SOX controls are the internal controls over financial reporting that US-listed companies must maintain, assess and have audited under the Sarbanes-Oxley Act 2002. India has no SOX, but its closest equivalent is the internal financial controls (IFC) regime in the Companies Act, 2013: directors state IFC are adequate, and the statutory auditor reports under section 143(3)(i) on whether adequate IFC with reference to financial statements exist and operate effectively.
Facts checked: 10 October 2026. SOX sections 302 and 404 were confirmed from secondary summaries and an SEC final rule (govinfo.gov); SEC and PCAOB pages were not fetched. Sections 134(5)(e) and 143(3)(i), the definition of IFC and the 2017 exemption for certain private companies (G.S.R. 583(E), 13 June 2017) were confirmed from ICAI and MCA-linked pages and professional notes; MCA and ICAI source pages could not be opened directly. The "and" reading of the private company exemption comes from MCA-linked professional notes that quote the 13 July 2017 corrigendum; the gazette itself was not opened. Whether the ICAI Guidance Note has been revised since 2015 could not be confirmed. Check current text before relying on this for a filing.
What SOX is
The Sarbanes-Oxley Act 2002 is a US federal law passed after major accounting failures. It applies to companies with securities registered with the US Securities and Exchange Commission, which can include Indian companies listed in the US and subsidiaries of US-listed groups. It created the Public Company Accounting Oversight Board (PCAOB) to oversee auditors of public companies.
Two sections drive "SOX controls". Section 302 requires the CEO and CFO to certify each periodic report, including that the financial statements are not materially misleading and that deficiencies in internal control have been disclosed to the audit committee. Section 404 requires management to assess internal control over financial reporting (ICFR) each year using a recognised framework, usually COSO, and for many larger filers, the auditor to attest to that assessment. In practice a "SOX control" is a documented control, such as a three-way match or a bank reconciliation review, mapped to a financial statement assertion and tested.
The Indian equivalent
- Directors: Section 134(5)(e) requires directors of a listed company to state that they have laid down internal financial controls and that those controls are adequate and operating effectively. Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014 separately requires the board's report to give details on adequacy of IFC with reference to financial statements; sources we saw describe its scope as narrower. Verify which companies each provision covers.
- Definition: IFC means the policies and procedures adopted by the company for orderly and efficient conduct of business, adherence to policies, safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information.
- Auditor: Section 143(3)(i) requires the auditor's report to state whether the company has adequate internal financial controls with reference to financial statements in place and the operating effectiveness of such controls.
- Guidance: The ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting (2015 edition seen) sets the approach. It does not prescribe one framework; it points to the SA 315 control components as criteria. COSO and similar frameworks are commonly used by management.
The CARO 2020 reporting is separate; see the clause-by-clause CARO 2020 guide.
Who is exempt from the auditor's IFC report
MCA notification G.S.R. 583(E) dated 13 June 2017 exempts certain private companies from the auditor's report under section 143(3)(i): one person companies, small companies, and private companies with turnover below ₹50 crore and aggregate borrowings below ₹25 crore, provided they have not defaulted in filing financial statements or annual return. The original notification joined the turnover and borrowing tests with "or"; a corrigendum dated 13 July 2017 changed it to "and", so the exemption applies only where both conditions are met, as professional notes on the notification and corrigendum report. MCA also clarified, by F.No. 1/1/2014-CL-V dated 25 July 2017, that the exemption applies to reports on financial statements for years commencing on or after 1 April 2016. Read the gazette text of the notification and the corrigendum before advising on a specific company. The exemption is from the auditor's reporting; it does not remove the company's own duty to maintain controls.
SOX vs IFC at a glance
| US SOX | India IFC | |
|---|---|---|
| Law | Sarbanes-Oxley Act 2002, sections 302 and 404 | Companies Act 2013, sections 134(5)(e) and 143(3)(i) |
| Applies to | SEC registrants | All companies for auditor reporting, subject to exemptions above; directors' statement for listed companies |
| Who reports | CEO and CFO certify; management assesses; auditor attests | Directors state; statutory auditor reports opinion |
| Framework | COSO required in practice | Not prescribed; COSO commonly used; SA 315 components as criteria |
| Consequence | Criminal and civil liability for false certification | Qualified or adverse IFC opinion; company and auditor consequences under general provisions of the Act |
Worked example (illustrative): a vendor payment control
Control: Before any vendor payment is released, the system performs a three-way match of purchase order, goods receipt note and invoice, and payments above ₹5,00,000 need a second approver.
Management assertion: Payments are made only for goods received and ordered (occurrence and authorisation).
Test: The auditor selects a sample of 25 payments across the year, confirms each has a matching PO, GRN and invoice, and that the six above ₹5,00,000 carry a second approval. Of the sample, 24 are clean; one ₹7,20,000 payment was released with one approver, after override by the finance head.
Evaluation: One exception in 25 for a preventive control with a system override is a control deficiency. The auditor asks whether it is isolated, how many overrides occurred, and whether any detective control would have caught it. If overrides are frequent and unlogged, this may be a material weakness, leading to an adverse IFC opinion. If isolated and compensated, it is reported as a deficiency to management.
For automating this kind of testing, see ICFR automation with AI, and check readiness with the IFC/ICFR readiness resource.
Frequently asked questions
Is SOX compliance mandatory in India?
Not under any Indian law. It applies to Indian companies only where they or their parent are SEC registrants.
Is IFC the same as ICFR?
Similar in spirit. IFC under the Act has a wider definition; the auditor's report is on IFC over financial reporting.
Do small private companies need an IFC report?
Not the auditor's report if exempt. The notification conditions need checking each year.
Is COSO mandatory in India?
No. The ICAI guidance does not mandate a framework; it accepts suitable criteria.
What happens if IFC are inadequate?
The auditor may qualify or give an adverse opinion on IFC and consider the effect on the audit report, as ICAI guidance describes.
See what is internal audit for related background.
Statutory facts on this page are checked against their sources, and the page says where it relied on secondary reporting. How we verify · Report an error