U.S. law governing public-company audit oversight, executive certifications, audit committees, records, and internal-control reporting.
The Sarbanes-Oxley Act of 2002 (SOX) is a U.S. federal law that changed public-company financial reporting, corporate responsibility, audit oversight, and auditor independence. It created the PCAOB, strengthened audit-committee authority, required specified executive certifications, and established internal-control reporting requirements administered through SEC and PCAOB rules.
SOX is not a promise that a public company’s statements contain no errors or fraud. Its requirements create governance, control, reporting, recordkeeping, and enforcement mechanisms; the exact obligation depends on the statutory section, SEC rules, issuer status, and any applicable exemption or transition period.
Congress enacted SOX after major financial-reporting and audit failures exposed weaknesses in auditor oversight, corporate governance, executive accountability, and records preservation. Before SOX, the accounting profession largely relied on self-regulatory structures for public-company audits. The Act introduced independent oversight through the PCAOB and assigned important implementation and oversight functions to the SEC.
SOX applies primarily in the U.S. public-company reporting environment, but it can also affect foreign private issuers, subsidiaries, officers, directors, audit firms, attorneys, and others depending on the provision. A statement that an entity is simply “SOX compliant” is incomplete unless it identifies the requirement, reporting period, control scope, and evidence.
| Section | Main subject | Practical significance |
|---|---|---|
| 101 | PCAOB establishment | Creates the audit-oversight body and its core duties |
| 201 | Auditor services outside the audit | Prohibits specified nonaudit services and supports auditor independence requirements |
| 301 | Public-company audit committees | Addresses audit-committee responsibility for the external auditor and complaint procedures |
| 302 | Corporate responsibility for reports | Requires principal executive and financial officers to make specified certifications in periodic reports |
| 404 | Internal-control reporting | Requires management reporting on internal control over financial reporting and, when applicable, auditor attestation |
| 802 | Records and obstruction | Addresses destruction or alteration of records and audit-record retention |
| 806 | Whistleblower protection | Provides protections and remedies concerning specified retaliation claims |
| 906 | Criminal certification | Requires a separate certification tied to periodic reports and establishes criminal consequences for knowing or willful violations |
This table summarizes the subjects; the statutory text and implementing rules control. SOX obligations should not be inferred from a section number alone.
These provisions are often conflated.
The principal executive and financial officers make certifications concerning the periodic report, including representations about review, material misstatements or omissions, and disclosure controls and procedures. The certifications also address specified control-related information and communications to auditors and the audit committee.
Section 404(a) underlies management’s annual report on internal control over financial reporting (ICFR). Management identifies the control framework used, assesses effectiveness as of the fiscal year-end, and discloses material weaknesses.
Section 404(b) addresses the registered public accounting firm’s attestation on management’s ICFR assessment. Auditor-attestation applicability varies. For example, issuer classifications and statutory or SEC exemptions can remove the 404(b) requirement even though management and certification obligations remain. Therefore, “public company” alone is not enough to determine the exact reporting package.
Assume a public software company discovers that too many employees can change billing data and post manual revenue entries. Reviews of those changes are inconsistent, and management cannot produce evidence that unauthorized entries would be detected promptly.
Management’s response may include:
A material weakness means ICFR cannot be considered effective. It does not prove that a material misstatement occurred. Conversely, correcting a known accounting error does not by itself remediate the control weakness that allowed it.
When the auditor reports on both financial statements and ICFR, the opinions are distinct. The financial statements could receive an unmodified opinion while ICFR receives an adverse opinion because of a material weakness, provided the statements themselves are fairly presented after any necessary corrections.
| Participant | Core responsibility |
|---|---|
| Management | Prepare financial statements, establish and maintain ICFR, assess controls, and make required certifications and disclosures |
| External auditor | Audit financial statements and, when required, audit ICFR under applicable PCAOB standards |
| Audit committee | Oversee financial reporting and the external auditor, including appointment, compensation, and independence matters |
| PCAOB | Register, standard-set for, inspect, and discipline covered audit firms and associated persons |
| SEC | Adopt and enforce implementing securities rules and oversee the PCAOB |
Management cannot transfer its responsibility for the financial statements or control assessment to the auditor. Auditor independence rules also limit the services an audit firm can provide to an audit client.
For analysts and investors, SOX-related disclosures can help identify reporting and governance risk. Useful items include:
The label “remediation underway” is not equivalent to remediation completed. Management generally needs evidence that redesigned controls were implemented and operated effectively before concluding that a material weakness no longer exists.
Requirements and consequences depend on facts, issuer status, SEC rules, and legal interpretation. This page is educational and does not provide accounting, audit, legal, regulatory, compliance, or investment advice.