ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / SEC ENFORCEMENT
2 AUG 2026 · UPDATED 20 AUG 2026 · 16 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: SEC ENFORCEMENT
DOCKET NO. 601 · THE DEFENSE DESK

CFO Liability for Financial Reporting Violations.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

As a result of the rules and exceptions discussed above, simply certifying an inaccurate financial statement should not make a CFO liable under either Section 302 or Section 906 of the Sarbanes-Oxley Act (SOX). Similarly, merely making an accounting mistake does not, by itself, constitute securities fraud under Section 10(b) of the Securities Exchange Act, nor does it necessarily amount to criminal fraud under the federal securities laws.

When the SEC pursues civil enforcement actions, potential remedies include financial penalties, disgorgement, injunctions, and officer-and-director bars. Under Rule 102(e) of the SEC’s Rules of Practice and Procedure, the Commission also has the authority to temporarily suspend or permanently bar CPAs and other professionals from practicing before the SEC.

Section 21(d)(2) of the Exchange Act gives the SEC the authority to impose officer-and-director bars, which can prevent individuals from serving as officers or directors of SEC-reporting companies in the future. These bars can be either for a specified time period or permanent.

While CFOs can face liability under federal law, they can also face liability under state corporate law for breach of fiduciary duty. A CFO’s duties to its company are determined by the applicable governing law, and these duties can vary depending on the jurisdiction. For example, if the company is a Delaware corporation, then Delaware law will apply.

Regarding the SEC’s enforcement statistics, totals such as the number of SEC enforcement actions initiated, the number of civil claims filed, or the total amount of fines and penalties imposed will not reveal the percentage of cases involving CFOs or individuals who have certified a company’s financial statements. These totals do not provide a complete picture of the government’s enforcement efforts or its focus on individual executives.

What Do SOX Sections 302, 404, and 906 Require?

SOX Section 302 applies to issuers’ annual and quarterly reports under the Securities Exchange Act of 1934. It requires CEOs and CFOs to certify that they have personally reviewed the report. CEOs and CFOs must also certify (among other things) that the report:

  • does not contain any untrue statements of material fact or omit any material fact necessary to make the statement not misleading;
  • sets forth the financial statements, which have been prepared in accordance with U.S. GAAP and fairly present the company’s financial condition in all material respects;
  • includes a disclosure of all material off-balance-sheet transactions, including undisclosed contractual obligations and commitments; and
  • contains disclosures as required by the Securities Exchange Act of 1934.

Under Section 302, certifying does not constitute a guarantee that every number reported is correct. Rather, it certifies the specific matters stated in the Section 302 certification, including the report’s compliance with applicable disclosure requirements and the officers’ responsibility for disclosure controls and ICFR.

Section 302 also requires CEOs and CFOs to certify their responsibility for establishing and maintaining the company’s internal controls over financial reporting (ICFR), including designing those controls to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes. As a result, an inaccurate certification concerning these internal controls could lead to liability under Section 302.

SEC Filing and Financial Reporting Compliance Obligations Under SOX Section 404

Section 404 of the Sarbanes-Oxley Act, known as “Section 404,” contains separate requirements for issuer financial reporting and internal control compliance. Unlike Section 302, Section 404 imposes a separate obligation to assess the company’s internal controls over financial reporting (ICFR) and require the company’s auditors to attest to the management’s assessment.

If companies and their management fail to assess the ICFR or if they disclose them inaccurately, they could face liability under Section 404. This obligation applies independently from the certification requirements of Section 302, but Section 404 itself does not impose a separate certification requirement on CEOs or CFOs.

Criminal Certifications and Financial Reporting Violations Under SOX Section 906

SOX Section 906 imposes criminal liability for any issuer’s certification in a periodic report containing financial statements. Unlike Section 302, Section 906 does not create its own separate reporting obligation, but rather requires the certified report to contain these certifications and establish the criminal penalties for knowingly and/or willfully certifying false statements.

