Equifax 10-K 2017-12-31

Filed 2018-03-01. 22 sections, 550K characters. Original on sec.gov · Markdown · JSON

What changed since the 2016-12-31 10-KNew, removed and reworded risk factor headings, then every item sentence by sentence.

Cover and table of contents

10-K 1 efx10k20171231.htm 10-K

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549


FORM 10-K

☒ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the fiscal year ended December 31, 2017

OR

☐TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the transition period from to

Commission File Number 001-06605


EQUIFAX INC.

(Exact name of registrant as specified in its charter)

Georgia58-0401110
(State or other jurisdiction of incorporation or organization)(I.R.S. Employer Identification No.)
1550 Peachtree Street, N.W.
Atlanta, Georgia30309
(Address of principal executive offices)(Zip Code)

Registrant’s telephone number, including area code: 404-885-8000

Securities registered pursuant to Section 12(b) of the Act:

Title of each className of each exchange on which registered
Common Stock, $1.25 par value per shareNew York Stock Exchange

Securities registered pursuant to Section 12(g) of the Act: None.


Indicate by check mark if Registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Exchange Act (“Act”). ☒ YES ☐ NO

Indicate by check mark if Registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. ☐ YES ☒ NO

Indicate by check mark whether Registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. ☒ YES ☐ NO

Indicate by check mark whether the Registrant has submitted electronically and posted on its corporate Web site, if any, every Interactive Data File required to be submitted and posted pursuant to Rule 405 of Regulation S-T during the preceding 12 months (or for such shorter period that the Registrant was required to submit and post such files). YES ☒ NO ☐

Indicate by check mark if disclosure of delinquent filers pursuant to Item 405 of Regulation S-K is not contained herein, and will not be contained, to the best of Registrant’s knowledge, in definitive proxy or information statements incorporated by reference in Part III of this Form 10-K or any amendment to this Form 10-K. ☐

Indicate by check mark whether the Registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and "emerging growth company" in Rule 12b-2 of the Exchange Act. (Check one):

☒ Large accelerated filer☐ Accelerated filer☐ Non-accelerated filer☐ Smaller reporting company☐ Emerging growth company
(Do not check if a smaller reporting company)

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the Registrant is a shell company (as defined in Rule 12b-2 of the Act). ☐ YES ☒ NO

As of June 30, 2017, the aggregate market value of Registrant’s common stock held by non-affiliates of Registrant was approximately $16,541,237,155 based on the closing sale price as reported on the New York Stock Exchange. At January 31, 2018, there were 120,123,872 shares of Registrant’s common stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

Portions of Registrant’s definitive proxy statement for its 2018 annual meeting of shareholders are incorporated by reference in Part III of this Form 10-K.

TABLE OF CONTENTS

Page
PART I
Item 1.Business2
Item 1A.Risk Factors14
Item 1B.Unresolved Staff Comments24
Item 2.Properties24
Item 3.Legal Proceedings25
Item 4.Mine Safety Disclosures27
PART II
Item 5.Market for the Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities28
Item 6.Selected Financial Data31
Item 7.Management’s Discussion and Analysis of Financial Condition and Results of Operations34
Item 7A.Quantitative and Qualitative Disclosures About Market Risk59
Item 8.Financial Statements and Supplementary Data60
Item 9.Changes in and Disagreements with Accountants on Accounting and Financial Disclosure109
Item 9A.Controls and Procedures109
Item 9B.Other Information110
PART III
Item 10.Directors, Executive Officers and Corporate Governance110
Item 11.Executive Compensation111
Item 12.Security Ownership of Certain Beneficial Owners and Management and Related Stockholder Matters111
Item 13.Certain Relationships and Related Transactions, and Director Independence111
Item 14.Principal Accountant Fees and Services112
PART IV.
Item 15.Exhibits and Financial Statement Schedules113
Item 16.Form 10-K Summary116
Signatures116

PART I

Item 1. BUSINESS

OVERVIEW

Equifax Inc. is a leading global provider of information solutions and human resources business process outsourcing services for businesses, governments and consumers. We have a large and diversified group of clients, including financial institutions, corporations, governments and individuals. Our services are based on comprehensive databases of consumer and business information derived from numerous sources including credit, financial assets, telecommunications and utility payments, employment, income, demographic and marketing data. We use advanced statistical techniques and proprietary software tools to analyze all available data, creating customized insights, decision-making solutions and processing services for our clients. We help consumers understand, manage and protect their personal information and make more informed financial decisions. We also provide information, technology and services to support debt collections and recovery management. Additionally, we are a leading provider of payroll-related and human resource management business process outsourcing services in the United States of America, or U.S.

We currently operate in four global regions: North America (U.S. and Canada), Asia Pacific (Australia and New Zealand), Europe (the United Kingdom, or U.K., Spain and Portugal) and Latin America (Argentina, Chile, Costa Rica, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay). We maintain support operations in the Republic of Ireland. We also offer Equifax branded credit services in Russia and India through joint ventures, have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and Dubai, and have an investment in a consumer and commercial credit information company in Brazil.

Equifax was originally incorporated under the laws of the State of Georgia in 1913, and its predecessor company dates back to 1899. As used herein, the terms Equifax, the Company, we, our and us refer to Equifax Inc., a Georgia corporation, and its consolidated subsidiaries as a combined entity, except where it is clear that the terms mean only Equifax Inc.

We are organized and report our business results in four operating segments, as follows:

•U.S. Information Solutions (USIS) — provides consumer and commercial information solutions to businesses in the U.S. including online information, decisioning technology solutions, fraud and identity management services, portfolio management services, mortgage reporting and financial marketing services.
•International —which includes our Asia Pacific, Europe, Canada and Latin America business units, provides products and services similar to those available in the USIS operating segment but with variations by geographic region. We also provide information, technology and services to support debt collections and recovery management.
•Workforce Solutions — provides services enabling clients to verify income and employment (Verification Services) as well as to outsource and automate the performance of certain payroll-related and human resource management business processes, including unemployment cost management, tax credits and incentives and I-9 management services and services to allow employers to ensure compliance with the Affordable Care Act (Employer Services).
•Global Consumer Solutions — provides products to consumers in the United States, Canada, and the U.K., enabling them to understand and monitor their credit and monitor and help protect their identity. We also sell consumer and credit information to resellers who combine our information with other information to provide direct to consumer monitoring, reports and scores.

2017 Cybersecurity Incident

Background. In fiscal 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers. Criminals exploited a U.S. website application vulnerability to gain unauthorized access to our network. Based on our forensic investigation, the unauthorized access of information occurred from mid-May through July 2017. The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. In addition, credit card numbers for approximately 209,000 U.S. and Canadian consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed. The investigation determined that personal information

of approximately 19,000 Canadian consumers was impacted and approximately 860,000 potentially affected U.K. consumers were contacted regarding access to personal information. The forensic investigation of the cybersecurity incident was, as previously disclosed, completed in the fourth quarter of fiscal 2017. No evidence was found that the Company's core consumer, employment and income, or commercial credit reporting databases were accessed.

The Company acted promptly to notify the approximately 145.5 million U.S. consumers whose personally identifiable information the Company had identified in 2017 as potentially accessed. As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify approximately 2.4 million U.S. consumers whose name and partial driver’s license information were stolen, but who were not in the affected population of approximately 145.5 million consumers previously identified by the Company in 2017. The Company is in the process of notifying these additional consumers.

As a result of the 2017 cybersecurity incident, we are party to numerous lawsuits and governmental investigations. See Item 1A. Risk Factors and Item 3. Legal Proceedings for more information regarding these lawsuits and investigations. We continue to cooperate with law enforcement in connection with the criminal investigation into the actors responsible for the cybersecurity incident.

Regaining Trust. The Company has taken and continues to take extensive steps designed to prevent this type of incident from happening again and to earn back the trust of consumers, customers and regulators.

Upon discovery of the unauthorized access, we acted immediately to stop the intrusion and promptly engaged a leading, independent cybersecurity firm to conduct a comprehensive forensic investigation to determine the scope of the intrusion, including the specific data potentially impacted. We have continued to analyze the data impacted, including through the use of external data providers, to identify and inform consumers who may have been impacted by this incident.

Following the cybersecurity incident, we began undertaking significant steps to enhance our data security infrastructure. In connection with these efforts, we have incurred significant costs and expect to incur additional significant costs as we take further steps to prevent unauthorized access to our systems and the data we maintain. The actions we have taken are based on our investigation of the causes of the cybersecurity incident, but there will be additional changes needed to prevent a similar incident. We have also enhanced our disclosure controls and procedures and related protocols to specifically provide that cyber incidents are promptly escalated and investigated and reported to senior management, and where appropriate, to the Board of Directors. We also engaged an independent outside consulting firm to help us with both strategic remediation activities and to review our cybersecurity framework, our controls framework and our management and employees' roles and responsibilities.

In the third and fourth quarters of 2017, our Board made strategic changes to our executive leadership

Showing the first 8K of 65K characters. Open the full section

Item 1A. RISK FACTORS

All of the risks and uncertainties described below and the other information included in this Form 10-K should be considered and read carefully. The risks described below are not the only ones facing us. The occurrence of any of the following risks or additional risks and uncertainties not presently known to us or that we currently believe to be immaterial could materially and adversely affect our business, financial condition or results of operations. This Form 10-K also contains forward-looking statements and estimates that involve risks and uncertainties. Our actual results could differ materially from those anticipated in the forward-looking statements as a result of specific factors, including the risks and uncertainties described below.

Security breaches like the cybersecurity incident announced in September 2017 and other disruptions to our information technology infrastructure could compromise Company, consumer and customer information, interfere with our operations, cause us to incur significant costs for remediation and enhancement of our IT systems and expose us to legal liability, all of which could have a substantial negative impact on our business and reputation.

In the ordinary course of business, we collect, process, transmit and store sensitive data, including intellectual property, proprietary business information and personally identifiable information of consumers. The secure operation of our information technology networks and systems, and of the processing and maintenance of this information, is critical to our business operations and strategy. Despite our substantial investment in physical and technological security measures, employee training and contractual precautions, our information technology networks and infrastructure (or those of our third-party vendors and other service providers) are vulnerable to unauthorized access to data or breaches of confidential information due to criminal conduct, attacks by hackers, employee or insider malfeasance and/or human error.

In 2017, we were the target of a cybersecurity attack that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers. As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify approximately 2.4 million U.S. consumers whose name and partial driver's license information were stolen, but who were not in the affected population of approximately 145.5 million consumers previously identified by the Company in 2017. The Company is in the process of notifying these additional consumers. It is possible that further analysis will identify additional consumers affected or additional types of data accessed, which could result in additional notifications and negative publicity.

Following the cybersecurity incident, we began undertaking significant remediation efforts and other steps to enhance our data security infrastructure. In connection with these efforts, we have incurred significant costs and expect to incur additional significant costs as we take further steps to prevent unauthorized access to our systems and the data we maintain. The actions we have taken are based on our investigation of the causes of the cybersecurity incident, but there will be additional changes needed to prevent a similar incident. We cannot assure that all potential causes of the incident have been identified and remediated and will not occur again.

