Most businesses control spending with approval limits: a supervisor may approve purchases up to $5,000, a manager up to $25,000, anything larger goes to the owner. That is sensible. But approval limits control one thing, what people may spend, and say nothing about another: what people may cause the business to owe.
Consider a scheduler who emails a crane hire company: “You’re booked for Monday, purchase order to follow.” Nothing has been approved and no limit has been exceeded. But the crane company may turn away other work in reliance on that email. If the job is then cancelled, the business may face a claim, and the person who created that exposure had no spending authority at all. The emails, phone calls and site conversations that keep a business running are also the evidence another party will rely on if a dispute arises.
This article explains the gap between authority to spend and the ability to create obligations, how to work out which roles can create the largest exposures, practical controls that do not stop people doing their jobs, and a related blind spot in risk reporting: risks that stop being red because the acceptable level was quietly moved rather than because anything was fixed. It is general information, not legal advice. Whether a particular email or conversation creates a legal obligation depends on the facts and the law, so take advice on specific situations.
Spending and owing are different
Approval limits are designed from the inside: they reflect what the business is prepared to spend and give everyone a clear rule. Whether the business owes something to another party is decided differently: by what its people said and did, judged by the other party and, if it comes to it, by a court or tribunal, after the fact.
Three common assumptions make the gap wider:
- Exposure begins at signature. Signature is when the business’s own paperwork catches up. The other party’s case is usually built from what happened before: the instruction to start, the assurance about volumes, the email recording agreement on price.
- Preliminary documents are harmless. Letters of intent, heads of agreement and “subject to contract” emails carry labels chosen to make them non-binding. Their effect is judged against how both parties then behaved. A business that acts as if bound while insisting it is not has created evidence, not protection.
- Exposure follows seniority. It follows contact. A scheduler, buyer or site supervisor who speaks to suppliers and customers every day creates far more of the relevant evidence than a director who speaks to them occasionally.
The when a conversation becomes a commitment article explains how agreements form and why everyday phrases can carry more weight than intended.
Four ways everyday work creates obligations
For any role that deals with suppliers or customers, ask how large an obligation it could create in a single day while staying within its approval limit, through four routes:
| Route | Question | Example |
|---|---|---|
| Mobilisation | What is the largest cost a supplier would incur if this person told them to start? | A supplier books crew, orders materials or turns away other work |
| Displacement | What is the largest opportunity another party would give up on this person’s assurance? | A customer cancels another supplier because they were told the job was confirmed |
| Documents | What is the largest value named in any preliminary document this person signs? | A letter of intent or “confirmed, contract to follow” email |
| Silence | What is the largest assumption a supplier or customer has written to this person and not been corrected on? | “As discussed, we’ll proceed on the revised price unless we hear otherwise” |
The largest of the four is that role’s practical exposure ceiling. Where it is much larger than the role’s approval limit, the business has an uncontrolled risk, even if nobody has ever exceeded a spending limit. Roles with no approval limit at all, such as schedulers and coordinators, can still have significant exposure ceilings.
Controls that do not stop the work
The emails and conversations that create these exposures are part of doing business well. The aim is not to stop them but to decide who may create them, with whom and under what rules. Practical options include:
- Co-approval for instructions to start above a set value: a second person confirms before a supplier is told to mobilise.
- Standard wording for confirmations, bookings and quotes, distinguishing “we would like to book you, subject to our purchase order” from “you are booked”.
- A named list of people who may issue letters of intent or similar documents, and a simple register of those issued: to whom, for what and for what value.
- A rule to correct assumptions promptly: when a supplier or customer writes down an understanding that is wrong, someone replies in writing the same day.
- Training for people with frequent outside contact, using real examples from the business.
- Matching authority to reality: if a role routinely creates large exposures, either raise its approval limit to match and hold it accountable, or reduce what it can create.
A useful governance rule is that every approval limit has an exposure ceiling beside it, so the business can see both numbers together.
The same applies with customers
Obligations run in both directions. A salesperson who tells a customer “we’ll have it to you by the fifteenth, guaranteed” or “that’s included in the price” may be creating a commitment the business must honour, even if the quotation says otherwise. Customer-facing staff need the same clarity as those dealing with suppliers: which promises they may make, which need approval, and how to word an intention without turning it into a guarantee. Under the Australian Consumer Law, statements to customers can also create obligations or exposure in their own right if they are misleading, so accurate wording matters for compliance as well as for contracts.
Risks that improve without anything being fixed
A related blind spot sits in risk reporting. Many businesses keep a risk list, with ratings such as red, amber and green, and items escalated when they exceed an acceptable level. A risk can stop being red for two very different reasons:
- It was treated: something was done, such as a supplier qualified, a check introduced or a backup arranged.
- The acceptable level moved: someone decided that an exposure that was unacceptable last month is acceptable now.
Both may be legitimate. Circumstances change, and the level of risk a business is willing to accept can reasonably change with them. But the first leaves a record: an action, an owner, a cost, a date. The second usually leaves only a colour change. A report showing “risks reducing” may be reporting the business’s own decision back to it as good news.
Moving the acceptable level is quick, free and produces the same report as months of real work. Nothing in a typical risk process prices it, so it tends to be used more than people realise.
Record changes to what is acceptable
A simple record makes the second route visible. Any change to an acceptable level, threshold or escalation trigger takes effect only when a short note records:
- The level before and after, in actual numbers.
