Procurement Policy: How to Write One That Works

Procurement Policy: How to Write One That Works

2026-10-02 · Tommaso Maria Ricci

Corruption showed up in 45% of the 2,402 occupational fraud cases analyzed in the ACFE's 2026 Report to the Nations, and more than half of all cases involved either missing internal controls or an override of the ones that existed. Most of those schemes run through the same door: someone buys something, from someone, without anyone else looking. A procurement policy is the document that decides who looks, when, and with what authority. Most companies either do not have one, or have one nobody follows.

This guide is about how to write a procurement policy that people actually use. You will get the sections every policy needs, approval thresholds you can adapt, the controls that matter most, a self-assessment scorecard, a 30/60/90-day rollout plan and the mistakes I see most often. No template full of legal boilerplate: the goal is a policy that a busy department head can read in ten minutes and follow without calling finance.

What a procurement policy is, and what it is not

A procurement policy is a short set of rules that governs how your company spends money with outside parties: who can commit spend, how suppliers are chosen, what approvals are required at which amounts, and what documentation must exist before a payment goes out.

It is worth separating it from three things it often gets confused with.

  • Procurement process. The process is the sequence of steps, from request to payment. The policy is the set of rules that the process enforces. If you want the step-by-step view, our guide to the procure to pay process and its controls covers it end to end.
  • Expense policy. An expense policy governs what employees spend on the company's behalf and then claim back: travel, meals, small purchases on a corporate card. It is a neighbor of the procurement policy, not a substitute. We covered it in detail in how to write an expense policy.
  • Procurement procedures manual. In larger organizations, a manual sits under the policy and describes, screen by screen, how to raise a purchase requisition in the ERP. Small and mid-sized companies rarely need one. They need a clear policy and a system that enforces it.

The test of a good procurement policy is simple. A new manager, on their second day, should be able to answer three questions by reading it: can I buy this, from whom, and who needs to approve it?

Why a procurement policy matters more than most companies think

Fraud and leakage

The ACFE's key findings from Occupational Fraud 2026 are useful here because they describe what happens when purchasing is uncontrolled. The study covered 2,402 cases across 143 countries and territories, with total losses above $3.4 billion and a median loss of $104,000 per case. Corruption, which includes bribery and conflicts of interest in purchasing, appeared in 45% of cases. Schemes ran for a median of 12 months before detection, and the longer they ran, the more they cost.

Procurement is where corruption lives because it is where money leaves the company toward outside parties who benefit from the decision. A supplier who pays a kickback, an employee who owns part of a vendor, a split purchase designed to stay under an approval threshold: none of these require sophisticated technology. They require the absence of a rule, or a rule nobody checks.

Money left on the table

Fraud is the dramatic risk. The everyday risk is quieter. When every department buys on its own, from its own preferred suppliers, at whatever price the supplier quotes, the company loses volume discounts, pays for duplicate subscriptions and signs contracts with terms nobody reviewed. Procurement teams call this maverick spend: purchases made outside agreed suppliers and agreed processes.

Procurement is becoming strategic

Deloitte's 2025 Global Chief Procurement Officer Survey, based on more than 250 CPOs in 40 countries, found that the most digitally mature procurement organizations allocate up to 24% of their budgets to technology, nearly double the 2023 level. The same survey lists siloed operations (57%) and competing priorities (46%) as the main barriers to progress. A clear policy is the cheapest fix for silos: it gives every department the same rules before any software is bought.

Some organizations are required to have one

If your organization receives US federal grants, a written procurement standard is not optional. Under 2 CFR 200.318, recipients must maintain documented procurement procedures and written standards of conduct covering conflicts of interest, including a ban on employees soliciting or accepting gratuities from contractors. Even if you never touch federal money, those requirements are a good checklist of what a serious policy covers.

How to write a procurement policy: the 10 sections every policy needs

Here is the structure I recommend. Each section should be short. If a section needs more than a page, it probably belongs in a procedure or a system configuration, not in the policy.

