Unified Travel & Expense

CFO vs Controller vs VP Who Owns T&E Policy

Ardra M B
August 24, 2026
Reading Time 14 mins
who owns T&E policy
Business Travel at its smartest
ITILITE offers modern UX, real human support, pricing built to save money.
Get Started

TLDR;

  • No single role owns T&E policy end to end; the CFO, the controller, and the VP of finance each own a different piece.
  • The CFO owns the strategy, the budget, and the risk appetite the policy has to serve.
  • The controller owns enforcement, compliance, and the month-end close where the policy is tested.
  • The VP of finance usually owns the policy document itself and keeps it aligned across the org.
  • Use a RACI split so exactly one role is accountable, even when several are responsible.
Summarize the article  with

A traveler books business class on a route the policy caps at economy. The expense surfaces at month-end, and three people point at each other. The controller says the policy belongs to the VP of finance. The VP says the CFO set the budget it has to fit. The CFO says enforcement is the controller's job. T&E policy ownership is the most quietly contested question in a finance org, because the honest answer is that three roles each own a different piece of it. This is who owns what, and how to make the split work.

Who owns T&E policy? The short answer

T&E policy has three finance owners, not one: the CFO sets the mandate it serves, the controller enforces it, and the VP of finance owns the document that ties the two together. The confusion is real because the work is genuinely shared. GBTA research on travel departments found that finance and accounting are the top collaborators on travel-expense policy, involved in about 79% of organizations, while the travel department is the sole primary owner in only around 43%. Those collaborators are senior finance roles, and there are a lot of them: the US employs about 868,600 financial managers, a group projected to grow 15% through 2034.

Getting the split right matters because the money is real and the leakage is quiet. Business travel is a $1.71 trillion category worldwide in 2026, and expense-reimbursement fraud shows up in about 13% of occupational-fraud cases at a median loss of $50,000 each. A policy nobody clearly owns is where that leakage hides. The rest of this piece assigns each role its piece, then puts them into one RACI model.

What the CFO owns: strategy, budget, and risk appetite

The CFO owns the "why" behind the policy, not its line items. In Deloitte's widely used model, the CFO plays Strategist and Steward, taking a seat at the strategy table while protecting the company's assets and communicating risk to the board. Applied to travel, that means the CFO sets the spend target, decides how much out-of-policy behavior the company will tolerate, and signs the large financial commitments the program runs on.

What the CFO does not do is write the per-diem or approve individual trips. They set the mandate and hold the biggest sign-offs, and delegate the rest. That division shows up clearly in the field. 

At a healthcare staffing firm, an operations manager approved travel upgrades and policy exceptions day to day but still routed corporate-card sign-off to the CFO, a clean split between running the policy and owning the money behind it. The way finance sets that mandate is changing as automation takes over the mechanics, a shift covered in the role of finance in travel and expense.

What the controller owns: enforcement, compliance, and the close

The controller owns the policy where it meets reality. As the company's chief accountant, the controller runs the financial close, internal controls, and compliance monitoring, and is responsible for keeping the books accurate and in line with company policy. Every out-of-policy expense eventually lands on the controller's desk at month-end, which makes them the enforcement owner whether or not the title says so.

That enforcement role is why the controller cares most about a policy that is written to be checked. Clear rules, a clean travel and expense audit process, and consistent travel and expense policy compliance are the controller's defense against the leakage the ACFE data quantifies. When enforcement is weak, the policy is words; when the controller owns it, the policy has teeth.

What the VP of finance owns: the policy document itself

The VP of finance usually owns the policy as a living document. Robert Half describes the role as the bridge between the controller's backward-looking precision and the CFO's forward-looking vision, owning day-to-day financial leadership, systems, and mid-range planning. In practice that makes the VP the person who drafts the policy, keeps it current, and aligns it across travel, HR, legal, and the department budgets.

The boundary here is genuinely fuzzy, and it moves with the org chart. In a company with no VP of finance, the controller absorbs the policy-ownership and planning duties; in a company with no separate controller, the VP of finance absorbs the close and compliance work. The role in the room is what matters, not the title. 

When a large energy and fuel-distribution company evaluated a new travel platform, the VP of finance was a lead voice in the room, which is where day-to-day T&E policy ownership tends to sit. Whoever holds it should start from a solid template, like the one in the comprehensive guide to corporate T&E policy.

