SOX Compliance for European Companies Listed in the US: What FPIs Actually Need to Know
April 24, 2026
If you’re a European company preparing for a U.S. listing, SOX compliance is one of the first things that comes up and one of the most misunderstood. Most finance teams assume it’s a massive, undifferentiated burden. It isn’t, at least not for foreign private issuers (FPIs). You have specific exemptions, and the path is more manageable than most people expect.
What matters is knowing which rules apply to you, which ones you can legitimately skip, and where cutting corners will cost you later.
The Core Distinction: SOX 404(a) vs. 404(b)
As an FPI, you almost certainly need to comply with SOX Section 404(a). The auditor attestation requirement in 404(b) is typically required for FPIs depending on accelerated filing status, unless you qualify as an emerging growth company (EGC).
If you also qualify as an EGC (annual gross revenues below approximately $1.235 billion, the current inflation-adjusted threshold under the JOBS Act), you also get a grace period on 404(a) itself and can defer management’s ICFR assessment for your first few years as a public company.
This distinction drives the entire SOX workload conversation.
Section 404(a) requires your company to certify the effectiveness of your internal control over financial reporting (ICFR) in your annual 20-F filing. Your management runs an assessment, documents your controls, evaluates them against a framework (almost always COSO), and makes a statement: “Our internal controls are effective” or “We identified a material weakness.” It is a management assertion, signed by the CEO and CFO.
Section 404(b) is the audit firm doing the same job independently. They assess your controls, test them, and issue their own opinion on top of yours. It is more thorough, more expensive, and historically required only for larger U.S. domestic companies.
In practice: you are not paying for two parallel audits. Your audit firm is not issuing an attestation on controls. Your costs are tighter, your timeline is shorter, and you can build your control environment in phases rather than all at once.
Understanding COSO: The Framework Behind SOX
COSO is a framework published by the Committee of Sponsoring Organizations of the Treadway Commission. It is the de facto global standard for internal control design, and the SEC expects you to use it. COSO 2013 has five components.
- Control Environment. This is the tone at the top: your values, your ethics policy, how you hire and train people, and how seriously management demonstrates a commitment to financial reporting integrity. It sounds soft, but it is not optional. Without a strong control environment, every other control you build is fragile. Your home country may have a more implicit approach to governance. SOX does not work that way. You need explicit documentation, training, a whistleblower policy, and clear accountability.
- Risk Assessment. This is your systematic identification of risks that could affect the accuracy of your financial reporting: revenue recognition, expense accrual, close procedures, intercompany transactions, currency translation, anything that feeds the financial statements. You document the risks, document who is responsible for mitigating each one, and revisit it annually.
- Control Activities. These are the actual controls: the procedures and systems that reduce risk to acceptable levels. A control might be: “The accounts payable supervisor reviews and approves every vendor invoice over 50,000 euros before payment.” Or: “System access to the general ledger is restricted to the controller and one backup, with monthly access reviews.” You do not need 500 controls. You need enough to reliably prevent or detect misstatement.
- Information and Communication. How does financial information flow through the organization? How do people report control issues or suspected fraud? This includes your close calendar, your consolidation procedures, how foreign subsidiaries report to the parent, how information systems are configured, and your whistleblower mechanism.
- Monitoring. This is your testing and oversight: management’s informal testing and formal control testing by the audit team or internal audit function. Monitoring answers the question: are our controls actually effective, or have they deteriorated?
All five components need to work together. Controls can fail over time. People leave. Procedures get circumvented informally. SOX requires an ongoing program, not a one-time documentation exercise.
CEO and CFO Certifications: Section 302 and 906
Section 302 requires annual CEO and CFO certifications attached to your 20-F filing. FPIs do not file quarterly 10-Qs. Instead, you file 6-Ks for material periodic reporting. The Section 302 certification covers the 20-F annually. In it, you certify that you have reviewed the report, it does not contain untrue statements, the financial statements fairly present your financial condition, you are responsible for disclosure controls, and you have disclosed any control deficiencies, material weaknesses, or fraud.
This is not a check-the-box exercise. The SEC has brought enforcement actions against executives who signed certifications without a reasonable basis. You need a documented process: someone (usually the controller or CFO) gathers control test results, identifies any deficiencies, assesses whether they are material weaknesses, and prepares a summary for the executives to review before signing.
Section 906 adds criminal penalties. If you know the certification is false when you sign it, you are exposed to up to 20 years in prison and fines. This is why you need actual evidence supporting the certification, not an assumption that things are fine.
Where FPIs Get Flexibility (And Where They Don’t)
FPIs have more flexibility on the governance side than U.S. domestic companies, but the boundaries matter.
You can follow home country governance practices for board committee structure, certain disclosure standards and formats, and some aspects of executive compensation disclosure.
You cannot avoid an independent audit committee with financial literacy, Section 302 and 906 certifications, disclosure controls and procedures, internal control assessments and disclosures, a whistleblower mechanism, or SOX-compliant financial statements and MD&A.
The audit committee is non-negotiable. It must have at least three members, a majority of whom must be independent, and at least one financial expert. This is where home country board governance approaches often need to shift most visibly.
Common Mistakes European Companies Make
- Underestimating the timeline. Most European companies assume they can go from planning to compliant in six months. It is usually 18 to 24 months from serious planning to the first 20-F filing. U.S. regulators and underwriters need to see a track record of control testing and operating effectiveness, typically at least one full fiscal year. Start early.
- Treating SOX as a one-time project. SOX is an ongoing program. Controls deteriorate. People leave. New risks emerge. You need a dedicated owner responsible for maintaining the control environment, testing controls annually, and updating documentation. Budget for it as a permanent function, not a one-time investment.
- Underestimating IT controls. European companies often have strong financial controls and weak IT controls. SOX treats IT controls as foundational: system access, segregation of duties, change management, backup and disaster recovery. Involve your IT team from the start.
- Assuming home country controls are good enough. Many European companies have strong controls in practice, but have not documented or tested them in the way SOX requires. It is usually not a redesign, but it is a project.
- Skipping the transition period. EGCs and FPIs get transition relief. Treat it as a runway to get to full compliance, not a permanent exemption. Build your control environment during the grace period so you are genuinely ready when it phases out.
A Realistic Roadmap
Months 1 to 3: Hire your compliance lead. Conduct a gap analysis. Kick off control documentation. Establish your steering committee.
Months 4 to 12: Design your control environment. Map key financial processes. Document control activities. Build testing workpapers. Start running control tests.
Months 13 to 18: Run a full cycle of control tests. Remediate failures. Build your evidence library. Prepare management assessments and certifications.
Months 19 to 24: Second cycle of testing. Finalize SOX disclosures in the 20-F. File.
This timeline is compressible if you start early and dedicate resources. Companies that run into trouble almost always discovered IT control gaps or documentation issues late in the process.
The Bottom Line
SOX compliance for European FPIs is neither trivial nor overwhelming. You have genuine exemptions, real flexibility on governance, and a path that is more manageable than most people assume. What you cannot do is treat it as a one-time project or assume your existing controls translate automatically.
The companies that succeed treat SOX as the foundation for scalable financial reporting and governance, not a regulatory checkbox.
Have questions about SOX compliance or your path to U.S. capital markets? Reach out directly.