Process Risk and Control Series Issue 2: Approval Grading and Authorization — Turning "Who Should Sign" into "Signatures Really Matter"

By: QTank Published: 6/10/2026 Views: 296
Current rating: ★★★☆☆ Rate this Equivalent to 9 ratings (from visitors: 1)

Abstract: Approval is the most common control measure in processes, but it is also the easiest to misuse. This article systematically discusses the design principles of approval points, the logical framework of graded authorization, and how to avoid "approval fatigue" and "approval for show," helping businesses transform approvals from formalities into genuine risk control measures.


1. A Common Dilemma: More Signatures, No Fewer Problems

You have certainly seen scenarios like these: a procurement request must be signed by the supervisor, manager, director, and vice president; a drawing change requires signatures from design, process, quality, production, and procurement departments; a business trip reimbursement involves filling out three forms and getting five seals, with the money arriving only after the trip has been over for half a month.

The more approval levels, the more exhausting it becomes for those who sign, yet the same issues still arise—purchases that should not have been made, changes that should have been implemented but were not, and goods that should have been returned but were accepted.

This is the "approval paradox" many companies face: the more approval points, the weaker each person's sense of responsibility for the approval. Everyone thinks, "So many people have already signed off, it should be fine by the time it gets to me, right?"

Approval grading and authorization address not just "who should sign," but "who should sign, what should they sign, and how can their signatures truly matter".

2. The Essence of Approval: It's Not Review, It's Risk Control

Many managers view approval as a "higher-level check"—the higher-ups are more experienced and can spot issues. This is certainly one purpose of approval, but if approvals rely solely on "higher-ups knowing more," it means the company is not operating based on processes and standards, but rather on the personal experience and diligence of its leaders.

The essence of approval is a decision point for risk control—not "another look to see if there are any issues," but "at this point, has the risk been controlled to an acceptable level? Is a higher decision-making level needed?"

From this perspective, the design of approval points must answer three questions:

  1. What risk is being controlled at this point? — Is it financial risk, technical risk, compliance risk, or delivery risk?
  2. Who is best suited to judge this risk? — Is it the person most knowledgeable about the business, or someone with a higher position?
  3. What input information is needed to make a judgment? — Is there sufficient risk evidence provided?

If these three questions cannot be answered, the approval point is likely a "signature zombie"—present in the process but ineffective in substance.

3. Approval Grading: From "Everyone Signs" to "Only the Right People Sign"

The core logic of approval grading is: matching the approval level to the risk level, rather than signing off at every level based on job titles.

Logical Framework for Three-Level Approval Grading

Approval Level Applicable Scope Approval Authority Core Concept
Level 1 (Routine Approval) Amount below threshold, low technical risk, routine operations Department Manager/Supervisor "Review according to rules" — mainly confirming compliance with preset standards
Level 2 (Escalated Approval) Amount exceeds threshold, involves cross-departmental impact, or process deviation Department Director/Division Leader "Exception judgment" — professional judgment needed beyond standards
Level 3 (Strategic Approval) Major investments, strategic changes, or potential compliance/safety impacts Senior Management/Committee "Decision accountability" — decisions that bear company-level risks

A Practical Design Method: RACI and Approval Matrix

Combining approval points with the RACI model can clearly define the role of each approver:

  • R (Responsible): Who performs the task
  • A (Approver): Who signs off on the result (Note: there is usually only one A, not multiple)
  • C (Consulted): Who provides professional advice (can be multiple, suggested as co-signers)
  • I (Informed): Who needs to know the result

The core principle of the approval matrix is: there can only be one A at each approval point. If both the Financial Director and Quality Director sign off on the same application, who is the true decision-maker? If both sign, it leads to "dilution of responsibility"—when an issue arises, each can say, "I didn't think it was my responsibility; I assumed the Quality Director would check it."

Step Thresholds for Financial Approval Grading

Financial approvals are the most common scenario for grading. A typical financial threshold might look like this (for reference, adjust according to company size):

Amount Range Level 1 Approval Level 2 Approval Level 3 Approval
Below 500,000 RMB Department Manager
500,000 RMB to 5,000,000 RMB Department Manager Director
5,000,000 RMB to 50,000,000 RMB Department Manager Director General Manager/President's Office
Above 50,000,000 RMB Department Manager Director Board of Directors

Threshold setting should be based on the company's annual revenue scale × risk sensitivity, rather than simply copying another company's standards. The biggest fear in financial grading is a "one-size-fits-all" approach—small companies using large company standards can result in too many approval levels and loss of response speed; large companies using small company standards can lead to over-authorization and loss of control.

4. Authorization: Its Premise Is Not Trust, But Control

Authorization is the most misunderstood aspect of approval grading. Many people think authorization means "letting people below you handle it"—based on trust. However, truly effective authorization is based on control capability.

