Current state review
Your existing delegations, board charter, reserved matters and approval practice, including how decisions are actually approved in practice.
A limits of authority matrix is the control between a decision and a payment. Most organisations have one. Fewer have one that is current, understood, built into the payment system and hard to get around. We design or review yours so unauthorised spending gets stopped rather than discovered.
A design or review engagement for your limits of authority, also called delegation of authority. We set or test who may approve what, to what value and with what papers, align it with your legal and constitutional approvals, and make sure the payment and procurement process enforces it.
Payments made without the required approval are among the most common findings in audit reports and investigations, and in statutory bodies they carry personal consequences: the Statutory Bodies (Discipline and Surcharge) Act 2000 allows an employee to be surcharged for any payment of moneys not duly approved. In companies, the same failure exposes directors, weakens the Section 17A adequate procedures defence, and is where fraud usually starts. A matrix that sits in a policy file does not prevent any of it.
We either design a new framework or review and repair the one you have, depending on its condition.
Your existing delegations, board charter, reserved matters and approval practice, including how decisions are actually approved in practice.
Decision categories, value thresholds, joint approvals, sub-delegation rules, conflicts of interest and the approvals that sit outside the organisation, such as a minister, the Ministry of Finance or a parent company.
A clear list of what only the board, or shareholders, may decide, aligned with your constitution and applicable law.
Building the matrix into procurement, contract and payment workflows so the system blocks what the policy prohibits.
Data analysis of past payments for split transactions, retrospective approvals, approvals outside the system and payments above authority.
Communication, approver briefings and a short training module, plus a process to keep the matrix current as the organisation changes.
Controls built into the payment process prevent the problem instead of documenting it afterwards.
A clear, current matrix removes the ambiguity that leads to well-meaning people approving what they should not.
When every approval sits within documented authority, the people who give them are protected.
Approval exceptions are among the first things auditors test. A working matrix shrinks that finding list.
Split payments and retrospective approvals are classic fraud patterns. Bypass testing and system controls close them.
A sound delegation framework is evidence for Section 17A adequate procedures and a foundation for ISO 37001 and ISO 37301.
Collecting delegations, charters, constitution, organisation chart and system workflows, and interviewing key approvers.
Comparing current practice with the legal and constitutional approvals that apply and with good practice.
Drafting the matrix and reserved matters with finance, legal and the company secretary.
Testing past payments for bypasses and quantifying exceptions.
Configuring workflows with your IT and finance teams and briefing approvers.
Presenting the framework for board approval, with a review cycle.
The policy, principles and governance for delegations.
Decision types, thresholds, approvers and supporting documents required.
What only the board or shareholders may decide.
Exceptions found in past payments, with values and root causes.
How the matrix is enforced in procurement and payment systems.
Training material and a quick reference for approvers.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
They are usually the same thing under different names: the framework setting out who may approve which decisions and payments, and to what value. Some organisations also use delegation of authority for the formal board resolutions that grant the powers.
Most matrices go stale as the organisation changes, and many are never built into the payment system. The review tests whether yours is current, followed and enforced, using real payment data.
Yes, and for statutory bodies and universities it must. Approvals reserved to a minister or the Ministry of Finance are built in as conditions that must be met before internal approval can take effect.
We specify the workflow rules and work with your IT team or ERP vendor on configuration. We do not sell software.
By analysing payment data for patterns such as multiple payments to one vendor just under a threshold within a short period, and then reviewing the underlying documents.
At least annually, and whenever the organisation restructures, changes its systems or creates new entities.
Send us your current delegations or tell us you do not have any. We will come back with a scope for design or review, and a fixed quotation.