Building a Safer University Procurement Card Framework
A procurement card can make everyday purchasing faster, reduce invoice handling, and give departments a practical way to obtain low-value goods and services. In a university, however, the same convenience can create exposure to fraud, conflicts of interest, inappropriate spending, duplicate payments, tax errors, and weak records. A well-designed policy must therefore connect card access with delegated authority, purchasing rules, financial reporting, and audit evidence.
Australian universities operate in a complex public environment. They may manage Commonwealth funding, state legislation, research grants, student services, commercial activities, and a wide supplier base across metropolitan and regional campuses. A centralised procurement card policy should support efficient work while making it clear who may spend, what may be purchased, how exceptions are approved, and how every transaction will be reviewed.
Set The Policy Around Risk And Accountability
The policy should begin with a documented risk assessment rather than a preferred card product or software feature. Identify the activities most likely to create loss or non-compliance, including urgent laboratory purchases, travel, hospitality, online subscriptions, construction-related supplies, fieldwork, and purchases made by staff working away from campus. The assessment should consider transaction value, supplier type, frequency, data sensitivity, grant restrictions, and the difficulty of independently verifying delivery.
A central control structure normally assigns responsibility to several parties. The cardholder makes an authorised purchase and keeps the supporting evidence. The cardholder’s supervisor confirms the business purpose and budget. A finance or procurement team monitors transactions, manages card limits, and investigates exceptions. Internal audit tests whether the controls operate in practice. No individual should be able to request a card, approve their own transactions, change their limit, and reconcile the account without independent oversight.
The policy should also define consequences. A late receipt may require correction and coaching, while personal expenditure, deliberate splitting of transactions, or repeated misuse may require card suspension, repayment, disciplinary action, or referral under the university’s fraud and corruption procedures. Clear consequences make the document operational rather than aspirational.
Define Eligibility, Spending Boundaries And Approval
Eligibility should be based on a demonstrated business need, not position alone. Suitable applicants may include staff who make frequent low-value purchases, support remote operations, manage approved events, or need controlled access to specialist suppliers. Seniority should not automatically justify a higher limit. Each card should have a named cardholder, a cost centre, a default account code, an approving officer, and an expiry or review date.
A useful policy separates permitted, restricted, and prohibited expenditure. Permitted categories might include low-value teaching materials, approved travel incidentals, minor maintenance supplies, and essential operational purchases. Restricted categories could include hospitality, gifts, software subscriptions, accommodation, research expenditure, and payments to related parties. Prohibited categories commonly include personal purchases, cash advances, salary or contractor payments, split transactions designed to avoid approval thresholds, and purchases from the cardholder or an associated business.
Limits should reflect actual need. Set a per-transaction ceiling, a monthly credit limit, merchant category restrictions, and geographic or online-use controls where available. A card used for a remote campus in regional Queensland may need a different operating profile from one used by a city-based faculty, but the rationale should be documented and reviewed. Emergency purchasing should have a defined pathway, including retrospective approval within a fixed number of business days.
Australian tax treatment needs particular attention. Receipts should record the supplier’s ABN where relevant, the GST amount, and enough detail to support the university’s tax position. A tax invoice is generally required to claim GST credits, subject to applicable thresholds and exceptions. Policy wording should direct staff to the university’s tax team when a supplier cannot provide acceptable documentation, rather than allowing informal workarounds.
Build Controls Into The Purchasing Process
The strongest controls operate before a transaction reaches the statement. Card management software can block high-risk merchant categories, require pre-approval for selected categories, enforce daily or monthly limits, and flag unusual spending. These settings should be designed with procurement and finance data, then tested against real purchasing scenarios. Overly broad restrictions encourage workarounds; overly permissive settings leave review teams with a large volume of preventable exceptions.
The following model shows how different control arrangements affect risk and administration:
| Control model | Main strength | Common weakness | Suitable use |
|---|---|---|---|
| Decentralised cards with informal review | Fast access for departments | Inconsistent approvals and weak visibility | Very limited, low-risk pilot activity |
| Central card programme with departmental approvers | Shared accountability and practical flexibility | Requires disciplined reconciliation | Most routine university purchasing |
| Central programme with automated rules | Strong preventive controls and useful data | Configuration can be complex | Higher-volume or higher-risk environments |
| Virtual cards for defined suppliers or projects | Narrow exposure and clear transaction purpose | Less flexible for unexpected needs | Travel, subscriptions, events, and projects |
| Central purchasing with no cards | Maximum procurement control | Slow processing and poor fit for urgent needs | High-value, strategic, or sensitive expenditure |
Every transaction should produce a complete audit trail. At minimum, retain the supplier receipt, business purpose, date, amount, GST treatment, cost centre, project or grant code, approver identity, and evidence of goods or services received. A receipt showing only “miscellaneous” is not enough. Digital records should be searchable and retained in line with the university’s records authority, privacy obligations, and research funding requirements.
