Global & Sector Regulation
SOX
Sarbanes-Oxley Act
Law / regulation
US / Global
US Congress / SEC / PCAOB
Since 2002
Requires management and auditors to assess and attest to internal control over financial reporting, with personal certification by the CEO and CFO.
Section 404 is why access controls, change management and audit trails on financial data pipelines are tested annually. Any data product feeding the numbers in a listed company's filings is in scope.
At a glance
- Category
- Global & Sector Regulation
- Jurisdiction
- US / Global
- Governance
- US Congress / SEC / PCAOB
- Status
- Enacted 2002; Sections 302 and 404 drive the controls work
- First released
- 2002
Links
Related regulation
Other entries under Global & Sector Regulation.
- BCBS 239: Principles for Effective Risk Data Aggregation and Risk Reporting
- HIPAA: Health Insurance Portability and Accountability Act
- CCPA / CPRA: California Consumer Privacy Act, as amended
See SOX in context
Open the interactive Data Landscape for Regulation to compare SOX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.