Corpay

Maverick Spend: The Off-Contract Buying That Policy Alone Will Not Stop

Category:Commercial Cards, Procure-to-Pay
Updated:2026-09-15
Author:David Luther

Maverick spend is company money spent outside the approved purchasing process, with a supplier nobody onboarded, at a price nobody negotiated, and usually without a requisition. Finance typically discovers it when the invoice arrives, which is several weeks after the decision that mattered.

It happens for an unglamorous reason. Someone needed something, the compliant path would have taken four days, and the job needed doing that afternoon. Understanding it as a process problem rather than a discipline problem is what separates the companies that shrink it from the companies that keep sending the same reminder email.

Key Takeaways

  • Maverick spend is off-contract, off-process buying. It's a controls gap, not usually a dishonesty problem.

  • Tail spend and maverick spend overlap but aren't the same. Tail spend is defined by size; maverick spend is defined by path.

  • You can size it without a procurement suite by comparing your payable population against your contracted supplier list.

  • Policy doesn't stop a purchase, and neither does a reminder. A spend limit, a merchant category restriction, or a single-use card number does.

  • Some urgent buying will always happen, so the practical goal is a reviewable record at the moment of purchase rather than zero exceptions.

What is maverick spend, and how is it different from tail spend?

Maverick spend is purchasing that bypasses the approved process. Tail spend is the long, low-value end of your supplier distribution, the many suppliers who individually account for very little. The two overlap heavily, because small urgent purchases are exactly the ones most likely to skip a requisition, but they're measured differently and fixed differently.

Tail spend is a consolidation problem. You address it by reducing supplier count and negotiating better terms with the survivors. Maverick spend is a control problem, and you address it by changing where the control sits in the buying sequence. A company can have well-consolidated tail spend and rampant maverick buying, and the reverse happens too.

Where does the term come from?

From procurement's own vocabulary, describing a buyer who goes off on their own rather than following the herd through the sourcing process. It's been in use in procurement circles for decades and carries a mild pejorative that isn't always deserved.

The framing matters because it shapes the response. Call it maverick spend and the instinct is to find the maverick. Call it off-process buying and the instinct is to ask why the process wasn't usable, which is the more productive question nine times out of ten.

Why is it not the same as fraud?

Because intent is different and so is the remedy. The overwhelming majority of off-contract purchases are people trying to get work done with company money for company purposes, using the fastest path available.

Weak controls still create room for both, and the overlap is real enough to take seriously. Lack of internal controls contributed to 32% of occupational fraud cases and override of existing controls to a further 19%, together more than half, according to the Association of Certified Fraud Examiners's 2024 Occupational Fraud: A Report to the Nations. Billing schemes accounted for roughly a fifth of cases, with a $100,000 median loss. A purchasing environment where anyone can commit company money without a record is the same environment where a billing scheme goes unnoticed, and the audit trail your AP function keeps is the thing that distinguishes the two after the fact.

What actually causes off-contract buying?

Four causes, and only the last one is about individual behavior.

  • The compliant path is slower than the business need

  • The contracted supplier doesn't stock what's needed, or can't deliver in time

  • Nobody knows a contract exists, because the contracted-supplier list lives in a system buyers don't use

  • Genuine indifference to the policy, which is real but much rarer than finance assumes

Diagnose before you intervene. A company whose buyers can't find the contract list has a publishing problem and will get nothing from a stricter approval workflow. A company whose requisition cycle runs four days on a purchase that needs to happen in four hours has a design problem, and tightening the workflow will make it worse.

Which purchases bypass the requisition first?

Software renewals, professional services, urgent maintenance and repair, and anything bought with a corporate card in a browser. Software renewals are the quiet one, because an auto-renewing subscription bought on a card two years ago never generates a new decision point and never reappears in procurement's view.

Marketing and IT tend to be the two functions most exposed, for opposite reasons. Marketing buys many small services quickly from suppliers that change often. IT buys fewer, larger things that renew automatically. Both produce spend nobody re-approved, and the compliant requisition path covers neither pattern well unless it's been designed with them in mind.

When is the bypass the rational choice?

When the cost of delay exceeds the value of the control, which happens more often than a policy document admits. A production line down at 6pm on a Friday and a part available from an unapproved supplier is not a governance dilemma; it's a decision anyone competent makes the same way.

The honest position is that a control framework that can't accommodate that purchase will be routed around, and the routing-around will then be used for less defensible purchases because the path already exists. Building a fast, recorded exception path is more effective than pretending exceptions won't happen. What the framework should insist on is not that the bypass never occurs, but that it leaves evidence.

How do you measure maverick spend without a procurement suite?

