Spend Policy Design and Enforcement
How to move spend controls before the purchase instead of after.
An expense report submitted three weeks after a purchase is an autopsy. It's an autopsy. The whole architecture of spend policy is built backward: a purchase happens, then finance finds out, then someone decides whether it should have happened at all. By then the money's gone, the vendor's already invoiced, and the "review" step is just paperwork with extra steps. This piece is about the shift away from that model, and what it takes to build a policy that stops bad spend before the card even swipes.
Start with maverick spend, the entry wound for basically every budget headache finance teams deal with. It's the purchase made outside approved channels, the booking done on a personal card, the SaaS subscription a marketing manager signed up for on a Tuesday afternoon because the approved tool "felt slow." According to the Skift and Navan State of Corporate Travel and Expense report, a significant share of business travel bookings now happen entirely outside approved tools, which weakens the company's negotiating power with vendors and wrecks forecasting. That's not a rounding error. It weakens the company's negotiating power with vendors, and it quietly wrecks forecasting, because finance is planning around numbers that don't reflect what's actually being spent.
Research on procurement performance puts a number on the damage: organizations can lose a significant share of targeted savings to maverick buying, a meaningful loss rather than marginal leakage. That's not marginal leakage. That separates a procurement team that looks good in a board deck from one that's actually delivering.
The root cause isn't defiance. Employees aren't rebelling against the rules. They bypass policy because the compliant path is slower, clunkier, or just less obvious than whatever workaround they reach for under deadline pressure. Tighten the language, add more audits, raise the stakes for getting caught, and none of that closes the gap. It just adds friction to a process that already has too much of it. If the compliant path can't compete on speed and convenience, enforcement was always going to lose.
What a spend policy contains and where each component tends to break down
Every spend policy, stripped down, needs to communicate three things: what counts as an eligible expense, what dollar amount triggers approval, and what documentation is required to prove it happened. Simple in theory. Messy in practice.
Approval thresholds aren't one-size-fits-all. They shift by business unit, cost center, geography, project code, and category. Capital expenditure might need a finance controller's sign-off. Indirect spend might route through sourcing and then legal. Layer in the IRS's accountable plan rules, which require that substantiation and documentation happen on a timely basis; missing that window means reimbursements can legally become taxable wages. Systems that capture documentation automatically at the point of transaction are the only real way to keep pace with that requirement.
Here's where it usually falls apart. Categories end up either so broad nobody can enforce them, or so narrow that employees just guess and submit anyway, figuring finance will sort it out later. Thresholds get buried in a PDF that lives on a shared drive nobody opens until an audit forces them to. And documentation gets collected after the fact, once the context is gone and half the receipts have vanished into a jacket pocket or a deleted email.
Industry benchmarks set targets that most organizations fall short of, with maverick spend and purchase order compliance both measured against thresholds that demand consistent, proactive controls. Most organizations fall well short of both.
SaaS makes every one of these problems worse. Business units subscribe directly to tools now, no IT involved, no finance sign-off, and the result is a fragmented mess where duplicate subscriptions pile up and approvals get routed around entirely because there was never a gate to route around in the first place. Zylo's SaaS Management Index found the average company spends a substantial sum a year on SaaS. At that scale, an unmanaged, undocumented subscription is a real budget risk sitting quietly on the books. It's a real budget risk sitting quietly on the books.
The shift from post-spend review to pre-spend control
The old model is familiar to anyone who's filed an expense report: spend first, submit later, wait for a reviewer to approve or reject something that's already happened. The money already moved. The "control" is really just a delayed opinion.
The model taking over works the other direction. Card authorization, merchant data, applicable tax and VAT rates, and policy rules all get checked before the transaction clears, not after. By 2026, this shift isn't just a best-practice trend, it's being forced structurally by the global spread of continuous transaction controls and e-invoicing mandates that are moving the control point earlier in the process. The control point is moving earlier in the process because regulation is dragging it there.
What that looks like on the ground:
- Corporate and virtual cards with per-card spend limits, merchant category restrictions, and the ability to block a transaction in real time
- Approval workflows that trigger before a purchase order is even issued, rather than after an expense report lands in someone's inbox
- Policy rules built into the payment instrument itself, so the card simply refuses to work outside its approved parameters
The behavioral shift matters more than the technical one. Compliance shifts from a choice the employee makes to the default the system enforces because the system now handles enforcement automatically. Nobody has to be virtuous. The card just doesn't work for the wrong thing.
There's a measurable payoff too. Research into automated travel and expense tools consistently finds that processing time drops substantially compared to manual methods. Pre-spend controls don't just catch fewer violations, they also cut the administrative overhead of catching them at all.
