Treasury & FX

Treasury Policy Template for SMBs: Sections and Sign-Off

A treasury policy fixes who approves each payment, which banks the company can use, and how often the document gets reviewed. This guide delivers it as a seven-section template.

Equipo Soulbit11 min read
Share
Treasury

Most SMBs with revenue in US dollars run treasury on memory, not on paper: which bank gets a wire, how much cash sits idle, and who can approve a payment above a certain amount are decisions made by whoever is at their desk that day. The gap shows up the moment the company grows past one signer. A founder travels and a supplier payment stalls because nobody else is authorized to release it, or two people approve the same invoice because neither checked whether the other already had.

In Soulbit Academy we lay out the sections a treasury policy needs so that gap stops depending on one person's memory. This guide works as a template: each numbered section states what it decides, who drafts it, and who signs it. Two of those sections, internal controls over payment approval and counterparty risk, are summarized here because each deserves its own deeper treatment later; this is the frame they sit inside.

What a treasury policy is and which companies need one

A treasury policy is the formal document that fixes a company's rules for handling cash: which banks and counterparties it can use, who approves each payment based on its size, how much liquidity it must keep on hand, and how often the document itself gets reviewed. It is not an accounting manual or a financial plan. It is the governance layer that decides how money moves before a payment ever leaves the account.

A company with 10 to 100 employees needs one the moment more than one person can initiate or approve a payment. While a single founder signs every wire, risk sits with one person and the process, informal as it is, stays traceable. The moment a second signer appears, a finance lead or an assistant with online banking access, the absence of written rules stops being theoretical and becomes the most common cause of duplicate payments, internal fraud, or two people making contradictory calls.

The 7 sections a treasury policy template needs

A complete treasury policy has seven sections, each tied to a concrete decision. This list works as a template: copy the headings, adapt the content to your company's size, and fill in who signs each one in the next section.

The first is objective and scope: which accounts, currencies and group entities the document covers, and what falls outside it. The second is roles and approval levels: who can initiate a payment, who authorizes it, and at what amount a second signature becomes mandatory. The third is authorized banks and counterparties: the list of entities the company can operate with, including how it converts balances under OTC pricing, and the criteria for adding a new one. The fourth is exposure and liquidity limits: how much cash the company must hold at all times, a figure that rests on the cash flow forecast, and how much it can concentrate in a single entity or currency, a limit that connects to FX hedging whenever revenue and costs sit in different currencies. The fifth is internal controls and payment approval: segregating who records, who approves and who executes. The sixth is counterparty risk: the criteria for evaluating every bank or provider the company moves money through. The seventh is review and update: how often the document gets reviewed and who can trigger a review off the regular calendar.

Does a small SMB need all seven sections from day one?

Yes, even if each section stays short. A ten-person company can resolve roles and approval levels in a single paragraph, with the general manager and one additional signer, but skipping the section entirely leaves unanswered what happens the day that second person is unavailable.

Who approves each section: the sign-off map

Every section of the treasury policy has someone who drafts it and a different level who approves it; confusing the two roles is the most common mistake when building the document. Whoever drafts it knows the operational detail; whoever approves it takes on responsibility for the rule being followed, and for the consequences if it is not. The G20/OECD Principles of Corporate Governance assign the board responsibility for overseeing a company's internal control and risk management systems, which at an SMB translates into final sign-off on these sections.

Policy sectionWho drafts itWho approves or signs it
Objective and scopeFinance lead or CFOBoard or majority owner
Roles and approval levelsCFOBoard or majority owner
Authorized banks and counterpartiesTreasuryTreasury committee or CFO
Exposure and liquidity limitsTreasuryTreasury committee
Internal controls and payment approvalController or internal auditCFO
Counterparty riskTreasury or risk functionTreasury committee or board
Review and updateCFOBoard or majority owner
Table 1. Drafting and approval map by section of a treasury policy, adaptable to the size of the SMB. Where no treasury committee exists, its functions fall to the CFO or the majority owner.

What happens if the SMB has no treasury committee?

The committee's functions do not disappear, they get reassigned. At a company with 10 to 30 employees, the CFO or finance lead takes on drafting, and a second person, the general manager or an owner, takes on sign-off. What cannot happen is the same person drafting, approving and executing a payment with no cross-check.

Internal controls and payment approval: what this section must fix

Internal controls and payment approval is the section that turns roles into checkable steps: whoever records a payment order, whoever approves it, and whoever executes it should be three different people whenever team size allows it. The policy also fixes the amounts above which a second signature becomes mandatory, which document must back each payment before it is authorized, whether an invoice, a contract or a purchase order, and how each payment gets reconciled against the accounting record, a process detailed in reconciling stablecoin payments with accounting.

This section does not end here: it also defines how approval evidence gets recorded and what happens when a payment is approved outside the normal flow, for example under urgency. The full treatment of internal controls and payment approval, with typical thresholds by company size, deserves its own article; this guide fixes the place it occupies inside the broader policy.

