Houston skyline at night with steam venting from a street grate in the foreground, cold blue tones and warm building lights
Applied Philosophy & Resilience

Sarbanes-Oxley: the law that tried to fix Enron

Applied Philosophy & ResilienceChange Management & Leadership

I was there when SOX landed in practice. Not reading about it. Living it. As Director of Global Logistics at Affymetrix, a biotechnology company in Santa Clara. My name then was Michael Smith. Affymetrix was publicly listed. Compliance was landing hard. And the question nobody had a clean answer to was exactly how far the internal control obligations extended. Did they stop at the company's own walls, or did they follow the product all the way through the supply chain?

Ravi Vora was our Director of Internal Audit. Precise, no-nonsense, and completely without patience for compliance theatre. Together we built out SOX-compliant processes for European Customer Service and Logistics, across the third-party network too. That experience shaped how I read SOX ever since. Not as legislation. As a test of whether an organisation actually wants to know what is happening inside it. Most do not pass that test.

What Congress did in eight months

Enron filed for bankruptcy in December 2001. Arthur Andersen was gone within months. Twenty thousand people lost their jobs. Billions in pension savings vanished. In July 2002, President George W. Bush signed the Sarbanes-Oxley Act, the most significant reform of US corporate governance since 1934. Eight months from collapse to legislation. The diagnosis was simple. Executives had lied. Auditors had looked away. Nobody had been personally on the hook for any of it.

Section 302 required CEOs and CFOs to personally certify the accuracy of financial statements. You signed it. You owned it. Section 404 required management to assess and report on the effectiveness of internal controls, with auditors independently verifying that assessment. The Public Company Accounting Oversight Board was created to regulate the audit profession. Andersen had received roughly 52 million dollars from Enron in 2000 alone, split between audit and consulting. The PCAOB prohibited that model.

What SOX got right

Personal certification changed executive behaviour. Not perfectly. But materially. When your signature is on a document and that document contains a lie, prosecutors have a cleaner path to your door. The end of the Andersen model mattered too. Section 404 forced internal controls onto the agenda at board level. For many companies, this was the first time senior leadership had formally asked whether their financial reporting infrastructure was actually reliable.

Ravi and I lived this at Affymetrix. Where are the control gaps? Who has authority over what? What can go wrong, and is there a compensating control in place? What are our third-party providers actually doing with our product and our data? The answers were sometimes uncomfortable. That was the point.

What SOX got wrong

Compliance became the product. Within a few years, a compliance industry had grown up around SOX. Armies of consultants and internal audit teams producing documentation, flowcharts and sign-off schedules. The paperwork became comprehensive. The understanding of what it represented often did not. Companies learned to pass SOX audits. That is not the same as having controls that actually work.

The burden fell disproportionately on smaller companies. Fixed compliance costs do not scale with company size. Some chose to go private. Others decided a public listing was no longer worth the cost. The lawmakers were focused on preventing another Enron. They were less focused on what a framework designed for a 70 billion dollar company would do to a 150 million dollar one.

The rating agencies were left completely untouched. This was the clearest miss, and the most costly. Moody's held an investment-grade rating on Enron until days before bankruptcy. Seven years later, rating agencies paid by the issuers they rated applied the same structural conflict to mortgage-backed securities. The result was the largest financial crisis since the Great Depression. SOX had missed it entirely. The lobby was effective. The lesson was not learned. It cost several trillion dollars.

Culture cannot be legislated. The deepest failure at Enron was cultural. The rank-and-yank performance system created relentless pressure to report success regardless of reality. People who raised doubts were pushed out. People who produced the numbers thrived. SOX produced no mechanism to address this. An organisation can have impeccable SOX documentation and a culture that systematically selects for people who game metrics over people who raise honest concerns.

Third-party risk was under-specified. SOX focused on the reporting entity. It did not create a clear framework for managing the control environment across supply chains, service providers and outsourced operations. Ravi and I built third-party controls into our programme deliberately because we understood the principle. The regulation pointed in the right direction but left too much to individual interpretation.

What was never fixed

No system of external gatekeepers is a reliable substitute for honest management. Gatekeepers can catch some fraud some of the time. They cannot catch determined, sophisticated fraud conducted with the cooperation of management, auditors and lawyers. What they can do is raise the cost and make it more likely that when fraud occurs, it gets caught earlier. That is worth something. It is not sufficient.

Enron used opacity deliberately. The SPE structures were not complicated by accident. Complexity made scrutiny difficult, and that was the point. SOX's personal certification raises the cost of deliberate obfuscation. It does not eliminate it. In financial markets, when something is genuinely hard to understand, the temptation is to assume the difficulty reflects sophistication rather than concealment by people who benefit from it. Enron exploited that assumption for years. It was not the last.

The question worth asking now

SOX requires personal certification of financial statements. It does not require certification that the assumptions underlying mark-to-market valuations of novel assets are reasonable. Enron's mark-to-market accounting was approved by the SEC in 1992. The value of a long-term contract was whatever Enron's internal models said it was. There was no external price to contradict them.

We now have AI companies building valuations on projected future value rather than current cash generation. Analysts whose employers have financial interests in maintaining those valuations. Auditors signing off on accounting treatments for assets whose value depends on models nobody outside the company can independently verify. SOX exists. The question is whether the specific mechanisms of the next failure fall inside or outside what SOX was designed to catch. Based on the history, the answer is usually outside.

The law that changed the floor

Sarbanes-Oxley changed the floor of US corporate governance. It did not change the human tendency to believe compelling stories about success, mistake complexity for competence, or let financial incentives override professional obligations. No legislation does. The next failure will use mechanisms that fall between the lines of what the regulators anticipated. They always do.

#Governance#Compliance#Enron#SOX#Leadership

References

  • Sarbanes-Oxley Act of 2002 (Pub. L. 107-204)
  • SEC rulemaking under SOX Sections 302 and 404
  • PCAOB establishment documentation, 2003
  • GAO report on SOX Section 404 implementation costs, 2006
  • Personal operational experience, Affymetrix Inc., 2007 to 2014

By Michael Lennard Gnaedinger. © 2026 Gnaedinger Consultancy. All rights reserved.

If any of this sounds familiar.

I work with a small number of founders and CEOs each year. The conversation starts here.

Begin the conversation
← Back to all insights