Because our products and services involve the storage and transmission of personal information of consumers, we will continue to routinely be the target of attempted cyber and other security threats by outside third parties, including technically sophisticated and well-resourced bad actors attempting to access or steal the data we store. Insider or employee cyber and security threats are also a significant concern for all companies, including ours. In addition, the 2017 cybersecurity incident may embolden individuals or groups to target our systems. We must continuously monitor and develop our information technology networks and infrastructure to prevent, detect, address and mitigate the risk of unauthorized access, misuse, computer viruses and other events that could have a security impact. If we experience additional breaches of our security measures, including from incidents that we fail to detect for a period of time, sensitive data may be accessed, stolen, disclosed or lost. Any such access, disclosure or other loss of information could subject us to significant additional litigation, regulatory fines, penalties, losses of customers or reputational damage, any of which could have a significant negative impact on our cash flows, competitive position, financial condition or results of operations. We expect our insurance coverage will not be adequate to compensate us for all losses that may occur due to the 2017 cybersecurity incident and we cannot ensure that our insurance policies in the future will be adequate to cover losses from any future failures. In addition, our third-party insurance coverage will vary from time to time in both type and amount depending on availability, cost and our decisions with respect to risk retention.

The government investigations and litigation resulting from the 2017 cybersecurity incident will continue to adversely impact our business and results of operations.

As a result of the 2017 cybersecurity incident, we are currently a party to a consolidated multi-district consumer class action lawsuit and a consolidated multi-district financial institution class action lawsuit, as well as securities class action lawsuits, shareholder derivative litigation and other lawsuits and claims allegedly arising out of the cybersecurity incident seeking monetary damages or other relief. A number of U.S. federal, state, local and foreign governmental officials and agencies, including Congressional committees, the FTC, the CFPB, the SEC, the U.S. Department of Justice and state attorneys general offices in the U.S., the FCA in the U.K. and the Office of the Privacy Commissioner in Canada, continue to investigate events related to the 2017 cybersecurity incident, including how it occurred, the consequences thereof and our response thereto. Additional lawsuits, investigations and reports related to the 2017 cybersecurity incident may be filed, commenced or issued. The claims and investigations have resulted in the incurrence of significant external and internal legal costs and expenses and reputational damage to our business and are expected to continue throughout 2018 and beyond. The resolution of these matters may result in damages, costs, fines or penalties substantially in excess of our insurance coverage, which, depending on the amount, could have a material adverse effect on our liquidity or compliance with our credit agreements. If such damages, costs,

fines or penalties were great enough that we could not pay them through funds generated from operating activities and/or cause a default under our revolving credit facility, we may be forced to renegotiate or obtain a waiver under our revolving credit facility and/or seek additional debt or equity financing. Such renegotiation or financing may not be available on acceptable terms, or at all. In these circumstances, if we were unable to obtain sufficient financing, we may not be able to meet our obligations as they come due. The outcome of such claims and investigations could also adversely affect or cause us to change how we operate our business. The governmental agencies investigating the cybersecurity incident may seek to impose injunctive relief, consent decrees, or other civil or criminal penalties, which could, among other things, impact our ability to collect and use consumer information, materially increase our data security costs and/or otherwise require us to alter how we operate our business. Any legislative or regulatory changes adopted in reaction to the cybersecurity incident or other companies’ data breaches could require us to make modifications to the operation of our business that could have an adverse effect and/or increase or accelerate our compliance costs. Furthermore, these matters necessitate significant attention by management, which may divert the focus of management from the operation of our business resulting in an adverse impact on our results of operations.

The cybersecurity incident and the adverse publicity that followed have had a negative impact on our reputation, and we cannot assure it will not have a long-term effect on our relationships with our customers, our revenue and our business.

Our revenue growth in 2017 as compared to 2016 was negatively impacted by the cybersecurity incident. Certain of our customers have determined to defer or cancel new contracts or projects and others could consider such actions unless and until we can provide assurances regarding our ability to prevent unauthorized access to our systems and the data we maintain. Many of our customers are requiring security audits of our systems and any negative results of such audits may cause further losses of customers. In addition, some of our current and potential customers and the contracts governing certain customer relationships, as well as certain of our data suppliers, require us to maintain International Organization for Standardization (“ISO”) certifications, such as ISO 27001 certification, that specify requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented information security management system. Due to the 2017 cybersecurity incident, certain of our ISO certifications have been suspended and we will be required to take additional remediation steps to retain such certifications, which efforts may not be successful. Additionally, certain of our payment card industry certifications have been suspended which could result in fines and loss of access to data if we are not able to complete the necessary remediation steps to retain these certifications, which would adversely affect our ability to offer certain products to customers. If we are unable to demonstrate the security of our systems and the data we maintain and rebuild the trust of our customers, consumers and data suppliers, and if further negative publicity continues, we could experience a substantial negative impact on our business.

The loss of access to credit, employment, financial and other data from external sources could harm our ability to provide our products and services.

We rely extensively upon data from external sources to maintain our proprietary and non-proprietary databases, including data received from customers, strategic partners and various government and public record sources. This data includes the widespread and voluntary contribution of credit data from most lenders in the U.S and many other markets as well as the contribution of data under proprietary contractual agreements, such as employers’ contribution of employment and income data to The Work Number, financial institutions’ contribution of individual financial data to IXI, and telecommunications, cable and utility companies’ contribution of payment and fraud data to the National Cable, Telecommunications and Utility Exchange. For a variety of reasons, including concerns of data furnishers arising out of the 2017 cybersecurity incident, legislatively or judicially imposed restrictions on use, additional security breaches or competitive reasons, our data sources could withdraw, delay receipt of or increase the cost of their data provided to us. Where we currently have exclusive use of data, the providers of the data sources could elect to make the information available to competitors. We also compete with several of our third-party data suppliers. If a substantial number of data sources or certain key data sources were to withdraw or be unable to provide their data, if we were to lose access to data due to government regulation, if we lose exclusive right to the use of data, or if the collection, disclosure or use of data becomes uneconomical, our ability to provide products and services to our clients could have a significant negative impact, which could result in decreased revenue, net income and earnings per share and reputational loss. There can be no assurance that we would be able to obtain data from alternative sources if our current sources become unavailable.

Negative changes in general economic conditions, including interest rates, unemployment rates, income, home prices, investment values and consumer confidence, could adversely affect us.

Our customers, and therefore our business and revenues, are sensitive to negative changes in general economic conditions, including the demand and availability of affordable credit and capital, the level and volatility of interest rates, inflation, employment levels, consumer confidence and housing demand, both inside and outside the U.S. Business customers

use our credit information and related analytical services and data to process applications for new credit cards, automobile loans, home and equity loans and other consumer loans, and to manage their existing credit relationships. Demand for our services tends to be correlated to general levels of economic activity and to consumer credit activity. Bank and other lenders’ willingness to extend credit is adversely affected by elevated consumer delinquency and loan losses in a weak economy. Consumer demand for credit (i.e., rates of spending and levels of indebtedness) also tends to grow more slowly or decline during periods of economic contraction or slow economic growth.

Our customer base suffers when financial markets experience volatility, illiquidity and disruption, which has occurred in the past and which could reoccur, and the potential for increased and continuing disruptions going forward presents considerable risks to our business and revenue. High or rising rates of unemployment and interest, declines in income, home prices or investment values, lower consumer confidence and reduced access to credit adversely affect demand for our products and services, and consequently our revenue and results of operations, as consumers may postpone or reduce their spending and use of credit, and lenders may reduce the amount of credit offered or available.

Our markets are highly competitive and new product introductions and pricing strategies being offered by our competitors could decrease our sales and market share or require us to enhance our products and services or reduce our prices in a manner that reduces our operating margins.

We operate in a number of geographic, product and service markets that are highly competitive. Competitors may develop products and services that are superior to or that achieve greater market acceptance than our products and services. The size of our competitors varies across market segments, as do the resources we have allocated to the segments we target. Therefore, some of our competitors may have significantly greater financial, technical, marketing or other resources than we do in one or more of our market segments, or overall. As a result, our competitors may be in a position to respond more quickly than we can to new or emerging technologies and changes in customer requirements, or may devote greater resources than we can to the development, enhancement, promotion, sale and support of products and services, or some of our customers may develop products of their own that replace the products they currently purchase from us, which would result in lower revenue. In addition, many of our competitors have extensive consumer relationships, including relationships with our current and potential customers. Moreover, new competitors or alliances among our competitors may emerge and potentially reduce our market share, revenue or margins.

We also sell our information to competing firms, and buy information from certain of our competitors, in order to sell “tri-bureau” and other products, most notably into the U.S. mortgage market. Changes in prices between competitors for this information and/or changes in the design or sale of tri-bureau versus single bureau product offerings may affect our revenue or profitability.

Some of our competitors may choose to sell products that compete with ours at lower prices by accepting lower margins and profitability, or may be able to sell products competitive to ours at lower prices, individually or as a part of integrated suites, given proprietary ownership of data, technological superiority or economies of scale. Price reductions by our competitors could negatively impact our margins and results of operations and could also harm our ability to obtain new customers on favorable terms. Historically, certain of our key products have experienced declines in per unit pricing due to competitive factors and customer demand. Since a significant portion of our operating expenses is relatively fixed in nature due to sales, information technology and development and other costs, if we were unable to respond quickly enough to changes in competition or customer demand, we could experience further reductions in our operating margins.

Our relationships with key long-term customers may be materially diminished or terminated

We have long-standing relationships with a number of our customers, many of whom could unilaterally terminate their relationship with us or materially reduce the amount of business they conduct with us at any time. Many of our material customer agreements can be terminated by the customer for convenience on advance written notice, which provides our customers with the opportunity to renegotiate their contracts with us or to award more business to our competitors.

We also provide our services to business partners who may combine them with their own or other branded services to be offered as a bundle to consumers, governmental agencies and businesses in support of fraud or credit protection, credit monitoring, identity authentication, insurance or credit underwriting, and collections. Some of these partners are the largest providers of credit information or identity protection services to the consumer market.

Market competition, business requirements, financial condition and consolidation through mergers or acquisitions, could adversely affect our ability to continue or expand our relationships with our customers and business partners. There is no guarantee that we will be able to retain or renew existing agreements, maintain relationships with any of our customers or

business partners on acceptable terms or at all, or collect amounts owed to us from insolvent customers or business partners. The loss of one or more of our major customers or business partners could adversely affect our business, financial condition and results of operations.

If we do not introduce successful new products, services and analytical capabilities in a timely manner, or if the market does not adopt our new services, our competitiveness and operating results will suffer.

We generally sell our products in industries that are characterized by rapid technological changes, frequent new product and service introductions and changing industry standards. In addition, certain of the markets in which we operate are seasonal and cyclical. Without the timely introduction of new products, services and enhancements, our products and services will become technologically or commercially obsolete over time, in which case our revenue and operating results would suffer. The success of our new products and services will depend on several factors, including our ability to properly identify customer needs; innovate and develop new technologies, services and applications; successfully commercialize new technologies in a timely manner; produce and deliver our products in sufficient volumes on time; differentiate our offerings from competitor offerings; price our products competitively; anticipate our competitors’ development of new products, services or technological innovations; and control product quality in our product development process. Our resources have to be committed to any new products and services before knowing whether the market will adopt the new offerings. In addition, our management is and will continue to be intensely focused on enhancing our security measures and responding to consumer and customer concerns relating to the 2017 cybersecurity incident and may not be able to devote sufficient time to new product development, which could cause us to be less competitive as compared to our peers, lose out on new revenue opportunities and have an adverse effect on our growth and our business.

The demand for some of our products and services may be negatively impacted to the extent the availability of free or less expensive consumer information increases.

