Last updated: 14 July 2026 By Aditi Rao, Compliance Research Lead.
Quick Answer: SOX compliance is adherence to the US Sarbanes-Oxley Act of 2002, which requires senior officers to certify financial reports and assess internal controls over financial reporting. In India it binds companies listed on US exchanges and Indian subsidiaries of US-registered parents. The domestic equivalent is Internal Financial Controls under the Companies Act, 2013.
SOX compliance indicates compliance with the provisions set forth in the Sarbanes-Oxley Act of 2002. Compliance is not obligatory for all Indian companies but only applies to those companies that are either listed on a US stock exchange or are part of a US group. For domestic companies, compliance is accomplished through the Internal Financial Controls (IFC) framework under the Companies Act of 2013 in conjunction with the guidance of SEBI Listing Obligations and Disclosure Requirements (LODR).
Which Regime Applies to Which Entity?
Regimen depends on where capital originates and where parent company is located. SOX is a foreign law. Companies Act and SEBI LODR correspondingly applies to domestic entities.
| Entity type | Primary regime | Core control obligation |
|---|---|---|
| Indian company listed on a US exchange (NYSE/NASDAQ, ADR programme) | SOX (US) plus Companies Act IFC | Section 302 and Section 404 certification and ICFR assessment; IFC under the Companies Act |
| Indian subsidiary of a US SEC-registered parent | SOX (US), via the parent's consolidated reporting, plus Companies Act IFC | ICFR testing that feeds the parent's Section 404 report; IFC |
| Indian company listed only on BSE or NSE | Companies Act IFC plus SEBI LODR | Sections 134(5)(e) and 143(3)(i); LODR Regulations 17(8), 18 and 33 |
| Unlisted public or large private company | Companies Act IFC | Auditor reporting on IFC under Section 143(3)(i), subject to exemptions |
What Is SOX Compliance?
SOX compliance is the set of controls, certifications and audit steps mandated by the Sarbanes-Oxley Act of 2002, a US federal law passed after the Enron and WorldCom failures. The Act targets financial-reporting fraud by holding senior management personally accountable for the accuracy of published financials and the controls behind them.
Who Falls Within SOX's Scope?
The statute reaches every SEC issuer and its subsidiaries, so a foreign private issuer such as an Indian company listed on a US exchange falls squarely within scope.
Who Enforces SOX?
In the United States, the implementation of SOX lies with the SEC, while the Public Company Accounting Oversight Board (PCAOB) is the organization that controls the actions of auditors. In contrast, these two organizations do not have any jurisdiction over Indian companies that operate entirely within India. In such instances, the Ministry of Corporate Affairs (MCA) or the Securities and Exchange Board of India (SEBI) steps in as the regulatory body.
What Is the Difference Between SOX Section 302 and Section 404?
The topic of Section 302 deals with the quarterly and annual certification of the report while Section 404 involves the annual assessments of the internal control over financial statements. When discussing Section 302, one must consider the fact that the officer will certify the report by signing it, whereas, in the case of Section, a number of analysis of internal control will be carried out over several years.
| Feature | Section 302 | Section 404 |
|---|---|---|
| Focus | Disclosure controls and accuracy of the report | Internal control over financial reporting (ICFR) |
| Frequency | Every quarterly (10-Q) and annual (10-K) report | Annual |
| Responsibility | Personal certification by the CEO and CFO | Management assessment under 404(a); external auditor attestation under 404(b) |
| Output | A signed certification inside each filing | A management report on ICFR effectiveness, plus an auditor opinion for larger filers |
Does Section 404(b) Apply to Every Filer?
The Section 404(b) auditor attestation is applicable to both accelerated and large accelerated filers; however, it is important to point out that non-accelerated filers do not go under the external attestation requirement, but they must also evaluate their internal control over financial reporting, as stated in the same section.
What Is the Indian Equivalent of SOX?
The Indian equivalent is Internal Financial Controls (IFC), and more specifically Internal Control over Financial Reporting (ICFR), governed by the Companies Act, 2013. India did not adopt SOX; it built a comparable control-and-certification framework into company law, replacing the older Clause 49 listing regime.
How Does the Companies Act Define Internal Financial Controls?
The Companies Act, 2013 defines internal financial controls as the policies and procedures adopted by a company to ensure the orderly and efficient conduct of its business. That statutory definition rests on four control objectives:
- Safeguarding of assets against loss or unauthorised use
- Prevention and detection of fraud and error
- Accuracy and completeness of the accounting records
- Timely preparation of reliable financial information
Which Sections of the Companies Act Govern Internal Financial Controls?
Three provisions carry the weight. Section 134(5)(e) requires the directors of a listed company to confirm, in the Directors' Responsibility Statement, that adequate internal financial controls were laid down and operated effectively. Section 143(3)(i) requires the statutory auditor to report on the adequacy and operating effectiveness of the IFC system with reference to financial statements, effective for financial years beginning on or after 1 April 2015. Section 177, read with Rule 6 of the Companies (Meetings of Board and its Powers) Rules, 2014, additionally requires every listed public company to constitute an Audit Committee tasked with evaluating internal financial controls and risk management systems. The same obligation extends to every other public company with paid-up share capital of ₹10 crore or more, turnover of ₹100 crore or more, or aggregate outstanding loans, borrowings, debentures or deposits exceeding ₹50 crore.
How Do SOX Controls Map to Indian Provisions?
