Governance / Approvals Review

Governance and Approvals Health Check

Most governance failures that end up in an audit report or a parliamentary committee are visible years earlier in the approval trail. We test yours now: whether the approvals your law, constitution and board require were actually obtained, whether the minutes prove it, and whether money is flowing where it is allowed to.

Approvals tested against your enabling Act, constitution and board resolutions Board minutes, delegations and parent to subsidiary fund flows reviewed Findings ranked by exposure, with a remediation plan
Overview

Governance & Approvals Health Check

What it is

A fixed-scope review of how decisions are approved and recorded across your organisation and its subsidiaries. We sample significant decisions, investments and payments, trace each one to the approval it needed, and report where the trail is missing, late or given by the wrong body.

Why organisations need it

Statutory bodies and public universities often need approvals that sit outside the board. Under the Universities and University Colleges Act 1971, for example, a university needs the Minister of Finance's approval to take equity stakes, form joint ventures, set up companies, borrow and invest. Officers of statutory bodies can be personally surcharged for payments not duly approved. Companies and GLCs face the same scrutiny from auditors, shareholders and enforcement agencies. An approval that was never obtained cannot be fixed after the Auditor-General has found it, but it can be fixed before.

Key features

What the engagement covers

Scoped to your legal structure. A statutory body with three subsidiaries and a listed group with thirty need different depth, and we size the sample accordingly.

Legal and constitutional approvals map

A map of every approval your enabling Act, constitution, articles and shareholder arrangements reserve to a minister, the Ministry of Finance, the board or shareholders, so the review tests against the right rules.

Sample testing of significant decisions

A risk-based sample of investments, capital projects, borrowings, company formations, large contracts and payments, each traced to the approval it required and the date it was obtained.

Board and committee minutes

Whether minutes record the decision, the papers considered, conflicts declared and the reasoning, well enough to show an auditor or investigator what was decided and why.

Delegations and limits of authority

Whether management acted within delegated authority, whether delegations are current and documented, and where they have been bypassed.

Parent and subsidiary fund flows

Capital injections, advances, guarantees, management fees and dividends between the parent and its companies, tested for approval, documentation and commercial basis.

Remediation plan

Findings ranked by legal and reputational exposure, with actions to regularise past decisions where possible and fix the process going forward.

Business value

What the business gets out of it

You find it before the auditor does

A missing approval found internally is a remediation item. The same gap found by the Auditor-General is a public finding.

Officers are protected

Clear evidence that decisions were properly approved protects the individuals who made them, including against surcharge and disciplinary action.

The board gets a straight answer

Directors see where the organisation stands on approvals and governance records, not just an assurance that policies exist.

Subsidiaries come into view

Group governance gaps usually sit in the companies furthest from the board. The review brings them into the same picture.

A basis for fixing the process

Findings lead directly into limits of authority design, board processes and training, so the same gap does not reopen.

Independent and vendor-neutral

We do not sell systems or take on the transactions we review, so the findings are not shaped by a follow-on sale.

How it works

How the engagement runs

01

Scoping

Agreeing entities, period, decision types and sample size, and collecting the enabling Act, constitution, delegations and minutes.

02

Approvals mapping

Building the map of approvals each type of decision required and who could give them.

03

Testing

Tracing sampled decisions and payments through papers, minutes, approvals and payment records, with interviews where the trail is unclear.

04

Findings validation

Walking management through draft findings so facts are right before anything reaches the board.

05

Reporting

A board-level report with findings ranked by exposure and a remediation plan with owners and dates.

06

Follow-up

An optional re-test after remediation to confirm the gaps are closed.

Deliverables

What you receive

Approvals map

Every reserved approval by decision type, source of the requirement and approving body.

Testing workpapers

Each sampled decision with the approval required, the approval obtained and the evidence.

Minutes and delegations review

Assessment of minute quality and delegation currency, with examples.

Fund flow review

Parent and subsidiary transactions tested for approval and basis.

Board report

Findings ranked by exposure, with a plain summary for directors.

Remediation plan

Actions, owners, dates and the steps to regularise past decisions where possible.

Who it is for

Who this is built for

Industries

Federal and state statutory bodiesPublic universities and their holding companiesGovernment-linked companiesGovernment-linked investment companiesCo-operatives and foundationsListed groupsFamily groups with holding structures

Company sizes

Statutory bodiesUniversity groupsGLCs and GLICsListed and unlisted groups

Departments

Board and audit committeeChief executiveCompany secretaryFinance and investmentLegalInternal auditIntegrity unit
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

How is this different from an internal audit?

It is narrower and deeper on one question: whether decisions were approved by the right body, at the right time, with records to prove it. Internal audit plans rarely test approvals against the enabling Act and minutes in this way, and the health check can feed their plan.

Can past decisions that lacked approval be fixed?

Sometimes. Some approvals can be sought after the event, some decisions can be ratified, and some cannot be cured at all. We set out which is which and what disclosure may be needed, and we recommend legal advice where the position is contentious.

Do you need access to board papers?

Yes. The review depends on minutes, papers, approvals and payment records. Everything is handled under a confidentiality agreement and restricted access.

Our organisation is a company, not a statutory body. Is this relevant?

Yes. Companies and groups have reserved matters in their constitutions, shareholder agreements and board charters, and payments made outside delegated authority are a common audit and fraud finding.

Will you name individuals in the report?

The report focuses on decisions and processes. Where individual accountability matters, we set out the facts and leave conclusions about individuals to the board and its advisers.

How long does it take?

Typically four to eight weeks depending on the number of entities and the sample size, which we fix at scoping.

Get started

Test your approval trail before someone else does

Tell us your structure, the entities you want covered and what prompted the review. We will come back with a scope, a sample approach and a fixed quotation.