Public or commercial sources of free or relatively inexpensive consumer credit, credit score and other information have become increasingly available, particularly through the internet, and this trend is expected to continue. In addition, governmental agencies in particular have increased the amount of information to which they provide free public access and these or other sources of free or relatively inexpensive consumer information from competitors or other commercial sources may reduce demand for our services, particularly in our USIS and Global Consumer Solutions business units. Recently, there also has been an increase in companies offering free or low-cost direct to consumer credit services (such as credit scores, reports and monitoring) as part of alternative business models that use such services as a means to introduce consumers to other products and services. To the extent that our customers choose not to obtain services from us and instead rely on information obtained at no cost or relatively inexpensively from these other sources, our business, financial condition and results of operations may be adversely affected.

Due to the 2017 cybersecurity incident and our provision of free services to consumers in connection therewith, we ceased the advertisement and sale of new products in our direct to consumer business, which resulted in a significant decline in revenue in that business. Furthermore, in late January 2018, we began offering a new credit lock service, Lock & AlertTM, that is free for life and is aimed at empowering consumers to control access to their Equifax credit file directly and quickly from their smartphone or computer. We expect services like our Lock & AlertTM to continue to increase, thereby eliminating the market for many consumer direct products and services. As a result of these factors, we expect that revenue from our direct to consumer business will continue to decline. Additionally, if a significant number of consumers lock or freeze their file, our population of data is reduced which could affect our product offerings and value to our customers in our other businesses.

If we experience system constraints or failures, or our customers do not modify and/or upgrade their systems to accept new releases of our products and services, our services to our customers could be delayed or interrupted, which could result in lost revenues or customers, lower margins, or other harm to our business and reputation.

We depend on reliable, stable, efficient and uninterrupted operation of our technology network, systems, and data centers to provide service to our customers. Many of the services and systems upon which we rely have been outsourced to third parties. In addition, many of our revenue streams are dependent on links to third party telecommunications providers. These systems and operations, and the personnel that support, service and operate these systems, could be exposed to interruption, damage or destruction from power loss, telecommunication failures, computer viruses, denial-of-service attacks, employee or insider malfeasance, human error, fire, natural disasters, war, terrorist acts or civil unrest. We may not have sufficient disaster recovery or redundant operations in place to cover a loss or failure of systems or telecommunications links in a timely manner. In addition, we will continue to be intensely focused on enhancing our data security infrastructure and implementation of those enhancements could result in service interruptions. Any significant delay or interruption could result in lost revenues or customers, lower margins, or other significant harm to our business or reputation.

We and our customers are subject to various current laws and governmental regulations, and could be affected by new laws or regulations, including as a result of the 2017 cybersecurity incident, compliance with which may cause us to incur significant expenses and change our business practices, and if we fail to maintain satisfactory compliance with certain regulations, we could be subject to civil or criminal penalties.

We are subject to a number of U.S. federal, state, local and foreign laws and regulations relating to consumer privacy, data and financial protection. See Item 1. Business - "Governmental Regulation" in this Form 10-K for a summary of the U.S. and foreign consumer and data protection laws and regulations to which we are subject. These regulations are complex, change frequently, have tended to become more stringent over time, and are subject to administrative interpretation and judicial construction in ways that could harm our business. Furthermore, we expect there to be an increased focus on laws and regulations related to our business because of the great public concern in the U.S. with regard to the operation of credit reporting agencies, as well as the collection, use, accuracy, correction and sharing of personal information, which was heightened by the 2017 cybersecurity incident. For example, there are a number of legislative proposals pending before the U.S. Congress, various state legislative bodies and foreign governments concerning data protection due to our 2017 cybersecurity incident and other high-profile breaches that could affect us and the President of the United States could act by Executive Order. In addition, a growing number of legislative and regulatory bodies have adopted consumer notification and other requirements in the event that consumer information is accessed by unauthorized persons and additional regulations regarding the use, access, accuracy and security of such data are possible. In the U.S., state laws provide for disparate notification regimes, all of which we are subject to. Further, any perception that our practices or products are an invasion of privacy, whether or not consistent with current or future regulations and industry practices, may subject us to public criticism, private class actions, reputational harm, or claims by regulators, which could disrupt our business and expose us to increased liability.

We devote substantial compliance, legal and operational business resources to facilitate compliance with applicable regulations and requirements. In the future, we may be subject to significant additional expense to ensure continued compliance with applicable laws and regulations and to investigate, defend or remedy actual or alleged violations. Additionally, we cooperate with CFPB supervisory examinations and respond to other state, federal and foreign government investigations of our business practices. Any failure by us to comply with, or remedy any violations of, applicable laws and regulations could result in the curtailment of certain of our operations, the imposition of fines and penalties, liability to private plaintiffs as a result of individual or class action litigation, restrictions on our ability to carry on or expand our operations, and reputational harm. In addition, because many of our products are regulated or sold to customers in various industries, we must comply with additional regulations in marketing our products. Moreover, our compliance with privacy laws and regulations and our reputation depend in part on customers' adherence to privacy laws and regulations and their use of our services in ways consistent with consumer expectations and regulatory requirements. We cannot predict the ultimate impact on our business of new or proposed CFPB, FCA or other rules, supervisory examinations or government investigations or enforcement actions.

The following legal and regulatory developments also could have a substantial negative impact on our business, financial condition or results of operations:

•amendment, enactment or interpretation of laws and regulations that restrict the access and use of personal information and reduce the availability or effectiveness of our solutions or the supply of data available to customers;
•changes in cultural and consumer attitudes in favor of further restrictions on information collection and sharing, which may lead to regulations that prevent full utilization of our solutions;
•failure of data suppliers or customers to comply with laws or regulations, where mutual compliance is required;
•failure of our solutions to comply with current laws and regulations; and
•failure of our solutions to adapt to changes in the regulatory environment in an efficient, cost effective manner.

For example, Ecuador passed a law in December 2017 that, if implemented, would effectively prohibit us from operating as a credit bureau within Ecuador unless we are selected to operate under contract to serve the public authority that the new law tasks with providing such services. These laws and regulations (as well as actions that may be taken by legislatures and regulatory bodies in other countries) and the consequences of any violation could limit our ability to pursue business opportunities we might otherwise consider engaging in, impose additional costs on us, result in significant loss of revenue, result in significant restitution and fines, impact the value of assets we hold, or otherwise adversely affect our business. See “Item 1. Business - Governmental Regulation” and “Item 3. Legal Proceedings” in this Form 10-K.

Regulatory oversight of our contractual relationships with certain of our customers may adversely affect our business.

The federal banking agencies, including the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the Board of Governors of the Federal Reserve System and the CFPB, as well as many state banking agencies

have issued guidance to insured depository institutions and other providers of financial services on assessing and managing risks associated with third-party relationships, which include all business arrangements between a financial services provider and another entity, by contract or otherwise, and generally requires banks and financial services providers to exercise comprehensive oversight throughout each phase of a bank or financial service provider’s business arrangement with third-party service providers, and instructs banks and financial service providers to adopt risk management processes commensurate with the level of risk and complexity of their third-party relationships. This guidance requires more rigorous oversight of third-party relationships that involve certain “critical activities.” In light of this guidance, our existing or potential bank and financial services customers subject to this guidance may continue to revise their third-party risk management policies and processes and the terms on which they do business with us, which may adversely affect our relationship with such customers. In response to the 2017 cybersecurity incident, we also have been contacted by state banking regulators seeking to examine our practices as a third-party service provider to the entities that they regulate. It is possible that these or similar examinations by federal or state banking regulators could lead to adverse changes in our customer relationships.

Economic, political and other risks associated with international sales and operations could adversely affect our results of operations.

Sales outside the U.S. comprised 29% of our operating revenue in 2017. As a result, our business is subject to various risks associated with doing business internationally. In addition, many of our employees, suppliers, job functions and facilities are located outside the U.S. Accordingly, our future results could be harmed by a variety of factors including:

•changes in specific country or region political, economic or other conditions;
•trade protection measures;
•data privacy and consumer protection regulations;
•difficulty in staffing and managing widespread operations;
•differing labor, intellectual property protection and technology standards and regulations;
•business licensing requirements or other requirements relating to making foreign direct investments, which could increase our cost of doing business in certain jurisdictions, prevent us from entering certain markets, increase our operating costs or lead to penalties or restrictions;
•difficulties associated with repatriating cash generated or held abroad in a tax-efficient manner;
•implementation of exchange controls;
•geopolitical instability, including terrorism and war;
•foreign currency changes;
•increased travel, infrastructure, legal and compliance costs of multiple international locations;
•foreign laws and regulatory requirements;
•terrorist activity, natural disasters and other catastrophic events;
•restrictions on the import and export of technologies;
•difficulties in enforcing contracts and collecting accounts receivable;
•longer payment cycles;
•failure to meet quality standards for outsourced work;
•unfavorable tax rules;
•the presence and acceptance of varying level of business corruption in international markets; and
•varying business practices in foreign countries

We earn revenue, pay expenses, own assets and incur liabilities in countries using currencies other than the U.S. dollar, including among others the British pound, the Australian dollar, the Canadian dollar, the Argentine peso, the Chilean peso, the Euro, the New Zealand dollar, the Costa Rican colon, the Singapore dollar, the Brazilian real, the Russian ruble and the Indian rupee. Because our consolidated financial statements are presented in U.S. dollars, we must translate revenue, income and expenses, as well as assets and liabilities, into U.S. dollars at exchange rates in effect during or at the end of each reporting period. Therefore, increases or decreases in the value of the U.S. dollar against major currencies will affect our operating revenues, operating income and the value of balance sheet items denominated in foreign currencies. In 2017, a general weakening of foreign currencies in countries where we have operations against the U.S. dollar had a negative impact on our results as reported in U.S. dollars. See “Segment Financial Results - International - Asia Pacific,” “ - Europe,” “ -Latin America,” and “- Canada” and “Effects of Inflation and Changes in Foreign Currency Exchange Rates” in the Management’s Discussion and Analysis section of this Form 10-K. Because of the geographic diversity of our operations, weaknesses in some currencies might be offset by strengths in others over time. We generally do not mitigate the risks associated with fluctuating exchange rates, although we may from time to time through forward contracts or other derivative instruments hedge a portion of our translational foreign currency exposure or exchange rate risks associated with material transactions which are denominated in a foreign currency. The use of such hedging activities may not offset any or more than a portion of the adverse financial effects of unfavorable movements in foreign exchange rates over the limited time the hedges are in place.

Accordingly, fluctuations in foreign currency exchange rates, particularly the strengthening of the U.S. dollar against major currencies, may materially affect our consolidated financial results.

We also have a cost method investment in a credit information company in Brazil valued in Brazilian reais. Economic and competition risks within Brazil, and the company’s ability to successfully implement its strategic and operating plans, have had an adverse financial impact on the value of our investment and could result in an additional impairment of the investment.

Compliance with applicable U.S. and foreign laws and regulations, such as anti-corruption laws, tax laws, foreign exchange controls and restrictions on repatriation of earnings or other similar restraints, data privacy requirements, labor laws and anti-competition relations increases the cost of doing business in foreign jurisdictions. Although we have implemented policies and procedures to comply with these laws and regulations, a violation by our employees, contractors or agents could nevertheless occur.

We are regularly involved in claims, suits, government investigations, supervisory examinations and other proceedings that may result in adverse outcomes.

