Entity-Level Control
An entity-level control is a control that operates across an entire organization rather than at the level of a single transaction or process. It helps ensure that management's directives affecting the whole entity are carried out, and typically includes things like organizational policies, cultural norms, and governance frameworks. Because it applies broadly, it shapes the overall environment in which more specific, process-level controls operate.
An entity-level control (ELC) is a control designed to ensure that management directives pertaining to the entire entity are implemented, operating pervasively across the organization rather than at the individual transaction or account level. ELCs generally encompass policies, principles, cultural norms, and governance frameworks that apply organization-wide, and they typically address elements such as the control environment, management override, risk assessment, centralized processing, monitoring of operations, and period-end financial reporting. Under frameworks such as COSO's Internal Control, Integrated Framework, ELCs support an organization's ability to articulate its purpose and pursue its objectives, and they are frequently assessed in contexts such as SOX compliance where they influence the design and reliance placed on more granular process-level controls. The precise scope, design, and required rigor of ELCs depend on the applicable framework, jurisdiction, entity type, and the professional judgment of those assessing them.
Why it matters
Entity-level controls shape the environment in which every other control operates. Because they apply pervasively across an organization, through policies, cultural norms, and governance frameworks, weaknesses at this level can undermine the reliability of even well-designed process-level controls. A strong control environment, effective risk assessment, and robust monitoring generally reinforce management's ability to ensure that directives affecting the whole entity are actually carried out, while deficient entity-level controls can signal broader systemic risk that granular controls alone cannot compensate for.
In contexts such as SOX compliance, entity-level controls are frequently assessed because they influence how much reliance can be placed on more specific, transaction-level controls. Under frameworks such as COSO's Internal Control, Integrated Framework, effective internal control helps an organization articulate its purpose, set objectives and strategy, and pursue those objectives with greater confidence. The condition of entity-level controls therefore often informs the scope and rigor of testing that assurance functions apply elsewhere in the control structure.
The significance of any particular entity-level control depends on the applicable framework, jurisdiction, entity type, and the judgment of those assessing it. This entry is educational and does not constitute legal, audit, or compliance advice; whether a given control is adequate in a specific situation is a facts-and-circumstances determination for the relevant professionals.
Who it's relevant to
Inside ELC
Common questions
Answers to the questions practitioners most commonly ask about ELC.