Skip to main content
Category: Controls Management

Entity-Level Controls

Also known as: ELC, entity-level control, company-level controls
Simply put

Entity-level controls are the policies, principles, cultural norms, and governance structures that apply across an entire organization rather than to a single transaction or process. They help ensure that direction set by management and the board is carried out consistently throughout the organization. Examples commonly include the control environment, the tone set by leadership, and organization-wide monitoring activities.

Formal definition

Entity-level controls are controls that operate pervasively across an organization to help ensure that management directives pertaining to the entire entity are carried out, in contrast to process-, transaction-, or application-level controls that address specific activities. In many financial reporting and internal control frameworks they encompass elements such as the control environment, management's risk assessment process, controls to address management override, centralized or shared processing controls, monitoring of controls, controls over the period-end financial reporting process, and self-assessment programs. Some entity-level controls operate indirectly by influencing the effectiveness of other controls, while others may be precise enough to detect or prevent misstatements on their own; the extent to which an entity-level control provides direct assurance varies with its design and specificity. This entry does not address implementation specifics, tooling, or the design of particular control activities.

Why it matters

Entity-level controls matter because they shape the environment in which all other controls operate. When leadership sets a credible tone at the top, defines clear governance structures, and maintains organization-wide monitoring, individual process- and transaction-level controls are more likely to function as intended. Conversely, weaknesses at the entity level, such as an ineffective control environment or an inadequate risk assessment process, can undermine the reliability of otherwise well-designed process controls, because those controls depend on the broader governance and cultural framework to be sustained.

In financial reporting contexts, entity-level controls are a central consideration when management and auditors evaluate internal control over financial reporting. Some entity-level controls, such as those addressing the risk of management override, are important precisely because they target risks that process-level controls are poorly positioned to catch. The extent to which any given entity-level control provides direct assurance varies with its design and specificity: some operate indirectly by influencing the effectiveness of other controls, while others may be precise enough to detect or prevent misstatements on their own.

Who it's relevant to

Internal auditors
Internal auditors assess the design and operating effectiveness of entity-level controls as part of evaluating an organization's overall control framework. Distinguishing entity-level controls from process-level controls helps auditors scope their work and identify where pervasive weaknesses could affect multiple downstream controls. Consistent with assurance independence, this evaluation is an assessment of controls that management owns, not a substitute for management's own control responsibilities.
Boards of directors and senior management
The board and senior management are responsible for setting the tone at the top and establishing the governance structures, policies, and standards of behavior that constitute many entity-level controls. Their direction shapes the control environment and the organization-wide monitoring that other controls depend upon.
Compliance and financial reporting teams
Teams responsible for internal control over financial reporting rely on entity-level controls such as the control environment, the risk assessment process, controls addressing management override, and controls over the period-end financial reporting process. Understanding which of these provide direct versus indirect assurance informs how they document and evaluate the control framework.
External auditors
External auditors consider entity-level controls when evaluating internal control over financial reporting, because these controls influence the reliability of process- and transaction-level controls. The degree of direct assurance an entity-level control provides, which varies with its design and specificity, affects how auditors plan and rely on it. This activity is an independent assessment, distinct from management's operation of the controls.

Inside ELC

Control Environment Elements
Entity-level controls commonly encompass the organization's control environment, including the tone at the top, integrity and ethical values, and the board's oversight responsibilities. These elements set the overall attitude toward internal control across the organization.
Governance and Oversight Structures
This includes the roles and responsibilities of the board, audit committee, and senior management in directing and monitoring the internal control system. These structures reflect the governance pillar by establishing decision rights and accountability.
Policies and Standards at the Organizational Level
Enterprise-wide policies, codes of conduct, and standards that establish expectations applicable across the entity, as distinct from transaction-specific or process-level procedures.
Risk Assessment Processes
Organization-wide mechanisms for identifying and assessing risks to objectives, which inform how controls are designed and prioritized. This links entity-level controls to the risk management pillar.
Monitoring Activities
Ongoing and separate evaluations that assess whether components of internal control are present and functioning, including management's monitoring and communication of deficiencies.
Pervasive or Indirect Nature
Entity-level controls typically operate broadly across the organization rather than at the individual transaction level, and their effect on specific assertions is often indirect. This distinguishes them from process-level or transaction-level controls.

Common questions

Answers to the questions practitioners most commonly ask about ELC.

