Login

Checklist

The Credit Application Audit Checklist

A checklist document with several items checked in green and two flagged items highlighted in amber, next to a credit file folder icon
July 18, 20267 min read

Most credit departments can tell you their process works. Fewer can show it — in writing, applied the same way to every applicant, with a paper trail that would hold up if a lender, insurer, or auditor asked to see it. That gap usually isn't visible until something forces the issue: a bad debt write-off big enough to draw questions, a new controller who wants documentation that doesn't exist, or an audit that finds three different credit managers have been making three different calls on the same type of account.

This checklist is built around the credit policy framework NACM (the National Association of Credit Management) has taught for decades, organized into the categories a wholesale distributor actually needs to get right. Run through it against your current process — not against how you'd like it to work, but against what actually happens the next time someone submits a credit application.

1. Is there an actual written policy — not just institutional knowledge?

A credit policy is a written document, approved by senior management, that states the company's position on credit risk and how credit decisions get made — as distinct from credit procedures, which are the specific steps used to carry that policy out. If your credit decisions live primarily in one person's head, you don't have a policy, you have a person, and the two are not the same thing when that person is out sick, on vacation, or leaves the company.

  • A written credit policy exists and has been formally approved by senior management
  • The policy is distinct from procedures — it states principles, not just steps
  • The policy is reviewed and updated on a set interval, not left stale for years
  • New credit staff are trained against the written policy, not just shadowing a colleague

2. Does the policy actually cover the full decision lifecycle?

NACM's own checklist for a well-defined credit policy runs to more than twenty items, spanning far more than just "how do we decide credit limits." A genuinely complete policy addresses the organizational structure of the credit function, what documentation is required in a credit file, how credit information gets gathered, time limits for turning around a decision, how new credit lines get established, and — critically — how the decision gets communicated to the customer, to sales, to operations, and to management, so nobody downstream is left guessing.

  • The department's formal structure, roles, and review process are documented
  • Required credit file documentation is specified — not left to individual discretion
  • Methods for gathering credit information are standardized across the team
  • A time limit exists for how long a credit decision should take
  • The process for establishing new credit lines is documented
  • Communication procedures exist for notifying the customer, sales, operations, and management of a decision
  • Guidelines exist for handling marginal or borderline accounts
  • Policies exist for disputes, unauthorized deductions, and returned or damaged merchandise

3. Is the decision actually consistent across applicants?

This is where most "we have a process" claims quietly fall apart. Consistency doesn't mean every applicant gets the same limit — it means every applicant is evaluated against the same inputs, using the same method, regardless of which credit manager or rep happens to handle the file. If two similar applicants can get meaningfully different outcomes depending on who reviewed them, that's not a policy problem, it's an execution problem, and it's exactly the kind of inconsistency that looks bad under any kind of external review.

  • Every applicant is evaluated using the same defined method (formula, payment performance, or a combination) — not left to individual judgment alone
  • The reasoning behind each credit decision is documented, not just the outcome
  • A second reviewer or approval threshold exists for larger credit lines
  • Exceptions to standard policy are logged and require sign-off, not made silently

4. Is credit approval actually separated from the functions it should be separated from?

Segregation of duties is one of the most basic internal controls in accounts receivable, and one of the most commonly skipped at smaller companies. The principle is simple: no single person should control an entire transaction cycle. The person who approves a customer's credit shouldn't be the same person with authority to write off that customer's bad debt, and the person applying cash receipts shouldn't be the same person reconciling the account. When those lines blur, both fraud risk and simple error risk go up — and it's exactly the kind of gap an auditor or lender will flag first.

  • Credit approval authority is separate from collections and write-off authority
  • Cash application is separate from account reconciliation
  • Large or unusual credit decisions require review by someone other than the original approver
  • Access to credit and AR systems is reviewed periodically for role overlap

5. Is the credit file itself actually defensible?

If a credit decision were questioned six months from now, could you reconstruct exactly why it was made? A defensible file isn't just the application — it's the reference checks, whatever financial data was gathered, the score or limit calculation, and a record of who approved it and when.

  • Each credit file contains the original application and any supporting financial documentation
  • Bank and trade reference results are documented, not just referenced verbally
  • The specific method used to calculate the credit limit is recorded, not just the final number
  • Approval sign-off is timestamped and attributable to a specific person

6. Is the limit revisited — or set once and forgotten?

A credit policy that only governs the initial decision isn't actually managing risk — it's managing onboarding. NACM's guidance on monitoring credit performance points to ongoing measurement against benchmarks like DSO and bad debt expense as part of the policy itself, not an afterthought. If your process has no defined trigger for revisiting an existing limit, every approved account is quietly aging out of relevance the moment the ink dries.

  • A defined cadence exists for reviewing existing credit limits, not just new applications
  • Specific triggers (missed payment, bureau change, order pattern shift) prompt an off-cycle review
  • Portfolio-level metrics like DSO and bad debt are tracked against policy goals, not just individual accounts

Using this checklist

Go through it honestly, not aspirationally. Most credit departments will find they're strong in one or two sections and thin in the rest — usually strong on the initial decision and weak on ongoing review, or strong on paperwork and weak on segregation of duties. That unevenness is normal. What matters is knowing where the actual gap is, rather than assuming "we have a process" covers all six areas equally.

If the honest answer is that most of this lives in one person's judgment rather than a documented, consistently applied system, that's not a character flaw in your credit department — it's what happens when a growing distributor never had the time to formalize what already works informally. That's the specific gap Thor's Credit Applications are built to close: a consistent, documented decision on every applicant, with the reasoning behind the recommended limit visible every time, not just when someone remembers to write it down.

If you want to see what a fully documented, consistent process looks like against your own accounts, book a free demo and we'll walk through it live.

Ready to see Thor on your accounts?

Book a free demo and we'll walk through your book live.