Stronger oversight for university procurement card programs

Procurement cards can help universities purchase low-dollar goods quickly, reduce paperwork, and give departments practical control over routine spending. They can also create significant exposure when cardholders, approvers, merchants, and financial systems operate without clearly defined boundaries. A well-managed program therefore treats each transaction as both a business activity and a public-record financial event.

At Texas public universities and related state agencies, oversight must support operational efficiency while protecting public funds. Program administrators should align card practices with state requirements, institutional policies, grant restrictions, accounting standards, and audit expectations. The goal is not to make every purchase slow or difficult; it is to make authorized spending easy to document and improper spending difficult to conceal.

Effective governance combines policy, technology, training, monitoring, and accountability. Senior business officers have an important role in connecting these elements across finance, procurement, departments, information technology, internal audit, and executive leadership.

Establish clear ownership and accountability

A procurement card program should have a designated owner with authority to maintain policy, set operating standards, coordinate training, and escalate exceptions. Depending on the institution’s structure, this responsibility may sit with procurement, finance, or a shared services function. Regardless of the reporting line, the owner needs a complete view of the card lifecycle, from application and issuance through suspension, reconciliation, and closure.

A written responsibility matrix can prevent gaps between central administration and departments. It should identify who approves applications, assigns credit limits, reviews transactions, verifies receipts, resolves disputed charges, monitors dormant accounts, and terminates cards when employees transfer or leave. Supervisors should not approve their own transactions, and cardholders should not be placed in a position where they can initiate, approve, and reconcile the same purchase.

The program should also define consequences for noncompliance. A late receipt may require a reminder and corrective training, while intentional misuse, personal purchases, split transactions, or falsified documentation may require immediate suspension and referral to appropriate authorities. Consistent enforcement is essential because exceptions become an unofficial policy when they are routinely overlooked.

Design policies around risk and purpose

A procurement card policy should explain what the card is intended to accomplish, which purchases are allowed, and which controls apply to different spending categories. Broad statements such as “use the card for business purposes only” are not enough. Cardholders need practical guidance on travel, hospitality, technology, subscriptions, emergency purchases, contracted goods, restricted commodities, and purchases involving sponsored funds.

Dollar thresholds should be designed around institutional risk. A single-transaction limit may be appropriate for ordinary supplies, while monthly limits and merchant restrictions can provide additional protection. The policy should prohibit transaction splitting, in which one purchase is divided into multiple charges to avoid a threshold or approval requirement. It should also address sales tax, shipping charges, tips, returns, warranties, recurring payments, and purchases from employees or related parties.

Universities should maintain a current list of prohibited or restricted merchants and commodities. Merchant category codes can block many high-risk transactions, but they are not perfect: a legitimate vendor may be classified incorrectly, and an inappropriate purchase may be processed under a general category. For that reason, category blocking should supplement human review rather than replace it. For example, administrators can examine how online gambling reviews illustrate the importance of distinguishing entertainment-related merchant activity from legitimate institutional spending when configuring restricted categories and exception procedures.

Strengthen the application and training process

Card issuance should follow a documented application process that confirms the employee’s job responsibilities, department, supervisor, funding source, and business need. Credit limits should be based on expected purchasing volume rather than convenience. Central administrators should review unusually high limits, temporary increases, and requests for multiple cards within a department.

Before receiving a card, each employee should complete training on allowable costs, documentation standards, security, fraud prevention, dispute procedures, and consequences for misuse. Training should include realistic examples drawn from the university’s own transactions. A short annual certification can reinforce expectations, but it should not be the only learning opportunity. Supervisors and reconciliers need separate training because their review duties differ from those of cardholders.

Access should be reviewed whenever an employee changes roles, transfers departments, takes extended leave, or separates from the institution. Human resources and finance systems should communicate promptly so that cards can be suspended or closed without waiting for a monthly report. Physical cards, virtual cards, and account credentials should be handled through the same lifecycle controls.

Connect transaction data with review procedures

Monthly reconciliation is a foundational control, but a strong program does more than match a statement total to a ledger entry. The reviewer should confirm the business purpose, itemized receipt, date, vendor, funding source, account code, approval, and compliance with applicable restrictions. Documentation should be stored in a system that allows authorized reviewers and auditors to retrieve it efficiently.

