Skip to main content
Category: Internal Controls

Entity-Level Control

Also known as: ELC, Entity-level controls, Company-level control
Simply put

An entity-level control is a control that operates across an entire organization rather than at the level of a single transaction or process. It helps ensure that management's directives affecting the whole entity are carried out, and typically includes things like organizational policies, cultural norms, and governance frameworks. Because it applies broadly, it shapes the overall environment in which more specific, process-level controls operate.

Formal definition

An entity-level control (ELC) is a control designed to ensure that management directives pertaining to the entire entity are implemented, operating pervasively across the organization rather than at the individual transaction or account level. ELCs generally encompass policies, principles, cultural norms, and governance frameworks that apply organization-wide, and they typically address elements such as the control environment, management override, risk assessment, centralized processing, monitoring of operations, and period-end financial reporting. Under frameworks such as COSO's Internal Control, Integrated Framework, ELCs support an organization's ability to articulate its purpose and pursue its objectives, and they are frequently assessed in contexts such as SOX compliance where they influence the design and reliance placed on more granular process-level controls. The precise scope, design, and required rigor of ELCs depend on the applicable framework, jurisdiction, entity type, and the professional judgment of those assessing them.

Why it matters

Entity-level controls shape the environment in which every other control operates. Because they apply pervasively across an organization, through policies, cultural norms, and governance frameworks, weaknesses at this level can undermine the reliability of even well-designed process-level controls. A strong control environment, effective risk assessment, and robust monitoring generally reinforce management's ability to ensure that directives affecting the whole entity are actually carried out, while deficient entity-level controls can signal broader systemic risk that granular controls alone cannot compensate for.

In contexts such as SOX compliance, entity-level controls are frequently assessed because they influence how much reliance can be placed on more specific, transaction-level controls. Under frameworks such as COSO's Internal Control, Integrated Framework, effective internal control helps an organization articulate its purpose, set objectives and strategy, and pursue those objectives with greater confidence. The condition of entity-level controls therefore often informs the scope and rigor of testing that assurance functions apply elsewhere in the control structure.

The significance of any particular entity-level control depends on the applicable framework, jurisdiction, entity type, and the judgment of those assessing it. This entry is educational and does not constitute legal, audit, or compliance advice; whether a given control is adequate in a specific situation is a facts-and-circumstances determination for the relevant professionals.

Who it's relevant to

Boards and Audit Committees
Directors exercising oversight generally have an interest in the strength of entity-level controls because they reflect the governance frameworks, tone, and organization-wide policies for which the board sets expectations. The board's role here is typically oversight rather than the design or operation of specific controls, which remains a management responsibility.
Management
Management is generally responsible for designing, implementing, and operating entity-level controls to ensure that its directives affecting the entire entity are carried out. This includes maintaining the control environment, risk assessment processes, and monitoring activities that apply organization-wide.
Internal Audit and Assurance Functions
Internal auditors and other assurance providers frequently assess entity-level controls to understand the pervasive environment and to inform how much reliance can be placed on process-level controls. Their evaluation typically distinguishes control design from operating effectiveness.
SOX and Compliance Teams
In contexts such as SOX compliance, entity-level controls are commonly evaluated because they influence the scope of testing and the reliance placed on more granular financial reporting controls. The required rigor depends on the applicable regime and professional judgment.

Inside ELC

Control Environment
The foundational element addressing the organization's tone at the top, integrity, ethical values, commitment to competence, and the board's oversight of management. Under the COSO framework, this is generally the first and most pervasive component that entity-level controls help operationalize.
Governance and Oversight Structures
Board and committee arrangements, delegations of authority, and reporting lines that establish accountability. These typically operate at the entity level rather than at the level of a specific transaction or process, and the board's oversight duty is distinct from management's operational responsibility for control execution.
Policies, Codes, and Standards
Enterprise-wide policies such as codes of conduct, ethics policies, whistleblower arrangements, and delegation-of-authority frameworks. Some of these may reflect legal requirements in certain jurisdictions or listing regimes, while others are voluntary best practice; the applicable status varies by jurisdiction, sector, and entity type.
Risk Assessment and Monitoring Activities
Organization-wide processes for identifying and assessing risk and for monitoring the functioning of the internal control system, including ongoing evaluations and separate evaluations. These are generally owned by management, with assurance functions providing independent evaluation.
Information, Communication, and Culture
Mechanisms for communicating expectations and control responsibilities across the entity, and the cultural factors that influence how controls operate in practice. Entity-level controls in this area typically set the conditions under which process-level and transaction-level controls function.
Pervasive Nature
A defining characteristic distinguishing entity-level controls from process-level or application controls: they generally affect many processes, locations, and outcomes across the organization rather than a single transaction stream, and a deficiency may have broad implications for the overall control system.

Common questions

Answers to the questions practitioners most commonly ask about ELC.

