# How To Write An Accounts Payable Policy Your Team Will Use

Learn what to include in your accounts payable policy, and how to write it so your team actually follows it.

**URL Source:** https://www.brex.com/spend-trends/accounting/accounts-payable-policy

---

How to write an accounts payable policy your team will use

### Key takeaways



- Use the information below to help inform your decision, and work with your appropriate professional advisor based on your specific circumstances.
- An AP policy works well if it matches how your team actually processes invoices, approves payments, and uses your tools. A policy that lives only on paper gets ignored, with controllers forced to manually catch exceptions themselves.
- An AP policy should be updated over time to reflect how your company grows and changes. Review it at least annually (or after major changes), track adoption metrics, and use the exception log to catch drift before it becomes an audit problem.



### Introduction



If you're a controller inheriting a policy from the last finance lead, the cost of leaving it untouched shows up fast. Invoices might get approved in chat tools. Vendors may send bills to whoever they have an email address for. The document may still sit in a shared drive, but it no longer reflects how the team works after enterprise resource planning (ERP) systems change and workflows shift.

An accounts payable (AP) policy works if it matches how AP actually runs. When it doesn't, people stop following it, and the controller becomes the person catching exceptions the document never anticipated. This guide covers three key things:

- What belongs in an AP policy
- How to write one your team actually uses
- What separates an impactful policy from one that only satisfies an auditor

The principles here hold whether you’re backed by a full AP team or you’re flying solo, and whether you’re on a legacy ERP or an AP automation tool. If you’ve inherited a policy nobody reads, or if you’re writing one from scratch, this blog post will help you build an AP policy that your [accounts payable process](https://www.brex.com/spend-trends/cash-flow-management/accounts-payable-process) can actually run on.



### What is an accounts payable policy?



An accounts payable policy is the written, authoritative set of rules governing how your company receives, approves, codes, pays, and documents vendor invoices. It answers seven questions AP teams run into constantly:

- Where do invoices arrive?
- Who validates and codes them?
- Who approves and at what thresholds?
- How and when are invoices paid?
- How are vendors set up and changed?
- What documentation must be retained?
- How are exceptions handled?

Leave any of these questions unanswered in the document, and whoever processes the next invoice that triggers it decides the answer on the spot. This results in policies that gradually drift until they no longer match how the team works.

Enforcing an AP policy in real life requires support in the form of procedures and controls. Think of it as a speed limit. The policy is the posted limit, the rule you’re expected to follow. The procedure is the manual that explains how to follow it. The control is the speed camera that catches you automatically, whether you remember the rule or not.

Similarly, the AP policy sets the rules and defines what must happen, who's responsible, and under what conditions. The procedure, which usually takes the form of a standard operating procedure (SOP) or a tool-specific runbook, shows the step-by-step instructions. The controls in your AP tool configuration or ERP logic help prevent errors even when people skip the process. Keeping these layers separate makes the policy easier to enforce and more useful in day-to-day work.



### 5 signs your current AP policy isn’t working



A failing policy shows up in familiar ways. The close cycle relies on individual memory instead of documentation. People approve invoices in chat tools simply because that’s how it’s always been done. The controller spends month-end chasing down answers the policy should’ve already settled. These bottlenecks show up in subtle ways until an audit forces them into the open. Here’s what the damage often looks like.

Your close relies on chasing signatures

Without clear intake, coding, and approval rules in writing, you spend most of close chasing signatures and untangling discrepancies days before the deadline. Chances are your approvers and AP staff aren’t working from the same assumptions, so questions that should’ve been settled weeks earlier surface with little time left to fix them. A written policy that standardizes how invoices flow through your [accounts payable management](https://www.brex.com/spend-trends/accounting/accounts-payable-management) process helps fix this upstream, well before the final review starts.

