The Sarbanes-Oxley Act (SOX)
The Ultimate Guide to

Sarbanes-Oxley Act (SOX) Compliance: Requirements and Controls

What is the Sarbanes-Oxley Act (SOX)?

The Sarbanes-Oxley (SOX) Act is a 2002 U.S. federal law requiring public companies to follow strict rules for financial reporting and internal controls. Passed in response to major corporate scandals that exposed serious failures in governance and accounting, SOX is intended to reduce fraud, protect investors, and improve the accuracy and reliability of financial disclosures. 

SOX holds executives personally accountable for the accuracy of financial statements, requires strong internal control frameworks, and gives regulators and auditors more power to detect and prevent fraud.

IT compliance and IT security professionals must pay close attention to SOX because the regulation has clear implications for data management, reporting, and security.

Key points of SOX include:

  • Applies to all U.S. public companies and some foreign issuers
  • Requires CEOs and CFOs to certify financial reports
  • Mandates internal control testing and independent audits
  • Imposes heavy fines and prison time for fraudulent reporting

Who needs to comply with SOX?

Publicly traded companies

All provisions of SOX apply to publicly traded companies headquartered in the United States, including wholly-owned subsidiaries and foreign companies that are publicly traded and do business in the United States. SOX also applies to any third parties to which a publicly traded company outsources financial work. 

SOX also affects HR departments within publicly traded companies as it requires a firm to establish payroll system controls. A company’s workforce, salaries, benefits, incentives, paid time off, and training costs must all be accounted for under Section 404 of SOX.

Private companies, charities, and nonprofits

In general, private companies, charities, and nonprofits are not required to comply with all SOX provisions. However, certain provisions of SOX do apply. For instance, intentionally destroying, altering, or falsifying documents with the intent to impede or influence a federal agency investigation or a federal bankruptcy proceeding carries fines and up to 20 years’ imprisonment.

In addition, whistleblower protection applies to these companies, which means that retaliating against someone who provides a law enforcement officer with information relating to a possible federal offense is punishable by up to 10 years imprisonment.

Accounting firms

SOX also affects accounting firms because the rule builds a firewall between the auditing function and other services available from accounting firms. The firm that audits the books of a publicly held company may no longer:

  • Do the company’s bookkeeping, on-financial audits, or business evaluations
  • Design or implement an information systemĀ 
  • Provide investment advisory and banking services
  • Consult on other management issues

Organizations planning for future IPOs

For companies planning to  go through an IPO in the next 2-3 years, it is beneficial to start planning for SOX compliance because it will require significant time to set up all necessary processes to fulfill SOX requirements.

What are the main requirements of SOX compliance?

To become compliant with SOX, organizations must adhere to the financial reporting, information security, and auditing requirements defined by the framework.

SOX is arranged into 11 sections, also called titles. Two sections of particular importance are Section 302 and Section 404.

Section 302 – Corporate Responsibility for Financial Reports

This section requires the CEO and CFO of a company to personally certify the accuracy and completeness of financial reports. They must attest that the financial statements fairly represent the financial condition and operations of the company. This section also establishes that the CEO and CFO are responsible for internal accounting controls.

Section 404 – Management Assessment of Internal Controls

This section requires management to assess and report on the effectiveness of the company’s internal control over financial reporting (ICFR). Internal controls include any computer, network hardware, and other electronic infrastructure through which financial data passes. Additionally, it mandates that an external auditor must independently attest to the accuracy of management’s assessment. . This audit assesses the effectiveness of all internal controls and reports its findings directly to the Security Exchange Commission (SEC).

Section 409 – Real Time Issuer Disclosures

This section requires companies to disclose material changes in their financial condition or operations within 48 hours, enhancing transparency and ensuring that investors have timely access to important information.

Other key provisions under SOX include:

  • Required disclosure of transactions and relationships that are off the balance sheet and could impact financial status;
  • Prohibition of personal loans from a corporation to executives;
  • Establishment of fines and terms of imprisonment for tampering with or destroying documents in the event of investigations or court action; and
  • Requirements for attorneys who represent public companies before the SEC to report security violations to the CEO.

SOX also encourages disclosure of corporate fraud by protecting whistleblower employees of publicly traded companies or their subsidiaries who report illegal activities against retaliation, including dismissal and discrimination.

SOX enforcement and penalties for non-compliance

The SEC  enforces SOX by imposing criminal penalties for certifying a misleading or fraudulent financial report. These can be upwards of $5 million in fines and 20 years in prison when someone willfully certifies misleading or fraudulent financial statements. Retaliation against a whistleblower for disclosing truthful information to a law enforcement officer regarding an alleged federal crime is punishable by up to 10 years imprisonment.

What is a SOX compliance audit and how does it work?

A SOX compliance audit is an annual, independent review of a company’s internal controls over financial reporting. The audit tests whether controls around access, security, change management, and backups are designed and operating effectively. Its goal is to confirm that financial data is accurate, complete, and protected from fraud or misuse. Companies often choose to schedule the audit so that results are available for inclusion in their annual report (to satisfy the requirement that audit findings must be accessible to stockholders).

