Insights · Approvals

Delegation of authority matrix for NBFCs: how to build one that holds up in an audit

Every NBFC has a delegation of authority matrix. Ask three people in credit and operations who can approve a ₹3 crore restructuring, or who can change a borrower’s bank account, and you will often get three answers. The document exists. The problem is everything around it.

2 October 20268 min read
Delegation of authority matrix for NBFCs: how to build one that holds up in an audit

What a DoA matrix is for

A delegation of authority (DoA) matrix, also called an approval matrix or schedule of authority, says who can decide what, up to what amount, and when a decision has to go up to a committee or the Board.

It does two jobs. It lets people move fast inside clear limits, and it gives the Board, auditors and the regulator a way to check that every decision was taken by someone who was allowed to take it. Most matrices are written for the first job and quietly fail the second.

What it needs to contain

  • Every decision type, not just credit: sanctions, renewals, covenant waivers, restructuring, disbursement release, write-offs, rate and fee deviations, vendor payments, manual journals, and changes to system access.
  • Amount bands for each decision type, set by your Board-approved policy.
  • For each band, the maker who prepares it, the checker, the final approver and the committee, named by role, never by person.
  • Quorum and voting rules for each committee, and who keeps the minutes.
  • The evidence that must be kept for each decision: credit note, risk rating, site visit, call-back record, committee minutes.
  • A target turnaround, so delays are visible.
  • A version log: what changed, who approved the change, and from when it applies.

The mistakes that show up in audits

  • Credit is covered in detail but operations and finance are not. The most common fraud route, a change to a borrower’s or vendor’s bank details, often has no named approver at all.
  • The matrix names people instead of roles, so it is out of date the day someone leaves.
  • Waivers and restructurings are treated as admin, not as credit decisions. They should go through the same authority as the original sanction.
  • Nothing stops sub-delegation. A head of credit forwards an approval to a deputy whose own limit is lower.
  • Leave cover is informal. The approver is away, someone else clicks approve, and nobody records that they were standing in.
  • Changes to the matrix itself are not approved or logged, so nobody can say which version applied to a decision made last March.

Rate changes, parameters and access are decisions too

It is easy to think of a DoA matrix as a lending document. But changing an interest rate on the rate card, a product parameter, or a user’s permissions in the loan system can do as much damage as a bad sanction.

The RBI’s 2026 cybersecurity and IT directions for NBFCs make this explicit for base layer NBFCs with assets of ₹500 crore and above: there must be clear, documented delegation of authority for changing user profiles and permissions and key business parameters such as interest rates (paragraph 21(3) of the directions). Put these changes in the same matrix as your credit decisions.

Handling leave cover and temporary delegation

Approvers go on leave, and work cannot stop. The answer is not to share passwords or forward approvals by email. It is a recorded temporary delegation: who is covering for whom, from when to when, and up to which limit.

The person covering should never get a higher limit than their own role allows unless the matrix says so. And every decision they take during cover should show that it was taken on behalf of the absent approver.

Keeping it alive

  • Review the matrix at least once a year, and whenever the organisation, product mix or policy changes.
  • Route every change through the same approval as the matrix itself, and record the version.
  • Compare the matrix with what actually happened: pull a sample of last quarter’s approvals and check that each one was taken by someone with the authority.
  • Report breaches. An approval outside authority is a control failure even when the decision itself was right.

From document to enforced rule

A matrix in a spreadsheet tells people the rules. It cannot stop someone from breaking them, and it cannot prove afterwards that nobody did. That only happens when the matrix drives the workflow: each item routes itself to the right approver by type and amount, self-approval is blocked, leave cover is recorded, and every decision carries its own evidence.

Averoic configures delegation of authority as live approval routing, with maker-checker controls and a tamper-evident audit trail, so the matrix and the way work actually flows stay the same thing.

This guide is general information for operations and credit teams, not legal or regulatory advice. Limits must come from your own Board-approved policies. The RBI reference is to the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, which apply by layer and asset size.

DG
· Sales Director, Averoic

Works with alternative lenders, AIFs, NBFCs and insurers in India on approvals, maker-checker controls and audit readiness.

See how your own process would run on Averoic — configured, not coded, with maker-checker controls and a tamper-evident audit trail built in.

Frequently asked questions

What is a delegation of authority matrix in an NBFC?

A document that sets out who can approve each type of decision, up to what amount, and when it must go to a committee or the Board. It covers credit sanctions, waivers and restructurings, and also operational and financial decisions such as disbursement release, payments, rate changes and system access.

Who approves the DoA matrix?

Usually the Board or the authority named in the NBFC’s policies. Any change to the matrix should go through the same approval and be recorded with a version and an effective date.

Should covenant waivers be in the delegation of authority matrix?

Yes. A covenant waiver changes the risk of a loan, so it should go through credit authority at the same level as the original sanction or higher, not be handled as an administrative change.

How should leave cover be handled in a DoA matrix?

Through a recorded temporary delegation that names the person covering, the period and the limit. Decisions taken during cover should be marked as taken on behalf of the absent approver, and the cover should not exceed what the matrix allows.

Is there a free DoA matrix template?

Yes. Averoic’s free Excel template has an approval matrix with 16 sample rows across credit, operations, pricing, finance, fund and access decisions, a committees sheet and a version log. The sample amounts are examples only.

Start building on your process.

Spin up a free workspace in minutes — no card. Or book a 30-minute walkthrough on your real workflow.