1. Recognise when growth has exceeded the current operating model
An operating model is the practical arrangement through which strategy becomes decisions and work. It includes governance, legal entities, accountabilities, decision rights, organisation structure, processes, information, technology, capabilities, incentives and management routines. An organisation chart shows reporting relationships. It does not by itself explain who may commit capital, change a price, enter a market, accept a risk, hire a leader, sign a contract or stop an underperforming initiative.
Growth increases the number and interdependence of those choices. A company operating in one market can rely on informal access to the founder. A group operating across the UAE, Saudi Arabia and other jurisdictions may face different legal entities, licences, taxes, employment rules, data obligations, customers and approval requirements. Product, commercial, finance, legal and operating teams can each hold part of the evidence needed for one decision.
Common symptoms include repeated escalation to the chief executive, decisions reopened after meetings, several people believing they own the same outcome, functions creating parallel approval routes, country teams waiting for headquarters, business units making inconsistent commitments, and boards receiving operational detail while material choices remain unclear. These symptoms should be tested with evidence rather than assumed from dissatisfaction.
The diagnostic should trace a sample of material decisions from trigger to outcome. It should record elapsed time, number of hand-offs, rework, missing information, escalations, approval basis and result. The company can then distinguish a rights problem from a capability, data, process, system, incentive or capacity problem.

The architecture is a general management model. Legal duties and regulatory responsibilities remain subject to applicable requirements.
Table 1. Evidence-led operating-model diagnostic
| Diagnostic lens | Evidence | Question | Possible root cause |
|---|---|---|---|
| decision speed | trigger, submissions, meetings, approvals and outcome dates | Where does elapsed time accumulate? | unclear right, missing data, limited capacity or excessive sequencing |
| rework | reopened decisions, repeated analysis and changed instructions | Why was the first decision incomplete or reversed? | weak evidence, absent consultation or authority mismatch |
| escalation | volume, reason, level and response time | Which choices reach leaders who add little incremental judgement? | low delegation, low trust, unclear thresholds or capability gap |
| accountability | owner, measure, dependency and result | Can one role explain the outcome and coordinate dependencies? | shared ownership without integration authority |
| control | exceptions, overrides, incidents and assurance findings | Does speed expose the company to unacceptable risk? | control outside workflow, poor aggregation or undocumented override |
| value | customer, margin, cash, quality and strategic effect | Does the decision architecture support the intended value flow? | structure optimised for hierarchy rather than outcome |
Measures and thresholds should be adapted to the company's material decisions and data quality.
2. Establish the governance perimeter before redesigning management
Management authority sits inside a governance and legal perimeter. The board retains responsibilities imposed by applicable law, constitutional documents, shareholder agreements and sector rules. Some matters may be reserved to shareholders or the board. Others may be delegated with conditions, limits and reporting. A management-design exercise should not silently reassign a legal duty or contractual right.
The G20/OECD Principles of Corporate Governance state that boards provide strategic guidance, monitor management and remain accountable to the company and shareholders. The Principles also recognise different board structures and encourage explicit articulation of responsibilities assumed by the board and those for which management is accountable.[1]
Saudi Arabia's Capital Market Authority Corporate Governance Regulations require, for companies within scope, an organisational structure that distributes competencies between the board and executive management. Article 22 addresses internal policies, a written and detailed delegation policy, a matrix of delegated powers, the period of delegation and matters reserved to the board.[2] The exact application and current legal effect require Saudi legal advice.
The UAE Securities and Commodities Authority describes accountability, transparency, responsibility and fairness as governance pillars and identifies the respective responsibilities of boards and executive management for public joint-stock companies within its scope.[3] Its 2024 annual report records amendments aligning the governance guide with the UAE Commercial Companies framework, including board obligations concerning internal control and risk management.[4]
Privately held mainland, free-zone and financial-free-zone companies may follow different laws, regulations and constitutional documents. The ADGM Companies Regulations 2020, as amended, provide one example of a separate company-law framework.[5] The design team should therefore build a legal-entity and authority register before choosing a group operating model.
3. Design decision rights as a complete specification
A decision right should identify more than the final approver. It should state the purpose, decision owner, authority source, financial or risk limit, required evidence, consultation, execution owner, notification, escalation and review date. This specification turns a conceptual right into an operating control.