None of this means clamping down until nobody can buy a stapler without three signatures. Too little oversight and the policy is a suggestion. Too much and legitimate, in-policy purchases grind to a halt. The goal is consistent enforcement that stays invisible to anyone doing things the right way.
How card-level controls and unified platforms embed policy into the purchase moment
Corporate card programs have quietly become the actual infrastructure of policy enforcement. Spend limits get set by employee or role. Merchant category codes block vendors that fall outside policy. And critically, the transaction gets blocked before it clears, not flagged in a report three weeks later.
Virtual cards do something similar for SaaS specifically: hard spend limits per subscription, approval workflows tied to whatever cost threshold a company sets. The card enforces the budget directly. Nobody has to audit it after the fact because there's nothing to overspend into.
Unified travel and expense platforms tie booking and payment into a single system, so policy gets checked at the moment of booking rather than getting reconciled against it weeks later. That closes the gap between what got approved and what actually happened, which used to be the exact gap maverick spend lived in.
Procurement intake works the same way when it's built right. An intake form triggers a policy check automatically, routes the request to the correct approver based on amount and category, and generates a purchase order before any money changes hands. No reconciliation needed afterward, because the check already happened before the purchase.
Dashboards and anomaly detection sit as a second layer on top of all this. Spend broken out by department, category, or merchant reveals patterns, like a team's meal costs creeping up, or one group racking up exceptions more than everyone else, without anyone reviewing every line item by hand. Automated anomaly detection flags weird vendor activity, repeat exceptions, or duplicate charges, so compliance teams spend their time on outliers instead of babysitting every transaction.
A few platforms illustrate the range of how this gets built. Expensify uses policy enforcement that catches violations, wrong category, amount too high, before they ever post to the books; its Visa Commercial Card syncs transactions in real time, and it's SOC 2 Type II and GDPR-ready, aimed mostly at growing SMBs and distributed teams. Cledara turns written AI tool policy into active enforcement through virtual cards with hard per-subscription limits, workflows tied to cost thresholds, and compliance questionnaires built specifically for AI tool requests. Zip focuses on procurement intake and workflow standardization, plugging into NetSuite, Coupa, and Slack, priced per user, SOC 2 certified. Ramp pairs spend controls with expense automation and leans on real-time visibility and budgeting, with a free tier available. Brex is card-led spend control built for startups and companies scaling into global spend management. Spendesk is finance-led, covering cards, expenses, and accounts payable, aimed at mid-market companies roughly in the 50 to 1,000 employee range.
According to Expensify, 84% of finance leaders say visibility and control over spend is critical to how the business performs. That's not a footnote, it's the reason pre-spend architecture has become the standard build, not a nice-to-have upgrade.
What AI-native policy agents add, where the hype still outpaces the evidence
As of 2026, the AI applications that actually work reliably in spend management are the boring ones. Anomaly detection flags spending that breaks from historical patterns in real time. Automated receipt processing using OCR kills off manual data entry at the point of submission. Spend analytics reveals category trends and vendor concentration risks without anyone building a pivot table.
Agentic AI goes a step further, at least on paper: interpreting unstructured data, weighing risk, routing requests to the right approver, escalating based on policy thresholds. It operates inside the governed workflows and role permissions an organization sets up; an agent without guardrails is just a fast way to make the same mistakes at scale.
A few named examples show where this stands today. Ramp's Policy Agent reviews every employee transaction against expense policy and makes recommendations, with the vendor reporting accuracy above 99%. Zip launched Superagents in 2026, governed AI agents that run procurement workflows autonomously, alongside AI Contract Orchestration for automating supplier contract review, negotiation, and compliance. Coupa's SpendGuard adds AI-powered fraud detection inside its unified spend platform; Coupa was named a Leader in three separate 2025 IDC MarketScape reports covering AI-enabled source-to-pay, procure-to-pay, and buy-side contract lifecycle management. GEP SMART targets large procurement teams with AI-driven spend analytics and sourcing, integrating with SAP, Oracle, and Microsoft Dynamics, with ISO 27001 and SOC 2 certification.
Now the caveat, and it's a real one. Only 15% of AI decision-makers reported an EBITDA lift from AI investments over the past year, and fewer than about a third can even tie AI spend to a real change in profit and loss. A meaningful chunk of planned AI investment is getting pushed into 2027 as inflated vendor promises collide with a market that's correcting hard. AI enforcement earns its keep by cutting manual review of routine, low-stakes transactions. It hasn't earned the right to replace human judgment on exceptions, edge cases, or anything with real money riding on it.
None of it works, though, without an unglamorous prerequisite: turning policy documents (thresholds, risk criteria, business rules) into a format machines can actually read. Without that step, an agent is just applying rules to input it can't parse correctly, confidently.
