Sarbanes-Oxley
Also known as: SOX
US 2002 law mandating financial reporting controls and executive certifications for public companies.
The Sarbanes-Oxley Act of 2002 was enacted in response to the Enron, WorldCom, and related financial reporting scandals, restructuring auditor oversight and substantially raising the standards for public-company financial reporting and corporate governance. SOX created the Public Company Accounting Oversight Board (PCAOB) to register and regulate audit firms; required CEO and CFO personal certifications of financial statements (Sections 302 and 906) with criminal liability; mandated management and external auditor assessment of internal control over financial reporting (Section 404, with 404(b) external audit relief for smaller reporting companies under JOBS Act 2012); strengthened audit committee independence (Section 301); and barred most non-audit services by an issuer's external auditor.
Core components
- Section 302 (CEO/CFO certification of financial reports)
- Section 404(a) management ICFR assessment
- Section 404(b) external auditor ICFR attestation
- Section 906 criminal certification
- Section 301 (audit committee independence)
- Section 802 (records retention/criminal)
- PCAOB establishment and standards-setting
- Auditor independence rules
Primary use case
US public-company financial reporting integrity and audit oversight; foundation of internal control programs at SEC registrants.
Common criticisms
- High compliance cost especially for newly public and smaller filers (driving 404(b) carve-outs)
- ICFR programs criticized as defensive over-control
- mixed empirical evidence on whether SOX measurably reduces fraud or restatement frequency
- PCAOB's constitutional structure challenged in Free Enterprise Fund v. PCAOB (2010, severability remedy preserved board)
- PCAOB inspections produce findings without consistent enforcement.
Lineage
- Siblings
- Dodd-Frank Act, COSO Internal Control-Integrated Framework