Sarbanes-Oxley Act
Sarbanes-Oxley Act of 2002 (SOX) is a federal statute regulating certain aspects of corporate financial reporting, auditing, and internal controls for public companies and other issuers subject to the federal securities laws. Congress enacted SOX in 2002 to protect investors by improving the accuracy and reliability of corporate disclosures made under securities laws. Much of SOX is codified in 15 U.S.C. Chapter 98, but important provisions also appear elsewhere in Title 15 and Title 18.
SOX created the Public Company Accounting Oversight Board (PCAOB) to oversee audits of companies subject to the securities laws. The PCAOB registers public accounting firms, sets auditing, quality-control, ethics, independence, and other standards, inspects registered firms, conducts investigations and disciplinary proceedings, and enforces compliance with SOX, PCAOB rules, professional standards, and related securities laws.
Section 301 strengthened audit committees. For issuers covered by audit-committee rules, the audit committee is directly responsible for the appointment, compensation, and oversight of the registered public accounting firm that prepares or issues the issuer’s audit report. The public accounting firm must report directly to the audit committee, and the audit committee must establish procedures for handling complaints about accounting, internal accounting controls, or auditing matters, as well as confidential, anonymous employee submissions about questionable accounting or auditing matters.
Several SOX provisions focus on management responsibility for financial reports. Section 302 requires a company’s principal executive and financial officers, often the chief executive officer and chief financial officer, to certify annual and quarterly reports filed with the Securities and Exchange Commission (SEC). The officers must certify, among other things, that they reviewed the report, that the report does not contain material misstatements or omissions, and that the financial information fairly presents the issuer’s financial condition and results of operations in all material respects. Section 303 prohibits officers, directors, and others acting under their direction from fraudulently influencing, coercing, manipulating, or misleading an independent auditor for the purpose of making financial statements materially misleading.
Section 404 requires annual reports to contain an internal control report in which management states its responsibility for internal control over financial reporting and assesses the effectiveness of those controls. A separate auditor-attestation requirement generally applies to accelerated filers and large accelerated filers that are not emerging growth companies; it does not apply to issuers that are neither accelerated filers nor large accelerated filers.
SOX also includes enforcement and investor-protection provisions beyond officer certifications and internal controls. Section 806 protects covered whistleblowers from retaliation for reporting certain suspected fraud or securities-law violations. Section 802 added federal criminal provisions, including a provision making it a crime to knowingly destroy, alter, conceal, falsify, or make a false entry in records with the intent to impede, obstruct, or influence a federal investigation, a matter within the jurisdiction of a federal department or agency, or a bankruptcy case. Section 906 separately requires chief executive and financial officers to certify certain periodic financial reports and creates criminal penalties for knowing or willful false certifications.
[Last reviewed in June of 2026 by the Wex Definitions Team]
Wex