Understanding SOX Compliance.
Sarbanes-Oxley records retention and destruction explained for Massachusetts public companies, their auditors and any business handling financial controls documentation.
The Sarbanes-Oxley Act of 2002, almost universally called SOX, is the federal law that imposed sweeping financial reporting and internal-controls requirements on US public companies after the Enron and WorldCom collapses. SOX touches almost every paper trail inside a public company. It also reaches public-company auditors and, increasingly, large private companies that adopt SOX-style controls in preparation for an IPO.
This guide explains what SOX requires for records retention and disposal, who is actually covered, the penalties for getting it wrong and how Massachusetts public companies handle disposal in practice.
Who SOX Applies To
SOX covers four primary categories.
Public companies. Any US-listed public company, plus foreign issuers registered with the SEC. Massachusetts has dozens of public companies headquartered or operating here, ranging from biotechs and software firms to financial services and consumer brands.
Public-company auditors. Audit firms working with public-company clients are SOX-covered for the work they do on those engagements. The PCAOB regulates these firms and reviews their compliance.
Pre-IPO companies. Private companies preparing for IPO typically adopt SOX-style internal controls 12 to 24 months before filing. Even though SOX does not technically apply yet, the records management discipline does.
Subsidiaries and affiliates. Subsidiaries of public companies generally fall under their parent’s SOX obligations for relevant financial records and controls.
SOX Sections That Drive Records Practices
Three SOX sections matter most for records retention and disposal.
Section 802: Records Destruction Liability
Section 802 makes it a crime to knowingly destroy, alter, conceal or falsify records “with the intent to impede, obstruct or influence” any federal investigation. This is the section that creates personal criminal liability for executives and employees who shred the wrong records at the wrong time. Penalties run up to 20 years in federal prison.
Section 802 also requires audit firms to retain audit papers for at least seven years following the audit completion. Destruction before that window violates the law.
Section 404: Internal Controls Over Financial Reporting
Section 404 requires public-company management to assess and report on the effectiveness of internal controls over financial reporting (ICFR). One element of effective ICFR is records management, including retention schedules and documented disposal procedures. Auditors test these controls during annual SOX 404 audits.
Section 1102: Tampering Penalties
Section 1102 penalizes anyone who corruptly “alters, destroys, mutilates or conceals” records to obstruct an official proceeding. This applies broadly, not just to public companies. Anyone who destroys records to avoid an investigation faces up to 20 years.
SOX Records Retention Schedules
SOX itself does not specify retention periods for every record category. Public companies typically build retention schedules from a combination of SOX, SEC Rule 17a-4, IRS rules, state records laws and industry-specific regulations. Common SOX-era retention windows include:
- Audit working papers and supporting documentation: 7 years from audit completion (Section 802 requirement)
- Financial statements, journals and ledgers: 7 years minimum, often retained permanently for IPO-era companies
- Tax records and supporting documentation: 7 years
- Internal controls documentation (SOX 404 evidence): 7 years
- Board meeting minutes and corporate records: permanent
- Contracts and agreements: 7 years past contract expiration
- Employee records (HR, payroll, benefits): varies, typically 7 years post-termination
- Email and electronic communications: per company policy, typically 3 to 7 years
Records held past their retention requirement become liabilities. SOX-aware destruction at end of retention is required, and the destruction event itself must be documented.
Disposal Documentation Required Under SOX
SOX-compliant destruction has specific documentation requirements that go beyond simple shredding. Public companies generally need:
- A written records retention and destruction policy approved by the Audit Committee
- A “litigation hold” process that pauses destruction when legal action is anticipated
- Documented destruction events with date, custodian, method, volume and operator
- Certificates of Destruction from any third-party shredding vendor
- Retention of destruction documentation itself (typically 7 years)
- Annual review of the retention schedule and destruction practices by the Audit Committee or its designate
Our Certificate of Destruction format covers the destruction-event documentation requirement. Internal policies and litigation holds remain your responsibility.
Litigation Holds and Destruction Pauses
One of the most consequential SOX-era practices is the litigation hold. When a company anticipates or learns of a federal investigation, regulatory inquiry or material litigation, normal records destruction must pause for any records that may be relevant. Continuing to destroy records during a litigation hold can trigger Section 802 personal criminal liability.
