Expenditure
How it works Security Pricing Blog
All articles Policy

Corporate Credit Card Policy: What a Company Credit Card Policy for a Business Must Include

The 13 sections a corporate credit card policy needs, the IRS receipt rule most policies get wrong, who is liable, and how to enforce it before month end.

By the Expenditure team · 8 min read · Last updated August 2026

Spend Desk
We never move your money
Drop a receipt, snap a photo, or forward an email
Sample
Connected

Receipts in, categorized spend out

Expenditure reads the vendor, amount, date and tax, categorizes the expense, checks it against your policy, and rolls it into a real-time picture of every dollar, then flags the waste.

Receipt OCR Category GL Policy ✓ Spend
↓ pick a sample receipt and hit Extract

Reading your receipt

Working

Not financial advice · we never move your money

Extracted & categorized

Real-time spend

Month to date

+ just now

save /mo

Live, interactive · categorized in seconds

Categorized & policy-checked · works with your existing cards · we never move your money · insights, not financial advice

A corporate credit card policy is the written document that says who gets a company card, what they may buy with it, what receipt each purchase needs, how fast expenses must be coded, and what happens when someone breaks the rules. It should be one page a cardholder can actually read, signed before the card is handed over, and backed by controls that catch violations automatically rather than at month end.

Most companies write this document twice. The first version gets drafted the week the cards arrive, lands in a shared drive, and is never opened again. The second version gets written after somebody expenses a $600 dinner, or after an auditor asks for the receipt file and half of it is missing. The second version is always better, because by then you know which rules people actually break. This is an attempt to skip to the second version.

What should be included in a corporate credit card policy?

A corporate credit card policy should cover eleven things: who is eligible for a card, spending limits, approved and prohibited purchases, receipt and documentation rules, submission deadlines, the approval chain, personal use, lost or stolen cards, what happens when someone leaves, consequences for misuse, and a signed acknowledgment. Anything shorter leaves a gap someone will find.

Here is that list expanded into the sections a policy actually needs, with the decision each one has to make. Write the decision, not the philosophy. A policy that says spending should be reasonable and appropriate has decided nothing.

SectionThe decision it has to makeCommon mistake
EligibilityWhich roles get a card, who approves the request, and whether contractors ever doIssuing by seniority instead of by need, so directors who never travel hold cards
Spending limitsA per transaction limit and a monthly limit, per role or per cardOne company-wide limit, which is too tight for the sales team and too loose for everyone else
Approved purchasesThe named categories a card may be used for, with examplesListing only what is banned, which implies everything else is allowed
Prohibited purchasesCash advances, gift cards, personal items, alcohol if you restrict it, anything requiring a signed contractForgetting recurring software, so anyone can start a subscription nobody tracks
Receipt rulesWhat counts as documentation, and the dollar threshold above which it is mandatoryCopying the $75 rule from somewhere and dropping the lodging half of it
Business purposeThat every charge carries who, what and why, not just a merchant nameAccepting the merchant name as the explanation, which fails in an audit
Submission deadlineA specific number of days, tied to your close calendarSaying promptly. Nobody has ever met a deadline called promptly
Approval chainWho approves what, and what happens above a thresholdRouting everything to one person, who becomes the bottleneck and starts rubber stamping
Personal useWhether accidental personal charges are allowed at all, and how they get repaidSilence, which is read as permission
Lost, stolen or compromised cardsWho to call, within how long, and who freezes the cardNaming a person rather than a role, so the policy breaks when that person leaves
OffboardingThat the card is cancelled on the last day and outstanding expenses are cleared firstCancelling the card but leaving three subscriptions billing to it
ConsequencesThe actual escalation path, from a warning to repayment to terminationThreatening consequences without naming any, which makes the whole policy advisory

What is the difference between a corporate card and a business credit card?

A business credit card is usually opened by the owner, underwritten against their personal credit, and carries a personal guarantee, so the owner is personally on the hook if the business does not pay. A corporate card program is underwritten against the company and issued to employees under the company's liability. The practical difference for your policy is who eats a bad charge.

That distinction changes how strict the document needs to be. On a small business credit card with two authorized users, an informal rule usually holds. Once you are handing plastic to fifteen people who do not report to you, the policy is the only control that scales, because you cannot personally see every transaction anymore.

Who is liable for a corporate credit card?

It depends on the liability model your issuer wrote into the program. Corporate liability means the company pays the issuer and pursues the employee internally. Individual liability means the employee is billed and claims reimbursement. Joint liability splits it. Read your card agreement, then state the model in the policy in plain language, because cardholders assume corporate liability by default and are frequently wrong.

Do I need receipts for company credit card purchases?

For tax substantiation, yes, in two situations. Under 26 CFR 1.274-5, documentary evidence is required for all lodging expenses regardless of amount, and for any other expenditure of $75 or more. The widely repeated shorthand that receipts are only needed over $75 quietly drops the lodging half, and lodging is the first thing an examiner asks to see.

The credit card statement alone is not documentary evidence in the sense the regulation means. It shows amount, date and merchant, but not what was bought or why, and business purpose is the element people fail on. A hotel folio, an itemized restaurant receipt or a software invoice carries the detail; the statement line carries none of it. Many companies set an internal receipt threshold well below $75, often at $25 or even at zero, simply because one rule is easier to enforce than two.

