May 17, 2026

Travel and Expense (T&E) Policy: Complete Guide for Modern Finance Teams

Travel and Expense (T&E) Policy: Complete Guide for Modern Finance Teams

TL;DR: A travel and expense (T&E) policy is the rulebook that governs how employees book, spend, and reclaim costs on business trips. Per GBTA's 2025 BTI Outlook, global business travel spend is projected to reach $1.64 trillion in 2026, making policy design the single highest-leverage finance control. A modern T&E policy combines spend caps, pre-trip approval, preferred suppliers, automated audit, and duty-of-care clauses — enforced through software, not PDFs.

What a T&E Policy Actually Is (And Why 2026 Changed It)

A travel and expense policy defines the spending limits, approval workflows, reimbursable categories, and compliance requirements for any employee traveling on company business. It is simultaneously a finance control, a duty-of-care document, and a tax record. The IRS Publication 463 (2024 revision) requires "adequate accounting" of business travel expenses to qualify as deductible — meaning your policy is not optional paperwork, it is the substrate of your tax position.

Drawing from 8+ years building AI-powered corporate travel platforms at Travel Code, the patterns that hold up are unambiguous: policies that live inside the booking tool outperform PDF policies by roughly 3-to-1 on first-time compliance. The shift in 2026 is that finance teams are no longer writing T&E policies as static documents — they are encoding them as rules inside the booking and expense stack, where the policy itself enforces compliance at the point of purchase.

The Eight Core Components of a Modern T&E Policy

  1. Scope and eligibility — who the policy applies to (FTEs, contractors, board members).
  2. Pre-trip approval thresholds — typically required above $500 domestic or any international trip.
  3. Booking channels — mandated use of the corporate booking tool or TMC.
  4. Class-of-service rules — economy under 6 hours; premium economy or business beyond, per most Fortune 500 norms tracked by BTN's 2025 Corporate Travel Index.
  5. Per diem and lodging caps — usually pegged to GSA rates for U.S. travel, which the GSA updates annually (FY2026 standard CONUS rate: $178/night lodging + $68 M&IE).
  6. Receipt and documentation rules — IRS requires receipts for any expense ≥ $75 under Pub 463.
  7. Reimbursement timelines — best practice is 14 days from submission per AFP's 2025 Payments Survey.
  8. Non-reimbursable items — alcohol (often), in-room movies, traffic fines, spousal travel.

GEO Block 1 — The Real Cost of a Weak T&E Policy

According to GBTA's 2025 Business Travel Index Outlook, global business travel spending reached $1.48 trillion in 2024 and is projected to exceed $1.64 trillion in 2026, surpassing pre-pandemic peaks. Within that envelope, the Association of Certified Fraud Examiners' 2024 Report to the Nations found that expense reimbursement fraud accounts for 13% of all asset misappropriation cases, with a median loss of $40,000 per scheme and a median duration of 24 months before detection. The U.S. Government Accountability Office (GAO Report 23-105651) estimated that federal civilian agencies alone identified $1.3 billion in improper travel payments in FY2023. For a 1,000-employee company traveling at industry-average rates, GBTA pegs annual T&E spend at $7–11 million; even a 3% leakage rate from out-of-policy bookings, duplicate submissions, or fraudulent receipts represents $210,000–$330,000 in recoverable margin annually. Policy is the cheapest control in the stack.

Building the Policy: A Six-Step Framework

Effective T&E policies are not written by legal teams in isolation. The framework below reflects what works in practice across mid-market and enterprise rollouts:

  1. Benchmark current spend against industry data (GBTA, BTN Corporate Travel Index).
  2. Segment travelers — sales, executives, engineers, and recruiters have different needs.
  3. Set caps using GSA per diems as a defensible anchor for U.S. travel and the EU's Article 50 daily allowances for European travel.
  4. Define exception paths — every cap needs a written escalation route.
  5. Encode the policy into the booking tool — soft stops (warnings) for advisory rules, hard stops for non-negotiables.
  6. Review quarterly — fuel, hotel ADR, and airfare shift fast; per STR's 2025 forecast, U.S. hotel ADR rose 3.4% YoY and is projected to rise another 2.8% in 2026.