Practical implication for SOX-covered businesses: when you call us to schedule destruction, we ask whether any litigation holds are in effect. If yes, we work with you to ensure only non-held records are processed. If you discover a hold mid-cycle, we can pause your scheduled service or hold pickup containers in our facility under documented chain of custody until the hold lifts.
SEC Rule 17a-4 and SOX
For broker-dealers, investment advisers and other SEC-regulated firms, SEC Rule 17a-4 layers on top of SOX. Rule 17a-4 requires preservation of specific records in non-rewritable, non-erasable format for defined retention periods, typically 3 to 6 years depending on record type. The first two years of any required retention must be in “easily accessible” storage.
Destruction at end of 17a-4 retention requires the same documented destruction event we provide for SOX compliance. Most SEC-regulated firms use professional shredding with a Certificate of Destruction to satisfy both SOX and 17a-4 simultaneously.
Common SOX Disposal Mistakes We See
Five mistakes show up in audit findings and enforcement actions repeatedly.
Destroying during an active litigation hold. Section 802 personal criminal liability. Avoid by maintaining a current list of active holds and circulating to all destruction-decision personnel.
Destruction without documentation. Office shredders that produce no Certificate fail the SOX “destruction event must be documented” expectation.
Inconsistent retention application across departments. Finance retains 7 years, HR retains 5, IT retains 3. Auditors flag this. Build one unified schedule.
No annual review of the retention schedule. SOX 404 audits look for evidence the controls are reviewed and updated. An outdated retention schedule signals weak controls.
Ignoring electronic records. Hard drives, backup tapes, server logs, email archives all count. Destruction at end of life requires the same documentation as paper.
Massachusetts Public Companies and SOX
Massachusetts is home to a substantial public-company population, with concentrations in biotech and pharma along Route 128, software and SaaS in Cambridge and Boston, financial services downtown and consumer brands across the suburbs. Each industry sector has its own SOX rhythm.
Biotech and pharma SOX cycles run heavy in Q1 around the 10-K filing and again in Q3 for annual SOX 404 audits. Major paper categories include clinical trial documentation aged out of retention, regulatory submissions, manufacturing records and HR files. Periodic destruction events run 30 to 100 boxes typically.
Software and SaaS companies tend to produce less paper but heavier electronic records. Hard drive destruction is a recurring need as servers, laptops and backup systems retire. Annual destruction events often pair paper with media destruction in a single coordinated visit.
Financial services public companies (banks, insurers, investment managers) layer SOX on top of GLBA, SEC 17a-4 and other industry rules. Recordkeeping is the heaviest in this sector and destruction documentation is the most scrutinized.
Consumer brands face SOX plus customer data protection rules (often state CCPA-style laws) plus retail-specific contracts. Holiday-season cleanouts of expired promotional materials and customer records are common patterns.
Across all sectors, Massachusetts public companies benefit from working with a local destruction vendor who understands the timing and documentation pressures of each industry. We have served Greater Boston public companies for years and our Certificate format has been accepted by every Big Four auditor and PCAOB inspector who has reviewed it.
SOX Penalties for Records Violations
SOX penalties are among the most severe in US business law.
- Section 802: up to 20 years federal prison for knowing destruction with obstructive intent
- Section 1102: up to 20 years federal prison for tampering with records
- Civil penalties: up to $25 million for the company per violation, with personal liability for executives
- SEC enforcement actions: typically settle in the multi-million dollar range
- Private securities fraud lawsuits: class actions with multi-billion-dollar exposure on large cases
- Auditor decertification: PCAOB can decertify audit firms with serious violations
SOX FAQ
Does SOX apply to private companies?
Who is responsible inside the company for SOX records compliance?
How do we handle records during a merger or acquisition?
Can we use one shredding vendor for both SOX and HIPAA records?
What about witnessed destruction for SOX?
SOX-Aware Destruction for Boston Public Companies.
Documented destruction events. Audit Committee-ready Certificates. Litigation hold accommodation. Get a free quote.