Reconciliation should occur monthly, with a shorter cycle for high-risk cards. The cardholder confirms each transaction, the approver checks the purpose and coding, and finance reviews exceptions. Automated matching can identify duplicate amounts, weekend or out-of-hours purchases, repeated transactions just below a threshold, unusual merchant categories, and spending after a cardholder changes role. These alerts should support judgement rather than replace it.
Connect Procurement With Facilities And Supplier Governance
Procurement cards should not become a substitute for strategic sourcing, contract management, or purchase orders. A university may use cards for low-value and routine purchases, while larger or recurring requirements move through a tender, panel, standing offer, or formal contract. The policy should state when a cardholder must use an existing agreement and prohibit bypassing a preferred supplier simply because a card makes the transaction convenient.
Facilities expenditure deserves special treatment. A small purchase of parts may be appropriate, yet repeated card transactions can conceal a larger maintenance programme, weak contractor controls, or an unplanned capital commitment. Finance, procurement, and estates teams should review card data alongside work orders, asset registers, insurance requirements, and contractor records. Guidance on deferred maintenance planning is relevant because tight budgets can increase pressure to make fragmented, reactive purchases.
Supplier due diligence should cover sanctions, conflicts of interest, insurance, cybersecurity, privacy, modern slavery requirements where applicable, and bank account verification. Staff must never change a supplier’s bank details solely because an email requests it. A second channel should confirm the change, particularly where payment data or a card-linked account is involved.
Community and charitable payments also need a clear process. They should be authorised under the university’s donations, sponsorship, or community engagement rules, with the beneficiary’s identity and purpose recorded. Where a transaction involves a charitable organisation, publicly available information such as that provided by the Avalokitesvara Trust can form part of the background record, alongside the university’s own approval and verification checks.
Monitor Performance And Improve The Control Environment
A policy is effective only when management can see whether it is being followed. A monthly dashboard should report active cards, total spend, average transaction value, outstanding reconciliations, missing receipts, policy exceptions, blocked transactions, disputed payments, and cards with no recent activity. Results should be segmented by faculty, campus, cost centre, merchant category, and cardholder role so that unusual patterns are visible.
The first review should occur shortly after implementation, followed by a formal review at least annually. Conduct additional reviews after a fraud incident, major system change, audit finding, merger, new campus opening, or change to government funding conditions. Remove unused cards promptly, reduce limits when duties change, and cancel cards when employment ends. Exit checklists should include confirmation that outstanding transactions have been reconciled.
Training should be practical and role-specific. Cardholders need examples of acceptable receipts, GST evidence, split transactions, hospitality approvals, lost-card procedures, and suspicious supplier communications. Approvers need to understand that approval confirms business purpose and compliance, not simply that the amount appears reasonable. Finance and procurement teams need escalation rules for suspected fraud and recurring control failures.
Australian terminology and working conditions should be reflected in training materials. Staff may purchase from a local supplier in Perth, organise fieldwork in the Northern Territory, or support a campus event during an afternoon or “arvo” when normal procurement staff are unavailable. Those situations can be accommodated without weakening controls if the policy provides a documented emergency route, a nominated after-hours contact, and a deadline for retrospective review.
A mature programme measures outcomes as well as compliance. Useful indicators include reduced invoice processing time, fewer duplicate payments, faster reconciliation, lower exception rates, improved GST documentation, and timely card cancellation. Internal audit can test a sample from each risk tier, while management can use trend data to adjust limits, merchant blocks, training, and sourcing arrangements.
A centralised university procurement card policy should now be treated as a managed financial control, not a form that staff sign when a card is issued. TASSCUBO members can strengthen their institutions by bringing finance, procurement, technology, facilities, internal audit, legal, and academic representatives into the design process. A cross-functional working group can map current risks, agree approval thresholds, test system rules, and establish reporting ownership.
Begin with a limited pilot covering a few departments and transaction categories. Record exceptions, examine where staff need legitimate flexibility, and correct unclear wording before expanding the programme. With disciplined governance, appropriate Australian tax and public-sector context, and regular data-led review, procurement cards can deliver convenience without sacrificing accountability.