Notes:

  • Sarbanes-Oxley Act (SOX) of 2002: Enacted in response to Enron and WorldCom, SOX revolutionized corporate governance by focusing on internal controls and accountability.
  • Section 302: Corporate Responsibility for Financial Reports:
    • Requires the CEO and CFO to personally certify the accuracy of financial reports and the effectiveness of disclosure controls.
    • Liability: CEOs/CFOs can face criminal penalties (up to 20 years prison) for certifying false reports knowingly.
  • Section 404: Management Assessment of Internal Controls:
    • The Core Requirement: Management must annually assess and report on the effectiveness of Internal Control over Financial Reporting (ICFR).
    • Auditor Attestation: For large accelerated filers, the external auditor must also attest to and report on management’s assessment.
    • COSO Framework: Most companies use the Committee of Sponsoring Organizations (COSO) framework to design and test controls. It covers five components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring.
  • Whistleblower Protections (SOX Section 806):
    • Protects employees of public companies who report fraud from retaliation.
    • Establishes a mechanism for employees to file complaints with the Department of Labor.
  • Audit Committee Independence:
    • Must be composed entirely of independent directors.
    • Must have at least one “Financial Expert” (as defined by the SEC) to oversee the financial reporting process.
  • Remediation of Deficiencies:
    • If a “material weakness” (a deficiency that could lead to a material misstatement) is identified, management must disclose it and outline a remediation plan. Persistent material weaknesses can lead to delisting or loss of investor trust.