Each SOX obligation has a close Indian counterpart, though the authority and wording differ.
| SOX requirement | Indian analogue | Governing provision |
|---|---|---|
| Section 302 CEO/CFO certification | CEO and CFO compliance certificate to the board | SEBI LODR Regulation 17(8), Schedule II Part B |
| Section 404(a) management ICFR assessment | Directors' Responsibility Statement on IFC | Companies Act Section 134(5)(e) |
| Section 404(b) auditor attestation on ICFR | Auditor's report on IFC with reference to financial statements | Companies Act Section 143(3)(i) |
| Section 301 audit committee oversight | Audit Committee constitution and role | Companies Act Section 177; SEBI LODR Regulation 18 |
| Section 906 criminal certification liability | Officer liability for fraud and false statements | Companies Act Sections 447 and 448 |
What Does SEBI LODR Require From Listed Entities?
The SEBI LODR Regulations, 2015 add a certification and disclosure layer for companies listed on Indian exchanges. Regulation 17(8), read with Part B of Schedule II, requires the CEO and CFO to give the board a compliance certificate confirming the financial statements and their responsibility for internal controls over financial reporting, mirroring the SOX Section 302 certification.
What Does Regulation 18 Require of the Audit Committee?
Regulation 18 governs the Audit Committee, setting four composition and cadence criteria:
- A minimum of three members on the committee
- Two-thirds of members independent directors
- An independent chairperson heading the committee
- At least four meetings in each financial year
What Reporting Cadence Does Regulation 33 Set?
Regulation 33 sets the reporting cadence, requiring audited annual results within 60 days of the financial year end and quarterly results within 45 days of each quarter.
How Does Compliance Software Support SOX and IFC Control Testing?
SOX compliance software supports SOX and IFC by turning a control framework into a scheduled, evidenced and auditable workflow, not a spreadsheet exercise. A dual-registered group must satisfy both the US Section 404 assessment and the Indian Section 143(3)(i) auditor report from a single control library, which is hard to run manually across entities.
How Does a Platform Evidence Each Control?
A platform such as LexComply allocates each control to a named owner, sets the test frequency, captures the supporting document, and preserves a time-stamped audit trail for enterprise compliance. Where controls address financial-statement risk, mapping them through a formal risk and control matrix keeps the ICFR scope defensible.
Why Does Evidence Matter More Than Policy?
Auditors do not certify intentions; they test operating effectiveness. Under both Section 404 and Section 143(3)(i), a control that exists on paper but leaves no evidence of execution is treated as a deficiency. A living repository of Central and State Acts and dated test evidence is what converts a documented policy into a passable control. Firms that lack in-house capacity often engage control design and remediation advisory to close gaps before the audit window.
What Are the Penalties for SOX Non-Compliance?
Section 906 of SOX has criminalized the false certification processes and in this regard the level of crime is determined together with the officer´s degree of knowledge. Sanctions will be applied personally to the executive at the time of wrongdoing and not as a representative of the corporation.
| Violation under Section 906 | Maximum fine | Maximum imprisonment |
|---|---|---|
| Knowing false certification | $1,000,000 | 10 years |
| Willful false certification | $5,000,000 | 20 years |
What Additional Penalty Applies Under Section 906?
There is another particular rule that imposes a punishment of maximum 20 years of imprisonment on those who tamper with or destroy documents. In India, this provision is found in the Companies Act where Section 447 speaks about fraud and Section 448 pertains to false statements and both sections provide for punishment of imprisonment and fine for the responsible people in case of defaults. In both the systems, the responsibility lies with the person who signed the document in question rather than the organization.
Legal Disclaimer
This article provides general information on SOX compliance and the Indian Internal Financial Controls framework and does not constitute legal, audit or professional advice. Readers should verify current provisions with the primary sources and consult a qualified professional before acting on any statutory obligation.
Frequently Asked Questions
Is SOX compliance mandatory for all Indian companies?
No. SOX applies only to Indian companies listed on a US exchange and to Indian subsidiaries whose results consolidate into a US SEC-registered parent. A company listed solely on BSE or NSE follows Internal Financial Controls under the Companies Act, 2013, and SEBI LODR, not SOX.
Does a SOX 404(b) auditor attestation apply to an emerging growth company?
No. An emerging growth company, as defined by the US JOBS Act of 2012, is exempt from the Section 404(b) external auditor attestation for up to five years after its initial public offering. Management must still perform its own Section 404(a) assessment during that period.
When did internal financial controls reporting become mandatory in India?
Auditor reporting on internal financial controls under Section 143(3)(i) applies for financial years beginning on or after 1 April 2015. Directors of listed companies must also confirm the adequacy of these controls in the Directors' Responsibility Statement each year under Section 134(5)(e).
Do private companies need internal financial controls?
Certain private companies are exempt from the auditor's IFC reporting requirement. The Ministry of Corporate Affairs exempted one-person companies, small companies, and private companies that stay below ₹50 crore turnover and ₹25 crore aggregate borrowings, subject to the notified conditions.
What does ICFR mean?
ICFR stands for Internal Control over Financial Reporting: the specific subset of controls that ensures financial statements are reliable and free from material misstatement. Both SOX Section 404 and the Indian Section 143(3)(i) auditor report focus on ICFR rather than on operational controls generally.
Who certifies internal controls in a listed Indian company?
The chief executive officer and chief financial officer jointly certify to the board under SEBI LODR Regulation 17(8), confirming the financial statements and their responsibility for internal controls over financial reporting. The Audit Committee, constituted under Section 177, reviews these controls independently.
What happens if internal financial controls are found deficient at year-end?
The statutory auditor reports the deficiency as a qualified or adverse opinion on internal financial controls under Section 143(3)(i). Directors must then disclose the material weakness and its remediation plan in the Directors' Responsibility Statement, and the Audit Committee oversees the corrective action.