Menu Close

Entity-Level Controls: What They Cover and Why Auditors Start There

Why auditors start at the top: entity-level controls, reliance below, close findings

Entity-level controls operate across the organization and influence the effectiveness of many process-level controls. They include governance, risk assessment, monitoring, information and communication, and aspects of period-end financial reporting.

Auditors begin with entity-level considerations because they shape the risk assessment and the amount of reliance that may be placed on controls throughout the organization. Strong entity-level controls can support a more focused approach. Weak controls at the top can increase risk across multiple processes.

What are entity-level controls?

Entity-level controls are controls that have a pervasive effect across the company or across multiple processes. They help establish how risks are identified, how authority is exercised, how information moves, how performance is monitored, and how financial reporting is governed.

Common examples include:

  • Board and audit-committee oversight of financial reporting and ICFR.
  • Standards of conduct and processes for reporting and investigating concerns.
  • Organizational structure and delegation of authority.
  • The company’s financial reporting risk-assessment process.
  • Monitoring activities that identify control failures.
  • Company-wide policies and communication.
  • Management’s oversight of the period-end financial reporting process.

Why do auditors start with entity-level controls?

PCAOB AS 2201 requires a top-down approach. The auditor begins at the financial statement level, develops an understanding of overall ICFR risks, considers entity-level controls, and then works down to significant accounts, disclosures, relevant assertions, and selected controls.

Some entity-level controls operate at a level of precision that can directly address a risk of material misstatement. Others have an indirect effect by strengthening or weakening the control environment. Auditors evaluate both their nature and their precision before deciding how they affect the broader testing strategy.

How are entity-level and activity-level controls different?

An activity-level control addresses a defined risk within a specific process, account, or transaction stream. Examples include a three-way match, journal-entry approval, or monthly bank reconciliation.

An entity-level control affects the broader organization. Examples include audit-committee oversight, a company-wide risk assessment, whistleblower procedures, or management monitoring of financial performance.

Activity-level controls often have transaction populations that can be sampled. Entity-level controls may require more judgment and a combination of inquiry, inspection, observation, and corroboration. Not every entity-level control is tested in exactly the same way.

What are the main categories of entity-level controls?

Control environment

This includes tone at the top, integrity and ethical values, board oversight, organizational structure, accountability, delegation of authority, and the company’s commitment to attracting and developing competent people.

Risk assessment

The company should have a repeatable process for identifying and assessing financial reporting risks. The assessment should be refreshed when the business changes, including acquisitions, new revenue models, system implementations, restructurings, or changes in key personnel.

Information and communication

People need timely information to perform controls and a credible way to communicate problems upward. Policies, role clarity, reporting channels, and escalation practices are relevant here.

Monitoring

Monitoring determines whether controls continue to operate and whether deficiencies are identified and corrected. Depending on the company’s size and complexity, monitoring may be performed by internal audit, an outsourced provider, management, or another appropriately objective function.

Period-end financial reporting

The period-end process includes consolidation, journal entries, estimates, nonroutine transactions, financial statement preparation, disclosure review, and management oversight. Because these activities often involve significant judgment, the precision and evidence of review are important.

How are entity-level controls tested?

Testing should match the control’s nature and objective. Common procedures include:

  • Inspecting board and audit-committee minutes, policies, risk assessments, organization charts, certifications, and monitoring reports.
  • Interviewing people at different levels and corroborating whether the described process is consistent.
  • Observing meetings or review activities when observation provides relevant evidence.
  • Examining examples of issues identified, escalated, investigated, and resolved.
  • Assessing the precision of management reviews and the evidence of matters challenged.
  • Connecting entity-level conclusions with deficiencies found in process-level testing.

A conclusion should explain why the evidence supports effectiveness. A bare ‘effective’ label is difficult to defend or reuse in a later period.

Where are entity-level controls commonly weak?

  • An important activity occurs, but there is little evidence of what was reviewed or decided.
  • The risk assessment has not been updated after significant business or system changes.
  • Monitoring focuses on established processes and misses emerging or troubled areas.
  • Policies and delegation matrices do not match actual practice.
  • Issues are identified but not escalated, tracked, or resolved consistently.
  • Period-end management reviews lack documented expectations, thresholds, and follow-up.

These are patterns to investigate, not automatic conclusions. Severity depends on the relevant risks, the precision of the control, other controls, and the possible effect on financial reporting.

What changes as a private company prepares to go public?

Many private companies already perform valuable oversight informally. Public-company readiness requires those activities to become repeatable, appropriately governed, and supportable with evidence.

  • Establish appropriate board and audit-committee oversight.
  • Document authority, accountability, and escalation paths.
  • Formalize and periodically refresh the ICFR risk assessment.
  • Define who monitors control performance and deficiencies.
  • Retain evidence of management reviews, challenges, decisions, and follow-up.

The goal is not to create paperwork for its own sake. The goal is to make important control activities visible, repeatable, and assessable by people outside the original conversation.

What is the right order of work?

Assess entity-level controls early enough for the conclusions to inform process scoping and testing. Then revisit the entity-level assessment after process-level testing. Several findings across different processes may reveal a broader monitoring, risk-assessment, or control-environment issue.

That feedback loop prevents the company from treating related symptoms as isolated exceptions and supports remediation aimed at the underlying cause.

Assess entity-level and process-level readiness with A2Q2

FAQ

Are entity-level controls the same as COSO components?

No. COSO’s five components provide a framework for internal control. Entity-level controls are specific controls that may support one or more components across the organization.

Can strong entity-level controls reduce other testing?

They can affect the risk assessment and, in some circumstances, reduce the extent of testing needed for other controls. The effect depends on the control’s precision, the risk addressed, and the evidence of its effectiveness.

Is internal audit required for entity-level monitoring?

Not in every organization. Monitoring needs clear ownership and sufficient objectivity, but the appropriate structure depends on the company’s size, complexity, risks, and governance.

Primary sources

Leave a Reply

Your email address will not be published.

Share This

Copy Link to Clipboard

Copy