1. Purpose and scope

Two or three sentences. Why the policy exists and what spend it covers. Be explicit about what is out of scope, because that is where confusion starts:

  • payroll and employee benefits;
  • taxes and statutory payments;
  • intercompany transfers;
  • employee expenses covered by the expense policy;
  • capital expenditure, if you have a separate capex approval process.

If capital spending follows its own rules, link to them. Our guide to the capex approval process explains how to set those thresholds.

2. Roles and responsibilities

Name the roles, not the people. A typical small or mid-sized company needs five:

  1. Requester. The person who needs the goods or service and raises the request.
  2. Budget owner. The person accountable for the cost center or project that will carry the cost.
  3. Procurement or finance reviewer. The person who checks supplier, price and contract terms. In small companies this is often the controller.
  4. Approver. The person with authority to commit the company at the requested amount.
  5. Accounts payable. The team that matches invoice, order and receipt before paying.

The key rule: the requester and the approver are never the same person, and the person who approves a supplier is never the person who pays it. That is segregation of duties applied to purchasing. If you have not mapped it yet, our segregation of duties matrix guide shows how to do it even with a small team.

3. Approval thresholds

This is the section people read, so make it a table. The thresholds below are an illustrative starting point for a company with $10 million to $100 million in revenue. Adjust them to your size and risk tolerance.

| Amount per purchase or contract | Quotes required | Approver | Purchase order |

|---|---|---|---|

| Under $2,500 | None, use preferred supplier if one exists | Budget owner | Optional, corporate card allowed |

| $2,500 to $25,000 | 2 written quotes | Budget owner plus finance | Required |

| $25,000 to $100,000 | 3 written quotes or documented sole source | Department head plus CFO | Required |

| Over $100,000 | Formal competitive process | CEO or board as defined | Required, with signed contract |

Three details make or break this table:

  • Measure the total commitment, not the invoice. A $4,000 per month subscription on a 24-month contract is a $96,000 decision, not a $4,000 one.
  • Ban splitting explicitly. Breaking a purchase into smaller pieces to stay under a threshold is a policy violation, and the policy should say so in plain words.
  • Review thresholds every year. Inflation and growth move the right numbers. A threshold set five years ago may now send trivial purchases to the CFO and real ones nowhere.

4. Supplier selection and onboarding

The policy should say how suppliers get on the approved list and what checks happen before the first payment. At a minimum:

  • legal identity and tax registration;
  • bank details verified through a channel independent of the email that sent them;
  • sanctions and basic reputational screening;
  • insurance and certifications where relevant;
  • conflict of interest declaration by the requester.

Bank detail verification deserves its own line. Vendor impersonation and business email compromise remain among the most common ways companies lose money: a fraudster sends a convincing email asking to update bank details, and the next payment goes to the wrong account. The fix is procedural, not technical: any change to bank details is confirmed by phone to a number already on file, never to one provided in the request. Our guide to the vendor onboarding process walks through each check in detail.

5. Competitive quotes and sole sourcing

When quotes are required, the policy should define what counts: written, comparable, from independent suppliers, dated, and kept on file. Three quotes from companies owned by the same person are not three quotes.

Sole sourcing is legitimate and sometimes the right call: a unique technology, an urgent repair, a supplier with proprietary knowledge of your systems. The policy should allow it with a short written justification approved one level above the normal approver. The justification forces someone to think, and it leaves a trail.

6. Purchase orders and contracts

Define when a purchase order is mandatory and what it must contain: supplier, description, quantity, price, delivery terms, cost center. The principle that saves the most trouble is no PO, no pay. If an invoice arrives without an approved purchase order above the threshold, it goes back to the requester, not into the payment run.

For contracts, the policy should specify:

  • who can sign at which amounts;
  • which contracts require legal review;
  • standard terms the company expects, such as payment terms, liability caps, termination rights and data protection clauses;
  • where signed contracts are stored and who tracks renewal dates.

Auto renewals are where software spend quietly grows. A renewal calendar with a named owner pays for itself the first time it catches a contract that should have been renegotiated.

