An approved governance framework defining acceptable credit risk, underwriting standards, authority, limits, documentation, monitoring, exceptions, and collection practices.
A credit policy is an approved governance framework that defines which credit risks an organization may accept and how those risks must be originated, approved, documented, monitored, and resolved. It translates risk appetite and legal requirements into usable limits, underwriting standards, delegated authority, exception rules, and review controls.
A policy is not a substitute for analyzing an individual borrower. It establishes decision boundaries and accountability so similar requests are evaluated consistently and material risks reach the right approver.
| Area | Questions the policy should answer |
|---|---|
| Scope and strategy | Which products, borrower types, industries, geographies, and purposes are permitted or restricted? |
| Underwriting | What evidence, repayment analysis, stress testing, collateral, and risk grading are required? |
| Terms and structure | What maturities, amortization, pricing, advance rates, covenants, and guarantees are acceptable? |
| Approval authority | Who may approve, decline, condition, renew, modify, or waive terms, and within what limits? |
| Exposure aggregation | How are related borrowers, guarantors, facilities, committed amounts, and exceptions combined? |
| Concentrations | What portfolio limits and escalation triggers apply by product, industry, geography, collateral, or channel? |
| Documentation | Which agreements, filings, insurance, valuations, and closing conditions are required? |
| Administration | How are payments, covenants, collateral, exceptions, renewals, and risk grades monitored? |
| Problem credit | When are accounts placed on watch lists, downgraded, transferred to workout, or charged off? |
| Collections | What escalation, customer treatment, legal review, and approval controls apply? |
| Reporting and review | Which metrics reach management or the board, how often, and who tests compliance? |
The appropriate detail depends on the organization. A bank, bond investor, manufacturer offering trade credit, and fintech lender do not need identical documents.
| Document | Primary purpose | Example |
|---|---|---|
| Risk appetite | States the amount and types of risk the organization is willing to take | Target portfolio mix and maximum concentration tolerance |
| Credit policy | Defines binding decision and control framework | Approval limits, underwriting requirements, exception authority |
| Procedure | Explains how staff perform a required process | How to verify income or prepare a covenant test |
| Product program | Applies policy to one product or channel | Eligibility and pricing for a small-business line |
| Credit memorandum | Applies evidence and policy to one request | Borrower analysis, proposed structure, risks, recommendation |
| Credit agreement | Creates contractual rights and obligations | Amount, interest, covenants, collateral, events of default |
Policy should not contain every screen click or operational detail. Procedures can change more frequently, but they should remain consistent with approved policy.
Assume a policy delegates approval based on total related exposure:
| Authority | Maximum total exposure | Other boundary |
|---|---|---|
| Credit officer | $500,000 | No policy exceptions |
| Senior credit officer | $1,500,000 | Limited documented exceptions |
| Credit committee | $5,000,000 | Within portfolio and legal limits |
A borrower group already has $1.2 million outstanding and requests a new $700,000 facility. The combined exposure would be $1.9 million.
The request exceeds the senior credit officer’s $1.5 million total-exposure authority even though the new facility alone is only $700,000. It should be escalated to the credit committee under this hypothetical matrix.
Before escalation, the file should also determine:
Splitting the request into smaller facilities should not be used to avoid the required authority.
Clear drafting distinguishes:
Vague words such as normally, generally, or acceptable can create inconsistent decisions unless the policy explains judgment, evidence, and escalation.
An exception is a deliberate departure from a policy requirement or guideline. It is not the same as a missing document, borrower covenant breach, model override, or legal violation, although one request can involve several types of deviation.
A useful exception record includes:
An approver cannot waive a law, binding program rule, or requirement outside that person’s authority. Repeated exceptions can indicate that the policy is unrealistic, staff are not following it, or risk appetite has changed without formal approval.
For covered credit decisions, policy and discretion should be applied consistently and in accordance with fair-lending and other applicable requirements. Controls can include:
Consistency does not require identical outcomes for borrowers with materially different facts. It requires that relevant differences, rather than prohibited or unsupported considerations, explain the outcome.
Policy review should consider both design and actual results:
Low losses do not automatically prove strong policy if the portfolio is new, rapidly growing, or supported by unusually favorable conditions.
A written policy cannot compensate for unreliable information, weak analysis, conflicts of interest, poor systems, unauthorized overrides, or ineffective monitoring. Policy also cannot replace product-specific legal, accounting, consumer-protection, or regulatory advice.
This page is educational and is not personalized lending, legal, compliance, accounting, or financial advice.