 30% for ACH debits and 25% for wire transfers. The FBI's Internet Crime Complaint Center has recorded $55.5 billion in exposed business email compromise losses across 305,033 incidents reported over roughly a decade through December 2023, which is the external version of the same authorization problem.
How should you set approval thresholds and escalation rules?
Build tiers on dollar amount, then add category exceptions where the risk profile differs from the amount. A worked model is more useful than a principle.
Claim total | Approval required | Typical turnaround |
Under $250 | Manager only | Same day |
$250 to $2,500 | Manager plus finance review | One to two days |
$2,500 to $10,000 | Manager, finance, and department head | Two to four days |
Over $10,000 | Adds CFO or delegated executive | Three to five days |
Adjust the dollar bands to your own spend distribution; the structure matters more than the numbers.
Category exceptions override the tiers in both directions. Client entertainment usually warrants finance review at any amount because the substantiation requirements are strict. Software and subscription purchases often warrant an extra approver regardless of amount because they create recurring commitments rather than one-time costs. Routine travel below the standard per diem can often skip finance review entirely, which is where most of the time savings live.
Escalation is the rule everyone forgets. Every approver needs a named delegate and an automatic escalation after a defined period, usually three business days. Without it, a single approver on leave during close holds the whole queue, and the practical workaround people invent is worse than the rule they're bypassing.
How many approval levels are too many?
Two levels is the defensible default for most mid-market organizations, and a third has to earn its place against a specific risk rather than a general sense of prudence.
The arithmetic is unforgiving. Each level adds roughly a day of turnaround at realistic response rates, and each level adds a person whose attention is divided across their actual job. Adding a third approver to a $400 claim doesn't triple the scrutiny; it usually means three people glance at it instead of one person reading it. Where a third level does earn its cost is above a threshold high enough that the reviewer treats it as an event rather than as routine. Tightening card controls on the front end reduces how much needs any of this, which is why card controls and spend policies and approval design should be planned together rather than sequentially.
How do multi-entity and shared-services teams route approvals?
Through entity-level queues with routing rules per subsidiary, rather than through one chain with more people in it. Each entity needs its own approval matrix, its own thresholds where local requirements differ, and its own queue so approvers see only what's theirs.
Shared services adds a wrinkle that catches teams out. The finance reviewer often sits in a central team while the manager approver sits in the entity, which means the chain crosses an organizational boundary and needs someone accountable for throughput on both sides. The practical failure is a central queue where entity-specific policy differences get applied inconsistently because the reviewer is working across six policies. Separate queues per entity, even where the same person works them, keep the context attached to the work. The general framing sits in what spend management covers.
How do you move approvals out of email without slowing the team down?
Configure the routing and the policy limits first, leave everything else manual for a month, then tighten. The teams that struggle with this migration are the ones that configure every rule before launch and spend the first month fixing rules nobody tested against real claims.
Two starting states are common and they migrate differently. Teams still building reports in spreadsheets need the submission side solved before the approval side is worth automating, since there's nothing to route until the claim exists in a system. Teams on a legacy travel and expense tool usually have the submission side working and the routing configured badly, which is a reconfiguration rather than a migration. Where a tool like Concur is already in place, the submission workflow is generally fine and the question is whether the approval matrix inside it reflects your current org chart, which for most companies it stopped doing several reorganizations ago.
Proving the new process to an auditor is the step to plan for up front. You'll need the approval record, the policy in force at the time, the delegation schedule, and evidence that exceptions were reviewed. That's easy to produce from a workflow system and close to impossible from a mailbox, which is the strongest single argument for the move.
What breaks when expense reports live in spreadsheets?
Four things, in increasing order of seriousness. Version conflicts, where nobody is certain which file is current. No audit trail, since an email approval can be edited, forwarded, or lost. No enforcement, because a spreadsheet will happily accept a claim that breaks every policy you have. And no link between the approval and the payment, which means nothing stops an approved report from being paid twice or an unapproved one from being paid at all.
The last one is the one that matters and the one nobody notices until an audit. The wider process picture is in expense management, and the case for the systems layer in how finance can use technology to have greater control.
How long should approval take once the process is right?