Vendor changes and duplicate payments slip through unnoticed

A lack of written controls leaves no consistent way to verify vendors, approve payments, or review changes before money leaves the business. A vendor added without verification, or banking details changed via email, is easy to miss when separation-of-duties requirements aren’t explicit. The [2026 AFP Payments Fraud and Control Survey](https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud) found that 76% of organizations reported attempted or actual payments fraud in 2025. Named controls close that gap, catching the vendor changes and duplicate payments that would otherwise slide through unreviewed.

Some finance teams handle this verification manually, checking vendor changes against a call-back or a second approver every time. Others build it into the AP tool itself, so verification happens automatically before a payment goes out.

Your policy and your actual process don’t match under audit scrutiny

The same controls that reduce fraud risk also make audit testing easier. An auditor reviewing AP may ask for the policy, then test whether actual transactions conform to it. If they don’t match, a routine test can turn into a longer, more painful fieldwork process that requires digging up support documentation from multiple sources. However, a policy that reflects how the team actually works can turn that same audit into a clean sign-off.

Approval thresholds shift depending on who’s asking

Without a written approval matrix, different approvers set their own informal thresholds. One manager signs off on $5,000 without a second look. Another requires VP approval at $1,000. Separately, each one might be fine, but together they turn approval into a matter of who happens to review the invoice. A documented threshold table, applied consistently across departments, can reduce ambiguity and replace more individual judgment with a verifiable organizational standard that [internal accounting controls](https://www.brex.com/spend-trends/accounting/internal-controls-for-accounting) can rely on.

Your liability numbers don’t match what you actually owe

Without a documented policy, invoice intake timing and payment run cadence vary week to week. That inconsistency shows up in missed accruals, skewed days payable outstanding (DPO) calculations, and unreliable cash-flow forecasts. A policy that standardizes intake and payment timing helps fix this at the source. [Accounts payable reporting](https://www.brex.com/spend-trends/accounting/accounts-payable-reporting) and [accounts payable metrics](https://www.brex.com/spend-trends/accounting/accounts-payable-metrics) are only as reliable as the process feeding them, so a consistent upstream process gives leadership numbers they can trust.



### Why do most AP policies fail?



Most failed AP policies break down in one of four ways.If you've inherited a policy nobody follows, you'll recognize at least one. Each of the signals below stems from a gap between the written rule and how work actually moves through the finance team.

Written for auditors instead of the people doing the work

Many AP policies read like they’re written for the auditor instead of the department manager who has to act on them. They use passive voice, undefined terms, and vague directives like "invoices should be submitted in a timely manner." When the document doesn't translate to what a specific person does in their actual role, they stop consulting it. The result is a policy that exists on paper but not in the workflow.

The exception path is missing

Real AP teams handle invoices that don't fit the standard process, including urgent payments and invoices from vendors that aren’t in the AP system yet. When the policy doesn't define how exceptions are handled, people improvise. Those improvisations become informal processes that contradict the written policy, and procedural drift becomes the working standard.

Not mapped to the actual tools the team uses

A policy that references "the finance platform" when your team uses NetSuite, or describes a workflow that predates the company's switch to [automated clearing house (ACH) payments](https://www.brex.com/spend-trends/business-banking/ach-payments), is hard to enforce. Rules are often easier to apply when they correspond to a specific action in a specific tool. A policy requiring "payments over $50,000 require CFO approval" is easier to enforce when your ERP blocks payment release without that approval. Without tool-based enforcement, the rule is harder to apply consistently.

No named owner after publication

A policy needs one named owner responsible for maintenance, updates, and resolving ambiguity, or it stagnates after publication. Controllers who inherit the document often find that the last person who updated it left the company months or years ago, without anyone noticing it has drifted since. Without an accountable owner, no one feels responsible for overseeing the policy until it becomes the controller’s problem.



### 10 sections to add to your accounts payable policy



Your policy document should adapt its scope and depth to the company's size. Even if one person owns AP end to end right now, the same core rules apply, just with fewer people to divide them across.The goal here is coverage that is specific enough to guide behavior without turning the policy into a full operating manual.

