Concourse Series A — read the announcement
Finance Automation

SOX Compliance: Requirements, Controls, and How AI Helps

A practical guide to SOX compliance in 2026: what the Sarbanes-Oxley Act requires, the key sections (302, 404, 906), internal controls and ITGCs, a compliance checklist, and where AI agents can automate control testing, evidence, and monitoring, with attestation staying human.

Logan Hine
Logan Hine
Growth
Published September 23, 2026 · 13 min read
Concourse "SOX Compliance" cover graphic: the Concourse wordmark and title in white on a dark background.

For any company that is public, or planning to be, SOX compliance is one of the most demanding recurring obligations the finance and accounting function carries. It is also one of the most manual: thousands of hours a year documenting controls, gathering evidence, and testing whether the financial reporting process actually works as designed. This guide explains what SOX compliance requires in plain terms, walks through the controls and the process, and shows where AI can take real work off the plate, and where a human has to stay firmly in the loop.

What is SOX compliance?

SOX compliance means adhering to the Sarbanes-Oxley Act of 2002, a U.S. federal law passed in the wake of the Enron and WorldCom accounting scandals to protect investors from fraudulent financial reporting. At its core, SOX requires public companies to establish, document, test, and certify the internal controls over their financial reporting, so that the numbers they report to the market can be trusted.

SOX compliance is, in one sentence, proving that your financial statements are produced by a controlled, reliable process, not just that the final numbers look right, but that the controls that produce them exist, operate, and are tested.

The law is administered under the oversight of the SEC, and it created the Public Company Accounting Oversight Board (PCAOB) to oversee the auditors of public companies. Compliance is not a one-time certification; it is an annual cycle of documenting controls, testing them, remediating gaps, and certifying the results.

Who has to comply with SOX?

SOX applies to all U.S. public companies (SEC registrants), their boards, and their management, as well as to foreign companies listed on U.S. exchanges and, in certain respects, to the public accounting firms that audit them. Private companies are generally not subject to SOX, though many adopt SOX-like controls when preparing for an IPO or to satisfy investors and lenders.

One important nuance: the requirement for an external auditor to attest to internal controls (Section 404(b), below) does not apply to every filer. Smaller reporting companies and non-accelerated filers are exempt from the auditor-attestation requirement, though management's own assessment still applies. If you are approaching an IPO, building SOX readiness early is far cheaper than retrofitting it under deadline.

The key sections of SOX

SOX is a broad law, but for finance teams a handful of sections do most of the work.

SectionWhat it requiresWho it lands on
302CEO and CFO personally certify that financial reports are accurate and that controls are in placeCEO, CFO
404(a)Management assesses and reports on the effectiveness of internal control over financial reporting (ICFR)Management
404(b)The external auditor independently attests to the effectiveness of ICFRExternal auditor
906Criminal certification of financial reports, with penalties for knowing false certificationCEO, CFO
802Retention of records and penalties for altering or destroying documentsThe company

Section 404 is the one that drives the workload. It is where "SOX compliance" becomes a year-round program of documenting and testing controls, not just a signature at quarter-end.

What SOX requires: internal controls

The heart of SOX is internal control over financial reporting, or ICFR: the set of controls that ensure transactions are recorded correctly and financial statements are reliable. Companies typically document these controls against a recognized framework, most commonly the COSO Internal Control, Integrated Framework.

Types of controls

  • Preventive controls stop errors or fraud before they happen, for example, requiring approval before a payment is released.
  • Detective controls catch issues after the fact, such as a reconciliation that surfaces a discrepancy.
  • Entity-level controls operate across the organization, like the tone set by management and the control environment.
  • Process-level controls sit inside specific workflows, such as the three-way match in procure-to-pay.
  • IT general controls (ITGCs) govern the systems that financial data runs through, access, change management, and operations.

A recurring theme in SOX is segregation of duties, ensuring no single person can both initiate and approve a transaction. Weaknesses here are among the most commonly cited control deficiencies.

The SOX compliance process

A SOX program runs on an annual cycle. The steps are consistent even as the details vary by company.

  • Scoping. Identify the accounts, processes, and systems material to the financial statements, and the key controls over them.
  • Documentation. Map each process and document the controls, who performs them, how often, and what evidence they produce.
  • Testing. Test each key control for design and operating effectiveness, gathering evidence that it actually ran.
  • Remediation. Where a control fails or is missing, fix it and re-test before year-end.
  • Assessment and certification. Management evaluates any deficiencies, classifies them, and certifies ICFR; the external auditor attests where 404(b) applies.

Deficiencies are graded by severity, from a simple control deficiency, to a significant deficiency, to a material weakness, the most serious, which must be disclosed. Much of the year's effort goes into finding and fixing issues before they reach that threshold.

A SOX compliance checklist

A simplified checklist for running a SOX program:

  • Scope the material accounts, processes, and systems, and refresh it annually.
  • Document key controls and keep the narratives and control matrices current.
  • Confirm segregation of duties across initiate, approve, record, and reconcile.
  • Test design and operating effectiveness on a defined schedule with sufficient samples.
  • Collect and retain evidence for every control tested, tied to the period it covers.
  • Track deficiencies and remediation to closure, with owners and dates.
  • Review ITGCs, access, change management, and operations for in-scope systems.
  • Certify under Sections 302 and 404, and coordinate 404(b) attestation with the auditor where required.

