Corporate Risk Mitigation • Delegation & Approval Controls • India • 2026

Delegation of Authority & Approval-Control Audit in India: Board Powers, Banking, Procurement, Contracts, Capex & Override Controls 2026

A corporate-standard framework for testing whether people, systems and approvals actually match the company’s legal authority structure and board-approved decision rights.

AuthorityBoard powers, reserved matters and delegated limits
ApprovalsBanking, contracts, procurement, capex and settlements
SystemsERP workflows, maker-checker and access rights
OverridesEmergency authority, post-facto approvals and exception logs

A delegation-of-authority matrix is effective only if the company’s contracts, bank mandates, ERP workflows, procurement systems and real-world management behaviour follow it. In many companies, the written matrix says one thing while operational practice is driven by email approvals, seniority, legacy signatories or informal instructions.

An approval-control audit determines who is legally and internally authorised to do what, whether system rights reflect that authority, whether approvals can be bypassed, and whether exceptions leave a defensible audit trail.

Governance standard: delegation transfers decision authority within defined limits; it does not eliminate the accountability of the board or senior management for oversight.

1. Map the sources of authority

The audit should begin with the Companies Act framework, memorandum and articles, shareholder arrangements where relevant, board resolutions, committee charters, bank mandates, powers of attorney, internal delegation matrices, procurement policies, HR approval rules and system-workflow configurations.

Sections dealing with board powers and matters requiring particular approvals should be checked for the company and transaction concerned. Internal delegation cannot authorise something that law or the constitutional documents reserve to the board or shareholders.

See Promoter & Director Risk Assessment in India for director-level governance exposure.

2. Build a transaction-by-transaction authority map

Decision area Typical authority question Evidence
Banking Who can create beneficiaries, release payments or change limits? Bank mandate, maker-checker logs, board resolutions
Procurement Who approves vendor, PO, rate and emergency purchase? Policy, ERP, bids, approvals
Contracts Who can bind the company and at what value/risk? DoA matrix, signature policy, contract repository
Capex Who approves budget and asset purchase? Capex policy, budgets, board records
HR Who appoints, revises compensation, suspends or terminates? HR authority matrix and employment records
Claims/settlements Who can admit liability, waive recovery or settle disputes? Legal policy, settlement approvals, releases

3. Test whether the ERP mirrors the policy

A paper authority matrix is weak if the ERP permits lower-level users to create vendors, alter prices, approve invoices or release transactions above their limits. Review user roles, approval workflows, super-user privileges, manual override rights and whether terminated or transferred employees still retain access.

Access recertification should be periodic and role-based. Finance, procurement and system administrators deserve enhanced scrutiny because their access can change both data and payment outcomes.

4. Maker-checker and segregation of duties

High-risk activities should not normally be controlled end-to-end by one person. Examples include vendor creation plus payment approval, employee creation plus payroll release, customer credit creation plus write-off, or contract creation plus settlement of claims arising from the same agreement.

The audit should identify incompatible roles and test whether emergency access, leave coverage or system limitations routinely defeat segregation.

5. Contract signature authority

Companies often focus on value thresholds but ignore risk terms. A relatively low-value contract may contain uncapped indemnity, exclusivity, data obligations, IP transfer or long-term minimum commitments. Authority rules should therefore include risk-based escalation, not merely rupee value.

Executed contracts should be tested against authorised signatory lists, powers of attorney and legal-review requirements. See Contract Risk Audit in India.

6. Procurement splitting and threshold avoidance

A common control weakness is dividing one requirement into several purchase orders, invoices or work orders so that each falls below a higher approval threshold. Analytics should therefore examine same-vendor, same-date or same-project transactions just below defined limits.

Splitting is not automatically misconduct; genuine phased purchases can occur. The pattern should be tested against business need, timing and approvals.

7. Banking authority and beneficiary controls

Review who can open accounts, change signatories, create beneficiaries, amend beneficiary bank details, initiate payments, release payments and alter online banking limits. Legacy signatories and shared credentials should be removed.

Vendor bank-detail changes should require independent verification and a separate approval trail. For related fraud controls, see Vendor & Procurement Fraud Risk in India.

8. HR authority and sensitive personnel decisions

Authority rules should define appointment, compensation change, incentive approval, transfer, suspension, disciplinary action, settlement and termination. High-risk exceptions arise where one business leader can both set targets and approve unusual incentive or expense outcomes without independent review.

Disciplinary authority should also align with employment documents, policies and applicable law so that urgency does not result in an unauthorised or procedurally defective decision.

9. Litigation, claims and settlement authority

Companies should define who may issue legal notices, appoint counsel, admit liability, waive claims, settle disputes, sign undertakings, approve refunds or compromise recovery. Material settlements should be documented with claim value, litigation risk, commercial rationale and approval authority.

Weak settlement authority can create value leakage or inconsistent positions across similar disputes.

10. Emergency and crisis authority

Crises may justify temporary higher authority, but emergency powers should have a start point, scope, monetary limits, named holders, prohibited actions and a post-event review. “Emergency” should not become a permanent alternative to ordinary controls.

See Corporate Crisis Risk Response in India.

11. Post-facto approvals and ratification risk

Post-facto approval may be unavoidable in genuine emergencies, but repeated retrospective approval signals that the authority model is not functioning. Maintain an exception register with transaction, amount, reason, original approver, required approver, date ratified and corrective action.

The board should receive trends, not merely individual exceptions, because repeated post-facto approval can indicate management override or deliberately weak governance.

12. Approval-control risk matrix

Rating Illustrative issue Response
Critical Unauthorised borrowing/security, payment release without control, senior override with material loss Immediate restriction and board/legal review
High Repeated post-facto approvals, incompatible system roles, threshold splitting Control redesign and targeted testing
Medium Stale matrix, legacy signatories, documentation gaps Update authority and recertify access
Low Isolated clerical exception Routine correction

13. Board-ready deliverables

  • legal/reserved-matter map;
  • master delegation-of-authority matrix;
  • authorised-signatory register;
  • banking authority matrix;
  • ERP role-conflict report;
  • procurement threshold exception analysis;
  • contract-signature exception list;
  • HR decision authority schedule;
  • settlement and waiver authority register;
  • emergency/post-facto approval log; and
  • remediation and access-recertification tracker.

14. 30/60/90-day remediation

0–30 days: revoke stale signatories and access, identify critical unauthorised rights, document reserved matters and stop unsupported payment or beneficiary overrides.

31–60 days: align ERP workflows with the DoA, introduce risk-based contract escalation, close incompatible roles, revise procurement and HR approvals.

61–90 days: implement quarterly access recertification, exception dashboards, periodic threshold analytics and board reporting on material overrides.

15. Frequently asked questions

Can the CEO approve everything?

Not necessarily. Some matters may be reserved by law, constitutional documents, shareholders or board policy.

Should approval limits be based only on value?

No. Data, liability, IP, exclusivity, regulatory exposure and reputation can justify higher escalation even at lower value.

Is email approval sufficient?

It may evidence a decision in some contexts, but companies should use controlled workflows for material transactions and ensure the approver actually had authority.

How often should the DoA be reviewed?

Periodically and after material changes in leadership, organisation structure, systems, financing or business model.

What is the biggest approval-control risk?

A gap between written authority and actual system capability—especially where one user can initiate and complete a high-risk transaction.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Website: fastracklegalsolutions.com
The particulars above are provided solely for identification and correspondence. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services.
General corporate-risk information only. Authority and approval requirements depend on current law, constitutional documents, board decisions, contracts and company-specific governance.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *