Frameworks
What is SOX compliance?
In short
SOX compliance means meeting the requirements of the US Sarbanes-Oxley Act of 2002, which requires public companies to maintain and assess internal control over financial reporting. Section 404 in particular drives IT general controls over the systems behind the financials.
Definition
SOX compliance is adherence to the Sarbanes-Oxley Act of 2002, a US federal law that requires public companies to establish, maintain, and assess internal control over financial reporting (ICFR) and to certify the accuracy of their financial statements.
Background
Sarbanes-Oxley was enacted after major accounting scandals to restore confidence in public-company financial reporting. Its best-known provision, Section 404, requires management (and, for larger companies, the external auditor) to assess the effectiveness of internal control over financial reporting. Section 404 itself lists no controls: the SEC rule implementing it requires management’s evaluation to rest on "a suitable, recognized control framework" and to name the framework used, which in practice is almost always COSO’s Internal Control—Integrated Framework (2013). Because the numbers live in IT systems, SOX programs lean heavily on IT general controls (ITGCs): access to financial systems, change management, and operations. Section 302 also requires executives to personally certify the financial statements.
Why it matters
SOX applies to US public companies (and companies going public), so it is usually out of scope for early-stage private SMBs. But its ITGC expectations, such as access control and change management over key systems, overlap with the same controls used for SOC 2 and ISO 27001, so a mature security program is a head start on SOX.
Step by step
- Identify the systems and processes that feed financial reporting.
- Document the controls over those systems, including access and change management.
- Test that the controls operate effectively over the period.
- Remediate gaps and retain evidence of control operation.
- Support management (and, where applicable, auditor) assessment and executive certification.
Examples
- A newly public company scopes its financial systems and formalizes access reviews and change management as IT general controls.
- A private SMB with SOC 2 finds its access-control and change-management evidence largely reusable when it later prepares for SOX.
Common mistakes
- Assuming SOX applies to private companies with no plans to go public; it generally does not.
- Treating SOX as purely a finance exercise and ignoring the IT general controls behind the numbers.
- Testing controls once rather than demonstrating they operated over the reporting period.
FAQ
-
Who does SOX apply to?
- Primarily US publicly traded companies, and companies preparing to go public. Private companies with no public-market plans are generally not subject to SOX, though acquirers or lenders may still ask about financial controls.
-
How does SOX relate to SOC 2?
- They are different: SOX is a law about financial-reporting controls, while SOC 2 is a voluntary report about security and related criteria. They overlap on IT general controls such as access and change management, so work on one can support the other.
-
What framework is a SOX assessment made against?
- A recognized internal-control framework, because Section 404 names none. The SEC rule (17 CFR 240.13a-15(c)) requires management’s evaluation to rest on "a suitable, recognized control framework", and Item 308 of Regulation S-K requires management’s report to identify the one used. Overwhelmingly that is COSO’s Internal Control—Integrated Framework (2013), whose five components (control environment, risk assessment, control activities, information and communication, and monitoring) break into seventeen principles. Those principles are the entity-level layer the assessment is made against, above the process-level controls over revenue, procure-to-pay, payroll, the financial close and management estimates.
-
Does Keel cover SOX?
- Yes, at Section 404 scope. Keel authors and scores the five components and seventeen principles of the COSO Internal Control—Integrated Framework (2013), the framework management evaluates internal control over financial reporting against. That is the complete declared scope: it is not the whole Sarbanes-Oxley Act, and it excludes the Section 302 and 906 officer certifications, the Section 404(b) auditor attestation, COSO’s points of focus, and the process-level controls over revenue, procure-to-pay, payroll, the close and estimates. Scoring 100% is an entity-level self-assessment, not a determination that ICFR is effective and not a Section 404 conclusion.
Next step
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.