A corporate credit card policy is the written document that says who gets a company card, what they may buy with it, what receipt each purchase needs, how fast expenses must be coded, and what happens when someone breaks the rules. It should be one page a cardholder can actually read, signed before the card is handed over, and backed by controls that catch violations automatically rather than at month end.
Most companies write this document twice. The first version gets drafted the week the cards arrive, lands in a shared drive, and is never opened again. The second version gets written after somebody expenses a $600 dinner, or after an auditor asks for the receipt file and half of it is missing. The second version is always better, because by then you know which rules people actually break. This is an attempt to skip to the second version.
What should be included in a corporate credit card policy?
A corporate credit card policy should cover eleven things: who is eligible for a card, spending limits, approved and prohibited purchases, receipt and documentation rules, submission deadlines, the approval chain, personal use, lost or stolen cards, what happens when someone leaves, consequences for misuse, and a signed acknowledgment. Anything shorter leaves a gap someone will find.
Here is that list expanded into the sections a policy actually needs, with the decision each one has to make. Write the decision, not the philosophy. A policy that says spending should be reasonable and appropriate has decided nothing.
| Section | The decision it has to make | Common mistake |
|---|---|---|
| Eligibility | Which roles get a card, who approves the request, and whether contractors ever do | Issuing by seniority instead of by need, so directors who never travel hold cards |
| Spending limits | A per transaction limit and a monthly limit, per role or per card | One company-wide limit, which is too tight for the sales team and too loose for everyone else |
| Approved purchases | The named categories a card may be used for, with examples | Listing only what is banned, which implies everything else is allowed |
| Prohibited purchases | Cash advances, gift cards, personal items, alcohol if you restrict it, anything requiring a signed contract | Forgetting recurring software, so anyone can start a subscription nobody tracks |
| Receipt rules | What counts as documentation, and the dollar threshold above which it is mandatory | Copying the $75 rule from somewhere and dropping the lodging half of it |
| Business purpose | That every charge carries who, what and why, not just a merchant name | Accepting the merchant name as the explanation, which fails in an audit |
| Submission deadline | A specific number of days, tied to your close calendar | Saying promptly. Nobody has ever met a deadline called promptly |
| Approval chain | Who approves what, and what happens above a threshold | Routing everything to one person, who becomes the bottleneck and starts rubber stamping |
| Personal use | Whether accidental personal charges are allowed at all, and how they get repaid | Silence, which is read as permission |
| Lost, stolen or compromised cards | Who to call, within how long, and who freezes the card | Naming a person rather than a role, so the policy breaks when that person leaves |
| Offboarding | That the card is cancelled on the last day and outstanding expenses are cleared first | Cancelling the card but leaving three subscriptions billing to it |
| Consequences | The actual escalation path, from a warning to repayment to termination | Threatening consequences without naming any, which makes the whole policy advisory |
What is the difference between a corporate card and a business credit card?
A business credit card is usually opened by the owner, underwritten against their personal credit, and carries a personal guarantee, so the owner is personally on the hook if the business does not pay. A corporate card program is underwritten against the company and issued to employees under the company's liability. The practical difference for your policy is who eats a bad charge.
That distinction changes how strict the document needs to be. On a small business credit card with two authorized users, an informal rule usually holds. Once you are handing plastic to fifteen people who do not report to you, the policy is the only control that scales, because you cannot personally see every transaction anymore.
Who is liable for a corporate credit card?
It depends on the liability model your issuer wrote into the program. Corporate liability means the company pays the issuer and pursues the employee internally. Individual liability means the employee is billed and claims reimbursement. Joint liability splits it. Read your card agreement, then state the model in the policy in plain language, because cardholders assume corporate liability by default and are frequently wrong.
Do I need receipts for company credit card purchases?
For tax substantiation, yes, in two situations. Under 26 CFR 1.274-5, documentary evidence is required for all lodging expenses regardless of amount, and for any other expenditure of $75 or more. The widely repeated shorthand that receipts are only needed over $75 quietly drops the lodging half, and lodging is the first thing an examiner asks to see.
The credit card statement alone is not documentary evidence in the sense the regulation means. It shows amount, date and merchant, but not what was bought or why, and business purpose is the element people fail on. A hotel folio, an itemized restaurant receipt or a software invoice carries the detail; the statement line carries none of it. Many companies set an internal receipt threshold well below $75, often at $25 or even at zero, simply because one rule is easier to enforce than two.