The decision owner is accountable for preparing the choice, obtaining required input, making or securing the decision within authority and ensuring execution. The approver may be a different role where law, delegation or risk requires it. Contributors provide expertise. Affected roles receive information. Assurance roles evaluate governance, risk and control without becoming management decision owners.
ISO 37000:2021 provides governance guidance applicable across organisation types and highlights purpose, strategy, oversight, accountability, data and decisions, risk governance and long-term viability. It states that governing bodies should define roles and responsibilities and maintain functioning reporting and accountability systems.[6]
The rights map should prioritise decisions with material value, risk, frequency or cross-functional dependency. Examples include pricing exceptions, customer credit, product launch, capital expenditure, market entry, contracts, hiring, data use, financing, acquisition and incident response. Routine operating tasks can remain within process controls.

The ladder is illustrative. Reserved matters, delegated limits and legal duties require entity-specific confirmation.
Table 2. Minimum decision-right specification
| Field | Required content | Control question | Evidence retained |
|---|---|---|---|
| decision and purpose | precise choice and intended outcome | Is the decision distinct from execution activity? | decision catalogue entry |
| authority | legal, constitutional, board or delegated source | Can this role make the decision at this value and risk? | authority matrix and approval record |
| owner | single coordinating role | Who is accountable for timely, complete preparation and follow-through? | named role and objective |
| inputs | minimum financial, commercial, legal, risk and operating evidence | Is the choice informed without requiring every available datum? | controlled submission |
| consultation | roles whose input is mandatory or discretionary | Does consultation add expertise without creating a hidden veto? | recorded comments or concurrence |
| threshold | value, risk, novelty, geography or exception condition | When does the right change level? | limits and aggregation rule |
| execution | role that implements and reports the outcome | Does authority remain connected to delivery? | action and outcome log |
| review | expiry, periodic review and override treatment | Will the right remain appropriate as the company changes? | version and review record |
The fields are a management template and do not replace legal advice or executed delegations.
4. Use organisation layers only where they add a distinct contribution
Organisation layers can integrate activity, develop capability, allocate resources and manage risk. They can also become relays that move information upward and instructions downward. The design test is whether each layer makes a distinct decision or integration contribution that cannot be delivered reliably elsewhere.
The governing body directs and oversees within its mandate. The group executive integrates enterprise choices. Business or country leadership manages a coherent market, customer or economic unit. Functional leadership defines capability, standards and professional control. Teams execute value-creating work. The exact shape depends on strategy, size, sector, ownership and legal entities.
Spans of control should reflect work complexity, interdependence, manager capability, geographic dispersion, standardisation and team maturity. A numerical span target cannot resolve a poorly defined role. A narrow span can be justified for complex integration or development. A broad span can work where work is standardised, data is reliable and teams are experienced.
The IFC Corporate Governance Methodology uses progression matrices tailored to listed, founder- or family-owned, fund, financial-institution and SME contexts. It recognises governance maturity and complexity rather than one universal structure.[7] IFC's SME governance work likewise describes fit-for-purpose evolution as companies grow.[8]

The model is illustrative and does not prescribe a fixed hierarchy or span.
Table 3. Layer and span design tests
| Design question | Evidence | Retain a layer when | Redesign signal |
|---|---|---|---|
| distinct decision | decision catalogue and authority map | the layer owns material choices with clear limits | approvals repeat decisions made elsewhere |
| integration | cross-unit dependencies and value flows | the layer resolves trade-offs across coherent units | it consolidates reports without resolving trade-offs |
| capability | standards, talent and professional judgement | specialist leadership improves quality and scale | functional oversight duplicates business management |
| managerial load | calendar, team needs and exception volume | the manager can coach, decide and integrate | most time is spent relaying information or expediting |
| local responsiveness | customer, regulator, labour and partner interfaces | local authority materially improves response | country layer lacks economic or decision accountability |
| cost and speed | fully loaded cost and decision-cycle evidence | contribution exceeds added delay and overhead | hierarchy grows while outcomes and control do not improve |
The tests are qualitative. Final structure requires workload, capability, cost and legal-entity evidence.
