Delegation of Authority Matrix Validator
Regime

COBIT 2019: what it asks of an approval matrix

The COBIT practices that name levels of authority and transaction limits outright, segregate origination from approval, and reduce reliance on a single person.

Quoted for every matrix.

Approval families anchored here

40
FamilyClause
Purchase ordersCOBIT DSS06.03
Invoices with no purchase orderCOBIT DSS06.03
Capital expenditureCOBIT DSS06.03
Leases and rental commitmentsCOBIT DSS06.03
Spend over budget and budget transfersCOBIT DSS06.03
Payment run releaseCOBIT DSS06.02 · COBIT DSS06.03
Urgent and manual paymentsCOBIT DSS06.02 · COBIT DSS06.03
Bank account opening and changesCOBIT DSS06.02 · COBIT DSS06.03
Vendor master data changeCOBIT DSS06.02 · COBIT APO10.03
Employee expense claimsCOBIT DSS06.02 · COBIT DSS06.03
Payroll releaseCOBIT DSS06.02 · COBIT DSS06.03
Customer and sales contractsCOBIT DSS06.03
Supplier contractsCOBIT DSS06.03 · COBIT APO10.03
Contracts signed for the companyCOBIT DSS06.03
Confidentiality agreementsCOBIT DSS06.03
Guarantees, indemnities and letters of creditCOBIT DSS06.03
Journal entriesCOBIT DSS06.02
Accruals and prepaymentsCOBIT DSS06.02
Provisions and reservesCOBIT DSS06.02
Write-offsCOBIT DSS06.02
Reconciliation sign-offCOBIT DSS06.02
FX, hedging and treasury dealsCOBIT DSS06.02
Price and price list changesCOBIT DSS06.02
Discounts and rebatesCOBIT DSS06.02
Credit notesCOBIT DSS06.02
Customer refundsCOBIT DSS06.02
Customer credit limitsCOBIT DSS06.02
New hires and headcountCOBIT APO01.05
Pay changesCOBIT APO01.05
Terminations and severanceCOBIT APO01.05
Bonuses and incentivesCOBIT APO01.05
Privileged system access grantsCOBIT DSS05.04
User access review sign-offCOBIT DSS05.04
Changes to production systemsCOBIT BAI06.01 · COBIT BAI06.02
Changes to approval workflows and limits in the systemCOBIT BAI06.01 · COBIT DSS06.03
Acquisitions, disposals and borrowingCOBIT APO01.05
Related-party transactionsCOBIT APO01.05
Donations, sponsorships, gifts and hospitalityCOBIT APO01.05
Litigation and claim settlementsCOBIT APO01.05
Changes to the delegation of authorityCOBIT APO01.05

COBIT 2019: every clause cited, quoted

9 of the 231 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

COBIT APO01.05 Establish roles and responsibilities

Roles and responsibilities for enterprise I&T are defined and communicated, including authority levels, responsibilities and accountability: I&T-related roles and responsibilities for all personnel are established, agreed and communicated in line with business needs, with responsibilities and accountabilities clearly delineated, especially for decision making and approvals; continuity requirements including staff backup and cross-training shape the roles; up-to-date contact information and role descriptions feed the service continuity process; role descriptions require adherence to management policies and procedures, the code of ethics and professional practice; accountability is defined through the roles; roles are structured so that no single role can compromise a critical process; and supervisory practices confirm that roles are properly exercised, that everyone has the authority and resources to perform them and that performance is reviewed.

What an auditor asks to see: Role descriptions with authority, accountability, policy adherence and segregation of duties; Supervisory review records
Where matrices usually fall short: Approval authority exercised by people whose role description does not grant it; One role able to initiate, approve and execute a critical process
Source: COBIT 2019
COBIT APO07.02 Identify key IT personnel

Key IT personnel are identified and reliance on any single individual performing a critical job function is minimised through knowledge capture, knowledge sharing, succession planning and staff backup: guidelines set a minimum annual vacation for key individuals as a security precaution, appropriate actions are taken on job changes and especially terminations, documentation, knowledge sharing, succession planning, backup, cross-training and job rotation reduce single-person dependence, and staff backup plans are tested regularly.