1. Purpose and scope

One paragraph establishes why the policy exists and who it applies to. Scope should explicitly name employees who submit, approve, or process a vendor invoice, including department managers who approve spend, employees who receive invoices directly from vendors, and AP staff who code and process them. A clear scope prevents the policy from being treated as applying only to accounting. Without it, an invoice can sit unapproved for days simply because a department manager assumed AP would catch it.

2. Roles and responsibilities

Name each role and, in direct language, state what they own. Here are some examples you may want to use for your own policy:

- AP staff own intake, validation, coding, and payment runs
- Approving managers and department heads confirm invoices against budget and business justification
- The controller owns oversight, exception approval, and policy maintenance
- The finance leader owns policy structure and major changes

On a smaller team, one person may hold several of these roles at once, but the ownership for each one should still be made explicit. Clear role ownership can reduce approval confusion and finger-pointing when exceptions surface.

3. Invoice intake requirements

Your intake section should state where invoices must go, who is allowed to receive them, and what happens to invoices missing important information. Getting this right at intake matters because errors caught late create clean-up work later on. Many companies route invoices through a shared AP email inbox or a dedicated portal in their AP system, while invoices sent directly to employees or department managers may need to be redirected immediately. Consider making the following fields a requirement for every invoice:

- Vendor name
- Invoice number
- Invoice date
- Amount
- Payment terms
- Purchase order (PO) reference or cost-center code

4. Invoice coding, matching, validation

Rules for coding invoices to general ledger (GL) accounts, departments, and projects should be explicit. Specify when [2-way matching in accounts payable](https://www.brex.com/spend-trends/accounting/2-way-matching-in-accounts-payable) or [invoice matching](https://www.brex.com/spend-trends/accounting/invoice-matching) is required, and name who resolves discrepancies. For example, if an invoice for $5,000 comes in against a purchase order for $4,500, the policy should clearly say who has the authority to approve the difference. Your policy should define how your team will [prevent duplicate payments in accounts payable](https://www.brex.com/spend-trends/accounting/prevent-duplicate-payments-in-accounts-payable) before payment goes out. Specific validation rules help protect both cash and close quality.

5. Approval thresholds and authority matrix

This is one of the most commonly bypassed sections when written vaguely, and it’s the section most likely to change day-to-day behavior when it’s specific. State dollar thresholds explicitly, name the role at each level, and include a threshold table the reader can reference. The no-self-approval rule should be stated in plain language, and thresholds above a routine amount may benefit from dual approval. There are no fixed rules for these numbers, so we recommend using the table below as a starting example and adjust it to fit your company’s spending and risk tolerance:



Manually enforcing this matrix means trusting every approver to remember it correctly every time. Some finance teams handle this with spot checks. Others route it through their AP tool, so a payment can’t clear without the right sign-offs at the right amount.

6. Payment methods

Your policy should name your company’s approved payment methods, such as ACH, wire, check, or virtual card, and state when each one should be used. It should also include how often payment runs happen and set a cut-off time for getting an invoice into a given run. For example, if the cut-off is Wednesday at noon, an invoice approved Wednesday at 3pm will go out in the following week’s run instead of that week’s.

The person who creates a payment run, the person who approves it, and the person who releases it should be three different people to maintain [separation of duties](https://www.brex.com/spend-trends/accounting/separation-of-duties-in-accounting). Handling for urgent or off-cycle payments should require a named approver and written documentation so speed doesn't override control.

7. Vendor setup controls

When creating a new vendor, ask for their legal name, tax identification number (TIN), banking details, and W-9 or W-8BEN tax forms. Any change to vendor payment information may be verified by calling a known contact directly. Your [vendor management guide](https://www.brex.com/spend-trends/vendor-management/vendor-management-guide) should spell out this verification step in detail. Some finance teams handle this verification manually, while others build it into their AP tool so vendor changes get flagged and routed for a second check automatically. Either way, this is one of the clearest places where written policy can reduce the risk of preventable fraud.

