Achievable logo
Achievable blue logo on white background

Sarbanes-Oxley Act

Also known as: sox, public company accounting reform and investor protection act

The Sarbanes-Oxley Act is a 2002 U.S. federal law that tightened corporate governance, financial reporting, and auditing requirements for public companies. It was passed after the Enron and WorldCom accounting scandals to restore confidence in published financial statements.

Sarbanes-Oxley, commonly called SOX, restructured how public companies report and how their reports are audited. Its central premise is that accurate financial statements depend on three things working together: management being personally accountable for what it publishes, internal controls being strong enough to catch errors and fraud, and auditors being independent enough to challenge management.

Several provisions carry most of the exam weight. Section 302 requires the CEO and CFO to personally certify that each periodic report is accurate and that they have evaluated the company's disclosure controls. Section 404 requires management to assess and report on the effectiveness of internal control over financial reporting, with the external auditor attesting to that assessment for larger filers. Section 802 sets record-retention requirements and criminal penalties for destroying or altering documents, and Section 806 protects employees who report suspected fraud from retaliation.

SOX also changed the auditing profession itself. It created the Public Company Accounting Oversight Board (PCAOB) to register, inspect, and discipline the firms that audit public companies, ending the profession's self-regulation. To protect independence, it bars audit firms from providing many non-audit services — such as bookkeeping, internal audit outsourcing, and certain systems design work — to the same client, requires rotation of the lead audit partner, and places the audit committee, composed of independent directors, in charge of hiring and overseeing the auditor.

On the CMA Part 1 exam, Sarbanes-Oxley appears in the internal control and governance section alongside the COSO framework and external audit requirements. Know which section imposes which obligation, the role of the PCAOB and the audit committee, and how SOX shapes management's responsibility for internal control over financial reporting.

Key takeaways

  • Sarbanes-Oxley (2002) responded to the Enron and WorldCom scandals by tightening reporting, governance, and audit rules for public companies.
  • Section 302 makes the CEO and CFO personally certify the accuracy of periodic reports.
  • Section 404 requires management to assess internal control over financial reporting, with auditor attestation for larger filers.
  • The Act created the PCAOB, replacing the accounting profession's self-regulation with independent oversight.
  • Auditor independence rules restrict non-audit services, require partner rotation, and give an independent audit committee responsibility for the auditor relationship.
Achievable blue logo on white background

Where you'll learn this

Sarbanes-Oxley Act is covered in this Achievable course — jump straight to the textbook sections that teach it, or explore the full course with practice questions and exams:

Achievable blue logo on white background