Are entity-level controls the same as high-level policies that don't really affect day-to-day operations?
No. Entity-level controls are not merely aspirational statements. While they operate at a broad organizational level, covering areas such as the control environment, governance, risk assessment processes, and monitoring, they can have a direct and pervasive effect on how transaction-level controls function. Some entity-level controls are precise enough to prevent or detect specific misstatements, while others operate more indirectly by shaping the environment in which other controls operate. Treating them as disconnected from operations understates their influence.
Do strong entity-level controls mean an organization can rely less on transaction-level or process-level controls?
Not automatically. Entity-level controls and process-level controls address different layers and are generally complementary rather than substitutes. A strong control environment may reduce the extent of testing needed at the process level in some assessment approaches, but pervasive entity-level controls typically do not, on their own, prevent or detect specific errors in individual transactions. The degree of reliance depends on how directly a given entity-level control operates and on the assessment framework applied.
How do you identify which entity-level controls exist within an organization?
Identification commonly begins by examining the broad components that shape governance and control across the organization, such as the tone set by leadership, organizational structure and assignment of authority, codes of conduct, risk assessment processes, and monitoring activities. Practitioners often map these against a recognized framework's components to locate controls that operate organization-wide rather than at a single process. The specifics vary by organization size, structure, and the framework in use.
How can the effectiveness of entity-level controls be evaluated when they are less tangible than transaction controls?
Because many entity-level controls are qualitative, evaluation often combines inquiry, observation, and inspection of supporting evidence rather than testing a sample of transactions. Assessors may review documentation of governance activities, board and committee minutes, communications, and evidence that monitoring occurred. Judgment plays a larger role than in process-level testing. The appropriate methods depend on the nature of the specific control and the assurance or management purpose of the evaluation.
How do entity-level controls relate to the three lines model?
Entity-level controls can be designed, operated, or overseen across the lines. Management functions typically own and operate many of them; risk and compliance functions may support their design and monitoring; and internal audit may provide independent assurance over their effectiveness. Maintaining the independence and objectivity distinctions of assurance functions remains important, so the function evaluating an entity-level control should generally not be the same one that owns it.
How should deficiencies in entity-level controls be assessed and reported?
Because of their pervasive nature, a deficiency in an entity-level control may have implications beyond a single process and can affect the assessed reliability of related controls. Assessment commonly considers the potential effect on other controls and the likelihood and magnitude of resulting issues. Severity classification and reporting expectations vary by framework, jurisdiction, and whether the assessment supports management representations or external assurance, so applicable requirements should be confirmed in context.

Common misconceptions

Entity-level controls and process-level controls are interchangeable, so strong entity-level controls remove the need to test transaction-level controls.
Entity-level controls typically operate pervasively and often affect assertions indirectly, whereas process-level controls operate at the transaction level. In many frameworks, strong entity-level controls may influence the nature and extent of process-level testing but generally do not eliminate the need to evaluate controls that directly address specific risks or assertions.
Entity-level controls are an assurance function, equivalent to what internal audit performs.
Entity-level controls are part of management's internal control system, not an independent assurance activity. Auditing or evaluating those controls is a separate activity performed by assurance functions; the distinction between the controls themselves and the independent evaluation of them should be maintained.
Effective entity-level controls guarantee that misstatements or compliance failures will not occur.
Entity-level controls can reduce the likelihood and impact of failures but do not guarantee outcomes. Like all internal controls, they are subject to inherent limitations such as management override, human error, and collusion.

Best practices

Clearly document how each entity-level control relates to organizational objectives and risks, distinguishing controls that operate pervasively from those addressing specific transactions or assertions.
Ensure the board and audit committee's oversight responsibilities are defined and evidenced, so that governance-level controls are demonstrable rather than assumed.
Map entity-level controls to the risk assessment process so that changes in the organization's risk profile inform whether existing controls remain appropriate.
Maintain the independence of assurance functions when evaluating entity-level controls, keeping the evaluation activity separate from the management activities that design and operate those controls.
Establish monitoring activities that identify and communicate control deficiencies to appropriate levels of management and governance on a timely basis.
Where entity-level controls are relied upon to reduce process-level testing, document the rationale and retain evidence supporting that judgment, recognizing that reliance depends on the nature and precision of the control.
Application Security Isn’t Optional Anymore.