The Credit Control Process: A Practical Framework for B2B Finance Teams
Most credit control failures are not decisions made badly — they are decisions made once and never revisited. This is the six-stage process, what each stage should produce, and the two review cycles that stop limits going stale.
On this page
Key takeaways
- Credit control is six stages, not one decision: assess, set, document, monitor, escalate, review. Most teams do the first three well and the last three not at all.
- In the UAE, overdue invoices affect 58% of B2B sales, and around half of all B2B sales are made on credit — so credit exposure is the normal state of the ledger, not an exception to manage.
- The limit is not the control. The monitoring is the control — a limit nobody compares against the live balance is a number in a field.
- Two review cycles matter: a portfolio review on a schedule, and an event-triggered review when behaviour changes. The second one is what catches a failing customer early.
- The single most useful credit input costs nothing to collect: whether the customer keeps the payment promises they make.
Extending credit is a lending decision that most businesses make without noticing they have made it. A customer asks for 30 days, somebody agrees, and the company has just written an unsecured, uninsured, interest-free loan — usually with less diligence than it would apply to buying a laptop.
That is not an argument for refusing credit. In the UAE, around half of B2B sales are transacted on credit and in sectors like steel and metals it is closer to 60%. A supplier who insists on cash up front in a market that runs on credit is not being prudent; they are opting out of most of the addressable revenue.
The argument is for making the decision deliberately, writing it down, and then — the part almost everyone skips — checking whether it is still the right decision three months later. This article sets out that process in six stages, what each stage should actually produce, and where it typically breaks.
What credit control actually is
Credit control is the management of the credit a business extends to its customers, and of the receivables that credit creates. It is preventative work: its purpose is that a bad debt never happens. Collections is the corrective half — recovering what has already gone wrong.
The two are usually run by the same people and often bought as one system, which is why "credit and collections" is a single job title. But they answer different questions, and confusing them is how a team ends up with excellent chasing discipline on a book it should never have taken on.
| Credit control | Collections | |
|---|---|---|
| Question it answers | Should this customer owe us this much? | How do we get paid what we are already owed? |
| When it happens | Before and during the trading relationship | After an invoice passes its due date |
| Primary artefact | A credit limit and agreed terms | A follow-up history and a payment promise |
| Failure mode | Exposure nobody was watching | An overdue invoice nobody was chasing |
| Measured by | Bad debt, exposure concentration, limit breaches | DSO, collections against target, promise-kept rate |
The six stages
The process below is deliberately plain. Every stage has an output, because a stage that produces nothing you can point at later is a conversation, not a control.
1. Assess the customer
Before the first credit sale, establish who you are actually dealing with. In the UAE that means the trade licence and its expiry, the legal entity name as it appears on it, whether the person negotiating has authority to commit the company, and — for anything material — trade references from two existing suppliers.
Trade references are undervalued because they feel informal. They are the only source that tells you how a customer behaves as a payer rather than how they look as a balance sheet, and the question that matters is specific: not "are they good" but "do they pay you on the terms you agreed, and if not, how late".
- Output: a credit application on file with the licence, entity details, references and a signed acceptance of your terms.
2. Set the limit and the terms
A limit should be derived, not guessed. The usual anchor is the customer's expected monthly purchasing multiplied by the payment cycle you are granting — a customer buying AED 100,000 a month on 60-day terms needs roughly AED 200,000 of headroom to trade normally, and a limit below that guarantees a breach in month two that has nothing to do with their behaviour.
Then apply the ceiling that has nothing to do with the customer: how much of this single name can the business afford to lose. Concentration is the risk that actually kills suppliers — one customer at 30% of the ledger is a more dangerous position than ten at 3% with worse credit.
- Output: a limit, terms in days, and a documented reason for both.
3. Document the sale properly
This is the stage that quietly determines whether the other five matter, and it is where a large share of "late" UAE invoices actually sit. An invoice that does not carry the customer's purchase order number, does not match the delivery note they signed, or was sent to a person who left, is not an invoice being paid late. It is an invoice that has not entered the customer's payment cycle at all.
- Output: every invoice carrying the customer's own reference, matched to signed proof of delivery, addressed to the named payables contact.
4. Monitor the exposure
Here is the stage that separates a credit control process from a credit control policy. Setting a limit is an act of intent. Comparing that limit against the live outstanding balance, continuously, is the actual control — and it is the one most often missing, because the limit lives in one system and the balance lives in another.