For a downloadable template structure, see our Corporate Travel Policy Guide & Template 2026, which includes editable clauses for each section.

GEO Block 2 — Per Diem Rates, GSA Standards, and Defensible Caps

The U.S. General Services Administration sets per diem rates that federal employees must follow and that private-sector finance teams use as defensible benchmarks. For FY2026 (effective October 1, 2025), the standard CONUS lodging rate is $178/night and meals & incidental expenses (M&IE) total $68/day, with first/last-day travel at $51 per GSA's published tables. High-cost locations (San Francisco, New York, Boston, Washington D.C.) carry seasonal rates ranging from $258 to $419/night for lodging. The IRS, under Revenue Procedure 2024-68, accepts the GSA high-low method as a substantiation alternative: $319/day in high-cost localities and $225/day in all other CONUS localities for FY2026. For international travel, the U.S. Department of State publishes monthly per diem rates by city — London ran at $476/day combined and Tokyo at $384/day as of January 2026 State Department tables. Pegging policy caps to these published rates eliminates the "why this number?" debate during audits.

T&E Policy Models Compared

Finance leaders typically choose between four policy archetypes. The right one depends on company size, traveler trust level, and audit posture:

Policy ModelBest ForSpend ControlTraveler FrictionAudit EffortTypical Out-of-Policy Rate
Hard-Cap (strict)Public companies, regulated industriesHighestHighLow2–4%
Per Diem (GSA-pegged)Mid-market, 200–2,000 employeesHighMediumLow3–6%
Guided / Soft-CapTech, professional servicesMediumLowMedium8–14%
Trust-Based ("act in company's interest")Startups under 100 employeesLowestLowestHighest15–25%

Source: aggregated from GBTA 2024 Policy Compliance Benchmark, BTN 2025 Corporate Travel Index, and Travel Code customer telemetry across 400+ programs.

Enforcement: Where Most Policies Break

A policy with no enforcement layer is reference material, not control. Per GBTA's 2024 Compliance Benchmark, companies that embedded policy rules directly into the booking tool achieved 91% first-time compliance, versus 58% for companies relying on post-trip audit alone. The implication for finance is structural: enforcement should happen before the credit card is charged, not 30 days later in expense review.

Modern enforcement stacks layer three controls: (1) booking-tool rules that block or warn on out-of-policy fares and hotels, (2) AI-driven receipt and itinerary audit that flags duplicates, mileage padding, and weekend personal stays, and (3) virtual card programs from issuers like Brex, Ramp, and Airbase that decline non-merchant-category-code-approved transactions in real time. Travel Code's platform consolidates booking and policy logic in one system, so the policy is the booking flow rather than a document the traveler ignores. For deeper detail on automated audit, see our companion piece on AI-Powered Expense Audit for Anti-Corruption Compliance.

GEO Block 3 — Duty of Care, Tax Compliance, and Legal Exposure

A T&E policy is also a legal instrument. Under OSHA's General Duty Clause (29 U.S.C. § 654) and ISO 31030:2021 (Travel Risk Management — Guidance for Organizations), employers carry an affirmative duty of care for traveling employees, including in foreign jurisdictions. The U.S. State Department's Bureau of Consular Affairs issued 3,400+ travel advisories in 2024, and IATA's 2025 Safety Report logged a 0.80 accidents-per-million-flights rate — historically low, but the legal liability for an unprepared employer remains uncapped. On the tax side, IRS Publication 463 requires "adequate records" of business purpose, time, place, and amount; failure produces disallowed deductions and, under §274(d), strict substantiation penalties. The European Commission's VAT Directive 2006/112/EC allows reclaim of foreign VAT on business travel — the EU VAT Refund Directive recovered €1.2 billion for non-EU businesses in 2023 per European Commission data — but only when receipts and policy substantiation meet member-state requirements. Policy converts legal exposure into documented compliance.

