Financial Services Regulatory Obligations Under SOX and Dodd-Frank
SOX and Dodd-Frank obligations depend on company size and structure, not just industry.

SOX casts a wide net by design. Every U.S. publicly traded company, every wholly-owned subsidiary, every foreign company doing business in the United States. That is the core understanding most people carry. What many miss is that several SOX provisions extend beyond public companies entirely. Document destruction rules, whistleblower retaliation prohibitions, and certain contractor protections apply regardless of whether a company has ever filed a prospectus. Private companies are not exempt from all of SOX. They are exempt from some of it, and that distinction matters more than most private company executives realize until it is too late — like discovering the exit row seatbelt rules apply to you too, not just the passengers in first class.
For private companies on a path toward an IPO, this carries serious operational weight. The internal controls infrastructure required for Section 404 compliance takes time to build, test, and evidence. Eighteen to twenty-four months before an expected filing date is the functional minimum runway. Not a planning heuristic. A hard project deadline.
Dodd-Frank works differently. Its obligations are tiered by institution size and type, which means the compliance picture for a community bank and a globally systemically important bank are not even approximately similar. The most demanding obligations, including enhanced capital and liquidity requirements, stress testing, and resolution planning, attach to SIFI designation. The risk committee mandate kicks in at $50 billion in average total consolidated assets. Enhanced prudential standards generally do not apply below $100 billion. CFPB rules and additional Dodd-Frank requirements begin at $10 billion in total consolidated assets.
The multi-regulator reality for Dodd-Frank covered entities is one of the most practically complex aspects of the law. Compliance obligations touch the SEC, CFTC, Federal Reserve, OCC, FDIC, and CFPB simultaneously, sometimes for the same underlying business activity. Coordinating across those regulatory relationships is not optional.
The SOX sections that create direct compliance obligations
Section 302 is where personal accountability begins. CEOs and CFOs must certify, in every quarterly 10-Q and every annual 10-K filing, that the financial statements are accurate and that disclosure controls are effective. Civil penalties attach to non-compliance. Section 906 layers criminal liability on top: a knowing false certification carries up to a $1 million fine and ten years in prison; a willful false certification carries up to $5 million and twenty years. The SEC also retains authority to bar individuals from serving as officers or directors.
I want to be direct about something: these are not abstract deterrents. They are the reason a CFO's sign-off on financial reporting is a substantive process rather than a formality. The executives I have seen treat it otherwise have not had a good time explaining that to regulators.
Section 301 governs audit committee independence. The audit committee must have genuine authority to investigate complaints about financial mismanagement or fraud, and the external audit relationship must rotate. Lead audit partner and reviewing partner are required to cycle off after five consecutive years on the engagement.
Section 404 is the most resource-intensive provision in the statute, and it gets its own section below. Sections 409, 802, 806, and 1107 round out the primary obligations. Section 409 requires real-time disclosure of material changes in financial condition or operations. Section 802 establishes record retention requirements: audit workpapers, financial records, and relevant electronic communications retained for a minimum of seven years, with willful destruction or falsification carrying up to twenty years in prison. Sections 806 and 1107 protect whistleblowers, shielding employees who report fraud from discharge, suspension, harassment, and discrimination. Complaints must be filed with the Department of Labor within ninety days of the retaliatory act. These provisions reach private companies, not only public ones.
What Section 404 compliance actually demands in practice
Section 404 is not a checkbox exercise. Management must establish, document, and test internal controls over financial reporting, then attest annually to their effectiveness. For larger public companies, external auditors independently verify that attestation under 404(b). The COSO framework is the de facto organizational standard most companies use to structure this work: risk assessment, control activities, and monitoring components provide the architecture.
The cost is real. According to a 2025 KPMG survey, the average annual cost of maintaining SOX 404 compliance is $2.3 million. Protiviti's 2024 report confirms that compliance requirements have increased over the prior two years, with more than half of respondents reporting rising internal costs. These figures reflect the cumulative burden of documentation, testing cycles, external auditor fees, and remediation of identified deficiencies.