By joining two lists you already have. Take your paid-invoice population for a period and your contracted-supplier list, then classify every payment as on-contract, off-contract with an approved supplier, or off-contract with an unknown supplier. The third bucket is the clearest signal and the easiest to act on.

Add a second cut for purchases with no requisition or purchase order, regardless of supplier. Those two cuts together give you a defensible number in an afternoon, and they don't require buying anything. The mechanics of three-way matching tell you which payments had a purchase order behind them, which is most of the work.

What denominator makes the number honest?

Addressable spend, not total spend. None of the following is going through a requisition, and including it in the denominator understates the problem by a large factor:

  • Payroll and benefits

  • Taxes and statutory payments

  • Rent and debt service

  • Intercompany transfers

State the denominator every time you report the number. A maverick spend rate quoted without its denominator is not a metric, and the first argument in every procurement steering committee is about what counts. Settle it once, write it down, and keep it stable across periods so the trend means something.

Best practices for a virtual card program

Learn the internal strategies that make a virtual card program succeed — from program design to driving the vendor acceptance that determines how much of your AP spend earns rebates.

Download the guide
gated.jpg

Which systems hold the evidence?

Three, and they rarely agree. The ERP or accounting system holds the payments, the card program holds the transactions, and the contract or procurement system holds the agreements. Reconciling the three is the actual work of measuring this.

Card transactions are the richest source and the most often overlooked, because they carry merchant detail at the moment of purchase rather than a vendor name keyed later by an AP clerk. If your card data sits in a portal nobody exports from, that's the first thing to fix, and the broader question of what spend management covers is worth settling alongside it.

What does an after-the-fact control record contain?

Five elements. Who authorized the purchase, what evidence supports that it was legitimate, which exception category it falls under, what the price was against any available benchmark, and when payment was released.

That record is the artifact that turns an uncontrolled purchase into a controlled one retroactively. It won't recover a negotiated discount you didn't get, but it gives an auditor a defensible answer and it gives you data about which exceptions keep recurring, which is where the process fix eventually comes from.

Who attests that the purchase was legitimate?

The budget owner, not the buyer, and not AP. The person whose budget absorbs the cost is the only one with both the standing and the incentive to confirm that the purchase served a business purpose.

Documentation matters more than approvers. The U.S. Government Accountability Office's 2017 report Government Purchase Cards found that the federal government spent $8.7 billion in micropurchases on purchase cards in fiscal 2014, and that 22% of transactions government-wide did not have complete documentation. That's an organization with extensive purchase-card policy, extensive training, and a documentation gap on roughly a fifth of transactions anyway, which tells you what policy alone accomplishes at scale.

What evidence releases the payment?

A receipt or invoice, a business purpose, and a budget-owner attestation, at minimum. For anything above a threshold you set, add a short justification of why the compliant path wasn't used, because that field is where your process-improvement backlog comes from.

Hold the payment until the evidence exists rather than paying and chasing. Payment release is the only leverage AP has, and once the money is gone the documentation rarely arrives. Sound vendor management practice says the same thing about a supplier nobody onboarded, since a payment to an unvalidated bank account is exactly the exposure the 2026 fraud numbers describe. According to the Association for Financial Professionals's 2026 Payments Fraud and Control Survey Report, 76% of US organizations experienced attempted or actual payments fraud in 2025, while just 17% use AI to fight it.

Which controls close the gap without blocking urgent work?

Controls that sit at issuance rather than at approval. An approval control asks a human to say yes before money moves, which adds time. An issuance control decides in advance what a given card or account can be used for, which adds none.

That distinction is the whole argument. A spend policy enforced at approval is a queue. The same policy enforced at authorization is a decline, and it happens in under a second at the point of sale with no one waiting on anyone. Cards are also where the spend already is, since cards accounted for 79% of noncash payments by number in 2024, up from 77% in 2021, according to the Federal Reserve's 2025 Federal Reserve Payments Study.

What do card-level limits and merchant category controls enforce?

Four things, all at the moment of purchase.

  • A per-transaction ceiling, which caps the size of any single uncontrolled decision

  • A monthly or cycle limit, which caps aggregate exposure per cardholder

  • Merchant category restrictions, which prevent whole classes of purchase rather than individual ones

  • Time-bounded activation, which limits a card to a project window or a trip

Set them per role rather than per company. A facilities manager needs merchant categories a marketing coordinator doesn't, and a single company-wide limit set high enough for the former is useless against the latter. Working through card controls and corporate card spend policies role by role is a half-day exercise that outperforms a year of policy reminders, and a properly designed corporate purchase card program is how most mid-market companies implement it.

Where does a single-use virtual card fit?

