Expense claim fraud and generative AI: how to protect your organisation

In our previous article,Whilst we await the benefits of AI, OBTs are already offering us automation that is transforming our lives’, we discussed AI as a means of optimising expense processing and the employee experience. But it also puts tools of unprecedented power into the hands of fraudsters.

Since spring 2025, it has taken just a few seconds to forge a receipt. Faced with this unprecedented threat, finance departments and travel managers must thoroughly rethink their controls.

The new face of document fraud: a perfect receipt… generated in 8 seconds

Picture the scene. Thomas, a senior sales representative, is returning from a business trip to Lyon. He’s forgotten to ask for his receipt. Without a moment’s hesitation, he opens ChatGPT, types in a few lines, and within 8 seconds receives a perfectly formatted receipt: name of the establishment, address, VAT number, and amounts excluding and including VAT.

The next morning, he submits it via his expense claim tool. The finance controller approves it with a single click. The matter is settled.

This scenario is not fiction. It is the documented reality of 2025–2026. According to AppZen, AI-generated fake receipts accounted for 0 per cent of fraud detected in March 2025. By May 2026, this figure had risen to 70.8 per cent. In just 14 months, generative AI had become the leading cause of document fraud in expense claims.

Expense claim fraud has always existed, but generative AI is radically changing its scale, ease and credibility.

Why your current checks are no longer sufficient 

For decades, a receipt was proof in itself. The effort required to forge one acted as a natural safeguard. That model has just collapsed.

Today, the tools used for fraud are the same as those employees use on a daily basis. Traditional OCR checks, rules based on fixed thresholds and manual visual verification are now ineffective. AI can replicate the texture of thermal paper, simulate the creases in a receipt and mimic the blurriness of a photo taken with a smartphone.

The counterattack: AI versus AI, but not only that

In the face of this threat, a single solution is not enough. The response must be architectural: several independent layers of detection, each targeting a different vector.

Layer 1: AI to detect AI

Next-generation audit tools analyse the invisible signatures left by image generators. They detect inconsistencies in lighting, compression artefacts and the absence of consistent EXIF metadata. Companies such as AppZen, SAP Concur Verify, Expensify and Tevasoft are now incorporating these capabilities.

Layer 2: transactional anchoring

The best defence is to stop relying on paper or PDF receipts. A genuine receipt corresponds to an actual bank transaction, which is time-stamped and geolocated. An AI-generated receipt, on the other hand, does not correspond to any transaction in any third-party system.

Transactional anchoring involves systematically cross-referencing expense claims with:

  • Statement of a corporate card or a registered personal card
  • Geolocation data (calendar, access badges, transport bookings)
  • Retailers’ databases to verify the supplier’s existence and trading status on the date specified

The roll-out of virtual debit cards or integrated corporate credit cards, together with direct links to suppliers’ stock records, enables data to be automatically cross-referenced

A practical example: a hotel receipt from Barcelona submitted on a Tuesday, when the employee’s calendar shows an internal meeting in Paris on the same day, automatically triggers an alert. No visual analysis of the document is required: it is the contextual inconsistency that reveals the fraud.

Layer 3: behavioural and statistical analysis

Rather than analysing each ticket individually, machine learning models build a behavioural profile for each employee. As a result, ratings submitted just below the approval thresholds, spikes in submissions at the end of the month or amounts that are systematically rounded off automatically trigger an alert

Layer 4: Human governance and a culture of integrity

Technology is not the be-all and end-all. The expenditure policy must make it clear that falsifying a receipt constitutes serious misconduct. At the same time, it is essential to train managers to recognise behavioural (rather than visual) warning signs. 

What this means for your T&E organisation

For finance teams, the first change is conceptual: a receipt is no longer proof in itself, but merely one piece of evidence amongst others. Documentary verification must give way to a triangulation approach: the document, the transaction and the behaviour. In practice, this involves moving from sample-based checks to 100 per cent coverage of transactions prior to payment. AI solutions now enable audit automation rates of up to 80 per cent, reducing operational costs by up to 50 per cent. 

For travel buyers and travel managers, the issue goes beyond mere receipt fraud. It raises broader questions about trust in the entire T&E documentation chain: expense claims, as well as hotel invoices, booking confirmations and transport receipts. Travel buyers must now include the following requirements in their calls for tenders and in their specifications:

  • Capabilities for detecting AI-generated documents in expense management solutions
  • Native integration with transaction data (corporate cards, bank statements) for transactional anchoring
  • Traceability and auditability of automated validation decisions

The question is no longer “Can our tool read receipts?”but “Can our tool tell the difference between a genuine receipt and a perfectly generated one?

 For senior management and finance directors, the nature of the risk has changed. It is no longer simply a matter of traditional internal fraud. It is now a systemic risk to financial integrity. Accordingto the ACFE/SAS 2026 report, more than half of organisations (55 per cent) plan to increase their anti-fraud budget over the next two years. 

 This realisation is positive, but it must be accompanied by a clear strategic vision: simply investing in detection tools without reviewing governance and organisational culture is not enough.

The good news is that the layered defence described above is now accessible, even to medium-sized organisations. Native solutions within the major T&E platforms significantly lower the cost of entry. What is often lacking is not so much the budget as thedecision to prioritise the issueand the expertise to orchestrate the various layers in a coherent manner.