The CFO reports to both the CEO and the board of directors, and whether the CFO reports to the CEO or the board depends on which duty you mean. The CEO is the CFO’s day-to-day supervisor, setting priorities and evaluating performance. The board, acting through its audit committee, holds a separate reporting line that federal securities law and stock exchange listing standards require to exist independent of the CEO. That second line is not a courtesy. It is the reason the CFO’s job is legally different from every other seat below the CEO.
The CEO Runs the Day-to-Day Relationship
In a typical corporate hierarchy, the CEO is the CFO’s direct boss. The CEO sets priorities, evaluates performance, and expects real-time financial data to inform decisions about capital spending, acquisitions, and resource allocation. When the CFO falls short of expectations, the CEO is usually the one who initiates corrective action or recommends termination.
Compensation reflects this order. CEO pay packages generally exceed CFO compensation by a wide margin, and the CFO’s performance-based incentives are often tied to metrics the CEO helped define during the budget cycle. What catches people off guard is that the CEO’s authority over the CFO is not absolute. In certain situations, the board can override it entirely.
The Board’s Audit Committee Holds a Separate Line
Alongside the CEO relationship, the CFO maintains what is often called a “dotted-line” reporting relationship to the board’s audit committee. SEC rules require that the audit committee of every listed company be directly responsible for overseeing the external auditors, and those auditors report to the audit committee rather than to management.1SEC.gov. Final Rule – Standards Relating to Listed Company Audit Committees The CFO sits at the center of that process, providing the financial data the committee needs to do its job.
The audit committee relies on the CFO to flag internal control weaknesses, accounting irregularities, and financial risks that could affect the company. This channel exists specifically so information can reach the board without being filtered through the CEO. If the CEO is the source of a problem, the audit committee needs to hear about it from someone with firsthand knowledge of the books. That someone is almost always the CFO.
Sarbanes-Oxley reinforces this structure by requiring the CFO to disclose all significant internal control deficiencies and any fraud involving management directly to the audit committee.2Office of the Law Revision Counsel. 15 U.S. Code 7241 – Corporate Responsibility for Financial Reports The CFO cannot wait for the CEO’s blessing to make those disclosures. The obligation runs to the board regardless of what the CEO wants.
Who Can Actually Hire and Fire the CFO
Under most state corporate law, the board of directors holds ultimate authority to appoint and remove corporate officers. The board can delegate hiring of lower-level officers to the CEO, but for executive officers like the CFO, stock exchange listing standards typically require the board or its compensation committee to approve both the hiring decision and any termination package. The CEO may recommend firing the CFO, but the board has the final say.
That structural reality matters when tensions arise. A CEO who wants to push out a CFO for raising uncomfortable questions about the financials cannot simply do it unilaterally. The board must approve, and if the audit committee is paying attention, the circumstances around the termination will get scrutiny. This is one of the practical checks that prevents the CEO from treating the CFO as just another direct report to be managed into silence.
Why the Dual Line Exists: The CFO’s Personal Legal Exposure
The reason the CFO cannot simply be a CEO subordinate is that federal law places obligations on the CFO personally. Sarbanes-Oxley makes the CFO individually accountable for the accuracy of financial reporting, and that accountability requires a channel to the board that the CEO does not control.
Section 302 Certifications
Every quarterly and annual report filed with the SEC must include a personal certification from both the CEO and the CFO. The signing officers must certify that they have reviewed the report, that it contains no material misstatements or omissions, and that the financial statements fairly present the company’s financial condition.2Office of the Law Revision Counsel. 15 U.S. Code 7241 – Corporate Responsibility for Financial Reports They must also certify that they are responsible for internal controls, that they have evaluated those controls within the prior 90 days, and that they have disclosed any deficiencies or fraud to the auditors and the audit committee.
The CFO is attesting under penalty of law that the numbers are right. If they are not, it does not matter whether the CEO told the CFO to sign. The signature creates personal exposure.
Section 906 Criminal Penalties
A separate provision requires the CEO and CFO to submit a written statement with every periodic financial report certifying that the report fully complies with SEC requirements and fairly presents the company’s financial condition. A knowing violation carries a fine of up to $1 million and up to 10 years in prison. A willful violation, where the officer knowingly certifies a false report, carries a fine of up to $5 million and up to 20 years in prison.3Office of the Law Revision Counsel. 18 U.S. Code 1350 – Failure of Corporate Officers to Certify Financial Reports
Section 404 Internal Controls
Each annual report must include management’s assessment of the effectiveness of internal controls over financial reporting.4Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls The statute assigns this responsibility to “management” broadly, but the CFO is the executive who oversees financial reporting processes and typically leads the evaluation. An independent auditor then reviews management’s assessment and issues its own opinion.
The Auditor Relationship
Under PCAOB standards, the completion of every audit requires a management representation letter signed by the CEO and CFO. In that letter, management confirms that the financial statements are fairly presented, that all information has been made available to the auditors, and that no fraud involving senior management has been concealed.5PCAOB. AS 2805 – Management Representations For the internal controls audit, the CFO must disclose all deficiencies identified during management’s evaluation, separately flag any material weaknesses, and describe any fraud that affects the financial statements or involves employees with a significant role in internal controls.6PCAOB. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements These disclosures go to the auditors, and the auditors report to the audit committee. The CEO is not a gatekeeper in this chain.
What Happens When the Two Lines Conflict
The dual reporting structure creates an obvious tension. The CFO works for the CEO every day but has a legal duty to tell the board things the CEO might not want disclosed. When that situation arises, two federal statutes protect the CFO.
Sarbanes-Oxley prohibits public companies from retaliating against any employee who reports conduct they reasonably believe violates securities laws, whether the report goes to a federal agency, a member of Congress, or a supervisor within the company.7Whistleblower Protection Program. Sarbanes-Oxley Act (SOX) – Whistleblower Protection Program A CFO who raises concerns about accounting manipulation to the audit committee is engaged in protected activity. If the company fires, demotes, or harasses the CFO for making that report, the CFO can seek reinstatement, back pay, and compensatory damages. The filing deadline is tight: a complaint must reach OSHA within 180 days of the retaliatory action.
The Dodd-Frank Act adds a second layer. If the CFO reports securities violations directly to the SEC and the resulting enforcement action produces sanctions exceeding $1 million, the whistleblower can receive an award of 10% to 30% of the money collected.8SEC.gov. SEC Issues Awards Totaling $98 Million to Two Whistleblowers Dodd-Frank also provides its own anti-retaliation protections with a longer three-year statute of limitations, though it allows for mandatory arbitration and does not provide the emotional distress damages available under SOX.
How This Changes in Private Companies and Nonprofits
The dual reporting structure described above applies primarily to publicly traded companies subject to SEC oversight. Smaller businesses, startups, and private companies often operate with simplified hierarchies where these formal channels do not exist. A CFO at a startup might report to a founder or managing director rather than a CEO. Many smaller firms lack a formal board entirely, which means the CFO’s accountability runs to the business owners alone.
In very small companies, the person handling CFO responsibilities may also manage operations, human resources, or other functions. The overlap can create efficiency, but it eliminates the separation between financial oversight and operational leadership that protects larger organizations. Without an independent audit committee, there is no external check on whether the financial picture being presented to owners is accurate.
Nonprofits introduce another variation. A 501(c)(3) typically has a board treasurer who serves as the principal financial officer in a governance role. In larger nonprofits that employ a professional CFO, the treasurer’s role shifts toward oversight, often receiving briefings from the CFO before board meetings rather than managing finances directly. The CFO in that setting reports operationally to the executive director or CEO but answers to the board for financial stewardship.