Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Board Resolution
Governance, Ownership & Risk

Board Resolution

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Governance, Ownership & Risk

A board resolution is formal corporate approval that authorises a named person or action on behalf of the company. In KYC, it provides evidence that a representative has legitimate signing or operational authority. It is especially important when onboarding entities with delegated decision making or restricted corporate controls.

What a board resolution does

A board resolution is the company’s formal way of recording authorisation. It establishes that a named person, committee, or action has been approved by the board, which makes the decision easier to verify, audit, and rely on in operational settings.

In practice, the value of a resolution is not just documentary formality. It creates a traceable link between corporate governance and execution, so banks, counterparties, auditors, and internal control teams can confirm that a representative acted within approved authority.

Where board resolutions are used

Board resolutions appear wherever a company must prove delegated authority: opening or changing accounts, appointing signatories, approving filings, authorising contracts, or permitting a representative to act for the entity. In KYC and onboarding, they are often used to show that the person presenting documents is not acting informally or by assumption.

They are especially important when corporate control is concentrated, when decision making is delegated, or when signing rights are limited to specific officers. In those cases, the resolution is part of the evidence chain that connects the entity’s internal approval process to the external action being requested.

Why the document quality matters

A board resolution is only as useful as its clarity and authenticity. It should identify the company, state the approved action, name the authorised person or role, and show that the approval came from the proper governing body. Ambiguous wording can create disputes about scope, timing, or who was actually empowered to act.

Because it is relied on as evidence of authority, weak document controls can lead to onboarding delays, rejected instructions, or acceptance of an invalid representative. That is why organisations often pair the resolution with supporting corporate records, such as company registry details, director lists, or signature authorities.

How board resolutions fit corporate control

Board resolutions sit at the intersection of governance and execution. They do not grant authority by themselves in the abstract, but they are the formal record that the company has approved a specific authority path. That makes them useful for internal accountability and for external parties that need a defensible basis to act.

The practical takeaway is that a resolution should be treated as an authority record, not a generic letter. When it is precise, current, and aligned with the action being requested, it reduces ambiguity across legal, operational, and onboarding workflows.

Risk and Threat Considerations

Board resolutions can be abused or misapplied when a company relies on outdated, forged, incomplete, or overly broad authority records. The main risk is that an unauthorised person may be treated as legitimate, or that a legitimate person may exceed the authority actually approved.

Failure mechanism: control failure occurs when the resolution does not match the current corporate structure, is not properly verified, or is used outside its intended scope, allowing invalid corporate action to proceed.

Impact: the result can be account misuse, unauthorised onboarding, improper contract execution, delayed remediation, legal disputes, or downstream fraud exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextBoard resolutions document who is authorised to act for the organisation.
Recommendation — Define authority records so corporate approvals align with organisational roles and decision rights.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeResolutions should limit actions to the specific authority approved.
Recommendation — Restrict delegated actions to the minimum authority stated in the board resolution.
ISO/IEC 27001:2022A.5.15 — Access controlBoard resolutions help evidence who may approve or perform controlled actions.
Recommendation — Maintain documented approval authority for actions that affect access or control.
CIS Controls v8CIS-6 — Access Control ManagementThe term supports governance over who can act on behalf of the company.
Recommendation — Verify that delegated authority matches the organisation's approved access control model.

Practitioner Guidance

Why practitioners should care: Treat board resolutions as part of the evidence chain for authority, not as a box-checking attachment. The key question is whether the document clearly supports the exact action being requested and whether that approval is still current.

What to watch for: Pay close attention to vague authorisation language, stale dates, mismatched signatory names, and resolutions that approve a broad class of actions without a clear boundary. Those are the situations most likely to create operational friction or control failure.

Practitioner takeaway: A good resolution should be specific enough that another reviewer can understand exactly who may act, what they may do, and on whose behalf they may do it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org