Finance operations · July 24, 2026
Expense approval workflow: the process, the steps, and the approvals that are not really approvals
An expense approval workflow routes a spending request to the right people in the right order: submit with documentation, manager review for business purpose and budget, finance review for policy and coding, escalation above a threshold, then payment and posting. Six steps, and most teams get the mechanics broadly right. The part that goes wrong is subtler: half of these workflows run before the money moves, and half run days after it is already gone, and almost nobody designs them differently.
That distinction is the useful thing in this article. A purchase request you can decline is a gate. An expense report on a corporate card charge that cleared last Tuesday is a review, and calling it an approval flatters it. Below: the six steps, where to put thresholds, who signs what, how long it should take, and what to do about the spend your workflow structurally cannot reach.
See which charges would have flagged before anyone approved anything
Live demo · computes entirely in your browser
Data source
Loading sample data…
Runs entirely in your browser. Nothing you paste is uploaded.
Monthly budgets
$0.00
The alert wire
Chronological replay of the month
Get alerts like these for your real spend.
From: Spendnotify Alerts <alerts@spendnotify.com>
Spendnotify app
Turn a channel back on to preview the message.
What is the expense approval process?
The expense approval process is the sequence a spending request or expense claim moves through before it is paid or booked: submission with documentation, a manager review for business purpose and budget, a finance review for policy and coding, escalation to a senior approver above a set amount, then payment and posting. Its purpose is to confirm the spend was legitimate, sat inside a budget, and got recorded correctly.
Three separate questions hide inside that one word. Was this a real business expense? Can the budget absorb it? Is it coded, documented, and treated correctly for tax and audit? Different people are qualified to answer each one, which is why a single approver rubber-stamping everything is not a workflow, it is a formality.
The six steps in an expense approval workflow
Every workflow, from a spreadsheet to a NetSuite implementation, is a variation on these six. The column that matters is the last one, because a step nobody can fail is a step you can drop.
Swipe the table sideways to compare all columns.
| Step | Owner | What it is actually checking | What it catches |
|---|---|---|---|
| 1. Submit | Employee | Amount, vendor, date, business purpose, category, receipt or invoice attached | Missing documentation, before it becomes an audit finding six months later |
| 2. Route | The system | Who should see this, based on requester, amount, category and cost center | Requests landing on the wrong desk, or on the desk of the person who spent the money |
| 3. Manager review | Direct manager or budget owner | Was this necessary, and does the budget have room | Spend that is legitimate in kind but not justified in context, and quiet budget overruns |
| 4. Finance review | Finance or controller | Policy compliance, receipts, tax treatment, ledger coding | Policy breaches, miscoding, sales tax errors, duplicates already submitted |
| 5. Escalate | Department head or executive | Anything over a threshold, or in a flagged category | Large commitments approved by someone without the authority to make them |
| 6. Pay and post | Accounts payable or payroll | Reimbursement or settlement, then posting to the ledger | Payment errors and unrecorded liabilities at close |
Step 2 is the one teams under-build and then complain about. When approvals are routed by hand, or by a rule that only knows the org chart, they land on managers who have no budget authority over the cost center being charged. The generic version of this problem, getting every incoming request to the person who is actually accountable for it, is worth solving properly with rules that route each request to its real owner rather than with a shared inbox and good intentions.
Who approves expense reports?
Usually two people with different jobs. The employee's direct manager or the budget owner approves the business purpose and confirms the budget can absorb it. Finance or the controller then checks policy compliance, receipts, tax treatment, and ledger coding. Above a threshold set in policy, a department head or executive signs off as well. The employee's own approval never counts, and that rule has no exceptions worth making.
The self-approval rule sounds obvious until you look at how it breaks in practice. A founder whose expenses route to nobody. A manager approving a team dinner they attended and their report paid for. A finance lead who is also the only approver on the finance cost center. Each of those is the same failure, which is segregation of duties quietly collapsing to one person, and it is worth checking who your workflow leaves unsupervised before you tune anything else.
What is a good approval threshold for expenses?
Set thresholds so review effort tracks risk. A common pattern is auto-approval with a receipt below roughly $100, single manager approval through the middle band, manager plus finance from around $1,000, and executive sign-off on the largest items. Layer category rules on top, so travel or professional services get a second look regardless of amount.
