The assumption that automating expense management reduces audit risk is not always correct. In several documented cases, automation introduced new risk by creating a false sense of control while removing the human review steps that previously caught anomalies.
Three specific failure patterns
First, over-reliance on OCR accuracy. When receipt capture tools misread amounts or dates, and no human reviews the extracted data before posting, errors enter the ledger as if they were verified. The audit trail shows a processed receipt, not a reviewed one.
Second, approval workflow bypasses. Many platforms allow expense submitters to reassign approvals when a manager is unavailable. Without a compensating control, this creates a pathway where submissions are approved by peers rather than supervisors, which external auditors will question.
Third, policy rules that are too broad. A rule flagging all submissions above EUR 500 sounds robust. If the threshold is set without reference to actual spend distribution, it may flag fewer than 3% of submissions while missing systematic low-value abuse across high-volume categories.
Resources for audit-aware configuration
- COSO internal control framework guidance on automated environments
- Your external auditor documentation on IT general controls
- Platform vendor security and access control documentation
Niamh Quigley, a chartered accountant who has reviewed expense systems during statutory audits, recommends treating the automation configuration itself as an auditable document, version-controlled and reviewed annually.