Deciding Which Purchases Need a Purchase Order
A purchase order process that covers everything gets abandoned in six weeks, and one that covers nothing was never a control.
Purchase orders are usually introduced as a policy rather than a design, and the policy says every purchase needs one. Six weeks later, roughly a third of the POs in the system were raised after the invoice arrived, which means they are not purchase orders. They are transcriptions of invoices, produced to satisfy a rule, and the person producing them has correctly worked out that the rule is the point rather than the control.
That failure is predictable and it is not a discipline problem. It is a coverage problem. The correct answer for a company of thirty people is partial coverage, written down, with the exempt categories named and controlled a different way. Not full coverage aspirationally and partial coverage in practice, which is where most companies actually sit and the worst of the three states, because nobody knows which purchases are covered.
What a purchase order actually does
Four things, and it is worth being precise, because a category where none of the four apply does not need one.
It records the commitment before the liability exists, which is the only reason your cash forecast can see next month’s spending before an invoice arrives.
It puts the approval in front of the spend. An approval collected afterwards is a ratification. The approval authority grid is worth nothing if the grid is applied to invoices, because by then the company is already committed and the approver’s only real option is to sign.
It gives receiving something to check against. Without an order, the only description of what should have arrived is the invoice from the party who sent it.
It gives the invoice a home. AP matches to a document rather than adjudicating whether a charge is legitimate, which is not a question an AP clerk should be asked and is the reason invoices sit in inboxes for three weeks.
Here is what a purchase order does not do, stated plainly because people expect it to. It does not stop a bad purchase, it does not validate that the price is reasonable, and it does not create budget discipline where none exists. It is a record and a sequencing device. The judgment still has to be made by a person, before they raise it.
The coverage matrix
The design question is per category, not per amount. Work down this table and mark each row for your own business, then write the result on one page and circulate it. The last column is the one to argue about, because a category with no purchase order and no alternative control is the actual gap.
| Spend category | Purchase order | Who raises it | Receiving evidence | If no purchase order, the control is |
|---|---|---|---|---|
| Materials and goods bought for a customer job | Yes, per job | Project or operations lead | Delivery note matched to the job | Not applicable |
| Subcontract labour on a customer job | Yes, blanket per job with a scope and a ceiling | Project lead | Signed timesheet or milestone sign-off by the project lead | Not applicable |
| Inventory and stock replenishment | Yes | Whoever owns the stock level | Receipt into the count | Not applicable |
| Equipment, fit-out and anything on the capital list | Yes, always, at any amount | Requester, through the capital approval path | Asset received and tagged | Not applicable. Capital spending has its own approval sequence and the order is the last step of it, not the first. |
| Professional services with an engagement letter or signed scope | No | Not applicable | The deliverable, accepted by the engaging manager | The engagement letter is the commitment document. Fees outside its scope need an order. |
| Professional services, one-off or unscoped | Yes | The engaging manager | Written acceptance of the work | Not applicable |
| Marketing campaigns and media buys | Yes, blanket per campaign | Marketing owner | The campaign report against the plan | Not applicable |
| Recurring software and subscriptions | No | Not applicable | Not applicable | A subscription register with a renewal date and a named owner per line, reviewed before each renewal. New subscriptions need an order the first time. |
| Rent, occupancy, utilities, insurance | No | Not applicable | Not applicable | The contract register. The commitment was made when the agreement was signed. |
| Travel | No | Not applicable | Not applicable | The expense policy and the card programme, which is where this spend is actually decided |
| Office consumables, kitchen, small hardware | No | Not applicable | Not applicable | One named buyer per category and a card limit that fits the category |
| Freight and courier | No | Not applicable | Not applicable | It follows the goods. Check it against the order for the goods it carried. |
| Repairs and maintenance, reactive | No below the line you set, yes above it | Facilities or operations | Work completion sign-off | A named approver and a monthly review of the category |
| Payroll, statutory remittances, loan payments, bank charges | Never | Not applicable | Not applicable | These are not purchases. A purchase order process that tries to cover them is a process that will be ignored. |
| Intercompany charges | Never | Not applicable | Not applicable | The written intercompany agreement is the authority |
Two rows deserve a second look.
The capital row is deliberately the only one with no amount qualifier, because the reason to raise an order for equipment has nothing to do with the size of the cheque. The asset needs to exist as a record from the moment it is ordered, and a capital purchase that arrives as an invoice with no prior document is how items end up expensed that should have been on the asset register, or the reverse.
The subcontract row is where blanket orders earn their place. A per-invoice order for a subcontractor working across four months on one job produces a stack of paper nobody reads. One order per job, scoped, with a ceiling and an end date, produces a document the project lead actually checks against.
