What reviewers commonly ask for
An expense audit — internal or external — works by sampling: the reviewer selects claims and asks for the complete story of each. For every sampled claim, finance should be able to produce, without reconstruction:
| Evidence item | What the reviewer is checking |
|---|---|
| Original receipt or invoice | The spend happened, at the stated merchant, for the stated amount |
| Employee and date | Who incurred it and when — matched against employment and travel records |
| Business purpose | Why this was the company’s cost — the substantiation standards auditors reference, such as IRS Publication 463, frame this as adequate, timely kept records proving time, place, and business purpose |
| Category | The claim was classified so the right policy rules applied |
| Approver identity and timestamp | Someone with authority accepted the cost, and when |
| Policy exception note | If a rule was waived: who waived it, and why |
| Payment record | What was actually reimbursed, when, matching the approved amount |
| Accounting export trail | The claim landed in the books, in the right entity and period |
| Rate source and converted amount | For foreign-currency claims: which rate, from where, fixed at which moment |
The last row is the one most checklists omit. A foreign-currency claim whose converted amount cannot be traced to a stated rate on a stated date turns a routine sample into a discussion — the mechanics of documenting rates are covered in foreign currency expenses.
The professional context reviewers work in is also worth knowing: the Global Internal Audit Standards (2024) organize internal auditing into five domains built on fifteen principles, including planning engagements effectively, conducting engagement work, and communicating results. The practical translation: reviewers arrive with a plan and a sample, and they escalate when the first items sampled cannot be evidenced — which is why the completeness of the routine trail matters more than any binder assembled the week before.
The seven dimensions the checklist scores
- Receipts and documentary evidence. Every claim above your receipt threshold has its document attached — legible, original, matching the claimed amount. The failure mode is not the missing receipt itself but the absence of a defined missing-receipt procedure, which turns each gap into an improvisation.
- Business purpose. Each claim states why it was the company’s cost, written by the submitter at submission — not inferred by finance at close. One sentence at the right time outweighs a paragraph reconstructed later.
- Approval history. Every claim shows who approved it, when, and under which rule — and the approver had authority over the money spent, per your delegation of authority. Approvals by the wrong person are findings even when the spend was legitimate.
- Policy exceptions. Every waived rule is recorded with its reason and its approver. An exception log that exists is a sign of a working policy; exceptions that are invisible are indistinguishable from control failures.
- Payment records. What was reimbursed matches what was approved, per claim, with dates. Differences between approved and paid amounts — even innocent ones like rounding — need to be explainable.
- Accounting exports. Each claim reconciles to the ledger entry it produced, in the correct entity and period, and re-running the export would produce the same result. A trail that ends at the expense system’s edge leaves the reviewer to bridge the gap by hand.
- Role conflicts. No one approves their own claims; the people who configure rules, approve claims, and prepare payments are not the same person — or, where a small team makes overlap unavoidable, a compensating review is documented. The full conflict matrix is in segregation of duties in expenses.
Score each dimension honestly against your last full quarter, not your best week. The checklist grades in three levels per dimension — consistently true, partially true, and not true — because “we mostly do this” is precisely the state audits surface.
Reading your score
The output is a percentage and a per-dimension breakdown, and it means exactly this: how much of the evidence a reviewer will predictably request already exists as a routine byproduct of your workflow. It is not an audit opinion, a compliance rating, or a prediction of any audit’s outcome — no checklist can guarantee an audit result, and this one does not try.
- Gaps in receipts, purpose, or approvals are workflow-design problems: the evidence is not being captured at the moment it exists. Fixing them means changing what the submission and approval steps require, not asking people to try harder — the design options are covered in spend controls.
- Gaps in exceptions or role conflicts are control-design problems: decisions are happening outside recorded channels. These are the findings that expand an audit’s scope, because they undermine confidence in every other answer.
- Gaps in payments or exports are reconciliation problems: the trail breaks between systems. They are cheap to fix and expensive to leave, because every sampled claim crosses that break.
Re-run the checklist after each fix and each quarter. A score that improves across quarters is itself useful evidence of a control environment that monitors and corrects — the posture the standards frameworks describe.
Multi-entity audit risks
Standard expense checklists assume one company. If your team operates several entities, three additional checks decide whether an entity-level audit is an export or a project:
Entity assignment
Every claim is bound to the entity that actually bears the cost — decided at submission, with any reassignment recorded with its reason. A claim in the wrong entity misstates two sets of books and only surfaces when the entity’s own reporting is reviewed.
Entity-scoped approval
The approver had authority in the claim’s entity, not just seniority in the group. An approval by a manager with no authority over the paying entity is organizationally sensible and legally meaningless.
Entity-correct export
The claim landed in the right entity’s ledger, in that entity’s functional currency, and one entity’s complete file can be produced without exposing the others’ records.
Cross-entity claims add a fourth: the link between the original expense and any intercompany recharge should be navigable in both directions, so a reviewer on either side reaches the same facts — the workflow that produces this is described in intercompany expenses, and the surrounding structure in multi-entity expense management.
Before the reviewer arrives
If an audit is scheduled, the useful preparation is a rehearsal, not a reorganization:
Sample yourself first
Pull a dozen claims across quarters, entities, and amounts, and produce each one’s complete story. Wherever you reach for email or memory, a reviewer will reach a finding.
Read your own exception log
Recurring exceptions mean a rule is mis-calibrated; be ready to explain the pattern or fix the rule before it is asked about.
Verify the export reconciliation once, end to end
One claim traced from submission to ledger entry, in each entity, proves the bridge works.
Check the period boundary
Claims dated near the period edge are the classic sample choice; confirm they landed in the right period.
Write down what you found and fixed
A self-review with documented remediation is evidence of exactly the monitoring posture reviewers are instructed to look for.
Where the workflow itself does the capturing, most of this preparation is already done: in Clara Global, receipts and approval history stay attached to each expense as it moves, the approval rules your finance team defines flag an out-of-policy expense before it reaches a reviewer, and the FX rate is locked at submission so every converted amount traces to a stated rate on a stated date. Flagging is pre-review support for your own controls — it is not a promise of compliance or of any audit outcome.