What Every Federal Manager Can Learn from Sarbanes-Oxley: Why OMB Circular A-123, the GAO Green Book, and Strong Internal Controls Matter More Than Ever
- John C. Blackshire, Jr.

- 2 days ago
- 5 min read
Learn How to Build a World-Class Federal Internal Control Program at the GAO Green Book Compliance Academy
Tuesday–Thursday, September 29 – October 1, 2026
Government managers often believe that the Sarbanes-Oxley Act (SOX) applies only to publicly traded companies.
Technically, that is correct.
Practically, it is one of the most valuable management lessons available to the Federal government.
When Congress enacted the Sarbanes-Oxley Act in 2002, it fundamentally changed how corporate executives evaluate, document, test, and report on internal controls over financial reporting.
Federal agencies were already subject to the Federal Managers' Financial Integrity Act (FMFIA) and OMB Circular A-123, but SOX prompted the federal government to reevaluate its own internal control expectations. OMB revised Circular A-123 to strengthen management's responsibility for assessing internal controls, particularly over financial reporting, while aligning more closely with modern internal control concepts.
One of the best resources explaining this relationship is OMB Circular A-123 and Sarbanes-Oxley: Management's Responsibility for Internal Control in Federal Agencies by Michael J. Ramos and his co-authors. The book explains how many of the concepts developed under SOX Section 404 can strengthen federal internal control programs implemented under OMB Circular A-123.
Today, those concepts are even more relevant because federal agencies now implement internal control using the GAO Green Book 2025, the government's authoritative framework for designing, implementing, operating, and evaluating internal control systems.
That is exactly why Corporate Compliance Seminars offers the GAO Green Book Compliance Academy, an intensive three-day program designed to help federal managers, internal auditors, inspectors general, financial managers, and compliance professionals develop practical Green Book compliance skills.
SOX Changed More Than Corporate America
Many people associate Sarbanes-Oxley with:
CEO certifications
CFO certifications
External auditor attestations
Public company reporting
Those are certainly important.
But SOX also introduced a disciplined methodology for evaluating internal control.
Organizations were required to:
Document controls
Identify risks
Test operating effectiveness
Evaluate deficiencies
Report material weaknesses
Monitor remediation
Hold management accountable
The Federal government recognized that these disciplines had value beyond publicly traded companies.
OMB Circular A-123 incorporated many of the same management concepts into federal internal control guidance. The 2026 revised Circular emphasized management responsibility, documentation, assessment, corrective action, and reporting while aligning federal internal control with the five-component framework familiar from modern control models.
The GAO Green Book Became the Foundation
Today, federal agencies establish and evaluate internal controls using the GAO Green Book.
The Green Book defines internal control as a process effected by management and personnel that provides reasonable assurance regarding the achievement of objectives related to:
Operations
Reporting
Compliance
It organizes internal control into five components supported by seventeen principles, providing agencies with a comprehensive framework for designing, implementing, and operating effective control systems.
Rather than viewing internal control as merely a financial exercise, the Green Book applies throughout the organization.
OMB Circular A-123 Makes Management Responsible
One of Michael Ramos' central observations is that strong internal controls cannot be delegated entirely to auditors.
Management owns the controls.
This is equally true under:
Sarbanes-Oxley
OMB Circular A-123
FMFIA
The GAO Green Book
Internal auditors provide assurance.
Inspectors General provide oversight.
External auditors provide independent opinions.
Management designs, implements, operates, and continuously improves the control system.
That distinction is one of the most important governance lessons in federal management to provide sustainability for a Federal Agency.
Documentation Is Not Bureaucracy
Federal employees sometimes view documentation as unnecessary paperwork.
SOX demonstrated why documentation matters.
If a process is undocumented:
It cannot be evaluated consistently.
It cannot be tested consistently.
It cannot be improved consistently.
It cannot easily survive employee turnover.
The Green Book similarly emphasizes that management should document internal control in sufficient detail to demonstrate that the system has been designed, implemented, and is operating effectively.
Good documentation protects both the agency and the people responsible for managing it.