- Who changed it, and under what authority.
- What changed in the circumstances to justify it. If the reason is about the risk itself rather than the business’s situation, it is a re-rating, not a change of threshold.
- Which risks are affected, and their status before and after.
- A review date, after which the wider level reverts unless renewed.
And one reporting rule: a risk may not improve its status in the same period as a change to its threshold unless the note is referenced. Where no note exists, the threshold has not moved.
A worked example
This is an illustration. A civil contracting business with 40 staff gives its site supervisors approval limits of $5,000 and its scheduler none at all. Last year, the scheduler emailed a crane hire company to confirm a crane for a Monday lift, “purchase order to follow”. The client postponed the job on the Friday. The crane company, which had turned away another booking, claimed $14,000. The business settled for $9,000 rather than dispute it.
The owner reviews the roles with the most outside contact, not the most senior: the scheduler, four site supervisors, the estimator and the purchasing officer. For each, they work out the largest exposure the role could create through the four routes. The scheduler’s ceiling, through crane and equipment bookings, is around $40,000. One supervisor regularly signs subcontractor “start notices” for jobs worth more than $100,000. None of this appears in the approval schedule.
The business introduces:
- standard booking wording making confirmations subject to a purchase order, with cancellation terms stated;
- co-approval by the operations manager for any instruction to start above $10,000;
- a short register of start notices and letters of intent, reviewed weekly;
- a same-day reply rule for any supplier email stating an understanding that is wrong;
- a one-hour session for the people concerned, using the crane claim as the example.
At the same time, the owner notices that a long-standing red risk, subcontractors working without current insurance certificates, turned amber three months ago. On investigation, nothing had been fixed. The operations manager had decided that a small number of lapsed certificates was acceptable given how hard they were to chase. The business reverses that decision, records it properly and introduces a simple check: no subcontractor is booked onto the schedule unless their certificate is current in the system. The risk becomes amber again two months later, this time with a reason.
How this applies to a small Australian business
In small businesses, a few people handle most of the contact with suppliers and customers, often informally. Practical steps:
- Map exposure for roles with outside contact, not just for those with approval limits.
- Use the four routes: mobilisation, displacement, documents and silence.
- Put an exposure ceiling beside each approval limit.
- Standardise wording for bookings, confirmations and quotes.
- Keep a register of letters of intent and start notices.
- Correct wrong assumptions in writing the same day.
- Record every change to an acceptable risk level, with a review date.
- Take legal advice if a claim arises from a booking, assurance or preliminary document.
The a signature is not the whole story and thinking clearly about a contract problem articles cover related issues.
Signals worth watching
- Claims or disputes arising from bookings, emails or verbal assurances.
- Letters of intent or start notices issued by many different people.
- Supplier emails stating “as agreed” terms that nobody remembers agreeing.
- Roles with frequent outside contact and no clear rules.
- Risks improving with no completed action behind them.
- Acceptable risk levels changed in conversation rather than in writing.
Common mistakes
- Assuming approval limits control exposure.
- Treating preliminary documents as harmless.
- Focusing controls on senior people rather than those with most outside contact.
- Leaving incorrect supplier assumptions unanswered.
- Celebrating improving risk ratings without asking why they improved.
- Moving acceptable risk levels without a record or review date.
Frequently asked questions
Does “purchase order to follow” protect us? Not necessarily. What matters is the whole exchange and how both parties behaved. Clear wording about what is and is not confirmed, and any cancellation terms, helps. Take advice on your standard wording.
Should we stop staff from talking to suppliers? No. That would stop the business working. Give them clear wording, clear limits and someone to check with for larger commitments.
What is a letter of intent for? It records intentions before a full contract is signed, often so work can start. It can be useful, but it can also create obligations depending on its wording and what happens next. Have it reviewed and keep a register of those issued.
Is changing an acceptable risk level wrong? Not at all. Businesses legitimately adjust what they will accept as conditions change. The point is to make the change deliberately, record it and review it, so it is not mistaken for improvement.
How often should we review exposure ceilings? When roles change, when a claim or near-miss occurs and at least once a year.
What about verbal commitments on site? They can matter as much as written ones, and they are harder to prove either way. Encourage supervisors to follow significant verbal agreements with a short email confirming what was and was not agreed, so both parties have the same record.
Questions to ask
- Which roles in our business create obligations through everyday contact?
- What is the largest exposure each could create in a day?
- Who may issue letters of intent or instructions to start?
- Do we correct wrong assumptions in suppliers’ emails promptly?
- Which risks improved last quarter, and was anything actually done?
- Who changed our acceptable risk levels, and is it written down?
Bringing it together
Approval limits control spending, but obligations are created by what people say and do. Map the exposure that roles with outside contact can create, through instructions to start, assurances, preliminary documents and silence, and put that figure beside each approval limit. Use standard wording, co-approval for larger commitments, a register of preliminary documents and a same-day correction rule. In risk reporting, record every change to what is acceptable, with a reason and a review date, so that improvement means something was fixed. Both habits close gaps that ordinary controls do not see.
Source: KEVOS notes, drawing on teaching material on delegation of authority, commercial commitment and risk appetite and tolerance. Examples and figures in this article are illustrations. This article is general information, not legal advice.