A travel audit checks booked travel and expenses against the organisation's policy, its approvals and the fares available at the time of booking. Most audits read a sample, which finds habits. An outlier fare is a single ticket far above its route's norm, and only testing every booking above a set fare threshold finds it reliably.
A traveller who books within policy all year and buys one $12,000 ticket never appears in a pattern. The ticket sits in the population, unreviewed, until a sample happens to land on it or somebody happens to look.
This guide sets out where the outlier test sits in a travel audit, why a sampled or one-way audit misses it, the five steps that find it, and a four-stage model for checking your own fare audit.
In this article
- What is a travel audit, and where does the outlier test sit?
- Why does audit sampling miss outlier fares?
- Why does a one-way route filter miss tickets?
- How do you audit high-value airline tickets?
- What do teams ask when they audit outlier fares?
- Is every outlier fare a sign of fraud?
- How mature is your fare audit?
- Which audit approach catches a single outlier fare?
- Frequently asked questions
- Where DetectX and Cogent sit in a travel audit
What is a travel audit, and where does the outlier test sit?
A travel audit is a review of business travel bookings and expenses against policy, approvals and the fares available when each trip was booked, to find spend that should not have happened or was recorded wrongly. It runs at two levels: the data, and the behaviour behind it.
There are two kinds of travel audit, and PredictX's guide to auditing traveller behaviour defines both. A data-quality audit catches system problems: the Unknown Employee, the unmapped cost centre, the miscoded transaction. A behavioural audit catches people problems, from the traveller who breaches the rate cap every month to the last-minute ticket booked at several times the fair fare.
Those last two examples need different tests. The rate-cap breach is a pattern, found by looking across one traveller's bookings over time. The expensive ticket is an incident, found by looking at one booking on its own, which makes the outlier test the transaction-level half of the behavioural audit.
The table places the outlier test beside the other two.
A programme that runs only the pattern test can report a clean quarter while a single $12,000 ticket goes unreviewed.
Why does audit sampling miss outlier fares?
Audit sampling misses outlier fares because it tests a selection of transactions and projects the result onto the rest. That works for a habit, which repeats and so turns up in most samples. A one-off ticket appears once, and a sample can pass straight over it.
The audit profession's own standard draws the same line. The PCAOB's AS 2315, Audit Sampling defines audit sampling as "the application of an audit procedure to less than 100 percent of the items within an account balance or class of transactions". It also tells the auditor to examine individually the items "for which, in his judgment, acceptance of some sampling risk is not justified", and a ticket priced several times above its route's norm is that kind of item.
Timing makes the gap wider. A quarterly audit reads bookings weeks after the tickets were flown, when the traveller has moved on and the approver no longer remembers the reason, so a flag raised then can only record what happened.
Four things keep the outlier from surfacing:
- Four sources, one question: fare, benchmark, timing and approval data rarely sit in one system.
- Quarterly cadence: the audit lands after the decision window has closed.
- Pattern bias: rules built for repeat behaviour pass over a one-off incident.
- Missing traveller context: default reports often omit the name and cost centre needed to act.
Fraud research shows what that delay costs. The ACFE's Occupational Fraud 2026: A Report to the Nations analysed 2,402 cases across 143 countries and territories and found a median loss of $104,000 per case, with the median scheme lasting 12 months before detection. Tips remained the most common way a scheme came to light, at 43% of cases.
The same report found that "controls such as management review, proactive data monitoring and surprise audits were associated with stronger outcomes". An outlier fare need not be fraud for the timing to matter: a ticket questioned a quarter later can no longer be changed.
Why does a one-way route filter miss tickets?
A one-way route filter misses tickets because it keeps only the bookings that start at the chosen origin, and drops every ticket flown in the other direction. At a global pharmaceutical manufacturer, a premium-fare search on one long-haul route returned 2 tickets. Including the return leg surfaced 15 more, for 17 in total.
