SOX compliance touches finance, IT, and the executive suite all at once. Here's what it actually requires, section by section, and why the access control piece is where most of the real work, and most of the real risk, lives.
The Sarbanes-Oxley Act became law in July 2002, four months after WorldCom disclosed that it had improperly capitalized $3.8 billion in expenses, and less than a year after Enron's collapse wiped out roughly $74 billion in shareholder value and took its auditor, Arthur Andersen, down with it.
Both scandals shared a common thread: internal controls that looked adequate on paper failed completely in practice, and nobody with the authority to catch the problem was personally accountable for missing it.
Congress's response, sponsored by Senator Paul Sarbanes and Representative Michael Oxley, was built around closing that accountability gap. Financial reports had to be accurate. The controls producing them had to be documented, tested, and independently verified. And the executives signing off on them had to carry personal legal exposure if the sign-off turned out to be wrong.
More than two decades later, that's still the core of SOX compliance: prove your controls work, not just claim they do, and put your name on it.
Who Has to Comply With SOX
SOX applies directly to:
- Publicly traded companies in the US, including those listed on the NYSE or NASDAQ
- Wholly-owned subsidiaries of publicly traded companies
- Foreign companies that trade on US exchanges, even if headquartered elsewhere
- Accounting firms that audit these companies, with independence rules restricting what non-audit services (bookkeeping, business valuations, management consulting) they can provide to a client they also audit
Private companies, non-profits, and charities aren't subject to most SOX provisions. But they're not entirely outside its reach either. Section 802's prohibition on intentionally destroying or falsifying financial records applies regardless of whether a company is public, and private companies sometimes find themselves subject to SOX-adjacent requirements anyway: a lender or insurer may require SOX-style controls as a condition of financing, prospective investors may request the same assurances as part of due diligence, and some state security regulators extend elements of SOX to certain private entities.
The category that matters most for a lot of fast-growing companies is the one in between: private companies preparing for an IPO. Once an S-1 is filed and the company starts trading, the full weight of SOX applies immediately, and the controls behind that first set of public filings need to already be operating, not just designed, by the time the company goes public.
The Sections That Actually Matter
SOX runs to eleven titles and dozens of individual sections, but in practice, a handful of them do almost all the work that IT, finance, and legal teams actually deal with day to day.
Section 302 requires the CEO and CFO to personally certify, on every quarterly and annual filing, that they've reviewed the report, that it doesn't contain false or misleading statements, and that they've evaluated the company's disclosure controls and procedures within the prior 90 days. The certification breaks into several distinct sub-requirements:
- Confirming safeguards exist to prevent data tampering
- Confirming controls are in place to ensure timely and accurate reporting
- Confirming internal controls are established and actively maintained (not just designed)
- Confirming those controls are operational, not merely documented
- Committing to periodically report on control effectiveness
- Confirming mechanisms exist to detect security breaches
Most organizations route this through a disclosure committee, typically drawn from legal and finance, that meets quarterly, generally 30 to 40 days after quarter-end, specifically to review the draft filing before the CEO and CFO sign.
Section 404 is the internal controls section, and it splits into two parts that get confused constantly, especially by companies newly subject to SOX. Section 404(a) requires management itself to assess and report on the effectiveness of internal controls over financial reporting, no external party required. Section 404(b) goes a step further: it requires an independent external auditor to test and formally attest to those same controls. Smaller reporting companies and emerging growth companies are generally exempt from 404(b), sometimes for the first several years after an IPO, which is exactly why the distinction matters so much for a company approaching public markets, it changes both the cost and the rigor of what's required in the first few reporting cycles.
Section 409 requires companies to disclose material changes to their financial condition or operations on a rapid, current basis, rather than holding the news for the next scheduled quarterly or annual filing.
Section 802 criminalizes altering, destroying, or falsifying records with intent to obstruct a federal investigation, carrying penalties of up to 20 years in prison. It's a distinct violation from a certification failure or a controls deficiency, and notably, it applies even to organizations that fall outside SOX's normal public-company scope.