At the exception, precisely. A single-use virtual card number is issued for one purchase, with an exact amount, an expiry, and a merchant lock, which means the record exists before the money moves rather than being reconstructed afterward.

That's what makes it the right instrument for urgent off-contract buying. The purchase happens as fast as the business needs, and the control exists anyway, because the card itself cannot be used for anything other than what it was issued for. Reuse exposure disappears with it, since the number is worthless after the transaction. For recurring exceptions that keep appearing in your control records, a virtual card per supplier is the step between "uncontrolled" and "under contract" that most companies skip.

Electronic rails are absorbing this work generally. B2B ACH volume grew 9.4% year over year to 2.1 billion transactions in the first quarter of 2026, per Nacha's Q1 2026 ACH Network volume statistics, and the same shift toward structured, recorded payment applies to the purchases that used to leave no trail at all.

Where Corpay fits in controlling off-contract spend

When off-contract buying happens on cards, which is where most of it happens, the control belongs on the card. Corpay purchasing cards and single-use virtual cards put per-transaction and cycle limits on the instrument itself, along with merchant category restrictions and time-bounded activation, so the record exists at the moment of purchase.

Worth saying plainly, this doesn't negotiate contracts or consolidate your supplier base. Those are procurement projects and a card program won't do them for you. What it does is stop the compliance problem from being invisible, which is the precondition for fixing anything else. Procurement leaders who have that visibility perform measurably better, meeting or exceeding plan on cost savings 96% of the time against 80% for followers, and on cost avoidance 94% against 75%, according to Deloitte's 2025 Global Chief Procurement Officer Survey.

What does fully managed AP change about this?

It closes the other end, which is the supplier nobody onboarded. Corpay's AP service is fully managed, so our team handles supplier enrollment with validated banking details, then delivers payment and follows up on exceptions rather than leaving that to whoever is free. Customers report about 40% less time spent on AP, single-use virtual cards remove the reuse exposure on one-off purchases, and Corpay returns more than $800 million in rebates to customers each year on card-eligible spend. Most programs are live in weeks.

Which ERPs does it connect to?

Corpay maintains 100+ ERP integrations, including NetSuite, Sage Intacct, Microsoft Dynamics 365 Business Central, and Acumatica, so card and payment data lands in the system where your spend analysis actually happens. That matters here more than it sounds, because a maverick spend measurement is a reconciliation exercise, and reconciliation across systems is where the number gets soft. The wider procure-to-pay chain is the context if you're deciding how much of this to solve at the payment layer versus upstream.

Frequently Asked Questions

What is maverick spend?

Maverick spend is company money spent outside the approved purchasing process, typically without a requisition, often with a supplier who was never onboarded, and at a price nobody negotiated. It's also called off-contract or off-process spend, and it's usually discovered when the invoice arrives.

What causes maverick spend?

Mostly process friction. The compliant path is slower than the business need, the contracted supplier can't deliver in time, or nobody knows a contract exists because the supplier list lives somewhere buyers don't look. Genuine indifference to policy is real but much less common than finance assumes.

How do you measure maverick spend?

Join your paid-invoice population to your contracted-supplier list and classify each payment as on-contract, off-contract with an approved supplier, or off-contract with an unknown supplier. Use addressable spend as the denominator, excluding payroll, taxes, rent, and debt service, and state the denominator every time.

How do you reduce maverick spend?

Move the control from approval to issuance. Per-transaction and cycle limits, merchant category restrictions, and single-use virtual cards enforce policy at the point of sale without adding a queue. Then use your exception records to find and fix the process gaps that caused the bypasses.

Is maverick spend the same as tail spend?

No. Tail spend is defined by size, meaning the long low-value end of your supplier distribution. Maverick spend is defined by path, meaning any purchase that skipped the approved process regardless of value. They overlap substantially, but consolidating tail spend and closing a controls gap are different projects.

What is an acceptable maverick spend rate?

There's no published benchmark worth quoting, and any figure you see attributed to one deserves scrutiny about its denominator. Track your own trend against a stable definition instead, and treat a rising rate as a signal that your requisition process has become harder to use.

Does a purchase card program increase or reduce maverick spend?

It can do either, depending on the controls. An uncontrolled card program converts off-process buying into faster off-process buying. A controlled one converts it into recorded buying with enforced limits, which is why the working-capital case for tighter payables discipline usually starts with the card controls rather than the policy.

Headshot.JPG

David Luther

Product Marketing Program Manager
David Luther, MBA is a product marketing program manager with years of experience in commercial banking, finance, and technology sectors, with research and writing appearing in financial publications.
Commercial Cards
Procure-to-Pay

Smarter payments. Stronger growth. Keep business moving.

Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.