Which U.S. statute — and year — first required issuers to keep accurate books and maintain internal accounting controls (Exchange Act §13(b)(2)(A)-(B))? This is the backbone of lawful operations and proactive compliance reviews.
Foreign Corrupt Practices Act, 1977 — amending the ’34 Act — first imposed the books-and-records and internal controls mandate; some cite the 1934 Act, but the explicit control requirement came with the FCPA. In my reviews I start by pulling the vendor-master change log and checking dual authorization, which maps to ‘access to assets is permitted only in accordance with management’s authorization’ — want a one-pager you can reuse?
, this always trips people up: it’s the FCPA amendments to the ’34 Act in 1977, which created §13(b)(2)(A)-(B) for “books and records” and internal controls — applies to issuers only. For the exact text, see 15 U.S.C. §78m(b)(2): 15 U.S. Code § 78m - Periodical and other reports | U.S. Code | US Law | LII / Legal Information Institute. Tiny caveat: SOX 404 (2002) layered on management/auditor reporting, but the underlying mandate is ’77 — do you fold SOX testing into those proactive reviews you mentioned?
Agree with @ashton_77r: Congress did it in 1977 via the FCPA amendments, adding the “reasonable assurances” internal-control standard in §13(b)(2)(B) — when they installed the thermostat, not just the thermometer. Tiny caveat: broker-dealers had earlier recordkeeping under §17(a), but issuer-wide controls start here; the DOJ/SEC guide sums it up well: https://www.justice.gov/criminal-fraud/file/1292051/download.
Public Law 95–213 (1977) did it; before that, the SEC’s 1976 voluntary disclosure push nudged companies but didn’t require internal control systems. If you need a clean cite, the text is here: https://www.congress.gov/public-law/95th-congress/house-bill/3815 — think of it as the post-Watergate lock-the-till rule. @ashton_77r, feel free to add any nuance.