5. Replace meeting accumulation with a governed forum architecture
Meetings are governance mechanisms only when they have a defined purpose, authority, inputs, participants, decisions and follow-through. A recurring meeting that shares information without resolving choices should be tested against asynchronous reporting or a shorter coordination routine.
The forum architecture should separate four needs. Operating reviews manage performance and exceptions. Decision forums make specified choices. Risk and control forums examine exposure and response. The board performs its governing responsibilities. Combining every purpose in one meeting creates crowded agendas and unclear authority.
The UK Infrastructure and Projects Authority Project Routemap governance module emphasises accountability, empowered decision-making, alignment, effective reporting, assurance and trigger conditions.[9] Those principles can inform management forums beyond infrastructure when applied proportionately.
Inputs should arrive before the meeting in a controlled format. The chair should distinguish items for information, discussion and decision. The minutes should capture the choice, authority, evidence, dissent where relevant, actions, owners and due dates. A decision log should remain accessible after the presentation has been replaced.

Cadence is illustrative. The organisation should set frequency according to volatility, authority and decision lead time.
Table 4. Minimum forum charter
| Charter field | Required content | Failure prevented | Evidence |
|---|---|---|---|
| purpose | decisions and outcomes within scope | status meeting without authority | approved charter |
| chair and members | accountable chair, decision roles and essential expertise | attendance as representation rather than contribution | role list |
| authority | delegated limits, reserved matters and escalation | forum decides outside its mandate | authority reference |
| inputs | measures, options, risks, recommendations and cut-off | decisions made from inconsistent or late information | controlled pack |
| cadence and trigger | frequency plus event-based convening | urgent issue waits for calendar | annual calendar and trigger rule |
| record | decision, rationale, dissent, owner, action and date | choice is reopened or forgotten | minutes and decision log |
| effectiveness | decision age, action closure and forum workload | governance accumulates without value | periodic review |
Meeting charters should remain consistent with legal and delegated decision rights.
6. Use RACI as a role-clarity tool within the decision architecture
A responsibility matrix can expose gaps and overlaps. RACI commonly distinguishes Responsible, Accountable, Consulted and Informed roles. Its value depends on precise activities or decisions. A matrix filled with broad process labels can create the appearance of clarity while leaving authority unresolved.
For each material decision, one accountable role should coordinate the end-to-end outcome. Several roles may be responsible for analysis or execution. Consultation should identify necessary expertise and avoid hidden vetoes. Information recipients should receive proportionate updates without being drawn into every approval.
RACI should be linked to the authority matrix. A person marked Accountable in a workshop does not acquire a legal or delegated power absent the required approval. Similarly, an approver is not automatically accountable for operational delivery. The company should reconcile the terminology used across policies, job descriptions, committees and systems.
The matrix should include controls. Legal, compliance, risk, finance, information security, data protection and human resources may have mandatory roles for defined choices. Those roles should enter early enough to shape options. A late control review often creates delay because the commercial commitment is already assumed.
Table 5. Illustrative responsibility matrix for selected decisions
| Decision | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| pricing exception | commercial leader within limit | account and finance analysts | finance, legal and product as required | business head and control reporting |
| market entry | chief executive or board within authority | strategy and country build team | legal, tax, finance, risk, technology and people | affected functions and shareholders as required |
| senior hire | designated executive or committee | hiring manager and people team | finance, legal and relevant leaders | team and governance forum |
| product launch | product leader within approved gate | product, engineering and operations | security, legal, finance, risk and commercial | executive and customer-facing teams |
| capital expenditure | business sponsor within delegated limit | project and procurement team | finance, legal, technology and operations | portfolio forum and board when required |
| material incident | incident executive under response plan | response teams | legal, security, risk, communications and advisers | board, regulator, customers or other parties as required |
Roles are examples. Authority, consultation and control requirements must be tailored to the entity and decision.
7. Balance group consistency with country and business accountability
A GCC operating model often spans different legal entities, licences, labour markets, customers and partner ecosystems. Centralisation can create common standards and scale. Local authority can improve speed, relationships and adaptation. The design should decide which choices require enterprise consistency, which require local judgement and which require joint approval.