In addition to what we are currently experiencing due to the 2017 cybersecurity incident, we are regularly involved in claims, suits, government investigations, supervisory examinations and regulatory proceedings arising from the ordinary course of our business, including actions with respect to consumer protection and data protection, including purported class action lawsuits. Such claims, suits, government investigations and proceedings are inherently uncertain and their results cannot be predicted with certainty. Regardless of their outcome, such legal proceedings can have an adverse impact on us because of legal costs, diversion of management and other personnel, and other factors. In addition, it is possible that a resolution of one or more such proceedings could result in reputational harm, liability, penalties, or sanctions, as well as judgments, consent decrees, or orders preventing us from offering certain features, functionalities, products, or services, or requiring a change in our business practices, products or technologies, which could in the future materially and adversely affect our business, operating results, and financial condition. The FCRA contains an attorney fee shifting provision to provide an incentive for consumers to bring individual and class action lawsuits against a CRA for violation of the FCRA, and the number of consumer lawsuits (both individual and class action) against us alleging a violation of FCRA and our resulting costs associated with resolving these lawsuits have increased substantially over the past several years.

We rely, in part, on acquisitions, joint ventures and other alliances to grow our business and expand our geographic reach. The acquisition, integration or divestiture of businesses by us may not produce the expected financial, operating results or IT and data security profile we expect. In addition, if we are unable to make acquisitions or successfully develop and maintain joint ventures and other alliances, our growth may be adversely impacted.

Historically, we have relied, in part, on acquisitions, joint ventures and other alliances to grow our business. Over the past several years, we have acquired many smaller businesses in the U.S. and across the world. Furthermore, during 2016, we acquired Veda, the leading provider of credit information and analysis in Australia and New Zealand, for cash consideration plus debt assumed of approximately $1.9 billion. In January 2014, we acquired TDX, a debt placement service and debt management platform company in the United Kingdom for approximately $323 million. Acquisitions may not be completed on favorable terms, and the expected benefits, synergies and growth from these initiatives may not materialize as planned. We may have difficulty assimilating new businesses and their products, services, technologies, IT systems and personnel into our operations. IT and data security profiles of acquired companies may not meet the Equifax standard and may take longer to integrate and remediate than planned. This may result in significantly greater transaction costs for future acquisitions than we have experienced historically, or it could mean that we will not pursue certain acquisitions where the costs of integration and remediation are too significant. We may also have difficulty integrating and operating businesses in countries and geographies where we do not currently have a significant presence, and acquisitions of businesses having a significant presence outside of the U.S. will increase our exposure to risks of conducting operations in international markets. Similarly, any divestitures will be accompanied by risks commonly encountered in the sale of businesses. These difficulties could disrupt our ongoing business, distract our management and workforce, increase our expenses and adversely affect our operating results and financial condition.

Despite our past experience, opportunities to grow our business through acquisitions, joint ventures and other alliances may not be available to us in the future. In addition, as a result of the 2017 cybersecurity incident and the resources and management attention required in connection therewith, there may be more limited resources available for acquisitions and management’s attention is likely to be diverted away from sourcing and developing potential acquisition and joint venture opportunities, resulting in decreased growth.

Dependence on outsourcing certain portions of our operations may adversely affect our ability to bring products to market and damage our reputation. Dependence on outsourced information technology and other administrative functions may impair our ability to operate effectively.

As part of our efforts to streamline operations and to reduce operating costs, we have outsourced various components of our application development, information technology, operational support and administrative functions and will continue to evaluate additional outsourcing. Although we have implemented service level agreements and have established monitoring controls, if our outsourcing vendors fail to perform their obligations in a timely manner or at satisfactory quality levels including with respect to data and system security, or increase prices for their services to unreasonable levels, our ability to bring products to market and support our customers, and our reputation could suffer. Any failure to perform on the part of these third-party providers could impair our ability to operate effectively and could result in lower future revenue, unrealized efficiencies and adversely impact our results of operations and our financial condition. Much of our outsourcing takes place in developing countries and, as a result, may be subject to geopolitical uncertainty.

Changes in income tax laws can significantly impact our net income.

Federal and state governments in the U.S. as well as a number of other governments around the world are currently facing significant fiscal pressures and have considered or may consider changes to their tax laws for revenue raising or economic competitiveness reasons. Changes to tax laws can have immediate impacts, either favorable or unfavorable, on our results of operations and cash flows, and may impact our competitive position versus certain competitors who are domiciled in other jurisdictions and subject to different tax laws. In December 2017, the U.S. enacted the Tax Cuts and Jobs Act of 2017 which will significantly impact our U.S. and global tax expense. The application of many provisions in the Tax Cuts and Jobs Act of 2017 are uncertain at this time. The impact on Equifax will not be fully known until further guidance is provided by the U.S. Treasury.

If our government contracts are terminated, if we are suspended from government work, or if our ability to compete for new contracts is adversely affected, our business could suffer.

We derive a portion of our revenue from direct and indirect sales to U.S., state, local and foreign governments and their respective agencies. Such contracts are subject to various procurement laws and regulations, and contract provisions relating to their formation, administration and performance. Failure to comply with these laws, regulations or provisions in our government contracts could result in the imposition of various civil and criminal penalties, termination of contracts, forfeiture of profits, suspension of payments, or suspension of future government contracting. Following the 2017 cybersecurity incident, our government contracts received enhanced scrutiny and negative media attention that resulted in the suspension of one of our contracts. If we are unable to repair the reputational damage cause by the 2017 cybersecurity incident and ensure the security of the data we maintain, our ability to maintain our existing and acquire new government contracts may be substantially impacted.

Also, the government programs to which we provide services, or which are the basis of compliance services we provide non-governmental clients, including, in particular, the employer requirements under the Affordable Care Act, may be terminated or substantially altered by the government and our services would no longer be needed. If our government contracts are terminated, if we are suspended from government work, if the services we provide are no longer needed due to government program change or termination, or if our ability to compete for new contracts is adversely affected, our business could suffer.

Third parties may claim that we are infringing on their intellectual property and we could suffer significant litigation or licensing expenses or be prevented from selling products or services.

There has been substantial litigation in the U.S. regarding intellectual property rights in the information technology industry. From time to time, third parties may claim that one or more of our products or services infringe their intellectual property rights. We analyze and take action in response to such claims on a case by case basis. Any dispute or litigation regarding patents or other intellectual property could be costly and time-consuming due to the complexity of our technology and the uncertainty of intellectual property litigation, could divert our management and key personnel from our business operations and we may not prevail. A claim of intellectual property infringement could force us to enter into a costly or restrictive license agreement, which might not be available under acceptable terms or at all, or could subject us to significant damages or to an injunction against development and sale of certain of our products or services. Our intellectual property portfolio may not be useful in asserting a counterclaim, or negotiating a license, in response to a claim of intellectual property infringement. In certain of our businesses we rely on third-party intellectual property licenses and we cannot ensure that these licenses will be available to us in the future on favorable terms or at all. Although our policy is to obtain licenses or other rights where necessary, we cannot provide assurance that we have obtained all required licenses or rights.

Third parties may misappropriate or infringe on our intellectual property and we may suffer competitive injury or expend significant resources enforcing our rights.

Our success increasingly depends on our proprietary technology. We rely on various intellectual property rights, including patents, copyrights, database rights, trademarks and trade secrets, as well as contract restrictions, confidentiality provisions and licensing arrangements, to establish our proprietary rights. The extent to which such rights can be protected varies in different jurisdictions. If we do not enforce our intellectual property rights successfully our competitive position may suffer which could harm our operating results. Our pending patent and trademark applications may not be allowed or competitors may challenge the validity or scope of our intellectual property rights. In addition, our patents, copyrights, trademarks and other intellectual property rights may not provide us a significant competitive advantage.

We may need to devote significant resources, including cybersecurity resources, to monitoring our intellectual property rights and we may or may not be able to detect misappropriation or infringement by third parties. Our competitive position may be harmed if we cannot detect misappropriation or infringement and enforce our intellectual property rights quickly or at all. In some circumstances, enforcement may not be available to us because a third party has a dominant intellectual property position or for other business reasons. In addition, competitors might avoid infringement by designing around our intellectual property rights or by developing non-infringing competing technologies. Intellectual property rights and our ability to enforce them may be unavailable or limited in some countries which could make it easier for competitors to capture market share and could result in lost revenue.

The U.K’s impending departure from the EU could adversely affect us.

The referendum on the U.K.’s membership in the EU (referred to as “Brexit”) approving the exit of the U.K. from the EU could cause disruptions to and create uncertainty surrounding our business, including affecting our relationships with our existing and future customers, suppliers and employees, which could have an adverse effect on our business, financial results and operations. While the referendum was non-binding, the U.K. parliament has voted in favor of allowing the government to commence negotiations to determine the future terms of the U.K.’s relationship with the EU, including the terms of trade between the U.K. and the EU and other nations. The effects of Brexit will depend on any agreements the U.K. makes to retain access to EU markets either during a transitional period or more permanently. In addition, developments regarding Brexit may also create global economic uncertainty, which may cause our clients to closely monitor their costs and reduce their spending on our solutions and services.

A downgrade to our credit ratings would increase our cost of borrowing under our credit facility and adversely affect our ability to access the capital markets.

We are party to a $900.0 million unsecured, revolving credit facility that matures in November 2020 and an $800.0 million term loan facility that matures in November 2018 (collectively, the “Senior Credit Facilities”). The cost of borrowing under the Senior Credit Facilities and our ability and the terms under which we may access the credit markets are affected by credit ratings assigned to our indebtedness by the major credit rating agencies. These ratings are premised on our performance under assorted financial metrics, such as leverage and interest coverage ratios and other measures of financial strength, business and financial risk, industry conditions, transparency with rating agencies and timeliness of financial reporting. Our current ratings have served to lower our borrowing costs and facilitate access to a variety of lenders. However, there can be no assurance that our credit ratings or outlook will not be lowered in the future in response to adverse changes in these metrics caused by our operating results or by actions that we take that reduce our profitability or that require us to incur additional indebtedness for items such as substantial cash acquisitions, significant increases in costs and capital spending in security and IT systems, significant costs related to settlements of litigation or regulatory requirements, or by returning excess cash to shareholders through dividends or under our share repurchase program. A downgrade of our credit ratings would increase our cost of borrowing under the Senior Credit Facilities, negatively affect our ability to access the capital markets on advantageous terms, or at all, negatively affect the trading price of our securities and have a significant negative impact on our business, financial condition and results of operations.

We may not be able to borrow under our revolving credit facility and Receivables Facility.

We are party to a $225.0 million, 2-year receivables funding facility ("the "Receivables Facility") as well as the Senior Credit Facilities. Our revolving credit facility and Receivables Facility have representations, covenants, financial covenants and events of default which may limit our ability to borrow under such debt obligations. Any breach of a representation or failure to comply with any covenant or financial covenant or the occurrence of any event of default under the Senior Credit Facilities or the Receivables Facility could result in a prohibition of further borrowings under the revolving credit facility and Receivables

Facility or acceleration of any obligations outstanding thereunder. Any event of default under the Senior Credit Facilities or Receivables Facility could result in a cross default under our other outstanding debt obligations.

Changes in interest rates could adversely affect our cost of capital and net income.

Rising interest rates, credit market dislocations and decisions and actions by credit rating agencies can affect the availability and cost of our funding and adversely affect our net income.

Our business will suffer if we are not able to retain and hire key personnel.

Our future success depends partly on the continued service of our key development, sales, marketing, executive and administrative personnel. Additionally, increased retention risk exists in certain key areas of our operations, such as IT and security, which require specialized skills, such as maintenance of certain legacy computer systems, data security experts and analytical modelers. If we fail to retain and hire a sufficient number of these personnel, we will not be able to maintain or expand our business. Further, as a result of the cybersecurity incident we may suffer increased attrition. We believe our pay levels are competitive within the regions in which we operate. However, there is also intense competition for certain highly technical specialties in geographic areas where we continue to recruit, and it may become more difficult to retain our key employees.