What an auditor asks to see: Key personnel list with succession and backup arrangements; minimum-vacation guideline; backup plan tests
Where matrices usually fall short: Critical function that only one person can perform; Backup named but never tested
Source: COBIT 2019
COBIT APO10.03 Manage vendor relationships and contracts

The supplier relationship is formalised and managed for each supplier, contracts and service delivery are managed, maintained and monitored, and new or changed contracts conform to enterprise standards and legal and regulatory requirements: relationship owners are assigned and accountable for service quality; a formal communication and review process sets interactions and schedules; formal contracts are agreed, managed, maintained and renewed in conformance with standards and law; contracts with key service vendors provide for review of the vendor's site, practices and controls by management or independent third parties, with independent audit and assurance agreed; disputes are handled through established procedures after relationship and communication have been tried; roles and responsibilities are formalised per vendor, with a lead contractor role considered where several vendors combine to deliver a service; and the relationship's effectiveness is evaluated with improvements defined, communicated and agreed.

What an auditor asks to see: Assigned relationship owners; contract register with audit and review rights; relationship review records
Where matrices usually fall short: Key vendor contract with no right to audit; Multi-vendor service with no lead accountable for the whole
Source: COBIT 2019
COBIT BAI06.01 Evaluate, prioritize and authorize change requests

All requests for change are evaluated to determine their impact on business processes and I&T services and to assess whether the change will adversely affect the operational environment and introduce unacceptable risk, and changes are logged, prioritised, categorised, assessed, authorised, planned and scheduled: formal change requests let process owners and IT request changes to processes, infrastructure, systems or applications, with all changes arising only through the change management process and pre-screened for standard changes; requests are categorised (business process, infrastructure, operating systems, networks, applications, packaged software) and related to affected configuration items; they are prioritised on business and technical requirements, resources and legal, regulatory and contractual reasons; each change is formally approved by process owners, service managers and IT technical stakeholders as appropriate, with low-risk frequent changes pre-approved as standard; approved changes are planned and scheduled; every request is evaluated in a structured way with impact analysis on processes, infrastructure, systems, applications, continuity plans and service providers so that all affected components are identified; and the effect of contracted providers on change management is considered, including integration of their processes into the enterprise's.

What an auditor asks to see: Change log with categorisation, prioritisation, impact analysis and approvals; standard change catalogue
Where matrices usually fall short: Changes made outside the process by administrators with direct access; Impact analysis that ignores the continuity plan and outsourced components
Source: COBIT 2019
COBIT BAI06.02 Manage emergency changes

Emergency changes are carefully managed to minimise further incidents, controlled and made securely, and assessed and authorised appropriately after the change: what constitutes an emergency change is defined; a documented procedure declares, assesses, preliminarily approves, authorises after the change and records emergency changes; all emergency access arrangements for changes are appropriately authorised, documented and revoked after the change is applied; and all emergency changes are monitored with post-implementation reviews involving all concerned parties, considering root causes such as problems with business processes, application development, infrastructure, testing or the environment and initiating corrective action.

What an auditor asks to see: Emergency change definition and procedure; records of post-change authorisation, revoked emergency access and post-implementation reviews
Where matrices usually fall short: Emergency access left in place after the change; Emergencies used as a route around normal change approval
Source: COBIT 2019
COBIT DSS05.04 Manage user identity and logical access

All users have information access rights in accordance with business requirements, coordinated with business units that manage their own access rights within processes: access rights follow business function, process requirements and security policy, with identity and access management aligned to defined roles and responsibilities and the principles of least privilege, need to know and need to have; all changes to access rights (creation, modification, deletion) are administered promptly on approved and documented transactions authorised by designated management; privileged accounts are segregated, reduced to the minimum necessary and actively managed with all their activity monitored; all information processing activities are uniquely identified by functional role with roles consistently defined across business units including those defined by the business within applications; all access is authenticated on the individual's role or business rules; all users, internal, external and temporary, and their activity on applications, infrastructure, operations, development and maintenance are uniquely identifiable; an audit trail of access is kept according to sensitivity and regulation; and management regularly reviews all accounts and privileges.