Section 906 is the criminal certification provision, separate from Section 302's civil certification, and it's the one that carries real prison time for executives personally. It's covered in detail further down, because it's the section most directly tied to what happens when compliance actually fails.
What SOX Actually Requires in Practice
Underneath the statutory language, SOX compliance runs on an annual testing cycle that repeats with predictable rhythm.
Interim testing happens throughout the year, evaluating whether key controls, including access controls, system configurations, and data accuracy checks, are operating the way they were designed to.
Year-end testing re-verifies those same controls right before the annual audit, specifically checking whether anything changed in the interim that introduced new risks the earlier testing didn't catch.
Independent auditors then perform their own testing on top of both, providing outside assurance that management's internal assessment alone can't provide, and often catching gaps that internal teams, too close to their own processes, miss.
Most organizations anchor this process around a Risk and Control Matrix (RCM), a structured document connecting identified financial reporting risks to the specific controls meant to mitigate them. A well-maintained RCM is what lets an auditor trace a straight line from "this is a risk to accurate financial reporting" to "here is the control that addresses it" to "here is the evidence that the control operated."
Many organizations build their control framework around COSO (the Committee of Sponsoring Organizations of the Treadway Commission), a widely used internal control framework that helps connect individual controls back to broader organizational processes and objectives, though SOX itself doesn't mandate a specific framework.
Controls get classified in ways that directly shape how much scrutiny they receive. Key controls are the ones that materially reduce risk to an acceptable level on their own, and they draw the most audit attention, quarterly access reviews of financial systems are a near-universal example. Secondary controls support the broader environment without being independently relied upon to prevent a material misstatement.
Controls are also either preventive, stopping a problem before it happens, like requiring documented approval before granting access to a financial system, or detective, catching a problem after the fact, like a periodic review that surfaces access that should have been revoked.
A well-designed control environment needs both categories working together, since prevention reduces how often problems occur and detection catches what prevention inevitably misses.
Where Access Controls Fit In
Ask which slice of SOX compliance actually falls on IT and security teams specifically, and the honest answer is narrower than most people expect walking in: access controls. Provisioning new access, deprovisioning it when someone leaves or changes roles, running periodic access reviews, and enforcing segregation of duties, these are the IT General Controls (ITGC) that most directly support ICFR (internal control over financial reporting), for a structural reason: every other control in the environment assumes access is already governed correctly.
Change management assumes only authorized people can push changes. Data integrity assumes only authorized people can touch the data. If access itself isn't controlled, every control built on top of it inherits that same weakness.
This is also, predictably, where compliance work tends to break down in practice. Manual access reviews run on exported spreadsheets and email approval threads, and while they technically happen, they rarely produce evidence that survives real scrutiny.
An auditor sampling a review doesn't just want to know it occurred, they want to know it covered the complete population of in-scope systems (not just the ones someone remembered to export), that an appropriately independent reviewer made a documented, timestamped decision, and that any flagged access was actually revoked, not just logged as a ticket that sat open for the rest of the quarter. That last gap, proof of remediation rather than just a record that a problem was found, is consistently where manual processes fail hardest.
For a closer look at exactly what auditors test for in this specific area, including how service accounts and non-human identities factor in, see our guides to [SOX ITGC access controls] and [SOX user access reviews].
SOX Violations and What Non-Compliance Actually Costs
Most SOX violations don't start as a single dramatic event. They start small: a former employee's account that was never deprovisioned, a service account with standing write access to the general ledger that nobody owns, an access review that happened on paper but wasn't consistently followed through. None of that looks like fraud on its own. It looks like an operational gap, right up until an auditor's sample happens to land on it and it becomes a disclosed material weakness.
SOX violations generally fall into a few categories, and access control failures show up across most of them:
Inaccurate certification. If the Section 302 certification doesn't match reality, whether from negligence, oversight, or intent, it's a violation. This is where personal accountability lands most directly on the CEO and CFO who signed.