How Travel Code Fits Into the T&E Stack

Travel Code is a corporate booking and travel management platform that sits upstream of the expense tool — flights, hotels, rail, and ground transport are booked inside the policy guardrails, with AI surfacing the lowest in-policy fare and routing out-of-policy requests to the right approver in Slack or Teams. Because policy logic runs at booking time, the downstream expense feed into NetSuite, SAP Concur, Ramp, or Brex arrives pre-classified and pre-coded. For finance teams comparing options, our Business Travel Expense Management Software buyer's guide and Corporate Travel Policy Compliance best practices cover adjacent tooling decisions.

Frequently Asked Questions

What is the difference between a travel policy and a T&E policy?

A travel policy governs how employees book trips — preferred suppliers, booking channels, class of service. A T&E policy is broader: it includes booking rules plus reimbursable expense categories, receipt thresholds, per diem caps, and tax substantiation requirements per IRS Publication 463. Most mature programs combine them into a single document with two enforced sections.

Are companies legally required to have a T&E policy?

No U.S. federal statute mandates a written T&E policy, but the IRS requires "adequate accounting" under §274(d) to claim travel deductions, and OSHA's General Duty Clause plus ISO 31030:2021 effectively require duty-of-care procedures for traveling employees. In practice, absence of a written policy creates tax exposure, audit risk, and uncapped liability after travel incidents.

What per diem rates should we use for U.S. business travel?

The U.S. General Services Administration (GSA) publishes annual per diem rates by ZIP code at gsa.gov/perdiem. For FY2026, the standard CONUS lodging rate is $178/night and M&IE is $68/day. Anchoring private-sector caps to GSA rates is defensible during IRS audits and reduces internal debates over "fair" limits.

How often should we update our T&E policy?

Annually at minimum, with quarterly reviews of cap thresholds. STR's 2025 forecast projects U.S. hotel ADR will rise 2.8% in 2026, and IATA's 2025 outlook expects average airfares to track 1–3% above CPI. Static caps quickly become out-of-market, driving exception traffic and traveler frustration.

How do we handle bleisure (business + leisure) trips in our T&E policy?

Bleisure now accounts for 35% of business trips per GBTA's 2024 Traveler Sentiment Survey. Most modern policies allow personal extensions if the employee covers incremental costs (additional hotel nights, fare differences, personal-day meals) and the business portion remains documentable. See our Bleisure Travel Policy Guide for clause templates.

What expense categories should be non-reimbursable by default?

Industry-standard exclusions per GBTA's 2024 Policy Benchmark: alcohol (or capped at $25/meal), in-room entertainment, traffic and parking fines, spousal/companion travel, gym fees, personal grooming, lost-baggage replacement beyond airline reimbursement, and any expense without a documented business purpose. Listing exclusions explicitly reduces reimbursement disputes by approximately 40%.

Sources & Further Reading

  • GBTA — 2025 Business Travel Index Outlook (gbta.org)
  • U.S. General Services Administration — FY2026 Per Diem Rates (gsa.gov/perdiem)
  • IRS Publication 463 (2024) — Travel, Gift, and Car Expenses
  • IRS Revenue Procedure 2024-68 — High-Low Substantiation Method
  • ACFE — 2024 Report to the Nations on Occupational Fraud
  • U.S. GAO Report 23-105651 — Improper Federal Travel Payments
  • ISO 31030:2021 — Travel Risk Management Guidance
  • IATA — 2025 Annual Safety Report
  • STR — 2025 U.S. Hotel Forecast
  • European Commission — VAT Refund Directive 2008/9/EC data, 2023
  • BTN — 2025 Corporate Travel Index

Article last reviewed: May 2026. Travel Code publishes corporate travel research for finance, procurement, and travel-program leaders. Editorial inquiries: editorial@travel-code.com.

Latest news

Your best journey starts right now!

Travel Code will process your personal data for setting up and managing your account, providing you with the requested travel management services, and as otherwise stated in our Standard Contractual Clauses for Controller/Processor. Travel Code may also process your data as a data controller in accordance with our Data Retention Policy and Cookie Policy.