The Enterprise Roles, Delegation of Powers & Operational Policies Handbook
A definitive operational handbook for Promoters, Board Directors, CFOs, and General Counsel: architecting the 4-tier operational hierarchy, operationalizing the IIA Three Lines Model (2020), engineering 5-tier Delegation of Financial Powers (DoFP) matrices, deploying ICFR Risk and Control Matrices (RCM), and codifying unbreachable Whistleblower, P2P 3-Way Match, and Section 128(5) document retention schedules.
Executive Blueprint: The Fiduciary & Operational Paradox
As commercial enterprises scale from founder-managed startups and family firms to institutional and publicly listed entities, operational risks rapidly outpace manual founder oversight. Failure to codify a formal Delegation of Financial Powers (DoFP) or establish independent 2nd and 3rd Line controllership exposes directors to personal criminal liability under Section 2(60) “Officer in Default” mandates and creates financial fraud vulnerabilities.
1. The 4 Operational Levels & The IIA Three Lines Model (2020)
An efficient institution establishes a structural hierarchy where strategic oversight is decoupled from routine transaction processing. Under the global Institute of Internal Auditors (IIA) Three Lines Model:
- Level 1 (Governance & Board Oversight): The Board of Directors, Audit Committee (§ 177), Nomination & Remuneration Committee (§ 178), and CSR Committee (§ 135). Accountable to shareholders for enterprise risk management, ethical tone at the top, and statutory disclosures.
- Level 2 (Executive Management & KMPs): The Chief Executive Officer (CEO), Chief Financial Officer (CFO), and Company Secretary (CS) under Section 203. Responsible for strategy execution, financial statement integrity u/s 134(1), and establishing the enterprise control environment.
- Level 3 (Functional Controllership & 2nd Line): Financial Controller, Chief Information Security Officer (CISO), Legal Counsel, and Quality Heads. Formulate operational policies, monitor control adherence, and challenge the 1st line.
- Level 4 (Frontline Execution & 1st Line): Operations managers, accounts payable clerks, storekeepers, and payroll administrators executing Maker-Checker segregation and physical custody.
- The 3rd Line (Independent Internal Audit): Mandated under Section 138 of the Companies Act, reporting functionally to the Audit Committee with zero operational responsibilities.
2. Engineering an Unbreachable Delegation of Financial Powers (DoFP)
A Delegation of Financial Powers (DoFP) matrix is the operational backbone of financial controllership. Without codified monetary limits, employees either incur unauthorized commitments or funnel trivial purchase requisitions to C-suite desks, paralyzing business velocity.
An institutional DoFP framework segregates financial authority across five standardized tiers:
| DoFP Tier | Operational Authority | Budgeted Capex / Opex | Banking & Contracts |
|---|---|---|---|
| Tier 1 | Plant / Project Manager | ≤ ₹1 Lakh | Requisition initiator only (Zero payment release) |
| Tier 2 | Functional Head / VP | ₹1L – ₹10 Lakhs | PO verification; Checker role |
| Tier 3 | CFO / COO | ₹10L – ₹50 Lakhs | Dual bank signatory (Category B) |
| Tier 4 | Managing Director / CEO | ₹50L – ₹2 Crores | Category A signatory; Strategic contracts |
| Tier 5 | Board of Directors (§ 179) | > ₹2 Cr / Unbudgeted | Formal Board Resolution required |
3. Internal Financial Controls (ICFR): The Risk & Control Matrix (RCM)
Under Section 134(5)(e) and Section 143(3)(i) of the Companies Act, 2013, companies and statutory auditors must evaluate Internal Financial Controls over Financial Reporting (ICFR). The foundational deliverable of ICFR is the Risk and Control Matrix (RCM) mapped across core financial cycles:
- Procure-to-Pay (P2P): Automated 3-Way Matching of Purchase Order, Goods Receipt Note (GRN), and Vendor Tax Invoice. Validating active GSTIN status and enforcing Section 43B(h) MSME payment windows (15/45 days) to prevent tax disallowances.
- Order-to-Cash (O2C): Formal customer credit checks, automated dunning schedules (30/60/90 days), and Ind AS 109 Expected Credit Loss (ECL) provisioning.
- Treasury & Cash: Adhering to RBI Current Account Opening exposure thresholds, Maker-Checker authorization for all bank transfers, and monthly Bank Reconciliation Statements (BRS) reviewed by an independent officer.
- Fixed Assets & Depreciation: Component accounting under Ind AS 16, useful lives under Schedule II of Companies Act, and 3-year physical asset verification cycles complying with CARO 2020 Clause i(a).
4. Whistleblower, ABAC & Document Retention Governance
An enterprise policy compendium protects the corporate body from systemic misconduct and regulatory sanctions:
- Whistleblower & Vigil Mechanism (§ 177(9)): Mandatory for listed entities and qualifying public companies. Provides a confidential channel for reporting fraud or ethical breaches with direct access to the Audit Committee Chairman and absolute protection against victimization.
- Anti-Bribery & Anti-Corruption (ABAC): Section 9 of the Prevention of Corruption Act, 1988 imposes corporate criminal liability for bribery committed by associated persons. Maintaining an adequate ABAC policy serves as a statutory defense.
- Document Retention (§ 128(5)): Mandatory 8-year statutory retention for books of accounts, vouchers, invoices, and tax filings. Permanent retention is required for corporate charters, board meeting minutes, and title deeds.
Evaluate Your Enterprise Governance & DoFP Tiers
Screen statutory board committees, generate customized 5-tier DoFP limits, and test policy readiness.
Design Your Institutional Governance & Policy Architecture
Consult with Senior Practice Partners to structure ICFR Risk Control Matrices, calibrate Delegation of Financial Powers (DoFP), and draft statutory corporate policies compliant with Companies Act 2013 and SEBI LODR.