Differences and Overlap Between SOX Section 302 and Section 906

While Sections 302 and 906 both impose certification requirements, they have key differences in their enforcement and potential penalties. Although the Securities and Exchange Commission (SEC) can seek civil liability for a violation of Section 302, it can only do so to the extent that the CEO or CFO personally signed the certification. In contrast, the Department of Justice (DOJ) can seek criminal liability for violations of Section 906.

Which Reporting Violations Can Create Direct CFO Liability?

Fraud Claims Under Rule 10b-5

Rule 10b-5, an SEC regulation promulgated under Section 10(b) of the Exchange Act, supports an implied private right of action that allows shareholders to bring civil fraud claims. To prove fraud under Rule 10b-5, plaintiffs generally must prove that the CFO acted with “scienter” (or “mens rea”). Scienter is defined as “an intent to deceive, manipulate, or defraud,” and when plaintiffs are able to prove the CFO acted with scienter, then they can recover actual damages, which Section 28(a) of the Exchange Act limits to the plaintiff’s actual economic loss. If plaintiffs cannot prove the CFO acted with scienter, plaintiffs should have no ground to seek damages against the CFO under Rule 10b-5.

Exchange Act Rule 13b2-1 Prohibits Falsifying Accounting Records and Falsifying and Manipulating Books and Records

Exchange Act Rule 13b2-1 prohibits direct or indirect falsification of books and records. Rule 13b2-1 applies to all company officials, so there is no “CFO exception.” With respect to civil litigation, Rule 13b2-1 imposes liability regardless of whether there is a finding of scienter. However, under Rule 13b2-1, criminal liability requires that the individual act “willfully” (as well as establish the intent to defraud). If there are grounds for the CFO’s defense to argue that there are no grounds for alleging scienter, then this could be an affirmative defense to civil litigation under Rule 13b2-1. However, Rule 13b2-1 does not create a private right of action, so private plaintiffs cannot recover damages from a CFO under the rule; enforcement rests with the SEC, which may seek civil penalties and equitable remedies.

Exchange Act Rule 13b2-2 Prohibits Officers from Materially Misleading Company Auditors

Similarly to Rule 13b2-1, Exchange Act Rule 13b2-2 creates liability for company officers who either (i) materially mislead company auditors in relation to their auditing services, or (ii) materially mislead their company auditors who, under the Sarbanes-Oxley Act, are performing other services that are permitted under the Act. Again, SEC civil enforcement actions under Rule 13b2-2 do not require evidence of scienter to seek civil penalties. Rule 13b2-2 itself does not prescribe criminal penalties; criminal liability for a willful violation may arise under Exchange Act Section 32(a). If there is an opportunity for the CFO’s defense to argue that the CFO did not act with scienter, that may be grounds for an affirmative defense to avoid civil liability under Rule 13b2-2, but not criminal liability.

Exchange Act Section 13(b)(5) Prohibits Knowingly Circumventing Internal Accounting Controls or Falsifying the Issuer’s Books and Records

Exchange Act Section 13(b)(5) gives the SEC and DOJ additional authority to investigate and prosecute issuers of securities for knowingly (i) circumventing internal accounting controls, or (ii) causing others to knowingly circumvent internal accounting controls, and (iii) knowingly falsifying the issuer’s books and records. While Section 13(b)(5) imposes criminal penalties, it requires that the act be “knowingly” committed. Therefore, a CFO who willfully falsifies the company’s books and records, or allows another individual to do so, could face the prospect of being criminally liable under Section 13(b)(5) of the Exchange Act.

Exchange Act Section 32(a) Generally Imposes Criminal Liability for Willful Reporting Violations

Exchange Act Section 32(a) provides for criminal penalties for anyone who “willfully” violates Section 13(b) or any other financial reporting provision of the Exchange Act. Therefore, to pursue criminal penalties under Section 32(a), the DOJ will have to establish that the CFO committed a willful violation. In other words, showing that the CFO acted “willfully” is a prerequisite for establishing criminal liability under Section 32(a) (unless the statute which allows for a criminal prosecution contains no such requirement).

