Insider Threat Matrix™Insider Threat Matrix™
  • ID: IF044
  • Created: 01st August 2026
  • Updated: 01st August 2026
  • Contributor: The ITM Team

Abuse of Decision-Making Authority

A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.

 

The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.

 

This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.

 

This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right.

Subsections (6)

ID Name Description
IF044.002Improper Denial

A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.

 

Examples include:

  • denying a legitimate customer request because of a personal dispute
  • refusing an employee entitlement in retaliation
  • blocking a supplier or applicant to benefit an associate
  • rejecting an access request despite established eligibility
  • withholding an approval to exert pressure on another individual
IF044.003Improper Preferential Treatment

A subject uses decision-making authority to provide an unauthorized advantage to a person, organization, account, supplier, applicant, or other beneficiary.

 

Examples include:

  • prioritizing an associate’s application outside established criteria
  • granting favorable commercial terms without authorization
  • selecting a supplier because of an undisclosed personal relationship
  • allocating a scarce benefit contrary to the approved process
  • overlooking a requirement for a favored party while enforcing it against others
IF044.004Suppression of Escalation or Review

A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.

 

Examples include:

  • preventing a security concern from being referred to the appropriate team
  • closing a complaint without the required review
  • declining to escalate a report involving an associate
  • directing that an audit finding not be formally recorded
  • narrowing an investigation to exclude relevant conduct or evidence
IF044.001Unauthorized Approval

A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.

 

Examples include:

  • approving access for a favored individual without business justification
  • approving a supplier despite an undisclosed conflict
  • authorizing expenditure outside the intended purpose
  • approving an exception using false or incomplete supporting information

 

The defining evidence is an affirmative decision made through authority legitimately assigned to the subject.

IF044.006Unauthorized Prioritization or Deprioritization

A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.

 

Examples include:

  • moving an associate’s request ahead of others without justification
  • deliberately delaying a complaint until a deadline expires
  • deprioritizing a customer because of a personal disagreement
  • changing case urgency to avoid scrutiny or service obligations
  • accelerating a transaction so that required review cannot occur
IF044.005Unauthorized Waiver or Control Exception

A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.

 

Examples include:

  • waiving identity-verification requirements
  • exempting a transaction from secondary review
  • overriding a mandatory security or compliance check
  • allowing work to proceed despite an unmet control condition
  • approving an exception without recording the required rationale