Skip to main content
Promotional banner for the pentest readiness checklist
Category: Internal Controls & Audit

Entity-Level Controls

Also known as: ELC, Entity-Level Control, Company-Level Controls
Simply put

Entity-level controls are the broad policies, rules, cultural norms, and governance structures that apply across an entire organization rather than to a single transaction or process. They help ensure that management's directives for the whole entity are actually carried out, often by setting the overall 'tone' and expectations for how the organization operates. Examples typically include the board's oversight practices, the organization's ethical standards, and its approach to assessing risk.

Formal definition

Entity-level controls (sometimes called company-level controls) are controls operating at the level of the whole organization that help ensure management directives pertaining to the entire entity are carried out. They commonly encompass the control environment, controls addressing management override, the entity's risk assessment process, controls over centralized or shared processing, and monitoring activities, as well as governance frameworks, policies, and standards of behavior applicable to the board and senior management. In a SOX compliance context they are frequently evaluated as part of assessing internal control over financial reporting, though their nature is often pervasive and indirect, meaning they may influence, rather than directly operate at, the transaction level. The precise scope and classification of entity-level versus process-level controls can be context-dependent and should be assessed against the applicable framework and engagement objectives.

Why it matters

Entity-level controls matter because they shape the environment in which every other control operates. Where process-level controls address specific transactions or activities, entity-level controls set the organization-wide expectations, governance structures, and cultural norms that determine whether management's directives are actually carried out across the whole entity. A weak control environment at the top can undermine even well-designed process controls, while strong entity-level controls can reinforce and, in some cases, compensate for gaps at the transaction level.

In a SOX compliance context, entity-level controls are frequently evaluated as part of assessing internal control over financial reporting. Because they are often pervasive and indirect, influencing rather than directly operating at the transaction level, they can be more difficult to test than discrete process controls, yet they carry significant weight in an overall assessment of control effectiveness. Elements such as board oversight, the entity's risk assessment process, monitoring activities, and controls addressing management override are commonly examined, since deficiencies in these areas can have broad implications.

Because the classification of entity-level versus process-level controls can be context-dependent, organizations should assess scope against the applicable framework and engagement objectives rather than assuming a fixed boundary. The relative emphasis placed on entity-level controls typically varies by jurisdiction, sector, and the size and complexity of the organization.

Who it's relevant to

Internal Auditors
Internal auditors frequently evaluate entity-level controls when assessing the overall effectiveness of an organization's internal control system. Because these controls are often pervasive and indirect, auditors typically consider how they influence process-level controls and how deficiencies at the entity level might affect broader control conclusions.
Compliance Officers
In a SOX context, compliance and financial reporting teams often assess entity-level controls as part of evaluating internal control over financial reporting. This includes examining the control environment, the risk assessment process, monitoring activities, and controls addressing management override, with scope determined by the applicable framework.
Boards and Senior Management
Entity-level controls commonly include standards of behavior and oversight practices that apply directly to the board of directors and senior management. These individuals set the organization's tone and governance expectations, and their oversight activities are themselves often a subject of entity-level control assessment.
Risk Managers
Because the entity's risk assessment process is commonly treated as an entity-level control, risk managers have a direct interest in how these controls are designed and monitored across the organization, and in how they interact with process-level activities.

Inside ELC

Control Environment
The foundational tone-setting elements of an organization, often encompassing the integrity, ethical values, and governance oversight established by the board and senior management. In frameworks such as the COSO Internal Control Integrated Framework, the control environment is typically treated as pervasive and influential over all other components.
Governance and Oversight Structures
The roles, committees, and decision rights, such as board and audit committee oversight, through which the organization is directed and controlled. These entity-level elements shape accountability but are distinct from the specific transactional or process-level controls they oversee.
Organization-Wide Policies and Codes
Broad policies, codes of conduct, and standards that apply across the entity rather than to a single process. These often express management's expectations regarding ethics, compliance, and risk, though their effectiveness typically depends on how they are communicated and enforced.
Communication and Information Flows
Mechanisms by which relevant information is captured and communicated across the organization, including channels for raising concerns. In many frameworks these support the functioning of more granular controls.
Monitoring Activities
Ongoing and separate evaluations that assess whether components of internal control are present and functioning at an organizational level, which may inform escalation and remediation.
Human Resources and Competence Practices
Entity-level practices relating to attracting, developing, and retaining competent individuals and holding them accountable, which can influence the reliability of controls throughout the organization.

Common questions

Answers to the questions practitioners most commonly ask about ELC.

