Back to Explore
⚠️

Internal Controls

Entity-Level Controls Assessment

Design and operating effectiveness of pervasive entity-level controls that set the tone from the top.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why tone at the top is itself a control

Entity-level controls set the conditions in which every transaction-level control operates, and weak ones erode assurance no matter how robust the detailed controls appear. The AGSA and King IV both treat ethical leadership, governance structures and oversight as foundational rather than peripheral. AuditPro Core assesses the design and operating effectiveness of these pervasive controls so the accounting officer can show the tone from the top is real and working.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Controls assessed

48

Operating effectively

39

81%

Design gaps

5

Not effective

4

▲ 1

Entity-level control status by domain

Entity-level control domains

DomainAssessedEffectiveRating
Tone at top109Strong
Delegations107Adequate
Policy framework108Adequate
Oversight bodies108Adequate
Ethics & values97Adequate

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Pervasive controls

Entity-level controls operate across the whole institution rather than over a single process. They include ethics, governance structures, delegations and oversight by those charged with governance.

Design versus operating effectiveness

A control can be well designed yet fail in operation, or operate informally without proper design. Both dimensions must be assessed to conclude on effectiveness.

Tone at the top

The behaviour and integrity modelled by leadership shapes whether lower-level controls are taken seriously. A strong tone makes detailed controls more reliable; a weak one undermines them.

Reliance effect

Strong entity-level controls can justify reduced testing of detailed controls. Weak ones force more substantive work because pervasive risk contaminates everything below.

How AuditPro Core Bridges the Gap

  • Dual assessment: each entity-level control is evaluated for both design adequacy and operating effectiveness.
  • Evidence linkage: ratings are supported by minutes, policies and delegations held against the control for traceability.
  • Exception workflow: deficiencies in pervasive controls escalate quickly given their broad effect.
  • Audit-ready export: the assessment supports the control-environment conclusion the AGSA expects.

Key Takeaways

  • Entity-level controls underpin every transaction-level control beneath them.
  • Assess both design and operating effectiveness; neither alone is conclusive.
  • Strong tone at the top makes detailed controls more reliable.
  • Weak pervasive controls force more substantive audit work everywhere.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.