Credit Control

The Credit Control Process: A Practical Framework for B2B Finance Teams

Most credit control failures are not decisions made badly — they are decisions made once and never revisited. This is the six-stage process, what each stage should produce, and the two review cycles that stop limits going stale.

Mudasar Nazir11 min read
On this page

Key takeaways

  • Credit control is six stages, not one decision: assess, set, document, monitor, escalate, review. Most teams do the first three well and the last three not at all.
  • In the UAE, overdue invoices affect 58% of B2B sales, and around half of all B2B sales are made on credit — so credit exposure is the normal state of the ledger, not an exception to manage.
  • The limit is not the control. The monitoring is the control — a limit nobody compares against the live balance is a number in a field.
  • Two review cycles matter: a portfolio review on a schedule, and an event-triggered review when behaviour changes. The second one is what catches a failing customer early.
  • The single most useful credit input costs nothing to collect: whether the customer keeps the payment promises they make.

Extending credit is a lending decision that most businesses make without noticing they have made it. A customer asks for 30 days, somebody agrees, and the company has just written an unsecured, uninsured, interest-free loan — usually with less diligence than it would apply to buying a laptop.

That is not an argument for refusing credit. In the UAE, around half of B2B sales are transacted on credit and in sectors like steel and metals it is closer to 60%. A supplier who insists on cash up front in a market that runs on credit is not being prudent; they are opting out of most of the addressable revenue.

The argument is for making the decision deliberately, writing it down, and then — the part almost everyone skips — checking whether it is still the right decision three months later. This article sets out that process in six stages, what each stage should actually produce, and where it typically breaks.

What credit control actually is

Credit control is the management of the credit a business extends to its customers, and of the receivables that credit creates. It is preventative work: its purpose is that a bad debt never happens. Collections is the corrective half — recovering what has already gone wrong.

The two are usually run by the same people and often bought as one system, which is why "credit and collections" is a single job title. But they answer different questions, and confusing them is how a team ends up with excellent chasing discipline on a book it should never have taken on.

Credit control and collections compared
Credit controlCollections
Question it answersShould this customer owe us this much?How do we get paid what we are already owed?
When it happensBefore and during the trading relationshipAfter an invoice passes its due date
Primary artefactA credit limit and agreed termsA follow-up history and a payment promise
Failure modeExposure nobody was watchingAn overdue invoice nobody was chasing
Measured byBad debt, exposure concentration, limit breachesDSO, collections against target, promise-kept rate

The six stages

The process below is deliberately plain. Every stage has an output, because a stage that produces nothing you can point at later is a conversation, not a control.

1. Assess the customer

Before the first credit sale, establish who you are actually dealing with. In the UAE that means the trade licence and its expiry, the legal entity name as it appears on it, whether the person negotiating has authority to commit the company, and — for anything material — trade references from two existing suppliers.

Trade references are undervalued because they feel informal. They are the only source that tells you how a customer behaves as a payer rather than how they look as a balance sheet, and the question that matters is specific: not "are they good" but "do they pay you on the terms you agreed, and if not, how late".

  • Output: a credit application on file with the licence, entity details, references and a signed acceptance of your terms.

2. Set the limit and the terms

A limit should be derived, not guessed. The usual anchor is the customer's expected monthly purchasing multiplied by the payment cycle you are granting — a customer buying AED 100,000 a month on 60-day terms needs roughly AED 200,000 of headroom to trade normally, and a limit below that guarantees a breach in month two that has nothing to do with their behaviour.

Then apply the ceiling that has nothing to do with the customer: how much of this single name can the business afford to lose. Concentration is the risk that actually kills suppliers — one customer at 30% of the ledger is a more dangerous position than ten at 3% with worse credit.

  • Output: a limit, terms in days, and a documented reason for both.

3. Document the sale properly

This is the stage that quietly determines whether the other five matter, and it is where a large share of "late" UAE invoices actually sit. An invoice that does not carry the customer's purchase order number, does not match the delivery note they signed, or was sent to a person who left, is not an invoice being paid late. It is an invoice that has not entered the customer's payment cycle at all.

  • Output: every invoice carrying the customer's own reference, matched to signed proof of delivery, addressed to the named payables contact.

4. Monitor the exposure

Here is the stage that separates a credit control process from a credit control policy. Setting a limit is an act of intent. Comparing that limit against the live outstanding balance, continuously, is the actual control — and it is the one most often missing, because the limit lives in one system and the balance lives in another.

What you need to be able to answer at any moment, without building anything: which customers are over their limit, by how much, and how old the balance is that put them there. If answering that takes a pivot table, it will be answered monthly at best, and a customer can go from compliant to seriously over-extended well inside a month.

  • Output: a live over-limit list, and an escalation that fires without anyone remembering to look.

5. Escalate on a defined path

Escalation should be a rule agreed in advance, not a judgement made under pressure. The reason is not bureaucracy — it is that the person deciding whether to keep supplying a slow-paying customer is usually the person whose sales target depends on it.

An escalation ladder — illustrative, not prescriptive
TriggerActionOwner
Invoice 7 days overdueStatement of account sent, payment date requestedCollector
Invoice 30 days overdueCall to payables, promise to pay recorded with amount and dateCollector
Promise broken onceEscalate to the customer's finance manager; account manager informedCredit controller
Over credit limit, or 60 days overdueFormal notice; further supply requires approvalFinance manager
90 days overdue, or a second broken promiseCredit stop; recovery options reviewedFinance manager / CFO

Thresholds should reflect your own terms — a ladder built for 30-day terms misfires on a book trading at 60. What matters is that the trigger is a fact, not an opinion, and that the owner is a named role.

  • Output: a written ladder where each rung has a factual trigger and a named owner.

