.png)
.png)
.png)
SOX (Sarbanes-Oxley Act)
Framework Name
Sarbanes-Oxley Act (SOX)
Type
Mandatory
Region / Jurisdiction
United States (applies to any company, including foreign companies, listed on a US stock exchange)
Enforcing Body / Certifying Party
US Securities and Exchange Commission (SEC), with the Public Company Accounting Oversight Board (PCAOB) specifically overseeing the external auditors who audit public companies' financial statements
Penalty / Consequence of Non-Compliance
Real criminal exposure, not just fines: knowingly certifying false financial statements can carry penalties up to $5 million and 20 years in prison, and willfully destroying relevant records carries similar criminal penalties. Civil penalties and SEC enforcement actions apply as well, and CEOs and CFOs are personally liable for the certifications they sign
What It Is & Why It Matters
Sarbanes-Oxley is a US federal law passed by Congress in 2002, directly in response to major corporate accounting scandals, Enron and WorldCom chief among them, that wiped out shareholder value and employee pensions almost overnight. It requires public companies to maintain effective internal controls over financial reporting, and it requires senior executives, personally, not just the company, to certify that financial statements are accurate. It also created the PCAOB to oversee the accounting firms that audit public companies, after auditor failures were found to have directly contributed to those earlier scandals.
It matters because it fundamentally changed the personal stakes for corporate leadership: before SOX, a CEO or CFO signing off on fraudulent numbers faced mostly reputational and civil risk; after SOX, they face real criminal liability for doing so knowingly. It's also the law behind Section 404, the internal controls requirement that made COSO the near-universal framework public companies use to structure and demonstrate financial control effectiveness, since SOX requires the outcome but never specifies the framework to get there.
Who Needs It
- You are a public company listed on a US stock exchange, including foreign companies with a US listing
- You are a private company preparing for an IPO and need to build SOX-compliant internal controls ahead of going public
- You are an accounting firm auditing a public company's financial statements, subject to PCAOB oversight
- You are a vendor or service provider whose systems or processes get assessed as part of a public company customer's SOX internal control review