RiskFits

How to Write a Credit Policy: A Step-by-Step Guide

How to write your company's credit policy: risk appetite, customer segments, underwriting criteria, credit limits, approval authority, exceptions and review. With a document outline.

· 5 min read

A credit policy is the document that says who can buy on terms, how much they can buy, under what conditions, and who signs off. When it does not exist in writing, the decision lives in two or three people's heads — and the result is inconsistency: the same customer profile gets approved one week and declined the next, depending on who looked at it.

This guide covers how to build the policy from scratch, section by section, and what has to be decided before you write the first line.

What a credit policy has to answer

Content comes before format. A policy is only useful if a new analyst can reach the right decision by reading the document, without asking anyone. In practice, it needs to answer:

Step 1: define risk appetite

Risk appetite is how much loss the company accepts in exchange for selling more. It is a decision for ownership, not for the analyst, and it has to be expressed as a number: maximum acceptable bad debt as a percentage of credit sales — typically between 0.5% and 3%, depending on margin.

Without that number, every approve-or-decline discussion is opinion. With it, the yardstick is objective: a policy producing losses above the ceiling is too loose, and one producing losses far below it is probably declining good customers.

High margin absorbs more bad debt. A business running 60% gross margin recovers one write-off with two more sales; a distributor at 8% needs twelve.

Step 2: segment the customer base

The same process cannot apply to an $800 order and a $300,000 one. Segment by size, channel or total exposure, and define a workflow for each group:

ExposureAnalysisDecision
Up to $5,000Automated bureau and public record checkAutomatic
$5,000 to $50,000Score, internal payment history, business dataCredit analyst
Above $50,000Financial statements and trade referencesCredit committee

Step 3: write the underwriting criteria

A criterion is a verifiable rule, not an impression. "Reputable customer" is not a criterion; "no unsatisfied judgments in the last 24 months" is. For every data source, define what declines, what approves, and what routes to manual review.

Split the criteria into three blocks:

  1. Knockouts — bankruptcy filing, inactive entity registration, falsified documents. These decline on their own.
  2. Scored factors — business credit score, years in business, revenue, internal payment history. These add or subtract.
  3. Offsettable factors — smaller derogatory marks that can be accepted with a personal guarantee, a deposit or a reduced limit.

Step 4: set limits and approval authority

The limit answers "how much"; approval authority answers "who signs." Both belong in a table with explicit cutoffs. See how to set a credit limit for the calculation methods and credit approval authority levels for the sign-off tiers.

Rule of thumb: if more than 20% of applications escalate to the top tier, your limits are miscalibrated — and the committee has become an operational bottleneck.

Step 5: handle exceptions in writing

Exceptions will happen: a strategic account, a large order at month end, an opportunity that will not wait for the full process. The mistake is not granting the exception — it is granting it without a record.

The policy has to say who can approve outside the rules, what the ceiling on that authority is, what must be documented, and how long the exception stays valid. An exception with no expiration quietly becomes the rule.

Step 6: establish the review cycle

A limit approved two years ago, based on financials from three years ago, says nothing about today's risk. Set review frequency by exposure tier — annual for small accounts, semiannual for material ones — plus triggers that pull the review forward, such as a past-due balance over 15 days or a new derogatory filing.

Suggested document outline

  1. Purpose and scope
  2. Definitions and responsibilities
  3. Risk appetite and tracking metrics
  4. Application: required documents and verifications
  5. Underwriting criteria by segment
  6. Credit limit methodology
  7. Approval authority matrix
  8. Accepted collateral and guarantee requirements
  9. Exceptions: who approves and how they are logged
  10. Monitoring and limit reviews
  11. Dunning process and past-due handling
  12. Version control

What turns a policy into dead paper

What to take from this

A credit policy is not a compliance artifact to show an auditor: it is the work instruction for whoever decides. Write it detailed enough that a new analyst can decide alone, put a number on everything you can, and set the review date before you publish it.

Related reading