Centralise where risk, capital, brand, data, technology architecture, financing, scarce capability or group economics require integration. Localise where customer knowledge, regulation, language, government interface, talent market or operating conditions materially affect the choice. Use a federated right where both contributions are essential and the final decision owner is explicit.
Legal entity directors may owe duties to the entity under applicable law even where group management sets strategy. Transfer pricing, tax residence, permanent establishment, regulated activity, employment, data transfer and related-party arrangements require professional advice. A group chart should not be treated as a substitute for legal-entity governance.
The rights map should therefore include jurisdiction and entity. A commercial limit may differ by country, currency, customer risk or licence. Aggregation rules should prevent several local approvals from creating an enterprise exposure above the intended limit.
8. Align information products with the decisions they support
Decision rights fail when information arrives late, uses conflicting definitions or cannot be reconciled. Each material decision should have an information product with a defined owner, source, cut-off, metric dictionary, version and quality control.
The board and executive team need different levels of detail. The board should receive material performance, risk, capital and governance evidence sufficient for its responsibilities. Executives need cross-business choices and exceptions. Teams need operational signals and actions. A single pack copied across all forums creates overload at one level and insufficient detail at another.
IFRS 18 introduces requirements concerning presentation, defined subtotals and management-defined performance measures within its scope for annual reporting periods beginning on or after 1 January 2027.[10] Internal operating measures may fall outside that definition. Finance should still govern labels, calculations and reconciliations, particularly where a measure may enter public communications.
The organisation should distinguish actuals, commitments, forecasts, scenarios and targets. A decision pack should state uncertainty and show the effect of major assumptions. Data quality limitations should be visible together with the action and decision consequence.
9. Embed risk, control and assurance without recreating approval congestion
Control should sit as close as practical to the decision and execution workflow. A control designed after the process may create a separate queue. The operating-model reset should identify preventive, detective and corrective controls, their owners, evidence and escalation.
The Financial Reporting Council's UK Corporate Governance Code 2024 addresses board monitoring of risk management and internal control for companies within its scope.[11] Its related guidance discusses board responsibilities, monitoring, review and the limitations of internal-control systems.[12] Other companies can consider the principles proportionately while applying their own legal and contractual requirements.
The Institute of Internal Auditors' refreshed Three Lines Model distinguishes governing-body accountability, management action, specialist support and monitoring, and independent internal audit assurance.[13] A growing company may not maintain a separate internal-audit function. It should still distinguish management ownership from independent assurance and protect objectivity where roles overlap.
HM Treasury's Orange Book describes risk management as integral to governance, strategy, planning, resource allocation, performance and decision-making, supported by clear roles, best available information, monitoring and timely reporting.[14] Its public-sector scope should be recognised. The integration principles remain a useful design reference.
10. Align roles, incentives and capability with the new rights
A new authority matrix does not become real because it is published. Role holders need capability, information, time, incentives and psychological permission to use the right. Senior leaders also need discipline to avoid reclaiming delegated decisions without an agreed trigger.
Job descriptions should state outcomes and authorities. Performance objectives should reflect end-to-end results, control and collaboration. Incentives should avoid encouraging one function to optimise its metric while transferring cost or risk elsewhere. Material incentive changes require employment, tax, legal and accounting advice.
Capability assessment should focus on decisions. Can the role interpret the evidence, understand the limits, consult the right expertise and act under uncertainty? Development can combine coaching, simulations, delegated pilots and review of actual decisions.
The company should establish an override protocol. An override can be necessary during crisis or novel circumstances. It should identify authority, reason, duration, action and review. Repeated overrides may indicate that the design, capability or limits are wrong.
11. Transition authority through controlled waves
Operating-model transitions create risk because the current and target models coexist. Employees may receive conflicting instructions, systems may retain old access rights and contracts may name former authorities. The transition plan should specify the effective date for each right, interim authority, dependencies and evidence of completion.
The first wave should clarify governance, critical decisions and safety controls. The second can adjust forums, reporting lines and management routines. The third can change systems, shared services, locations and incentives. Sequencing should follow business continuity and legal requirements rather than the visual neatness of the target chart.
