Who Can Sign What? 6 Rules for a Delegation of Authority Matrix That Stops Fraud Without Slowing the Company
By Victor Fdez. de Manzanos · CEO & Owner, Manzanos Enterprises
On February 26, 1995, Barings, the London merchant bank that had helped finance the Louisiana Purchase and counted the Queen among its clients, collapsed. It had been founded in 1762. The hole in its balance sheet was £827 million, roughly twice its capital, and it had been dug by one 28-year-old trader in Singapore named Nick Leeson. Within days, ING bought what was left for a single pound.
Leeson was not a criminal genius. He was a man with two jobs. He ran the Singapore trading desk, and he also ran the back office that settled and recorded those same trades. Nobody else had to sign off on what he booked, so an error account numbered 88888 hid his losses for almost three years.
Most private companies are organized exactly like Barings' Singapore office: the same person can commit the money, approve the payment and record it. It rarely ends in a headline. It ends in a quiet loss nobody finds for a year.
The numbers are not abstract. The Association of Certified Fraud Examiners' Occupational Fraud 2024: A Report to the Nations put the median loss per case at $145,000, and at $141,000 for organizations with fewer than 100 employees, which hurts far more on a small balance sheet. The median scheme ran 12 months before anyone noticed, and more than half of the cases were tied to missing internal controls or to managers overriding them. Outside the building, the FBI's Internet Crime Complaint Center logged 21,442 business email compromise complaints in 2024, with $2.77 billion in reported losses.
Our group runs eight active businesses, from wine and real estate to hospitality and mobility, selling into more than 75 countries. When a company grows that way, the founder's signature stops being a control and becomes a bottleneck, and the people around the founder start improvising their own limits. The fix is a written delegation of authority: one document that says who can commit what, up to how much, and with whose second signature. Here are the six rules I would apply to any company building one.
Rule 1: Write it as a matrix, not a memo
A paragraph that says "managers may approve reasonable expenses" is not a control. It is an argument waiting to happen.
A delegation of authority works when anyone can find the answer to "can I sign this?" in under a minute. That means a grid. The rows are decision types: operating spend, capital projects, customer contracts, supplier contracts, hiring and pay, discounts and credit terms, bank accounts, legal matters. The columns are roles, not names. Each cell holds a limit, or a blank that means "not this role."
Larger companies usually pair the grid with a short policy explaining the principles. For a private company of 20 or 200 people, one page of grid and one page of rules is enough. The point is not bureaucracy. The point is that a new plant manager in Navarra and a new sales director in Miami read the same answer.
Rule 2: Separate the four keys: commit, approve, pay, record
Barings failed because four keys hung on one ring. Every material transaction has four steps, and no single person should hold all of them:
- Commit: the person who negotiates the purchase or signs the order.
- Approve: the person who confirms it is within budget and authority.
- Pay: the person who releases the money from the bank.
- Record: the person who books it and reconciles the account.
The minimum rule is simple: whoever creates a new supplier in the system cannot also pay that supplier. Fake vendors and altered bank details are the classic schemes, and they survive only where one person controls both ends.
Small teams will say they do not have enough people to separate duties. Then compensate. The owner reviews the bank statement personally every month, looking at the payee list rather than the totals. Bank platforms require two users to release any transfer. Anyone who handles cash takes a real vacation, during which someone else does the job. Hidden schemes tend to surface when their author is not there to maintain them.
Rule 3: Set limits by consequence, not by rank
The natural instinct is to hand out limits by title: $5,000 for a manager, $50,000 for a director, everything above for the CEO. That is a start, but it misses where the real risk sits.
A 3% discount granted to your largest customer for three years can cost more than a new forklift, yet most companies let a salesperson approve the first and make the CEO approve the second. Limits should follow the consequence of the decision, which depends on three things:
- Size over the full term. Measure contracts by total contract value, not the annual amount. A five-year lease at $4,000 a month is a $240,000 commitment.
- Reversibility. A purchase you can return deserves a looser limit than an exclusive distribution agreement you cannot exit for five years.
- Precedent. Payment terms, price exceptions and exclusivity create expectations across the whole customer base.
Some decisions go to the top regardless of amount: personal guarantees, exclusivity, anything touching intellectual property, litigation, opening or closing bank accounts, and any transaction with a related party. Add an anti-splitting clause, because the fastest way around a $10,000 limit is four invoices of $9,900.

Rule 4: Make the payment door the hardest one to open
Most modern theft does not come from inside. It arrives as an email that looks exactly like a supplier asking you to update their bank details.
