SOX and ICFR Modernization
Modernize SOX and ICFR evidence, technology controls, deficiency management, and the December 2026 PCAOB standards transition
Continue readingA credible compliance program does not prove effectiveness by accumulating policies. It shows which requirements apply, who owns the resulting risks and controls, what evidence demonstrates operation, how problems are detected, and whether remediation changes outcomes.
Substantively reviewed . This revision corrects DORA article mappings, replaces superseded DOJ references, and separates legal obligations from prosecutorial guidance and sentencing incentives.
Primary sources: DOJ Evaluation of Corporate Compliance Programs (September 2024), DOJ corporate-enforcement materials, 2025 U.S. Sentencing Guidelines Chapter Eight, and EU DORA.
The strongest compliance operations model has a common workflow without pretending that every authority creates the same duty. Statutes and regulations create legal obligations. Supervisory guidance may describe regulator expectations for entities within scope. DOJ's Evaluation of Corporate Compliance Programs (ECCP) is prosecutorial evaluation guidance. U.S. Sentencing Guidelines Chapter Eight creates sentencing incentives and criteria for an effective compliance and ethics program. Those sources can shape the same operating model, but they should remain labeled accurately.
What legal, regulatory, contractual, or policy requirement actually applies to the entity, activity, product, or jurisdiction?
What preventive, detective, approval, monitoring, or response mechanism addresses the requirement or underlying risk?
What retained record shows the control operated, exceptions were handled, and accountable people reached a defensible conclusion?
The Criminal Division's current ECCP remains the September 2024 update. It asks prosecutors to evaluate whether a compliance program is well designed, applied earnestly and in good faith, adequately resourced and empowered, and effective in practice. The 2024 update also asks how organizations identify and manage risks from emerging technologies such as artificial intelligence.
DOJ's corporate-enforcement materials have continued to evolve around that document, including a department-wide Corporate Enforcement Policy dated March 10, 2026. Treat the ECCP as an evaluation lens and the enforcement policy as a separate current policy source; do not describe a DOJ questionnaire as if it were a regulation that every company must implement identically.
The 2025 Guidelines Manual retains Chapter Eight's organizational framework. Section 8B2.1 describes an effective compliance and ethics program around due diligence, governing-authority oversight, responsible personnel, resources and authority, training, monitoring and auditing, reporting mechanisms, incentives and discipline, response to misconduct, and periodic risk assessment.
For operations teams, the practical value is not a sentencing-score calculation. It is the reminder that an effective program needs governance, resourcing, communication, detection, evaluation, and response working together.
DORA has applied since January 17, 2025 to the financial entities and other actors within its scope. Its article structure matters when converting the regulation into a control catalog:
DORA source: Regulation (EU) 2022/2554. Confirm entity scope and applicable delegated/implementing acts before converting any article into a mandatory task.
A useful obligation register is not a list of regulation names. It lets a reviewer trace a requirement from authoritative text to implementation and current evidence.
Controls should be written so a person who did not design them can understand what happens, who performs the work, what inputs are used, how exceptions are recognized, and what evidence remains.
Continuous monitoring should not mean collecting every possible metric. It should detect events that make the current risk assessment, control design, or applicability decision unreliable.
A program cannot demonstrate that it works in practice if allegations disappear into disconnected case folders. Compliance operations should preserve a traceable lifecycle from intake through triage, investigation, conclusion, remediation, discipline where appropriate, and verification.
The September 2024 DOJ ECCP explicitly asks how companies assess and govern risks from new technologies, including AI. That creates two separate operating questions: what technology-related misconduct or control risk exists in the business, and whether the technology used by compliance is itself reliable and appropriately governed.
Do not assume a monitoring platform, anomaly model, hotline classifier, or automated screening workflow is reliable because it is automated. Validate source data, access, configuration, thresholds, change management, exception handling, and false-positive/false-negative consequences.
For an in-scope financial entity, DORA can be mapped into the same evidence architecture rather than maintained as a separate binder:
Map Articles 5–6 to management-body oversight, role definitions, ICT risk strategy, policy approval, training, and evidence of periodic review.
Map Articles 17–19 to detection, logging, classification, escalation, notification decisions, reporting records, root cause, and corrective action.
Map Articles 24–26 to the testing program, scope decisions, remediation evidence, and threat-led penetration-testing obligations where applicable.
Map Articles 28–30 to the contractual-arrangement register, concentration assessment, due diligence, required contract terms, monitoring, and exit readiness.
Activity metrics are useful for capacity management but weak evidence of effectiveness on their own. Pair them with outcome and risk indicators.
Material obligations with an owner, control mapping, current source, and evidence path.
Failure rate, recurring exceptions, overdue reviews, automation failures, and unresolved design gaps.
Age of high-risk findings, repeat findings after closure, root-cause recurrence, and validation failure.
Triage timeliness, aging by severity, repeat themes, retaliation concerns, and remediation conversion.
New regulatory or business changes awaiting applicability review and controls awaiting redesign.
Decisions requiring executive or board action, expired risk acceptances, and unresolved resource constraints.
This guide describes an operating model, not a universal list of legal duties. Applicability, reporting deadlines, regulator jurisdiction, privilege, disclosure, and escalation requirements must be determined from the organization's facts and current authoritative sources.
Follow the next implementation topic without returning to search.
Modernize SOX and ICFR evidence, technology controls, deficiency management, and the December 2026 PCAOB standards transition
Continue readingCreate accountable oversight for technology and operational risk
Continue readingUse the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.