RegTech Reviews

Sarbanes-Oxley Compliance Requirements for Public Companies

Executives face prison time and million-dollar fines for signing off on faulty financial controls.

Staff Writer · · 11 min read
Cover illustration for “Sarbanes-Oxley Compliance Requirements for Public Companies”
Industry Regulations · September 3, 2026 · 11 min read · 2,398 words

Sarbanes-Oxley treats corporate fraud as a chain of failures, not a single bad actor cutting corners. Congress passed it on July 30, 2002, in direct response to Enron, WorldCom, and Tyco, and it rebuilt the plumbing of public company accountability: executive certification, internal control testing, auditor independence, and disclosure timing. What follows breaks down each requirement by the specific failure it was built to close, because SOX makes the most sense when read as a diagnosis of what went wrong before it existed. The diagnosis was blunt: executives faced no personal accountability for false disclosures, auditors had financial incentives to look the other way, and internal controls were either missing or ignored.

Every major SOX section maps back to one of those three problems. The law hasn't sat still since 2002, either; PCAOB standards, SEC enforcement priorities, and court rulings keep sharpening what companies actually owe, year after year. Wirecard's 2020 collapse and Silicon Valley Bank's failure in 2023 both show what happens when financial controls and risk management break down, even in places outside the reach of U.S. securities law. This pattern doesn't stay contained to one jurisdiction, and it's worth sitting with before getting into the mechanics of the statute itself.

Which companies SOX covers and which are partially exempt

Coverage is broad by design. Every U.S.-listed public company and its wholly-owned subsidiaries has to comply, and there's no size-based opt-out anywhere in the statute. Foreign private issuers registered with the SEC and trading on U.S. exchanges face the same core obligations as domestic filers; listing on a U.S. exchange means playing by U.S. disclosure rules, full stop.

The real carve-out sits in Section 404(b), the requirement that an external auditor attest to a company's internal controls. That obligation skips non-accelerated filers (public float below a defined SEC threshold), smaller reporting companies under SEC size rules, and emerging growth companies for up to five years after their IPO. The EGC revenue threshold sits below $1.235 billion, adjusted for inflation over time.

Here's what trips people up: exemption from 404(b) is a much narrower deal than the word "exempt" suggests. Exempt companies still owe the Section 404(a) management assessment, Section 302 executive certifications, real-time disclosure under Section 409, and the full set of recordkeeping and whistleblower obligations. The GAO's July 2025 report (GAO-25-107500) shows exactly why that gap costs something real. Looking at a sample of 100 restatements from 2022 to 2023, the GAO found that 73% of exempt companies cited both ineffective internal controls and material weaknesses, compared to 59% of nonexempt companies. That fourteen-point gap reflects what the 404(b) audit attestation is meant to catch, and its absence shows up in outcomes.

Diagram: The 404(b) Exemption Gap: Restatements by Filer Type. Visualizes: Visualize a single stark contrast: among a GAO sample of 100 restatements from 2022–2023, 73% of exempt companies (those without 404(b) auditor attestation) cited both…

Section 302 and what executive certification actually requires

CEOs and CFOs sign a certification with every quarterly and annual SEC filing, personally, not through a designee and not through outside counsel. That signature says several specific things happened: the financial statements are complete and free of material misstatement, the signing officers reviewed the company's disclosure controls, any significant deficiencies or material weaknesses got reported to the audit committee and external auditors, and any fraud involving management got disclosed.

The penalties for a false certification aren't symbolic. Knowing violations carry fines up to $1 million and up to 10 years in prison; willful violations go up to $5 million and 20 years. That gap between "knowing" and "willful" is intentional, and it exists so prosecutors can reach both the executive who signed carelessly and the one who signed knowing the numbers were cooked.

The practical effect is that plausible deniability mostly disappears: an executive who signs a 302 certification every quarter has, by definition, already attested to reviewing the controls and disclosing what's broken. Claiming ignorance after the fact runs straight into that paper trail. Section 302 works less like a disclosure rule and more like an incentive structure, one that pushes executives to actually engage with Section 404's control assessment instead of handing it off to someone else and hoping for the best.

Section 404 and the internal control assessment that drives most of the compliance workload

Section 404 splits into two distinct obligations, and mixing them up is a common mistake. 404(a) requires management to assess the effectiveness of internal controls over financial reporting and include that assessment in the annual report; it applies to every public company, no matter the size. 404(b) requires the company's independent auditor to separately attest to that assessment, and it only applies to accelerated and large accelerated filers.

