Skip to main content

How do I build an approval matrix / delegation of authority for AP?

An approval matrix sets dollar-amount thresholds that determine who has to approve an invoice before it's paid — a manager for small amounts, a director or CFO as the amount rises. It's a control activity under COSO's framework, distinct from segregation of duties: the matrix decides who approves, SoD decides why the approver can't also be the one releasing payment.

Zuny FesterBy Zuny Fester, Head of Operations and Marketing
Reviewed by Zuny Fester
Published Last reviewed Editorial policy

Part of the accounts payable and invoice processing guide.

What an approval matrix doesMaps dollar-amount thresholds to required approver levels before an invoice can be paid
Where it fits in COSOA control activity — one of COSO's five internal control components
Not the same as segregation of dutiesSoD governs who can approve vs. who can release payment; the matrix governs how much authority each level has
Typical structureMultiple tiers by dollar amount, each requiring a higher level of authority as the amount increases
What breaks itA single amount split into multiple smaller invoices specifically to stay under a threshold

Why this is a different control from segregation of duties

Segregation of duties answers who's allowed to touch a payment at each stage, and why the same person can't approve an invoice and also release its payment. An approval matrix — delegation of authority — answers a different question: given that some person is going to approve this invoice, how much authority do they actually have, and does this invoice's dollar amount exceed it? A well-designed AP process needs both: SoD prevents one person controlling an entire payment end to end, and the matrix prevents any single approver, however trusted, from having unlimited authority regardless of amount.

Why this is a control activity, specifically

COSO's Internal Control–Integrated Framework names control activities as one of its five components — the policies and procedures that help ensure management's directives are carried out. A dollar-threshold approval matrix is a textbook control activity: it's a specific, checkable rule (does this invoice's amount exceed this approver's authorized limit?) rather than a general principle, which is exactly the kind of concrete mechanism the framework is describing when it talks about control activities operating at all levels of an organization.

How to set the actual thresholds

There's no universal dollar figure that's correct for every company — the right thresholds depend on the organization's size, its risk tolerance, and how much friction is acceptable at each level. What matters structurally is that the tiers actually escalate meaningfully (a jump from a $5,000 manager limit straight to a $500,000 CFO limit leaves a huge range effectively under-scrutinized) and that every tier maps to someone with real authority to say no, not just a rubber-stamp step that exists to satisfy the policy on paper.

Why invoice-splitting is the specific failure mode to watch for

A threshold-based matrix has one predictable failure mode: splitting a single purchase into multiple invoices, each individually under the threshold that would otherwise require higher approval. A $60,000 purchase split into three $20,000 invoices, each requiring only manager-level approval, defeats the matrix's purpose entirely even though every individual invoice technically complied with the rule. Detecting this needs a check that isn't purely per-invoice — looking for multiple invoices from the same vendor within a short window that together exceed a threshold none of them individually crossed.

Next step

Map the finance workflow with the most exposure and prove the automation path.

Bring the invoice, contract, payment reconciliation, or customer finance workflow you have to defend at audit. Loopfour can map the trigger, controls, integrations, and approval loop.

Book a workflow review

Checklist

A 4-tier threshold matrix applied to one borderline invoice

TierInvoice amountRequired approver
1Up to $2,500Department manager
2$2,500.01 – $25,000Department director
3$25,000.01 – $100,000VP of Finance
4Over $100,000CFO

A $24,800 invoice routes to the department director under Tier 2 — a straightforward case. Two days later, a second invoice for $19,000 arrives from the same vendor, also individually within Tier 2. Evaluated invoice by invoice, both comply with the matrix. Evaluated together — $43,800 from the same vendor within a 48-hour window — they exceed Tier 2's $25,000 ceiling and should have escalated to Tier 3's VP-of-Finance approval. This is exactly the split-invoice pattern the matrix's design has to account for: a same-vendor, short-window aggregation check catches what a purely per-invoice check misses.

Frequently Asked Questions

It's not legally mandated outside of specific regulatory contexts, but any company past a small handful of approvers benefits from writing it down — an unwritten, informally-understood matrix tends to erode under pressure (a large purchase quietly approved by whoever's available) in exactly the way a documented one is designed to prevent.

The dollar-amount logic still applies, but a recurring payment that's already been approved once (a signed contract, a standing subscription) is a different risk than a brand-new, unreviewed invoice — many matrices route recurring, pre-approved amounts through a lighter check than a first-time or unusually large invoice from the same vendor.

A PO-matched invoice within the PO's approved amount is generally treated as already having cleared the relevant approval, since the spending decision was made at PO issuance — the matrix matters most for invoices with no PO, or for amounts that exceed what the PO originally approved.

Sources

Related

Topic

AP & Invoice Processing

Accounts payable and invoice processing is the set of steps a vendor bill goes through between arriving at a company and turning into a payment: capturing what the vendor sent, checking it against wha…

Read more

Diagnostic

Why should the person approving a vendor payment never be the one who releases it?

One person controlling both approval and release removes the second set of eyes segregation of duties exists to provide — GAO's Green Book names segregation of duties as a core internal-control activity precisely so no single individual can both authorize and complete a transaction. In AP specifically, the FBI names it directly as a fraud defense: separate vendor setup from payment release.

Read more

How-to

How do I maintain segregation of duties in an automated AP approval workflow?

Keep three roles distinct in the workflow itself: who can create or edit a vendor record, who can enter or submit a bill, and who can approve it for payment. Institutional guidance is explicit that authorizing a payment and the person who executes it shouldn't be the same individual — automation makes it easy to collapse these into one click, which is exactly the risk to design against.

Read more

Diagnostic

How do I automate invoice GL coding in AP?

GL coding happens at the invoice line-item level, each line pointing to a specific GL account. Automating it means deriving that account from a default mapping — a vendor's typical category, an item's linked expense account — instead of a human picking it per line, and routing anything that doesn't match a confident default to manual review rather than guessing.

Read more