Payment authorization is the approval that permits a payment instruction to proceed. A business may require one approver or several, depending on amount, Recipient, currency, business unit or risk. Authorization is an internal control milestone, not evidence that the Recipient has been paid.
Common authorization controls
- Role-based permission to prepare or approve payments
- Approval limits by user or transaction amount
- Two-step verification for sensitive actions
- Supporting invoice or purchase-order review
- Additional approval for new or changed Bank details
| Role | Responsibility | Control purpose |
|---|---|---|
| Maker | Prepares instruction and supporting record | Keeps data entry separate from final approval |
| Checker | Reviews and authorizes | Provides independent review |
| Administrator | Sets roles and limits | Separates policy setup from transaction execution |
Approval should fail closed
A payment should be held when the invoice cannot be matched, Recipient details changed without independent confirmation, the currency differs from the obligation, or the payment exceeds an approved limit. The delay has a cost, but approving uncertain instructions costs more.
Evidence to keep
Retain who prepared the payment, who approved it, the time, the applied rule, the supporting document and any exception. This record helps explain why the instruction was released.
Configure Quotable Payments authorization around the business’s actual roles and limits. A workflow is only useful if it blocks release when the required approver, verified Recipient or supporting record is missing.


