Compliance frameworks
SOX (Sarbanes-Oxley Act)
The Sarbanes-Oxley Act of 2002 imposes accuracy and accountability requirements on US public-company financial reporting. Section 302 requires executive certification of disclosure controls. Section 404 requires assessment of internal controls over financial reporting (ICFR), including the IT systems that support those processes. Section 802 imposes record retention requirements with criminal penalties for tampering. Auditors commonly test the IT general controls behind those systems, such as change management, access control, and audit logging.