In 2019 Toyota Boshoku, a Toyota group parts maker, disclosed that its European subsidiary had been tricked into transferring about ¥4 billion, just over $37 million, after criminals impersonating a business partner persuaded staff to change the account details for a payment. The company was large, audited and well run. The weak point was a single instruction that nobody verified through a second channel.
No change to a supplier's bank details should ever be accepted on the strength of an email, however authentic it looks. Write the following into the matrix as non-negotiable:
- Any new beneficiary or changed bank account requires a call-back to a phone number already on file, never one given in the request.
- Transfers above a threshold need two approvers inside the banking platform, not just inside the accounting system.
- Urgency and secrecy, "the CEO needs this today, don't tell anyone," trigger more verification, not less.
These controls cost a few minutes per payment. The alternative is a loss that insurance often excludes, a point I made when writing about the risk transfer rules private companies overlook.
Rule 5: The owner is not exempt
This is the rule founders dislike most. It is also the one the data supports most strongly.
In the ACFE study, frauds committed by owners and executives carried a median loss of $500,000, several times the overall median, because the people at the top can override every control below them. Even when the owner is honest, an owner with unlimited authority is the easiest person for an outside fraudster to impersonate.
The owner's limit should be written into the matrix too, with a second signature required above it. In a family company that second signature can be a sibling who is a shareholder, the CFO, or the chair of an independent board. It also solves a problem that has nothing to do with fraud. If every major decision flows through one signature, the company stops the day that person is unavailable, which is exactly the key person risk most private companies never test.
Rule 6: Treat it as a living system
A delegation of authority written in 2019 and filed in a shared drive is almost as dangerous as none, because people believe controls exist that no longer match reality.
Review the matrix at least once a year, and change it the same day someone joins, is promoted or leaves. Revoking a departed employee's banking token and signing rights on their last day matters more than any annual review. Each quarter, pull a random sample of 20 or 30 transactions and check them against the matrix: was the right person the approver, and was anything split to stay under a limit?
The goal is not to centralize everything. Berkshire Hathaway is famous for the opposite. In his 2010 letter, Warren Buffett wrote that "we delegate almost to the point of abdication." But Berkshire's subsidiaries still send their surplus capital to Omaha, where the largest allocation decisions are made. Delegation works when the boundaries are sharp, which is the same balance I described in choosing between a centralized and a decentralized operating model.
Key Takeaways
- A delegation of authority is a one-page matrix of decision types, roles and limits, not a vague policy paragraph.
- No single person should commit, approve, pay and record the same transaction; where the team is small, compensate with owner review and dual bank approval.
- Set limits by total contract value, reversibility and precedent, not only by job title, and ban splitting invoices to dodge a limit.
- Treat every change of bank details as suspect until verified by a call to a number already on file.
- The owner needs a written limit and a second signature above it, both to prevent override and to keep the company running without them.
- Review the matrix yearly, update it on every hire and exit, and test a sample of transactions each quarter.
Frequently Asked Questions
What is a delegation of authority (DOA) matrix?
A delegation of authority matrix is a governance document that maps each type of business decision to the roles allowed to approve it and the financial limit for each role. It typically covers spending, contracts, hiring, pricing, banking and legal matters. Its purpose is to make approval rules explicit, consistent and auditable.
What should a delegation of authority policy include?
A good policy includes the decision categories, approval limits by role, the second signature required above each limit, and decisions reserved for the owner or board. It should also cover segregation of duties, an anti-splitting rule, how temporary delegations work during absences, and how often the document is reviewed.
What is the 70% rule of delegation?
The 70% rule is a management heuristic: if someone else can do a task at least 70% as well as you can, delegate it. The remaining gap usually closes with experience, and the time you free up is worth more than the difference in quality. It applies to tasks and decisions, not to removing controls over payments.
How can you make it harder for a business email compromise scammer to trick you?
Verify every request to change bank details or send an urgent payment through a second channel, ideally a call to a phone number you already have on file. Require two approvers for new beneficiaries and large transfers inside the banking platform. Train staff that pressure, urgency and requests for secrecy are warning signs.
How often should a delegation of authority be reviewed?
At least once a year, and whenever the organization changes: new hires in approval roles, promotions, departures, acquisitions or new bank accounts. Access and signing rights should be removed on an employee's last day, not at the next scheduled review.
One thing to do this week
Open your bank's online platform and list every person who can release a payment on their own. If any name on that list can also create a new supplier in your accounting system, you have found your Singapore office. Fix that one door before you write anything else.
Explore the eight businesses of Manzanos Enterprises to see how a group founded in 1890 builds companies designed to outlast their founders.
Building or scaling something interesting?
Let’s talk about how we can collaborate.
Talk to our team →最新情報を受け取る
グループの四半期アップデート、新規オープン情報、厳選ストーリー。




