
SEC enforcement shifts toward CFO liability as case counts fall
Fewer corporate actions do not mean less personal exposure. The 2026 enforcement recalibration points at named officers, certification support and the evidence behind materiality calls.
A falling enforcement case count is the easiest statistic in corporate life to misread. Across the securities enforcement post-mortems published in the first quarter of 2026, the consistent finding was not that the Securities and Exchange Commission had gone quiet, but that the composition of its docket had changed. For finance leaders, that recalibration turns SEC enforcement CFO liability from an abstraction into a named-defendant problem, and it lands at a moment when the finance seat has quietly absorbed enterprise risk ownership without a matching budget.
What actually changed in the enforcement mix
The clearest framing came from Cleary Gottlieb, whose 2026 alert memo separated what has changed from what has not. The change: fewer cases built on novel or expansive legal theories, and less appetite for sweeping industry-wide initiatives. What has not changed: the Commission's willingness to pursue financial reporting fraud, improper revenue recognition, misleading disclosure and false officer certifications. Those are the core accounting cases, and they have never depended on a novel theory to succeed.
Gibson Dunn's Securities Enforcement 2025 Year-End Update, published in February 2026, remains the benchmark for the fiscal-year action counts and the corporate-versus-individual split. Morgan Lewis and Morrison Foerster followed with January 2026 roundups that put named, dated matters behind the trend line. Read together, the three documents describe an agency doing less volume and more of the kind of case that ends with a person's name in the caption.
That distinction matters because the two outcomes are not scaled versions of each other. A corporate resolution is negotiated, budgeted and disclosed. An individual action reaches the officer's compensation, professional licensure in some cases, and indemnification arrangements that behave very differently once a charge is filed against a person rather than an entity.
Why a lower case count is not lower CFO risk
Three mechanics turn individual accountability into a material personal exposure. The first is clawback. Listed-company recovery policies now operate on a no-fault basis for incentive compensation tied to restated financials, which means the clawback conversation can begin before any finding of misconduct. The second is directors-and-officers coverage: severability provisions, conduct exclusions and advancement disputes surface precisely when an individual is charged, and few CFOs have read their own tower closely enough to know how it responds.
The third is the certification itself. A Section 302 or 906 certification is a personal statement, and enforcement staff treat the file supporting it as the most direct evidence of what the CFO knew and when. If the support file is thin, retrospective or assembled by someone else, the certification stands alone as an assertion. If it is contemporaneous, dated and tied to identifiable reviewers, it is a defence.
Running underneath all of this is a structural point CFO.com made in April 2026: the CFO is already functioning as chief risk officer at most mid-cap and many large-cap companies, typically without incremental headcount or a separate risk budget. Protiviti's Top Risks 2026 finance-function cut ranks regulatory and compliance risk near the top of the list. The person most likely to be named is also the person carrying the risk function part-time.
A March 2026 filing obligation that attaches to the person
One concrete deadline has already passed its start date and is worth confirming against your own filing calendar. Per Skadden's guidance, SEC insider reporting requirements for directors and officers of foreign private issuers apply beginning March 18, 2026. That is a personal filing obligation, not a company one, and it lands on finance executives at FPIs who have historically been outside the Section 16 regime.
Late or missed personal filings are not the kind of matter that builds a career-ending case on its own. They are, however, exactly the kind of low-effort finding that appears in an enforcement release alongside more serious allegations, and they signal to staff that personal compliance hygiene is weak. If your issuer is an FPI, the answer to who is monitoring officer filings should be a name, not a department.
Three artifacts that should exist before a subpoena does
The controls that matter here are unglamorous and cheap relative to their defensive value. First, a certification support file for each reporting period: the disclosure committee materials, the sub-certifications from business and functional owners, the list of open items and how each was resolved, all dated and retained under a documented policy rather than in an executive's inbox.
Second, a materiality judgment record. When a close-process issue is assessed and not corrected, the reasoning should exist in writing at the time of the decision, with the quantitative and qualitative factors considered and the people who signed off. Reconstructed materiality memos written after a restatement announcement carry almost no weight and can look worse than silence.
Third, a close-process audit trail that answers who reviewed what and when. Most enterprise close tools already capture this. The failure is usually that reviewers approve in bulk at the end of the cycle, producing timestamps that undermine rather than support the claim of substantive review. Fixing that is a process discipline question, not a software purchase.
What to ask the general counsel and audit committee chair this quarter
Four questions are enough to surface most of the gaps. Ask the general counsel: does our indemnification agreement cover advancement of defence costs for an individual SEC action, and at what point does advancement stop? Ask for the D&O policy's Side A limits and conduct exclusion language in plain English, not a summary slide.
Ask the audit committee chair: if I were the subject of an inquiry tomorrow, who selects my counsel and who selects the company's, and at what point do those become different people? The answer should be agreed in calm conditions, not negotiated during a document preservation notice.
Finally, ask internally: can we produce, within 48 hours, the support file for the last four certifications? If the answer involves reconstructing anything, that is the project for this quarter. The enforcement mix has moved toward individuals, and the documentation that defends an individual is created before it is needed or not at all.
Key takeaways
- Enforcement volume has cooled, but the mix has shifted toward individual accountability and classic financial reporting fraud, per early-2026 law firm reviews.
- Personal exposure runs through three channels: incentive compensation clawback, D&O conduct exclusions and severability, and the officer certification itself.
- SEC insider reporting for directors and officers of foreign private issuers applies from March 18, 2026, a personal filing duty on FPI finance executives.
- Build three artifacts now: a dated certification support file, a contemporaneous materiality judgment record, and a close-process review trail with credible timestamps.
- Confirm with the GC how defence-cost advancement works for an individual action, and with the audit committee chair who selects separate counsel and when.


