Credit Policy

An approved governance framework defining acceptable credit risk, underwriting standards, authority, limits, documentation, monitoring, exceptions, and collection practices.

A credit policy is an approved governance framework that defines which credit risks an organization may accept and how those risks must be originated, approved, documented, monitored, and resolved. It translates risk appetite and legal requirements into usable limits, underwriting standards, delegated authority, exception rules, and review controls.

A policy is not a substitute for analyzing an individual borrower. It establishes decision boundaries and accountability so similar requests are evaluated consistently and material risks reach the right approver.

Key Takeaways

  • A credit policy should identify acceptable products, markets, borrowers, structures, concentrations, and risk levels.
  • It should separate mandatory requirements from guidelines that permit documented judgment.
  • Approval authority must consider total related exposure, not merely the amount of one new request.
  • Exceptions should identify the provision, reason, risk, mitigants, approver, duration, and monitoring.
  • Procedures explain how to implement policy; they should not quietly change the policy’s risk boundary.
  • Policy must be reviewed when products, law, economic conditions, portfolio performance, or operating systems change.
  • A policy that is routinely bypassed is not an effective control, even if the document appears comprehensive.

What a Credit Policy Usually Covers

AreaQuestions the policy should answer
Scope and strategyWhich products, borrower types, industries, geographies, and purposes are permitted or restricted?
UnderwritingWhat evidence, repayment analysis, stress testing, collateral, and risk grading are required?
Terms and structureWhat maturities, amortization, pricing, advance rates, covenants, and guarantees are acceptable?
Approval authorityWho may approve, decline, condition, renew, modify, or waive terms, and within what limits?
Exposure aggregationHow are related borrowers, guarantors, facilities, committed amounts, and exceptions combined?
ConcentrationsWhat portfolio limits and escalation triggers apply by product, industry, geography, collateral, or channel?
DocumentationWhich agreements, filings, insurance, valuations, and closing conditions are required?
AdministrationHow are payments, covenants, collateral, exceptions, renewals, and risk grades monitored?
Problem creditWhen are accounts placed on watch lists, downgraded, transferred to workout, or charged off?
CollectionsWhat escalation, customer treatment, legal review, and approval controls apply?
Reporting and reviewWhich metrics reach management or the board, how often, and who tests compliance?

The appropriate detail depends on the organization. A bank, bond investor, manufacturer offering trade credit, and fintech lender do not need identical documents.

DocumentPrimary purposeExample
Risk appetiteStates the amount and types of risk the organization is willing to takeTarget portfolio mix and maximum concentration tolerance
Credit policyDefines binding decision and control frameworkApproval limits, underwriting requirements, exception authority
ProcedureExplains how staff perform a required processHow to verify income or prepare a covenant test
Product programApplies policy to one product or channelEligibility and pricing for a small-business line
Credit memorandumApplies evidence and policy to one requestBorrower analysis, proposed structure, risks, recommendation
Credit agreementCreates contractual rights and obligationsAmount, interest, covenants, collateral, events of default

Policy should not contain every screen click or operational detail. Procedures can change more frequently, but they should remain consistent with approved policy.

Worked Example: Applying an Approval Matrix

Assume a policy delegates approval based on total related exposure:

AuthorityMaximum total exposureOther boundary
Credit officer$500,000No policy exceptions
Senior credit officer$1,500,000Limited documented exceptions
Credit committee$5,000,000Within portfolio and legal limits

A borrower group already has $1.2 million outstanding and requests a new $700,000 facility. The combined exposure would be $1.9 million.

The request exceeds the senior credit officer’s $1.5 million total-exposure authority even though the new facility alone is only $700,000. It should be escalated to the credit committee under this hypothetical matrix.

Before escalation, the file should also determine:

  • whether undrawn commitments and guarantees count toward exposure;
  • whether related entities must be aggregated;
  • whether an exception or adverse risk grade changes the authority level;
  • whether a concentration or legal lending limit is implicated; and
  • whether approval conditions must be completed before funding.

Splitting the request into smaller facilities should not be used to avoid the required authority.

Mandatory Standard or Judgment Guideline?

