Credit Policy · By Lenext Team · Published on 2026-08-13 · 11 min read
Credit policy: how to scale trade credit without scaling bad debt
A practical guide to turning credit policy into a growth lever — risk appetite, segmentation, cost-ordered data waterfall, limits, approval authority and the 7 KPIs your committee needs to see.
Seventy-seven percent of business-to-business transactions in Brazil are settled on terms. That is R$ 4.1 trillion that leaves the invoice and only returns to the bank account 30, 60 or 90 days later (Qive, Accounts Payable Outlook, 2026).
Every time your company issues an invoice with payment terms, it lends money. No loan agreement, no interest rate — but all of the risk.
So the question is not whether your company grants credit. It is whether it has decided how.
Without a policy, the policy is the mood of whoever approves
There is a simple test for whether a company has a credit policy. Put two analysts in front of the same customer, with the same information, and compare the decisions.
If they differ, the company does not have a policy. It has opinions.
This is not a discipline problem. It is an architecture problem: where there is no written, testable, enforced criterion, every decision becomes an isolated judgement. And isolated judgement does not scale, cannot be audited, and walks out of the door with the analyst who carried it in their head.
The cost shows up in four places, and only one of them tends to be measured.
| Cost | Where it appears | Why it goes unnoticed |
|---|---|---|
| Direct loss | Bad debt, provisions, write-offs | The only one everyone sees — and the least actionable, because it arrives late |
| Cost of capital | Cash trapped in overdue receivables | With corporate lending rates near 25% a year in Brazil (Central Bank), every idle real has a price |
| Invisible loss | Good customers rejected, timid limits, slow decisions | It appears in no report: nobody counts the order that went to a competitor |
| Compliance risk | Audit, committee, due diligence | It only hurts when someone asks for the document — and there is nothing to hand over |
The third one is the most expensive and the least discussed. Credit policy has a reputation as a brake. In practice, it is a bad policy (or the absence of one) that brakes: with no criteria, the team's default answer to any doubt is "no" — or "let me analyse it", which usually amounts to the same thing.
Policy, procedure and decision engine are not the same thing
Much of the confusion around this topic comes from treating three distinct layers as synonyms. They have different owners, different cycles and fail in different ways.
- Policy — defines. Risk appetite, criteria, limits, approval authority, exceptions. Approved by the credit committee. Changes by formal decision.
- Procedure — applies. How each criterion is verified: sources consulted, documents required, indicators calculated, the analyst's written opinion.
- Decision engine — automates. The rules parameterised in a system: automatic decision, routing to manual review, full log.
The most common failure is not writing a bad policy. It is writing a good one and never translating it into the other two layers. The Word document describes the intent; the system executes something else; and nobody compares the two.
A practical warning sign: if changing a credit rule requires opening a ticket with IT and waiting weeks, the policy does not belong to the credit team. It belongs to the development backlog.
The 7 pillars of a credit policy
This is the framework we use with credit teams. Each pillar holds up the next — skipping steps means building on sand.
1. Risk appetite
The question leadership has to answer, with a number: how much is the company willing to lose on credit in order to sustain its growth target?
Zero is not an answer. Zero risk means not selling on terms, and 77% of the B2B market sells on terms.
What has to be written down:
- Acceptable expected loss — an explicit ceiling, for example losses of up to 1.5% of annual credit sales.
- Boundaries — sectors, company sizes, regions and situations the company will not accept at any price.
- An assumed trade-off — a looser policy means more revenue and more loss; a tighter one, the opposite. If the board does not choose, the analyst chooses on its behalf, every day, without knowing it.
2. Segmentation
Not every customer deserves the same treatment. Running a committee review on an R$ 8,000 order burns money; running an automatic decision on a R$ 2 million exposure is a gamble.
| Segment | Profile | Depth of analysis |
|---|---|---|
| High volume | Low ticket, high frequency | Automatic: registry data + knockout rules + bureau, decision in seconds |
| Intermediate | Medium exposure | Automatic with sampled manual review |
| Strategic | Large limits, long contracts | Full: financial statements, systemic debt, site visit, committee |
3. Eligibility: rule out cheaply, analyse expensively
This is where money leaks without anyone noticing.
Most decision workflows run in the wrong order: paid query first, registry rule second. In a workflow with roughly 15% approval, up to 85% of bureau spend is consumed by companies that a free registry rule would have eliminated — irregular status, insufficient time in business, sector outside the appetite.
The fix is to order queries by increasing cost:
- Internal and registry data — near-zero cost
- Compliance: restrictions, watchlists, certificates — low cost
- Bureaus and indebtedness: score, protests, systemic debt — medium cost
- Deep financial analysis: balance sheet, income statement, cash flow — high cost
- Decision and limit
Reordering the workflow alone has produced up to a 64% reduction in cost per approved customer in real operations. No new rules, no new models — just no longer paying to discover what was already known for free.
4. Assessment: score, rating and matrix
A score is an input, never a decision. It states the statistical probability of default; it does not state whether that order, at that value, fits your appetite.
The internal rating combines score, financial analysis, behaviour and sector into bands (A to E). The matrix crosses that rating with the intended exposure — because medium risk at R$ 20,000 and medium risk at R$ 2 million are different decisions.
| Rating ↓ / Exposure → | Low | Medium | High |
|---|---|---|---|
| A — minimal | Automatic | Automatic | Manual review |
| B — low | Automatic | Manual review | Review + collateral |
| C — medium | Manual review | Review + collateral | Committee |
| D — high | Review + collateral | Committee | Decline |
| E — outside appetite | Decline | Decline | Decline |
One thing a traditional score will not show: systemic indebtedness. A customer can be impeccable with you and with the supplier market while carrying bank facilities that consume all of its cash generation. Debt registry queries — in Brazil, the Central Bank's SCR, where applicable — capture exactly that blind spot.
