An Expense Policy Short Enough That People Follow It
An expense policy nobody has read is not a control, it is a document that exists to be produced after something goes wrong.
Expense policies fail in exactly two ways, and both are fixable in an afternoon.
The first is length. A nine page policy is not read, and a policy that is not read cannot be followed, so its only remaining function is to be produced afterwards as evidence that someone was told. Policies get long the same way every time: an incident happens, a clause is added, and nothing is ever removed. After four years you have a document that answers questions nobody asked and buries the four rules that matter.
The second is that most policies never say what happens if you do not follow them. They describe the process in careful detail and then stop. A rule with no stated consequence is a request, and everyone reads it correctly as a request.
What follows is the section list for a policy that fits on two pages, and the enforcement step that gives it teeth. Draft it in an afternoon, get it approved, and be done with it for a year.
Draw the boundary first
This policy governs money an employee spends and asks the company to repay. That is all.
Spend on a company card is governed by the card programme, which is a different control problem, because approval there happens after the money has gone. Committing the company to a purchase is governed by whatever purchase order coverage you have set. Stating those two boundaries in the first paragraph saves you the three pages of cross-references that most policies grow instead.
The section list
Ten sections. Most of them are a paragraph. If any section runs past half a page, something in it belongs somewhere else.
| Section | What it says | The trap |
|---|---|---|
| 1. Scope | Who it applies to, what it covers, what it does not | Trying to be exhaustive about coverage instead of naming the two neighbouring policies |
| 2. The principle | One sentence that decides the cases the policy does not list | Writing a mission statement instead of a test |
| 3. What is reimbursable | Categories with a short characterisation of each, not a catalogue | An allowlist. Every item you fail to list becomes an argument. |
| 4. What is never reimbursable | A short, explicit, specific list | Softening it into guidance. This is the one section that should read as absolute. |
| 5. Limits | The categories that carry a limit, and where the current figures are published | Putting the figures in the policy itself. See below. |
| 6. Receipts | One rule, with the two exceptions | A tiered receipt rule with several thresholds, which nobody remembers and everybody resolves in their own favour |
| 7. Approval | Who approves whose claims, including the people at the top | Leaving the owner and the senior team out, which is the omission everybody notices |
| 8. Submission and payment | When claims are due, when they are paid, what happens to a late one | Stating a date instead of a rule tied to the close |
| 9. What happens if the policy is not followed | The escalation ladder, in the policy, in writing | Omitting it, which is what almost every policy does |
| 10. Ownership and review | Who owns the document, when it is reviewed, where the current version lives | No named owner, so the version in circulation is whichever one somebody has a copy of |
On section 2, the principle
You need one sentence that resolves the cases the policy does not list, because there will always be cases the policy does not list and the alternative is that each one becomes a conversation.
Write it as a test rather than a value. Something a person can apply alone, at a restaurant, in thirty seconds. The version I find works is close to: if you would be uncomfortable having this item read out with your name against it at a company meeting, do not claim it. It is uncomfortable on purpose, it decides almost every borderline case correctly, and it does not require anybody to interpret the word “reasonable”.
On section 4, the prohibited list
Short and absolute. Personal items. Fines and penalties of any kind. Spending for family members or guests who are not there for the business. Anything already paid on a company card, which is the duplicate claim and the most common real problem in this whole area. Anything bought for someone else to claim. Cash withdrawals.
Six lines. No hedging, no “generally”, no “except where approved in advance”, because each exception you write in is an exception someone will find.
The receipt rule
One rule, stated once: an itemised receipt for every claimed item, attached at submission.
Not a threshold below which no receipt is needed, because a threshold is a rule with a boundary and boundaries invite management. Not a card statement line, which shows a total and a merchant and proves nothing about what was bought. The itemised receipt is the whole point. A statement line for a restaurant tells you an amount. The itemised receipt tells you it was four people at lunch, which is what the reviewer is actually assessing.
Two exceptions, both narrow.
Hospitality needs a note as well as a receipt. Who was there and why, written on the claim. Not a policy burden: it is one line and it is the only evidence that separates a client meal from a personal one. A hospitality claim with no attendee note is incomplete and goes back.
A genuinely lost receipt gets a declaration. A short statement of what was bought, where, when, and why the receipt is unavailable, signed by the claimant and approved one level up. Then cap the exception by count rather than by amount: a stated small number of declarations per person per year. Capping by dollar value produces lost receipts that are all just under the cap. Capping by count produces people who look after their receipts, because the fourth one is a conversation with their manager.