Does Being CFO Make Me Liable for Others’ Misconduct?

Exchange Act Section 20(a) Liability for Financial Reporting Violations

The “control person” liability imposed by Section 20(a) of the Exchange Act is a form of secondary liability, and it may be implicated if an issuer’s subordinate violates either Section 10(b) or Section 13(a) of the Exchange Act. In order to seek liability under Section 20(a), the plaintiff will first need to prove that there is a primary violation by another party. The plaintiff will then need to prove that there are sufficient grounds for designating the CFO as a “control person” with respect to the individual who committed the primary violation. As a result, if the CFO was not involved in the primary violation, then being the CFO will not be sufficient, in and of itself, to prove that the CFO is a “control person” for purposes of Section 20(a).

Section 20(a) is primarily the source of secondary liability in private securities fraud litigation. As a result, while the SEC can pursue “control person” liability under Section 20(a) of the Exchange Act, it can also seek to impose liability on a CFO under the aiding-and-abetting provision of the Exchange Act (specifically, Exchange Act Section 20(e), 15 U.S.C. § 78t(e)). Under Exchange Act Section 20(e), an individual who “knowingly or recklessly provides substantial assistance” to the primary violator is deemed to be in violation of that provision to the same extent as the primary violator. When a CFO is accused of providing such “assistance,” the CFO can potentially argue that they did not provide any material assistance. Similarly, a CFO can also potentially argue that there are no grounds for establishing the knowledge or recklessness required under Exchange Act Section 20(e).

With respect to Section 20(a), a CFO who certifies an inaccurate annual report has the opportunity to use a statutory affirmative defense if they:

  • acted in good faith, and,
  • did not directly or indirectly induce the act or acts constituting the violation or cause of action.

Can I Defend Against Securities Fraud and Other Reporting Charges Without Asserting These Defenses?

Why Don’t the SOX Certification Obligations of CEOs and CFOs Differ Based on Who Certifies?

Does Being a CFO Make You Liable for Others’ Misconduct in SEC Enforcement Actions?

Does Being CFO Make an Individual Liable for Others’ Misconduct in a Securities-Fraud Claim?

Does Being CFO Create Liability for Others’ Misconduct in a Reporting Violation Charge?

Do CFOs Have a Duty to Oversee Other Employees?

Can I Defend Against Civil or Criminal Penalties for Reporting Violations If I Did Not Directly Participate in the Falsification of a Report?

What Types of Remedies Can the SEC Seek Against a CFO Charged With Financial Reporting Violations?

Are Financial Reporting Violations Considered “Misdemeanors” or “Felonies”?

Do Financial Reporting Violations Constitute Violations of Federal Law?

Spodek Law Group, led by managing partner Todd Spodek, defends clients in federal criminal and white collar matters.

Can a Private-Company CFO Face Federal Criminal Charges?

Because private companies generally do not have any SOX certification obligations, a private-company CFO is not likely to face civil or criminal penalties under Section 302 or Section 906 of the Sarbanes-Oxley Act. However, private-company CFOs (and other executives) can still face liability under generally applicable federal fraud laws. This includes, but is not limited to, statutes that penalize bank fraud, tax evasion, mail and wire fraud, conspiracy, and other related offenses.

A CFO at a private company can also face liability for the destruction or spoliation of company documents. However, for a CFO to be liable, a prosecutor must show that the statutory elements of the relevant obstruction statute are met. For example, in order to establish criminal liability under 18 U.S.C. § 1519, a prosecutor must establish that the CFO knowingly “alters, destroys, mutilates, conceals, covers up, falsifies, or makes false entries in any record, document, or tangible object” with the intent to “impede, obstruct, or influence” a federal matter. This broadly defined offense can be triggered in various scenarios and can subject an individual to criminal prosecution. Under Section 1519, a CFO can face liability for a reporting violation regardless of whether the company is a public or private company, and regardless of whether the CFO holds a C-level title.

