The Sarbanes-Oxley Act (SOX), enacted in the United States in 2002 following the Enron and WorldCom scandals, remains in 2026 one of the most demanding regulations for IT and finance teams at US-listed groups. Its reach extends well beyond American borders: any consolidated subsidiary of a group listed on the NYSE, NASDAQ or AMEX is in scope — whether it is based in the UK, Germany, the Netherlands or anywhere else in Europe.
This practical guide is aimed at CIOs, finance managers and internal auditors at European subsidiaries. It covers the concrete requirements SOX imposes on your ERP configuration, the specific challenges faced by non-listed but consolidated subsidiaries, and how SAP, Oracle, Dynamics 365 and NetSuite address these requirements.
Who Is Subject to SOX in Europe?
Consolidated Subsidiaries of US-Listed Groups (NASDAQ, NYSE, AMEX)
SOX applies to issuers registered with the SEC and their consolidated subsidiaries, regardless of geographic location. A UK or German subsidiary of a US-listed group is fully in scope for SOX if its financial data feeds into the group’s consolidated financial statements — even if that subsidiary is not itself publicly traded.
In practice, the information systems of that subsidiary, particularly the ERP, fall within the scope of IT General Controls (ITGC) assessed each year by the group’s external auditors. A “local” European ERP can therefore end up in the scope of a Big 4 testing engagement conducted from New York.
A commonly misunderstood point: this situation must not be confused with that of “Foreign Private Issuers” (FPI). European groups themselves listed in the United States under FPI status benefit from certain accommodations (notably Form 20-F). However, a subsidiary of a US group does not benefit from these accommodations: its ITGC obligations are identical to those of an entity based in the United States.
Section 302 vs Section 404: Practical Differences for IT Teams
Section 302 requires the CEO and CFO of the group to certify, in each quarterly and annual report filed with the SEC, the accuracy of the financial statements and the effectiveness of internal controls. For IT, this means that the systems supporting financial reporting must be reliable, documented and auditable on an ongoing basis — not just at the time of an annual review.
Section 404 is more demanding. It requires management to formally assess the effectiveness of Internal Controls over Financial Reporting (ICFR) and external auditors to validate that assessment. PCAOB standard AS 2201 governs this audit on the external auditor side: it mandates a top-down approach starting from the financial statements to identify significant accounts, associated processes, and then the IT controls that secure those processes. The PCAOB has formalised amendments to AS 2201 applicable to fiscal years beginning after 15 December 2026 (PCAOB announcement), reinforcing this risk-based approach.
For a European subsidiary, Section 404 translates into annual IT control tests conducted by the group’s auditors, with a requirement for documented evidence.
The 4 ERP Pillars of SOX Compliance
SOX compliance on the ERP side rests on four fundamental domains. These pillars correspond to the main ITGC categories that auditors systematically test each year.
Pillar 1: Complete and Immutable Audit Trail
The audit trail is the cornerstone of SOX compliance. It must record every modification to financial data: who did what, when, on which transaction, with what value before and after the change.
Two critical requirements coexist. Completeness: every significant event must be captured (creation and modification of master data, journal entries, configuration changes, payment approvals). Immutability: logs must be technically unalterable. A system administrator must not be able to modify or purge the transaction history. A cloud ERP with immutable logs generally offers stronger guarantees than an on-premise ERP where an administrator can theoretically access the underlying database tables directly.
Retention period is another control point: SOX auditors typically require a seven-year retention period for the history of financial transactions.
Pillar 2: Segregation of Duties (SoD)
Segregation of Duties is the principle that no single person should be able to initiate, approve and record a financial transaction from end to end.
Concrete examples of SoD conflicts to avoid in an ERP:
- Creating a vendor AND approving that vendor’s invoices.
- Entering a purchase order AND validating the goods receipt.
- Modifying a vendor’s bank account details AND executing a wire transfer.
- Posting a journal entry AND approving monthly close entries.
In practice, SOX auditors analyse the ERP role matrix to detect these conflicts. A user may have accumulated access rights progressively, through successive exceptions, without anyone having re-evaluated their overall profile. This is one of the most frequently identified gaps during ITGC audits.