Clear drafting distinguishes:

  • prohibition: the organization will not extend the specified type of credit;
  • mandatory eligibility requirement: the request cannot be approved without satisfying the rule;
  • approval condition: a stated action must occur before or after closing;
  • guideline: the normal expectation, with an authorized exception path;
  • monitoring trigger: a condition requiring review, escalation, or reporting; and
  • portfolio limit: an aggregate boundary rather than an individual-loan test.

Vague words such as normally, generally, or acceptable can create inconsistent decisions unless the policy explains judgment, evidence, and escalation.

Managing Policy Exceptions

An exception is a deliberate departure from a policy requirement or guideline. It is not the same as a missing document, borrower covenant breach, model override, or legal violation, although one request can involve several types of deviation.

A useful exception record includes:

  1. the exact policy provision;
  2. the reason compliance is not achieved;
  3. the additional risk created;
  4. relevant compensating factors or mitigants;
  5. the requested duration and cure plan;
  6. the authorized approver;
  7. monitoring and reporting requirements; and
  8. whether similar approvals reveal a policy design problem.

An approver cannot waive a law, binding program rule, or requirement outside that person’s authority. Repeated exceptions can indicate that the policy is unrealistic, staff are not following it, or risk appetite has changed without formal approval.

Fair and Consistent Application

For covered credit decisions, policy and discretion should be applied consistently and in accordance with fair-lending and other applicable requirements. Controls can include:

  • defined underwriting criteria and permitted data;
  • comparable assistance and exception treatment;
  • documented reasons tied to facts in the file;
  • review of overrides, approvals, counteroffers, and denials;
  • monitoring by product, channel, decision maker, and relevant applicant groups; and
  • accurate adverse-action notices when required.

Consistency does not require identical outcomes for borrowers with materially different facts. It requires that relevant differences, rather than prohibited or unsupported considerations, explain the outcome.

Reviewing Policy Effectiveness

Policy review should consider both design and actual results:

  • approval, decline, counteroffer, and withdrawal patterns;
  • policy and pricing exceptions by type and approver;
  • delinquencies, defaults, losses, recoveries, and risk-grade migration;
  • concentrations and limit breaches;
  • documentation and collateral exceptions;
  • complaints and fair-lending monitoring;
  • model performance and overrides;
  • new products, channels, vendors, or data sources; and
  • changes in law, regulation, funding, and economic conditions.

Low losses do not automatically prove strong policy if the portfolio is new, rapidly growing, or supported by unusually favorable conditions.

Common Mistakes

  • Copying another lender’s policy without adapting it to products, authority, systems, and risk appetite.
  • Mixing mandatory rules and flexible guidelines without an exception process.
  • Setting approval limits by new money while ignoring total related exposure.
  • Letting procedures or model settings change risk boundaries without proper approval.
  • Recording exception counts without age, severity, concentration, or outcomes.
  • Reviewing policy on a calendar schedule while ignoring material business changes.
  • Treating collateral as the primary repayment source for ordinary lending.
  • Writing a policy so broad that nearly every decision appears compliant.

Risks and Limitations

A written policy cannot compensate for unreliable information, weak analysis, conflicts of interest, poor systems, unauthorized overrides, or ineffective monitoring. Policy also cannot replace product-specific legal, accounting, consumer-protection, or regulatory advice.

This page is educational and is not personalized lending, legal, compliance, accounting, or financial advice.

Authoritative Sources

FAQs

Who approves a credit policy?

Approval depends on the organization and applicable governance requirements. A bank’s board commonly approves core lending policy, while delegated bodies may approve procedures or product details within defined authority.

Is a credit policy the same as underwriting guidelines?

No. Underwriting guidelines are one part of the policy framework. Credit policy also addresses authority, concentrations, documentation, administration, exceptions, collections, monitoring, and governance.

Can a lender make an exception to credit policy?

Only when the policy permits it, the approver has authority, the departure is documented, and no mandatory legal or program rule is waived.

How often should credit policy be reviewed?

There is no universal interval for every organization. Review should be periodic and should also occur when products, law, portfolio performance, systems, vendors, or economic conditions materially change.
Browse Credit and Lending