Card programs · July 7, 2026
Corporate card policy template: spending limits by role
A corporate card policy is the written rulebook for company cards: who gets one, what it may be used for, how much each role may spend per transaction and per month, and what happens when a charge falls outside the lines. Below is a working template you can adapt, including a limits-by-role table, plus the part most policies skip: how to enforce it.
What a corporate card policy should cover
Most card policies fail not because they are too short but because they are vague where it matters. A useful policy answers every question an employee or an auditor could ask about a charge, in plain language, in a few pages. The core sections:
- Eligibility and issuance. Which roles qualify for a card, who approves issuance, and how cards are requested and activated.
- Spending limits. Per-transaction and monthly caps by role or level, and the approval path for anything above them.
- Allowed and prohibited categories. What the card is for (software, travel, client meals, supplies) and what it is never for (cash advances, gift cards, personal purchases, crypto).
- Documentation. Receipt requirements, coding deadlines, and what counts as a business purpose note.
- Personal use and accidental charges. How an accidental personal charge is reported and repaid, and why hiding one is treated more seriously than making one.
- Violations and consequences. A graduated response: reminder, limit reduction, card suspension, termination for deliberate misuse.
- Offboarding. Cards are cancelled on the employee's last day, not at the end of the billing cycle.
- Review cadence. Who reviews card activity, how often, and against what thresholds.
Spending limits by role: a starting-point template
The table below is a template, not benchmark data. The figures are reasonable starting points for a company of roughly 25 to 500 employees in the US; scale them to your revenue, industry, and risk tolerance. The structure matters more than the exact numbers: every role gets a per-transaction cap, a monthly cap, and a named approval path for exceptions.
Swipe the table sideways to compare all columns.
| Role | Per transaction | Monthly limit | Typical categories | Above limit |
|---|---|---|---|---|
| Individual contributor | $250 | $1,000 | Supplies, small software, meals | Manager approval |
| Manager | $1,000 | $5,000 | Team tools, travel, client meals | Department head approval |
| Department head | $5,000 | $20,000 | Vendors, contractors, events | Finance approval |
| Executive | $10,000 | $50,000 | Strategic vendors, travel | CFO or CEO co-sign |
| Ops / IT (SaaS owner) | $2,500 | $15,000 | Subscriptions, infrastructure | Finance approval |
Two refinements worth adding once the basics hold. First, category-level caps that sit on top of role caps: a manager with a $5,000 monthly limit might still be capped at $500 per month for meals. Second, a velocity rule: more than a set number of transactions per day triggers a review even if each charge is small, because split purchases are the oldest trick for staying under a per-transaction cap.
A card policy that nobody monitors is a suggestion with a signature line.
The enforcement gap: policy without monitoring
Here is the uncomfortable part. Almost every company that issues cards has a policy document. Far fewer have any mechanism that notices a violation before the statement arrives. The policy says $250 per transaction; the card network happily approves $900; and finance finds out three to six weeks later, during close, when the money is long gone and the conversation has become an awkward retroactive one.
Closing that gap does not require moving your card program to a new provider. It requires a monitoring layer that knows your policy numbers and watches transactions as they post: real-time budget alerts that fire the moment a role, team, or category crosses its threshold, so the exception conversation happens the same day as the exception. The policy sets the lines; the alerts are what make the lines real.
A practical convention many teams adopt: warn at 80 percent of any limit, escalate at 100 percent. The 80 percent warning goes to the cardholder and their manager as a nudge; the 100 percent breach goes to finance as an action item. Written into the policy, this turns enforcement from an accusation into a process everyone signed up for.
A monthly card review workflow
Even with real-time alerts, a short monthly review keeps the policy honest. Thirty to sixty minutes, first week of the month, run by the controller or finance manager:
- Pull the full transaction list for the prior month, all cards, sorted by cardholder.
- Check every alert that fired. Confirm each warning and breach was resolved: documented, approved as an exception, or repaid.
- Scan for pattern risks the per-charge rules miss: repeated just-under-limit amounts, split transactions, weekend charges from office-based roles. Our post on expense fraud red flags lists the twelve patterns worth scanning for.
- Review recurring charges against the subscription list; new recurring merchants get an owner or get cancelled. A quarterly subscription audit goes deeper.
- Reconcile missing receipts and chase them with a deadline, not a reminder.
- Adjust limits. Roles that hit 80 percent every month may need a higher cap; cards unused for 90 days should be reduced or cancelled.
- Log the review. One line in a shared doc: date, reviewer, exceptions found, actions taken. Auditors love it, and it keeps the process alive when people change roles.
Common corporate card policy mistakes
Four failure modes account for most policies that exist on paper and nowhere else:
- Limits nobody can check. The policy says $250 per transaction, but no system enforces or even reports it, so the limit becomes folklore within a quarter.
- One limit for every role. If the intern and the VP share a cap, the cap is either uselessly high for one or constantly violated by the other. Limits must map to roles.
- Consequences that are never applied. The first tolerated violation resets everyone's expectations. A mild consequence applied every time beats a severe one applied never.
- No exception path. If following the rules is slower than breaking them, people break them. A same-day approval route for legitimate above-limit purchases is what keeps the rest of the policy intact.
Rolling the policy out
Keep the document to three or four pages, have every cardholder sign it at issuance and re-acknowledge annually, and publish the limits table where people can find it. The goal is not to catch people; it is to make the boundaries so clear and the feedback so fast that staying inside them is the path of least resistance. A short policy, enforced in real time, beats a long one enforced at month-end every time.