That left 88% of the tickets above the threshold invisible to a query that looked correct. A business trip usually ends where it started, so a city-pair question almost always implies travel in both directions, and an audit that fixes origin and destination one way round discards every ticket flown the other way.
The Bidirectional Audit Rule is PredictX's correction for this: any route-level audit resolves both directions of a city pair before the result is trusted.
A route-level audit that skips the return leg is not a conservative audit. It is a wrong one, and its total has to be re-run rather than caveated.
How do you audit high-value airline tickets?
Audit high-value airline tickets in five steps: set a fare threshold, resolve each route in both directions, benchmark every fare against the compliant alternative, attach the traveller and approval context, then route each exception to the person who can act on it. Step 2 is the step a one-way filter leaves out.
Run on every ticket as it arrives, these five steps become continuous auditing of travel and expense: each booking above the threshold is tested while the approval trail is current and someone can still act on it.
- Set the threshold: choose the fare level above which every ticket warrants individual review. Run more than one level, because each returns a different population.
- Resolve both directions: expand the city pair to include the return leg before any filter is applied.
- Benchmark the fare: compare each ticket with the compliant alternative available on that route and date.
- Attach the context: pull traveller, grade, department, cost centre and approval trail alongside the fare.
- Route the exception: send each confirmed outlier to the person who can act on it, with the working attached.
Without traveller detail, an outlier report is a list of fares. With it, each line has a name and an owner against it.
The five steps are standard audit practice. The work is in the join between fare, benchmark, timing and approval data, which rarely sit in one system and which a quarterly extract assembles by hand.
What do teams ask when they audit outlier fares?
Teams name a threshold and a route, and ask for the traveller context with the result. They run several thresholds in one sitting and compare the populations, so the brief reads as a set of questions about named tickets and the people who booked them.
The query patterns below are drawn from live enterprise deployments of Cogent, the agentic AI workspace for T&E, with route, region and business-unit names removed. PredictX does not name a client without its written permission. The deployment figures in this article were produced by Cogent from each organisation's own travel and expense data, and are held with their method in our evidence records.
Briefs of this kind look like this:
- "Show all single tickets above $10,000, grouped by traveller and route."
- "Show tickets above $12,000 between these two cities, bidirectional."
- "Show single tickets above $18,000 by business unit and evaluate against lowest logical fare policy."
- "Show the highest-cost tickets with employee name, grade and cost centre."
- "Show all hotel bookings above the nightly rate cap by market and traveller."
At a global pharmaceutical manufacturer, thresholds were queried at $10,000, $12,000 and $18,000 in the same session, each returning a different population and a different owner. At a global financial services group, the equivalent question was asked of hotel bookings above a fixed nightly rate cap.
Sources for this section: the thresholds as queried in one Cogent session on the first organisation's own air booking data, and the rate-cap question as queried in a Cogent session on the second organisation's own hotel booking data.
The strongest briefs name their context fields up front, as the fourth does. A result without traveller, grade and cost centre is a list of fares with nobody to send it to, so the fields belong in the first question.
Cogent returns each population in seconds (based on enterprise deployment patterns, individual results vary), so three thresholds can be compared in one session. Agentic analytics, meaning AI that plans a task and carries it out across systems instead of answering from one, performs the join on request.
Is every outlier fare a sign of fraud?
No: an outlier fare is a booking that needs a reason, and many have one, such as a meeting called at two days' notice. The outlier test asks whether a booking was justified, while fraud detection asks whether a claim was legitimate. The audit is what tells the two apart.
Expense fraud tends to show in different signals from a fare outlier, and pre-reimbursement checks look for them:
- Duplicate submissions: the same cost claimed twice, caught before reimbursement rather than after.
- Receipt anomalies: altered or generated receipts, flagged at the point of claim.
- Threshold clustering: claims that sit consistently just under an approval limit.
- Round-number patterns: particularly in self-reported categories such as mileage.
Those checks belong to DetectX, PredictX's expense fraud detection engine, which audits every expense report in real time, before reimbursement. The PredictX product team reports that DetectX catches 5x more fraud before reimbursement than traditional methods (2026), based on enterprise deployment patterns, individual results vary.
