Skip to main content
Multi-entity delegated-authority matrix for boards and subsidiary oversight

Multi-entity delegated-authority matrix for boards and subsidiary oversight

How to map who can decide what, where escalation triggers fire, and how decision trails survive across every subsidiary

Most authority problems don't show up as one dramatic failure. They show up as a slow drift — nobody is quite sure who approved a €2.4M capex spend at a subsidiary two countries away, or why a regional GM signed a supplier contract that legally binds the parent, or how a treasury guarantee got issued without hitting anyone's radar until the audit.

By the time a board notices, the answer is usually the same: the delegation of authority existed on paper, but nobody could reconcile it against what actually happened. The matrix said one thing. The bank mandate said another. The subsidiary board minutes said a third. And the parent's own records had no line of sight into any of it.

A multi-entity delegated authority matrix is supposed to prevent this. But in practice, the matrix itself is rarely the failure point. The failure is that the matrix isn't wired into escalation, reporting cadence, signoff gates, or evidence capture. It's a static document sitting in a shared drive while decisions move through fifteen different subsidiaries at their own speed.

This article covers the whole system — how authority, escalation, reporting, and evidence lanes connect, where they break as the group grows, and how to build something that actually holds up when a regulator or an acquirer starts pulling threads.

Why authority drifts in the first place

A single-entity delegation of authority is manageable. You have a board, a CEO, a handful of officers, and a clean chain of who can spend what and sign what. Everyone can more or less hold the whole thing in their head.

Then the group grows. You add a subsidiary for a new market. An acquisition brings in three more entities, each with their own pre-existing authority structures, their own bank relationships, and their own idea of what "board approval" means. A joint venture appears with shared control. A special-purpose vehicle gets stood up for a financing. Now you have twelve, twenty, forty legal entities — each technically a separate governance unit with its own directors and its own local law obligations.

  1. Threshold mismatch — limits set for the parent applied blindly to entities of very different size and risk
  2. No cross-entity aggregation — three separate €1.5M approvals at three subsidiaries fund the same project that would have required board signoff at €4M
  3. Silent local overrides — a local director exercises a statutory power the parent didn't know existed, entirely legally, and the group has no visibility

The last one is the sneaky one. In many jurisdictions, subsidiary directors have personal fiduciary duties to that entity, not to the group. A delegation matrix written from headquarters cannot override local company law. If you don't design for that reality, your matrix is aspirational at best.

What actually breaks at scale

Scale doesn't just add more of the same problem. It changes the nature of the problem. A few things tend to fail simultaneously.

Aggregation blindness. The single most expensive gap. Individual decisions each sit under their approval threshold, but no one is summing them across the group. A fairly typical scenario: a group had a policy requiring group treasury signoff on any commitment over €3M. Over eighteen months, four subsidiaries each signed leasing arrangements between €1.8M and €2.6M with the same equipment vendor — roughly €9M in aggregate exposure to a single counterparty that never triggered a single group-level review. Nobody broke a rule. The rules just weren't designed to see across entities.

Reporting lag. With one entity, the board sees decisions in near real time. With thirty entities on different close calendars, a decision made at a subsidiary in March might not surface in consolidated reporting until the Q2 pack in July. By then it's history, not oversight. The gap between decision made and decision visible to the people accountable for it is where most governance risk actually lives.

Evidence fragmentation. This is the one that turns a manageable problem into a crisis during a regulatory inquiry or M&A due diligence. The approval was made — but the evidence trail is scattered. The email approving it lives in someone's inbox. The board resolution is in a local secretary's files in a different language. The bank instruction is in the treasury system. The contract is in the legal repository. When someone asks "show me the complete decision trail for this transaction," you spend three weeks assembling it and you're never quite sure you found everything.

Signoff theater. As entities multiply, signoff gates degrade into rubber stamps. A group finance director "approving" forty subsidiary budgets in one afternoon isn't reviewing anything. The gate exists, the signature exists, but the control is hollow. Auditors are increasingly good at spotting the difference between a real review and a bulk click-through.

The four layers that make a matrix actually work

A delegated-authority matrix that survives contact with a multi-entity group isn't a spreadsheet. It's four connected layers. The matrix is only the first one.

Layer 1: The authority matrix itself

The core grid — decision type by role by threshold by entity. What makes it work is calibration, not comprehensiveness. Every threshold should map to the entity's actual risk profile and the group's risk tolerance, which connects directly to your broader enterprise risk oversight and the tolerances you've mapped to board agendas. If a decision type could breach a group risk tolerance, its threshold belongs to the board, not a local officer, regardless of the entity.

Layer 2: Escalation triggers

Every authority limit needs a paired escalation rule that fires when the limit is approached, exceeded, or aggregated past a group threshold. This is the layer most matrices lack entirely. The matrix says who can decide; the escalation layer says what happens when something exceeds that authority or crosses a group-level line.

Layer 3: Reporting cadence

The rhythm at which decisions made under delegated authority roll up to committees and the board. Different decision types need different cadences — a treasury guarantee can't wait for a quarterly pack; a routine capex approval can.

