A credit policy is not a compliance document that lives in a drawer. It is the operating system for every credit decision your company makes: who gets terms, how much, on what conditions, and what happens when payment stops. Companies that run without one do not actually avoid having a credit policy; they just have an undocumented one that changes depending on who is in the room, how loud the sales rep is, and how the last quarter went.
The payoff of a written policy is speed and consistency, not bureaucracy. When investigation depth, limit methodology, and approval authority are defined in advance, an analyst can clear a $15,000 application in an hour instead of routing it through three email threads. When the rules are written down, a denied applicant gets the same answer no matter which analyst reviews the file, which matters both commercially and legally.
This guide walks through the sections a working credit policy needs, how to tier investigation effort by exposure so you spend analyst time where the dollars are, how to design an approval authority matrix, and how to keep the document alive after the initial drafting energy fades. At the end you will find a starter outline you can adapt to your business in a week.
What a credit policy is for (and what it is not)
A credit policy has three jobs. First, consistency: two customers with the same financial profile should get the same terms and the same limit, regardless of which analyst handles the file or which sales region originated the deal. Second, speed: when the rules for a $10,000 net-30 account are pre-decided, nobody needs a meeting to approve one. Third, defensibility: when a large write-off lands on the CFO's desk, a documented policy that was followed converts a blame exercise into a process review.
What a credit policy is not: a mechanism to say no more often. A well-written policy usually increases approval velocity because it removes the fear-driven habit of escalating everything. It also is not a legal contract with customers; it is an internal operating document. Keep customer-facing terms in your credit application and terms-of-sale documents, and keep the decision logic internal.
One sizing note before drafting: match the policy to your risk reality. A distributor with 4,000 accounts averaging $8,000 exposure needs fast, rules-driven decisions and light documentation. An equipment supplier with 120 accounts averaging $400,000 needs deep investigation and committee review. The same template serves both, but the thresholds inside it should differ by an order of magnitude.
The core sections every policy needs
Most working credit policies run 8 to 15 pages and contain the same ten building blocks. Missing any of them creates a gap that gets filled by improvisation, and improvisation is exactly what the policy exists to eliminate.
The mission and risk appetite statement matters more than it looks. One or two paragraphs stating what the credit function optimizes for: for example, 'We extend credit to support profitable sales growth while keeping bad-debt expense below 0.4% of credit sales and DSO within 8 days of weighted average terms.' Every downstream rule should be traceable to this statement. If your appetite statement says growth-supportive and your investigation requirements demand audited financials for $20,000 accounts, the policy contradicts itself.
- Mission and risk appetite: what credit optimizes for, with numeric targets (bad-debt %, DSO band)
- Credit application requirements: what every applicant must provide before any account opens
- Investigation standards by exposure tier: what gets checked at each dollar level
- Approval authority matrix: who can approve what, by amount and condition
- Terms standards: the default terms offered, and who can deviate
- Credit limit methodology: how limits are calculated, not just who sets them
- Review cadence: when existing accounts get re-underwritten
- Credit hold and release rules: automatic triggers and who can override
- Collections escalation path: the timeline from past-due to third party
- Write-off authority: who can recognize a loss, at what thresholds, with what documentation
Tier investigation depth by exposure
The single most common failure in credit policies is uniform investigation: every applicant gets the same checklist regardless of exposure. The result is that $5,000 accounts wait a week for trade references that tell you nothing, while $250,000 accounts get the same shallow review because the process was built for volume. Tier the work so effort tracks dollars at risk.
A three-tier structure covers most businesses. For requested limits under $10,000, run a bureau report and check for open judgments, liens, and severe delinquency; if the score clears your threshold, approve same-day without references. Between $10,000 and $50,000, add three trade references (verify high credit and payment habits, not just existence), bank reference where available, and a check of years in business and ownership. Above $50,000, require financial statements, at minimum a current balance sheet and income statement, calculate your standard ratios (current ratio, debt-to-equity, and a cash-flow proxy), and consider a personal guarantee if the entity is thin.
Set the tier boundaries from your own portfolio math, not from this article. A useful rule: your top tier should start roughly where a single loss would be visible in your annual bad-debt line. If bad debt runs $300,000 a year, a $50,000 single-account loss is 17% of it and deserves financial-statement scrutiny. Also define what happens when data is missing: if a Tier 2 applicant refuses references, the policy should say whether the file is declined, downgraded to a lower starting limit, or escalated, rather than leaving it to mood.
