Section 906: criminal certifications
Section 906 requires the CEO and CFO of a public company to certify that their periodic financial reports fully comply with SEC requirements and fairly present the company's financial condition. Unlike other SOX provisions, Section 906 attaches criminal penalties—including fines and imprisonment—to executives who knowingly or willfully certify false statements.
What it means
The intent of Section 906 is to hold top executives personally accountable for the integrity of financial reporting. It prevents leadership from claiming ignorance regarding accounting errors or fraud by requiring a formal, signed statement that accompanies every quarterly (10-Q) and annual (10-K) report.
In practice, this means the CEO and CFO cannot simply rely on the word of their subordinates. They must have reasonable assurance that the financial statements are accurate. The law distinguishes between "knowing" certifications (lower penalty) and "willful" certifications (higher penalty), where the executive intentionally misled investors.
How to meet it
- Implement a formal "sub-certification" process where lower-level managers and controllers certify their specific business units' data before the CEO/CFO sign the final report.
- Establish a recurring financial review committee or meeting prior to each filing deadline to challenge assumptions and review anomalies in the numbers.
- Ensure the certification document contains the exact statutory language required by Section 906 regarding compliance with SEC rules and fair presentation of financials.
- Maintain a rigorous internal control framework (ICFR) that provides the CEO/CFO with reliable data feeds, reducing the risk of certifying inaccurate information.
- Conduct a final legal and compliance review of the financial statements to ensure all disclosures are complete and not misleading.
Evidence an auditor asks for
- Signed and dated copies of the Section 906 certifications filed with each periodic report.
- A completed "certification package" containing the sub-certifications signed by departmental heads and controllers.
- Minutes or agendas from pre-filing review meetings showing that executives questioned the financial data before signing.
- Documentation of the process used to aggregate data for the certification, proving a systematic approach was taken rather than a rubber-stamp approval.
Common pitfalls
- Signing certifications as a formality without reviewing the supporting sub-certifications or evidence from lower management.
- Failing to maintain an audit trail of the "due diligence" performed by executives before they signed the certification.
- Assuming that Section 302 (civil) and Section 906 (criminal) are identical, thereby underestimating the legal risk associated with a willful misstatement.