Back to Blog
SOX

What Is Sarbanes-Oxley (SOX)? A Practical Guide for Companies Facing Compliance

September 10, 20265 min read
A SOX book and financial reports inside a translucent blue protective frame.

Ask ten finance professionals what SOX means and you'll get ten different answers. Some think of quarterly certifications. Some think of control matrices. Some think of the fourth-quarter scramble to find evidence for a control that operated in March.

All of them are partly right. But SOX is a narrower and more coherent piece of law than its reputation suggests, and understanding what it actually requires makes compliance considerably less painful.

What Sarbanes-Oxley actually is

The Sarbanes-Oxley Act of 2002 is a US federal law enacted in the wake of the Enron, WorldCom, and Tyco accounting scandals. Named for Senator Paul Sarbanes and Representative Michael Oxley, it was signed into law on July 30, 2002.

Those scandals had a common feature: the financial statements were wrong, and the systems meant to catch that failed. Auditors had conflicts of interest. Executives disclaimed knowledge of numbers they had signed. Documents disappeared.

SOX responded to each of those failures directly. It created the Public Company Accounting Oversight Board (PCAOB) to regulate audit firms, which had previously been self-policing. It restricted the consulting services auditors could sell to their own audit clients. And it moved responsibility for the accuracy of financial statements squarely onto named executives.

A few sections do most of the work:

  • Section 302 requires the CEO and CFO to personally certify each periodic report and the effectiveness of disclosure controls.
  • Section 404 requires management to assess and report on internal control over financial reporting (ICFR), and requires the external auditor to attest to that assessment for larger companies.
  • Section 802 makes destruction or alteration of records to obstruct an investigation into a criminal offense, carrying up to twenty years' imprisonment.
  • Section 906 imposes criminal penalties for false certifications, with maximum penalties of $5 million and twenty years for willful violations.
  • Section 806 protects employees of public companies who report suspected fraud from retaliation.

Which companies it applies to

The core reporting requirements apply to companies registered with the SEC. That means US public companies, foreign private issuers listed on US exchanges, and the accounting firms that audit them. Private companies with no public debt or equity generally fall outside Sections 302 and 404.

But two important qualifications are overlooked.

First, the criminal provisions are broader. Section 802's record-destruction rules and Section 1107's anti-retaliation protections apply to any organization, private companies included. Shredding documents to obstruct a federal investigation is a crime regardless of listing status.

Second, the scope of Section 404 varies by company size. Management's own assessment under 404(a) generally applies to annual reports of reporting companies, subject to applicable exemptions and transition provisions, including for newly public companies. The auditor attestation under 404(b) applies only to accelerated and large accelerated filers. Since 2020, companies that qualify as smaller reporting companies with annual revenue under $100 million have been carved out of those definitions and are therefore exempt from 404(b). Emerging growth companies are exempt while they retain that status, generally for up to five years after IPO, with earlier loss of status possible under the JOBS Act thresholds.

This landscape may shift again. In May 2026 the SEC proposed collapsing the current filer categories into a two-tier structure and raising the large accelerated filer threshold from $700 million to $2 billion in public float. If adopted, that would extend the 404(b) exemption to a substantially larger share of public companies. As of September 29, 2026, the SEC lists this action as a proposed rule; the proposal itself does not change the existing requirements. Companies near the boundary should plan for both outcomes.

Private companies preparing for an IPO face a different clock. Control environments cannot be built in the quarter before a listing. Most companies that go public smoothly started work eighteen to twenty-four months out.

Why it matters

The straightforward answer is that non-compliance carries real consequences: restatements, material weakness disclosures, share price damage, and personal liability for executives who certify inaccurate reports.

The more useful answer is that the discipline SOX imposes tends to be worth having on its own merits. A company that can produce reliable, timely, well-evidenced financial information makes better decisions, closes its books faster, and negotiates from a stronger position with lenders and acquirers. The controls exist to catch errors before they reach investors, but errors caught early are cheaper to fix for everyone, including management.

How companies achieve compliance

Scope by risk, not by habit. Start from material financial statement accounts and the processes that feed them. Many programs carry controls that were added years ago in response to a problem that no longer exists. Rationalization is not cutting corners; it is directing attention where risk actually sits.

Adopt a recognized framework. The COSO 2013 Internal Control – Integrated Framework is the standard reference for ICFR, and auditors expect to see controls mapped to its components and principles.

Document controls precisely. A control description should specify who performs it, how often, against what threshold, using which source of data, and what happens when an exception is found. Vague descriptions fail testing even when the underlying control works.

Don't neglect ITGCs. Access management, change management, and computer operations underpin nearly every automated control in the environment. A weakness here undermines everything built on top of it.

Test throughout the year. Deficiencies found in the first quarter can be remediated and retested. The same deficiency found in the fourth quarter often cannot.

Automate repeatable work. Evidence collection, population testing, and status tracking consume enormous effort and produce little judgment. Pulling evidence directly from source systems and testing full populations rather than samples frees experienced people to focus on the controls that genuinely require thought.

Compliance is not the goal in itself. A financial reporting process people can trust is the goal, and SOX, applied sensibly, is a reasonable way to get there.

© 2026 Audagic. All rights reserved.

See Deterministic Testing in Action

Get early access and try Audagic on your own audit evidence.