8. Documentation retention

Your retention section should specify what must be attached to each invoice record. Required attachments usually include the invoice itself, evidence of approval, supporting PO or contract, and any exception approvals. Documents should be stored in the AP tool, ERP attachment field, or a [paperless accounts payable](https://www.brex.com/spend-trends/accounting/paperless-accounts-payable) document management tool. [The IRS generally requires companies to keep records for 3 years](https://www.irs.gov/publications/p583), although certain situations, like underreported income or unfiled returns, can extend that significantly. For company-specific retention treatment, consult a qualified tax or accounting professional.

9. Separation of duties

This section should state which duties can't be held by the same person. A [2026 report from the Association of Certified Fraud Examiners (ACFE)](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2026/2026-report-to-the-nations.pdf) found that a lack of internal controls was the single most common factor behind occupational fraud, cited in 33% of cases. Because of risks like this, the following four categories are typically kept separate:

- Authorization of transactions
- Custody of assets
- Transaction recordkeeping
- Reconciliation

Match the policy’s complexity to your team’s size. A 15-person finance team doesn’t need a Fortune 500 structure with five approval tiers. Simplify where it makes sense until the team needs more separation. Lean teams, for instance, might opt for compensating controls like controller review of new vendor setups and payment-run reconciliation sign-off.

10. Exception handling

Your policy should define a specific path for exceptions. A common approach is for exceptions to be submitted to the controller or a delegated authority with written business justification, documented in the AP tool with an exception code, and reviewed in aggregate on a defined cadence. Exception approvers should typically sit one organizational level above the normal approver for that transaction type. Keep exceptions as visible, auditable deviations from the process so they don’t become the unofficial workflow.



### Follow these 7 practices to ensure your AP policy sticks



Knowing what to include isn't the same as knowing how to write it. These seven decisions determine whether the policy shapes actual behavior or sits unread in a shared drive. Most teams can draft, review, and roll this out in a couple of weeks, resulting in exceptions that get handled without guesswork.

1. Write for the person doing the work

Replace passive constructions with direct instructions, and vague directives with named actions. For example, write "forward all invoices to ap@company.com within one business day of receipt" instead of "invoices should be submitted in a timely manner." Each clause should be easily understood by a department manager with no accounting background and immediately tell them what they're required to do. Clear instructions make the policy usable in the moment, when an invoice arrives and someone has to decide what to do with it.

2. Anchor each rule to a specific action in a specific tool

Match policy language to the tools your team actually uses. If your ERP refers to the payables queue as "bills," the policy should also call them "bills." If your AP tool routes approvals by dollar threshold, the policy states the exact thresholds that feed those routing rules. A policy clause with no corresponding tool action is harder to enforce consistently, so audit your own document by asking, for each rule, where in the tool it happens.

3. Keep the policy document short and push process detail into SOPs

Move detailed process flows, tool screenshots, edge cases, and role-specific instructions into separate SOPs that the policy references. The policy sets the standard, while the SOP shows how to meet it in the tool. That separation keeps the policy readable while preserving the detail operators still need. It also makes future tool updates easier because the policy and the operating steps don't have to change simultaneously.

4. Get visible sign-off from leadership before publishing

Secure explicit sign-off from the finance leader or CFO in writing before publishing, and have leadership communicate it to department heads before the document goes out. A policy with that visible endorsement carries more weight as a company requirement. Sponsorship matters because policy adoption often depends on approvers outside finance, and leadership support reduces the time AP staff spend negotiating exceptions that should already be settled.

