Frameworks

What is SOX compliance?

SOX compliance means meeting the requirements of the US Sarbanes-Oxley Act of 2002, which requires public companies to maintain and assess internal control over financial reporting. Section 404 in particular drives IT general controls over the systems behind the financials.

Definition

SOX compliance is adherence to the Sarbanes-Oxley Act of 2002, a US federal law that requires public companies to establish, maintain, and assess internal control over financial reporting (ICFR) and to certify the accuracy of their financial statements.

Background

Sarbanes-Oxley was enacted after major accounting scandals to restore confidence in public-company financial reporting. Its best-known provision, Section 404, requires management (and, for larger companies, the external auditor) to assess the effectiveness of internal control over financial reporting. Because the numbers live in IT systems, SOX programs lean heavily on IT general controls (ITGCs): access to financial systems, change management, and operations. Section 302 also requires executives to personally certify the financial statements.

Why it matters

SOX applies to US public companies (and companies going public), so it is usually out of scope for early-stage private SMBs. But its ITGC expectations, such as access control and change management over key systems, overlap with the same controls used for SOC 2 and ISO 27001, so a mature security program is a head start on SOX.

Step by step

  1. Identify the systems and processes that feed financial reporting.
  2. Document the controls over those systems, including access and change management.
  3. Test that the controls operate effectively over the period.
  4. Remediate gaps and retain evidence of control operation.
  5. Support management (and, where applicable, auditor) assessment and executive certification.

Examples

  • A newly public company scopes its financial systems and formalizes access reviews and change management as IT general controls.
  • A private SMB with SOC 2 finds its access-control and change-management evidence largely reusable when it later prepares for SOX.

Common mistakes

  • Assuming SOX applies to private companies with no plans to go public; it generally does not.
  • Treating SOX as purely a finance exercise and ignoring the IT general controls behind the numbers.
  • Testing controls once rather than demonstrating they operated over the reporting period.

FAQ

Who does SOX apply to?

Primarily US publicly traded companies, and companies preparing to go public. Private companies with no public-market plans are generally not subject to SOX, though acquirers or lenders may still ask about financial controls.

How does SOX relate to SOC 2?

They are different: SOX is a law about financial-reporting controls, while SOC 2 is a voluntary report about security and related criteria. They overlap on IT general controls such as access and change management, so work on one can support the other.

Related

What is a security control? → What are access reviews? → What is SOC 2? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free