Risk Assessment Should Drive Everything
One of the most significant changes introduced by modern internal control frameworks is the movement away from checklist compliance.
Instead of asking:
"Did we complete the required form?"
Organizations ask:
"What are our greatest risks?"
Risk assessment drives:
Audit planning
Control design
Resource allocation
Testing priorities
Monitoring
Reporting
The strongest agencies do not attempt to control everything equally.
They devote the greatest attention to the greatest risks.
Internal Control Is More Than Financial Reporting under the Green Book
Sarbanes-Oxley focused heavily on financial reporting.
Federal agencies operate under a much broader mission.
The Green Book applies to:
Operations
Helping agencies accomplish their mission efficiently and effectively.
Reporting
Producing reliable financial and nonfinancial information.
Compliance
Following laws, regulations, grant requirements, and policies.
Modern internal control systems must address all three objectives simultaneously.
Continuous Monitoring Matters
One lesson repeatedly reinforced by SOX is that internal controls are not evaluated once each year.
Controls operate every day.
Management should continually ask:
Are controls still operating?
Has risk changed?
Have systems changed?
Has staffing changed?
Are corrective actions effective?
Have new risks emerged?
The May 2025 Green Book likewise identifies monitoring as one of the five foundational components of internal control. Monitoring helps management determine whether controls continue to operate effectively over time.
Fraud Prevention Requires Strong Internal Controls
Strong internal controls do more than improve accounting.
They reduce opportunities for:
Fraud
Waste
Abuse
Improper payments
Asset misappropriation
Unauthorized transactions
The May 2025 Green Book places additional emphasis on preventive controls, fraud risks, improper payments, and information security as part of an effective internal control system.
Federal managers should recognize that every control weakness creates an opportunity for something to go wrong.
Technology Has Changed Internal Control
When Ramos' book was published in 2006, Artificial Intelligence was not part of internal control discussions.
Today it is.
Federal managers must now consider:
AI governance
Cloud computing
Cybersecurity
Data governance
Automated decision-making
Robotic Process Automation
Continuous monitoring
Advanced analytics
The Green Book's principles remain remarkably adaptable because they focus on governance rather than individual technologies.
Good internal control applies whether a transaction is processed manually or through AI.
Why Government Managers Should Attend the GAO Green Book Compliance Academy
Corporate Compliance Seminars' GAO Green Book Compliance Academy helps participants move beyond simply reading the Green Book.
Attendees learn practical methods for:
Applying all five Green Book components
Implementing the seventeen principles
Conducting effective risk assessments
Designing control activities
Evaluating deficiencies
Improving documentation
Monitoring corrective actions
Strengthening governance
Preparing management assurance documentation
Supporting OMB Circular A-123 compliance
The emphasis is practical implementation—not simply understanding the framework.
Who Should Attend?
This academy is designed for:
Federal Managers
Internal Auditors
Inspectors General staff
Financial Managers
Program Managers
Compliance Officers
Risk Managers
Grant Managers
Agency Executives
Internal Control Coordinators
Performance Auditors
Anyone responsible for strengthening federal governance will benefit from understanding how the Green Book, OMB Circular A-123, and SOX-inspired internal control disciplines fit together.
Internal Controls Build Public Trust
Federal agencies manage taxpayer resources.
Strong internal controls protect:
Public funds
Federal programs
National security
Grants
Benefits
Procurement
Information systems
Public confidence
Every control that prevents an improper payment, detects fraud, improves reporting accuracy, or strengthens accountability ultimately supports public trust in government.
That is why internal control matters.
Join Us September 29 – October 1, 2026
Whether you are building a new internal control program or strengthening an existing one, the GAO Green Book Compliance Academy provides practical tools you can immediately apply within your agency.
Drawing on decades of federal internal control evolution—from FMFIA to OMB Circular A-123, through the lessons of Sarbanes-Oxley and today's GAO Green Book—the academy prepares federal professionals to build stronger governance systems, improve accountability, reduce risk, and enhance organizational performance.
Join Corporate Compliance Seminars for this comprehensive three-day program and learn how to transform internal control from a compliance requirement into a strategic management tool.
Comments