Our retirement and post-retirement pension plans are subject to financial market risks that could adversely affect our future results of operations and cash flows.

We have significant retirement and post retirement pension plan assets and obligations. The performance of the financial markets and interest rates impact our plan expenses and funding obligations. Significant decreases in market interest rates, decreases in the fair value of plan assets and investment losses on plan assets will increase our funding obligations, and adversely impact our results of operations and cash flows.

We are subject to a variety of other general risks and uncertainties inherent in doing business.

In addition to the specific factors discussed above, we are subject to risks that are inherent to doing business. These include growth rates, general economic and political conditions, customer satisfaction with the quality of our services, costs of obtaining insurance, changes in unemployment rates, and other events that can impact revenue and the cost of doing business.

Item 1B. UNRESOLVED STAFF COMMENTS

None.

Item 2. PROPERTIES

Our executive offices are located at 1550 Peachtree Street, N.W., Atlanta, Georgia. Our other properties are geographically distributed to meet sales and operating requirements worldwide. We consider these properties to be both suitable and adequate to meet our current operating requirements. We ordinarily lease office space for conducting our business and are obligated under approximately 80 leases and other rental arrangements for our field locations. We owned 8 office buildings at December 31, 2017, including our executive offices, one campus which houses our Alpharetta, Georgia data center, a building utilized by our Workforce Solutions operations located in St. Louis, Missouri, as well as three buildings utilized by our Latin America operations located in Mexico City, Mexico and Asuncion, Paraguay. We also own 23.5 acres adjacent to the Alpharetta, Georgia data center.

For additional information regarding our obligations under leases, see Note 6 of the Notes to Consolidated Financial Statements in this report. We believe that suitable additional space will be available to accommodate our future needs.

Item 3. LEGAL PROCEEDINGS

Cybersecurity Incident Litigation, Claims and Government Investigations. Following the 2017 cybersecurity incident, hundreds of class actions were filed by consumers against us in federal, state and Canadian courts relating to the cybersecurity incident. The plaintiffs in these cases, who purport to represent various classes of consumers, generally claim to have been harmed by alleged actions and/or omissions by Equifax in connection with the cybersecurity incident and assert a variety of common law and statutory claims seeking monetary damages, injunctive relief and other related relief. In addition, certain class actions have been filed by financial institutions who allege their businesses have been placed at risk due to the cybersecurity incident and generally assert various common law claims such as claims for negligence and breach of contract, as well as, in some cases, statutory claims. The financial institutions class actions seek compensatory damages and other related relief. Furthermore, a lawsuit has been filed by the City of Chicago with respect to the cybersecurity incident alleging violations of state laws and local ordinances governing protection of personal data, consumer fraud and breach notice requirements and business practices. Beginning on December 6, 2017 and pursuant to multiple subsequent orders, the U.S. Judicial Panel on Multidistrict Litigation ordered the consolidation and transfer for pre-trial proceedings with respect to the U.S. cases pending in federal court discussed above to the Northern District of Georgia as the single U.S. District Court for centralized proceedings. Based on this order, consolidated pre-trial hearings with respect to U.S. consumer and financial institution federal class actions related to the cybersecurity incident have begun in the Northern District of Georgia. In addition to these federal court proceedings, four putative class actions arising from the cybersecurity incident have been filed in the Fulton County Superior Court in Georgia. We have also appeared or notified the appropriate parties of representation in the Canadian class actions, but such actions are all at the preliminary stages. In addition, a civil enforcement action has been filed by the Attorney General of Massachusetts and a lawsuit has been filed by the City of San Francisco, each of which are in the initial pre-trial stages. We dispute the allegations in the complaints described above and intend to defend against such claims.

In addition, we continue to cooperate with federal, state, city and foreign governmental agencies and officials investigating or otherwise seeking information and/or documents, including through Civil Investigative Demands, regarding the cybersecurity incident and related matters, including 49 state Attorneys General offices, as well as the District of Columbia, the Federal Trade Commission, the Consumer Finance Protection Bureau, the U.S. Securities and Exchange Commission (“SEC”), the U.S. Department of Justice, the New York Department of Financial Services, the New York Department of State - Division of Consumer Protection, other U.S. state regulators, including state banking regulators, the Financial Industry Regulatory Authority, certain Congressional committees of both the U.S. Senate and House of Representatives, the United Kingdom’s Financial Conduct Authority (“FCA”), the Information Commissioner’s Office in the United Kingdom and the Office of the Privacy Commissioner of Canada. Although we are actively cooperating with these investigations and inquiries, an adverse outcome to any such investigations and inquiries could subject us to fines or other obligations, which may have an adverse effect on how we operate our business or our results of operations. In addition, we continue to cooperate with the SEC and the U.S. Attorney’s Office for the Northern District of Georgia regarding investigations into the trading activities by certain of our employees in relation to the cybersecurity incident.

TransUnion Litigation. On November 27, 2017, Trans Union LLC and TransUnion Interactive, Inc. (collectively, “TransUnion”) filed a lawsuit in the U.S. District Court for the Northern District of Illinois against Equifax Information Services LLC, Equifax Inc., and Equifax Consumer Services LLC f/k/a Equifax Consumer Services, Inc. In its lawsuit, TransUnion asserts claims for declaratory relief, breach of contract, and anticipatory repudiation of contract based on our Reciprocal Data Supply Agreement (the “Agreement”), which sets forth the pricing terms for credit monitoring supplied by the parties to each other. TransUnion seeks a declaration regarding its contractual rights under the Agreement and monetary damages. On January 26, 2018, we moved to dismiss TransUnion’s claims, and discovery in the case has been stayed until a ruling on that motion is issued. We dispute the allegations by TransUnion and intend to defend against its claims.

Securities Class Action Litigation. A consolidated putative class action lawsuit alleging violations of the federal securities laws in connection with statements regarding our cybersecurity systems and controls is pending against us and certain of our current and former officers and directors in the Northern District of Georgia. The complaints seek certification of a class of all persons who purchased or otherwise acquired Equifax securities during a set period of time and unspecified monetary damages, costs and attorneys’ fees. We dispute the allegations in these complaints and intend to defend against the claims.

Shareholder Derivative Litigation. Four putative shareholder derivative lawsuits have been commenced in the Northern District of Georgia naming certain of our current and former officers and directors as defendants and naming us as a nominal defendant. Among other things, the complaints allege claims for breaches of fiduciary duties, unjust enrichment, corporate waste, and insider selling by certain defendants. Three of the complaints also allege claims for violations of certain federal securities laws. The Complaints seek unspecified damages on behalf of the Company, plus certain equitable relief. Certain plaintiffs have filed motions seeking consolidation of the actions and appointment as lead plaintiffs. We have appointed

a committee of independent directors empowered to evaluate and respond in our best interests to the claims and related litigation demands.

It is not possible at this time to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of the above described proceedings and investigations based on the early stage of these proceedings and investigations, that alleged damages have not been specified, the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues.

Additional lawsuits and claims related to the 2017 cybersecurity incident may be asserted by or on behalf of consumers, customers, shareholders or others seeking damages or other related relief and additional inquiries from governmental agencies may be received or investigations by governmental agencies commenced.

ACCC Investigation. In March 2017, the Australian Competition and Consumer Commission (the “ACCC”) commenced an investigation to determine whether the Company has been or is engaged in unlawful acts or practices relating to advertising, marketing and sale of consumer reports, credit scores or credit monitoring products in violation of the Australian Consumer Law, which prohibits misleading or deceptive conduct and false representations. The ACCC issued a number of notices to produce documents and information. The Company expects that the ACCC will commence proceedings. If this occurs the ACCC may seek restitution, civil monetary penalties, injunctive and declaratory relief or other corrective action. The Company continues to cooperate with the ACCC in its investigation.

California Bankruptcy Litigation. In consolidated actions filed in the U.S. District Court for the Central District of California, captioned Terri N. White, et al. v. Equifax Information Services LLC, Jose Hernandez v. Equifax Information Services LLC, Kathryn L. Pike v. Equifax Information Services LLC, and Jose L. Acosta, Jr., et al. v. Trans Union LLC, et al., plaintiffs asserted that Equifax violated federal and state law (the FCRA, the California Credit Reporting Act and the California Unfair Competition Law) by failing to follow reasonable procedures to determine whether credit accounts are discharged in bankruptcy, including the method for updating the status of an account following a bankruptcy discharge. On August 20, 2008, the District Court approved a Settlement Agreement and Release providing for certain changes in the procedures used by defendants to record discharges in bankruptcy on consumer credit files. That settlement resolved claims for injunctive relief, but not plaintiffs’ claims for damages. On May 7, 2009, the District Court issued an order preliminarily approving an agreement to settle remaining class claims. The District Court subsequently deferred final approval of the settlement and required the settling parties to send a supplemental notice to those class members who filed a claim and objected to the settlement or opted out, with the cost for the re-notice to be deducted from the plaintiffs’ counsel fee award. Mailing of the supplemental notice was completed on February 15, 2011 and the deadline for this group of settling plaintiffs to provide additional documentation to support their damage claims or to opt-out of the settlement was March 31, 2011. On July 15, 2011, the District Court approved the settlement. Several objecting plaintiffs subsequently filed notices of appeal to the U.S. Court of Appeals for the Ninth Circuit, which, on April 22, 2013, issued an order vacating the settlement and remanding the case to the District Court for further proceedings. On January 21, 2014, the District Court denied the objecting plaintiffs’ motion to disqualify counsel for the settling plaintiffs and granted the motion of counsel for the settling plaintiffs to be appointed as interim lead class counsel. On March 28, 2016, the U.S. Court of Appeals for the Ninth Circuit affirmed the District Court’s lead counsel appointment. On January 9, 2017, the United States Supreme Court denied the objectors’ Petition for a Writ of Certiorari. The parties re-engaged in settlement discussions, including participation in mediations in August 2016 and November 2016, and reached an agreement to again settle the monetary claims. Settlement documents were filed with the District Court on April 14, 2017. On June 16, 2017, the Court granted preliminary approval of the proposed settlement, conditionally certified the settlement class, and appointed class counsel and administrator. A Final Fairness Hearing was held on December 11, 2017. Upon issuance of a Final Order by the Court, any appeals will be due within thirty days.

Other. Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest, many of these matters. Given the number of these matters, some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.

For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in this Form 10-K.

Item 4. MINE SAFETY DISCLOSURES

Not applicable.

PART II

Item 5. MARKET FOR THE REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES

Equifax’s common stock is traded on the New York Stock Exchange under the symbol “EFX.” As of January 31, 2018, Equifax had approximately 2,206 holders of record; however, Equifax believes the number of beneficial owners of common stock exceeds this number.

The table below sets forth the high and low sales prices per share of Equifax common stock, as reported on the New York Stock Exchange, for each quarter in the last two fiscal years and dividends declared per share:

High Sales PriceLow Sales PriceDividends (1)
2017
First Quarter$137.76$116.31$0.39
Second Quarter$144.00$131.62$0.39
Third Quarter$147.02$89.59$0.39
Fourth Quarter$120.77$105.31$0.39
2016
First Quarter$114.67$91.72$0.33
Second Quarter$128.41$113.09$0.33
Third Quarter$136.97$127.85$0.33
Fourth Quarter$134.56$110.87$0.33
(1)Equifax’s Senior Credit Facilities, as defined in Note 5 of the Notes to Consolidated Financial Statements in this Form 10-K, restricts our ability to pay cash dividends on our capital stock or repurchase capital stock if a default exists or would result according to the terms of the credit agreement.