A RACI model for T&E policy ownership

The clean way to settle ownership is a RACI matrix, which forces exactly one role to be Accountable for a task even when several are Responsible for the work. That single-owner rule is the whole point: many people touch T&E policy, but only one should be answerable for it. The table below maps the roles to a typical mid-size finance org.

RoleRACI on T&E policyWhat they do
VP of financeAccountableOwns and maintains the policy document; the single answerable owner
ControllerResponsibleEnforces the policy, runs compliance and the close
Travel managerResponsibleExecutes booking and day-to-day policy application
CFOConsultedSets strategy, budget, and risk appetite; signs major commitments
HR, legal, securityConsultedAdvise on duty of care, employment, and data rules
Department heads, travelersInformedFollow the policy and receive updates

In a company with no VP of finance, move the Accountable role to the controller or the CFO, but keep it to one. The failure mode is not having two owners; it is having none.

How a platform supports shared T&E policy ownership

Software does not decide who owns the policy, but it is what makes a shared model workable instead of a standing argument. The point is to encode the policy once and give each owner the view they need, so the CFO sees spend against the target, the controller sees enforcement and exceptions, and the VP of finance sees a policy that is actually being followed.

ITILITE supports that split directly. The VP of finance gets the policy encoded as configurable rules and approval workflows; the controller gets automatic out-of-policy flagging, an audit trail, and reporting that holds up at close; and the CFO gets spend visibility against budget, plus the business travel and expense card controls that keep the big commitments in view. Running it on one corporate travel booking platform means the same policy the VP owns is the one the controller enforces and the CFO can see, rather than three versions in three systems.

FAQ

Who owns the T&E policy in a company?

Ownership is shared across finance, but one role should be accountable. Typically the CFO sets the strategy and budget, the controller enforces the policy and runs compliance, and the VP of finance owns and maintains the policy document. In a RACI model the VP of finance is usually Accountable, with the controller and travel manager Responsible and the CFO Consulted.

Is T&E policy the CFO's responsibility?

The CFO is accountable at the top but should not own the day-to-day policy. The CFO sets the spend target, the risk appetite, and signs the major financial commitments, then delegates the drafting to the VP of finance and the enforcement to the controller. Writing per-diems or approving individual trips is not a good use of the CFO's role.

What is the difference between the controller and the VP of finance?

The controller is the company's chief accountant, focused on backward-looking accuracy: the close, internal controls, compliance, and reporting. The VP of finance is the forward-looking bridge to the CFO, owning FP&A, budgeting, systems, and usually the policy document itself. In smaller firms one role absorbs the other's duties, which is why T&E ownership varies by org chart.

Should the travel manager own the T&E policy?

The travel manager executes and advises on the policy but rarely owns it. They apply the rules day to day, negotiate with suppliers, and flag what is not working, which makes them Responsible and Consulted in a RACI model. Formal ownership sits in finance, because the policy governs company money and internal controls, not just travel logistics.

How do you assign T&E policy ownership?

Use a RACI matrix and name exactly one Accountable owner. Make the VP of finance or, if there is none, the controller Accountable for the policy; make the controller and travel manager Responsible for enforcement and execution; Consult the CFO, HR, legal, and security; and keep department heads and travelers Informed. The rule that matters is one accountable owner, not several.

Why does T&E policy ownership matter?

Because unowned policy leaks money. Business travel is a $1.71 trillion category in 2026, and expense-reimbursement fraud appears in roughly 13% of occupational-fraud cases at a $50,000 median loss. When no single role is accountable for the policy, out-of-policy spend and reimbursement abuse have room to grow, and no one is answerable for closing the gap.

Ardra M B
Content Strategist

Ardra is a Content Strategy Manager at ITILITE with 6+ years of experience in travel and SaaS content. She holds a Master’s degree in Political Science from Lady Shri Ram College for Women and transitioned from academic research and travel content into SaaS content strategy.

She previously worked with JustWravel, where she focused on travel storytelling and digital content. Today, she specializes in SEO and AEO-driven content strategies that help businesses simplify complex travel and expense workflows into search-optimized narratives.

When she’s not working, Ardra is usually reading or watching films.

Read more
CTA Download File
Share this article
Set it, enforce it, prove it

Give every T&E policy a single clear owner

A fully integrated corporate travel management software that dramatically reduces spends while improving user experience

Read More Blogs