Counterparty risk: what the policy must fix with banks and providers

Counterparty risk is the chance that a bank, a payment provider or any third party the company moves money through fails to meet its obligation, and the policy must fix how that risk gets assessed before operating with that entity. The section defines, at minimum, what information gets requested from a new counterparty before approval, what share of the company's cash can sit with a single entity, and how often already-authorized counterparties get reviewed.

A useful reference framework for this section is the international risk management standard ISO 31000, which treats concentration in a single counterparty as a risk to be identified, assessed and treated explicitly, not as an implicit assumption of doing business. On the accounting side, exposure to a financial counterparty falls under financial instruments standards: IFRS 9 requires assessing each counterparty's credit risk for impairment purposes, a criterion an internal policy can borrow even though its scope differs. In practice, rating a counterparty means checking its regulatory licence or registration, its operating track record and its incident history before approving it.

What Soulbit V1 delivers to support the policy and what stays the company's job

Soulbit V1 supports the execution of several treasury policy sections without replacing the document itself. Mass payroll disbursement in stablecoin leaves a record by beneficiary and by batch, useful as evidence for the internal controls section. The back office (S3) lets a company configure roles and approval profiles, which helps separate who initiates a payment from who authorizes it. Institutional custody of the USDC and USDT balance, built on MPC technology, backs the authorized banks and counterparties section, and the criteria for approving a new counterparty rests on the same KYB documents checklist any financial platform requests before opening an account.

What Soulbit V1 does not do matters just as much for the policy. There is no automatic connection to the company's ERP to reconcile payments: exporting the history is manual. Converting balance to local currency happens under case-by-case eOTC pricing, not automatically according to the policy's limits. And rating the counterparty risk of each bank or provider the company operates with remains a decision that belongs to the company, not to any platform it uses.

Treasury policy elementDoes Soulbit V1 cover it?How it gets resolved
Traceability of each payment and beneficiaryYesTransaction history by batch and by beneficiary
Approval roles in the back officeYesConfigurable roles and permissions in the back office (S3)
Custody of the stablecoin balanceYesInstitutional custody built on MPC technology
Automatic ERP connection to reconcileNoManual export, no API or SDK in V1
Automatic conversion of balance under policy limitsNoCase-by-case eOTC pricing, not automatic
Rating the counterparty risk of banks and providersNoThe company's own responsibility, outside V1's scope
Table 2. What a treasury policy can lean on Soulbit V1 for today, and what remains the company's own responsibility.

How often to review it and who can call an out-of-cycle update

A treasury policy gets reviewed at least once a year, on the same date the board or majority owner approves next year's budget. That annual cycle is not the only trigger. A change of primary bank, a new investor coming in, a fraud or duplicate-payment incident, or team growth that adds a new approval level should each force a review outside the regular calendar.

Who can request an out-of-cycle review of the policy?

Usually the CFO or any member of the treasury committee, and the request should be logged with a date and a reason. A policy that only gets reviewed when someone remembers to do it ends up describing a process the company stopped following long ago, at which point it loses its value as a control document.

Frequently asked questions

What is a treasury policy template?

It is a formal document that fixes a company's rules for handling cash: which banks and counterparties it can use, who approves each payment above a given amount, and how often the document is reviewed. A template gives you the section headings and the sign-off structure so the company only has to fill in its own numbers and names.

What should a treasury policy include at minimum?

At minimum it should include seven sections: objective and scope, roles and approval levels, authorized banks and counterparties, exposure and liquidity limits, internal controls and payment approval, counterparty risk, and review and update. A small company can resolve each section in a few lines, but skipping one leaves a governance gap.

Who should sign a treasury policy at an SMB?

Final approval sits with the board or the majority owner, while each section can have a different drafter, usually the CFO or the finance lead. At a company with no formal board, sign-off falls to the majority owner together with the general manager, as long as that person is not the same one who drafted the document.

How often should a treasury policy be reviewed?

At least once a year, aligned with the approval cycle for next year's budget. A change of primary bank, a fraud or duplicate-payment incident, or a new investor coming in should each trigger an out-of-cycle review rather than waiting for the annual date.

Can an SMB without a treasury committee still have a formal policy?

Yes. When no committee exists, the CFO or finance lead takes on the drafting role, and the general manager or majority owner takes on approval. What the policy cannot allow is the same person drafting, approving and executing the same payment with no cross-check at all.

Want your company to add stablecoins to its operations?

Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.

Join the waitlist

Related articles

Treasury

Cash flow forecast: USD revenue, local currency costs

Forecasting an entire cash flow at today's exchange rate is the most common mistake a company makes when revenue arrives in dollars and costs are fixed in local currency.

11 min read
Cash flow forecast: USD revenue, local currency costs
Treasury

Colombia's TRM: Which Rate DIAN Requires for USD

A US parent or client dealing with a Colombian counterpart needs to know which TRM applies, and on what date, before an accountant can book a dollar receipt correctly.

10 min read
Colombia's TRM: Which Rate DIAN Requires for USD