7. Conflicts of interest and gifts

State that any employee involved in a purchase must declare a personal or financial interest in a supplier, and must step out of the decision if one exists. Define a gift limit, require gifts above it to be declared, and prohibit gifts of any value during an active tender.

This section is short, but it is the one that protects people as much as the company. An employee who declares a conflict and steps aside is covered. One who stays silent is exposed, even if the decision was fair.

8. Receiving and three-way match

Before paying, someone should confirm that what was ordered actually arrived, in the right quantity and condition. Accounts payable then matches three documents: purchase order, receipt and invoice. Differences above a defined tolerance go back for review.

For services, receipt is harder to define. The policy should name who confirms that a service was delivered, usually the budget owner, and require that confirmation in writing or in the system before payment.

9. Exceptions and emergencies

Real businesses have emergencies: a broken machine on a production line, a security incident on a Friday night. A policy without an emergency path will be ignored, and once it is ignored in emergencies it will be ignored everywhere.

Define an emergency procedure: who can authorize spending outside the normal flow, up to what amount, and the requirement to regularize the paperwork within a fixed number of working days. Then report every exception monthly. If exceptions grow, the policy is wrong or people are abusing it, and both need fixing.

10. Monitoring, consequences and review

Close with how compliance is checked and what happens when it is not:

  • monthly reporting on spend without a PO, sole source purchases and exceptions;
  • periodic review of the supplier master file for duplicates and dormant suppliers;
  • a clear statement that violations may lead to disciplinary action;
  • an annual review of the whole policy, with a named owner.

Procurement policy approval thresholds by company size

The table above is a starting point. Here is how I adapt it to different sizes.

Fewer than 20 employees. Two levels are enough. The founder or managing director approves anything above a low threshold, and finance reviews payments. The biggest risk is not fraud but invisible recurring spend: subscriptions, services on autopilot, contracts nobody remembers signing.

20 to 200 employees. Three or four levels, with department heads approving within their budgets and the CFO above a defined amount. This is the size at which a purchase order system starts paying for itself, and at which segregation of duties becomes realistic.

Over 200 employees. A dedicated procurement function, category strategies for the main spend areas, framework agreements with preferred suppliers and a formal tender process for large contracts. The policy stays short; the detail moves into category playbooks.

Whatever your size, one principle holds: the threshold should reflect risk, not hierarchy. A $5,000 contract with a new supplier who will process customer data deserves more scrutiny than a $20,000 order of office furniture from a supplier you have used for ten years.

The controls that matter most

If you can implement only a handful of controls, these are the ones that prevent the most damage.

  1. No PO, no pay above the threshold, enforced in the payment system, not by memory.
  2. Independent verification of bank details for every new supplier and every change.
  3. Separation between who approves suppliers and who pays them.
  4. Three-way match with defined tolerances.
  5. Monthly review of the supplier master file for duplicates, missing tax data and suppliers sharing bank accounts or addresses with employees.
  6. Contract renewal calendar with a named owner.
  7. Exception reporting to the CFO every month.

Notice that none of these require expensive software. They require a decision, an owner and a recurring check. Software makes them cheaper to run, but it does not replace the decision.

Where AI helps in procurement control

AI is genuinely useful in a few areas of procurement, and mostly as a second pair of eyes:

  • Spend classification. Reading invoice lines and assigning them to categories, so you can finally see how much you spend on software or logistics.
  • Anomaly detection. Flagging split purchases just below thresholds, invoices from new suppliers with round amounts, or a supplier whose bank account matches an employee's.
  • Contract review. Extracting renewal dates, notice periods and payment terms from signed contracts and feeding them into the renewal calendar.
  • Policy questions. An assistant that answers "can I buy this, and who approves it?" from the policy text, so managers stop calling finance for every doubt.

Where AI does not help: deciding whether a sole source justification is valid, judging a conflict of interest, or approving spend. Those decisions remain with people who carry the accountability. If you want a broader view, our guide to AI for procurement covers the main use cases and their limits.