Pillar 3: Access Controls and Periodic User Access Reviews
Access to financial systems must be strictly controlled: assignment based on business need, immediate revocation upon departure, and formal periodic review.
The User Access Review (UAR) is a review conducted at least annually — often semi-annually for privileged accounts — in which business managers confirm or revoke each user’s access rights. This process must be documented and traceable: auditors request evidence including the date of the review, participants, and decisions made.
Key points of attention for European subsidiaries:
- Service accounts and technical accounts must be inventoried and justified.
- Super-user accounts or emergency accounts (known as firefighter accounts in SAP terminology) must be restricted in number and subject to enhanced logging.
- Temporary access granted during an ERP migration or implementation is a critical control point: access is often provisioned quickly and forgotten, remaining active long after go-live.
Pillar 4: Automated Financial Close Controls
Manual controls are tolerated by SOX provided they are documented and traceable. But automated controls are more robust because they do not depend on human behaviour.
Examples of automated controls to configure in your ERP:
- Automated three-way matching (purchase order / goods receipt / invoice) before vendor payment.
- Approval workflows with configured delegation levels that prevent self-approval.
- Automatic alerts on transactions exceeding thresholds (unusual amounts, unregistered vendors).
- Technical blocking of modifications to already-posted transactions without separate authorisation.
How the Leading ERPs Support SOX Compliance
SAP S/4HANA: SAP GRC Access Control, Audit Journal, Process Control
SAP offers an integrated GRC (Governance, Risk and Compliance) suite within S/4HANA. SAP GRC Access Control analyses SoD conflicts in real time at the level of PFCG authorisation objects, generates risk reports classified by criticality, and manages emergency access (firefighter) with full session logging.
The SAP Security Audit Log records critical events (logons, sensitive transactions, configuration changes) and can be configured for export to an external SIEM. For European subsidiaries, US audit teams typically request GRC Access Risk Analysis reports as evidence of SoD controls.
SAP Process Control manages the control catalogue, test automation and ICFR compliance reporting, which simplifies the preparation of deliverables for external auditors.
Oracle Cloud Financials: Audit Policies, Role Separation and Oracle ACSF
Oracle Cloud Financials (Fusion Applications) includes an Audit Policies module allowing fine-grained configuration of which attributes and tables must be traced. Audit logs are stored with integrity guarantees within the Oracle Cloud infrastructure.
Oracle also offers the Advanced Controls Framework (ACSF) for continuous monitoring of application controls, and an integrated role separation module allowing SoD rules to be defined at the business function level. These controls can be tested on a continuous basis (continuous control monitoring) rather than just once a year, enabling deviations to be detected between formal reviews.
Microsoft Dynamics 365 Finance: Segregation of Duties, Audit Logs, Power Automate
Dynamics 365 Finance natively includes a Segregation of Duties module allowing conflict rules to be defined between access rights and violations to be detected automatically. Identified violations can be accepted with documented justification or blocked technically.
Audit logs are managed via Azure Monitor and Microsoft Purview Audit, enabling long-term retention and technical immutability in line with SOX requirements. For additional controls such as complex approval workflows or transactional monitoring, Power Automate allows custom automations to be built.
NetSuite: SuiteAudit, Granular Roles, Compliance Reports
NetSuite offers a native audit trail mechanism known as System Notes. These system notes are permanently enabled by default: they record every addition, modification or deletion on financial records and master data, with a timestamp, user identifier, and before/after values. These logs are technically immutable and cannot be modified by any user, including administrators (source: houseblend.io, NetSuite SOX 404 ITGC Controls Checklist).
NetSuite is certified SOC 1 Type II, SOC 2 Type II and ISO 27001. Roles are configurable with granular precision to accurately separate sensitive functions, and compliance reports are available to facilitate presentation to auditors.
Common Gaps Identified During SOX IT Audits
Despite the native capabilities of modern ERPs, ITGC auditors consistently identify the same shortcomings:
Unrestricted super-user accounts. ERP administrator accounts have access to the entire system without restriction or enhanced logging. In a SOX context, these accounts must be limited in number, subject to formal approval for each use, and comprehensively logged.