5. Roll out by role with targeted briefings

Emailing the document isn't a rollout. A rollout tied to role tends to land better than broad distribution alone. Hold brief, role-specific briefings, including one for AP staff covering the full policy and tool walk-through, one for approvers covering exactly what changes for them, and one for any employee who regularly submits or receives invoices. For each group, the briefing should answer one question about what they do differently tomorrow. If a department head pushes back on a new threshold or requirement, route that conversation through the finance leader who already signed off.

6. Configure your AP tool to enforce the rules

For each policy requirement, identify the corresponding setting that enforces it. Approval thresholds map to routing rules in the AP tool, vendor-setup requirements map to vendor-master change controls, and duplicate detection maps to matching logic in the ERP. Rules configured into the tool can often be enforced at the transaction level without anyone having to remember them manually. [AP automation](https://www.brex.com/spend-trends/accounting/ap-automation) and the ability to [automate accounting processes](https://www.brex.com/spend-trends/accounting/how-to-automate-accounting-processes) can help turn policy language into tool logic.

7. Version and date for every release

Each published version should generally have a version number, the date it takes effect, and a named owner in the document header. A policy without a date is harder to audit, and a policy without a version number makes it less clear which version governs a past transaction under review. When a revision is made, archive the prior version and redistribute the updated one.



### How to keep your AP policy working after launch



These practices apply once the policy is live. They keep the document functioning as an active control rather than drifting back into irrelevance. A policy usually stays useful only if the finance team treats it as something to maintain, test, and refine.

Review the policy at least annually after trigger events

Many companies review their policy on an annual basis, though certain events trigger a review sooner. A formal policy update may also be required when your company changes accounting tools, adds a new entity through acquisition, receives an audit finding related to AP, or faces a change in applicable regulations. Each completed review should be version-stamped, the prior version archived, and the updated document redistributed.

Track these metrics to know whether the policy is being followed

Compliance can't be assumed, so track a small set of monthly indicators. Some examples include the following:

- Percentage of invoices received through the standard intake channel
- Average approval cycle time
- Count of invoices overdue in the approval queue

Number of policy exceptions logged per month, by departmentIf any of your metrics trend in the wrong direction after a policy update, the cause is often in the policy language, the tool configuration, or the training. Your [accounts payable best practices](https://www.brex.com/spend-trends/accounting/accounts-payable-best-practices) should include regular metric review as a standing agenda item.

Use the exception log as a policy improvement tool

The exception log shows where the policy is unclear, where thresholds are unrealistic, and where the process doesn't match how work actually flows. A recurring exception type signals either a policy update or an investigation. An empty exception log after launch isn’t a good sign either, as it usually means exceptions aren’t being documented and the informal workarounds the policy should replace are still running behind the scenes.



### Build an accounts payable policy your team will actually use



An accounts payable policy should shape how invoices arrive, how vendors are set up, how approvals are routed, and how payments are released. However, this document only shapes behavior when the company actively uses it. The moment a controller stops manually checking every approval against the written rule, the policy and the workflow start to drift apart, and no one notices until something goes wrong.

The fix lives in the workflow itself, where the rules and the process stay intertwined, rather than in a longer document. When approval thresholds, vendor-change verification requirements, duplicate detection, and separation-of-duties logic are built into the AP tool, you no longer have to be the one enforcing every rule manually.

Brex’s [accounts payable automation software](https://www.brex.com/solutions/accounts-payable-automation-software) is one way to put this into practice. Custom approval workflows route invoices based on the rules you set, so a policy requirement gets applied automatically instead of relying on your team’s memory. Brex’s AP automation uses machine learning to catch unusual invoice amounts or vendor changes, and it also requires dual sign-off multi-factor authentication before releasing payments.

When enforcement lives in the tool, everything gets traced automatically, so audits become a simple matter of pulling records instead of reconstructing them. That’s what happened with HappyCo, a global property management company that centralized its AP process with Brex before its first full audit. As Liz Hanson, Director of Accounting at [HappyCo](https://www.brex.com/resources/customer/happy-co), put it, "AP was the simplest part of the audit. Everything was in one place, and they didn't push back on a single thing."

