Entity-level controls are the controls that operate across the organization rather than inside a single process — the tone at the top, the risk assessment, the monitoring that catches what the process controls miss. They are also the controls most often described in a paragraph and tested with a conversation, which is why they attract more audit attention than their documentation usually deserves.
This guide covers the three kinds of entity-level control, how they map to the COSO principles, why their quality changes how much else has to be tested, and what evidence a tester actually accepts.

The three kinds of entity-level control
| Type | Example | What it can do for the assessment |
|---|---|---|
| Direct / precise | A monthly review of results against budget at a level of detail that would catch a material misstatement | Can address a risk on its own and reduce testing of process controls |
| Indirect | Code of conduct, organizational structure, hiring and competence policies | Affects the reliability of other controls; cannot address a specific risk alone |
| Monitoring | Internal audit, the audit committee’s oversight, self-assessment programmes | Detects failures in other controls; strength influences the extent of other testing |
Precision is the whole distinction. PCAOB AS 2201 requires the auditor to test the entity-level controls that are important to the conclusion on internal control, and notes that some have an important but indirect effect on whether a misstatement would be caught. That evaluation can increase or decrease the testing otherwise performed elsewhere — which is why strong, precise entity-level controls are worth investing in and vague ones are worth nothing at all.
Mapping entity-level controls to the COSO principles
The COSO framework’s five components and 17 principles are the usual structure for organizing them. The control environment principles map almost entirely to entity-level controls; risk assessment and monitoring largely so; information and communication partly; control activities much less, because that is where process-level controls live.
- Control environment — integrity and ethical values, board oversight, structure and authority, competence, accountability.
- Risk assessment — objective setting, risk identification, fraud risk, and assessing changes.
- Information and communication — quality of information, internal communication, external communication.
- Monitoring — ongoing and separate evaluations, and communicating deficiencies.
Our guide to the COSO 17 principles covers each one; the point here is that all 17 principles must be present and functioning for internal control to be effective, and most of them are satisfied by entity-level controls rather than by transaction-level ones.
Testing entity-level controls without hand-waving
- Write down the precision first. What level of error would this control detect, and how do you know? A review that would catch a $5m variance is not evidence over a $200k risk.
- Identify the review criteria. What thresholds trigger investigation, who investigates, and what happens next. “Management reviews the results” describes an activity, not a control.
- Test the exceptions, not the meeting. Minutes prove a meeting happened. The evidence that matters is what was questioned, what the answer was, and what changed.
- Look for the negative. A control that has never raised an exception is either operating in a perfect environment or not operating at all.
- Keep the population defined. Twelve monthly reviews is a population you can sample. “Ongoing oversight” is not.
The evidence problem with soft controls
A code of conduct exists; that is not the control. The control is that it is distributed, acknowledged annually, that violations are reported through a route people trust, and that reported violations are investigated and acted on with a record. Whistleblowing statistics, exit interview themes and disciplinary outcomes are the evidence that an indirect entity-level control is real — and our guide to the whistleblowing policy covers the reporting route in more detail.
Where entity-level controls are over-relied on
Using indirect controls to cover a specific risk. A strong control environment reduces the likelihood of failures broadly; it does not address the risk that a particular reconciliation was not performed.
Assuming scope reduction that was never agreed. The reduction in other testing depends on the auditor’s evaluation, and it is negotiated on evidence — not assumed at planning.
Confusing management review with monitoring. A management review is a control if it has criteria, exceptions and follow-through. Otherwise it is a meeting on the same day each month.
Frequently asked questions
What are entity-level controls?
Controls that operate across the whole organization rather than within one process — governance, the control environment, risk assessment, and monitoring activities that apply to everything beneath them.
Are entity-level controls the same as general IT controls?
No. General IT controls sit at application and infrastructure level over access, change and operations. Some IT governance controls are entity-level; most ITGCs are not.
Can strong entity-level controls reduce SOX testing?
They can reduce the extent of other testing where they are precise enough to address a specific risk. Indirect ones influence the auditor’s judgement without replacing process-level testing. Our guide to SOX 404 covers the wider assessment.
Who owns entity-level controls?
Senior management and the board, in practice. That is what makes them powerful, and also what makes evidence harder to gather than for a process control with a named operator.
How many should we document?
Enough to demonstrate that all 17 COSO principles are present and functioning. More documentation than that dilutes attention from the few controls that carry real weight.
Where this leaves you
Sort your entity-level controls by precision before anything else, because that determines what each one can carry. Document the criteria, thresholds and follow-up for the precise ones and test them like any other control, with a defined population and real exceptions. Treat the indirect ones honestly — they support the environment, they do not cover specific risks — and make sure the monitoring layer actually reports deficiencies to somebody with authority to fix them.
References
- PCAOB AS 2201 — the integrated audit standard, including the treatment of entity-level controls.
- COSO Internal Control — Integrated Framework — the five components and 17 principles.
More on internal control
- Entity-level controls — you are here
- The COSO 17 principles
- The two COSO frameworks
- Segregation of duties
Control matrices, principle mapping and test plans are in the COSO ERM & Internal Control Toolkit, or start with the free ISO templates.