We anticipate continuing the payment of quarterly cash dividends. The actual amount of such dividends is subject to declaration by our Board of Directors and will depend upon future earnings, results of operations, capital requirements, our financial condition and other relevant factors. There can be no assurance that the Company will continue to pay quarterly cash dividends at current levels or at all.

Shareholder Return Performance Graph

The graph below compares Equifax’s five-year cumulative total shareholder return with that of the Standard & Poor’s Composite Stock Index (S&P 500) and a peer group index, the S&P 500 Banks Index (Industry Group). The graph assumes that the value of the investment in our Common Stock and each index was $100 on the last trading day of 2012 and that all quarterly dividends were reinvested without commissions. Our past performance may not be indicative of future performance.

COMPARATIVE FIVE-YEAR CUMULATIVE TOTAL RETURN AMONG EQUIFAX INC., S&P 500 INDEX, AND S&P 500 BANKS INDEX (INDUSTRY GROUP)

chart-65abe6a099a053f1b3e.jpg

Fiscal Year Ended December 31,
Initial20132014201520162017
Equifax Inc.100.00129.52153.68214.06226.90228.22
S&P 500 Index100.00132.39150.51152.59169.24205.24
S&P 500 Banks Index (Industry Group)100.00132.25149.79148.23178.13214.75

The table below contains information with respect to purchases made by or on behalf of Equifax of its common stock during the fourth quarter ended December 31, 2017:

Issuer Purchases of Equity Securities

PeriodTotal Number of Shares Purchased (1)Average Price Paid Per Share (2)Total Number of Shares Purchased as Part of Publicly-Announced Plans or ProgramsMaximum Number (or Approximate Dollar Value) of Shares that May Yet Be Purchased Under the Plans or Programs (3)
October 1 - October 31, 201748,395$——$590,092,166
November 1 - November 30, 2017450$——$590,092,166
December 1 - December 31, 2017958$——$590,092,166
Total49,803$——$590,092,166
(1)The total number of shares purchased includes: (a) shares purchased pursuant to our publicly-announced share repurchase program, or Program; and (b) shares surrendered, or deemed surrendered, in satisfaction of the exercise price and/or to satisfy tax withholding obligations in connection with the exercise of employee stock options and vesting of restricted stock, totaling 48,395 shares for the month of October 2017, 450 shares for the month of November 2017 and 958 shares for the month of December 2017.
(2)Average price paid per share for shares purchased as part of our Program (includes brokerage commissions).
(3)Under the Program, we repurchased 0.5 million common shares during the twelve months ended December 31, 2017 for $77.1 million. At December 31, 2017, the amount authorized for future share repurchases under the Program was $590.1 million.

Information relating to compensation plans under which the Company’s equity securities are authorized for issuance is included in the section captioned “Equity Compensation Plan Information” in our 2018 Proxy Statement and is incorporated herein by reference.

Item 6. SELECTED FINANCIAL DATA

The table below summarizes our selected historical financial information for each of the last five years. The summary of operations data for the years ended December 31, 2017, 2016, 2015, and the balance sheet data as of December 31, 2017 and 2016, have been derived from our audited Consolidated Financial Statements included in this report. The summary of operations data for the years ended December 31, 2014 and 2013, and the balance sheet data as of December 31, 2015, 2014 and 2013, have been derived from our audited Consolidated Financial Statements not included in this report. The historical selected financial information may not be indicative of our future performance and should be read in conjunction with the information contained in Management’s Discussion and Analysis of Financial Condition and Results of Operations, and the Consolidated Financial Statements and the accompanying Notes to the Consolidated Financial Statements in this report.

Twelve Months Ended December 31,
2017 (1) (2)2016 (3)2015 (4)(5)2014 (6)2013(7)(8)
(In millions, except per share data)
Summary of Operations:
Operating revenue$3,362.2$3,144.9$2,663.6$2,436.4$2,303.9
Operating expenses2,537.62,327.01,969.71,798.21,692.7
Operating income824.6817.9693.9638.2611.2
Consolidated income from continuing operations598.0495.1434.8374.0341.5
Discontinued operations, net of tax (7)————18.4
Net income attributable to Equifax$587.3$488.8$429.1$367.4$351.8
Dividends paid to Equifax shareholders$187.4$157.6$137.8$121.2$106.7
Diluted earnings per share
Net income from continuing operations attributable to Equifax$4.83$4.04$3.55$2.97$2.69
Discontinued operations attributable to Equifax————0.15
Net income attributable to Equifax$4.83$4.04$3.55$2.97$2.84
Cash dividends declared per share$1.56$1.32$1.16$1.00$0.88
Weighted-average shares outstanding (diluted)121.5121.1120.9123.5123.7
As of December 31,
2017 (1) (2)2016 (3)2015 (4)(5)2014 (6)2013(7)(8)
(In millions)
Balance Sheet Data:
Total assets$7,233.4$6,664.0$4,501.5$4,661.0$4,522.5
Short-term debt and current maturities965.3585.449.3380.4296.5
Long-term debt, net of current portion1,739.02,086.81,138.41,145.71,145.5
Total debt, net2,704.32,672.21,187.71,526.11,442.0
Total equity3,239.02,721.32,350.42,234.62,341.0
(1)Through December 31, 2017, the Company recorded $164.0 million of pretax expenses related to the cybersecurity incident and insurance recoveries of $50.0 million for net expenses of $114.0 million. We included $14.2 million of these expenses in Cost of services and $99.8 million in Selling, general and administrative expenses in the accompanying Consolidated Statements of Income for the year ended December 31, 2017. Expenses include costs to investigate and remediate the cybersecurity incident and legal and other professional services related thereto, all of which were expensed as incurred. Additionally, as a result of the cybersecurity incident, we offered free credit file monitoring and identity theft protection to all U.S. consumers. We have recorded the expenses necessary to provide this

service to those who signed up. For additional information, see Note 6 of the Notes to the Consolidated Financial Statements in this report.

(2)The Tax Cuts and Jobs Act of 2017 (“Tax Act”), as signed by the President of the United States on December 22, 2017, significantly revises U.S. tax law. The legislation will positively impact the Company’s ongoing effective tax rate due to the reduction of the U.S. federal corporate tax rate from 35% to 21%. The Tax Act makes major changes to the U.S. international tax system. Under previous law, foreign earnings were subject to U.S. tax when repatriated to the U.S. Under the Tax Act, foreign earnings are generally exempt from U.S. tax. Additionally, there is a one-time deemed repatriation tax on undistributed foreign earnings and profits (the “transition tax”). The Tax Act imposes other U.S. taxes on “global intangible low taxed income” and “base erosion anti-abuse transactions.” Other significant changes include limitations on the deductibility of interest expense and executive compensation, and repeal of the deduction for domestic production activities. As a result of the current interpretation and estimated impact of the Tax Act, the Company recorded adjustments totaling a net tax benefit of $48.3 million in the fourth quarter of 2017 to provisionally account for the estimated impact. Refer to Note 7 of the Notes to the Consolidated Financial Statements in this Form 10-K for additional information. We also prospectively applied the provisions of ASU 2016-09 "Compensation - Stock Compensation (Topic 718)," related to the recognition of windfall tax benefits in the Consolidated Statement of Income which resulted in the recognition of $26.7 million of tax benefits for the year ended December 31, 2017.
(3)In the first quarter of 2016, we completed the acquisition of 100% of the ordinary voting shares of Veda for cash consideration plus debt assumed of approximately $1.9 billion. The acquisition provides a strong platform for Equifax to offer data and analytic services and further broaden the Company's geographic footprint. Additionally, on August 23, 2016, the Company completed the acquisition of 100% of the assets and certain liabilities of unemployment tax and claims management specialists Barnett & Associates ("Barnett"), as well as the verifications business, Computersoft, LLC ("Computersoft"). For the year ended December 31, 2016, we recorded $40.2 million ($28.2 million, net of tax) for Veda acquisition related amounts. Of this amount, $30.1 million relates to transaction and integration costs in operating income, $9.2 million is recorded in other income and is the impact of foreign currency changes on the transaction structure, including the economic hedges, $0.2 million is recorded in depreciation and amortization, and $0.7 million is recorded in interest expense. For additional information, see Note 3 of the Notes to the Consolidated Financial Statements in this report.
(4)In the first quarter of 2015, we recorded a $20.7 million restructuring charge ($13.2 million, net of tax) all of which was recorded in Selling, general and administrative expenses on our Consolidated Statements of Income. This charge resulted from our continuing efforts to realign our internal resources to support the Company’s strategic objectives and increase the integration of our global operations. For additional information, see Note 12 of the Notes to Consolidated Financial Statements in this report.
(5)During the second quarter of 2015, the management of Boa Vista Servicos S.A. ("BVS"), in which we hold a 15% cost method investment, updated the financial projections of BVS. The updated projections, along with the continued weakness in the Brazilian consumer and small commercial credit markets were considered indicators of impairment. As a result of these changes, and the associated near-term changes in cash flow expected from the business, we recorded a 46.0 million Brazilian Reais ($14.8 million) impairment of our investment. For additional information, see Note 2 of the Notes to Consolidated Financial Statements in this report.
(6)During the first quarter of 2014, we acquired 100% of the stock of TDX, a data, technology and services company in the United Kingdom that specializes in debt collections and recovery management through the use of analytics, data exchanges and technology platforms. The results of this acquisition have been included in our USIS and International operating segments subsequent to the acquisition. We also purchased Forseva, a provider of end-to-end, cloud-based credit-management software solutions. The results of this acquisition have been included in our USIS operating segment subsequent to the acquisition.
(7)During the first quarter of 2013, we divested two non-strategic business lines, Equifax Settlement Services, which was part of our Mortgage business within the USIS operating segment, and Talent Management Services, which was part of our Employer Services business within our Workforce Solutions operating segment, for a total of $47.5 million. We have presented the Equifax Settlement Services and Talent Management Services operations as discontinued operations for all periods presented.
(8)During the fourth quarter of 2013, the management of BVS, in which we hold a 15% cost method investment, revised its near-term outlook and its operating plans to reflect reduced near-term market expectations for credit information services in Brazil and increased investment needed to achieve its strategic objectives. As a result of these changes, and the

associated near-term changes in cash flow expected from the business, we recorded a 40 million Brazilian Reais ($17.0 million) impairment of our original investment of 130 million Brazilian Reais. For additional information, see Note 2 of the Notes to Consolidated Financial Statements in this report.

Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS

As used herein, the terms Equifax, the Company, we, our and us refer to Equifax Inc., a Georgia corporation, and its consolidated subsidiaries as a combined entity, except where it is clear that the terms mean only Equifax Inc.

All references to earnings per share data in Management’s Discussion and Analysis, or MD&A, are to diluted earnings per share, or EPS, unless otherwise noted. Diluted EPS is calculated to reflect the potential dilution that would occur if stock options or other contracts to issue common stock were exercised and resulted in additional common shares outstanding.

BUSINESS OVERVIEW

We are a leading global provider of information solutions, employment and income verifications and human resources business process outsourcing services. We leverage some of the largest sources of consumer and commercial data, along with advanced analytics and proprietary technology, to create customized insights which enable our business customers to grow faster, more efficiently and more profitably, and to inform and empower consumers.