What an auditor asks to see: Access request and approval records; privileged account inventory with monitoring; periodic account and privilege reviews; access audit trails
Where matrices usually fall short: Shared administrator accounts; Leavers' accounts still active weeks later; Access reviews signed without the reviewer checking
Source: COBIT 2019
COBIT DSS06.02 Control the processing of information

The execution of business process activities and related controls is operated on enterprise risk so that information processing is valid, complete, accurate, timely and secure, reflecting legitimate and authorised business use: the originator of transactions is authenticated and their authority verified; duties are segregated between origination and approval; transactions are verified as accurate, complete and valid through controls such as sequence, limit, range, validity, reasonableness, table look-ups, existence, key verification, check digit, completeness, duplicate and logical relationship checks and time edits, with validation rules and criteria reviewed periodically; erroneously input data are corrected and resubmitted without compromising original authorisation levels, retaining original source documents for reconstruction; data integrity and validity are maintained through the processing cycle with erroneous transactions not disrupting valid ones; output is handled in an authorised manner, delivered to the right recipient, protected in transmission and verified for accuracy and completeness; data integrity is maintained through unexpected interruptions and confirmed after failures; and transaction data passed between applications and functions inside or outside the enterprise are checked for proper addressing, authenticity of origin and integrity of content, with authentication and integrity protection in transit.

What an auditor asks to see: Input validation and authorisation controls; segregation of duties matrices; output distribution controls; interface integrity checks; error correction records
Where matrices usually fall short: One person able to originate and approve a payment; Interface files accepted without checking origin or integrity
Source: COBIT 2019
COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority

Business roles, responsibilities, levels of authority and segregation of duties supporting the process objectives are managed, and access to all information assets related to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; levels of authority for approving transactions, transaction limits and other decisions follow approved job roles; sensitive activities are allocated so that duties are clearly segregated; access rights and privileges are the minimum needed for predefined job roles, removed or revised immediately on role change or termination; regular awareness and training cover roles, responsibilities, the importance of controls and the security, integrity, confidentiality and privacy of information; administrative privileges are secured, tracked and controlled to prevent misuse; and access control definitions, logs and exception reports are periodically reviewed so that privileges remain valid and aligned with current staff and roles.

What an auditor asks to see: Authority and limit matrices; segregation of duties allocations; access aligned to roles with prompt removal; privilege reviews and exception reports
Where matrices usually fall short: Transaction limits not enforced in the system; Access accumulated across role changes
Source: COBIT 2019
COBIT MEA02.01 Monitor internal controls

The I&T control environment and control framework are continuously monitored, benchmarked and improved to meet organisational objectives: the boundaries of the internal control system are identified, including how controls cover outsourced and offshore development or production; the status of external service providers' internal controls is assessed and their compliance with legal, regulatory and contractual obligations confirmed; monitoring and evaluation follow organisational governance standards and industry-accepted frameworks and practices, including monitoring of controls' performance and the control environment; control exceptions are promptly reported, followed up and analysed, with corrective actions prioritised and implemented according to the risk profile and recurring exceptions raised for management attention; independent evaluations by internal audit or peers are considered; the control system is maintained against ongoing change in business and I&T risk, the control environment and processes, with gaps evaluated and recommended for improvement; and the control framework's performance is regularly evaluated against industry standards and good practice with a continuous improvement approach considered.

What an auditor asks to see: Defined control system boundaries including outsourced activities; provider control assessments; exception reports with prioritised corrective actions; independent evaluations
Where matrices usually fall short: Outsourced processing outside the boundary of the control system; Same exception recurring without escalation
Source: COBIT 2019