Ineffective internal controls. Under Section 404, a pattern of control failures, including unremediated access violations, missing service account governance, or reviews that exist as a process on paper but don't operate consistently, is a well-documented path to a disclosed material weakness. IT-driven material weaknesses commonly trace back to inadequate access controls, missing segregation of duties, poor change management documentation, or gaps in audit logging, not exclusively to outright fraud.
Record tampering and obstruction. Section 802 separately criminalizes altering, destroying, or falsifying records with intent to obstruct an investigation, a distinct violation from either a certification failure or a control deficiency.
The penalty structure under Section 906 is genuinely severe, and it scales directly with intent. An executive who knowingly certifies a report that doesn't meet SOX requirements faces a fine of up to $1 million and up to 10 years in prison. If the certification is willfully false, meaning there was demonstrable intent to mislead, the penalties rise to $5 million and up to 20 years. These aren't theoretical maximums, they're written directly into the statute at 18 U.S.C. 1350, and they apply personally to the certifying officer, separate from and in addition to any penalty the company itself faces.
The consequences have played out in real cases. Jerry Dale Cash, the former CEO of Quest Resource Corporation, was sentenced to 108 months, nine years, in federal prison after pleading guilty to making a false Section 906 certification. He had diverted $10 million in corporate funds and then certified the company's SEC filing knowing that the diversion hadn't been disclosed. The sentencing judge specifically rejected a request for probation, calling it inappropriate because it would undercut the principle of equal justice regardless of the defendant's financial standing. The case is a useful reminder that Section 906 isn't a symbolic provision; prosecutors and judges treat a false certification as a serious federal crime in its own right, independent of whatever underlying conduct the false certification was covering up.
Beyond individual criminal liability, a disclosed control deficiency carries consequences of its own, even when nobody goes to prison. It has to be reported in the company's next 10-Q or 10-K filing. Auditors typically increase testing scope and fees in subsequent quarters to compensate for the identified weakness. And in serious or repeated cases, companies face real delisting risk from their exchange. None of that requires fraud or intent, it's simply the standard consequence of a control that didn't operate the way it was certified to.
It's worth being precise about terminology here, since the two get conflated constantly. A significant deficiency is a control gap important enough to report to the audit committee, but not severe enough on its own to create a reasonable possibility of a material misstatement in the financial statements. A material weakness crosses that line and has to be publicly disclosed in SEC filings, where investors and analysts will see it directly.
Access control failures are a particularly common path to this outcome, and there's a structural reason why. They're often invisible until something else surfaces them. A stale account that wasn't deprovisioned doesn't announce itself. A service account with unclear ownership and standing access to financial systems doesn't trigger an alert on its own. These gaps sit quietly, sometimes for months, until an audit sample happens to land on exactly the wrong user, or a review cycle that looked complete on paper turns out to have missed an entire category of systems nobody thought to include.
Common Compliance Challenges
A handful of patterns show up repeatedly in organizations that struggle with SOX compliance, and they're rarely unique to any one industry or company size:
- Treating SOX as a routine checklist rather than a genuine risk-based exercise, which leads to controls that satisfy the letter of the requirement without addressing the risks specific to the business
- Lack of executive or board support, since resource allocation and prioritization both flow from the top, and a program without that backing struggles to get budget or attention
- Miscoordination with external auditors, when management and auditors aren't in continuous, open communication about risk profile and control strategy, audits become adversarial and surprises multiply on both sides
- Misalignment between control ownership and daily operations, when the person responsible for a control doesn't fully understand how it connects to broader risk management, they deprioritize it in favor of whatever's more visible in their day-to-day work
- Environment complexity, large distributed user populations, multiple business units, or a sprawling SaaS footprint make consistent controls genuinely difficult, not just administratively tedious
- Under-resourcing, SOX compliance requires specialized personnel, audit fees, technology investment, and ongoing training, and smaller organizations often lack the internal expertise to manage all of it without outside help
The organizations that manage this well tend to share one trait more than any other: they treat access governance specifically as a standing operational process built into how the business runs, not a quarterly scramble assembled under deadline pressure. That distinction is what determines whether an audit is a formality or a source of findings.
