MYOB does not enforce a delegation of authority structure for invoice approvals natively. Any user with the right MYOB access level can enter, code and approve a bill. Nothing stops a bookkeeper approving a AU$60,000 subcontractor payment, even when the written policy says a director signs off above AU$20,000. Building an audit-ready authority structure means designing the delegation policy first and then configuring MYOB and, where needed, an AP automation layer to enforce it.
When an unenforced threshold fails
A bookkeeper managing AP for a manufacturing business received a subcontractor invoice for approval. Her MYOB access allowed her to approve bills at any amount. The delegation policy said invoices above a set threshold required CFO sign-off. Because MYOB didn’t enforce the threshold, the policy was only as reliable as her memory of it.
When a fraudulent invoice arrived - constructed to resemble a known subcontractor - it was approved and paid before the anomaly was noticed. The amount had been chosen deliberately to sit below the level that might trigger unusual scrutiny. That isn’t a lapse in anyone’s judgement. It’s a documented threshold policy with nothing enforcing it. With invoice approval workflows explained as the wider context, delegation of authority is one control within that structure.
Design the matrix before opening MYOB
The most common mistake in building a delegation of authority structure is configuring the software before defining the policy. The guide to delegation of authority for Australian SMBs covers how to design the policy framework before touching any software configuration. What gets configured is then whatever MYOB’s defaults suggest rather than what the business actually needs.
The right order is: document who holds financial authority at each level, what amounts each role can approve independently, whether categories like capital expenditure or new suppliers require different routing, and who holds delegated authority when a primary approver is unavailable. That document is the delegation matrix. The MYOB configuration should reflect it - not create it.
Anchor the matrix on roles, not names. List individuals and you’re updating it every time someone leaves or changes position. An approval matrix built on roles - Financial Controller, Operations Manager, CFO, Director - survives all of that without a rebuild. One illustrative structure: AP officer for routine invoices up to AU$5,000 from approved suppliers; Operations Manager up to AU$25,000; Financial Controller up to AU$50,000; Director above that; Board resolution for capital expenditure above the threshold or amounts requiring separate approval. Applying the same thresholds at the commitment stage helps too, so a purchase order generator that records the approving role on each order gives the matching invoice a documented authority to check against. Map your actual staff to those roles in a separate document. That’s the only part anyone should have to touch when someone leaves.
What can MYOB enforce and what can it not?
MYOB’s user role system provides the structural foundation for segregation of duties: a user can be restricted to entering bills without the ability to approve or pay, and the approver role can be separated from the payment role. A user who processes, approves, and pays invoices operates without any independent check - the condition that enables both internal fraud and error to go undetected.
What MYOB cannot enforce is the dollar-value threshold, and mapping out what you can and cannot configure in MYOB workflows makes the boundary clear before you design around it. A user with approval access can approve a AU$500 stationery invoice and a AU$120,000 capital purchase with identical permissions. The threshold policy exists in a document. The system records whatever approval occurs, at whatever amount.
Most businesses past a single approver need that threshold enforced somehow. Either a structured manual review process, documented and audited regularly for compliance, or an AP automation layer that routes by value before bills reach MYOB. Manual review is fine at low volumes. Past a few dozen invoices a week it comes down to someone staying vigilant every single time, and that’s where the gaps turn up.
Segregation at the payment step
The most consequential segregation of duties control is the separation between the person who approves a bill and the person who initiates payment. In MYOB, this means restricting Pay Bills access to a small named group who do not also hold invoice approval authority. If the person who approves a fraudulent or erroneous invoice can also process the payment without a second checkpoint, the approval step provides no protection - it merely records a name against a payment that is going through regardless.
Where businesses use bank feed connections for payment processing, the banking credentials should sit with a separate named individual from the bill approver. A single person with both Adviser-level access and banking credentials can approve and pay without any independent review.
What delegation gap do auditors find?
The finding that appears most frequently in Australian SMB AP audits is not that approvals didn’t happen - it’s that the approvals that happened can’t be linked to a documented authority structure. A complete audit trail must connect each approval to the delegated authority that authorised it. The auditor asks: was the AU$45,000 invoice on 14 March approved by someone who had delegated authority for that amount? The answer depends on whether a formal matrix exists, whether the system was configured to enforce it, and whether those two things match.
A delegation matrix document and a MYOB configuration that don’t match each other are both unreliable. The auditor compares them. If the policy says amounts above AU$20,000 require CFO sign-off and the MYOB access log shows a bookkeeper approving AU$38,000 bills, the finding is the same regardless of whether those payments were legitimate. Review the matrix and the system configuration together at least annually, and whenever a key approver joins or leaves.
Sources: ATO - Record-keeping requirements for business · ASBFEO - Small business resources
Further reading: Best Invoice Approval Workflow Software Australia 2026 · Invoice Workflow Software: What It Actually Needs to Do · Invoice Approval Workflow Software: What Australian Businesses Need