Continuous controls monitoring is the governance term for the same idea applied across a whole control environment: every control tested continuously instead of sampled at audit time. Travel and expense suits it, because transaction volumes are high and the rules are already written down.
How mature is your fare audit?
A fare audit matures in four stages, from a list of the most expensive tickets to every booking above the threshold reviewed as it arrives. Each stage is defined by what it still cannot say: a stage-two programme can flag that a booking broke policy, but cannot show whether a compliant fare existed when it was booked.
Place your own programme against the four stages below.
The right-hand column is the test, and the stage you reach is the last one whose gap you have closed. A programme that places itself at stage three can check the claim with the two-direction query above, because a stage-three programme running one-way filters is reporting a number that is wrong rather than incomplete.
Which audit approach catches a single outlier fare?
Only testing every booking as it arrives catches a single outlier while the approval trail is still current. Dashboard reporting and a quarterly behavioural audit surface it after the ticket has been flown, and a forensic review finds it only once somebody already suspects it.
The table compares four audit approaches on whether each catches an individual outlier, and when.
A forensic review is the right instrument after something has gone wrong, and the wrong one for the routine weekly question.
Sources behind the numbers
A median of twelve months before detection is the case for testing transactions as they arrive.
Frequently asked questions
What does a travel audit check?
A travel audit checks business travel bookings and expenses against the organisation's policy, the approvals given and the fares available at the time of booking. It covers data quality, such as unmapped cost centres, and behaviour, such as repeated rate-cap breaches and single tickets booked far above their route's norm.
Should a travel audit test every booking or a sample?
Test every booking above a fare threshold, and sample below it if you must. Audit sampling suits habits, which repeat and show up in most samples, but a single outlier fare appears once and a sample can miss it. The PCAOB's audit sampling standard also tells auditors to examine individually any item whose sampling risk they cannot accept.
What fare threshold should trigger a travel audit review?
There is no universal figure. One pharmaceutical manufacturer reviewed at $10,000, $12,000 and $18,000 in a single session, and the right level depends on route mix and cabin policy. Run several thresholds in one session rather than committing to one, because each returns a different population and a different owner.
Why do fare audits miss tickets on the same route?
A route filter applied in one direction discards every ticket flown the other way. At one programme, a one-way filter returned 2 of the 17 tickets above $12,000 on a single route. Resolving both directions of a city pair before filtering is the first correction to make to any route-level audit.
Is every outlier fare a sign of fraud?
No: an outlier fare needs a reason, and many have one, such as a meeting called at short notice. The outlier test asks whether the booking was justified, while expense fraud detection asks whether a claim was legitimate. Duplicate submissions and altered receipts are fraud signals; an expensive ticket on its own only calls for a reason.
Can an outlier fare audit run on the systems we already use?
Yes. The audit is an analysis layer over the booking, card, expense, HR and finance feeds already in place. What it needs is for those feeds to be consolidated and queryable together, so that the fare, the route benchmark, the booking time, the approval history and the traveller can be joined on one ticket.
Where DetectX and Cogent sit in a travel audit
DetectX runs the continuous half of the outlier test. It tests every transaction against policy as it arrives and routes each flagged item into a review workflow, where an auditor can send it back to the submitter, approve it or queue it for further review.
Cogent runs alongside DetectX on the same consolidated booking, card and expense data, and answers the questions around each flag: which threshold, which route, in which direction, and whose name sits against each ticket.
The first test needs neither. Pick your highest-value route and run the threshold both ways: if the second number differs from the first, you have found your audit gap.
Related Posts

Beyond Data Quality: Auditing Traveller Behaviour with Cogent Agentic AI

Finding the Spend You Can't See: How Cogent Agentic AI Surfaces T&E Leakage in Seconds
.webp)
Beyond Dashboards: Cogent - The Agentic AI Revolution in T&E Reporting & Expense Audit

