Sarbanes-Oxley Act of 2002 (SOX)

· About Sarbanes-Oxley Act of 2002 (SOX)

Key Takeaways

  • Sarbanes-Oxley Act of 2002 applies primarily to U.S. public companies, their officers and directors, auditors, and certain broker-dealers, and it requires accurate financial reporting, internal control over financial reporting, and record-retention controls.
  • Section 404(b) requires an external auditor attestation on management’s assessment of internal control over financial reporting for most accelerated and large accelerated filers, while non-accelerated filers and many emerging-growth or smaller reporting companies remain exempt unless their status changes.
  • The SEC enforces the securities-law reporting provisions, and the PCAOB oversees audit firms that audit public companies; criminal enforcement can also arise through the Department of Justice for willful violations and fraud.
  • SOX has no major 2025–2026 statutory amendment enacted in the materials reviewed, but the SEC and PCAOB have active rulemaking affecting audit and filer-status thresholds that may change SOX compliance scope if finalized.
  • Violations can trigger SEC enforcement, PCAOB disciplinary action, delisting risk, civil liability, and criminal penalties, including fines and imprisonment for certifying false reports or destroying records.
  • Companies that rely on SOX-compliant controls typically map them to ISO 27001, NIST CSF 2.0, and ISO 42001 for evidence management, control testing, cyber resilience, and AI governance where systems support financial reporting.

What It Is

The Sarbanes-Oxley Act of 2002 (SOX) is a U.S. federal statute enacted after major accounting scandals to strengthen corporate governance, improve the reliability of public-company financial reporting, and increase accountability for executives, auditors, and records management. Congress enacted it as Public Law 107-204 on 30 July 2002; it is enforced mainly through the Securities and Exchange Commission (SEC) for issuer disclosure rules and the Public Company Accounting Oversight Board (PCAOB) for audit-firm oversight.[2][3]

SOX did not become fully operational on one date; its main provisions phased in through SEC and PCAOB rulemaking, including auditor independence rules, internal-control reporting requirements, and document-retention obligations. The core framework has remained in force, while later SEC and PCAOB actions have adjusted implementation details and exemptions; the current review found no enacted 2025–2026 amendment to SOX itself, but there are active proposals and standards changes affecting compliance scope and audit practice.[1][4][5]

Who Must Comply

SOX applies most directly to issuers with securities registered under the Exchange Act, especially public companies filing periodic reports with the SEC, their chief executive and chief financial officers, officers and directors, and their independent auditors. It also reaches audit committees of listed companies, registered public accounting firms, and, for certain provisions, broker-dealers and their recordkeeping systems.[1][2][3]

The broadest operational obligations fall on public companies subject to SEC reporting rules, but the internal-control attestation requirement in Section 404(b) does not apply equally to all filers. Smaller reporting companies and non-accelerated filers are generally exempt from auditor attestation unless they cross filer thresholds or lose exempt status, and SEC proposals in 2026 have considered raising the public-float threshold for large accelerated filer status from $700 million to $2 billion, which would further narrow the population subject to 404(b) if finalized.[5][9]

SOX also has extraterritorial impact where a non-U.S. company is SEC-registered and files as a foreign private issuer or otherwise falls within SEC reporting obligations. Exemptions are statutory and rule-based rather than universal: private companies with no SEC reporting obligations are generally outside SOX, though they may be affected indirectly through financing covenants, acquisition diligence, or customer requirements.[1][2]

Core Requirements

  1. Management certification of reports: The CEO and CFO must certify the accuracy and completeness of periodic reports and the effectiveness of disclosure controls and procedures, and knowingly false certification can support civil and criminal liability.[1][3]
  2. Internal control over financial reporting: Public companies must design, document, test, and maintain effective ICFR so management can assess whether controls materially affect financial reporting, with annual reporting expectations and remediation of material weaknesses.[1][5]
  3. Auditor attestation for covered filers: Companies subject to Section 404(b) must obtain an independent auditor’s attestation of management’s ICFR assessment, and this requirement is a major cost and scope driver for compliance teams.[1][5][9]
  4. Audit committee independence and authority: Listed issuers must have an independent audit committee that appoints, compensates, and oversees the external auditor and establishes complaint and whistleblower-related processes.[1][3]
  5. Document retention and destruction controls: Companies and their agents must preserve audit and review workpapers and relevant records, and unlawful destruction or concealment of records can trigger criminal penalties.[1][3]
  6. Off-book transactions and financial transparency: SOX restricts misleading disclosures and requires accurate presentation of liabilities, related-party matters, and off-balance-sheet arrangements in financial reporting.[1][3]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | SOX enacted | 30 July 2002 | Public Law 107-204 became effective framework for U.S. corporate governance and reporting reforms.[2] | | PCAOB established | 30 July 2002 | Oversight body for auditors of public companies created under SOX.[1][3] | | Current PCAOB budget/support-fee approval cycle | 22 January 2026 | SEC approved PCAOB 2026 budget and accounting support fee under SOX Section 109.[3][13] | | PCAOB QC 1000 effective date | 15 December 2026 | New audit-firm quality-control standard and related audit-standard amendments are scheduled to take effect, subject to any further change.[1] |

