Sarbanes-Oxley Act (SOX) of 2002
Sarbanes-Oxley was passed after the Enron and WorldCom scandals to restore trust in corporate financial reporting. It directly governs public companies and their auditors, but its record-keeping expectations have become the standard many private companies, nonprofits and lenders follow too.
What it says about records
- Section 802 makes it a federal crime to knowingly alter, destroy or conceal any record with the intent to obstruct a federal investigation or bankruptcy proceeding — punishable by up to 20 years in prison.
- The same section requires auditors to retain audit workpapers for five years; the SEC's implementing rule extended that to seven years.
- Section 404 requires management to document and test internal controls over financial reporting — which in practice means documented, consistent record-handling.
Why that makes a destruction policy essential
SOX creates a two-sided problem. Destroy the wrong document at the wrong time and you may face criminal exposure. Keep everything forever and you drown in liability and storage cost. The answer both auditors and attorneys recommend is a written retention schedule — each record type, how long it's kept, and what happens when the clock runs out — applied consistently, with proof.
That last word matters. A certificate of destruction showing what was destroyed and when demonstrates that a document was disposed of on schedule under a normal policy, not selectively after an inquiry began.
Who follows it beyond public companies
Nonprofits (SOX's whistleblower and document-destruction provisions apply to them directly), companies preparing to be acquired or go public, and any business whose lenders or investors expect audited financials.
This page is a plain-English summary for business owners, not legal advice. Talk to your attorney or compliance officer about how the law applies to you.