Technology can improve oversight by combining card feeds with the enterprise resource planning system, purchasing platform, travel system, and employee records. Automated alerts can identify unusual amounts, weekend activity, duplicate invoices, rapid repeat purchases, transactions near approval thresholds, and spending after an employee’s separation date. Data analytics can also reveal patterns across departments that may not be visible during a single monthly review.

Oversight area Practical control Evidence to retain Escalation trigger
Card issuance Documented application and supervisor approval Application, training record, assigned limit Missing business need or unusual limit
Transaction review Independent review of receipt, purpose, coding, and approval Receipt, business justification, approval history Unsupported, late, or restricted purchase
Merchant controls Category restrictions and vendor monitoring Exception log and configuration history Repeated attempts at blocked merchants
Reconciliation Timely monthly certification by cardholder and reviewer Signed certification and reconciliation report Unreconciled items or recurring delays
Account lifecycle Prompt suspension, closure, and periodic access review Closure record and access review results Terminated or transferred employee with active card
Program monitoring Trend analysis and risk-based sampling Monitoring reports and corrective action records Repeated exceptions or unusual department patterns

Review frequency should reflect risk. Low-volume departments with consistent compliance may be subject to periodic sampling, while high-volume units, new cardholders, and departments with prior findings may warrant more frequent review. Sampling should be documented, reproducible, and broad enough to test both ordinary and unusual activity.

Monitor exceptions and investigate patterns

An exception report is valuable only when someone is responsible for reviewing it and taking action. Program administrators should track missing receipts, late reconciliations, personal charges, split purchases, unsupported business purposes, restricted commodities, and transactions posted to incorrect funds. The report should distinguish an isolated administrative error from a pattern that suggests weak supervision or intentional abuse.

Investigations should follow a consistent process. The reviewer should preserve transaction records, request an explanation, compare the purchase with policy and procurement rules, and document the final determination. Repayment may be required for an unallowable personal purchase, but repayment alone does not resolve the underlying control issue. The institution may also need to provide training, reduce a limit, suspend the card, or refer the matter to internal audit, compliance, human resources, or law enforcement.

Program leadership should provide periodic reporting to senior administration and, where appropriate, audit or finance committees. Useful metrics include the number of active cards, total spend, average transaction value, reconciliation timeliness, exception rates, repeat findings, dormant accounts, terminated-card closure times, and recovered amounts. Trends are more informative than isolated totals because they show whether controls are improving.

Implement practical governance improvements

A sustainable program should be easy for compliant employees to follow and difficult to exploit. The following actions provide a practical starting point for institutions reviewing their current framework:

These controls should be supported by a formal review calendar. At least annually, the institution should evaluate policy language, card limits, restricted categories, training content, system access, vendor performance, and monitoring results. A review after a major audit finding, fraud incident, system implementation, or regulatory change is also appropriate.

Procurement card oversight should be coordinated with broader purchasing and financial governance. If a university has separate rules for purchase orders, travel cards, petty cash, reimbursements, and contract payments, administrators should compare them for conflicting thresholds or duplicate controls. Consistent terminology and aligned approval paths make it easier for employees to follow requirements and for auditors to assess them.

Build a culture of responsible stewardship

Policies and software cannot compensate for unclear expectations or weak supervisory engagement. Department leaders should communicate that procurement cards are institutional tools, not employee benefits, and that accurate documentation protects both public resources and individual cardholders. Managers should review exception trends with their teams rather than treating every issue as a central finance problem.

Senior business officers can reinforce this culture by sharing lessons learned across campuses, recognizing departments with strong compliance, and using professional networks to compare approaches. Peer benchmarking can reveal practical ways to handle high-volume purchasing, emergency needs, grant-funded activity, and decentralized operations without weakening accountability.

A mature program also treats control reviews as an opportunity to improve service. If employees repeatedly submit incomplete receipts because the system is difficult to use, the institution should examine the workflow, mobile capture options, guidance, and approval timing. Strong oversight is measured by the quality of decisions and documentation, not by the number of obstacles placed in front of legitimate purchasing.

TASSCUBO members can use their collaboration, professional development, and shared best-practice channels to strengthen procurement card governance across Texas higher education. By comparing metrics, policies, training models, and audit responses, institutions can build programs that protect public funds while preserving the speed and flexibility that make purchasing cards valuable. The next step is to review current controls against the card lifecycle, prioritize the highest-risk gaps, and assign accountable leaders to implement measurable improvements.