Sarbanes-Oxley Act Summary: Certifications, Controls, and Audits

The Sarbanes-Oxley Act of 2002 rewrote the rules for public company financial reporting in the United States after the Enron and WorldCom scandals. In broad terms, a Sarbanes-Oxley Act summary comes down to four things: senior executives must personally certify their company’s financial reports, companies must build and test the internal controls behind those reports, external auditors must stay independent and answer to an oversight board rather than to management, and fraud or destruction of records now carries far heavier criminal penalties. The law applies to every company listed on a U.S. exchange, including foreign issuers, and a handful of its criminal and whistleblower provisions reach private companies too.

Who Has to Comply

SOX applies primarily to “issuers,” meaning companies with a class of securities registered under Section 12 of the Securities Exchange Act of 1934 or that file reports under Section 15(d). That includes every company listed on the NYSE or Nasdaq, U.S. or foreign. Foreign private issuers must register their auditors with the PCAOB and comply with the certification and audit-committee independence rules, with some accommodations on filing format and timing.1U.S. Securities and Exchange Commission. Information About Foreign Issuers – Division of Corporation Finance

Two SOX provisions reach beyond public companies. The prohibition on destroying records to obstruct a federal investigation applies to any person or entity.2Office of the Law Revision Counsel. 18 U.S. Code 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations And the whistleblower retaliation protections cover subsidiaries, contractors, and subcontractors of publicly traded companies, not just direct employees of the issuer.

Executive Certification of Financial Reports

Title III of SOX makes the CEO and CFO personally accountable for what the company files with the SEC. There are two separate certifications, and they carry different consequences.

Section 302

The CEO and CFO must sign a certification attached to every quarterly and annual report. By signing, each officer confirms they have reviewed the report, that it contains no material misstatements or misleading omissions, and that the financial statements fairly present the company’s financial condition and results. The officers also certify that they designed and evaluated the company’s disclosure controls and reported any significant deficiencies or fraud to the audit committee.3U.S. Securities and Exchange Commission. Certification of Disclosure in Companies’ Quarterly and Annual Reports

Section 906

A second written certification accompanies each periodic report and states that the report fully complies with the Exchange Act and that the information fairly presents the company’s financial condition. Section 906 carries criminal penalties. An officer who knowingly signs a false certification faces up to $1 million in fines and 10 years in prison. If the false certification is willful, the ceiling rises to $5 million and 20 years.4Office of the Law Revision Counsel. 18 U.S.C. 1350 – Failure of Corporate Officers to Certify Financial Reports

Clawback of Executive Pay

Section 304 removes the financial upside of inflated numbers. If a company restates its financials because of misconduct, the CEO and CFO must reimburse the company for any bonus, incentive-based pay, or equity-based compensation received during the 12 months after the original flawed filing, along with any profits from selling company stock during that same window.5Office of the Law Revision Counsel. 15 U.S. Code 7243 – Forfeiture of Certain Bonuses and Profits

Internal Controls Over Financial Reporting

Section 404 is the most operationally demanding piece of SOX. It forces companies to document and test the systems that produce their financial statements before those statements reach investors.

Management’s Assessment

Every public company must include an internal-control report in its annual filing. Management takes explicit responsibility for internal control over financial reporting (ICFR), identifies the evaluation framework used (almost always the COSO Internal Control—Integrated Framework), and states whether the controls are effective.6U.S. Securities and Exchange Commission. Study of the Sarbanes-Oxley Act of 2002 Section 404 Internal Control Over Financial Reporting Requirements The work involves documenting the relevant controls, testing that they operate as designed, and identifying any material weakness serious enough that a significant error could slip through undetected. It covers routine matters like segregation of duties as well as the review of complex accounting estimates at period-end.

Auditor Attestation

For accelerated filers, the external auditor must independently evaluate the ICFR and issue a separate opinion on it. The result is an “integrated audit” producing two related opinions, one on the financial statements and one on the effectiveness of the internal controls, both applying PCAOB Auditing Standard No. 5.7U.S. Securities and Exchange Commission. SEC Approves PCAOB Auditing Standard No. 5 Regarding Audits of Internal Control Over Financial Reporting If the auditor finds even one material weakness, the company receives an adverse opinion on its controls, which typically triggers a sharp stock reaction and regulator scrutiny.

Carve-Outs for Smaller Companies

Not every public company faces the full 404. The Dodd-Frank Act permanently exempted non-accelerated filers from the auditor-attestation piece of Section 404(b). Those companies still complete management’s own assessment under 404(a), but they do not need an external auditor’s separate opinion on their internal controls. Emerging growth companies get the same exemption for as long as they qualify under the JOBS Act.8U.S. Securities and Exchange Commission. Emerging Growth Companies

A 2020 SEC rule narrowed the accelerated-filer definition further, taking companies with public floats between $75 million and $700 million and less than $100 million in annual revenue out of the 404(b) requirement.9U.S. Securities and Exchange Commission. Statement on the Rollback of Auditor Attestation Requirements The auditor-attestation mandate now falls primarily on the largest issuers.

