C-levels should be personally responsible for the decisions "made by the corp". They will need to obviously add checks and verification to what happens inside the company and could not claim anymore they "didn't know" because it would be explicit that their role is exactly to know and respond for it. Simple as that
In theory SOX only has benefits, but in practice the compliance costs due to it are very high. I'm sure some of that is for the better (bad oversight before SOX) but I can't imagine the insane paper tigers that come out of it are a net positive in the end.