If you want to understand which of these controls and tools make sense for your company, and which would add process without adding protection, we can work through it together starting from your real spend data. A consultation request through the website is the right first step.

Special cases: software, contractors and professional services

Most procurement policy templates were written for physical goods. Today, in many companies, the biggest and fastest growing spend is something else. Three categories deserve their own rules.

Software and SaaS

Software is bought with a credit card in five minutes, renews automatically and often processes company or customer data. That combination makes it the category where uncontrolled spend grows fastest. Add three rules to your policy:

  • Every new tool that touches company data needs IT or security review, whatever the price. A free plan can still expose customer records.
  • Annual and multi-year commitments follow the contract value thresholds, not the monthly price.
  • Each subscription has a named owner responsible for usage, renewal and cancellation. When the owner leaves the company, ownership is reassigned before their account is closed.

A quarterly review of active subscriptions against actual usage is one of the fastest savings exercises available to any mid-sized company.

Contractors and freelancers

Contractors are often engaged directly by managers, without a purchase order, on terms agreed by email. The policy should require a written agreement before work starts, define who can engage contractors at which rates and durations, and require the same onboarding checks as any other supplier. In many jurisdictions, how you engage and manage contractors also affects worker classification, so involve HR or legal for long engagements.

Professional services

Consultants, agencies and advisers are hard to compare on price because the scope is different each time. The policy should require a written scope of work with deliverables, a fee structure (fixed, capped or time and materials), and a named internal owner who confirms delivery before invoices are paid. For time and materials engagements, a cap that requires new approval when reached prevents the classic budget that doubles without anyone deciding it should.

Procurement policy metrics worth tracking

A policy without measurement decays. These metrics are simple to produce from accounting data and tell you quickly whether the policy is working.

  1. Spend under management. The share of total spend that went through the defined process with a purchase order and an approved supplier. Track the trend, not the absolute number.
  2. Spend without a PO above threshold. Count and value, by department. This is the clearest compliance signal.
  3. Number of active suppliers. If it keeps growing faster than the business, purchasing is fragmenting.
  4. Exceptions and sole source purchases. Count, value and justification. A rising number is a warning, either of abuse or of a policy that does not fit reality.
  5. Bank detail changes and how they were verified. Every change should have a verification record.
  6. Contracts renewed without review. Each one is a missed negotiation.
  7. Cycle time from request to approved order. If it gets too long, people will route around the policy. Speed is a compliance metric too.

Share these monthly with department heads. Visibility changes behavior faster than enforcement.

How to communicate the policy so people follow it

The best written policy fails if nobody knows it exists. Rollout deserves as much attention as drafting.

  • Lead with the why. Explain the risks in concrete terms: payment fraud, forgotten renewals, duplicated tools. Managers follow rules they understand.
  • Give a one-page summary. The threshold table, the emergency contact, the three most important rules. Put it where people will look when they need it.
  • Train approvers, not everyone. The people who can commit spend need a short session. Everyone else needs to know where to ask.
  • Make the right path the easy path. If raising a purchase order takes ten minutes and buying with a card takes one, you know what will happen. Fix the process before blaming people.
  • Celebrate catches. When the bank detail check stops a fraudulent change, tell the company. Nothing builds support for a control like a story of the loss it prevented.

The most common procurement policy mistakes

I have seen procurement policies fail in the same ways across very different businesses.

Writing for the auditor, not the manager. A 40-page document full of definitions and cross references satisfies an audit checklist and is read by nobody. Write for the department head who has five minutes. Put the threshold table on page one.

Thresholds that ignore contract value. Approving the monthly invoice instead of the total commitment lets large multi-year contracts slip through at a low approval level.

No emergency path. Without a legitimate way to move fast, people find illegitimate ones, and the habit spreads.

A policy without a system. If the policy says "no PO, no pay" but the accounting system will pay an invoice without a PO, the policy is a suggestion. Configure the system to enforce the rules that matter.

No consequences, no reporting. If nobody measures compliance, compliance decays within a year. Monthly exception reports, shared with department heads, change behavior faster than any training.