Meals deserve their own line in the policy. Business meals are generally 50 percent deductible under the Internal Revenue Code, and a meal without an attendee list and a business purpose is difficult to defend at any percentage. If your policy asks for one thing beyond the receipt, make it the names of who was there.
What happens if an employee misuses a company credit card?
Whatever your policy says will happen, applied the same way every time. That is the part that matters. An unenforced consequence is worse than none, because it establishes that the policy is decorative. Most companies land on a graduated path: a first accidental personal charge gets a warning and repayment through payroll deduction or a direct transfer, a repeated pattern goes to a formal performance conversation, and deliberate misuse is a termination and potentially a police matter.
Two cautions before you write the repayment clause. Payroll deduction for a personal charge is governed by state wage law, and several states restrict deductions from wages or require written employee authorization first, so have counsel review that specific sentence. Separately, if the company covers a personal charge and never collects it, that value generally becomes taxable compensation to the employee rather than a business expense, which is a payroll problem and not just a housekeeping one. Neither of these is a reason to skip the clause. They are reasons to write it once, correctly, with your own advisers.
How do you enforce a corporate credit card policy?
You enforce it by checking transactions against it as they land, not by reading statements at month end. By the time a statement arrives, the money is gone, the receipt is lost, and the conversation is retrospective and awkward. The controls that actually work are card level limits and merchant category restrictions set at the issuer, a receipt requirement enforced at submission, an approval routed automatically above a threshold, and a policy check applied to every transaction as it posts.
This is where expense policy software earns its keep. The policy stops being a document people remember and becomes a rule the system applies, so an out of policy charge surfaces the same day rather than three weeks later. The same machinery handles the boring half of the job: reading the receipt, coding it to the right general ledger account, and matching it to the card transaction so the corporate card reconciliation is not a spreadsheet exercise every month.
Pay attention to the recurring charges in particular. Corporate cards are how most SaaS subscriptions enter a company, and nobody writes a policy line for the tool a team signed up for in March and stopped using in June. Reviewing card spend for duplicate subscriptions before each renewal usually pays for the whole control program on its own.
How do you get employees to actually follow it?
Three things move compliance more than the wording does. Make the submission path faster than not submitting, because most late expense reports are friction, not defiance. Get a signed acknowledgment before the card is handed over, which is both a legal record and the only moment a cardholder reads the document with any attention. And put the policy where it gets refreshed rather than filed, which for most companies means running it through the same onboarding and training system that tracks every other acknowledgment, so you can prove who agreed to what and when.
Review the document once a year and after any incident. A policy written when eight people had cards will not survive forty. If you are also picking software at the same time, be careful about what you are actually buying: a platform that requires you to move your card program to get good pricing is making a different trade than a tool that works on the cards you already carry, and the same is true of suites that price expenses as one module on a required platform, as our breakdown of Rippling pricing walks through in detail.
A corporate credit card policy outline you can copy
Use this as a skeleton and fill in your own numbers. It is deliberately short, because a policy nobody finishes reading controls nothing.
- Purpose and scope. One sentence on why the program exists and who it applies to.
- Eligibility and issuance. Who qualifies, who approves, how a card is requested.
- Limits. Per transaction and monthly limits by role, and how to request a temporary increase.
- Permitted use. Named categories with examples: travel, client meals, approved software, supplies.
- Prohibited use. Cash advances, gift cards, personal purchases, anything requiring a signed contract, any new recurring subscription without approval.
- Documentation. Itemized receipt required for lodging regardless of amount and for anything at or above your threshold, plus business purpose and attendees for meals.
- Deadlines. Expenses coded and submitted within a set number of days, aligned to your close.
- Approvals. Manager approval as standard, with a named second approver above a stated amount.
- Personal charges. Whether permitted, how reported, how repaid, and by when.
- Lost, stolen or suspected fraud. The role to contact and the time limit.
- Departure. Card cancelled on the final day, outstanding expenses submitted first, subscriptions transferred.
- Violations. The escalation path, stated plainly.
- Acknowledgment. Signature and date, collected before issuance.
If you already have an expense policy, do not duplicate it here. The card policy governs the instrument and the expense policy governs the spending; keep the rates, per diems and reimbursement mechanics in the expense document and cross reference it. Our guide to what to include in a company expense policy covers that side, and if you reimburse mileage or pay per diems, the accountable plan rules decide whether those payments stay off the W-2.
This article is general information about building an internal control, not legal, tax or accounting advice. Wage deduction rules and the tax treatment of employee charges vary by state and by facts, so review your policy with your own counsel and accountant before you issue it.