The Delegation of Authority
In a founder-run company, the rule for who can commit the company to what lives in one person's head. The delegation of authority is how that instinct becomes a document the organization can operate — and a regulator can test. It is the piece we see companies underestimate most.
Ask the founder of a fast-growing company who can approve a SAR 2 million contract, and the answer is instant: "I do." Ask who approves it when the founder is travelling, unreachable, or simply no longer wants every decision on their desk, and the answer gets vague. That vagueness is not a small administrative gap — it is the point at which a business either becomes an institution that can operate without one person, or stays a company that stops when that person does.
A delegation-of-authority (DoA) framework is the document that closes it. It states, plainly, who may commit the company to what, and above which limits a decision must rise to a more senior level — management, the board, or the owners. It is how "the owner decides" becomes "the organization decides, within limits the board has set."
What the framework actually is
Stripped to its core, a DoA framework is a matrix. Down one side sits every kind of decision that binds the company. Across the top sit the roles that can approve them and the monetary or risk thresholds attached to each. Any given decision can then be traced to a single answer: who is allowed to say yes to this, and up to what limit?
Done well, it removes ambiguity in both directions. A manager knows exactly what they can approve without escalating — which speeds the business up, not down. And everyone above them knows what must come to them, so nothing large slips through unseen.
What it should govern
Founders often think of DoA as being about payments. Payments matter, but the framework should reach every way the company can be committed:
- Expenditure and payments — operating spend and the release of funds, by tier.
- Capital expenditure — assets and projects, which usually carry lower thresholds than routine spend.
- Contracts and commitments — signing the company up to obligations, including their duration, not just their value.
- Banking and treasury — who can open accounts, borrow, give guarantees, or move money between entities.
- Hiring and compensation — headcount, salary bands, and senior appointments.
- Pricing and discounts — how far commercial teams can move price before approval.
- Related-party transactions — which should almost always escalate, regardless of value.
- Legal and regulatory — settlements, litigation, and anything that creates legal exposure.
Thresholds and escalation
The mechanism that makes a DoA work is the tiered threshold. Below a limit, a role decides alone; above it, the decision escalates. A simple, common shape:
- A department manager approves routine spend up to a modest limit.
- The CEO or general manager approves up to a higher limit, and everything within approved budget.
- The board (or a committee) approves major commitments, anything outside budget, and defined categories regardless of amount.
- The owners or shareholders retain a small set of fundamental decisions.
The numbers themselves matter less than the discipline. Set them too low and everything escalates, choking the business and training people to work around the framework. Set them too high and the board sees nothing until it is too late. The right thresholds reflect the company's size, risk appetite, and how much the board wants to see.
A threshold set so low that everyone routinely bypasses it is worse than no threshold at all — it teaches the organization that the rules are optional.
Reserved matters: what only the top decides
Above the tiers sits a short list of reserved matters — decisions that never delegate downward, no matter the amount. Typically these include changes to strategy, the annual budget, major acquisitions or disposals, taking on significant debt or guarantees, related-party dealings of substance, and senior executive appointments and pay. Naming these explicitly is what stops the most consequential decisions from being made quietly at the wrong level.
How it connects to your controls
A DoA framework is not a standalone policy; it is the backbone that several controls hang from. It gives segregation of duties its authorization step — the "approve" that must sit apart from "record" and "pay." It gives the budget its teeth, by defining who can commit against it and who must approve anything outside it. And it gives the board its line of sight, by routing the decisions that matter up to where they can be seen. Without a DoA, these controls have no agreed definition of who is allowed to act.
Making it real — not a document in a drawer
The most common failure is not a badly designed DoA; it is a well-designed one that nobody follows. Three things make it real:
- Board approval. The framework should be formally adopted by the board, so its limits carry authority rather than being one manager's preference.
- Embedded in the systems. The thresholds should live in the accounting system's approval workflows and the bank's authorization rules — so the limit is enforced automatically, not remembered.
- Tested against reality. Auditors will check whether actual approvals matched the matrix. If a payment above a limit went out on one signature, the DoA failed, however elegant it looked on paper.
What a delegation-of-authority framework should cover
- Every category of commitment — spend, capex, contracts, banking, hiring, pricing, legal
- Tiered thresholds for manager, CEO, board, and owners
- A defined list of reserved matters that never delegate downward
- Related-party transactions routed to escalate regardless of value
- Formal board approval of the framework
- Thresholds embedded in system and bank approval workflows
- Periodic review against actual approvals, so reality matches the matrix
Writing the delegation of authority down is one of the least glamorous things a growing company does, and one of the most consequential. It is the document that lets the founder step back without the business holding its breath — and the first thing a serious investor, lender, or regulator will ask to see as proof that the company is governed by structure rather than by a single person's presence in the room.
Turning the founder's instinct into structure?
We design delegation-of-authority frameworks — tiered, board-approved, and built to sit inside your systems — for companies making the move from owner-led to governed.
Discuss your mandate →This article is general guidance on governance practice and does not constitute legal, audit, or regulatory advice. Obtain professional advice for your specific circumstances.