é É « » à è ù ç ô é
Sarbanes-Oxley: definition & meaning
‹ Go back | Glossary

Sarbanes-Oxley: definition & meaning

What is Sarbanes-Oxley (SOX)?

The Sarbanes-Oxley Act of 2002 (SOX) is a US federal law enacted in response to the Enron and WorldCom accounting scandals. It established stringent requirements for financial reporting, internal controls, and corporate governance for companies listed on US exchanges.

Key sections of SOX

  • Section 302: CEOs and CFOs must personally certify quarterly and annual financial reports. Criminal penalties up to $5M and 20 years for wilful violations.
  • Section 404: Management must annually assess ICFR effectiveness using COSO 2013. External auditors must attest for accelerated filers.
  • Section 802: Seven-year minimum retention of financial records and audit workpapers.
  • Section 906: Criminal certification of financial reports with additional penalties.

Who must comply

All companies with securities registered with the SEC, including foreign private issuers. Requirements vary by filer status — large accelerated filers face the most demanding obligations, including external auditor attestation under Section 404(b). In March 2026, the SEC launched a dedicated SOX enforcement group.

SOX and Supervizor

Supervizor strengthens SOX 404 compliance by testing controls on 100% of financial transactions rather than samples — producing continuous evidence of ICFR effectiveness for management's assessment and external auditor reliance. Read our guide: SOX compliance: what internal auditors need to do now.

Related Supervizor pages

Compliance — SOX testing and continuous monitoring

SOX compliance guide for internal auditors

AI & Controls — pre-built SOX controls

PCAOB auditing standards — complete guide