Governance / Delegation of Authority

Limits of Authority Design and Review

A limits of authority matrix is the control between a decision and a payment. Most organisations have one. Fewer have one that is current, understood, built into the payment system and hard to get around. We design or review yours so unauthorised spending gets stopped rather than discovered.

Approval matrix and board reserved matters, designed or reviewed Linked to procurement, contracts and payment systems Tested against real payments for bypasses and split approvals
Overview

Limits of Authority Design & Review

What it is

A design or review engagement for your limits of authority, also called delegation of authority. We set or test who may approve what, to what value and with what papers, align it with your legal and constitutional approvals, and make sure the payment and procurement process enforces it.

Why organisations need it

Payments made without the required approval are among the most common findings in audit reports and investigations, and in statutory bodies they carry personal consequences: the Statutory Bodies (Discipline and Surcharge) Act 2000 allows an employee to be surcharged for any payment of moneys not duly approved. In companies, the same failure exposes directors, weakens the Section 17A adequate procedures defence, and is where fraud usually starts. A matrix that sits in a policy file does not prevent any of it.

Key features

What the engagement covers

We either design a new framework or review and repair the one you have, depending on its condition.

Current state review

Your existing delegations, board charter, reserved matters and approval practice, including how decisions are actually approved in practice.

Matrix design

Decision categories, value thresholds, joint approvals, sub-delegation rules, conflicts of interest and the approvals that sit outside the organisation, such as a minister, the Ministry of Finance or a parent company.

Board reserved matters

A clear list of what only the board, or shareholders, may decide, aligned with your constitution and applicable law.

System integration

Building the matrix into procurement, contract and payment workflows so the system blocks what the policy prohibits.

Bypass testing

Data analysis of past payments for split transactions, retrospective approvals, approvals outside the system and payments above authority.

Rollout and training

Communication, approver briefings and a short training module, plus a process to keep the matrix current as the organisation changes.

Business value

What the business gets out of it

Unauthorised payments get stopped

Controls built into the payment process prevent the problem instead of documenting it afterwards.

Approvers know their limits

A clear, current matrix removes the ambiguity that leads to well-meaning people approving what they should not.

Officers are protected

When every approval sits within documented authority, the people who give them are protected.

Auditors find less

Approval exceptions are among the first things auditors test. A working matrix shrinks that finding list.

Fraud gets harder

Split payments and retrospective approvals are classic fraud patterns. Bypass testing and system controls close them.

It supports your wider programme

A sound delegation framework is evidence for Section 17A adequate procedures and a foundation for ISO 37001 and ISO 37301.

How it works

How the engagement runs

01

Discovery

Collecting delegations, charters, constitution, organisation chart and system workflows, and interviewing key approvers.

02

Gap assessment

Comparing current practice with the legal and constitutional approvals that apply and with good practice.

03

Design

Drafting the matrix and reserved matters with finance, legal and the company secretary.

04

Data testing

Testing past payments for bypasses and quantifying exceptions.

05

Implementation

Configuring workflows with your IT and finance teams and briefing approvers.

06

Board adoption

Presenting the framework for board approval, with a review cycle.

Deliverables

What you receive

Limits of authority policy

The policy, principles and governance for delegations.

Approval matrix

Decision types, thresholds, approvers and supporting documents required.

Board reserved matters schedule

What only the board or shareholders may decide.

Bypass testing report

Exceptions found in past payments, with values and root causes.

Workflow specification

How the matrix is enforced in procurement and payment systems.

Approver briefing pack

Training material and a quick reference for approvers.

Who it is for

Who this is built for

Industries

Statutory bodiesPublic universities and holding companiesGovernment-linked companiesListed companiesConstruction and propertyManufacturingHealthcare groupsCo-operatives

Company sizes

Large enterpriseMid-marketGroup structures with subsidiariesStatutory bodies

Departments

BoardChief executiveFinanceProcurementCompany secretaryInternal auditIT systems owners
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

What is the difference between limits of authority and delegation of authority?

They are usually the same thing under different names: the framework setting out who may approve which decisions and payments, and to what value. Some organisations also use delegation of authority for the formal board resolutions that grant the powers.

We already have a matrix. Why review it?

Most matrices go stale as the organisation changes, and many are never built into the payment system. The review tests whether yours is current, followed and enforced, using real payment data.

Can the matrix handle approvals from outside the organisation?

Yes, and for statutory bodies and universities it must. Approvals reserved to a minister or the Ministry of Finance are built in as conditions that must be met before internal approval can take effect.

Do you configure our systems?

We specify the workflow rules and work with your IT team or ERP vendor on configuration. We do not sell software.

How do you find split payments?

By analysing payment data for patterns such as multiple payments to one vendor just under a threshold within a short period, and then reviewing the underlying documents.

How often should the matrix be reviewed?

At least annually, and whenever the organisation restructures, changes its systems or creates new entities.

Get started

Make approvals mean something

Send us your current delegations or tell us you do not have any. We will come back with a scope for design or review, and a fixed quotation.