Process Risk and Control Series Issue 2: Approval Grading and Authorization — Turning "Who Should Sign" into "Signatures Really Matter"
Abstract: Approval is the most common control measure in processes, but it is also the most easily abused. This article systematically discusses the design principles of approval nodes, the logical framework of graded authorization, and how to avoid "approval fatigue" and "approval performance," helping companies transform approvals from formalism into genuine risk control measures.
1. A Common Dilemma: More Signatures, Same Problems
You have certainly seen such scenarios: a procurement application must be signed by the supervisor, manager, director, and vice president; a drawing change requires the signatures of five departments—design, process, quality, production, and procurement; a business trip reimbursement involves filling out three forms and getting five stamps, with the money only arriving half a month after the trip.
The more approval levels there are, the more exhausting it becomes for those signing, but the same issues still arise—purchases that should not have been made, changes that should have been implemented but were not, and nonconforming products that should have been rejected but were accepted.
This is the "approval paradox" many companies face: the more approval nodes there are, the weaker each individual's sense of responsibility becomes. Everyone thinks, "So many people have already signed off, it should be fine by the time it gets to me, right?"
Approval grading and authorization address not just "who should sign," but "who should sign, what should they sign, and how can their signatures truly matter?"
2. The Essence of Approval: It's Not Review, It's Risk Control
Many managers view approval as a "gatekeeping" function by superiors—superiors are more experienced and can spot issues. This is certainly one use of approval, but if approval relies solely on "superiors knowing more," it means the company is not operating based on processes and standards, but rather on the personal experience and diligence of leaders.
The essence of approval is a decision node for risk control—not "checking again for any issues," but "at this node, has the risk been controlled to an acceptable level? Is a higher decision-making level needed?"
From this perspective, the design of approval nodes needs to answer three questions:
- What risk does this node control? —Is it financial risk, technical risk, compliance risk, or delivery risk?
- Who is best suited to judge this risk? —Is it the person most knowledgeable about the business, or someone with a higher position?
- What input information is needed to make a judgment? —Is there sufficient risk evidence provided?
If these three questions cannot be answered, the approval node is likely a "signature zombie"—it exists in the process but is ineffective in substance.
3. Approval Grading: From "Everyone Signs" to "Only the Right People Sign"
The core logic of approval grading is: matching approval levels to risk levels, rather than signing off at every hierarchical level.
Logical Framework for Three-Level Approval Grading
| Approval Level | Applicable Scope | Approval Subject | Core Concept |
|---|---|---|---|
| Level 1 (Routine Approval) | Amount below threshold, low technical risk, routine operations | Department Manager/Supervisor Level | "Review according to rules" — mainly confirming compliance with preset standards |
| Level 2 (Escalated Approval) | Amount exceeds threshold, involves cross-departmental impact, or process deviation | Department Director/Deputy Leader | "Exception judgment" — professional judgment required beyond standards |
| Level 3 (Strategic Approval) | Major investment, strategic changes, or potential impact on compliance/safety | Company Leadership/Committee | "Decision accountability" — decisions that bear enterprise-level risks |
A Practical Design Method: RACI and Approval Matrix
Combining approval nodes with the RACI model can clearly define each approver's role:
- R (Responsible): Who performs the task
- A (Approver): Who signs off on the result (Note: there should typically be only one A, not multiple A's in parallel)
- C (Consulted): Who provides professional advice (multiple people can be involved, recommended for co-signing)
- I (Informed): Who needs to know the result
The core principle of the approval matrix is: each approval node can only have one A. If both the Financial Director and the Quality Director sign off on an application, who is the true decision-maker? If both sign, it leads to "responsibility dilution"—when an issue arises, they can say, "I didn't think it was my responsibility; I assumed the Quality Director would handle it."
Step Thresholds for Amount Grading
Financial approvals are the most common scenario for grading. A typical amount threshold (for reference, adjust according to company size) is as follows:
| Amount Range | Level 1 Approval | Level 2 Approval | Level 3 Approval |
|---|---|---|---|
| Below 50,000 RMB | Department Manager | — | — |
| 50,000 to 500,000 RMB | Department Manager | Director | — |
| 500,000 to 5,000,000 RMB | Department Manager | Director | General Manager/Presidential Office |
| Above 5,000,000 RMB | Department Manager | Director | Board of Directors |
Thresholds should be set based on the company's annual revenue scale × risk sensitivity rather than simply copying from other companies. The biggest fear in amount grading is "one-size-fits-all"—small companies using large companies' standards, leading to too many approval levels and loss of response speed; large companies using small companies' standards, leading to over-authorization and loss of control.
4. Authorization: Its Premise Is Not Trust, But Control
Authorization is the most misunderstood aspect of approval grading. Many people believe that authorization means "letting subordinates handle it"—based on trust. However, truly effective authorization is not based on trust, but on control capability.
Three Conditions for Effective Authorization
- Clear Standards: Processes are standardized, and operations have clear SOPs, so the executor does not need to make frequent subjective judgments. The clearer the standards, the more boldly you can authorize.