Two to four business days from submission to final approval is a reasonable target for a two-level chain, with same-day approval for low-value claims under a manager-only tier. Anything consistently over a week usually indicates an escalation rule that doesn't exist rather than approvers who are slow.
What drives the number is response latency rather than review time. The actual reviewing takes a minute or two per report; the waiting takes days. That's why delegates and automatic escalation move cycle time more than any other single change. Finance leadership is broadly aligned on removing this kind of work: Deloitte's Q4 2025 CFO Signals Survey found 50% of large-company CFOs naming digital transformation of finance their top 2026 priority and 49% naming process automation that frees employees for higher-value work as their top finance talent priority, with 87% expecting AI to be extremely or very important to finance operations in 2026.
How does approval connect to payment and reconciliation?
An approved report becomes a payment instruction, the payment clears, and the transaction matches back against the ledger. Every one of those handoffs is a place the chain can break, and the most common break is an approved report that gets paid without the approval record traveling with it.
Out-of-pocket claims flow into reimbursement, which is covered in employee expense reimbursement. Card spend flows into corporate card reconciliation instead, which is a different closing activity and one reason mixed programs are harder to run than either pure model. The broader automation pattern is in the four most critical AP automation workflows, and the preventive side in locking down spend before it slips. What an expense report contains in the first place is covered in expense reports.
Enforce your expense policy where the spend happens, with Corpay
The approval chain is a detective control, and every claim it reviews is spend that already happened. Moving part of the enforcement to the moment of purchase is the only change that reduces both review volume and out-of-policy spend at the same time.
Corpay runs corporate cards, expense management, and AP on one platform, with card-level limits and merchant category rules preventing non-compliant spend before it occurs and approval routing handling what's left. Coded, approved transactions flow into your accounting system through 100+ ERP integrations including NetSuite, Sage Intacct, Business Central, and Acumatica, so the approval record and the ledger entry stay connected. Most programs are live in weeks.
See expense management for the approval and card workflow together.
Frequently Asked Questions
What is expense approval?
Expense approval is the review an employee expense claim passes through before payment, where a manager and usually a finance reviewer confirm the spend was legitimate, within policy, properly documented, and correctly coded. Each approver holds a defined authority limit for the amounts they can approve.
What are the steps in the expense approval process?
An employee submits a coded claim with receipts, their manager confirms the spend was necessary and belongs to their budget, finance reviews policy compliance and coding, and a final approver signs where the amount exceeds the manager's authority. The approved claim then flows to payment.
How long does an expense report take to process?
Two to four business days from submission to final approval is a reasonable target for a two-level chain, with same-day turnaround on low-value claims. Cycle times over a week usually reflect missing escalation rules rather than slow reviewers.
What is an expense report?
An expense report is an employee's itemized claim for work-related costs they incurred, listing each expense with its date, amount, business purpose, account coding, and supporting receipt. It's the document the approval chain reviews.
How do you create an expense report?
Gather the receipts for the period, list each expense with its date, merchant, amount, and business purpose, assign a GL account and cost center to each line, attach the receipts, then submit for approval. Most of that is automatic where the spend went on a company card.
Do you need a receipt for every business expense?
Not under federal tax rules, which require documentary evidence for lodging and above a set dollar threshold. Many companies set a lower internal threshold as a control measure, which is a policy decision rather than a tax requirement.
What is the difference between expense approval and invoice approval?
Expense approval reviews an employee's claim against your expense policy, testing receipts and business purpose. Invoice approval reviews a supplier's invoice against a purchase order and goods receipt, testing the three-way match. Different counterparty, different evidence, different checks.
What does expense approval software do that a spreadsheet cannot?
It enforces policy limits at submission, routes claims automatically by amount and department, escalates when an approver is unresponsive, and produces an audit trail linking each approval to the payment that followed. A spreadsheet does none of those and accepts any claim entered into it.
- What is an expense approval process, and what is it supposed to catch?
- What checks should an approver perform before approving an expense claim?
- How should you set approval thresholds and escalation rules?
- How do you move approvals out of email without slowing the team down?
- Enforce your expense policy where the spend happens, with Corpay
Switch to Corpay
Discover how making the move to Corpay streamlines payments and strengthens your business.
Talk to an ExpertSmarter payments. Stronger growth. Keep business moving.
Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.