Typical steps in a SOX compliance audit:

  1. Management and the external audit firm agree on scope, timelines, and objectives.
  2. Auditors identify key financial systems, applications, and controls to review.
  3. Evidence is collected and tested for access, change management, security, and backup controls.
  4. Control gaps and deficiencies are documented and discussed with management.
  5. Audit findings are reported and included in the company’s annual filings for investors and regulators.

The first step to an audit is to have your management team meet the accounting firm to discuss the specifics of the audit, including when it will take place, what it will cover, what its purposes are, and what results management expects to see.

SOX audit of internal controls

The biggest portion of a SOX audit is a review of internal controls, including computers, network hardware and other electronic infrastructure that financial data passes through. From an IT perspective, a typical audit will look like this:

Access

Access controls can be physical or electronic; their purpose is to prevent unauthorized users from viewing sensitive information. This includes ensuring that cloud resources and physical servers are secure, effective password controls are being used, and lockout screens and other measures are in place. Implementing the principle of least privilege is considered one of the best methods of access control.

Change management process

Change management involves your internal processes for adding new users or workstations, updating and installing new software, and making any changes to Active Directory databases or other information architecture components. Having a record of what was changed, when it was changed, and who changed it is necessary for a SOX IT audit, and these records will make it much easier to correct problems when they emerge.

Security

A SOX audit will examine the technology, policies, and procedures your organization has put in place to prevent breaches and promptly remediate incidents as they occur.

Backup procedures

The auditor will expect to see backup systems in place to protect your sensitive data.

Segregation of duties in the software development cycle

A SOX audit will evaluate your control mechanisms designed to prevent conflicts of interest, unauthorized changes, and operational risks in software development. Dividing responsibilities among multiple roles creates checks and balances that enhance accountability, transparency, and compliance.

SOX Compliance Checklist

While each audit will be tailored to the organization, there are a few general questions each organization should consider before an audit:

Am I working from an accepted framework such as COBIT, ITGI, or COSO?

Do we have policies that outline how to create, modify, and maintain accounting systems, including software that handles financial data?

What safeguards do we have to prevent data tampering? Have they been tested and found functional?

Is there a protocol for dealing with security breaches?

Is access to sensitive data being monitored and recorded?

Have previous breaches and failures of security safeguards been disclosed to auditors?

Have we provided SOX auditors with the access needed to do their job?

Do we use data classification to make it easier to monitor and enforce corporate policies for data handling?

Best practices for achieving SOX compliance:

  • Implementing strong internal controls and regularly testing their effectiveness.
  • Ensuring clear documentation of processes and procedures.
  • Conducting regular risk assessments and addressing identified risks.
  • Providing SOX-specific training for employees.
  • Leveraging automation to manage SOX activities, achieve audit readiness, and ensure continuous compliance.

SOX: Frequently Asked Questions

The Sarbanes-Oxley Act establishes a comprehensive framework to regulate corporate governance and financial practices. It mandates strict reforms to improve financial disclosures and prevent accounting fraud. Key provisions include:

  • Executive accountability: Corporate executives, including CEOs and CFOs, must personally certify the accuracy of financial statements, making them directly accountable for any discrepancies.
  • Enhanced financial disclosures: SOX requires companies to provide accurate and complete financial information, ensuring transparency and accountability in financial reporting.
  • Internal controls: Companies must establish and maintain robust internal controls to safeguard against financial fraud and inaccuracies.
  • Oversight of the accounting profession: The Act established the Public Company Accounting Oversight Board (PCAOB) to oversee the auditing profession, ensuring the independence and competence of auditors.

The Sarbanes-Oxley Act (SOX) was created in response to several high-profile corporate scandals that occurred in the early 2000s, including those involving Enron, WorldCom, and Tyco. These scandals revealed significant deficiencies in corporate governance, accounting practices, and financial reporting. The primary objective of SOX was to protect investors by improving the accuracy and reliability of corporate disclosures, thereby restoring public confidence in the financial markets. Enacted in 2002, SOX introduced stringent reforms to enhance transparency, accountability, and integrity in the corporate sector.

SOX controls are specific measures implemented by companies to ensure compliance with the Sarbanes-Oxley Act, particularly Section 404. These controls are designed to safeguard financial data, ensure accurate reporting, and prevent fraud. The four primary types of SOX controls are:

  1. Access controls: These controls regulate who has access to financial systems and data. They ensure that only authorized personnel can access sensitive financial information. This includes measures such as user authentication, role-based access controls, and regular reviews of access permissions.
  2. IT controls: These controls focus on the integrity and security of the IT systems used to process and store financial data. They include measures like data encryption, network security, system backup and recovery procedures, and regular IT audits to identify and address vulnerabilities.
  3. Change management controls: These controls manage and document changes to financial systems and processes. They ensure that any modifications are properly authorized, tested, and implemented without compromising the integrity of financial data. This includes maintaining detailed records of system changes and conducting impact assessments.
  4. Operational controls: These controls are designed to ensure that day-to-day operations align with established financial policies and procedures. They include regular reconciliations, transaction validations, and reviews of financial statements to detect and correct any discrepancies. Operational controls help maintain accuracy and consistency in financial reporting.