The exemptions, and the conditions that make each one valid
An exemption names a category where the control sits somewhere else, and it is only legitimate if you can say where it sits. A category with no order and no named alternative is not exempt, it is uncovered. Four kinds.
The contract-in-place exemption. The commitment was made when the agreement was signed, so a purchase order would be recording a decision already taken. Valid only if the contract is in a register with an owner and a renewal or expiry date. Without the register, this is not an exemption, it is untracked recurring spend, which is the largest category of unnoticed cost in most companies this size.
The blanket order. One order covering a period or a project, with a stated scope, a ceiling and an end date. Valid only if someone checks the running total against the ceiling, which means the order has to be visible in the system rather than a document in a folder. A blanket order with no ceiling is a purchase order that has been disarmed.
The named-buyer exemption. A category where one named person buys, within a stated limit, without raising anything. Valid only if the limit is enforced by something other than that person’s memory, which in practice means the card limit is the control and the category is on the card review.
The exclusion. Payroll, remittances, financing, intercompany. These are not purchases, and listing them explicitly matters more than it sounds, because the alternative is a policy that reads as universal and is therefore visibly not being followed.
The line inside a category, and how to set it
Some categories need an amount as well, most obviously reactive repairs and one-off services. Set it with one question: at what size does this category’s spend need to be visible to somebody before it happens rather than after? Not at what size it becomes significant to the statements, which is a different and much higher number.
Then handle the aggregation problem, because it is how every amount line is defeated. Splitting one commitment into several smaller orders to stay under a line is usually done by somebody acting in good faith who has found the process slow. The fix is a monthly same-supplier review at close and a design change if it keeps happening, not a lecture. Repeated splitting is a message about the process, and the message is accurate.
What a purchase order has to contain
Seven fields. Anything beyond this is a form somebody will fill in badly.
- A number, from a single sequence, with no gaps.
- The supplier, selected from the vendor list rather than typed. A purchase order to a supplier who is not yet on the vendor file is a queue item, not an order.
- What is being bought, in enough detail that a person receiving it could tell whether the right thing arrived.
- The amount, or the ceiling if it is a blanket.
- The account and the dimension it will be coded to. Coding at the order stage rather than at the invoice stage is the single largest quality improvement available in a small company’s ledger, because the person raising the order knows what it is for and the person coding the invoice is guessing.
- The approver, by name, per the authority grid.
- The date it is needed, and for a blanket, the date it expires.
Receiving, kept to the smallest thing that works
The receiving step is where purchase order processes get heavy, so hold it to the principle and no more: somebody other than the person who raised the order confirms that what was ordered arrived. For goods, that is a delivery note or a receipt into stock. For services, there is no delivery note, and pretending otherwise produces a fiction. The evidence for services is a named person recording that the work was delivered, against the scope on the order, before the invoice is approved.
The full mechanics of matching an order, a receipt and an invoice in a company with no purchasing team is a separate exercise. What matters at the design stage is that every row you mark “yes” in the matrix has a plausible answer in the receiving column, because a purchase order with no receiving step is a commitment record and not a control.
How to tell whether your coverage is right
Two counts, quarterly, and they are the only measurement this process needs.
The retro rate. What proportion of purchase orders in the quarter were raised on or after the date of the supplier’s invoice. Every one of those is a category where the process does not fit the way that spend actually happens.
The uncovered rate. How many invoices arrived with no purchase order in a category you marked as requiring one. Break it down by category and by requester, and look at the category first.
Then do the thing most companies will not do: move the boundary rather than escalate the enforcement. If a category shows a persistent retro rate, the honest reading is that it does not suit an order, and it should be moved to an exemption with a named alternative control. Tightening enforcement on a category that structurally does not fit produces compliance theatre, and compliance theatre is worse than an acknowledged exemption because it looks like a control on paper and functions as nothing.
What changes as the company grows
The design above assumes the person approving an order still knows most of what is being bought and why. That holds to somewhere around forty or fifty people and then it stops, quietly, and the tell is that approvals start being granted on trust in the requester rather than on the merits of the purchase.
At that point coverage widens, because the alternative controls that worked at thirty people all depended on one person having visibility they no longer have. The named-buyer exemption is the first to go, the contract register becomes a real register with an owner rather than a spreadsheet, and reactive repairs get a line where they previously had a judgment. That transition is a rewrite of the whole control set rather than a tightening of this one, and it is worth treating as such, because bolting purchase orders onto a design that has been outgrown produces a slow process that still misses the spend it was meant to catch.
Partial coverage is not a stage on the way to full coverage. It is where a company this size should stay, deliberately, with the boundary written down and reviewed twice a year. The companies that get this wrong are not the ones with too few purchase orders. They are the ones whose policy says everything and whose practice says something else, because in that company nobody, including the owner, can tell you which purchases were actually approved before they happened.