← Back to resources
Guide · Capex governance

Capex governance for portfolios over $100M.

Approval thresholds, separation of duties, and the audit trail your CFO and external auditor both want.

PulsePMO IQ · Field guide for finance and PMO leaders

Capex governance that works at $10M in annual commitments usually breaks somewhere between $50M and $150M — not because the dollar amounts get harder to track, but because the number of concurrent projects, vendors, and approvers crosses the point where a spreadsheet-and-email process can no longer guarantee that every commitment above threshold actually got the review it required.

This guide covers the four elements of a capex governance model built for that scale: a threshold ladder that routes decisions to the right level without bottlenecking everything at the top, clean separation of duties, an audit trail structured the way auditors actually sample it, and visibility into vendor commitments that span more than one project.

1. Build a threshold ladder, not a single approval gate

The most common failure in capex governance at scale is a single approval threshold that routes too much through too few people. A ladder with three or four tiers keeps decision speed proportional to risk:

Commitment sizeApproverRequired documentation
Up to $250KCost-center owner + finance business partnerBusiness case summary, budget line confirmation
$250K – $2MDivisional capital committeeFull business case, vendor comparison (if applicable), 3-year TCO
$2M – $10MEnterprise capital committeeFull case, sensitivity analysis, alternatives considered, sponsor sign-off
Over $10MExecutive committee / board capital subcommitteeFull case plus independent review, board memo

Set the tiers to your organization's actual risk appetite, not a round number that sounded reasonable in a policy meeting. The test of a good ladder is that fewer than 10% of commitments require the top tier of approval — if more than that are reaching the executive committee, the lower tiers are set too conservatively and you have built a bottleneck.

2. Separate the four duties that must not sit with one person

Auditors look for four distinct roles in a capex approval trail, and the finding that comes up most often in control reviews is the same person occupying two of them:

  • Requester — proposes the spend and owns the business case.
  • Budget owner — confirms the commitment fits an approved budget line, independent of the requester.
  • Approver — authorizes the commitment at the threshold tier it falls into.
  • Verifier — confirms, after the fact, that spend tracked to the approved scope — typically internal audit or a finance controller, never the original approver.
Common finding

A project sponsor who is also the divisional capital committee chair approving their own project's commitment. This is the single most frequent segregation-of-duties finding in capex audits above $100M in annual commitments — structurally prevent it by excluding sponsors from the vote on their own requests, not by relying on recusal norms.

3. Structure the audit trail the way auditors sample it

External and internal auditors do not read every approval end to end — they pull a statistical sample and reconstruct each one. An audit trail that survives that process, reliably, contains five things for every commitment above the lowest threshold tier:

  1. The original business case, timestamped, in the version that was actually approved (not a later, edited version).
  2. Who approved it, at what threshold tier, and on what date — with the approver's role visible, not just a name.
  3. What changed between approval and actual spend, and whether the change required re-approval.
  4. Which budget line the commitment drew against, and confirmation it did not exceed the approved envelope.
  5. The final reconciliation — actual spend against approved commitment, with variance explained.

The recurring gap is item three: scope or vendor changes that happen after initial approval, absorbed informally because re-running the full approval process feels disproportionate to a modest change. Define a change threshold (for example, more than 10% of the original commitment, or any change in vendor) that triggers a lightweight re-approval, so the record stays accurate without requiring a full committee cycle for every adjustment.

4. Track vendor commitments across projects, not just within them

At $100M-plus in annual capex, the same vendor is frequently committed across multiple concurrent projects, each of which looks reasonably resourced in isolation. The risk that matters at the portfolio level — a vendor over-committed at 130–150% of capacity across projects that don't talk to each other — is invisible to any single project's governance and only shows up when someone rolls up vendor commitment across the whole portfolio.

Two practices close this gap:

  • Maintain a single, portfolio-level view of committed hours or dollars per vendor, updated as each project's commitments change — not reconstructed periodically from separate contracts.
  • Flag any vendor crossing 85% of stated capacity across concurrent commitments for review before approving additional work with that vendor, rather than after a project reports a resourcing shortfall.

5. Keep it fast, not just controlled

Governance that only adds friction gets worked around — informal side agreements, spend split into pieces to stay under a threshold, or approvals sought after the fact. Two design choices keep the ladder credible with the people using it:

  • Parallel review where possible. Budget confirmation and business-case review can usually happen at the same time, not in sequence, without weakening either check.
  • A logged exception path for genuinely time-critical spend, with mandatory retroactive approval within a fixed window (5 business days is typical) — visible in the same system as routine approvals, not a separate off-book process.
See capex thresholds enforced in a live portfolio.

Approval routing, audit trail, and vendor commitment tracking — in the product tour.

See it in action

This guide reflects general capital-governance practice patterns and is not specific to any named customer or engagement.