Layer 4: Evidence lanes

The predefined path each decision's evidence follows so the trail is complete and reconstructable without a scramble. This is where a disciplined document taxonomy and metadata standard pays off — evidence lanes only work if every artifact is captured in a consistent, searchable structure the moment it's created.

Each layer depends on the one before it. A well-calibrated matrix without escalation triggers is just a reference document. Escalation triggers without a reporting cadence fire into a void. And none of it matters if the evidence trail is scattered across inboxes and local drives that nobody can find eighteen months later.

Process diagram

Here's a simple workflow diagram showing how the four layers feed each other and how decisions flow through escalation into the evidence lane.

A sample delegated-authority matrix

Here's a workable structure. Adjust thresholds to your group's scale — the point is the shape, not the specific numbers.

Decision typeSubsidiary officerSubsidiary boardGroup CFO/CEOParent boardEscalation trigger
Operating expenditureUp to €250kUp to €1MUp to €5MAbove €5MAny single item >€1M or aggregated >€3M to one counterparty
Capital expenditureUp to €100kUp to €2MUp to €10MAbove €10MCross-entity project totaling >€5M
Financial guarantees / letters of creditNoneUp to €500kUp to €5MAbove €5MAny guarantee binding the parent, regardless of size
New banking mandate / signatory changeRecommend onlyApprove localGroup treasury signoffNotifyAny new signatory with >€1M limit
Contracts binding the groupNoneUp to €1MUp to €10MAbove €10MAny contract with change-of-control or cross-default clauses
Related-party transactionsNoneDisclose + approveApproveApprove + discloseAny RPT above €100k, no aggregation floor
Litigation settlementUp to €50kUp to €500kUp to €2MAbove €2MAny settlement with admission of liability
Hiring / severance (senior roles)Standard rolesLocal seniorGroup senior leadershipExecutive committeeAny severance >12 months' pay

Two things about this table matter more than the numbers. First, the escalation trigger column — that's what turns a static grid into a live control. Notice that guarantees binding the parent and related-party transactions have no aggregation floor: they escalate regardless of size, because those categories create disproportionate risk relative to their value.

Second, some rows deliberately say "None" or "Recommend only" at the subsidiary officer level. Certain decisions should never be exercisable locally, no matter how small. New banking mandates and parent-binding guarantees are the classic examples. If a subsidiary officer can quietly change who's authorized to move money, your matrix has a hole regardless of what the thresholds say elsewhere.

Wiring escalation triggers to the reporting cadence

The matrix tells you who decides. The escalation triggers tell you when something needs to jump levels. But those triggers only work if they're connected to a reporting rhythm that gets the right decision in front of the right body fast enough to matter.

  1. Immediate (within 48 hours)

    Anything that hits an escalation trigger. Parent-binding guarantee, aggregated exposure breach, litigation with admitted liability, new banking mandate. These don't wait for a scheduled meeting — they go to the relevant chair or group officer directly.

  2. Monthly

    A delegated-decisions log per entity, rolling up to group. Every decision made under delegated authority that month, with amount, approver, and threshold band. This is where aggregation gets caught — you can only sum exposures if you're collecting them at least monthly.

  3. Quarterly

    Consolidated authority report to the parent board. Trends, threshold breaches, near-misses, any decisions ratified after the fact, and a reconciliation of subsidiary board actions against the group matrix.

  4. Annually

    Full matrix review and recalibration. Thresholds tested against the year's actual decision volume and the group's current risk tolerance. Entities that grew or shrank get their limits adjusted.

The monthly log is the workhorse. It's also the step most groups skip, because it feels like overhead when nothing's going wrong. But aggregation blindness — the €9M single-counterparty exposure that nobody saw — only becomes invisible because there's no monthly rollup summing decisions across entities. The cadence is the control, not a formality on top of it.

Evidence lanes: the part everyone underinvests in

An evidence lane is the predefined route every decision's supporting documents travel so that, at any point, you can reconstruct the complete trail: who decided, on what authority, based on what information, ratified how, and recorded where.

The test is simple. Pick any material decision from eighteen months ago at any subsidiary. Can you produce, in under a day, the complete package — the approval, the authority basis, the supporting analysis, the board or officer signoff, and the downstream execution record? Most groups can't. The pieces exist but they're spread across systems, inboxes, languages, and jurisdictions with no index tying them together.

  1. The authority basis — which line of the matrix this decision was made under
  2. The approval record — signed, dated, by the person with actual authority
  3. The supporting information — what the decision-maker was shown at the time
  4. The ratification — where a subsidiary board or committee formally confirmed it, if required
  5. The execution proof — the contract, bank instruction, or payment that followed

The reason this matters isn't bureaucratic. When a group goes through due diligence for a sale, or a regulator opens an inquiry, or a D&O claim tests whether a decision was properly authorized, the speed and completeness of your evidence trail is what separates a contained situation from a spiraling one. A complete, indexed trail closes questions. A scattered one invites more of them.