Three Conditions for Effective Authorization

  1. Clear Standards: Processes are standardized, and operations have clear SOPs, reducing the need for frequent subjective judgments. The clearer the standards, the more boldly you can authorize.
  2. Measurable Results: The outcomes of execution can be tracked with data—such as on-time delivery rates for purchases, price compliance rates, and supplier quality access. The more transparent the data, the more confidently you can authorize.
  3. Exception Escalation Mechanism: When situations arise that fall outside the standard, there is a clear escalation path, rather than leaving the decision to the executor.

Four Levels of Authorization

Authorization Level Description Applicable Scenario
L1 Notification Level Executor informs the superior after completion Historical operations, extremely low risk
L2 Record Level Executor completes the task, and the system automatically notifies the superior Routine operations, with standard templates
L3 Approval Substitution Level Executor has full authority to make decisions in a specific scenario, without additional approval High-frequency, low-risk, mature standards
L4 Budget/Constraint Level Authority is tied to quantifiable constraints (e.g., amount, quantity, cycle), allowing free execution within these constraints Clear budget or quota control

Counterintuitive Point: The More You Authorize, The Stronger Your Control

A common concern among managers is "losing control after authorization." However, in practice, you will find that: companies without authorization are overwhelmed by approvals, leaving managers no time for genuine risk assessment.

In companies with good authorization practices, the number of approvals that managers need to sign actually decreases—because they are freed from reviewing a pile of routine operations that are already well-regulated by standards, allowing them to focus on true exceptions and anomalies.

A medium-sized manufacturing company found that 85% of procurement orders were below 100,000 RMB. If these were all authorized to department managers, the director's approval volume would drop from 200 per month to 30, and the 30 that require his attention would be the largest and highest-risk orders. This is what approval should look like.

5. Approval Efficiency: From "Waiting for Signatures" to "Systematic Speed-Up"

Slow approvals are the most common complaint in process management. However, a closer analysis often reveals that the root cause is not that the signers are "slow," but rather issues with the system design.

Common Efficiency Bottlenecks

Bottleneck Type Typical Manifestation Countermeasure
Serial Queuing A signs → B signs → C signs, each step taking 1 day, a week goes by Change to parallel co-signing (technical + commercial simultaneously)
Approval Timeout Approver is on a business trip, in a meeting, or on leave, causing the process to stall Set automatic reassignment rules, automatically transfer to deputy after 24 hours
Ambiguous Standards Approver is unsure whether to approve, repeatedly asking for additional materials Standardize approval forms, mandatory key fields + automatic validation
Repeated Approvals The same risk is repeatedly confirmed by different approvers Clearly define the focus of each approval point, subsequent approvers do not review the same content again

Three Principles for Efficiency Improvement

  1. Information Precedence Principle: When an approver opens an approval form, they should see all the information needed to make a decision—not "provide this again," but already displayed on the form.
  2. Default Approval Principle: If not processed within the specified time, it is automatically approved (approvers need to actively intercept nonconformities, not passively wait). Suitable for low-risk routine approvals.
  3. One Matter, One Approval Principle: Each approval form should correspond to one matter. Do not combine "purchase 3 machines + hire 2 people + sign a customer service contract" on the same form—this makes it impossible to judge.

6. Approval Fatigue and Approval for Show: Two Traps to Beware

Approval Fatigue

When someone has to sign hundreds of documents daily, they cannot carefully review each one. They will enter a "reflexive signing" mode—glance, sign, flip. This is called approval fatigue, a direct result of having too many approval points.

The solution is simple and counterintuitive: reduce approval points. If an approval point has not rejected any application in the past three months, it indicates that the point is not effectively controlling risks and can be canceled or downgraded.

Approval for Show

A more hidden issue is approval for show—some approval points exist not to control risks but to "prove someone has reviewed it." For example:

  • Stamping "reviewed" without actually reviewing
  • Signing off in a rumor-mongering section to indicate "aware of the matter"
  • Shifting responsibility by pushing decisions that could be made independently to higher-ups

The essence of approval for show is a problem with the company's responsibility assignment mechanism. When employees believe "signing = taking the blame," they will try to push the signature to someone else. The solution is not to eliminate approvals but to align approval responsibility with decision-making authority—the person signing must have the information and capability to make the decision and also bear the consequences of that decision.

7. Conclusion

Approval grading and authorization, on the surface, are a sub-topic of process management, but they actually reflect the maturity of company management: where standards and systems can manage, there is no need for personal judgment from leaders; where data and results can be tracked, there is no need for multiple signatures to control.

Good approval design is not about "the more signatures, the safer," but using the fewest approval points to cover the most critical risks.

Turning "who should sign" into "signatures really matter" is not about eliminating control, but ensuring that every signature has meaning—this is the true goal of approval grading and authorization.

Knowledge Number: 3.4.2

Version: v20260610

Author: Quality Excellence Think Tank