Related Disclosure Rules

Title IV also requires rapid current disclosure of material changes in financial condition, a reconciliation of any non-GAAP measure (adjusted earnings, EBITDA, and similar figures) to the closest comparable GAAP measure, and clear disclosure of material off-balance-sheet transactions and obligations.

Auditor Independence and PCAOB Oversight

Title I created the Public Company Accounting Oversight Board, a nonprofit corporation supervised by the SEC that oversees auditors of companies subject to the securities laws. Its creation ended a system in which the accounting profession largely regulated itself.10Office of the Law Revision Counsel. 15 U.S. Code 7211 – Establishment; Administrative Provisions Any firm that wants to issue an audit report for a public company must register with the PCAOB and follow its standards on auditing, quality control, ethics, and independence. The Board inspects firms auditing more than 100 issuers annually and inspects smaller firms at least once every three years.11PCAOB. Basics of Inspections Sanctions for violating PCAOB rules run from monetary penalties to permanent revocation of a firm’s registration.

Banned Non-Audit Services

Title II bars a public company’s external auditor from providing a list of non-audit services to that same client: bookkeeping, financial-information-systems design, appraisal and valuation, actuarial services, internal audit outsourcing, management and human-resources functions, broker-dealer or investment-advisory services, and legal or expert services unrelated to the audit.12U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence Tax compliance, planning, and advisory work is still allowed, but only with specific advance approval from the independent audit committee, which must evaluate and document whether the tax engagement could compromise the auditor’s objectivity. All permitted non-audit services need this pre-approval.

Partner Rotation and Cooling-Off

The lead audit partner and the concurring review partner must rotate off an engagement after five consecutive years and then sit out for five years before returning to that client. Other significant partners face a seven-year rotation with a two-year cooling-off period. A firm also loses its independence if someone now in a financial-oversight role at the client (CEO, CFO, controller, or chief accounting officer) served as the lead partner, concurring partner, or provided more than ten hours of audit services for that issuer within the preceding year.

Audit Committee Requirements

SOX makes the audit committee, not management, responsible for the outside auditor. Every member must be an independent director, meaning they accept no consulting or advisory fees from the company beyond their director pay and are not an affiliated person of the company or any subsidiary. The committee hires, compensates, and oversees the external auditor, and the auditor reports to the committee.13Office of the Law Revision Counsel. 15 U.S.C. 78j-1 – Audit Requirements The committee must set up procedures for handling accounting and auditing complaints, including an anonymous channel for employees, and it can hire outside counsel or advisers on the company’s dime whenever it decides it needs them.

Criminal Penalties and Record Retention

SOX raised the stakes for corporate fraud sharply. Mail fraud and wire fraud now carry up to 20 years in prison, up from five.14Office of the Law Revision Counsel. 18 U.S. Code 1341 – Frauds and Swindles The Act also created a standalone federal crime of securities fraud punishable by up to 25 years.15GovInfo. 18 U.S.C. 1348 – Securities and Commodities Fraud

Section 802 added two provisions to the criminal code. Destroying, altering, or falsifying a record with intent to obstruct a federal investigation is a federal crime punishable by up to 20 years, and it applies to anyone.2Office of the Law Revision Counsel. 18 U.S. Code 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations Auditors of public companies must also retain all audit and review workpapers for at least five years from the end of the fiscal period in which the engagement concluded, with up to 10 years in prison for knowing or willful violations.16Office of the Law Revision Counsel. 18 U.S. Code 1520 – Destruction of Corporate Audit Records PCAOB rules under Section 103 push the retention window to seven years, and that longer standard is what most firms actually follow.17U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews

Whistleblower Protections

Section 806 protects employees who report suspected fraud at publicly traded companies, their subsidiaries, contractors, and subcontractors. An employer cannot fire, demote, suspend, threaten, harass, or otherwise retaliate against an employee for reporting potential securities fraud, mail fraud, wire fraud, or bank fraud to a federal agency, a member of Congress, or an internal supervisor.18U.S. Department of Labor. Sarbanes-Oxley Act of 2002, P.L. 107-204, Section 806

An employee who is retaliated against must file a complaint with OSHA within 180 days of the adverse action or of learning about it.19Occupational Safety and Health Administration. Filing Whistleblower Complaints Under the Sarbanes-Oxley Act That deadline is strict. Available remedies include reinstatement, back pay with interest, and compensation for other damages including legal fees. Missing the 180-day window generally forfeits the claim under this section.