Entity-Level Controls
Entity-level controls are the broad policies, rules, cultural norms, and governance structures that apply across an entire organization rather than to a single transaction or process. They help ensure that management's directives for the whole entity are actually carried out, often by setting the overall 'tone' and expectations for how the organization operates. Examples typically include the board's oversight practices, the organization's ethical standards, and its approach to assessing risk.
Entity-level controls (sometimes called company-level controls) are controls operating at the level of the whole organization that help ensure management directives pertaining to the entire entity are carried out. They commonly encompass the control environment, controls addressing management override, the entity's risk assessment process, controls over centralized or shared processing, and monitoring activities, as well as governance frameworks, policies, and standards of behavior applicable to the board and senior management. In a SOX compliance context they are frequently evaluated as part of assessing internal control over financial reporting, though their nature is often pervasive and indirect, meaning they may influence, rather than directly operate at, the transaction level. The precise scope and classification of entity-level versus process-level controls can be context-dependent and should be assessed against the applicable framework and engagement objectives.
Why it matters
Entity-level controls matter because they shape the environment in which every other control operates. Where process-level controls address specific transactions or activities, entity-level controls set the organization-wide expectations, governance structures, and cultural norms that determine whether management's directives are actually carried out across the whole entity. A weak control environment at the top can undermine even well-designed process controls, while strong entity-level controls can reinforce and, in some cases, compensate for gaps at the transaction level.
In a SOX compliance context, entity-level controls are frequently evaluated as part of assessing internal control over financial reporting. Because they are often pervasive and indirect, influencing rather than directly operating at the transaction level, they can be more difficult to test than discrete process controls, yet they carry significant weight in an overall assessment of control effectiveness. Elements such as board oversight, the entity's risk assessment process, monitoring activities, and controls addressing management override are commonly examined, since deficiencies in these areas can have broad implications.
Because the classification of entity-level versus process-level controls can be context-dependent, organizations should assess scope against the applicable framework and engagement objectives rather than assuming a fixed boundary. The relative emphasis placed on entity-level controls typically varies by jurisdiction, sector, and the size and complexity of the organization.
Who it's relevant to
Inside ELC
Common questions
Answers to the questions practitioners most commonly ask about ELC.