PCAOB 2024 inspection findings surface three recurring failure patterns worth building against explicitly. First, controls with a review element are frequently tested insufficiently. Management review controls are not self-evidencing. The documentation must show what was reviewed, by whom, with what criteria, and what conclusions were reached, not simply that a review occurred. Second, firms are selecting the wrong controls to test. Scoping errors that leave material risks untested are among the most serious failures an auditor can surface, because they represent gaps in the entire assurance structure. Third, audit evidence is not calibrated to the actual assessed level of risk. Higher-risk controls require more rigorous evidence. Treating all controls with equivalent evidentiary standards is a structural flaw, not a minor procedural lapse.
The 404(b) external attestation requirement is phased for smaller reporting companies and emerging growth companies. But the 404(a) management assessment applies regardless. The phase-in does not create a grace period from the underlying control requirement.
The main Dodd-Frank obligations financial institutions face
SIFI classification is the threshold that triggers the most demanding Dodd-Frank obligations. Once an institution receives that designation, enhanced capital and liquidity requirements, annual stress testing under DFAST, and living will obligations all apply. The Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 modified the original thresholds, but the architecture of heightened oversight for the largest institutions remains intact.
Stress testing under DFAST deserves particular attention because the methodology itself is evolving. Twenty-two banks participated in the 2025 stress test cycle. The Federal Reserve proposed material changes in December 2024, including averaging the maximum CET1 capital decline from current and prior year results to reduce volatility in capital requirements. That proposal was open for public comment when this was written, which means the framework institutions are testing against is not static.
Resolution planning, colloquially called living wills, requires covered institutions to document in credible detail how they would wind down operations and distribute liquidity in an orderly manner upon failure. The FDIC maintains Orderly Liquidation Authority under Title II as a backstop for institutions whose failure would pose a systemic threat. These are operationally demanding documentation and governance commitments that require ongoing maintenance, not periodic attention.
The Volcker Rule restricts bank proprietary trading. The 2020 revisions relaxed some of the original limitations, allowing banks to invest in venture capital and certain securitized loan structures, but the core prohibition on short-term proprietary trading in securities, derivatives, and commodity futures remains.
Derivatives regulation under Dodd-Frank requires swap dealer registration, mandatory clearing, and margin requirements for derivatives market participants. Single Counterparty Credit Limits cap net counterparty credit exposure at 25% of capital for Category II and III banks. For G-SIBs, exposure to another G-SIB or nonbank SIFI is capped at 15% of capital. The precision of these limits reflects the systemic risk logic embedded in Dodd-Frank: concentrated counterparty exposure was a direct amplifier of the 2008 crisis, and the rule exists because we saw what happens without it.
CFPB obligations attach at the $10 billion total consolidated assets threshold. The Bureau is authorized to prevent unfair, deceptive, and abusive practices and to promote fair, transparent, and competitive consumer financial markets. What that authorization means in practice has shifted considerably under different administrations.
How the current deregulatory environment is reshaping enforcement, and why that doesn't reduce underlying obligations
The enforcement data tells a clear directional story. PCAOB enforcement actions in 2024 produced $35.7 million in penalties across 51 actions, a record and a 78% increase over 2023. In 2025, that trajectory reversed sharply: 37 enforcement actions, down 27%, with monetary penalties for auditing actions falling 50% to $17.6 million. The SEC's accounting and auditing enforcement fell even more dramatically. Only 10 actions in 2025, down from 31 in 2024, the lowest level in nine years. Monetary settlements dropped to $31 million from $907 million the prior year.
The CFPB story is similarly stark. Under the current administration, multiple consent orders have been rescinded, large-scale supervisory activity has been paused, and enforcement actions have fallen sharply. Wolters Kluwer's 2025 data shows a 37% drop in enforcement actions and a 32% fall in monetary penalties in the first half of 2025 compared to the second half of 2024. The Section 1033 open banking rule, finalized in October 2024, was stayed in 2025 as the CFPB reconsidered its position, while bank trade associations challenged it in court.
