Entity-Level Controls
Entity-level controls are the policies, principles, cultural norms, and governance structures that apply across an entire organization rather than to a single transaction or process. They help ensure that direction set by management and the board is carried out consistently throughout the organization. Examples commonly include the control environment, the tone set by leadership, and organization-wide monitoring activities.
Entity-level controls are controls that operate pervasively across an organization to help ensure that management directives pertaining to the entire entity are carried out, in contrast to process-, transaction-, or application-level controls that address specific activities. In many financial reporting and internal control frameworks they encompass elements such as the control environment, management's risk assessment process, controls to address management override, centralized or shared processing controls, monitoring of controls, controls over the period-end financial reporting process, and self-assessment programs. Some entity-level controls operate indirectly by influencing the effectiveness of other controls, while others may be precise enough to detect or prevent misstatements on their own; the extent to which an entity-level control provides direct assurance varies with its design and specificity. This entry does not address implementation specifics, tooling, or the design of particular control activities.
Why it matters
Entity-level controls matter because they shape the environment in which all other controls operate. When leadership sets a credible tone at the top, defines clear governance structures, and maintains organization-wide monitoring, individual process- and transaction-level controls are more likely to function as intended. Conversely, weaknesses at the entity level, such as an ineffective control environment or an inadequate risk assessment process, can undermine the reliability of otherwise well-designed process controls, because those controls depend on the broader governance and cultural framework to be sustained.
In financial reporting contexts, entity-level controls are a central consideration when management and auditors evaluate internal control over financial reporting. Some entity-level controls, such as those addressing the risk of management override, are important precisely because they target risks that process-level controls are poorly positioned to catch. The extent to which any given entity-level control provides direct assurance varies with its design and specificity: some operate indirectly by influencing the effectiveness of other controls, while others may be precise enough to detect or prevent misstatements on their own.
Who it's relevant to
Inside ELC
Common questions
Answers to the questions practitioners most commonly ask about ELC.
