What It Is

The Sarbanes-Oxley Act (SOX) is a U.S. federal law designed to protect investors by ensuring the accuracy, integrity, and reliability of financial reporting for publicly traded companies.

SOX is Public Law 107-204, enacted July 30, 2002 in response to major corporate accounting scandals. Its long title states the purpose plainly: "To protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws." Title I of the Act created the Public Company Accounting Oversight Board (PCAOB), which oversees the audits of public companies.

The Act focuses on internal controls, accountability, and auditability - and the SEC administers its disclosure requirements.

What Information Is Regulated

SOX focuses on financial reporting and the systems that support it, including:

  • General ledger and ERP platforms: where the numbers live.
  • Accounting and payroll systems: transaction sources feeding the ledger.
  • Revenue recognition tools: where judgment meets automation.
  • Financial reporting databases, warehouses, and integrations: every hop the data takes.
  • Change management and deployment systems: how financial logic gets modified.
  • User access to financial systems: who can touch the numbers, and how.

From an IT perspective, SOX is about preventing unauthorized changes, errors, or manipulation of financial data.

IT Requirements

SOX does not prescribe specific technologies. It requires strong, auditable controls around systems that impact financial reporting - and two sections drive most of the IT work.

Section 302 - executive accountability. The principal executive officer and principal financial officer (in practice, the CEO and CFO) must certify in each annual and quarterly report that internal controls are effective, financial reports are accurate, and deficiencies are disclosed (P.L. 107-204 §302). That certification puts direct pressure on the IT controls behind reporting accuracy.

Section 404 - internal control over financial reporting (ICFR). Organizations must design and maintain effective internal controls, test control effectiveness, and document and remediate deficiencies. Management's assessment is §404(a); the independent auditor's attestation is §404(b) - required for accelerated filers, not for smaller reporting companies with revenues under $100 million. Most SOX IT work exists under Section 404.

The IT control areas auditors test:

Access controls and identity management. Role-based access to financial systems, least-privilege permissions, segregation of duties, formal provisioning and deprovisioning, and regular access reviews. Unauthorized access is a major SOX risk.

Change management controls. Formal change approval, testing before production, separation between development and production access, and logging of system and configuration changes. Uncontrolled changes can directly impact financial integrity.

Logging, monitoring, and audit trails. System activity logging, user access logging, change logs, and retention of audit evidence. Auditors must be able to trace financial data back to controlled systems.

Data integrity and backup controls. Protection against unauthorized modification, secure backups, recovery testing, and controls ensuring completeness and accuracy.

Outsourced systems and vendors. SOX does not name vendors - no provision of the Act imposes vendor-management requirements. But outsourced processes that affect financial reporting remain inside your §404 ICFR scope, which is why auditors ask for SOC 1 reports on your service organizations. Outsourcing the process never outsources the control responsibility.

How It Fits Into Cyber Risk Management

SOX rewards exactly what good cyber risk management already builds: controlled access, controlled change, complete audit trails, and tested recovery.

A company that runs a real security program does not build SOX controls from scratch - it maps existing controls to ICFR and closes the documentation gap.

That is also the efficient order of operations: security first, compliance evidence second.

How We Help With SOX Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates the IT general controls behind your financial reporting - access, change management, and audit trails - the way a §404 auditor will.

How to Prepare

  1. Identify financially relevant systems

    Document the systems supporting financial reporting, data flows between them, users and roles, and vendors with access. ICFR scope starts with an honest inventory.

  2. Define and document IT controls

    Ensure controls exist for access management, change management, incident handling, backup and recovery, and logging and monitoring. Controls must be documented and repeatable - an undocumented control fails testing by default.

  3. Test control effectiveness

    Validate that controls operate as designed, evidence can be produced, and exceptions are tracked and remediated. Testing is central to SOX - do it before the auditor does.

  4. Address segregation of duties

    Ensure no single user can create, approve, and post transactions, administrative access is limited and monitored, and compensating controls exist where separation is not possible.

  5. Manage vendors and outsourced systems

    Confirm vendor responsibilities are clear, controls over outsourced processes are tested, and SOC 1 and SOC 2 reports are collected and actually reviewed. Outsourced processes stay inside your ICFR scope.

Official source

Official source: U.S. Securities and Exchange Commission

Secondary source: govinfo, Public Law 107-204

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25