Most companies build their assessment around the COSO framework, which sorts controls into five buckets: control environment, risk assessment, control activities, information and communication, and monitoring. In practice, the work runs through four stages. Scoping figures out which financial reporting processes and systems actually matter. Documenting maps each identified risk to the control meant to catch it. Testing checks whether controls are designed properly and actually operating as intended, not just written down somewhere and left unreviewed. Reporting discloses whatever material weaknesses the testing turns up.

None of this comes cheap. The KPMG 2025 SOX Survey put the average annual cost of a 404 compliance program at $2.3 million, eating up 15,581 hours, with 45% of organizations reporting cost increases year over year. A material weakness, in the statute's own language, is a deficiency, or combination of deficiencies, where there's a reasonable possibility a material misstatement wouldn't get caught in time. Disclosing one triggers real scrutiny from investors and auditors alike, and that's exactly the point: controls left untested tend to reveal their gaps only after the damage is already done, which is the whole argument for testing them twice a year instead of once a decade.

How auditor independence rules limit the relationships between companies and their accounting firms

Before SOX, auditors often made more money selling consulting services to the same companies they audited, and that arrangement put a soft thumb on the scale. An auditor who needs the client's consulting fees has a harder time issuing an unfavorable opinion, even when the opinion looks objective on paper.

SOX rebuilt the structure around that exact problem. The PCAOB, a nonprofit the statute created, oversees every audit firm that audits a public company, and its rules need SEC approval before they take effect. Audit committees, not company management, now hire and supervise the external auditor. The lead audit partner and the reviewing partner have to rotate off an engagement after five consecutive years. Certain non-audit services, like bookkeeping, financial system design, or anything that resembles a management function, are off-limits for a company's own auditor.

The PCAOB's enforcement teeth are real, and they've gotten sharper. Firms can face fines up to $2 million per violation for misconduct, and under the most serious penalty tier, reserved for intentional, knowing, or reckless conduct, a firm faces roughly $26.1 million per violation and an individual roughly $1.3 million, under the inflation-adjusted schedule that took effect in January 2025. Enforcement activity has remained active in recent years, which says the oversight body is actively pursuing violations rather than just filing paperwork about them. The rulemaking hasn't slowed down; if anything it keeps tightening.

Real-time disclosure, document retention, and the other operational requirements that run year-round

Section 409 requires companies to disclose material changes to their financial condition or operations fast, without the grace period companies used to lean on before SOX existed. Investors get material information as it becomes known, not three months later once it's convenient to fold into a quarterly filing. Material changes that trigger this include major contract wins or losses, significant litigation developments, leadership changes with financial consequences, and internal control failures that just got discovered.

Section 802 covers records, and it doesn't leave much room for interpretation: willfully destroying, altering, or falsifying documents tied to a federal investigation or bankruptcy proceeding carries up to 20 years in prison. That covers audit workpapers, financial records, and electronic communications alike. The operational lesson is that retention schedules need to be written down and applied the same way every time, and preserved the moment litigation or a regulatory inquiry becomes reasonably foreseeable. Deleting things after a problem surfaces is precisely the scenario Section 802 exists to punish, and courts have shown little patience for companies caught doing it.

SOX never mentions cybersecurity by name, but the financial data behind internal control assessments lives inside IT systems, which pulls IT general controls, access controls, change management, system availability, fully into Section 404's reach. Companies have to show that only authorized people can touch systems that affect financial reporting. Outsourcing to a cloud vendor doesn't outsource the compliance obligation either; companies stay on the hook for validating vendor IT controls every year, regardless of the vendor's own preferences. Auditing standards continue to evolve in ways that raise the bar on how auditors evaluate evidence generated by company information systems, so system-generated data gets more scrutiny going forward, not less.

Whistleblower protections under Section 806 and why they matter for the overall compliance structure

Section 806 bars retaliation against employees who report suspected securities fraud, whether the report goes to the SEC, to Congress, or to an internal supervisor. Retaliation covers demotion, suspension, harassment, and termination, and the protection reaches past direct employees to contractors, subcontractors, and agents of the company.

The Supreme Court's 2024 ruling in Murray v. UBS Securities matters here more than most people give it credit for. UBS researcher Trevor Murray reported unethical trading practices, got fired, and sued for retaliation; the Court ruled in his favor and clarified the standard employees need to meet to win a SOX retaliation claim. That clarification lowers the bar for plaintiffs, which means employers now have less room to treat internal complaints as background noise.