Businesses rely on us for consumer and business credit intelligence, credit portfolio management, fraud detection, decisioning technology, marketing tools, debt management and human resources-related services. We also offer a portfolio of products that enable individual consumers to manage their financial affairs and protect their identity. Our revenue stream is diversified among businesses across a wide range of industries, international geographies and individual consumers.

2017 Cybersecurity Incident

In fiscal 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers. Criminals exploited a U.S. website application vulnerability to gain unauthorized access to our network. Based on our forensic investigation, the unauthorized access of information occurred from mid-May through July 2017. The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. In addition, credit card numbers for approximately 209,000 U.S. and Canadian consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed. The investigation determined that personal information of approximately 19,000 Canadian consumers was impacted and approximately 860,000 potentially affected U.K. consumers were contacted regarding access to personal information. The forensic investigation of the cybersecurity incident was, as previously disclosed, completed in the fourth quarter of fiscal 2017. No evidence was found that the Company's core consumer, employment and income, or commercial credit reporting databases were accessed.

The Company acted promptly to notify the approximately 145.5 million U.S. consumers whose personally identifiable information the Company had identified in 2017 as potentially accessed. As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify approximately 2.4 million U.S. consumers whose name and partial driver’s license information were stolen, but who were not in the affected population of approximately 145.5 million consumers previously identified by the Company in 2017. The Company is in the process of notifying these additional consumers.

As a result of the 2017 cybersecurity incident, we are party to numerous lawsuits and governmental investigations. See Part I, Item 1A. Risk Factors and Part I, Item 3. Legal Proceedings for more information regarding these lawsuits and investigations. We continue to cooperate with law enforcement in connection with the criminal investigation into the actors responsible for the cybersecurity incident.

Expenses Incurred. Through December 31, 2017, the Company recorded $113.3 million of pretax expenses related to the cybersecurity incident. We have included $14.2 million of these expenses in Cost of services and $99.1 million in Selling, general and administrative expenses in the accompanying Consolidated Statements of Income for the year ended December 31, 2017. Expenses include costs to investigate and remediate the cybersecurity incident and legal and other professional services related thereto, all of which were expensed as incurred.

Product Liability. Additionally, as a result of the cybersecurity incident, we offered free credit file monitoring and identity theft protection to all U.S. consumers. We have recorded the expenses necessary to provide this service to those who signed up. We have recorded $50.7 million through December 31, 2017 included in Selling, general and administrative expenses in the accompanying Consolidated Statements of Income.

Litigation, Claims and Government Investigations. As a result of the cybersecurity incident, we are subject to a significant number of proceedings and investigations as described in Part I, "Item 3. Legal Proceedings." While we believe it is reasonably possible that we will incur losses associated with these proceedings and investigations, it is not possible to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of such proceedings and investigations based on the early stage of these proceedings and investigations, that alleged damages have not been specified, the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues. The Company will continue to evaluate information as it becomes known and will record an estimate for losses at the time or times when it is both probable that a loss has been incurred and the amount of the loss is reasonably estimable. The Company believes that the ultimate amount paid on these actions, claims and investigations could be material to the Company’s consolidated financial condition, results of operations, or cash flows in future periods.

Future Costs. We expect to incur significant legal and other professional services expenses associated with the cybersecurity incident in future periods. We will recognize these expenses as services are received. Costs related to the cybersecurity incident that will be incurred in future periods will also include increased expenses and capital investments for IT and security. We expect to incur increased expenses for insurance, finance, compliance activities, and to meet increased legal and regulatory requirements. We will also incur increased costs to provide free services to consumers including increased customer support costs.

Insurance Coverage. We maintain $125 million of cybersecurity insurance coverage, above a $7.5 million deductible, to limit our exposure to losses such as those related to the cybersecurity incident. As of December 31, 2017, the Company has recorded a receivable of $35.0 million and received payments of $15 million for costs incurred to date that are reimbursable and probable of recovery under our insurance coverage.

Segment and Geographic Information

Segments. The USIS segment, the largest of our four segments, consists of three service lines: Online Information Solutions; Mortgage Solutions; and Financial Marketing Services. Online Information Solutions and Mortgage Solutions revenue is principally transaction-based and is derived from our sales of products such as consumer and commercial credit reporting and scoring, identity management, fraud detection and modeling services. USIS also markets certain decisioning software services, which facilitate and automate a variety of consumer and commercial credit-oriented decisions. Financial Marketing Services revenue is principally project and subscription based and is derived from our sales of batch credit and consumer we

Showing the first 8K of 119K characters. Open the full section

Item 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK

In the normal course of our business, we are exposed to market risk, primarily from changes in foreign currency exchange rates and interest rates that could impact our results of operations and financial position. We manage our exposure to these market risks through our regular operating and financing activities, and, when deemed appropriate, through the use of derivative financial instruments, such as interest rate swaps, to hedge certain of these exposures. We use derivative financial instruments as risk management tools and not for speculative or trading purposes.

Foreign Currency Exchange Rate Risk

A substantial majority of our revenue, expense and capital expenditure activities are transacted in U.S. dollars. However, we do transact business in other currencies, primarily the British pound, the Australian dollar, the Canadian dollar, the Chilean peso, the Argentine peso and the Euro. For most of these foreign currencies, we are a net recipient, and, therefore, benefit from a weaker U.S. dollar and are adversely affected by a stronger U.S. dollar relative to the foreign currencies in which we transact significant amounts of business.

We are required to translate, or express in U.S. dollars, the assets and liabilities of our foreign subsidiaries that are denominated or measured in foreign currencies at the applicable year-end rate of exchange on our Consolidated Balance Sheets and income statement items of our foreign subsidiaries at the average rates prevailing during the year. We record the resulting translation adjustment, and gains and losses resulting from the translation of intercompany balances of a long-term investment nature within other comprehensive income, as a component of our shareholders’ equity. Foreign currency transaction gains and losses, which have historically been immaterial, are recorded on our Consolidated Statements of Income. We generally do not mitigate the risks associated with fluctuating exchange rates, although we may from time to time through forward contracts or other derivative instruments hedge a portion of our translational foreign currency exposure or exchange rate risks associated with material transactions which are denominated in a foreign currency.

For the year ended December 31, 2017, a 10% weaker U.S. dollar against the currencies of all foreign countries in which we had operations during 2017 would have increased our revenue by $54.7 million and our pre-tax operating profit by $18.6 million. For the year ended December 31, 2016, a 10% weaker U.S. dollar against the currencies of all foreign countries in which we had operations during 2016 would have increased our revenue by $50.2 million and our pre-tax operating profit by $16.5 million. A 10% stronger U.S. dollar would have resulted in similar decreases to our revenue and pre-tax operating profit for 2017 and 2016.

On average across our mix of international businesses, foreign currencies at December 31, 2017, were weaker against the U.S. dollar than the average foreign exchange rates that prevailed across the full year 2017. As a result, if foreign exchange rates were unchanged throughout 2018, foreign exchange translation would reduce growth as reported in U.S. dollars. As foreign exchange rates change daily, there can be no assurance that foreign exchange rates will remain constant throughout 2018, and rates could go either higher or lower.

Interest Rate Risk

Our exposure to market risk for changes in interest rates relates to our variable-rate commercial paper borrowings. We attempt to achieve the lowest all-in weighted-average cost of debt while simultaneously taking into account the mix of our fixed- and floating-rate debt, and the average life and scheduled maturities of our debt. At December 31, 2017, our weighted average cost of debt was 3.4% and weighted-average life of debt was 4.95 years. At December 31, 2017, 61% of our debt was fixed rate, and the remaining 39% was variable rate. Occasionally we use derivatives to manage our exposure to changes in interest rates by entering into interest rate swaps. A 100 basis point increase in the weighted-average interest rate on our variable-rate debt would have increased our 2017 interest expense by $10.6 million.

Based on the amount of outstanding variable-rate debt, we have exposure to interest rate risk. In the future, if our mix of fixed-rate and variable-rate debt were to change due to additional borrowings under existing or new variable-rate debt, we could have additional exposure to interest rate risk. The nature and amount of our long-term and short-term debt, as well as the proportionate amount of fixed-rate and variable-rate debt, can be expected to vary as a result of future business requirements, market conditions and other factors.

Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA

Index to Financial Statements
Report of Independent Registered Public Accounting Firm on Internal Control over Financial Reporting61
Report of Independent Registered Public Accounting Firm62
Consolidated Statements of Income for each of the three years in the period ended December 31, 201763
Consolidated Statements of Comprehensive Income for each of the three years in the period ended December 31, 201764
Consolidated Balance Sheets at December 31, 2017 and 201665
Consolidated Statements of Cash Flows for each of the three years in the period ended December 31, 201766
Consolidated Statements of Shareholders’ Equity and Other Comprehensive Income for each of the three years in the period ended December 31, 201767
Notes to Consolidated Financial Statements69

Report of Independent Registered Public Accounting Firm

To the Shareholders and the Board of Directors of Equifax Inc.

Opinion on Internal Control over Financial Reporting

We have audited Equifax Inc.’s internal control over financial reporting as of December 31, 2017, based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (“2013 framework”) (the COSO criteria). In our opinion, Equifax Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of December 31, 2017, based on the COSO criteria.

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of December 31, 2017 and 2016, the related consolidated statements of income, comprehensive income, cash flows, and shareholders’ equity and other comprehensive income for each of the three years in the period ended December 31, 2017, and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) (collectively referred to as the "consolidated financial statements") and our report dated March 1, 2018 expressed an unqualified opinion thereon.

Basis for Opinion

The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting included in the accompanying Management’s Annual Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects.

Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.

Definition and Limitations of Internal Control Over Financial Reporting

A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.

Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.

/s/ Ernst & Young LLP

Atlanta, Georgia

March 1, 2018

Report of Independent Registered Public Accounting Firm

To the Shareholders and the Board of Directors of Equifax Inc.

Opinion on the Consolidated Financial Statements

We have audited the accompanying consolidated balance sheets of Equifax Inc. (the Company) as of December 31, 2017 and 2016, the related consolidated statements of income, comprehensive income, cash flows, and shareholders’ equity and other comprehensive income for each of the three years in the period ended December 31, 2017, and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at December 31, 2017 and 2016, and the results of its operations and its cash flows for each of the three years in the period ended December 31, 2017, in conformity with U.S. generally accepted accounting principles.

We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company's internal control over financial reporting as of December 31, 2017, based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) and our report dated March 1, 2018 expressed an unqualified opinion thereon.

Basis for Opinion

These consolidated financial statements are the responsibility of the Company's management. Our responsibility is to express an opinion on the Company’s consolidated financial statements based on our audits. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audits in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether the consolidated financial statements are free of material misstatement, whether due to error or fra

Showing the first 8K of 225K characters. Open the full section

Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE

None.

Item 9A. CONTROLS AND PROCEDURES

Evaluation of Disclosure Controls and Procedures

Our management, with the participation of our Interim Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of Equifax’s disclosure controls and procedures as of the end of the period covered by this report. Based on that evaluation, our Interim Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures as of the end of the period covered by this report (i) were appropriately designed to provide reasonable assurance of achieving their objectives and (ii) were effective and provided reasonable assurance that the information required to be disclosed by Equifax in reports filed under the Exchange Act is (a) recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms and (b) accumulated and communicated to Equifax’s management, including our Interim Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions regarding required disclosure.