Internal controls are processes and procedures implemented by a company to ensure the integrity of financial and accounting information, promote accountability, and prevent fraud. Under SOX, companies must establish and maintain effective internal controls and procedures for financial reporting.

Here are four resources you can use to help develop and assessĀ  internal controls objectives:

  • ISACA publishes many helpful resources, including its IT Control Objectives for Sarbanes-Oxley.
  • The Public Company Accounting Oversight Board (PCAOB) was created to develop auditing standards and train auditors on the best practices for assessing a company’s internal controls. PCAOB publishes updates and changes to the auditing processes; you can refer to these as you’re preparing for an audit.
  • Control Objectives for Information Technologies (COBIT) is a framework published by ISACA, a leading organization in the production of guidelines for developing and assessing internal controls for IT systems. COBIT outlines best practices for 34 IT processes.
  • The Committee of Sponsoring Organizations (COSO) consists of representatives from the Institute of Management Accountants (IMA), the American Accounting Association (AAA), the American Institute of Certified Public Accountants (AICPA), the Institute of Internal Auditors (IIA), and Financial Executives International (FEI). COSO publishes periodic updates to its internal control framework recommendations, a document which outlines guidelines for creating and implementing internal controls and serves as the basis for the auditing standards developed by PCAOB.

SOX audits are typically conducted annually. Companies must submit annual reports on their internal controls over financial reporting, which are then reviewed by external auditors as part of the company’s financial statement audit.

While SOX does support good IT control hygiene, not all of your data security risks are fully addressed by SOX. The SOX audit will only cover the internal controls related to a company’s accounting and financials — not other types of sensitive data. Today, many organizations have various types of sensitive data in third-party SaaS applications. The scope of a SOX audit omits certain key security principles that are imperative for ensuring your cloud environment, such as Governance and Identity and Access Management.

To ensure sufficient security across all of your environments (cloud and on-premise) and all types of data, refer to guidelines from other security and cloud security frameworks in addition to SOX, such as the CSA Cloud Controls Matrix and NIST SP 800-53.

Hyperproof for SOX Compliance

Hyperproof is a compliance operations software solution that helps organizations get through their SOX compliance audits faster and more cost-effectively. Here are just a few of the ways Hyperproof can be used to make SOX compliance audits more manageable and less stressful:

SOX

Hit the ground running

Hyperproof comes with a SOX starter compliance template designed to help organizations accelerate their journey to compliance. The template comes with all SOX requirements and access to COSO and COBIT controls you can use as a starting point to develop your SOX controls. Once you’ve implemented the template, you can upload your existing evidence files, link them to the right controls and requirements, and iterate from there (e.g., tailor certain controls or collect additional pieces of evidence). For organizations who already have existing controls in place, it’s quite simple to edit the provided controls, add new controls, and remove superfluous ones.

Streamline the evidence collection and management processes

Instead of developing your own file system and using spreadsheets to track updates, you can store all of your evidence in Hyperproof and link each piece of evidence to the right control and requirement. Hyperproof provides the ability to link one evidence file to multiple requirements/controls, so you don’t have to pull the same evidence files again and again if you’re preparing for multiple audits.

Hyperproof also makes it easy for compliance professionals to collect evidence from business stakeholders. A compliance project owner can assign tasks to business stakeholders (e.g. submit this type of evidence) and remind people to complete their tasks on a cadence. Business stakeholders do not need to learn the language of compliance or any new tools. They can receive notifications to complete tasks through the tools they are already using (e.g., Outlook, Slack, Gmail), complete the tasks in those tools, and have information routed back and reflected in Hyperproof in near real-time.

Know exactly where you stand with an audit

Hyperproof provides real-time feedback on your audit preparedness and control evaluation efforts. It comes with dashboards to help you identify what controls are already in place and what’s missing in real-time so you can put solutions in place to close those gaps well ahead of an auditor’s visit.

When you’re ready to share your work with your auditor, you can invite your auditor to review your work in Hyperproof, so no one has to spend their precious time uploading/downloading files and sending emails back and forth. Additionally, Hyperproof provides a central place for compliance process owners and auditors to communicate with one another.

SOX expertise

Hyperproof has partnerships with professional service firms with proven track records and deep expertise in the SOX standard. If you need a referral, we’d love to talk.

Ready to see
Hyperproof in action?

G2Crowd Leader Enterprise
G2Crowd Leader Mid-Market
G2Crowd High Performer Enteprise
G2Crowd Momentum Leader
G2Crowd Users Love Us