Incomplete audit trail or over-frequent purging. In some on-premise ERPs, log purging is configured to run every few months to save disk space. An inadequate audit trail can constitute a material weakness — the most serious internal control deficiency recognised by SOX.
Undocumented User Access Reviews. Accesses are reviewed informally but without formal records. Auditors require dated evidence with participants and decisions noted: an undocumented review does not exist as far as the audit is concerned.
Workflow configuration allowing self-approval. A user can approve their own transactions because no technical control prevents it. Detecting this type of bypass is a priority for IT audit teams.
Migration temporary access not revoked. During an ERP implementation or migration, extended access is created for project teams and system integrators. If these accesses are not revoked after go-live, they represent a major risk that is systematically flagged during ITGC reviews.
Typical Annual SOX Review Calendar for Your ERP
For a subsidiary with a fiscal year aligned to the calendar year:
Q1 (January – March): Inventory and Planning
Inventory of key ITGC controls in scope (logical access, change management, IT operations). Identification of financial systems feeding the group’s consolidation. Preparation of SoD matrices and analysis rules in GRC tools.
Q2 (April – June): Control Testing and Remediation
Design and operating effectiveness testing of key controls. Identification of gaps and remediation plan. Implementation of fixes before the end of the half-year to avoid an extended period of non-compliance.
Q3 (July – September): External Audit Preparation
Collection of evidence (GRC report screenshots, log exports, User Access Review minutes). Walkthroughs with external auditors (Big 4). Documentation of compensating controls for formally accepted exceptions.
Q4 (October – December): Annual Report and Certification
Finalisation of management’s report on ICFR for Form 10-K or 20-F. CEO and CFO certification under Section 302. Year-end close with a complete audit trail covering the full year.
Third-Party Tools to Complement Your ERP
The native capabilities of ERPs do not always cover all SOX requirements, particularly for complex SoD matrices in multi-ERP environments or for continuous transaction monitoring.
Pathlock (formerly Greenlight Technologies/Soterion, now incorporating SecurityWeaver and SAST Solutions) is positioned as a specialist in SoD analysis for SAP and Oracle environments. The platform offers more than 500 pre-configured SoD rules, automates User Access Reviews and continuous transaction monitoring, and also covers Dynamics 365 and NetSuite (source: erpresearch.com).
Fastpath (acquired by Delinea) is a multi-ERP agnostic solution, particularly popular in Dynamics 365 and NetSuite environments. It automates security controls, audit workflows and compliance reporting, with direct integrations for most ERPs on the market (source: delinea.com).
These platforms are commonly used by the Big 4 (Deloitte, PwC, KPMG, EY) for automated SoD analysis during SOX IT audit engagements, complementing the native tools provided by ERP vendors.
5 Practical Recommendations for European Subsidiaries
1. Map the systems within the consolidation scope from the outset. Identify precisely which systems (ERP, consolidation tools, payroll solutions, banking systems) feed into the group’s consolidated statements. This is the foundation of ITGC scoping and compliance effort estimation.
2. Document in English from the implementation phase. US audit teams work in English. Bilingual documentation is a worthwhile investment as it avoids significant delays during walkthroughs with group auditors.
3. Test the audit trail six months before the first formal review. Do not discover during the audit that certain events are not being traced. Run a complete test of your audit trail configuration early enough to remediate any gaps.
4. Treat migration temporary access as a first-order risk. Define in your ERP project plan a list of access to be revoked on go-live day and within the 30 days following. Document each revocation with the date and the responsible party.
5. Align the SOX calendar with the ERP close calendar. Access reviews and control tests must be scheduled outside accounting close periods. In Europe, local fiscal close obligations (VAT, corporate tax) create additional calendar constraints to anticipate when planning with the group’s audit teams.
To go deeper on SoD controls in your ERP, see our checklist of 12 SoD controls to implement before the annual audit and our guide on GRC integration in your ERP.
For data retention obligations and audit trail configuration, our guide on ERP data archiving and retention covers the legal and technical requirements applicable in Europe.