To the extent that the government can establish a CFO’s involvement in a fraud against shareholders or investors, there can be additional criminal liability as well. As an illustration of what is possible for an executive involved in corporate accounting fraud:

  • Former WorldCom CFO Scott Sullivan received a five-year prison sentence after his role in WorldCom’s approximately $11 billion in improper accounting entries (charged with aiding and abetting securities fraud and aiding and abetting money laundering).
  • Former Safety-Kleen CFO Paul Humphreys received a seventy-month prison sentence after his role in the Company’s inflation of earnings and subsequent attempts to mislead investors about the Company’s financial condition.

As a result of their criminal convictions, both former CFOs have also been ordered to pay substantial fines and restitution.

Does a Financial Restatement Prove Fraud, Trigger a SOX Clawback, or Require Repayment of Incentive Compensation?

SOX Section 304: “Clawback” Liability for Reimbursement of Compensation Received by Issuer CEOs and CFOs

Under Section 304 of the Sarbanes-Oxley Act, issuers have a financial reporting obligation that requires their CEOs and CFOs to personally reimburse the company for any securities-related compensation they receive during the twelve-month period following an inaccurate certification. While Section 304 of the Sarbanes-Oxley Act requires issuers’ CEOs and CFOs to personally reimburse their companies in the event of an issuer’s financial restatement that is required due to “misconduct resulting in noncompliance,” the statute is clear about which misconduct triggers the reimbursement: “misconduct, regardless of whether it is the CEO or CFO, results in a misstatement which necessitates an issuer financial restatement.” To this extent, SOX Section 304 allows for reimbursement even if there are no grounds for establishing the CFO’s personal misconduct.

Exchange Act Rule 10D-1: Recovery of Erroneously Awarded Incentive Compensation

In recent years, the Securities and Exchange Commission (SEC) has proposed (and adopted) Exchange Act Rule 10D-1, which creates an obligation for issuers to adopt clawback policies. Exchange Act Rule 10D-1 imposes an obligation to recover incentive-based compensation (which covers bonuses, awards, or other incentive-based compensation received during a three-fiscal-year period) in the event that an issuer financial restatement is required due to (i) a failure to comply with compliance obligations, or (ii) a material non-compliance with the Securities Exchange Act of 1934. Like SOX Section 304, Rule 10D-1 does not require a finding of “scienter” or other proof of executive misconduct. Additionally, Rule 10D-1 triggers “recovery” (not “reimbursement”) from all issuer officers who received erroneously awarded compensation during the applicable three-fiscal-year period. As a result, for CFOs who have been wrongly accused of fraud (and who have not wrongfully benefited from the Company’s misstatements), Rule 10D-1 recovery imposes a substantial burden on the CFO to assert a “clean record” affirmative defense.

There is substantial debate in the securities bar with respect to the interpretation and enforcement of Rule 10D-1. Some believe that the Rule represents a step toward requiring “compensation for any financial misstatement, regardless of who is responsible,” while others believe that the Rule represents a significant overreach that potentially violates the statutory authority under the Dodd-Frank Wall Street Reform and Consumer Protection Act. Given these outstanding issues, executives who face the potential for a Rule 10D-1 clawback should seek to work with their Company’s compensation committee and potential defense counsel to assert appropriate (and, if necessary, affirmative) defenses to avoid unnecessary (or erroneous) recovery demands.

Are Inaccurate Certifications and Financial Restatements Alone Sufficient to Establish Liability in Securities Fraud Claims?