_Created with AI assistance and reviewed by Brex. This article reflects Brex's perspective at the time of publication and is intended for general informational purposes only. It is not intended as legal, tax, accounting, or financial advice. Laws, regulations, and guidance may vary based on your specific circumstances, and interpretations or outcomes may differ. Information may also change over time. Before making any decisions, you should consult your own qualified legal, tax, accounting, or financial advisors._

_The testimonials on this website are from actual Brex and Brex Treasury clients, and reflect their personal experiences and opinions. Please note:_

_- Testimonials may not represent the experiences of all clients, which can vary based on individual goals, market conditions, and services used._

_- They are not guarantees of future results. All investments carry risk, including potential loss._

_- Clients were not compensated for their statements._

_- Testimonials are presented as provided, without substantive edits._

_- Prospective clients should conduct their own due diligence, consider their financial circumstances, and consult a qualified professional before making investment decisions._



## Frequently asked questions about accounts payable policy

### What should an accounts payable policy include?

A complete accounts payable policy covers purpose and scope, roles and responsibilities, invoice intake, coding and matching rules, approval thresholds, payment methods, vendor setup controls, documentation and retention, separation of duties, and exception handling. Each section should also name the responsible role so decisions don't drift across teams. Use this information to help inform your decision, and work with your appropriate professional advisor based on your specific circumstances.

### What are the generally accepted accounting principles (GAAP) rules for accounts payable?

Under accrual accounting, companies record accounts payable when they incur the obligation, match it to the correct accounting period, and support it with documentation that verifies the amount and timing. GAAP doesn't prescribe a specific policy format, but it does support the controls, documentation, and consistency a well-written AP policy puts in place. For company-specific accounting treatment, consult a qualified accounting professional.

### What is the difference between an AP policy and AP procedures?

An AP policy defines the rules and requirements for how invoices and payments are handled, including what must happen and who's responsible. AP procedures are the step-by-step operating instructions for applying those rules within the tools your team uses. Keeping them separate makes the policy easier to maintain and the operating details easier to update.

### How often should an AP policy be reviewed?

An annual review is a common minimum for many teams. Triggered reviews may also be needed when the company changes accounting tools, adds new entities, receives an AP-related audit finding, or faces regulatory changes. Each completed review should be version-stamped, with the prior version archived so finance can show which rules applied at a given time.

## Related Articles

### [Separation of duties in accounting: A guide to preventing errors and fraud](https://www.brex.com/spend-trends/accounting/separation-of-duties-in-accounting)

Improve financial controls with separation of duties in accounting. Find out how to implement this essential practice in your accounting department.

### [The definitive guide to accounts payable management](https://www.brex.com/spend-trends/accounting/accounts-payable-management)

Accounts payable management spans the policies and procedures for processing and paying bills. Explore how to implement effective AP management in this guide.

### [How To Structure An Accounts Payable Department That Scales](https://www.brex.com/spend-trends/accounting/accounts-payable-department)

Read this practical guide on structuring your AP department at every growth stage, from 10-500+ employees, with controls that keep close clean and audit-ready.

### [The 5 best retail ERP software systems in August 2026](https://www.brex.com/spend-trends/accounting/retail-erp-software)

Explore the 5 best retail ERP software systems for 2026. Compare solutions to optimize inventory, improve forecasting, and enhance customer relationships.

### [The complete guide to 2-way matching in accounts payable](https://www.brex.com/spend-trends/accounting/2-way-matching-in-accounts-payable)

Learn the importance of two-way matching in invoice processing. This essential verification step ensures payment accuracy and efficiency while preventing errors.

### [A Practical Guide to Switching to Paperless Accounts Payable](https://www.brex.com/spend-trends/accounting/paperless-accounts-payable)

Discover the benefits of paperless accounts payable, including cost savings, faster processing, and better accuracy. Learn practical steps to transition smoothly.