Maximum fines and sanctions: SOX authorizes substantial civil enforcement, bar orders, disgorgement, officer-and-director bars, and delisting consequences through SEC and exchange actions; criminal provisions can reach imprisonment and monetary penalties for willful false certification, destruction of records, and fraud. The statute’s well-known criminal exposure includes fines and prison terms for certifying false filings and altering or destroying documents to impede investigations or audits.[1][3]

How to Comply

  1. Map the filing perimeter and filer status: Confirm whether each legal entity is an SEC reporting issuer, foreign private issuer, subsidiary with roll-up obligations, or exempt entity, and track accelerated, non-accelerated, smaller reporting company, and emerging-growth status each quarter.
  2. Build an ICFR control library: Document entity-level controls, process controls, IT general controls, access controls, change management, segregation of duties, and financial-close controls in a single control matrix aligned to significant accounts and assertions.
  3. Test, remediate, and evidence controls continuously: Run periodic walkthroughs, design tests, operating-effectiveness tests, and remediation validation so management can support the annual ICFR assessment and auditor review.
  4. Align cyber and identity controls to reporting risk: Use ISO 27001 and NIST CSF 2.0 to strengthen access management, logging, backup, incident response, and vendor oversight where failures could affect the integrity of financial reporting systems.
  5. Govern AI and automation in the reporting stack: Where AI tools assist forecasting, consolidation, journal-entry analysis, or close workflows, apply ISO 42001-style governance, approval, traceability, and human review so outputs remain explainable and auditable.
  6. Harden records retention and legal holds: Maintain retention schedules, litigation hold procedures, immutable storage for key records, and deletion controls across email, collaboration tools, ERP logs, and audit workpapers.
  7. Prepare for the external audit early: Pre-clear management’s control testing, evidence packages, deficiency assessments, and remediation plans so the auditor can rely on well-governed documentation and avoid late-cycle surprises.
  8. Monitor rulemaking and filer-threshold changes: Track SEC and PCAOB developments on attestation exemptions, quality-control standards, and audit requirements, because 2026 proposals could materially change which issuers are in scope.[5][9]

Related Regulations

  • Dodd-Frank Act: It amended parts of the securities-law framework and added whistleblower incentives that reinforce SOX compliance and audit reporting, but it did not replace SOX’s core ICFR regime.[2]
  • Exchange Act reporting rules: SOX sits on top of the periodic-reporting system under the Securities Exchange Act of 1934, so violations often arise as reporting failures under both regimes.
  • FCPA: The Foreign Corrupt Practices Act overlaps with SOX on books-and-records accuracy and internal accounting controls, but FCPA targets bribery and foreign-corruption conduct more directly.
  • GDPR: GDPR can conflict operationally with SOX retention and preservation obligations because one regime favors minimization while the other can require retention and legal holds for audit evidence and investigations.
  • EU Corporate Sustainability Reporting Directive: CSRD is broader on sustainability disclosure and assurance, and multinational groups may need one evidence architecture for both SOX financial controls and CSRD reporting controls.

FAQ

Does SOX apply to companies outside the United States?

Yes, if a non-U.S. company is SEC-registered or otherwise filing reports subject to U.S. securities law. Foreign private issuers still face disclosure, internal-control, and audit oversight obligations tied to their U.S. reporting perimeter.[1][2]

Does SOX Section 404(b) apply to all public companies?

No. The auditor attestation requirement applies to many accelerated and large accelerated filers, but smaller reporting companies and non-accelerated filers are generally exempt unless their filer status changes. SEC proposals in 2026 could narrow the covered population further if adopted.[5][9]

What is the biggest IT obligation under SOX?

The biggest IT obligation is preserving the integrity and evidence trail of systems that feed financial reporting, including access management, change control, backups, logs, and retention of electronic records. IT controls matter because control failures in ERP, consolidation, identity, or document systems can create material weaknesses in ICFR.[1][3]

Can a SOX violation lead to jail?

Yes. SOX includes criminal provisions for knowingly certifying false reports and for destroying, altering, or falsifying records to obstruct investigations or audits. Enforcement can therefore include prison terms as well as fines and civil sanctions.[1][3]

Did anything change in 2025 or 2026?

The review found no enacted statutory amendment to SOX itself in 2025–2026, but there were active SEC and PCAOB developments that may change audit practice and filer scope. In particular, proposed or adopted PCAOB standards scheduled for 15 December 2026 could affect audit firms and, indirectly, issuer SOX programs.[1][5][6]

Sources

Put it into practice

More compliance guides