Those numbers are a starting shape, not a recommendation for your company. Calibrate them against your own spend distribution: pull twelve months of expenses, sort by amount, and find the point where reviewing everything below it costs more in approver time than the errors it catches. In most small and mid-sized US companies that line sits lower than people expect, because the volume is concentrated in software subscriptions, travel, and meals.
Two thresholds are worth adding beyond the amount bands. A cumulative one, so a vendor receiving many small charges eventually surfaces rather than staying invisible under the auto-approve line forever. And a novelty one, so the first charge to a merchant nobody has used before gets looked at even if it is small, since that is where both honest mistakes and deliberate expense fraud tend to start.
How long should expense approval take?
Set a service level and measure it. Many teams target 48 hours for a manager decision and close the cycle within one reimbursement run. The specific number matters less than having one, because unmeasured approval queues are where reports sit for weeks, employees float company costs on personal credit, and approvers start clearing batches of twenty without reading any of them.
Two mechanics keep the clock honest. Automated reminders, so chasing is not a person's job. And delegation, so a manager on vacation names a substitute rather than becoming a two-week bottleneck. A workflow with no delegation path teaches employees to route around it, and once that habit forms you have a policy nobody follows and no data about how often.
The difference between a gate and a review
Here is the part most guides skip. A purchase request or pre-approval runs before money moves, so declining it genuinely prevents the spend. An expense report approval on a company card charge runs after the charge has cleared, so approving or rejecting it only decides how the money gets classified and whether anyone is held accountable. One is a gate. The other is a review with a decisive-sounding name.
Both are worth having. Reviews are how you enforce policy over time, and an employee who knows their charges get read behaves differently from one who does not. But a review cannot do a gate's job, and treating it as though it can is how a finance team ends up genuinely surprised by a number at close, despite having approved every line that produced it. The approval happened. It just happened afterwards.
So the design question is which spend actually passes through a gate. Purchase orders and pre-approved requests do. Reimbursement claims do, in the sense that you can refuse to pay them. Card spend usually does not, unless your card issuer enforces the limit at the moment of authorization, which is exactly what platforms like Ramp and BILL sell you a card to do. If your cards come from a bank rather than a spend platform, most of your card spend has no gate at all, and your approval workflow is reviewing history.
Where the workflow cannot reach
For the spend that has no gate, the only lever left is time. You cannot stop the charge, but you can shorten the distance between the charge happening and a human knowing about it, and that distance is usually the entire problem. A subscription that quietly renewed at a higher price, a duplicate charge, a card used at an unusual merchant on a Saturday: each of those is obvious in hindsight and invisible for three weeks.
That is what real-time budget alerts are for. Spendnotify connects read-only to the cards and accounts you already have and watches spend against budgets and thresholds, with a warning at 80% and a breach alert at 100%, delivered by email, SMS, or Slack. Alongside it, corporate card monitoring flags duplicates, outliers, and new merchants as they land rather than at month end.
It is worth being clear about the limit, because it is the same limit your approval workflow has: monitoring cannot move, hold, or block money, and it cannot decline a transaction. Only the issuer can do that. What it changes is when a person finds out. A charge that breaks a budget reaches someone in moments instead of on next month's report, and someone with a phone can still call the cardholder, freeze the card at the bank, or cancel the renewal before it bills again.
A workflow worth having
If you are rebuilding yours, the order to do it in is: fix routing first, because a request on the wrong desk fails every later step. Then set thresholds from your own spend data rather than a template. Then add a service level and delegation so the queue keeps moving. Then, separately and last, work out which of your spend is genuinely gated and which is only reviewed, and put real-time visibility on the second category, because no amount of workflow design will turn a review into a gate.
Most teams do the first three and stop. The fourth is the one that stops surprises, and it is also the cheapest, because it does not require anyone to change how they buy things or which card they carry. It only requires that finance finds out on the day.
Spendnotify watches the cards and accounts you already have and tells a human the moment spend breaks a budget. No new card, no credit line, read-only. It is in early access: leave your work email and we will write when your spot opens.