Ask your compliance data anything. Sienna Insights, now available.
Join the webinar

SOX Compliance: The Sarbanes-Oxley Act explained

What SOX compliance requires under the Sarbanes-Oxley Act, its whistleblower protections, and how to build a compliant internal reporting channel.

August 24, 2026
—
15 min read
Share

Table of contents

What is SOX compliance?

The Sarbanes-Oxley Act (SOX) is a US federal law passed in 2002 after the Enron and WorldCom accounting scandals. It sets standards for financial reporting, internal controls, and corporate governance at publicly traded companies and their auditors. Complying with SOX means meeting these requirements, from financial disclosure to protecting employees who report fraud.

SOX reaches beyond US borders. If your company is listed on a US stock exchange, you must comply, no matter where you're headquartered. That includes European organizations with US listings and subsidiaries of US-listed parents operating in the EU.

Who does SOX apply to?

SOX covers every company publicly traded on a US exchange, including non-US companies with American Depositary Receipts (ADRs), plus the accounting firms that audit them. Private companies are generally exempt, though many align with SOX principles as governance best practice, especially ahead of an IPO.

The Act names specific parties: your board and senior management, your CEO and CFO (who must personally certify financial statements), internal and external auditors, and anyone who handles financial reporting or has access to material non-public information.

Key requirements of the Sarbanes-Oxley Act

Section 302: corporate responsibility for financial reports

Your CEO and CFO must personally certify that they've reviewed your financial statements, that the statements contain no material misstatements, and that they fairly represent your company's financial condition. Personal liability attaches to this certification. Knowingly signing a false one carries criminal penalties under Section 906, covered below.

Section 404: internal controls over financial reporting

This is the most demanding provision. You must establish, document, test, and report on your internal controls over financial reporting (ICFR), and an independent auditor must attest to their effectiveness. For most organizations, Section 404 compliance means real investment in internal audit infrastructure and process documentation.

Section 806: whistleblower protections

Section 806 bars publicly traded companies from retaliating against employees who report suspected securities violations, SEC rule breaches, or fraud against shareholders. Protected disclosures include reports to a supervisor, a board member, or a federal regulator.

An employee who faces retaliation can file with OSHA. If OSHA doesn't act within 180 days, they can bring an action in federal district court, seeking reinstatement, back pay, and legal fees. They have 180 days from the retaliatory act to file.

To support this, SOX requires you to give employees a confidential, anonymous way to raise concerns about accounting, internal controls, or auditing. Most organizations meet this through an ethics hotline or a whistleblowing software platform.

Section 1107: criminal penalties for retaliation

Section 1107 makes it a federal crime to knowingly retaliate against someone who gives truthful information to law enforcement about a possible federal offense. Penalties include fines and up to ten years in prison.

SOX and the EU: what your organization needs to know

If you operate in both the EU and the US, SOX compliance intersects with the EU Whistleblowing Directive. Both require confidential internal channels and prohibit retaliation, but they differ in scope and process.

SOX targets financial fraud and securities violations, and applies only to publicly traded companies and their subsidiaries. The EU directive covers a much wider range of law breaches and applies to any organization with 50 or more employees. SOX requires audit committee oversight of your reporting channel; the EU directive requires designated follow-up persons and documented response timelines.

If you're subject to both, one well-configured whistleblowing system can typically satisfy the core requirements of each: anonymous reporting, strict confidentiality, a documented case lifecycle, and protection against retaliation.

SOX whistleblowing requirements: what your reporting channel needs

To meet Section 806, your internal channel needs:

  • Confidentiality: employees can raise concerns without their identity reaching anyone outside the investigation.
  • Anonymity: employees who don't want to identify themselves can still submit a report.
  • Audit committee oversight: reports on accounting, controls, and auditing route to the audit committee, not just line management.
  • A clear non-retaliation commitment, communicated to every employee.
  • Access for every employee, including those at international subsidiaries covered by the Act.

For a broader view of what a compliant reporting program looks like in practice, see our complete guide to whistleblowing, our guide to the 5 conditions of effective whistleblowing, and our guide to building a whistleblowing policy.

Penalties for non-compliance

The stakes are high, and they scale with intent. Under Section 906, a knowing false certification carries fines up to $1 million and up to 10 years in prison. A willful violation, where the executive certified a report they knew didn't comply, carries fines up to $5 million and up to 20 years. Companies that willfully fail to keep required records face fines and possible delisting. Retaliation against whistleblowers carries civil liability under Section 806 and criminal penalties under Section 1107.

Beyond the legal exposure, non-compliance costs you trust with investors, auditors, and regulators, the exact relationships your market position depends on.

How SpeakUp supports SOX compliance

With SpeakUp's whistleblowing platform, you get anonymous reporting across web, app, and phone, so every employee has a way to raise a concern. End-to-end encryption and strict access controls protect reporter identity. A documented case management workflow gives you an auditable record of every report and every action taken. Configurable routing sends financial fraud and audit concerns straight to the right oversight body. And with support for 100+ languages, your reporting channel reaches every part of your multinational workforce.‍

‍

Frequently asked questions

Does SOX apply to non-US companies?
Yes. If your company is listed on a US stock exchange, SOX applies regardless of where you're incorporated or headquartered, including European companies with US listings and subsidiaries of US-listed parents.

What's the difference between SOX and the EU Whistleblowing Directive?
SOX is US law focused on financial fraud and securities violations, and applies specifically to publicly traded companies. The EU Whistleblowing Directive is broader, covering a wide range of EU law breaches, and applies to any organization with 50 or more employees in an EU member state. Both require confidential internal channels and prohibit retaliation.

What does a SOX-compliant reporting channel look like?
It lets employees report concerns confidentially and anonymously, routes audit-related concerns to the audit committee, prohibits retaliation, and is accessible to every employee, including those at international subsidiaries. A clear whistleblowing policy and regular employee communication support it.

Can one whistleblowing platform satisfy both SOX and EU directive requirements?
In most cases, yes. A platform that supports anonymous reporting, strict confidentiality, documented case management, and configurable routing can meet the core requirements of both. Review your specific obligations with legal counsel to confirm alignment with any national implementation requirements.

‍

Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share