6. Review, on two different clocks

Almost every credit control process in the wild has stages one to five in some form. Stage six is the one that is genuinely rare, and it is the reason limits go stale: a limit set in a customer's good year is still sitting there in their bad one.

Two cycles are needed, and they catch different things. A scheduled portfolio review — quarterly for the largest exposures, annually for the rest — catches drift. An event-triggered review catches deterioration, and it is the more valuable of the two because it is timely.

Events that should trigger a credit review immediately

  • A payment promise is broken
  • The customer's average days-to-pay increases materially over two consecutive periods
  • A cheque is returned, or a payment is reversed
  • The customer requests longer terms or a higher limit
  • A trade licence lapses, or the entity is restructured
  • Ordering volume jumps sharply without explanation

What this looks like in a UAE trading group

Two structural features change how the process has to be implemented here, as opposed to how it reads in a textbook.

The first is branch structure. A trading or contracting group typically runs Dubai, Abu Dhabi and Sharjah operations with separate customer books and separate sales management — and the same customer name frequently appears in more than one of them. Credit exposure is only meaningful consolidated: three branches each comfortably inside a AED 150,000 limit for the same group customer is AED 450,000 of exposure to one payer, and nobody looking at a single branch's report can see it.

Accountability, meanwhile, is only meaningful at branch level. So the process needs both views: consolidated exposure for the credit decision, branch-level performance for the collections decision. Getting one without the other is the most common reporting gap in groups of this shape.

The second is language. A credit and collections function here is routinely bilingual, and the person who negotiated a limit is very often not the person who has to enforce it at 4pm on a Thursday. A process that only works if everyone reads the same English-language spreadsheet is a process with a single point of failure.

Where to start if you have none of this

Do not attempt all six stages at once. In practice the sequence below produces the most improvement for the least disruption, because each step makes the next one cheaper.

  1. Write down the limits you already have. Most businesses are operating on limits that exist only in someone's judgement. Getting them into a field — any field — is the whole of stage two for an existing book.
  2. Compare them against the live balance once. The first over-limit list a team produces is usually uncomfortable and immediately actionable. This is stage four, and it is where the process starts paying.
  3. Start recording promises as data. Amount, date, who took the call. Within a quarter you have a payment-behaviour record no external source can sell you.
  4. Agree the escalation ladder in writing. Two rungs is enough to begin. The value is that it is decided when nobody is under pressure.
  5. Fix the documentation leaks the over-limit list exposed. By this point you will know which customers have stuck invoices rather than slow ones.
  6. Then, and only then, schedule the portfolio review. It is worth doing once the other five produce something to review.

None of that requires software to begin. It does become considerably harder to sustain without it, because stages four and six are the ones that depend on the limit and the live balance being in the same place — which is what credit control software is for, and why credit and collections are usually managed in one system rather than two.

For the corrective half of the job — assignment, follow-up history and escalation once an invoice is already overdue — see collections management software, and what accounts receivable management covers for how the two fit into the wider receivables cycle.

Sources

Frequently asked questions

What is the credit control process?
It is the sequence a business follows to decide how much credit a customer gets and to keep that exposure under control: assess the customer, set a limit and terms, document the sale so the invoice is payable, monitor the outstanding balance against the limit, escalate on defined triggers when it goes overdue, and review the limit on both a schedule and on events. The first three stages are usually in place in some form; monitoring and review are the ones most often missing.
What is the difference between credit control and credit management?
In practice the terms are used interchangeably, and both cover the same work. Where a distinction is drawn, credit management refers to the policy level — the framework, the risk appetite, the limits methodology — and credit control to the operational execution of it: applying the limits, monitoring the balances, chasing the breaches. A small finance team does both from the same desk.
How do you calculate a credit limit for a new customer?
Start from the trading requirement: expected monthly purchasing multiplied by the payment cycle in months. A customer buying AED 100,000 a month on 60-day terms needs roughly AED 200,000 of headroom simply to trade without breaching. Then apply two constraints — what their references and financial position support, and what your own business can afford to lose to a single name. The limit is the lowest of the three, and the reason it was set should be recorded alongside it.
How often should credit limits be reviewed?
On a schedule and on events. Scheduled: quarterly for the largest exposures and the concentration risks, annually for the rest of the book. Event-triggered: immediately when a payment promise is broken, when average days-to-pay deteriorates over two consecutive periods, when a cheque is returned, when the customer asks for more credit or longer terms, or when a trade licence lapses. The event-triggered review is the one that catches a deteriorating customer in time to reduce exposure rather than after the fact.
Who should own credit control in a small finance team?
One named person should own the process, and the escalation ladder should take the individual decisions out of their hands above a threshold. The reason is structural rather than a question of trust: the person under most pressure to keep supplying a slow-paying customer is usually the person whose sales target depends on it, so the point at which supply stops needs to be a rule agreed in advance rather than a judgement made in the moment.

Continue reading

Accounts Receivable Fundamentals

What Is Accounts Receivable Management? A Complete Guide for Finance Teams

Invoicing a customer is not the same as being paid by one. This guide covers what accounts receivable management actually involves — the full cycle, the ownership problem, the metrics worth reporting, and the mistakes that quietly add weeks to your DSO.

19 min read

Collection Management

Payment Promise Tracking: How to Turn 'We'll Pay Thursday' Into Data

A promise to pay is the only forward-looking information in the whole receivables process, and in most finance teams it is written on a notepad and gone by Thursday. Here is how to capture it, resolve it, and use what it tells you.

10 min read

Stop guessing which invoices need chasing today

CollectFlows shows every overdue invoice, every promise to pay and every follow-up in one place — so nothing sits unchased because it was nobody's job.

14 days free · No credit card required · Cancel anytime