Operational policies.The controls written down, before somebody asks to see them.
Most growing businesses run on convention. Everyone knows roughly who can approve what, until the person who knew leaves, or an auditor asks, or a payment goes out that should not have. Spurwing writes the policy layer that turns convention into control: who can commit the business, to what, with whose sign-off, and what happens when somebody goes around it.
What gets written.
- Delegation of authority and approval matrixSpend thresholds, who signs, what needs two signatures, and what needs the board.
- Treasury policyBanking mandates, payment release, where cash is held and why, foreign currency exposure, and who is able to move money.
- Expense policyWhat the business pays for, what it does not, the evidence required, and how a claim gets approved.
- Financial controls documentationThe controls that actually operate, described as they operate, with segregation of duties made explicit rather than assumed.
- Procurement and supplier onboardingHow a new supplier gets onto the payment list, and who checks the bank details before the first payment leaves.
Why it earns its place.
Three moments make a policy layer worth having before you need it.
An audit, where "we just know" is not an answer. A diligence process, where the absence of documented control gets read as risk whether or not the control exists. And the day somebody does something they should not have, when the only thing standing between the business and a loss is whether the limit was written down.
How Spurwing writes them.
Not out of a template library. The policies are written against how your business actually runs, which means a short piece of work first to establish who approves what today and where the gaps sit.
A policy nobody follows is worse than no policy, because it documents a control you do not have.
What you get. The documents in a form the board can adopt, the adoption resolutions to go with them, and a walkthrough with the people who have to operate them. Policies that live in a folder nobody opens were not worth writing.
Not sure what is actually documented?
That is the usual starting point. A short review establishes what exists, what is assumed, and what is missing.
Start a conversation