Files
hermes-brain/ideas/compliance/sox.org
Hermes cc3976fb7f ideas: editorial sweep — atomization, interlinking, restructuring
- Split competitive-analysis-2026-05.org → TOC + 9 competitor files in
  ideas/competitors/. Dropped date from filename. All competitor UUIDs
  generated, TOC keeps original UUID for backlink continuity.
- Deleted passepartout-economics.org archive (replaced by 27-node KB).
- Inlined 5 'See also' blocks into natural prose (compliance-index,
  first-mover-window, revenue-table, orders-of-magnitude-time,
  native-org-knowledge-base).
- Linked 7 orphan compliance pages back to compliance index + finished
  truncated sentences.
- Linked all 14 Agora requirement docs from topic-relevant pages
  (identity→lisp-machine-security, infrastructure→compute-marketplace,
  social-space→growth-strategy, exchange→agora-contracts, etc.).
- Linked ai-industry-impact from investment-thesis, sufficiency-flip,
  verification-appliance, effects-growth-flywheel (up from 1 to 10+ pages).
- Fixed CREATED timestamps to use git commit dates instead of today.
- Made all links absolute from root (no port inheritance).
- Removed stale agora/docs/ duplicate content.
2026-05-24 16:25:55 +00:00

29 lines
1.2 KiB
Org Mode

:PROPERTIES:
:ID: c9830152-0160-4bdc-ab03-6f308ad43536
:ID: auto-sox
:CREATED: [2026-05-23 Sat]
:END:
#+title: SOX (Sarbanes-Oxley Act)
#+filetags: :passepartout:compliance:framework:sox:
US federal law (2002). Mandates internal controls over financial reporting
(ICFR) for publicly traded companies. Section 404 requires management to assess
and auditors to attest to the effectiveness of internal controls.
Who must comply: All US public companies; foreign issuers trading on US exchanges.
~6,000 public companies + foreign filers.
Penalties: Up to $5M fines and 20 years imprisonment for certifying false
financial statements. CEO and CFO personally liable.
Why it matters: Every financial control is a gate rule — who can approve a
journal entry, who can release a payment, who can modify a vendor record. The
gate stack encodes these as ACL2-verified rules and produces the audit trail
that the external auditor needs for Section 404 attestation. First-mover
advantage: SOX is mature (24 years old) but the audit market is $4B+ and
entirely manual — no competitor has automated the evidence pipeline.
** [[id:4a2bc62b-3f21-4212-9cd9-f9add8fc0be1][GLBA (Gramm-Leach-Bliley Act)]]