Why the category list isn’t the hard part
Search "business expense categories" and you’ll find dozens of near-identical lists - office supplies, travel, software, payroll. Categorizing an expense is genuinely easy once you see the receipt. The problem businesses actually struggle with is upstream of that: deciding who is allowed to commit the spend before the receipt exists, and how fast that decision gets made.
A policy without a limit isn’t a policy
"Get manager approval for large purchases" isn’t a policy - it’s a suggestion with no enforcement mechanism, because "large" means something different to everyone who reads it. A real policy states a number: below this amount, a person can spend without asking; at or above it, a named approver has to say yes first.
| Spend level | Who approves | Turnaround expectation |
|---|---|---|
| Under a small fixed threshold | No approval needed - just recorded | Same day |
| Mid-range, routine category | Direct manager | Within 24 hours |
| Large or unusual category | Finance lead or owner | Within 48 hours |
| Anything touching a new vendor or contract | Owner, regardless of amount | Before commitment, not after |
A simple tiered approval structure
Pre-approval vs. post-approval - and why the difference matters
Approve before spending vs. after spending
Pre-approval
- Stops an unwanted purchase before it happens
- Requires the requester to plan slightly ahead
- The only real control on spend, not just on records
Post-approval (review only)
- Only documents what already happened
- Can flag a problem, but the money is already spent
- Useful as a secondary check, not a substitute for pre-approval on anything material
A slow process gets bypassed
If approval routinely takes a week, people will find a way around it - a personal card "reimbursed later," a purchase split into smaller pieces to dodge a threshold, or simply not asking. Speed is a control feature: a policy nobody can live with gets quietly ignored, which is worse than no policy at all.
Sizing approval tiers to your actual team, not a template
A three-person team doesn’t need five approval tiers - one clear threshold with the owner as the single approver is often enough. Past roughly ten people, a single approver becomes a bottleneck, and tiered limits by role start to earn their complexity. Revisit the thresholds as the business grows; a limit that made sense at ten employees is often wrong at fifty.
What belongs in a written policy
The minimum a real policy states
- The spending threshold below which no approval is needed
- Who approves at each tier above that
- How long approval should realistically take
- What documentation is required (receipt, purpose, category)
- What happens if spend occurs without approval - a real consequence, not just a note
Handling the exception, not just the rule
Worked example: the urgent, unavoidable purchase
A server goes down and a same-day replacement part costs more than the standard threshold. A workable policy has a named emergency-approval path (a phone call, not a form) precisely so people don’t have to choose between "break policy" and "leave the business down." A policy with no exception path invites the exception to happen silently instead.
Reviewing the policy itself
A quarterly policy check
- 1
Pull actual spend against thresholds
How often did spend land right at or just under the limit? That’s a signal the limit may be wrong, not that people are gaming it.
- 2
Ask approvers about turnaround
If approvers say they’re a bottleneck, the tier structure needs adjusting, not just a reminder to be faster.
- 3
Check for workaround patterns
Repeated small purchases from the same person, same day, same vendor is the classic sign of an evaded threshold.
- 4
Update in writing
A policy that lives only in someone’s memory isn’t a policy the next hire can follow.
What is the simplest expense approval policy a very small team can use?
One threshold, one approver - usually the owner. Below the threshold, spend and record it; at or above it, ask first. Add tiers only once a single approver genuinely becomes a bottleneck, typically past around ten people.
Should approval happen before or after the money is spent?
Before, whenever realistically possible. Pre-approval actually prevents an unwanted purchase; post-approval only documents one that already happened. Reserve post-approval review for routine, low-risk spend where pre-approval would add friction without adding real control.
What should I do about a genuine emergency purchase that can’t wait for approval?
Build a named emergency-approval path into the policy itself - a phone call or a quick message to a specific person, not the standard form process. Without one, people either break policy silently or leave a real problem unaddressed while waiting.
A policy nobody can actually live with isn’t a control. It’s a reason to work around you.
Resources
Was this guide helpful?