Skip to main content

Overview

The Sarbanes-Oxley Act of 2002 (SOX) applies to public companies listed on US stock exchanges and their subsidiaries, as well as accounting firms auditing those companies. It imposes requirements on the accuracy and integrity of financial reporting - and on the internal controls that produce that reporting. SOX created significant personal liability for CFOs and CEOs who certify the accuracy of financial statements. As a result, internal control frameworks have become critical corporate infrastructure - and the audit evidence supporting those controls must be verifiable. ROOTKey addresses the audit trail and evidence integrity requirements that underpin SOX Section 302 and 404 compliance.

Section-Level Coverage

Section 302 - Corporate Responsibility for Financial Reports

Section 302 requires the principal executive officer and principal financial officer to personally certify the accuracy of financial reports and the effectiveness of internal controls - every quarter. The certification covers:

Section 404 - Management Assessment of Internal Controls

Section 404 requires management to annually assess and report on the effectiveness of internal controls over financial reporting (ICFR). External auditors must then attest to that assessment.

Section 409 - Real-Time Disclosure

Section 409 requires companies to disclose material changes in financial condition or operations on a rapid and current basis. ROOTKey anchors disclosure records at submission - providing independently verifiable proof of timing.

IT General Controls (ITGC) and SOX

SOX compliance increasingly depends on IT General Controls - the controls over the IT systems that produce financial data. External auditors and their IT auditors examine:

PCAOB Standards and Audit Evidence

The Public Company Accounting Oversight Board (PCAOB) sets standards for external auditors. Auditors examining ICFR must evaluate whether:
  1. Evidence of control operation is authentic - not created after the fact
  2. Evidence of exception handling is complete - not selectively disclosed
  3. Evidence of IT controls is technically sound
ROOTKey blockchain anchors provide audit evidence that auditors can verify independently:

Applicability


Request a SOX compliance review

We’ll design a ROOTKey implementation for your ICFR audit trail that satisfies both management and external auditor requirements.

Regulatory audit trails use case

Full implementation guide for SOX-compliant audit trail infrastructure.