Are entity-level controls the same as company-wide policies documents?
Not exactly. While written policies can be an expression of entity-level controls, the term refers more broadly to controls that operate across an organization to influence how objectives are pursued and how other controls function, such as the control environment, governance oversight, risk assessment processes, and monitoring activities. A policy document alone does not constitute an entity-level control unless it is actually operating and influencing behavior. Treating the existence of a document as equivalent to a functioning control is a common misconception; the control's design and operating effectiveness are what matter.
Do strong entity-level controls mean transaction-level or process-level controls are unnecessary?
No. Entity-level controls typically operate at a higher, more pervasive level and often influence the effectiveness of more granular controls, but they generally do not replace them. In many control frameworks, some entity-level controls are too indirect to prevent or detect a specific misstatement or failure on their own. Process-level and transaction-level controls address risks at a level of precision that entity-level controls usually cannot. The two are often viewed as complementary rather than substitutes, and reliance on entity-level controls without adequate lower-level controls can leave specific risks inadequately addressed.
How do we identify which of our controls qualify as entity-level controls?
A common approach is to consider whether a control operates pervasively across the organization and influences multiple processes, objectives, or other controls, rather than addressing a single transaction or process. Controls associated with the control environment, governance and board oversight, organization-wide risk assessment, information and communication, and monitoring activities are frequently classified this way. Because classification can be context-dependent, organizations often document their rationale and align it with the framework they have adopted. Where classification is ambiguous, it is advisable to be explicit about the reasoning rather than assume a single correct answer.
How can entity-level controls be tested for operating effectiveness?
Testing approaches vary with the nature and precision of the control. Some entity-level controls are more direct and can be tested through inspection of evidence, reperformance, or observation, while others, such as aspects of tone at the top or the control environment, are more qualitative and may be assessed through inquiry, review of governance records, surveys, or corroborating evidence. Because some entity-level controls are indirect, evaluators often consider what a given control can and cannot demonstrate on its own. The appropriate methods and sufficiency of evidence depend on the framework applied and the judgment of those performing the evaluation.
What is the relationship between entity-level controls and management's or an external assessment of the control system?
Entity-level controls are often considered early in an assessment because they can affect the scope, nature, and extent of testing of other controls. Where entity-level controls are assessed as effective, some approaches may allow reduced testing elsewhere, whereas weaknesses at the entity level can have pervasive implications across the control system. The precise weight given to entity-level controls in any formal assessment depends on the applicable framework, regulatory context, and professional judgment, and organizations subject to specific regulatory regimes should confirm requirements against the relevant primary sources.
How should deficiencies in entity-level controls be evaluated and remediated?
Because entity-level controls can be pervasive, a deficiency at this level may have broader implications than a deficiency in a single process control, potentially affecting confidence in multiple areas. Evaluation typically considers the significance of the control, the potential effect on objectives, and whether compensating controls exist. Remediation often addresses root causes, such as governance structures, risk assessment processes, or the control environment, rather than isolated symptoms. The severity classification and required response can vary by framework and, in regulated contexts, by applicable requirements, so specifics should be confirmed against the relevant standards and, where appropriate, with professional advice.

Common misconceptions

Entity-level controls are a substitute for process-level or transactional controls.
They typically operate at different levels and serve complementary purposes. Entity-level controls often set the environment and oversight within which more granular controls function, but in many frameworks they generally do not, on their own, address specific transaction-level risks. Effective internal control commonly relies on both.
Because entity-level controls are broad, they cannot be tested or evaluated.
Many entity-level controls can be assessed, though the approach often differs from testing a discrete transactional control. Evaluation frequently involves inquiry, observation, and review of governance and policy evidence, and the degree of precision varies by the specific control.
Strong entity-level controls guarantee compliance or eliminate risk.
No control eliminates risk or guarantees an outcome. Entity-level controls may reduce the likelihood or impact of certain failures and support a sound control environment, but residual risk typically remains, and their effectiveness depends on consistent operation over time.

Best practices

Map entity-level controls to the components of a recognized framework, such as the COSO Internal Control Integrated Framework, to identify where oversight, policy, and monitoring elements exist and where gaps may remain.
Distinguish clearly in documentation between entity-level controls and the process-level controls they influence, so that reliance placed on each is transparent and defensible.
Define how each entity-level control will be evaluated, for example through inquiry, observation, or review of governance evidence, recognizing that these controls often operate at a lower level of precision than transactional controls.
Ensure governance and oversight bodies, such as the board and audit committee, have clearly documented roles and decision rights so that entity-level accountability is unambiguous.
Communicate organization-wide policies and codes effectively and monitor their operation over time, since documented policies typically depend on consistent enforcement to be effective.
Confirm that applicability of any related regulatory obligations is assessed against the organization's jurisdiction, sector, and size, and seek professional advice where legal interpretation is required.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps