Internal Controls
Entity-Level Controls Assessment
Design and operating effectiveness of pervasive entity-level controls that set the tone from the top.
Why tone at the top is itself a control
Entity-level controls set the conditions in which every transaction-level control operates, and weak ones erode assurance no matter how robust the detailed controls appear. The AGSA and King IV both treat ethical leadership, governance structures and oversight as foundational rather than peripheral. AuditPro Core assesses the design and operating effectiveness of these pervasive controls so the accounting officer can show the tone from the top is real and working.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Controls assessed
48
Operating effectively
39
81%
Design gaps
5
Not effective
4
▲ 1
Entity-level control status by domain
Entity-level control domains
| Domain | Assessed | Effective | Rating |
|---|---|---|---|
| Tone at top | 10 | 9 | Strong |
| Delegations | 10 | 7 | Adequate |
| Policy framework | 10 | 8 | Adequate |
| Oversight bodies | 10 | 8 | Adequate |
| Ethics & values | 9 | 7 | Adequate |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Pervasive controls
Entity-level controls operate across the whole institution rather than over a single process. They include ethics, governance structures, delegations and oversight by those charged with governance.
Design versus operating effectiveness
A control can be well designed yet fail in operation, or operate informally without proper design. Both dimensions must be assessed to conclude on effectiveness.
Tone at the top
The behaviour and integrity modelled by leadership shapes whether lower-level controls are taken seriously. A strong tone makes detailed controls more reliable; a weak one undermines them.
Reliance effect
Strong entity-level controls can justify reduced testing of detailed controls. Weak ones force more substantive work because pervasive risk contaminates everything below.
How AuditPro Core Bridges the Gap
- Dual assessment: each entity-level control is evaluated for both design adequacy and operating effectiveness.
- Evidence linkage: ratings are supported by minutes, policies and delegations held against the control for traceability.
- Exception workflow: deficiencies in pervasive controls escalate quickly given their broad effect.
- Audit-ready export: the assessment supports the control-environment conclusion the AGSA expects.
Key Takeaways
- Entity-level controls underpin every transaction-level control beneath them.
- Assess both design and operating effectiveness; neither alone is conclusive.
- Strong tone at the top makes detailed controls more reliable.
- Weak pervasive controls force more substantive audit work everywhere.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