The enforcement numbers back that up. In 2024, the SEC's Whistleblower Program took in around 24,000 tips, and the SEC hit J.P. Morgan with an $18 million civil penalty, the largest on record for a standalone whistleblower protection rule violation. Substantial whistleblower awards have been granted to employees who were fired for reporting financial misconduct. Numbers like that say regulators treat retaliation cases as a real enforcement priority, not an afterthought. The practical upshot: companies need an internal reporting channel that's actually confidential and actually works, with audit committees generally required to set up procedures for handling employee complaints about accounting and controls, plus training so managers know what counts as prohibited retaliation before they stumble into it by accident.

The cost structure of SOX compliance and how it scales with company size

Diagram: SOX Compliance Cost: Where the Money Goes. Visualizes: Show how the $2.3 million average annual SOX compliance cost (KPMG 2025 SOX Survey, 15,581 hours) breaks into three buckets: internal labor (finance, internal audit, IT, legal —…

SOX spending breaks into three buckets. Internal labor covers the hours finance, internal audit, IT, and legal teams spend on documentation, testing, and fixing whatever the testing finds broken. External consulting and technology covers advisory firms, governance software, and the specialist tools used for controls documentation. Auditor attestation fees cover the added cost of the 404(b) opinion for accelerated filers.

The KPMG 2025 SOX Survey put average total cost at $2.3 million a year and 15,581 hours, and that number describes a program that's already mature; a company standing up its SOX program for the first time should expect to pay more in year one, not less.

Size matters here in a way that cuts against intuition. The GAO's 2025 report found accelerated filers paid roughly 19% more in dollar terms than exempt firms, but the burden lands harder, proportionally, on smaller companies measured against their revenue. The jump into 404(b) audit attestation raised issuer audit fees by roughly 13% in the first year, a median increase of $219,000, which is not a small sum for a company just crossing the accelerated filer threshold. So the intuitive story, that big companies eat the biggest compliance bill, is true only in raw dollars; scaled to revenue, it's the smaller company writing the harder check.

Most of the labor cost sits inside the 404 assessment cycle itself: scoping, documenting, testing, remediating. IT controls testing and auditor support are the fastest-growing pieces as systems get more tangled together. There's an early signal that technology is starting to bend that cost curve, with AI-based tools being piloted for evidence retrieval and control-to-risk mapping, work that used to burn analyst hours by the hundreds. Whether that becomes the industry norm or stays a one-off experiment is still an open question, and it's a fair one to ask again in a couple of years.

Penalties for non-compliance and what enforcement cases reveal about where risk is highest

Criminal exposure for individuals scales with intent. Knowing violations, like a false Section 302 certification, carry up to $1 million in fines and 10 years in prison. Willful violations climb to $5 million and 20 years. Document destruction under Section 802 tops out at 20 years on its own. Civil penalties under PCAOB enforcement reach roughly $26.1 million per violation for firms and $1.3 million per violation for individuals, under the most serious tier of the January 2025 inflation-adjusted schedule.

Enforcement history says where the risk actually concentrates, and it's rarely in exotic derivatives or complicated hedge accounting; it's usually somewhere much plainer. Monsanto paid an $80 million SEC fine in 2016 for failing to properly record state-funded rebates on pesticide sales, inflating earnings over three years through a basic revenue recognition failure rather than any elaborate financial engineering scheme. ArthroCare's former CFO got sentenced to 50 months in prison in 2018 over a $750 million revenue misstatement scheme, where control failures combined with active concealment to make things far worse than either factor alone would have.

The pattern across these cases is the real lesson: the failures tend to sit in the ordinary mechanics of revenue recognition and rebate accounting, the unglamorous corners of the ledger that don't get attention until someone finds them under a microscope. That throughline runs across every section here, from executive certification to auditor independence to the whistleblower who eventually decides to say something. SOX bets on redundancy rather than trusting any single safeguard to catch everything: certifications that build a paper trail, controls tested twice a year, auditors who can't moonlight as consultants, and employees who get a legal shield when they raise their hand. No single layer catches everything on its own, but stacked together, they make it a lot harder for a Monsanto-sized rebate problem to sit unnoticed for three years before someone with the authority to fix it actually looks.

Sources

  1. gao.gov

More in Industry Regulations