Here is what those numbers do not mean: the underlying legal obligations have changed. The CFPB was created by statute within Dodd-Frank. Executive action cannot eliminate it. Reduced enforcement is a bit like a speed camera being switched off — the speed limit is still the speed limit. Reduced probability of federal enforcement is not equivalent to reduced legal exposure, and any compliance officer who conflates the two is making a career-defining mistake.
States are moving to fill the enforcement gap. State attorneys general and state regulators are increasing financial services enforcement activity in areas where federal agencies have pulled back. Institutions that interpret the current federal posture as permanent deregulation are accumulating latent liability. When enforcement priorities shift again, and they will, the conduct record during this period will be fully available to regulators and litigants alike.
Where SOX and Dodd-Frank obligations intersect for financial services firms
A publicly traded bank or broker-dealer does not get to choose between SOX and Dodd-Frank. Both apply simultaneously, and the compliance functions they demand are not fully separable.
Governance structures are the clearest convergence point. SOX's audit committee independence requirements and Dodd-Frank's risk committee mandate at the $50 billion threshold both shape board-level governance architecture. A firm needs structures that satisfy both frameworks, which means designing committees, charters, and reporting lines with dual compliance in mind from the outset, not retrofitting one framework onto a structure built for the other.
Section 404's internal controls scope expands materially for large financial institutions. The ICFR assessment must encompass the business processes that Dodd-Frank also regulates: derivatives clearing, stress test data integrity, living will documentation systems. For a large bank, the ICFR scope is substantially broader than it would be for a non-financial public company of comparable size. The data systems that produce SOX-compliant financial reporting also feed regulatory examinations across the Federal Reserve, OCC, FDIC, CFTC, and CFPB. These are not parallel data infrastructures. They are, or should be, the same underlying systems held to multiple simultaneous standards.
Record retention creates another practical convergence. SOX Section 802's seven-year minimum retention requirement must coexist with examination documentation requirements from Dodd-Frank regulators. A single retention framework needs to satisfy multiple regulatory masters; designing that framework in silos is the kind of inefficiency that becomes expensive during an examination.
Whistleblower programs add a further layer. SOX Sections 806 and 1107 protect internal reporters. Dodd-Frank established a separate SEC whistleblower program that provides financial awards to individuals who report securities law violations. Institutions need internal policies that affirmatively acknowledge both channels, because employees who are aware of violations are also aware of both sets of protections.
Practical steps for maintaining compliance across both regimes
Start with mapping. Confirm which SOX sections apply, confirm which Dodd-Frank thresholds are triggered, and only then allocate compliance resources. Designing controls for obligations that do not apply is waste. Failing to design controls for obligations that do apply is risk. That distinction is where most compliance programs fail before they even begin.
For Section 404, use COSO as the organizing framework. Document controls at a level of specificity that supports external auditor testing, not merely management assertion. Then address the three PCAOB-identified deficiency patterns directly. For management review controls, document the evidence of review: what was examined, who examined it, what criteria were applied, what the conclusion was. For control selection, scope testing to cover all material risk areas, including those that have not historically generated findings. For evidence calibration, ensure that the rigor of audit evidence reflects the assessed risk level of the control, not a uniform standard applied across all controls regardless of materiality.
For Dodd-Frank covered institutions, build a regulatory calendar and treat it seriously. Stress test submission deadlines, living will update cycles, and tiered CFPB compliance dates recur on schedules that require proactive tracking. Institutions that treat these as episodic obligations rather than ongoing program management commitments routinely find themselves in reactive remediation mode, which is both more expensive and more visible to examiners than getting ahead of it.
Monitor the Section 1033 open banking rule's status actively. The largest institutions face compliance dates starting April 2026 if the stay is lifted. The technical and operational infrastructure required is not buildable in weeks, so preparation cannot responsibly wait for final regulatory resolution.
Finally: do not calibrate compliance investment to current enforcement levels. Legal obligations exist independently of whether regulators are actively pursuing them. State-level enforcement is expanding to fill the federal gap, and when federal enforcement resumes, it will resume against a conduct record that has been accumulating the entire time.