Copying a template from a different industry. A policy written for a public body with tender laws, or for a manufacturer buying raw materials, will not fit a software company whose biggest spend is cloud services and contractors. Start from your own spend analysis.

Forgetting indirect and recurring spend. Many policies focus on large one-off purchases and ignore the long tail of subscriptions, consultants and services that together often exceed them.

Procurement policy vs purchasing policy: does the name matter?

You will see both terms. In practice, many small companies call the document a purchasing policy and larger ones a procurement policy. The distinction, where people make it, is about breadth. Purchasing usually means the transaction: raising an order, receiving goods, paying the invoice. Procurement includes everything upstream: deciding what to buy, choosing suppliers, negotiating contracts and managing supplier relationships over time.

The name matters less than the coverage. If your document only describes how to raise a purchase order, it is missing the decisions that carry most of the risk and most of the savings: which suppliers are approved, how contracts are negotiated, who owns renewals. Whatever you call it, make sure it covers the full cycle, from the moment someone decides they need something to the moment the supplier relationship ends.

A related question is whether the procurement policy should live inside a broader finance policy manual. For companies under a few hundred employees, I prefer a standalone document. It is easier to find, easier to update, and easier to point to when a manager asks why their purchase was sent back.

A worked example: a 60-person company

Consider a 60-person services company with $15 million in revenue. Before writing a policy, the finance lead pulls twelve months of accounts payable data. What they typically find in a company like this:

  • a few hundred active suppliers, many used only once;
  • several overlapping software subscriptions bought by different teams;
  • a handful of contracts on auto renewal that nobody owns;
  • most payments made without a purchase order;
  • bank detail changes accepted by email.

The policy they write fits on four pages. Three approval levels: budget owner under $5,000, department head plus finance up to $50,000, CEO above. Two quotes above $10,000. Mandatory purchase orders above $5,000, enforced in the accounting system. Bank detail changes confirmed by phone to a number on file. A monthly exception report to the CEO.

The policy itself takes two weeks to draft. The harder work is the rollout: configuring the system, cleaning the supplier master file, consolidating subscriptions and explaining the rules to managers. That is where the 90-day plan below comes in.

Self-assessment scorecard: how strong is your procurement policy?

Score each item 0 (no), 1 (partly) or 2 (yes).

Policy and roles

  1. There is a written procurement policy, approved by management, reviewed in the last 12 months.
  2. Roles are defined: requester, budget owner, reviewer, approver, accounts payable.
  3. The requester and the approver are never the same person.
  4. Approval thresholds are based on total contract value, not single invoices.

Suppliers and contracts

  1. New suppliers go through a defined onboarding check before the first payment.
  2. Bank detail changes are verified through an independent channel.
  3. Signed contracts are stored centrally with renewal dates tracked by a named owner.
  4. Conflicts of interest are declared and recorded.

Execution and monitoring

  1. Purchase orders are mandatory above a threshold and enforced in the system.
  2. Invoices are matched against PO and receipt before payment.
  3. Exceptions and spend without a PO are reported monthly.
  4. The supplier master file is reviewed at least quarterly.

How to read your score:

  • 0 to 10: You do not have a working policy yet. Start with roles, thresholds and bank detail verification; they prevent the most damage for the least effort.
  • 11 to 18: The policy exists but depends on people remembering it. Move enforcement into your systems and start monthly reporting.
  • 19 to 24: You are in good shape. Focus on spend analysis, supplier consolidation and contract terms, where the savings are.

A 30/60/90-day plan to roll out a procurement policy

Days 1 to 30: understand your spend

  • Extract twelve months of accounts payable data and group it by supplier and category.
  • Identify your top 20 suppliers by spend and the contracts behind them.
  • List recurring subscriptions and services with their owners and renewal dates.
  • Map who currently approves what, in practice, not on paper.
  • Score yourself with the scorecard above.

