Corporate Administration · Kapiti Vault

Who Can Approve, Sign, and Act? A Practical Guide to Company Authority

A practical guide to shareholder, board, manager, contractual, banking, and delegated authority—and how to build a clear company authority framework.

Reading time
9 min read
Updated
5 August 2026
Review cycle
Monthly review
Signing authorityDelegation of authorityGovernanceCompany management

In brief

Company authority is not a single permission. A person may be able to approve a transaction internally, sign a document on the company's behalf, operate a bank account, submit a regulatory filing, or carry out an approved decision—but not necessarily all five.

The safest approach is to identify separately:

  • who makes the decision;
  • who may bind the company externally;
  • who may carry out the decision in practice; and
  • what evidence a bank, regulator, counterparty, or court will expect.

These questions are answered by the law governing the company, its constitutional documents, appointments and resolutions, applicable registers, powers of attorney, bank mandates, contracts, and internal policies. They should be checked together, not in isolation.

Authority is not one concept

A practical authority framework usually has several layers:

  1. Ownership authority: decisions reserved to shareholders or members.
  2. Governance authority: decisions allocated to the board or equivalent governing body.
  3. Management authority: powers given by law or the constitutional documents to a manager, director, officer, or other representative.
  4. Delegated authority: a limited power given by resolution, policy, employment terms, or power of attorney.
  5. Operational access: the technical ability to use a bank portal, government platform, company seal, or electronic signature.

The layers may overlap, but they are not interchangeable. In particular, access to a system does not prove that the user was authorised to make the underlying decision.

Ownership does not automatically mean management authority

A shareholder owns an interest in the company. That does not, by itself, mean the shareholder can sign contracts, instruct the bank, employ staff, or represent the company.

The same person may also be a director, manager, or authorised signatory, but that authority comes from the separate office or appointment. Keeping the capacities distinct makes resolutions, contracts, and audit trails clearer.

What shareholders usually decide

Depending on the jurisdiction, legal form, and constitutional documents, shareholder approval may be required for matters such as:

  • amendments to the constitutional documents;
  • changes to share capital;
  • appointment or removal of directors or managers;
  • approval of accounts or distributions;
  • mergers, conversions, or liquidation; and
  • other matters expressly reserved to shareholders.

A shareholder resolution records approval. It should not be assumed that every shareholder who voted for the resolution may also sign the implementing document for the company.

What the board usually decides

The board or equivalent governing body commonly oversees strategy, major commitments, risk, senior appointments, financing, and matters not reserved to shareholders or delegated to management.

A well-drafted board resolution should answer two questions:

  1. What has the board approved?
  2. Who is authorised to sign, submit, negotiate, or otherwise implement it?

For important transactions, the resolution should identify the document or transaction, any value or other limits, whether signatories act singly or jointly, and whether further delegation is permitted.

Manager, director, and officer authority

Titles alone do not establish the extent of a person's authority. The answer may depend on the company type, the constitutional documents, the appointment instrument, registered particulars, and any valid limitations.

For a UAE limited liability company within the scope of the Commercial Companies Law, a manager's powers may be broad unless the appointment contract or memorandum or articles of association restrict them. The manager must act in the stated capacity when acting for the company. This makes it especially important to reconcile internal approvals with the company's formal and registered authority position.

An internal delegation-of-authority policy is a useful control, but it does not necessarily change what a third party may be entitled to rely on. Restrictions that need to affect third parties should be documented, approved, notified, and registered where the applicable law or authority requires it.

Approval and signature answer different questions

Approval authority asks who may decide that the company will enter into a transaction. Signing authority asks who may execute the document so that it binds the company.

The approver and signer may be the same person, but often are not. For example, the board may approve a loan and authorise two directors to sign the facility documents jointly. The signatures implement the decision; they do not replace the board approval.

The reverse problem also occurs: a person may appear on a licence, register, or bank mandate as a signatory but still breach an internal approval limit by acting without the required consent. The external effect and the person's internal responsibility may therefore need separate analysis.

Contract signing authority

Before a material contract is signed, check:

  • the company's governing law and legal form;
  • the constitutional documents;
  • current director, manager, and signatory records;
  • any board or shareholder approvals required for the transaction;
  • any power of attorney or delegated authority being relied on;
  • internal financial or risk limits; and
  • whether the proposed signing method and counterparts are accepted.

Counterparties commonly request a licence or registry extract, constitutional documents, incumbency evidence, a resolution, and specimen signatures. The exact evidence should match the transaction and jurisdiction.

Powers of attorney

A power of attorney can give a named person authority to perform specified acts for the company. It should be treated as a controlled delegation, not a general substitute for governance.

Before relying on one, confirm:

  • that the grantor had authority to issue it;
  • the acts, entities, territories, and value limits it covers;
  • whether it permits sub-delegation;
  • its effective and expiry dates;
  • any notarisation, legalisation, attestation, translation, filing, or registration requirements; and
  • how revocation must be documented and communicated.

A power may be valid internally yet unusable for a particular bank, authority, or transaction if its form or scope does not meet that recipient's requirements.

Bank mandates are a separate authority layer

Bank account authority is governed by the mandate and operating rules accepted by the bank. It may use single, joint, threshold-based, or role-based permissions and may distinguish between preparing, approving, and releasing a payment.