SOX compliance software and tools

Most SOX programs run on dedicated governance, risk, and compliance (GRC) software that stores the control matrix, schedules testing, and tracks deficiencies and evidence in one place. When evaluating SOX tools, the features that matter most are the control repository and testing workflow, evidence management with a clear audit trail, deficiency and remediation tracking, and integrations with the ERP and systems that hold the underlying data.

GRC platforms are good at managing the program, the workflow, the documentation, the sign-offs. What they have historically not done is the labor-intensive work inside each control: pulling the evidence, testing the sample, reconciling the detail. That is where AI is changing the picture.

How AI helps with SOX compliance

SOX is unusually well-suited to AI assistance because so much of the work is repetitive evidence gathering and testing against defined rules, exactly the kind of judgment-adjacent execution AI agents handle well. Used carefully, AI can take significant hours out of a SOX program:

  • Evidence collection. Agents can pull the documents and system records a control test requires, an approval, a reconciliation, an access log, and assemble them against the control, rather than a person chasing them across systems.
  • Control testing support. For high-volume, rules-based controls, an agent can test the full population instead of a sample, flagging exceptions for a human to judge.
  • Continuous controls monitoring. Rather than testing once a year, agents can monitor transactions continuously for control breaks, out-of-policy approvals, duplicate payments, or segregation-of-duties conflicts, and surface them in real time.
  • Audit request handling. During the audit, agents can respond to the auditor's evidence requests (the PBC list) by locating and packaging the support, a task we cover more in our guide to AI agents for audit workflows.
  • Anomaly detection. Machine learning is well proven at surfacing unusual transactions that warrant a closer look, complementing rules-based detective controls.
AI does not sign the 404 certification. It does the hours of evidence gathering and testing underneath it, so the people who own the controls spend their time on judgment and remediation instead of assembling PDFs. The attestation, and the accountability, stay human.

That boundary matters. SOX is built on management accountability and, where 404(b) applies, auditor independence. AI is a tool that helps management and internal audit do the work faster and more completely; it does not replace the judgment about whether a control is effective, or the certification that stands behind it. The durable model is the same one that applies across finance: the agent does the work, a human reviews, judges, and signs.

The cost and challenge of SOX

SOX compliance is expensive and time-consuming, especially in the first year of being public, when controls must be documented and tested from scratch. The recurring burden is heavy too: coordinating control owners, gathering evidence, and testing on a schedule, largely by hand. This is precisely why automation and AI have become central to the SOX conversation, the manual evidence-and-testing load is the single biggest cost lever a program has.

SOX vs. SOC: a quick clarification

These get confused because the acronyms look alike. SOX is a law governing financial reporting controls for public companies. SOC (System and Organization Controls, e.g. SOC 1 and SOC 2) are voluntary audit reports a service organization obtains to give its customers assurance over controls, commonly around security and data. SOX is a legal obligation; a SOC report is a trust artifact you choose to produce. A company can be subject to SOX and also pursue a SOC 2 report; they serve different purposes.

Frequently asked questions

What is SOX compliance?

SOX compliance means adhering to the Sarbanes-Oxley Act of 2002, which requires U.S. public companies to establish, document, test, and certify their internal controls over financial reporting so that reported results can be trusted. In practice it is an annual cycle of scoping, documenting controls, testing them, remediating gaps, and certifying the results.

Who needs to be SOX compliant?

All U.S. public companies (SEC registrants), their management and boards, and foreign companies listed on U.S. exchanges. Private companies are generally exempt, though many adopt SOX-like controls ahead of an IPO. The external-auditor attestation under Section 404(b) does not apply to smaller reporting and non-accelerated filers, but management's own assessment still does.

What is the difference between SOX Section 302 and 404?

Section 302 requires the CEO and CFO to personally certify that financial reports are accurate and that disclosure controls are in place. Section 404 goes deeper: management must assess and report on the effectiveness of internal control over financial reporting (404a), and, for larger filers, the external auditor must independently attest to it (404b). Section 404 is what makes SOX a year-round controls program.

Can AI do SOX compliance?

AI can automate much of the work inside a SOX program, collecting evidence, testing high-volume controls across the full population, monitoring for control breaks continuously, and responding to auditor requests, but it cannot replace the certification. Management still owns and signs the assessment, and, where required, an independent auditor attests. AI does the work; a human reviews, judges, and certifies.

What is the difference between SOX and SOC compliance?

SOX is a U.S. law requiring public companies to maintain and certify financial reporting controls. SOC reports (such as SOC 1 and SOC 2) are voluntary third-party audit reports a service organization obtains to give customers assurance over its controls, often around security. SOX is a legal obligation; a SOC report is a trust document you choose to pursue.

The bottom line

SOX compliance is the discipline of proving your financial reporting runs on controls that exist, operate, and are tested, an annual obligation for public companies that is as much about evidence and testing as it is about the numbers. The work is heavy and largely manual, which is exactly why AI has become central to it: agents can take on the evidence gathering, control testing, and continuous monitoring, while management keeps ownership of the judgment and the certification.

If you want to see where AI agents can reduce the manual load in your controls and close process, all with every piece of evidence traceable to source, talk to our team. We will map which SOX and close workflows an agent can support today, with a human firmly in the loop.

Built for the teams that can’t afford to get it wrong