SOX (Sarbanes-Oxley) Explained: What It Means for IT

SOX (Sarbanes-Oxley Act): The Financial Reporting Law That Became an IT Problem

SOX is the federal law that requires publicly traded companies to maintain, test and certify internal controls over financial reporting. A surprising amount of that work lands on IT.

SOX was born from scandal. After the Enron and WorldCom accounting frauds wiped out billions in shareholder value in the early 2000s, Congress passed the Sarbanes-Oxley Act in 2002 to make it much harder for companies to cook their books without anyone noticing. The law added requirements around financial controls, audit independence and executive accountability. What most people don't realize is how much of SOX compliance lives with whoever runs the computers.

What does SOX stand for?

Sarbanes-Oxley Act. It is named after Senator Paul Sarbanes and Representative Michael Oxley, who co-sponsored the legislation, and was signed into law on July 30, 2002. It is enforced by the Securities and Exchange Commission (SEC). The law also created the Public Company Accounting Oversight Board (PCAOB), a nonprofit that oversees the auditors of public companies.

The simple way to think about it

SOX is financial integrity enforcement with teeth. Before SOX, executives could plausibly claim ignorance when financial statements turned out to be fraudulent. After SOX, the CEO and CFO must personally certify the accuracy of financial reports and can face criminal liability if those certifications are knowingly false.

From an IT standpoint, SOX comes down to one question: can you prove that the financial data in your systems is accurate, complete and protected from unauthorized changes? Answering it takes audit trails, access controls, change management and data integrity protections, and all of those are IT jobs.

Who has to comply?

SOX applies to public companies. In practice that includes:

  • Publicly traded companies that file reports with the SEC. This is the core scope.
  • Subsidiaries of public companies, whose systems and controls fall inside the parent's assessment of internal controls.
  • Foreign private issuers listed on U.S. exchanges, which are subject to most SOX requirements.
  • Companies preparing for an IPO, which need SOX-ready controls in place as they become public. Some requirements phase in after listing.

Private companies, including most privately held investment advisers and professional firms, are generally not subject to SOX. A few provisions, such as the criminal penalties for destroying records to obstruct a federal investigation and some whistleblower protections, reach private companies too. Many private companies also adopt SOX-style controls voluntarily because lenders, investors or larger customers ask for them, or because they are building toward an acquisition or IPO.

The sections IT teams care about

SOX has eleven titles, but two sections drive most IT compliance work.

Section 302: Corporate responsibility for financial reports

The CEO and CFO must certify that financial statements are accurate and that they have evaluated the effectiveness of disclosure controls within 90 days before the report. They must also disclose significant deficiencies and material weaknesses to the auditors and the audit committee. That creates a direct line of accountability from the executive suite to the systems that generate and store financial data.

Section 404: Management assessment of internal controls

This is the big one. Management must assess and report each year on the effectiveness of internal controls over financial reporting (ICFR). For larger public companies, the external auditor must also attest to that assessment. In practice, Section 404 work often turns into a thorough review of IT general controls, the technical foundation under the financial systems.

What IT general controls (ITGCs) cover

When SOX auditors examine IT, they focus on IT General Controls (ITGCs): the foundational controls that keep financial systems reliable and their data trustworthy. ITGCs typically cover four areas.

Access controls: who can reach financial systems, what they can do there, and how access is granted, changed and removed. Auditors look for least-privilege access, segregation of duties (the person who enters a transaction shouldn't also approve it), multi-factor authentication and regular access reviews.

Change management: how changes to financial systems and applications are requested, tested, approved and deployed. Unauthorized or untested changes to financial software are a red flag. Auditors want formal change control with documented approvals.

Computer operations: how financial systems are monitored, backed up and recovered. Job scheduling, batch processing and data integrity checks fall here.

Program development: how new financial applications and major system changes are built and rolled out. Auditors want evidence that development and production environments are separated and that new systems are tested before going live.

What happens when SOX controls fail?

SOX distinguishes three levels of control weakness, and the consequences escalate with each.

Control deficiency: a weakness that could, under some circumstances, allow a misstatement. Usually handled internally without public disclosure.

Significant deficiency: more serious than a control deficiency but less than a material weakness, and important enough to merit the attention of those overseeing financial reporting. Reported to the audit committee.

Material weakness: a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement won't be prevented or detected in time. Material weaknesses must be disclosed publicly and can hurt the stock price, invite shareholder lawsuits and draw SEC attention.

For individuals, SOX carries criminal penalties for executives who willfully certify false financial statements, including large fines and prison terms of up to 20 years.

How SOX connects to managed IT services

Many smaller public companies, and divisions of larger ones, don't have a dedicated IT compliance team. The work often falls to a Managed Service Provider (MSP), the internal IT team or both. SOX-relevant work an MSP typically supports includes:

  • Access management: provisioning and removing user accounts, a core ITGC that auditors test every year.
  • Audit logging: records of who accessed financial systems and when, which auditors rely on as evidence.
  • Change management documentation: an MSP that changes financial system environments needs to document those changes in a form auditors can review.
  • Backup and recovery: tested and documented, with recovery objectives that match business continuity needs. See our backup and disaster recovery service.
  • Patch management through remote monitoring and management (RMM). Unpatched systems in a financial environment tend to become audit findings.
  • Endpoint protection such as EDR. SOX doesn't name specific security tools, but EDR is commonly used to support the protection of financial systems.
  • Environment separation: keeping development, testing and production distinct.

One thing worth flagging: if your MSP changes financial system infrastructure, it may need to be included in your SOX change management process. Auditors increasingly ask about third-party access to financial systems and whether it is controlled and logged.

How SOX fits into the bigger compliance picture

SOX rarely stands alone, especially in financial services.

  • SEC and FINRA rules govern registered investment advisers and broker-dealers whether or not they are public. A publicly traded broker-dealer or advisory firm faces SOX on top of those recordkeeping and cybersecurity rules.
  • GLBA applies separately to financial institutions that handle consumer financial data. A public financial services company can face both SOX and GLBA.
  • NIST frameworks are often used as the implementation blueprint for IT general controls. NIST SP 800-53 maps well to ITGC requirements.
  • SOC reports from cloud and software vendors matter in SOX audits. If your financial systems run on a third-party platform, auditors will want that provider's SOC 1 report, and often its SOC 2 report as well.

Key terms at a glance

  • SOX: federal law requiring public companies to maintain and certify internal controls over financial reporting.
  • Sections 302 and 404: the two sections that drive most IT compliance work.
  • ITGCs: IT general controls covering access, change management, operations and development.
  • Material weakness: the most serious control failure, disclosed publicly.
  • PCAOB: the board that sets auditing standards for public company audits.
  • Who it applies to: public companies, their subsidiaries and IPO-track companies. Many private companies adopt SOX-style controls voluntarily.

SOX audit findings in IT are often surprises: gaps in access controls or change management that nobody flagged until an auditor asked. If you are a public company, or headed that way, NerdSquad can help you put access, logging, backup and change controls in place and document them before your auditors arrive. NerdSquad is not a law firm or an audit firm; confirm your obligations with your compliance counsel and auditors.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT for financial advisers and wealth managers