Groups that get this right treat evidence capture as part of the decision itself, not a cleanup task afterward. The approval isn't finished until the evidence lane is populated. That discipline is far easier to embed if you've already run a proper governance digitization program that preserves audit trails by design rather than bolting evidence capture on after the fact.

A real scenario

A mid-market industrials group — roughly €400M revenue, seventeen legal entities across five countries — went through a refinancing that triggered a lender's due diligence on the group's control environment.

Before: their delegation of authority was a single PDF, last updated three years earlier, that referenced only the parent and two of the seventeen entities. Subsidiary approvals lived in local systems. When the lender asked for a complete decision trail on four cross-border intercompany loans, it took the finance team about three weeks and pulled in local staff across four countries to assemble it. They found two intercompany guarantees that had been issued at subsidiary level with no group treasury signoff — technically valid under local authority, but outside what the group thought its own policy allowed. That surfaced as a diligence finding and shaved terms off the deal.

After: they rebuilt the matrix to cover all seventeen entities with entity-calibrated thresholds, added escalation triggers with hard aggregation limits, and stood up a monthly delegated-decisions log rolling into a quarterly board report. Every material decision now runs through a defined evidence lane. When the same lender ran a follow-up review the following year, the complete trail for any transaction came back in a day or two, not weeks. The two-guarantee gap couldn't recur, because parent-binding guarantees now escalate regardless of amount and appear in the monthly log automatically.

The point isn't the deal terms. The group had always had rules. What they'd lacked was the wiring between the rules and the reality — escalation, cadence, evidence. Once that wiring existed, the rules finally did what everyone had assumed they were already doing.

Where lightweight tooling earns its place

You can run this on spreadsheets and shared drives, and plenty of groups do. It works until it doesn't — usually somewhere past ten or twelve entities, when the manual rollup of the monthly log becomes a job nobody wants and aggregation breaches slip through because summing that many entities by hand is error-prone.

Pro-tip: commit to the monthly delegated-decisions log discipline before automating; the control value comes from the rollup, not the software.

Past that point, a governance platform that maps entities, roles, thresholds, and escalation rules — and captures the evidence lane at the moment of decision — stops being a nice-to-have. The value isn't automation for its own sake. It's that aggregation gets calculated instead of hoped for, escalation triggers fire without depending on someone remembering to check, and the evidence trail assembles itself as decisions happen rather than during a panicked three-week reconstruction.

When to invest in this — and when not to

This makes sense when:

  1. You have more than a handful of legal entities with real decision-making happening at each
  2. Subsidiaries have their own bank relationships or can bind the group
  3. You've been through, or expect, an acquisition, refinancing, or regulatory review
  4. Cross-entity exposures — single counterparties, shared projects, intercompany arrangements — are material

This is overengineered when:

  1. You have two or three entities and everyone genuinely sees every material decision already
  2. Subsidiaries are dormant or purely holding vehicles with no operational activity
  3. The whole group's decision volume is low enough to hold in one person's head

Who should be careful: groups that just made an acquisition and are tempted to force the target's entities onto the parent's thresholds immediately. The acquired entities came with existing authority structures, local law obligations, and often good reasons their limits differ.

Recalibrate deliberately, don't overwrite. The wrong threshold, confidently enforced, is worse than an honest gap you're actively closing.

Pulling it together

The reason a multi-entity delegated authority matrix fails isn't usually the matrix itself. It's that the matrix sits alone — no escalation triggers to catch what exceeds it, no reporting cadence to surface decisions while there's still time to act, no evidence lanes to reconstruct the trail when someone asks. Authority becomes a document instead of a control.

Build the four layers together and they reinforce each other. The matrix sets the limits. The escalation triggers catch what crosses them, including aggregated exposures that no single approval would flag. The cadence gets decisions in front of accountable people fast enough to matter. The evidence lanes make the whole thing defensible when it's tested — and it will be tested, whether by an auditor, a lender, an acquirer, or a claim.

Start with the matrix you already have, wire in the escalation triggers next, then the monthly rollup, then the evidence discipline. Each layer makes the next one more valuable, and none of them require you to redesign everything at once.

The reason a multi-entity delegated authority matrix fails isn't usually the matrix itself. It's that the matrix sits alone — no escalation triggers to catch what exceeds it, no reporting cadence to surface decisions while there's still time to act, no evidence lanes to reconstruct the trail when someone asks. Authority becomes a document instead of a control.

Build the four layers together and they reinforce each other. The matrix sets the limits. The escalation triggers catch what crosses them, including aggregated exposures that no single approval would flag. The cadence gets decisions in front of accountable people fast enough to matter. The evidence lanes make the whole thing defensible when it's tested — and it will be tested, whether by an auditor, a lender, an acquirer, or a claim.

Start with the matrix you already have, wire in the escalation triggers next, then the monthly rollup, then the evidence discipline. Each layer makes the next one more valuable, and none of them require you to redesign everything at once.

Built for Boards Tailored to governance workflows and compliance needs
Save Time Automate scheduling, document management, and task tracking
Enhance Collaboration Securely share materials and communicate seamlessly
Drive Decisions Facilitate informed, timely board decisions and follow-ups