SOX is the federal law that requires publicly traded companies to maintain, test and certify internal controls over financial reporting. A surprising amount of that work lands on IT.
SOX was born from scandal. After the Enron and WorldCom accounting frauds wiped out billions in shareholder value in the early 2000s, Congress passed the Sarbanes-Oxley Act in 2002 to make it much harder for companies to cook their books without anyone noticing. The law added requirements around financial controls, audit independence and executive accountability. What most people don't realize is how much of SOX compliance lives with whoever runs the computers.
Sarbanes-Oxley Act. It is named after Senator Paul Sarbanes and Representative Michael Oxley, who co-sponsored the legislation, and was signed into law on July 30, 2002. It is enforced by the Securities and Exchange Commission (SEC). The law also created the Public Company Accounting Oversight Board (PCAOB), a nonprofit that oversees the auditors of public companies.
SOX is financial integrity enforcement with teeth. Before SOX, executives could plausibly claim ignorance when financial statements turned out to be fraudulent. After SOX, the CEO and CFO must personally certify the accuracy of financial reports and can face criminal liability if those certifications are knowingly false.
From an IT standpoint, SOX comes down to one question: can you prove that the financial data in your systems is accurate, complete and protected from unauthorized changes? Answering it takes audit trails, access controls, change management and data integrity protections, and all of those are IT jobs.
SOX applies to public companies. In practice that includes:
Private companies, including most privately held investment advisers and professional firms, are generally not subject to SOX. A few provisions, such as the criminal penalties for destroying records to obstruct a federal investigation and some whistleblower protections, reach private companies too. Many private companies also adopt SOX-style controls voluntarily because lenders, investors or larger customers ask for them, or because they are building toward an acquisition or IPO.
SOX has eleven titles, but two sections drive most IT compliance work.
The CEO and CFO must certify that financial statements are accurate and that they have evaluated the effectiveness of disclosure controls within 90 days before the report. They must also disclose significant deficiencies and material weaknesses to the auditors and the audit committee. That creates a direct line of accountability from the executive suite to the systems that generate and store financial data.
This is the big one. Management must assess and report each year on the effectiveness of internal controls over financial reporting (ICFR). For larger public companies, the external auditor must also attest to that assessment. In practice, Section 404 work often turns into a thorough review of IT general controls, the technical foundation under the financial systems.
When SOX auditors examine IT, they focus on IT General Controls (ITGCs): the foundational controls that keep financial systems reliable and their data trustworthy. ITGCs typically cover four areas.
Access controls: who can reach financial systems, what they can do there, and how access is granted, changed and removed. Auditors look for least-privilege access, segregation of duties (the person who enters a transaction shouldn't also approve it), multi-factor authentication and regular access reviews.
Change management: how changes to financial systems and applications are requested, tested, approved and deployed. Unauthorized or untested changes to financial software are a red flag. Auditors want formal change control with documented approvals.
Computer operations: how financial systems are monitored, backed up and recovered. Job scheduling, batch processing and data integrity checks fall here.
Program development: how new financial applications and major system changes are built and rolled out. Auditors want evidence that development and production environments are separated and that new systems are tested before going live.
SOX distinguishes three levels of control weakness, and the consequences escalate with each.
Control deficiency: a weakness that could, under some circumstances, allow a misstatement. Usually handled internally without public disclosure.
Significant deficiency: more serious than a control deficiency but less than a material weakness, and important enough to merit the attention of those overseeing financial reporting. Reported to the audit committee.
Material weakness: a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement won't be prevented or detected in time. Material weaknesses must be disclosed publicly and can hurt the stock price, invite shareholder lawsuits and draw SEC attention.
For individuals, SOX carries criminal penalties for executives who willfully certify false financial statements, including large fines and prison terms of up to 20 years.
Many smaller public companies, and divisions of larger ones, don't have a dedicated IT compliance team. The work often falls to a Managed Service Provider (MSP), the internal IT team or both. SOX-relevant work an MSP typically supports includes:
One thing worth flagging: if your MSP changes financial system infrastructure, it may need to be included in your SOX change management process. Auditors increasingly ask about third-party access to financial systems and whether it is controlled and logged.
SOX rarely stands alone, especially in financial services.
SOX audit findings in IT are often surprises: gaps in access controls or change management that nobody flagged until an auditor asked. If you are a public company, or headed that way, NerdSquad can help you put access, logging, backup and change controls in place and document them before your auditors arrive. NerdSquad is not a law firm or an audit firm; confirm your obligations with your compliance counsel and auditors.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.