ISO 37004:2023 provides guidance for a governance maturity model that builds on ISO 37000.[15] A maturity lens can help management sequence improvements without presenting governance as a binary state.

Timing is illustrative. Transition waves should follow legal, operational, technology and people dependencies.
Table 6. Transition control plan
| Transition element | Entry evidence | Completion evidence | Principal risk |
|---|---|---|---|
| authority | approved target right, legal review and effective date | signed delegation, system access and tested decision | old and new authorities operate simultaneously |
| role | approved accountabilities, selection and consultation | accepted role, objectives and operating support | title changes without capability or authority |
| forum | charter, participants, calendar and pack | decisions logged and prior meeting retired | duplicate committees remain active |
| process | target flow, controls, owner and training | live transactions completed and reconciled | informal workaround bypasses control |
| technology | access design, data migration and support | tested access, audit trail and legacy removal | excessive privilege or broken workflow |
| performance | baseline, measures and review date | evidence of speed, quality, control and value | success declared from implementation activity alone |
The plan is illustrative. Employment consultation, regulatory notification and contractual consent may be required.
12. Execute a ninety-day reset programme
During days one to fifteen, management should confirm scope, sponsor, legal perimeter and baseline evidence. It should identify the twenty to forty decisions with the greatest value, risk, frequency or friction. Interviews should be tested against workflow and system evidence.
During days sixteen to thirty-five, the design team should specify decision rights, reserved matters, delegation limits, escalation triggers and information products. Leaders should test the design against realistic scenarios such as a price exception, senior hire, market entry, major contract or incident.
During days thirty-six to sixty, the company should design roles, layers, spans and forums around the approved rights. Cost, capability, customer, control and geographic consequences should be modelled. Employment, tax, legal, data and regulatory requirements should enter before decisions become difficult to reverse.
During days sixty-one to seventy-five, transition owners should prepare delegations, role charters, communications, access changes, training and continuity plans. The board or relevant authority should approve reserved elements.
During days seventy-six to ninety, the company should pilot selected rights and forums, measure decision cycles, resolve ambiguity and establish the next maturity priorities. Full rollout should follow evidence of readiness rather than a fixed communication date.
13. Measure whether the reset changes outcomes
Implementation metrics should include both speed and control. Decision-cycle time can fall because approvals are clearer or because necessary challenge has been removed. The company should therefore pair time with rework, exception, control and outcome measures.
Useful measures include elapsed decision time, percentage decided at intended level, number of escalations, rework rate, action closure, meeting hours, management layers, manager load, control exceptions, customer response, employee clarity and financial or operating outcomes linked to the decision.
The baseline and metric definitions should be retained. A survey of role clarity can add insight, but it should be compared with observed behaviour. Faster meetings do not prove faster execution. Fewer escalations may reflect stronger delegation or suppressed reporting.
Benefits should be stated with attribution limits. External demand, hiring, technology and other initiatives may influence results. The operating-model contribution should be evaluated through plausible mechanisms and contemporaneous evidence.
14. Avoid recurring redesign failures
The first failure is beginning with boxes and lines. Reporting changes are announced before decision rights, value flows and controls are designed. The new chart reproduces old ambiguity.
The second is universal centralisation or decentralisation. The company applies one philosophy to choices with different economics, risks and local requirements. Rights should follow the decision mechanism.
The third is excessive consultation. RACI matrices assign many consulted roles without defining mandatory input or response time. Consultation becomes a veto by delay.
The fourth is shadow governance. Old committees, founder approvals and informal channels continue after formal delegation. Decisions are made twice and accountability remains unclear.
The fifth is control at the end. Legal, finance, risk, security or people review begins after commercial commitment. The organisation experiences control as obstruction because it was not integrated into option design.
The sixth is a single launch date. Authority, systems, roles and contracts change at different speeds while management communicates one target model. Controlled waves and interim rights reduce ambiguity.
The seventh is measuring implementation rather than outcome. Role descriptions and committees are counted while decision quality, speed, control and value remain untested.