5. Limits and approval authority
Two different decisions, frequently treated as one: how much credit, and who approves it.
Limit calculation methods that work in B2B: a percentage of the customer's revenue; ability to pay derived from cash flow; a behavioural limit that grows with payment history; and a concentration cap per customer and per economic group.
And the approval matrix, which defines who signs off on what:
| Total exposure | Low risk (A–B) | Medium risk (C) | High risk (D) |
|---|---|---|---|
| Up to R$ 50k | Engine (automatic) | Analyst | Credit manager |
| R$ 50k–500k | Analyst | Credit manager | Committee |
| R$ 500k–2m | Credit manager | Committee | Committee + collateral |
| Above R$ 2m | Committee | Committee | Committee + board |
Two classic anti-patterns show up here:
- Splitting. A large order broken into several small ones so it fits the analyst's authority. The policy has to sum exposures, not evaluate isolated orders.
- The invisible economic group. Five "safe" R$ 400,000 limits granted to five entities under the same controlling shareholder are, in practice, a single R$ 2 million exposure.
6. Monitoring
A customer's risk changes every day after approval — but most operations only look at it again when an invoice comes due.
What to track: portfolio ageing, default by origination vintage, rating drift, days sales outstanding, external alerts (protests, restrictions, insolvency filings), and concentration by customer, group and sector.
And, above all, automatic triggers: what happens when an A customer becomes a C? Limit reduction, collateral requirement, order block — defined in advance, not negotiated in the heat of the moment.
The link to collections is arithmetic: more than 82% of B2B debts up to 10 days overdue are recovered; after day 20, the rate drops to roughly 50%. Monitoring that only reacts at month end misses the window in which the money still comes back.
7. Governance
The pillar that holds the other six up, and the first to be cut when deadlines get tight.
- Exceptions with method — higher approval authority, written justification, log. Above roughly 10% of decisions, the policy is miscalibrated: either the rules do not reflect reality, or they have become suggestions.
- Version control — number, date, author, changelog. Without it, nobody can answer "which rule approved this customer in March?".
- Access segregation — viewing, editing drafts and publishing to production must be distinct roles.
- Audit trail — every decision with the data consulted, the rules triggered and the person responsible.
- Review cycle — periodic (semi-annual or annual) and trigger-based (change of scenario, bad vintage, entry into a new sector).
Speed is policy, not customer service
Decision time is usually treated as an internal SLA metric. It is a commercial metric.
A customer who needs credit to close an order will not wait days for an answer if a competitor answers in hours. Every day of analysis is another day the order stays open to someone else.
The gain from standardising and automating shows up on both sides of the ledger: companies that adopted next-generation credit decisioning reduced losses by up to 40% and gained up to 40% in operational efficiency (McKinsey & Company). It is not a choice between selling and protecting yourself. It is about no longer paying the price of deciding slowly.
One caveat is worth stating: automation does not replace criteria. AI accelerates the analysis; the policy still decides. In credit, explainability is not optional — a decision nobody can justify will not survive the first committee that questions it.
The 7 indicators the committee needs to see
| KPI | What it reveals | Warning sign |
|---|---|---|
| Approval rate | How the policy is calibrated | A sharp change with no change in policy |
| Default by vintage | Quality of each month of origination | New vintages worse than older ones |
| Expected vs. actual loss | How well the model matches reality | Actual consistently above expected |
| Cost per approved customer | Efficiency of the data workflow | Growing faster than volume |
| Decision time | Commercial friction of the policy | Deals lost to slowness |
| Days sales outstanding | Capital trapped in receivables | Persistently above 45 days |
| Exception rate | Health of governance | Above 10% of decisions |
Of the seven, cost per approved customer is the one almost no operation tracks. And there is a rule that rarely fails: when it is not measured, it is high — and growing faster than volume.
The five most common mistakes
- The shelved policy. Written, approved, never parameterised. The system keeps doing what it always did.
- The copied policy. Another company's document with the logo swapped. Risk appetite is not transferable: it depends on the cash, the margin and the strategy of whoever is selling.
- A rule that never becomes code. "Prioritise established companies" is intent. "Company with less than 24 months of activity: decline" is a rule. If the sentence does not become an
IF, it is still intent. - Unlogged exceptions. Exceptions are healthy; what corrodes is the informal exception, approved over chat and never counted.
- Ignoring the cost of data. Querying everything about everyone looks like prudence. It is waste wearing the costume of care.
Where to start
You do not need to rewrite everything before changing anything. A route that usually fits in one quarter:
First weeks — diagnosis. Map the real rules (the ones the team applies, not the ones the document states), the sources consulted, the cost per query and last year's exception volume.
Following weeks — formalisation. Write the policy with a numeric risk appetite, segments, knockout rules and an approval matrix. Validate it with risk, compliance and — deliberately — with sales.
Then — parameterisation and pilot. Translate the rules into the engine and run the new policy over the last 12 to 24 months of originations before publishing it. Backtesting shows, at no cost, how many good customers the new policy would have rejected.
Finally — scale and review. Expand by product and business unit, switch on continuous monitoring and put the 7 KPIs on the committee's monthly agenda.
A credit policy is not defensive bureaucracy. It is the infrastructure that lets you say "yes" more often, faster, and knowing exactly which risk is being accepted.
If an auditor asked today for the document that defines your approval criteria, your limits and your approval authority — would you have something to hand over?