Days 31 to 60: write and agree the policy

  • Draft the ten sections, keeping each short.
  • Set thresholds based on your spend profile, not on a template.
  • Review the draft with department heads before finalizing; they are the ones who will live with it.
  • Define the emergency procedure and the exception report.
  • Get formal approval from management or the board.

Days 61 to 90: enforce and communicate

  • Configure your accounting or procurement system to enforce PO requirements and approval routing.
  • Clean the supplier master file: merge duplicates, deactivate dormant suppliers, verify bank details of active ones.
  • Run a 30-minute session with every manager who can approve spend.
  • Publish a one-page summary with the threshold table where people will see it.
  • Produce the first monthly exception report and discuss it with the leadership team.

Ninety days is enough to go from no policy to an enforced one. The policy will not be perfect, and it does not need to be. It needs an owner and a review date, because the first version will teach you what the second one should say.

What a working procurement policy changes

In the work I do with companies, from a sports distribution business that grew sales by 30% with AI-driven marketing to a medical center that increased capacity by 20%, one pattern repeats: growth exposes every process that was held together by informal habits. Purchasing is usually the first to break, because spend grows faster than the people who used to keep an eye on it.

A good procurement policy does not slow a company down. It removes the daily friction of not knowing who can approve what, it protects employees who would otherwise be exposed to suspicion, and it turns spend data into something leadership can actually use. The companies that get it right treat the policy as an operating tool, not a compliance document.

If your company is growing and purchasing still runs on trust and email, a structured review of your spend and approval flows is usually the fastest way to find both the risks and the savings. You can request a consultation through the dedicated page on the website and start from there.

FAQ

How do I write a procurement policy?

Start by analyzing twelve months of spend to understand what you buy and from whom. Then write ten short sections: purpose and scope, roles, approval thresholds, supplier selection and onboarding, quotes and sole sourcing, purchase orders and contracts, conflicts of interest, receiving and three-way match, exceptions, and monitoring. Keep it short enough for a manager to read in ten minutes, and configure your systems to enforce the most important rules.

What should a procurement policy include?

A procurement policy should include its scope, the roles involved in purchasing, approval thresholds based on total contract value, rules for choosing and onboarding suppliers, requirements for competitive quotes and sole source justifications, purchase order and contract rules, conflict of interest and gift rules, receiving and invoice matching requirements, an emergency procedure, and how compliance will be monitored and the policy reviewed.

What approval thresholds should a procurement policy have?

There is no universal number. A common structure for mid-sized companies uses three or four levels: budget owner approval for small purchases, budget owner plus finance for mid-range spend, department head plus CFO above that, and CEO or board approval for the largest commitments. Thresholds should be based on the total value of a contract over its life, should explicitly ban splitting purchases, and should be reviewed every year.

What is the difference between a procurement policy and a procurement process?

The procurement policy is the set of rules: who can buy, from whom, with what approvals and documentation. The procurement process is the sequence of steps that applies those rules, from purchase requisition through supplier selection, purchase order, receipt, invoice matching and payment. A company can have a process without a policy, but then nobody knows which steps are mandatory and which are habits.

Does a small business need a procurement policy?

Yes, though it can be very short. Even a company with 15 employees benefits from three rules: a clear limit above which the owner must approve spending, independent verification of supplier bank details, and a list of recurring contracts with renewal dates. These prevent the most common losses, payment fraud and forgotten subscriptions, with almost no administrative burden.

How does a procurement policy prevent fraud?

It removes the conditions fraud needs: one person controlling a purchase from start to finish, suppliers added without checks, bank details changed by email, and payments made without evidence of what was ordered and received. Segregation of duties, supplier onboarding checks, mandatory purchase orders, three-way matching and monthly exception reports make schemes harder to start and faster to detect.

Can AI help enforce a procurement policy?

Yes, as a support to human review. AI can classify spend, flag anomalies such as purchases split just below a threshold or suppliers sharing bank details with employees, extract renewal dates and terms from contracts, and answer managers' questions about the policy. Decisions about sole sourcing, conflicts of interest and approvals should remain with accountable people.