Meals deserve their own line in the policy. Business meals are generally 50 percent deductible under the Internal Revenue Code, and a meal without an attendee list and a business purpose is difficult to defend at any percentage. If your policy asks for one thing beyond the receipt, make it the names of who was there.

What happens if an employee misuses a company credit card?

Whatever your policy says will happen, applied the same way every time. That is the part that matters. An unenforced consequence is worse than none, because it establishes that the policy is decorative. Most companies land on a graduated path: a first accidental personal charge gets a warning and repayment through payroll deduction or a direct transfer, a repeated pattern goes to a formal performance conversation, and deliberate misuse is a termination and potentially a police matter.

Two cautions before you write the repayment clause. Payroll deduction for a personal charge is governed by state wage law, and several states restrict deductions from wages or require written employee authorization first, so have counsel review that specific sentence. Separately, if the company covers a personal charge and never collects it, that value generally becomes taxable compensation to the employee rather than a business expense, which is a payroll problem and not just a housekeeping one. Neither of these is a reason to skip the clause. They are reasons to write it once, correctly, with your own advisers.

How do you enforce a corporate credit card policy?

You enforce it by checking transactions against it as they land, not by reading statements at month end. By the time a statement arrives, the money is gone, the receipt is lost, and the conversation is retrospective and awkward. The controls that actually work are card level limits and merchant category restrictions set at the issuer, a receipt requirement enforced at submission, an approval routed automatically above a threshold, and a policy check applied to every transaction as it posts.

This is where expense policy software earns its keep. The policy stops being a document people remember and becomes a rule the system applies, so an out of policy charge surfaces the same day rather than three weeks later. The same machinery handles the boring half of the job: reading the receipt, coding it to the right general ledger account, and matching it to the card transaction so the corporate card reconciliation is not a spreadsheet exercise every month.

Pay attention to the recurring charges in particular. Corporate cards are how most SaaS subscriptions enter a company, and nobody writes a policy line for the tool a team signed up for in March and stopped using in June. Reviewing card spend for duplicate subscriptions before each renewal usually pays for the whole control program on its own.

How do you get employees to actually follow it?

Three things move compliance more than the wording does. Make the submission path faster than not submitting, because most late expense reports are friction, not defiance. Get a signed acknowledgment before the card is handed over, which is both a legal record and the only moment a cardholder reads the document with any attention. And put the policy where it gets refreshed rather than filed, which for most companies means running it through the same onboarding and training system that tracks every other acknowledgment, so you can prove who agreed to what and when.

Review the document once a year and after any incident. A policy written when eight people had cards will not survive forty. If you are also picking software at the same time, be careful about what you are actually buying: a platform that requires you to move your card program to get good pricing is making a different trade than a tool that works on the cards you already carry, and the same is true of suites that price expenses as one module on a required platform, as our breakdown of Rippling pricing walks through in detail.

A corporate credit card policy outline you can copy

Use this as a skeleton and fill in your own numbers. It is deliberately short, because a policy nobody finishes reading controls nothing.

  1. Purpose and scope. One sentence on why the program exists and who it applies to.
  2. Eligibility and issuance. Who qualifies, who approves, how a card is requested.
  3. Limits. Per transaction and monthly limits by role, and how to request a temporary increase.
  4. Permitted use. Named categories with examples: travel, client meals, approved software, supplies.
  5. Prohibited use. Cash advances, gift cards, personal purchases, anything requiring a signed contract, any new recurring subscription without approval.
  6. Documentation. Itemized receipt required for lodging regardless of amount and for anything at or above your threshold, plus business purpose and attendees for meals.
  7. Deadlines. Expenses coded and submitted within a set number of days, aligned to your close.
  8. Approvals. Manager approval as standard, with a named second approver above a stated amount.
  9. Personal charges. Whether permitted, how reported, how repaid, and by when.
  10. Lost, stolen or suspected fraud. The role to contact and the time limit.
  11. Departure. Card cancelled on the final day, outstanding expenses submitted first, subscriptions transferred.
  12. Violations. The escalation path, stated plainly.
  13. Acknowledgment. Signature and date, collected before issuance.

If you already have an expense policy, do not duplicate it here. The card policy governs the instrument and the expense policy governs the spending; keep the rates, per diems and reimbursement mechanics in the expense document and cross reference it. Our guide to what to include in a company expense policy covers that side, and if you reimburse mileage or pay per diems, the accountable plan rules decide whether those payments stay off the W-2.

This article is general information about building an internal control, not legal, tax or accounting advice. Wage deduction rules and the tax treatment of employee charges vary by state and by facts, so review your policy with your own counsel and accountant before you issue it.

See it on your own spend

Expenditure reads your receipts, categorizes every expense, checks your policy and flags the waste, all on the cards and banks you already have.

Explore features

See where every dollar goes, and where you are wasting it.

Receipts read and categorized, policy enforced, real-time spend, and the duplicate subscriptions and savings flagged. It works with the cards you already have.

See pricing

Receipts in, categorized spend out · real-time budgets · waste flagged · we never move your money