A publicly traded healthcare technology firm in the United States is deploying an enterprise resource planning (ERP) system to process billing records and forecast quarterly corporate revenues. During an operational risk review, the audit committee emphasizes that the application must enforce strict separation of duties, tamper-evident audit logging, and verifiable internal controls specifically to prevent fraudulent reporting of financial statements. Which of the following regulatory frameworks or federal mandates primarily governs these financial data integrity requirements?
- Sarbanes-Oxley Act (SOX)Answer
- BHealth Insurance Portability and Accountability Act (HIPAA)
- CPayment Card Industry Data Security Standard (PCI-DSS)
- DFederal Information Security Modernization Act (FISMA)
Answer
Sarbanes-Oxley Act (SOX)
The correct option is Sarbanes-Oxley Act (SOX). SOX regulates US publicly traded companies and mandates rigorous internal controls over financial data reporting, separation of duties, and audit logs to prevent corporate fraud and ensure accounting integrity.
Step-by-Step Solution
Key Concept
Sarbanes-Oxley Act (SOX) Statutory Scope and Internal Financial Controls