Are entity-level controls just high-level policies that don't need testing?
No. While entity-level controls often operate at a broad, organization-wide level, such as the control environment, governance structures, and codes of conduct, being high-level does not exempt them from evaluation. Many frameworks, including COSO's Internal Control, Integrated Framework, treat entity-level controls as a component that typically requires assessment of both design and operating effectiveness, though the nature and rigor of that assessment depend on the control's precision and the reliance placed on it. Some entity-level controls are precise enough to be tested directly; others are more pervasive and support, rather than replace, transaction-level testing. The specific expectations vary by framework, regulatory context, and the professional judgment applied to the engagement.
Can strong entity-level controls replace the need for process-level or transaction-level controls?
Generally, no. Entity-level controls and process-level controls typically serve complementary rather than substitutable roles. A strong control environment or effective board oversight can influence the assessed risk and may affect the extent of testing at the process level, but it does not, on its own, address the specific risks of misstatement or failure within individual processes and transactions. The degree to which an entity-level control reduces reliance on lower-level testing depends on how directly and precisely it addresses a given risk. This is a matter of judgment and varies by framework and jurisdiction; this entry is educational and not audit or compliance advice.
How do you identify which entity-level controls are relevant to a given assessment?
Identification generally begins by mapping the objective of the assessment, such as financial reporting reliability, compliance, or broader governance, to the components of an internal control framework in use. Under COSO, this often means considering controls related to the control environment, risk assessment, information and communication, monitoring activities, and certain aspects of control activities that operate entity-wide. Practitioners typically consider governance bodies (board and committee oversight), management's tone and policies, organizational structure, and monitoring mechanisms. Relevance depends on the specific objectives, the entity's size and complexity, its sector, and applicable requirements, so the selection is a matter of professional judgment rather than a fixed checklist.
Who is responsible for designing, operating, and evaluating entity-level controls?
Responsibilities are typically distributed across the lines of accountability. Management generally owns the design and operation of entity-level controls, including the policies, structures, and monitoring activities that make up the control environment. The board and its committees generally provide oversight, for example, an audit committee overseeing the integrity of financial reporting and the internal control system, rather than operating the controls themselves. Assurance functions, such as internal audit, typically provide independent evaluation of design and operating effectiveness, and external auditors may assess relevant entity-level controls where they bear on their engagement objective. The precise allocation depends on the entity's structure and applicable requirements.
How can an entity-level control's design and operating effectiveness be evaluated in practice?
Evaluation generally distinguishes between design effectiveness, whether the control, as designed, would address the relevant risk if it operated as intended, and operating effectiveness, whether it actually operated consistently over the relevant period. In practice, this may involve reviewing documentation such as charters, policies, and meeting records; inquiry of relevant personnel; observation of processes; and, where a control is sufficiently precise, direct testing. Because many entity-level controls are qualitative and pervasive, evidence is often more judgmental than for transaction-level controls. The appropriate approach, evidence, and documentation depend on the framework, the objective, and the practitioner's judgment; this entry does not prescribe a specific methodology.
How should entity-level control deficiencies be assessed and reported?
Assessment of a deficiency in an entity-level control typically considers both its potential effect and its pervasiveness, because these controls can influence multiple processes, a weakness may have broad implications for the reliability of other controls. Frameworks and regulatory regimes generally provide criteria for classifying deficiencies by severity, and the specific terminology and thresholds vary by context. Reporting pathways commonly run to management and, for significant matters, to the board or audit committee, with disclosure obligations depending on the applicable legal and regulatory regime and entity type. The evaluation of severity and any reporting or disclosure requirement is fact-specific and jurisdiction-dependent; professional judgment and, where appropriate, legal or audit advice should be sought.

Common misconceptions

Entity-level controls are just high-level statements that cannot be tested or relied upon for assurance.
While some entity-level controls are indirect and less precise, others can be defined specifically enough to be evaluated for both design and operating effectiveness. Whether a given control can be relied upon depends on its precision and the facts, and requires professional judgment; the distinction between control design and operating effectiveness applies here as elsewhere.
Strong entity-level controls eliminate the need to test process-level or transaction-level controls.
Entity-level controls generally set the environment in which more granular controls operate but do not, on their own, address specific risks at the transaction level. They typically complement rather than replace process and application controls, and the extent of reliance depends on the assessed precision of each control.
Entity-level controls are the board's responsibility to execute.
The board typically holds an oversight role over the control environment, while management generally owns the design and operation of entity-level controls. Attributing operational execution to the board, or oversight duties to management, without qualification misstates where accountability sits under commonly used governance models.

Best practices

Map entity-level controls to a recognized framework such as COSO, being clear about which controls address the control environment, risk assessment, monitoring, information and communication, and control activities, and noting that no single framework is universally mandatory.
Assess the precision of each entity-level control to determine the degree of reliance it can support, and document whether it is being evaluated for design, operating effectiveness, or both.
Clarify accountability by distinguishing the board's oversight role from management's ownership of control design and operation, and from assurance functions' independent evaluation.
Avoid over-relying on entity-level controls as a substitute for process-level and transaction-level controls; use them to complement, not replace, more granular controls where specific risks require it.
Confirm which underlying policies or structures reflect binding legal or listing requirements in the relevant jurisdiction versus voluntary best practice, since this varies by jurisdiction, sector, and entity type.
Reassess entity-level controls periodically, since a deficiency at this level may have pervasive implications across multiple processes and locations, and treat conclusions as matters of professional judgment rather than fixed rules.