The approval route
Every claim is approved by the claimant’s manager, one level up, before it is paid. Nobody approves their own claim, and nobody approves a claim from which they personally benefited.
Then handle the people at the top, because this is the section most policies quietly skip and everybody in the company notices.
The owner’s own claims go to a second person. In a company with a board or outside shareholders, that is the obvious route. Without one, it is the finance lead, and the finance lead’s role is narrow and should be written narrowly: they check the claim against the policy and raise anything that does not meet it. They are not being asked to judge whether the owner should have made the purchase. That distinction is what makes the arrangement workable rather than awkward.
Say this out loud when the policy is introduced. A policy where the owner is visibly subject to the same route is a policy people follow. A policy where the owner is not is a policy about junior staff, and it will be enforced as one.
Submission and payment
Tie both to the close rather than to a date, so the policy stays true when the calendar changes.
Claims for a period are due by the cut-off in the close calendar, which is the same notice that goes out for everything else. Approved claims are paid in the next scheduled payment run, with the suppliers, rather than by a separate transfer somebody makes on request. A claim submitted after the cut-off goes in the following period, and it is paid in that period’s run. Paying reimbursements off cycle because somebody asked is how a company ends up with two payment processes, one of which has no controls on it at all.
Then set an outside limit, in periods rather than days: claims older than a stated number of closes are not reimbursed without an approval from a named person. Every company needs this and almost none have it. Without it, someone eventually submits eleven months of receipts in one envelope, and by then there is no way to check any of it and no budget it belongs to.
The section everybody omits
Section 9. What happens when the policy is not followed, written into the policy, in language a person can act on.
A ladder, and it should be short.
- First instance: the claim is returned. Not paid, not partially paid, returned with the reason. Returning a claim is a stronger signal than any warning and it costs nothing.
- Repeated instances: the manager is copied. The point at which it stops being between the claimant and finance.
- A pattern: the item is not reimbursed. The claimant was told, in writing, twice.
- Anything that looks deliberate: it stops being an expense matter. It goes to the owner and it is handled as conduct.
Two things to be careful about. Do not write a step that touches somebody’s pay. Anything in the neighbourhood of deducting from wages is an employment question with legal consequences and it is not a step to design into a policy on your own. And do not write a ladder you will not walk. A policy that threatens step four and has never reached step one is training people to ignore all four.
What gives the ladder something to act on
A monthly sample. Somebody who did not approve the claims reads a small number of them in full, against the policy, every month. Not all of them, and not a formula: a handful, chosen so that over a year most people and most categories have been looked at at least once.
What it produces is a short list of findings, each with a name against it, which feeds the ladder. What it produces more importantly is the knowledge, held by everybody in the company, that claims are read by somebody. That knowledge is most of the control, and it exists only if the review actually happens every month rather than in the months when there is time.
The design of the sample itself, meaning how to get useful coverage without reading everything, is a bigger subject than a policy needs to contain, and it belongs with the rest of the controls work rather than inside the document employees read. The policy needs one sentence: claims are reviewed monthly by a named role, and findings are actioned under section 9.
What must not be in the policy
No mileage rate. No per diem figures. No meal allowances quoted as amounts in the document.
This surprises people, so here is the reasoning. A rate written into a policy goes stale, and a stale rate in a signed document is worse than no rate, because people follow it. Worse, a rate quoted in a policy implies a position on how the reimbursement is treated for tax, and that is not a position an expense policy is competent to take.
Publish the current figures on a single page kept alongside the policy, dated, updated when they change, and point section 5 at it. The policy then says which categories carry a limit and where the numbers live, and the numbers can move without reopening the document.
No tax treatment. Not for reimbursements, not for allowances, not for the deductibility of any category. Whether a given reimbursement is taxable to the employee, and what the company may claim, are questions for whoever handles your payroll reporting and whoever reports on your statements. Put those questions to them once, get the answer, and reflect it in how the items are set up in the payroll and the ledger. Do not write the answer into a policy that gets circulated to the whole company, because it will be read as advice and it will be out of date before it is wrong.
The test before you circulate it
Read the draft out loud. If it takes more than four minutes, cut it. Then hand it to someone who submits claims and ask them one question: what happens if you lose a receipt. If they can answer without opening the document again, the policy is short enough.
Then put it somewhere with a version and a date, name the owner, and review it once a year rather than after each incident. The instinct after a problem is to add a clause. Resist it. Most incidents are not caused by a missing rule, they are caused by nobody reading the claims, and the fix for that is section 9 and the monthly sample, both of which you already have.