What a delegation of authority matrix defines
Each row of the matrix answers one complete question: for this kind of spend, in this part of the organization, up to this amount — who decides? The columns that make the answer usable:
- Amount band. The range the row covers, in a stated currency. Bands must be contiguous and non-overlapping — a claim that fits two rows has two possible approvers, which in practice means whoever is asked first.
- Spend category. Travel, meals, software, professional services. Category matters because risk does: a modest software subscription can commit the company for longer than an expensive flight.
- Entity and department. Authority is granted within a legal entity, and often within a budget line. A matrix that ignores entity boundaries assigns approvals to people with no authority over the money being spent — the multi-entity version of this problem has its own dedicated treatment in the multi-entity guide.
- Primary approver, by role. Name roles, not people. “Finance manager, entity X” survives a resignation; “María” does not.
- Backup approver. Who decides when the primary is on leave or is the submitter. A matrix without backups routes exceptional claims to nobody, and urgent claims to whoever is willing.
Internal-control frameworks treat this as core design material rather than bureaucracy: COSO’s Internal Control — Integrated Framework organizes effective internal control into interdependent components and is explicit that internal control has value beyond compliance and external financial reporting, and the GAO’s Green Book — the U.S. federal internal-control standard, revised May 15, 2025, effective from fiscal year 2026, and harmonized with COSO — emphasizes prioritizing preventive control activities. An authority matrix is precisely that: a preventive control, deciding who may commit the company before the money moves.
Build the table
The builder collects rows with the six fields above and renders the matrix as a finance-readable table you can check by eye before exporting. Guidance per field:
| Field | What to enter | What to avoid |
|---|---|---|
| Amount band | A contiguous range in one stated currency, e.g. 0–500, 500–5,000 | Overlapping bands; bands in mixed currencies; an open top band with no escalation row |
| Category | The spend categories your policy already uses | Inventing categories for the matrix that the expense system does not have |
| Entity / department | The legal entity, and the department when authority is budget-line specific | “Group” as an entity — someone specific pays every claim |
| Primary approver | A role: manager, department head, finance manager, CFO | Named individuals; roles no one currently holds |
| Backup approver | The role that decides in the primary’s absence or conflict | Leaving it blank; naming the submitter’s peer |
| Notes | Escalation conditions, exception owners, effective date | Policy prose — the matrix is a table, not a document |
Two properties make the output survive contact with reality. Completeness: every plausible claim should land in exactly one row — including the very large one, which needs an explicit top band routed to executive or board authority rather than an implicit “that never happens.” Readability: if a row needs explaining, it needs rewriting. A matrix that only its author can interpret will not survive an audit walkthrough or a new manager’s first week.
Set amount bands from your own data
There are no universal thresholds, and this page deliberately does not suggest any. A band that routes most claims to senior approvers in one company is a rounding error in another — copying a template’s numbers imports someone else’s spend distribution along with them.
Pull your last two quarters of claims
Look at the distribution by amount, per entity. The bands should follow the distribution’s natural breaks, not round numbers chosen in a meeting.
Put the routine bulk in the lowest band
If the majority of claims sit under some amount, that is your first boundary — those claims get the lightest authority that your risk tolerance allows, so attention concentrates where amounts are exceptional.
Size the top of each band by attention, not prestige
Each escalation adds a busier person to the chain. A band boundary that sends a third of claims to the CFO does not add control; it adds a queue that gets skimmed.
Denominate per entity
The same numeric threshold means different things in different markets. Set bands in each entity’s own currency, with a group floor if you need consistency — the reasoning is the same as for spend-control thresholds generally.
Record the effective date
Bands are calibrated to a spend distribution that will drift. A dated matrix tells the next reviewer what era its numbers belong to.
Backups, conflicts, and exceptions
The rows cover the normal case. Three abnormal cases decide whether the matrix works under pressure:
- Absence. The backup column exists so that a claim never waits on one person’s vacation. The backup inherits the same band and category scope — a backup with wider authority than the primary is a quiet escalation nobody approved.
- Conflict. When the approver is the submitter — or the cost benefits the approver’s own budget in a way that compromises review — the claim must route around them, upward or sideways to finance, never downward. The duty-splitting logic behind this is covered in segregation of duties in expenses.
- Exception. Someone will eventually need to approve outside the matrix — a new category, an amount above every band, an entity with no local approver yet. The matrix should name who may grant exceptions and require that each one is recorded with its reason. An exception without a record is indistinguishable from a control failure.
Review the matrix when the company changes
A matrix is calibrated to an org structure and a spend distribution, and both drift. Review it quarterly, and immediately when any of these occur:
A new entity or market opens
New currency, new local roles, new rows.
Reporting lines change
Roles in the matrix may no longer exist or may have moved entities.
Budgets reset
Annual planning changes what a “large” claim is.
An audit finding names an approval gap
The matrix is the artifact the remediation lands in.
The exception log grows
Repeated exceptions in one row mean the row is mis-calibrated; the exception has become the real policy and should be promoted into the table or explicitly rejected.
The quarterly pass itself is short if the matrix is a table: check that every role still exists, every band still matches the distribution, every backup is still valid, and the exception log has nothing recurring. Date the review — an undated matrix is presumed stale by exactly the people it is meant to convince.