A bank mandate does not necessarily prove that a payment was properly approved under the company's internal governance. Conversely, a board resolution does not always update the bank's systems automatically. Both layers must be maintained.

Online banking access should also be separated from legal and internal authority. User accounts, tokens, and credentials should be personal, promptly removed when roles change, and periodically reviewed against the approved mandate.

Regulatory and tax representation

Government portals and regulators may maintain their own authorised-user, representative, or signatory records. A company should keep those records aligned with its current appointments and delegations.

For example, the UAE Federal Tax Authority lists a change of authorised signatory among amendments to tax records and states that changes requiring an update should be notified within 20 business days. The correct procedure and deadline should always be checked for the particular authority and change.

Build a delegation-of-authority matrix

An authority matrix turns constitutional and governance rules into a usable operating control. It might look like this:

| Decision or action | Internal approval | Signer or representative | Supporting evidence | | --------------------------------------- | --------------------------------------- | ------------------------------------ | ------------------------------------------- | | Routine supplier contract within budget | Designated manager | Authorised signatory | Approved budget and contract record | | Material customer or supplier contract | Board or delegated committee | Named signatory or signatories | Resolution and authority evidence | | Bank payment | Budget owner or finance approver | Bank users under mandate | Invoice, approval trail, and mandate | | Borrowing or security | Board and, where required, shareholders | Specifically authorised signatories | Resolutions and transaction documents | | Share issue or capital change | Board and/or shareholders, as required | Authorised filer or signatory | Resolutions, updated registers, and filings | | Tax or regulatory filing | Responsible function or officer | Registered user, agent, or signatory | Submission record and appointment evidence |

The matrix should reflect the governing documents and formal appointments. It is not, by itself, a source of external legal authority.

Test the framework with real scenarios

A framework is only useful if it produces clear answers. Test it against common events:

  • Can the general manager sign a five-year lease?
  • Who approves a contract above the annual budget?
  • Can one bank user add a beneficiary and release the payment?
  • Who may appoint an external tax agent?
  • Who signs an employment contract for a senior executive?
  • What happens when a director or manager leaves unexpectedly?
  • Who can revoke an existing power of attorney?

If the answer requires several conflicting documents or depends on informal knowledge, the authority structure needs attention.

When the records and actual practice differ

One of the highest-risk situations is a gap between formal records and daily practice—for example, a former manager remains registered, a departed employee retains banking access, or a founder approves every transaction despite having no recorded management office.

UAE commercial-register legislation gives registered data evidential significance and limits when information required to be registered or annotated can be invoked against third parties. A discrepancy should therefore be reviewed promptly, with legal advice where the external effect is uncertain. The company may need resolutions, registry or licence amendments, bank updates, portal changes, revocations, and notices to relevant counterparties.

When authority should be reviewed

Review the authority framework whenever there is:

  • a new director, manager, officer, or shareholder;
  • a resignation, termination, or extended absence;
  • a change of licence, activity, legal form, or constitutional documents;
  • a new bank account or payment platform;
  • borrowing, investment, acquisition, or restructuring;
  • entry into a new jurisdiction;
  • a new government portal, tax registration, or regulated permission;
  • a material increase in contract or payment values; or
  • an incident involving an unauthorised commitment, payment, or filing.

Even without a trigger, an annual review is a sensible minimum for many owner-managed companies; higher-risk businesses may need more frequent checks.

Maintain an authority file

A current authority file should make it possible to establish quickly who can do what and why. It may include:

  • constitutional documents and amendments;
  • current licence and registry extracts;
  • registers of directors, managers, officers, members, and signatories;
  • appointment and resignation records;
  • board and shareholder resolutions;
  • the delegation-of-authority policy and approval matrix;
  • powers of attorney and a revocation log;
  • bank mandates and access reviews;
  • government-portal and tax-authority access lists;
  • specimen signatures, where appropriate; and
  • an index showing effective dates, expiry dates, and document owners.

Sensitive documents and credentials should be stored with appropriate access controls. The objective is an auditable record, not a shared folder that creates new security risks.

Common mistakes

Recurring authority problems include:

  • assuming ownership automatically gives signing power;
  • relying on a job title without checking the appointment and governing documents;
  • approving a transaction without naming the person who will implement it;
  • treating a bank mandate as the complete governance framework;
  • issuing an overly broad or open-ended power of attorney;
  • changing internal roles without updating formal records and external systems;
  • allowing former personnel to retain portal or banking access; and
  • using an internal approval matrix that conflicts with the company's constitutional or registered position.

The Kapiti view

Good authority design is less about concentrating power than making responsibility visible. For each material action, the company should be able to show who decided, who signed, who carried it out, what limits applied, and where the evidence is stored.

That clarity reduces delays, disputed commitments, control failures, and founder dependency. It also gives banks, auditors, investors, regulators, and counterparties a coherent answer when they ask who can act for the company.

Sources & review

Primary references used to prepare and review this guidance.

3 sources
  1. 01Official source · UAE Commercial Companies Lawuaelegislation.gov.ae
  2. 02Official source · UAE Commercial Register Lawuaelegislation.gov.ae
  3. 03Official source · Federal Tax Authority — Tax Records Amendmenttax.gov.ae

General information only. Requirements can change based on authority rules, document availability, due diligence, and applicable law. This is not legal, tax, or financial advice.