SaaS and AI tool spend as the hardest category to control at point of purchase
Business units subscribe directly to collaboration tools, analytics platforms, customer engagement software, developer tools, and AI applications constantly now, and finance and IT often find out last, if they find out at all. Zylo's report puts shadow IT at roughly a third of the average company's application stack. Those tools carry untracked spend, security exposure, and governance gaps all at once, stacked on top of each other.
The waste is measurable. Zylo's SaaS Management Index found organizations waste a substantial sum on average each year on unused licenses. And per a cloud risk-scoring index cited in Zylo's report, 46% of applications in the average stack carry poor or low risk scores. Spend risk and compliance risk are the same problem wearing two hats in an unmanaged SaaS stack. They're the same problem wearing two hats.
AI tools add a layer that older SaaS policy frameworks were never built to handle. The category moves faster than any other software segment, usage-based pricing makes budgets swing unpredictably month to month, and a tool that looked best-in-class six months ago might already be outclassed by two or three competitors. An annual policy review cycle, standard for most SaaS categories, is far too slow for AI governance in 2026.
The policy responses built for this specific problem look different from standard SaaS controls. Procurement intake forms trigger a policy check before any subscription activates, not after. Virtual cards carry hard limits per subscription instead of per employee, which matters because one employee might reasonably need five tools. Compliance questionnaires built specifically for AI tool requests capture security posture, data handling practices, and cost at the moment of request, not after the tool's already embedded in someone's workflow. And utilization reviews happen quarterly, checking usage rates, cost efficiency, security posture, and shifts in the market, on a cycle that actually matches how fast this category moves.
A handful of platforms focus specifically on SaaS visibility rather than broader spend management. Zylo tracks SaaS usage and license optimization, integrating with Okta, Azure Active Directory, and HR systems, quote-based pricing, SOC 2 certified. Productiv tracks application usage and ROI for SaaS-heavy organizations, integrating with SSO providers and HR platforms, custom enterprise pricing, SOC 2 and GDPR compliant. Zylo's own June 2026 roundup of top SaaS spend management tools also named Zluri, CloudEagle, BetterCloud, Lumos, Torii, FlexeraOne, and ServiceNow SAM Pro. On the purchasing side, Vendr helps companies buy and renew SaaS contracts with pricing benchmarks, working on a success-fee model, SOC 2 certified, while Tropic handles SaaS purchasing and vendor negotiation for companies managing large contract portfolios, custom pricing based on portfolio size, also SOC 2 certified.
Why employees route around compliant systems
Low compliance almost always means the booking tool is clunky, the approval workflow adds a two-day delay to something that needed an answer in an hour, and the consumer-grade alternative sitting one tab over is simply faster. It means the booking tool is clunky, the approval workflow adds a two-day delay to something that needed an answer in an hour, and the consumer-grade alternative sitting one tab over is simply faster.
Every extra approval step, every form demanding manual entry, every system that doesn't plug into the tools employees already use day to day, is a leak point. Compliance doesn't drop because people are careless. It drops because the workaround is genuinely, measurably easier. Expensify's research found companies waste an average of 25% to 30% of their SaaS budgets every year, and that number reflects bad policy adoption at least as much as it reflects bad contract terms.
A few behavioral levers work alongside the system-level controls, rather than replacing them:
- Rewarding departments that hit over 90% policy adherence with budget flexibility, recognition, or a cut of the savings, so compliance earns something instead of just avoiding a scolding
- Simple leaderboards that show adherence rates by team, creating competitive pressure without adding another layer of enforcement
- Transparent dashboards that let teams see their own spend patterns directly, building accountability without a top-down audit hanging over anyone
The Hackett Group's research backs this up structurally: top-performing procurement organizations generate more than double the cost savings of their peers, lose 60% less of those savings to noncompliance, and pull in several times greater cost savings by staying ahead of opportunities and keeping renegotiation leverage intact. Culture and structure aren't competing approaches here. They reinforce each other, or they don't work at all.
The test for any policy is blunt: if the compliant path takes more steps than the workaround, the policy loses, no matter how well it was written. Every friction point in the "approved" process is a risk in disguise.
How to measure whether pre-spend controls are working
Three numbers tell most of the story, and they come from widely cited industry benchmarks. Maverick spend percentage should sit below 10% of total spend. Purchase order compliance should sit above 95%. And savings leakage recovered, the gap between targeted savings and what actually lands, should be tracked directly rather than assumed away.
Anything short of those numbers means the policy is still being enforced after the money's gone, no matter how the system is described internally. Pre-spend control isn't a feature checkbox. A policy that gets followed because it's easiest is different from one that gets followed only when someone's watching.