15. Board and executive diagnostic
Boards and executives can test the operating model through twelve questions:
1. Which twenty decisions most influence value, risk and strategic speed? 2. Where is the legal or delegated authority for each decision recorded? 3. Can one role explain the evidence, decision and execution outcome? 4. Which consultations are mandatory, and which are advisory? 5. Which thresholds change the decision level? 6. Does each organisation layer add a distinct decision or integration contribution? 7. Which forums can make decisions, and which only coordinate or report? 8. Are country and group rights explicit for each material legal entity? 9. Do controls enter the workflow before commitment? 10. Can systems access and workflow reproduce the authority matrix? 11. Which old rights, forums and access paths will be retired during transition? 12. Which evidence would show that the reset improved speed, quality, control and value?
A missing answer identifies a design or evidence gap. The appropriate response depends on materiality, risk and decision urgency.
16. Conclusion
A fast-growing GCC business needs an operating model that directs enterprise choices while enabling local execution. The design should begin with strategy, value flows and material decisions. Decision rights can then define authority, evidence, consultation, thresholds and accountability. Organisation layers, forums, roles, information and controls should support those rights.
The practical objective is a company that makes material choices at the intended level, with the necessary evidence, within the available decision window, and follows them through to accountable outcomes. A controlled transition protects continuity while the organisation develops the capability and trust required for delegated authority.
References
- OECD. G20/OECD Principles of Corporate Governance 2023. 2023. https://doi.org/10.1787/ed750b30-en
- Capital Market Authority, Saudi Arabia. Corporate Governance Regulations. Current official English version accessed August 2026. https://cma.org.sa/en/RulesRegulations/Regulations/Documents/CorporateGovernanceRegulations1.pdf
- Securities and Commodities Authority, United Arab Emirates. Corporate Governance. Current official resource accessed August 2026. https://www.sca.gov.ae/en/corporate-governance.aspx
- Securities and Commodities Authority, United Arab Emirates. Annual Report 2024. 2025. https://www.sca.gov.ae/assets/download/27cc1e3b/sca-annual-report-english-2024.aspx
- Abu Dhabi Global Market. Companies Regulations 2020 showing the effect of amendments. Current official consolidation accessed August 2026. https://assets.adgm.com/download/assets/Annex%20B%20-%20Companies%20Regulations%202020%20showing%20effect%20of%20amendments.pdf/d4859f6875c311efbaedbea611f5fc3a
- International Organization for Standardization. ISO 37000:2021 Governance of organizations: Guidance. 2021. https://www.iso.org/standard/65036.html
- International Finance Corporation. Corporate Governance Methodology Tools. Current official resource accessed August 2026. https://www.ifc.org/en/what-we-do/sector-expertise/corporate-governance/cg-methodology-tools
- International Finance Corporation. Governance for SME Sustainability and Growth. 2019. https://www.ifc.org/en/insights-reports/2019/governance-for-sme-sustainability-and-growth
- Infrastructure and Projects Authority. Project Routemap: Governance. 2022. https://assets.publishing.service.gov.uk/media/62971fff8fa8f5039927d160/Governance_-_FINAL.pdf
- IFRS Foundation. IFRS 18 Presentation and Disclosure in Financial Statements. Issued 2024. https://www.ifrs.org/issued-standards/list-of-standards/ifrs-18-presentation-and-disclosure-in-financial-statements/
- Financial Reporting Council. UK Corporate Governance Code 2024. 2024. https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/uk-corporate-governance-code/
- Financial Reporting Council. Guidance on Risk Management, Internal Control and Related Financial and Business Reporting. Current official guidance accessed August 2026. https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/guidance-on-risk-management-internal-control-and-related-financial-and-business-reporting/
- Institute of Internal Auditors. Statements of Position: Three Lines Model. 2026. https://www.theiia.org/en/resources/statements-of-position/
- HM Treasury. The Orange Book: Management of Risk, Principles and Concepts. Updated 2026. https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts
- International Organization for Standardization. ISO 37004:2023 Governance of organizations: Governance maturity model, Guidance. 2023. https://www.iso.org/standard/65039.html
About the Author
Chennakeshav Adya is an independent researcher whose work focuses on corporate finance, value creation, private capital and transaction execution. His research translates financial, commercial and operating evidence into decision frameworks for boards, investors and management teams.

