What Is SOX Compliance? Requirements, Controls, and the Checklist
SOX compliance means meeting the requirements of the Sarbanes-Oxley Act of 2002, and in practice it comes down to one thing: a public company has to maintain internal control over financial reporting, test that it works, and have its executives certify the results every quarter and every year. The law applies to companies with securities registered with the SEC, including foreign private issuers listed in the US, and it reaches private companies only when they are preparing to go public or are owned by a registrant. The operative sections are 302, which requires CEO and CFO certifications on each periodic report, and 404, which requires an annual management assessment of internal control and, for larger filers, an independent auditor's attestation. Everything else in a SOX program exists to make those certifications true.
Who has to comply, and when
Every SEC registrant files Section 302 certifications from its first periodic report as a public company. Section 404(a), management's annual assessment of internal control over financial reporting, phases in: a newly public company is not required to include the management report until its second annual report on Form 10-K. Section 404(b), the auditor's attestation, applies only to accelerated and large accelerated filers, meaning public float of $75 million or more together with revenue tests, and emerging growth companies under the JOBS Act are exempt from 404(b) for up to five years after their IPO. Non-accelerated filers are permanently exempt from the auditor attestation but still owe the management assessment. The practical consequence is that a company has roughly a year after listing before its controls are formally assessed, and that year is where readiness work either happened or did not.
The sections that do the work
Section 302 requires the principal executive and financial officers to certify, on every 10-Q and 10-K, that they reviewed the report, that it contains no material misstatements, that the financial statements fairly present the company's condition, and that they are responsible for disclosure controls and internal control and have evaluated them. Section 906 attaches criminal penalties to knowingly false certifications: fines up to $5 million and up to 20 years in prison for willful violations. Section 404 requires the annual internal control report and, where applicable, the auditor's opinion on internal control over financial reporting, which the auditor issues under PCAOB Auditing Standard 2201 as part of an integrated audit. Section 301 requires an independent audit committee with a whistleblower channel. Section 802 sets record retention requirements and penalties for altering documents. Section 409 requires rapid disclosure of material changes. A compliance program that maps to these sections has a defensible structure; one built around a vendor's checklist alone usually does not.
Internal control over financial reporting, defined
Internal control over financial reporting, or ICFR, is the set of policies, procedures, and system controls that give reasonable assurance the financial statements are reliable and prepared in accordance with GAAP. Nearly every US registrant evaluates ICFR against the COSO Internal Control framework, which organizes controls into five components: control environment, risk assessment, control activities, information and communication, and monitoring. In practice, a company's SOX program documents three layers of control. Entity-level controls cover tone, governance, and the period-end close. Process-level controls sit inside revenue, procure-to-pay, payroll, treasury, inventory, and financial close, as preventive and detective steps such as three-way matches, reconciliations, and management review of estimates. And IT general controls sit underneath both, governing access to systems and data, changes to applications, and operations, so that the automated controls and system reports the process controls depend on can be trusted. The IT layer is where readiness programs most often fall short, and BD Emerson runs that testing through our ITGC audit practice.
Disclosure controls versus internal control
SOX asks companies to maintain two related but distinct systems. Internal control over financial reporting, the subject of Section 404, covers the controls that make the financial statements reliable. Disclosure controls and procedures, referenced in Section 302, cover the broader process by which everything a company must disclose, financial and otherwise, is captured, evaluated, and reported on time, including risk factors, legal proceedings, material events, and, more recently, cybersecurity incidents. A company can have effective internal control and still fail on disclosure controls if a material contract loss or a security breach never reaches the people who decide what goes in the filing. The practical structure most companies use is a disclosure committee of finance, legal, operations, and security leaders that meets each quarter before the filing, reviews what happened, decides what is material, and documents the decision. The 302 certifications rest on that process as much as on the control testing.
How a SOX program runs each year
A working program follows the same cycle annually. Scoping starts from materiality: which accounts and disclosures are significant, which locations and systems feed them, and which risks of material misstatement each one carries. Risk assessment then identifies where a misstatement could occur and which controls address it, producing the key control population, typically dozens to a few hundred controls depending on company complexity. Documentation records each control's design in a risk and control matrix and process narratives or flowcharts. Testing evaluates design effectiveness first, then operating effectiveness across the period, with sample sizes scaled to control frequency. Deficiencies are evaluated individually and in aggregate and classified as a control deficiency, a significant deficiency, or a material weakness based on the likelihood and magnitude of the misstatement they could allow. Remediation closes gaps before year end so that the control operates effectively for a long enough period to be tested again. Then management concludes, the auditor concludes where 404(b) applies, and the certifications are signed. Companies that treat this as a project rediscover it every year; companies that treat it as an operating rhythm get cheaper and faster each cycle.
What SOX compliance costs, and what drives it
First-year programs are the expensive ones. A smaller newly public company typically spends in the low-to-mid hundreds of thousands of dollars on readiness, documentation, and testing, before audit fees, and larger or more complex companies spend well into seven figures. The drivers are the number of significant locations and systems, the degree of manual processing in the close, the maturity of IT general controls, and how much of the work is done by internal audit versus outside advisors. Costs fall in later years as control populations are rationalized and testing becomes routine, and they rise again with acquisitions, system implementations, and restatements. The single largest avoidable cost is a material weakness in the first assessment year, which triggers disclosure, remediation under scrutiny, and often a second round of advisory and audit fees.
The checklist for a company starting out
The starting point is a written scope: the significant accounts, the processes that produce them, the systems in scope, and the entity-level controls. From there the program needs a risk and control matrix for each in-scope process with key controls identified and owners named, IT general controls documented for every in-scope system, a testing plan with sample sizes and a calendar that finishes before year end, a deficiency evaluation framework that the audit committee has seen, a remediation tracker with dates, a disclosure controls and procedures process that supports the 302 certifications each quarter, an audit committee charter and whistleblower channel that satisfy Section 301, and a record retention policy that satisfies Section 802. Each item is ordinary on its own. The failure mode is starting them in the fourth quarter of the year in which the first assessment is due.
SOX and the security program
SOX is a financial reporting law, but its IT general controls overlap heavily with the access, change, and logging controls in a security program. Companies already holding a SOC 2 report or an ISO 27001 certificate, whose controls we map in our SOC 2 compliance checklist, have most of the ITGC evidence in hand and mainly need to scope it to financially relevant systems and align the testing periods. The reverse is also true: a SOX program run without the security team produces controls that satisfy the auditor and miss the actual risk. BD Emerson works both sides of that line through our SOX compliance consulting practice, from first-year readiness and control design through annual testing that internal audit can rely on, with the ITGC work performed by practitioners who also run SOC 2 and ISO programs. We prepare the company and its evidence; the independent 404(b) opinion, where one is required, comes from the company's external auditor.