How Organizations Get and Stay Compliant
For companies newly subject to SOX, most commonly ones heading toward an IPO, the standard guidance is to start preparation 18 to 24 months before the intended filing date.
That timeline isn't arbitrary: it allows roughly a full year of the controls actually operating and generating evidence before the first real test, rather than trying to design, implement, and prove out a control environment simultaneously while also drafting the S-1 itself.
Companies that compress this timeline consistently end up managing both processes under strain at the same time, and that's when both the registration statement and the control environment tend to suffer.
Ongoing compliance, once a company is established, comes down to three things operating together:
- People. Assigning SOX responsibilities to individuals with real accounting, finance, and process expertise, since the CEO and CFO carry ultimate accountability for the program regardless of who executes it day to day.
- Process. Building risk assessment, control design, and testing into the operating rhythm of the business rather than treating them as an annual event.
- Technology. Using automation for the controls that benefit most from consistency and auditability, since automated controls tend to produce more reliable evidence and are less susceptible to the human error and scheduling drift that erodes manual processes over time.
When deficiencies do turn up during testing, whether from an internal review or the annual audit itself, the remediation path follows a fairly consistent shape:
- Compile a clear summary of what was found
- Rank issues by severity and urgency rather than trying to fix everything simultaneously
- Set a realistic timeline for corrective action
- Communicate the plan to control owners and relevant stakeholders
- Actually monitor progress rather than treating the plan as a document that gets filed away
Timing matters here too, most organizations find it easier to kick off a remediation effort at the start of a new fiscal year, aligning it with the broader annual planning cycle rather than trying to retrofit changes mid-year.
Frequently Asked Questions
What is SOX compliance?
SOX compliance means adhering to the Sarbanes-Oxley Act of 2002, which requires public companies to maintain accurate financial reporting, document and test internal controls over that reporting, and hold executives personally accountable through certification requirements under Sections 302 and 906.
What's the difference between SOX Section 302 and Section 404?
Section 302 requires the CEO and CFO to personally certify the accuracy of financial reports every quarter, based on a review conducted within the prior 90 days. Section 404 requires companies to assess and report on the effectiveness of their internal controls, with 404(a) covering management's own internal assessment and 404(b) adding independent external auditor testing on top of it.
What's the difference between SOX 404(a) and 404(b)?
404(a) is management's own internal assessment of control effectiveness, conducted without outside involvement. 404(b) requires an independent external auditor to separately test and formally attest to those same controls. Smaller reporting companies and emerging growth companies are typically exempt from 404(b) for a defined period, often the first several years after an IPO.
What are the penalties for a SOX violation?
Under Section 906, a knowing false certification carries a fine of up to $1 million and up to 10 years in prison. A willful false certification, made with demonstrable intent to mislead, carries penalties of up to $5 million and up to 20 years. Section 802 separately penalizes intentional record tampering with up to 20 years in prison.
Do access control failures commonly cause SOX violations?
Yes. Inadequate access controls, missing segregation of duties, and gaps in audit logging are consistently cited among the most common drivers of IT-related material weaknesses, alongside change management gaps, and they're often invisible until an audit sample happens to catch them.
Does SOX apply to private companies?
Not for most provisions, but private companies are still subject to rules against intentionally destroying or falsifying financial records under Section 802, and any company planning an IPO needs SOX-compliant controls actually operating, not just designed, before it goes public.
How long does SOX compliance preparation typically take for a company heading toward an IPO?
Most guidance recommends starting 18 to 24 months before the intended filing date, which allows roughly a year of controls actually operating and producing evidence before they're tested for real, rather than designing and testing them simultaneously under filing deadline pressure.



.webp)












