- SOX was enacted in 2002 following the Enron and WorldCom accounting scandals, to restore confidence in public company financial reporting.
- Section 302 requires the CEO and CFO to personally certify the accuracy of financial reports and the effectiveness of disclosure controls.
- Section 404 requires management to assess and report on the effectiveness of internal control over financial reporting (ICFR), with an external auditor attestation for larger filers.
- SOX applies to companies listed on US exchanges — which includes Australian and other foreign companies that are dual-listed or file with the SEC, not only domestic US corporations.
Why SOX exists, and why Section 404 is the part that bites
The Sarbanes-Oxley Act was passed in 2002 in direct response to the Enron and WorldCom collapses, where financial reporting failures wiped out shareholder value and, in Enron's case, an entire accounting firm. The Act's core aim was to make senior executives and their internal control environment personally accountable for the accuracy of financial statements, rather than leaving that accountability diffused across a finance function.
Section 302 gets cited often — it requires the CEO and CFO to personally certify each quarterly and annual report. Section 404 is the one that actually reshaped internal audit and control functions: it requires management to assess and report on the design and operating effectiveness of internal control over financial reporting, with an external auditor's independent attestation required for larger filers under SEC rules.
It's not just a US-domestic obligation
SOX applies to any company that is listed on a US securities exchange or files reports with the SEC — a wider net than 'US company' implies. Australian companies with a US listing, ADR programs, or SEC-registered debt can find themselves subject to SOX's control assessment and certification requirements, on top of their domestic obligations.
For a GRC platform vendor, this means SOX readiness isn't a niche, US-only checkbox. Any Australian or APAC organisation with cross-border listing ambitions, or an existing US-listed parent or subsidiary, needs a platform that can support SOX-style control testing evidence alongside APRA or other local regulatory requirements.
What Section 404 actually requires from the platform, not just the process
Passing a SOX 404 assessment on paper and having a system that can withstand an external auditor's scrutiny are two different things. The practical requirements are specific: a documented control framework mapped to financial reporting risk, evidence that each key control was actually tested (not just designed), a record of who tested it and when, and a remediation trail for any control found deficient.
This is functionally the same evidence discipline COSO's Internal Control — Integrated Framework describes, which is not a coincidence — COSO's framework is the most commonly used basis for SOX 404 assessments in practice. A platform that claims COSO alignment without a genuine, testable evidence trail behind that claim will struggle under SOX just as it would under a COSO-based internal audit.
What to check when SOX applies to your organisation
Three things matter in vendor evaluation here. First, can the platform maintain a control library mapped to financial reporting risk with version history, not just a static document? Second, does it capture test evidence — who performed the test, on what date, against what sample — in a form an external auditor can independently review? Third, does it track remediation of control deficiencies through to closure, with a full audit trail?
None of this is about whether a GRC platform vendor is itself 'SOX compliant' — SOX is an obligation on public companies and their officers, not a certification a software vendor holds. The relevant question for a buyer is narrower and more useful: does the platform generate the specific, testable evidence a Section 404 assessment and its external auditor will actually demand.
Why This Matters for RiskBridge
RiskBridge's click-through evidence trail — built to give audit teams documented, testable control evidence — maps directly onto what SOX Section 404 requires of internal control assessment: not a policy statement that controls exist, but a traceable record that they were tested and found effective.
RiskBridge is developed and operated by Effective Risk Management Pty Ltd. All product names, trademarks, and analyst frameworks (including Gartner®, Forrester®, APRA®, ISO®, NIST®, COSO®, IIA®) referenced herein belong to their respective registered trademark owners. Reference to these frameworks is provided solely for independent practitioner research and does not imply official affiliation, endorsement, or formal legal advice. GRC platform evaluation and regulatory compliance strategies should always be verified against your organization's specific jurisdictional and legal obligations.
See how RiskBridge applies this in practice.
Run a guided, criteria-driven evaluation across 200+ tracked GRC vendors — or consult with an experienced GRC practitioner about your requirements.
