A Delegation of Authority (DoA) is the document that says who can approve what, up to which limit, and at what point a decision must climb higher. It's what lets an organisation move quickly without losing control — every approval has a named owner and a ceiling.
What actually belongs in it
A useful DoA maps each type of decision to the role allowed to make it, banded by size or risk:
- Decision types — spend and purchase orders, contracts, hiring, investments, write-offs, and policy exceptions.
- Thresholds — the amount or risk band at which each role's authority stops and the next one begins.
- Escalation — what must reach senior management, and what must reach the board.
- Dual approval — where two signatures are required, and who they must be.
- Cover — who holds the authority when the usual approver is on leave.
Where it meets Segregation of Duties
A DoA and a segregation-of-duties review have to be read together. If the matrix lets one role both raise a transaction and approve it, you've written a conflict into the framework itself. The moment authority is assigned, the question “can this person now do two things that should stay apart?” has to be asked.
Authority without segregation is just permission to move money alone.
Our free Segregation of Duties analyzer checks exactly that — and the conflict examples guide shows the pairs to watch.
How to build one
Inventory the decisions that need approval, set sensible bands for each, assign the approving role at every band, mark where dual approval or board escalation applies, then publish it with a version and a review date. Keep it living — a DoA that doesn't track reorganisations quietly stops being true.
Build it, guided step by step.
The interactive builder is part of GRC Forge Pro — join now to be first in when it launches.
Get started