What you need to be able to answer at any moment, without building anything: which customers are over their limit, by how much, and how old the balance is that put them there. If answering that takes a pivot table, it will be answered monthly at best, and a customer can go from compliant to seriously over-extended well inside a month.
- Output: a live over-limit list, and an escalation that fires without anyone remembering to look.
5. Escalate on a defined path
Escalation should be a rule agreed in advance, not a judgement made under pressure. The reason is not bureaucracy — it is that the person deciding whether to keep supplying a slow-paying customer is usually the person whose sales target depends on it.
| Trigger | Action | Owner |
|---|---|---|
| Invoice 7 days overdue | Statement of account sent, payment date requested | Collector |
| Invoice 30 days overdue | Call to payables, promise to pay recorded with amount and date | Collector |
| Promise broken once | Escalate to the customer's finance manager; account manager informed | Credit controller |
| Over credit limit, or 60 days overdue | Formal notice; further supply requires approval | Finance manager |
| 90 days overdue, or a second broken promise | Credit stop; recovery options reviewed | Finance manager / CFO |
Thresholds should reflect your own terms — a ladder built for 30-day terms misfires on a book trading at 60. What matters is that the trigger is a fact, not an opinion, and that the owner is a named role.
- Output: a written ladder where each rung has a factual trigger and a named owner.
6. Review, on two different clocks
Almost every credit control process in the wild has stages one to five in some form. Stage six is the one that is genuinely rare, and it is the reason limits go stale: a limit set in a customer's good year is still sitting there in their bad one.
Two cycles are needed, and they catch different things. A scheduled portfolio review — quarterly for the largest exposures, annually for the rest — catches drift. An event-triggered review catches deterioration, and it is the more valuable of the two because it is timely.
Events that should trigger a credit review immediately
- A payment promise is broken
- The customer's average days-to-pay increases materially over two consecutive periods
- A cheque is returned, or a payment is reversed
- The customer requests longer terms or a higher limit
- A trade licence lapses, or the entity is restructured
- Ordering volume jumps sharply without explanation
What this looks like in a UAE trading group
Two structural features change how the process has to be implemented here, as opposed to how it reads in a textbook.
The first is branch structure. A trading or contracting group typically runs Dubai, Abu Dhabi and Sharjah operations with separate customer books and separate sales management — and the same customer name frequently appears in more than one of them. Credit exposure is only meaningful consolidated: three branches each comfortably inside a AED 150,000 limit for the same group customer is AED 450,000 of exposure to one payer, and nobody looking at a single branch's report can see it.
Accountability, meanwhile, is only meaningful at branch level. So the process needs both views: consolidated exposure for the credit decision, branch-level performance for the collections decision. Getting one without the other is the most common reporting gap in groups of this shape.
The second is language. A credit and collections function here is routinely bilingual, and the person who negotiated a limit is very often not the person who has to enforce it at 4pm on a Thursday. A process that only works if everyone reads the same English-language spreadsheet is a process with a single point of failure.
Where to start if you have none of this
Do not attempt all six stages at once. In practice the sequence below produces the most improvement for the least disruption, because each step makes the next one cheaper.
- Write down the limits you already have. Most businesses are operating on limits that exist only in someone's judgement. Getting them into a field — any field — is the whole of stage two for an existing book.
- Compare them against the live balance once. The first over-limit list a team produces is usually uncomfortable and immediately actionable. This is stage four, and it is where the process starts paying.
- Start recording promises as data. Amount, date, who took the call. Within a quarter you have a payment-behaviour record no external source can sell you.
- Agree the escalation ladder in writing. Two rungs is enough to begin. The value is that it is decided when nobody is under pressure.
- Fix the documentation leaks the over-limit list exposed. By this point you will know which customers have stuck invoices rather than slow ones.
- Then, and only then, schedule the portfolio review. It is worth doing once the other five produce something to review.
None of that requires software to begin. It does become considerably harder to sustain without it, because stages four and six are the ones that depend on the limit and the live balance being in the same place — which is what credit control software is for, and why credit and collections are usually managed in one system rather than two.
For the corrective half of the job — assignment, follow-up history and escalation once an invoice is already overdue — see collections management software, and what accounts receivable management covers for how the two fit into the wider receivables cycle.