How do I build an approval matrix / delegation of authority for AP?
An approval matrix sets dollar-amount thresholds that determine who has to approve an invoice before it's paid — a manager for small amounts, a director or CFO as the amount rises. It's a control activity under COSO's framework, distinct from segregation of duties: the matrix decides who approves, SoD decides why the approver can't also be the one releasing payment.
Part of the accounts payable and invoice processing guide.
| What an approval matrix does | Maps dollar-amount thresholds to required approver levels before an invoice can be paid |
|---|---|
| Where it fits in COSO | A control activity — one of COSO's five internal control components |
| Not the same as segregation of duties | SoD governs who can approve vs. who can release payment; the matrix governs how much authority each level has |
| Typical structure | Multiple tiers by dollar amount, each requiring a higher level of authority as the amount increases |
| What breaks it | A single amount split into multiple smaller invoices specifically to stay under a threshold |
Why this is a different control from segregation of duties
Segregation of duties answers who's allowed to touch a payment at each stage, and why the same person can't approve an invoice and also release its payment. An approval matrix — delegation of authority — answers a different question: given that some person is going to approve this invoice, how much authority do they actually have, and does this invoice's dollar amount exceed it? A well-designed AP process needs both: SoD prevents one person controlling an entire payment end to end, and the matrix prevents any single approver, however trusted, from having unlimited authority regardless of amount.
Why this is a control activity, specifically
COSO's Internal Control–Integrated Framework names control activities as one of its five components — the policies and procedures that help ensure management's directives are carried out. A dollar-threshold approval matrix is a textbook control activity: it's a specific, checkable rule (does this invoice's amount exceed this approver's authorized limit?) rather than a general principle, which is exactly the kind of concrete mechanism the framework is describing when it talks about control activities operating at all levels of an organization.
How to set the actual thresholds
There's no universal dollar figure that's correct for every company — the right thresholds depend on the organization's size, its risk tolerance, and how much friction is acceptable at each level. What matters structurally is that the tiers actually escalate meaningfully (a jump from a $5,000 manager limit straight to a $500,000 CFO limit leaves a huge range effectively under-scrutinized) and that every tier maps to someone with real authority to say no, not just a rubber-stamp step that exists to satisfy the policy on paper.
Why invoice-splitting is the specific failure mode to watch for
A threshold-based matrix has one predictable failure mode: splitting a single purchase into multiple invoices, each individually under the threshold that would otherwise require higher approval. A $60,000 purchase split into three $20,000 invoices, each requiring only manager-level approval, defeats the matrix's purpose entirely even though every individual invoice technically complied with the rule. Detecting this needs a check that isn't purely per-invoice — looking for multiple invoices from the same vendor within a short window that together exceed a threshold none of them individually crossed.
Next step
Map the finance workflow with the most exposure and prove the automation path.
Bring the invoice, contract, payment reconciliation, or customer finance workflow you have to defend at audit. Loopfour can map the trigger, controls, integrations, and approval loop.
Checklist
A 4-tier threshold matrix applied to one borderline invoice
| Tier | Invoice amount | Required approver |
|---|---|---|
| 1 | Up to $2,500 | Department manager |
| 2 | $2,500.01 – $25,000 | Department director |
| 3 | $25,000.01 – $100,000 | VP of Finance |
| 4 | Over $100,000 | CFO |
A $24,800 invoice routes to the department director under Tier 2 — a straightforward case. Two days later, a second invoice for $19,000 arrives from the same vendor, also individually within Tier 2. Evaluated invoice by invoice, both comply with the matrix. Evaluated together — $43,800 from the same vendor within a 48-hour window — they exceed Tier 2's $25,000 ceiling and should have escalated to Tier 3's VP-of-Finance approval. This is exactly the split-invoice pattern the matrix's design has to account for: a same-vendor, short-window aggregation check catches what a purely per-invoice check misses.
Frequently Asked Questions
Sources
Related
Topic
AP & Invoice Processing
Accounts payable and invoice processing is the set of steps a vendor bill goes through between arriving at a company and turning into a payment: capturing what the vendor sent, checking it against wha…
Read moreDiagnostic
Why should the person approving a vendor payment never be the one who releases it?
One person controlling both approval and release removes the second set of eyes segregation of duties exists to provide — GAO's Green Book names segregation of duties as a core internal-control activity precisely so no single individual can both authorize and complete a transaction. In AP specifically, the FBI names it directly as a fraud defense: separate vendor setup from payment release.
Read moreHow-to
How do I maintain segregation of duties in an automated AP approval workflow?
Keep three roles distinct in the workflow itself: who can create or edit a vendor record, who can enter or submit a bill, and who can approve it for payment. Institutional guidance is explicit that authorizing a payment and the person who executes it shouldn't be the same individual — automation makes it easy to collapse these into one click, which is exactly the risk to design against.
Read moreDiagnostic
How do I automate invoice GL coding in AP?
GL coding happens at the invoice line-item level, each line pointing to a specific GL account. Automating it means deriving that account from a default mapping — a vendor's typical category, an item's linked expense account — instead of a human picking it per line, and routing anything that doesn't match a confident default to manual review rather than guessing.
Read more