No, an inaccurate financial restatement or a misleading financial statement, in and of itself, should be insufficient to prove that a CFO engaged in fraud or has scienter. A financial restatement is an acknowledgment that a prior statement was incorrect. However, showing that a prior statement was incorrect should not, by itself, allow plaintiffs to prove that a CFO committed fraud. Similarly, while inaccuracies in financial reports and certifications do warrant questions regarding the CFO’s involvement in the Company’s reporting violations, they do not establish the CFO’s involvement in the Company’s reporting violations. Similarly, while there are grounds for denying a CFO’s scienter, there are also grounds for asserting a CFO’s defense to scienter, which should be scrutinized carefully in light of the relevant facts.

What Defenses and Protections Can a CFO Actually Use?

Can CFOs Assert a Good-Faith Reliance Defense to Negate Personal Liability?

Good-faith reliance on company auditors or company counsel is evidence that does not automatically exempt the CFO from personal liability for securities fraud or other reporting violations. However, demonstrating that the CFO relied on information from auditors or counsel in good faith can be a critical element of the CFO’s defense to avoid liability. For example, a CFO who relies on his or her auditor’s opinion after affirmatively inquiring about a potential problem, or a CFO who relies on a company counsel’s opinion after presenting relevant facts can both serve as a basis for asserting good-faith reliance. When successful, this affirmative defense can protect CFOs from both civil and criminal penalties. To this end, proving the existence of “warning signs” during the time the CFO relied on the auditor’s or company counsel’s opinion can both undermine a claimed good-faith reliance defense to avoid liability.

Do Privileges Apply When CFOs Are Investigated for Participating in Issuer’s Financial Reporting Violations?

One of the common mistakes in financial investigations involving companies is for company executives to wrongly rely on company counsel’s role as company counsel. When executives are investigated for participating in their companies’ financial reporting violations, as executives, they are not represented by their company’s corporate counsel. Instead, in most cases, corporate counsel represents the organization. As a result, a CFO who is accused of a financial reporting violation can seek to avoid liability by hiring their own defense counsel and asserting their own individual (rather than corporate) privilege.

Does the CFO Rely on Company Counsel’s Legal Opinion, or Do Company Auditors Give the “All-Clear”?

When a CFO does seek to avoid liability based on reliance on an auditor’s (and/or a company lawyer’s) “all-clear” statement or opinion, the CFO must be able to demonstrate the authenticity of the communication. In other words, a CFO who did not document his or her good-faith reliance on the company’s legal counsel’s or company auditors’ affirmative statements or opinions may find it difficult to defend against an accusation of personal involvement in the company’s financial misstatements.

Is a CFO Indemnified or Entitled to Advancement of Defense Costs?

CFOs are similarly entitled to indemnification and advancement protections, and both are distinct protections. Indemnification and advancement are two separate issues; and, while they both fall under the corporate governance laws of the applicable jurisdiction, each can also be influenced by individual company bylaws, employment agreements, and other corporate-governance instruments. While individual executive indemnity arrangements can create protection in the case of financial reporting violations, the scope and enforceability of individual executive indemnity or advancement arrangements can depend on a broad range of factors.

Do D&O Policies Cover Fraud?

Generally, D&O insurance policies do not cover fraud committed by the insured, and thus, do not cover a CFO who willfully engages in financial reporting fraud. Most D&O policies restrict coverage to the event that the insured committed an “intentional act” or other specified conduct, and most D&O policies restrict coverage to the event that there is no finally adjudicated finding of intent to deceive, manipulate, or defraud. While D&O policies can impose substantial restrictions on an insured’s recovery under a variety of circumstances, they also generally afford “adequate” defense-cost coverage to the CFO, provided the CFO is not excluded under the policy’s specific coverage restrictions.

Speak With a Federal Defense Lawyer

If you are dealing with any part of what this article describes, the next step is a conversation with a lawyer who handles these cases. Spodek Law Group is a second generation criminal defense firm practicing since 1976, representing clients nationwide from offices in New York, Brooklyn, Queens and Los Angeles. Call 212-300-5196 to speak with our team.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.