- Measurable Results: The effectiveness of execution can be tracked by data—such as on-time delivery rates for procurement, price compliance rates, and supplier quality standards. The more transparent the data, the more confident you can be in authorizing.
- Exception Escalation Mechanism: When situations arise that fall outside the standard scope, there is a clear escalation path, rather than leaving it to the executor to decide.
Four Levels of Authorization
| Authorization Level | Description | Applicable Scenario |
|---|---|---|
| L1 Information Level | Executor informs the superior after completion | Historical operations, extremely low risk |
| L2 Filing Level | Executor completes the task, and the system automatically sends a copy to the superior | Routine operations, with standard templates |
| L3 Approval Substitution Level | Executor's judgment authority fully covers a specific scenario, no additional approval needed | High-frequency, low-risk, mature standards |
| L4 Budget/Constraint Level | Authority is tied to quantitative constraints (e.g., amount, quantity, cycle), allowing free execution within the constraints | Clear budget or quota control |
A Counterintuitive Point: The More You Authorize, The Stronger Your Control
A common concern among managers is "losing control when authorizing." However, in practice, you will find that: companies without authorization are overwhelmed by approvals, leaving managers no time to make genuine risk assessments.
Companies that do authorization well actually see a reduction in the number of approvals managers need to sign—because they are freed from reviewing a pile of routine operations that are already standardized, allowing them to focus on true exceptions and anomalies.
A medium-sized manufacturing company conducted a statistical analysis: 85% of procurement orders are below 100,000 RMB. If all these were authorized to department managers, the director's approval volume would decrease from 200 per month to 30 per month, and the 30 that require his attention are the largest and highest-risk orders. This is how approvals should work.
5. Approval Efficiency: From "Waiting for Signatures" to "Systematic Acceleration"
Slow approvals are the most common complaint in process management. However, a closer analysis reveals that the root cause is often not the "slowness" of the signatories, but issues in the system design.
Common Efficiency Bottlenecks
| Bottleneck Type | Typical Manifestation | Countermeasure |
|---|---|---|
| Serial Queuing | A signs → B signs → C signs, each step takes 1 day, a week passes | Change to parallel co-signing (technical + business simultaneously) |
| Approval Timeout | Approver is on a business trip, in a meeting, or on leave, causing the process to stall | Set automatic reassignment rules, automatically transfer to deputy after 24 hours |
| Ambiguous Standards | Approver is unsure whether to approve, repeatedly asks for additional materials | Standardize approval forms, mandatory key fields + automatic validation |
| Repeated Approvals | The same risk is repeatedly confirmed by different approvers | Clearly define the focus of each approval node, subsequent nodes do not re-verify the same content |
Three Principles for Efficiency Improvement
- Information Prepositioning Principle: When an approver opens an approval form, they should see all the information needed to make a decision—not "provide more," but already displayed on the form.
- Default Approval Principle: If not processed within the specified time, it is automatically approved (approvers need to actively intercept nonconformities, not passively wait). Suitable for low-risk routine approvals.
- One-Item-One-Approval Principle: Each approval form corresponds to one item. Do not combine "purchase 3 devices + hire 2 people + sign a customer service contract" on the same form—this makes it impossible to judge.
6. Approval Fatigue and Approval Performance: Two Traps to Beware
Approval Fatigue
When someone has to sign hundreds of documents daily, it is impossible for them to carefully review each one. They enter a "reflexive signing" mode—glance, sign, flip the page. This is called approval fatigue, a direct result of too many approval nodes.
The solution is simple and counterintuitive: reduce approval nodes. If a certain approval node has not rejected any application in the past three months, it indicates that the node is not effectively controlling—such nodes can be canceled or downgraded.
Approval Performance
A more hidden issue is approval performance—some approval nodes exist not to control risk but to "prove someone has seen it." For example:
- Stamping "reviewed" without actually reviewing
- Signing off in a rumor mill section to indicate "awareness of the matter"
- Shifting responsibility by pushing decisions that could be made independently to superiors
The essence of approval performance is a problem with the company's responsibility attribution mechanism. When employees believe "signing = taking the blame," they will try to push the signing to others. The solution is not to eliminate approvals, but to align approval responsibility with decision-making authority—the person signing must have the information and capability to make the decision and also bear the consequences of that decision.
7. Conclusion
Approval grading and authorization, on the surface, are subtopics of process management, but they actually reflect the maturity of enterprise management: where standards and systems can manage, there is no need for personal judgment by leaders; where data and results can be tracked, there is no need for multiple signatures to control.
Good approval design is not about "the more signatures, the safer," but about using the fewest approval nodes to cover the most critical risks.
Turning "who should sign" into "signatures really matter" is not about eliminating control, but ensuring that each signature has meaning—this is the true goal of approval grading and authorization.
Knowledge code: 3.4.2
Version: v20260610
Author: Quality Think Tank