Terms, limits, and review cadence
The terms section should name your standard offering, commonly net 30, and enumerate the permitted variants: net 60 for specific customer classes, 2/10 net 30 where early-pay discounts are strategic, cash-in-advance or credit-card-only for accounts that fail underwriting. Every variant needs an owner: who is allowed to grant net 60, and does it require the same authority as a limit increase? Unmanaged terms drift is one of the quietest ways DSO deteriorates; a portfolio that migrates from an average of 32 days of terms to 41 will show a 9-day DSO increase with no change in payment behavior at all.
For limit methodology, the policy should name the calculation method (or methods, by tier) rather than just saying limits are 'based on creditworthiness.' Whether you use a percentage of tangible net worth, a requirement-based calculation from expected purchase volume, or a scorecard-driven table, write the formula down so two analysts produce the same number. The methodology deserves its own detailed treatment, and it should live in the policy, not in one analyst's head.
Review cadence closes the loop. New accounts deserve a first review at 6 months; established accounts, annually. Tie review depth to the same exposure tiers as origination. Then add event-driven triggers that force an off-cycle review: a payment that goes 30+ days beyond terms, an NSF check, a bureau alert, a limit utilization that exceeds 85% for two consecutive months, or news of ownership change. Calendar-only review programs miss the deterioration that happens between anniversaries, which is where most large losses incubate.
Exceptions: the part that decides whether the policy survives
Every policy will be overridden. The question is whether overrides happen silently or through a documented exception process. A policy with no exception mechanism gets ignored the first time it collides with a strategically important deal, and once ignored once, it is ignored forever. Build the pressure valve in deliberately.
A workable exception rule has four parts. The override must be written, an email or system note, never verbal. It must name the specific policy provision being waived and the business justification. It must be approved one authority level above the level that would have approved the conforming decision, so a $50,000 exception needs the signature that a $100,000 conforming approval would need. And it must carry an expiry or review date, typically 90 days, so exceptions do not silently become the new normal.
Then measure them. Track the exception rate monthly: exceptions as a percentage of decisions. A healthy portfolio runs somewhere under 5%. If exceptions climb toward 15%, the policy is miscalibrated for the business you actually have, and the fix is to revise the policy, not to keep signing waivers. Exception tracking is also the best early-warning input to your annual policy review, because it shows exactly where the written rules and commercial reality are grinding against each other.
Keeping the policy alive
A credit policy decays. Terms creep, new market segments appear, the risk appetite that was right at $50M in revenue is wrong at $150M. Schedule a formal annual review with a fixed agenda: bad-debt actuals versus the appetite statement, DSO versus target, exception log analysis, authority matrix fit against current org chart, and threshold recalibration against inflation and average order growth. A threshold set at $10,000 in 2019 is doing a different job in 2026.
Version the document like code. Every revision gets a version number, an effective date, a changelog entry, and an approver. When an auditor or a new hire asks why a 2024 decision looks wrong under the current policy, the answer should be 'it was compliant under v3.2, here is what changed in v4.0' rather than a shrug. Keep superseded versions accessible.
Finally, make the current version findable and short enough to be read. Publish it where analysts actually work, and consider a one-page quick-reference card with the tiers, the authority matrix, and the hold triggers. If the only complete copy lives in a 40-page PDF on a shared drive, the real policy is whatever people remember of it.
Starter outline: your first draft checklist
Use this as the skeleton for a first draft. Filling it in honestly, with your real numbers and your real org chart, takes most teams under a week, and a rough complete policy beats a polished incomplete one.
Draft it with the people who will live under it. A half-day session with the credit team, the controller, and one sales leader surfaces the friction points before they become exceptions, and the co-authorship buys compliance that a top-down memo never will.
- Purpose and risk appetite: 2 paragraphs, with numeric bad-debt and DSO targets
- Scope: which entities, geographies, and sale types the policy covers
- Credit application: required fields, signatory requirements, personal guarantee language
- Investigation tiers: 3 exposure bands with required evidence per band
- Scoring and decision criteria: score floors, ratio minimums, automatic-decline conditions
- Limit methodology: the formula(s), by tier, with a worked example
- Terms standards: default terms, permitted variants, and who approves deviations
- Approval authority matrix: dollar bands x roles, plus forced-escalation conditions
- Account review: cadence by tier plus event-driven triggers
- Credit hold: automatic triggers, release authority, and sales notification protocol
- Collections escalation: timeline from day 1 past due to agency/legal referral
- Write-offs: authority thresholds, required documentation, recovery handling
- Exceptions: documentation, elevated approval, expiry, and monthly tracking
- Version control: version number, effective date, changelog, annual review date
About the author
SGUTTI · Founder, EFILOS
SGUTTI is the founder of EFILOS and the architect of SCREDIT, the trade-credit operating platform. He writes about credit operations, financial statement analysis, and receivables management based on the workflows SCREDIT is built around.
Connect on LinkedIn