I've seen some very strange things done in the name of SOX compliance. I was involved in the potential acquisition in the UK of a subsidiary of a US public company and they used to print out their AD group memberships (as screenshots) and have someone sign (wet sign - with a pen!) the printouts every week/month.
When I asked whether SOX compliance really required this they basically said they didn't really know but had to play safe as the regulations were just so vague.
Reminds me a little of the medical device industry. We do a lot of things that from an engineering perspective result in worse products but since nobody understands the regulations fully we do them. Until a new guy comes in, re-reads the rules and says we can do it differently now.
I work in the biotech industry and it's the exact same way. We have legions of lawyers who try and decipher the regulations.
A great example is price reporting to the gov't. You're supposed to report your net price across all sales to CMS on a quarterly basis. Problem is, the regulations are so vague that it falls on companies as to how to interpret them. Naturally, companies err on the conservative side (at least most of them). My old company probably had 20 FTE's dedicated to this one regulation.
And if you reach out to the regulatory body for clarification, that's a multi-year process. A great example is the AMP rule (average manufacturer price). I think CMS was supposed to role out the clarification back in 2012, but only finalized it last year. And there are still unanswered questions.
I used to work in the ecommerce space.. along with PCI our security/compliance people made us do lots of vague things with our delivery pipeline with the broad excuse of "SOX compliance"
When asked for the specific rule we had to follow, there was never any response.
When I asked whether SOX compliance really required this they basically said they didn't really know but had to play safe as the regulations were just so vague.