As discussed in Note 6 of the Notes to the Consolidated Financial Statements in this Form 10-K, on September 7, 2017, we announced a cybersecurity incident. Our review of the circumstances and resulting impact on our internal controls over financial reporting (ICFR) identified two significant deficiencies in our IT General Controls environment, in the third quarter of 2017. As of December 31, 2017, management has remediated the two significant deficiencies.

Incorporating these results, our management, with the participation of our Interim Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of Equifax's disclosure controls and procedures as of the end of the period covered by this report. Based on that evaluation, our Interim Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures as of the end of the period covered by this report (i) were appropriately designed to provide reasonable assurance of achieving their objectives and (ii) were effective and provided reasonable assurance that the information required to be disclosed by Equifax in reports filed under the Exchange Act is (a) recorded, processed, summarized and reported within the time periods specified in the SEC's rules and forms and (b) accumulated and communicated to Equifax's management, including our Interim Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions regarding required disclosure.

Management’s Annual Report on Internal Control Over Financial Reporting

Our management is responsible for establishing and maintaining adequate internal control over financial reporting. Internal control over financial reporting is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act as a process designed by, or under the supervision of, our Interim Chief Executive Officer and Chief Financial Officer and effected by our Board of Directors, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles and includes those policies and procedures that:

•pertain to the maintenance of records that in reasonable detail accurately and fairly reflect transactions and dispositions of our assets;
•provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that our receipts and expenditures are being made only in accordance with authorizations of our management and directors; and
•provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on the financial statements.

Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.

Our management assessed the effectiveness of Equifax’s internal control over financial reporting as of December 31, 2017 using the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) in Internal Control-Integrated Framework (2013 Framework). Based on this assessment using those criteria, our management concluded that, as of December 31, 2017, Equifax’s internal control over financial reporting was effective. Management

reviewed the results of its assessment with the Audit Committee of its Board of Directors. The effectiveness of Equifax’s internal control over financial reporting as of December 31, 2017 has been audited by Ernst & Young LLP, Equifax’s independent registered public accounting firm, as stated in their report, which appears in Part II, Item 8 of this Form 10-K on page 61.

Changes in Internal Control Over Financial Reporting

There have been no changes in internal control over financial reporting identified in connection with the foregoing that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

Item 9B. OTHER INFORMATION

None.

PART III

Item 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE

Except for the information about our executive officers shown below, the information required by this Item 10 is incorporated herein by reference from the information contained in our Proxy Statement to be filed with the SEC in connection with the solicitation of proxies for our 2018 Annual Meeting of Shareholders (the “2018 Proxy Statement”) under the sections entitled “Proposal 1 Election of Directors,” “Section 16(a) Beneficial Ownership Reporting Compliance” and “Board Leadership and Corporation Governance Committees of the Board of Directors.”

We have adopted a written Code of Ethics and Business Conduct applicable to all our employees, including our principal executive officer, principal financial officer, and principal accounting officer and controller, and to members of our Board of Directors. Our Code of Ethics and Business Conduct is available on our investor relations website: www.equifax.com/about-equifax/corporate-governance. We will disclose amendments to certain provisions of our Code of Ethics and Business Conduct, or waivers of such provisions granted to executive officers and directors, on this website.

Executive Officers

Information regarding the executive officers of Equifax Inc. is set forth below.

J. Dann Adams (60) has been President, Global Consumer Solutions, since November 2015. Prior thereto, he served as President, Workforce Solutions, since July 2010. Prior thereto, he served as President, U.S. Information Solutions from 2007 to June 2010. Prior thereto, he served as Group Executive, North America Information Services from November 2003 until December 2006.

Paulino do Rego Barros, Jr. (61) has been Interim Chief Executive Officer since September 2017. Prior thereto, he led the Company’s Asia-Pacific business since July 2017. Prior thereto, he was President, U.S. Information Solutions, since November 2015. Prior thereto, he served as President, International, since April 2010. Prior thereto, he served as President of PB&C Global Investments, LLC, an international consulting and investment firm. Prior thereto, he was President of Global Operations for AT&T.

Jamil Farshchi (40) was appointed as our Chief Information Security Officer on February 26, 2018. Prior to joining Equifax, Mr. Farshchi served as Chief Information Security Officer at The Home Depot since April 2015. Prior thereto, he was the first Global Chief Information Security Officer at Time Warner Inc., from August 2014 to March 2015. Prior thereto, he was the Vice President of Global Information Security at Visa Inc. from August 2011 to August 2014. Mr. Farshchi has also held senior roles at Los Alamos National Laboratory, Sitel Corporation, Nextwave Broadband and NASA.

John W. Gamble, Jr. (55) has been Corporate Vice President and Chief Financial Officer since May 2014. Prior to that, Mr. Gamble was Executive Vice President and Chief Financial Officer of Lexmark International, Inc., a global provider of document solutions, enterprise content management software and services, printers and multifunction printers, from September 2005 until May 2014.

John T. Hartman (58) has been President, International, since November 2015. Prior thereto, he served as Senior Vice President, Corporate Development, since July 2010. Prior thereto, he served as President of Growth Vector from 2009 to 2010. Prior thereto, he served as Executive Vice President and Chief Commercial Officer for Acuity Brands from 2004 to 2009.

Julia A. Houston (47) has been Chief Transformation Officer since October 2017. Prior thereto, she was Senior Vice President, U.S. Legal, since October 2013. Prior to joining Equifax, Ms. Houston was Senior Vice President, General Counsel and Corporate Secretary at Convergys Corporation, from 2011 to 2013. Prior thereto, she served was Senior Vice President, General Counsel, Chief Compliance Officer and Corporate Secretary at Mirant Corporation, from 2004 to 2010.

John J. Kelley III (57) has been Corporate Vice President and Chief Legal Officer since January 2013. Prior to joining Equifax, Mr. Kelley was a senior partner in the Corporate Practice Group of the law firm of King & Spalding LLP from January 1993 to December 2012.

Nuala M. King (64) has been Senior Vice President and Controller since May 2006. Prior thereto, she was Vice President and Corporate Controller from March 2004 to April 2006. Prior to joining Equifax, Ms. King served as Corporate Controller for UPS Capital from March 2001 until March 2004.

Joseph M. Loughran, III (50) has been President, U.S. Information Solutions, since July 2017. Prior thereto, he was Chief Marketing Officer since March 2015. Prior thereto, he served as President, Global Consumer Solutions since January 2010. Prior thereto, he was Senior Vice President Corporate Development from April 2006 to December 2009. Prior to joining Equifax, he held various executive roles at BellSouth Corporation from May 2001 to April 2006, including most recently Managing Director Corporate Strategy and Planning from May 2005 to April 2006.

Rodolfo O. Ploder (57) has been President, Workforce Solutions, since November 2015. Prior thereto, he served as President, U.S. Information Solutions, since April 2010. Prior thereto, he served as President, International, from January 2007 to April 2010. Prior thereto, he was Group Executive, Latin America from February 2004 to January 2007.

Coretha M. Rushing (61) has been Corporate Vice President and Chief Human Resources Officer since 2006. Prior to joining Equifax, she served as an executive coach and HR Consultant with Atlanta-based Cameron Wesley LLC. Prior thereto, she was Senior Vice President of Human Resources at The Coca-Cola Company, where she was employed from 1996 until 2004.

Laura L. Wilbanks (50) has been Chief Marketing Officer since August 2017. Prior thereto, she served as Senior Vice President and Senior Marketing Officer for U.S. Information Solutions, since May 2013. Prior thereto, she served as Senior Vice President, Strategic Marketing since January 2010. Prior thereto, since February 1998, Ms. Wilbanks held positions of increasing responsibility at Equifax, including leadership roles in global product management, global strategy, market development and market insight and planning.

Item 11. EXECUTIVE COMPENSATION

The information required by this Item 11 is incorporated herein by reference from the information contained in our 2018 Proxy Statement under the sections entitled “Executive Compensation” and “Director Compensation.”

Item 12. SECURITY OWNERSHIP OF CERTAIN BENEFICIAL OWNERS AND MANAGEMENT AND RELATED STOCKHOLDER MATTERS

The information required by this Item 12 is incorporated herein by reference from the information contained in our 2018 Proxy Statement under the sections entitled “Security Ownership of Management and Certain Beneficial Owners” and “Executive Compensation Equity Compensation Plan Information.”

Item 13. CERTAIN RELATIONSHIPS AND RELATED TRANSACTIONS AND DIRECTOR INDEPENDENCE

The information required by this Item 13 is incorporated herein by reference from the information contained in our 2018 Proxy Statement under the sections entitled “Board Leadership and Corporate Governance Director Independence, ” “Related Person Transaction Policy” and “Certain Relationships and Related Person Transactions of Directors, Executive Officers, and 5 Percent Shareholders.”

Item 14. PRINCIPAL ACCOUNTANT FEES AND SERVICES

The information required by this Item 14 is incorporated herein by reference from the information contained in our 2018 Proxy Statement under the section entitled “Proposal 3 Ratification of Appointment of Ernst & Young LLP as Independent Registered Public Accounting Firm for 2018.”

PART IV

Item 15. EXHIBITS AND FINANCIAL STATEMENT SCHEDULES

(a)List of Documents Filed as a Part of This Report:
(1)Financial Statements. The following financial statements are included in Item 8 of Part II:
•Consolidated Balance Sheets — December 31, 2017 and 2016;
•Consolidated Statements of Income for the Years Ended December 31, 2017, 2016 and 2015;
•Consolidated Statements of Comprehensive Income for the Years Ended December 31, 2017, 2016 and 2015;
•Consolidated Statements of Cash Flows for the Years Ended December 31, 2017, 2016 and 2015;
•Consolidated Statements of Shareholders’ Equity and Other Comprehensive Income for the Years Ended December 31, 2017, 2016 and 2015; and
•Notes to Consolidated Financial Statements.
(2)Financial Statement Schedules.
  • Schedule II — Valuation and Qualifying Accounts

All other schedules for which provision is made in the applicable accounting regulation of the SEC are not required under the related instructions or are inapplicable and, therefore, have been omitted.

(3)Exhibits. See exhibits listed under Part (b) below.

(b) Exhibits:

Exhibit NumberDescription
Plan of Acquisition
2.1Scheme Implementation Deed, dated as of November 22, 2015 (Sydney, Australia time), by and between Equifax Inc. and Veda Group Limited (incorporated by reference to Exhibit 2.1 to Equifax's Form 8-K filed November 24, 2015).
Articles of Incorporation and Bylaws
3.1Amended and Restated Articles of Incorporation of Equifax Inc. (incorporated by reference to Exhibit 3.1 to Equifax's Form 8-K filed May 14, 2009).
3.2Amended and Restated Bylaws of Equifax Inc. (incorporated by reference to Exhibit 3.1 to Equifax's Form 8-K filed February 21, 2017).
Instruments Defining the Rights of Security Holders, Including Indentures
4.1Amendment to Rights Agreement dated as of February 19, 2015, between Equifax Inc. and American Stock Transfer & Trust Company, LLC, as successor Rights Agent to SunTrust Bank, amending the Amended and Restated Rights Agreement dated as of October 14, 2005, between Equifax Inc. and SunTrust Bank, as Rights Agent (incorporated by reference to Exhibit 4.1 to Equifax’s Form 8-K filed February 20, 2015).
4.2Indenture dated as of June 29, 1998, between Equifax Inc. and The First National Bank of Chicago, Trustee (the “1998 Indenture”)(under which Equifax's 6.9% Debentures due 2028 were issued) (incorporated by reference to Exhibit 4.4 to Equifax's Form 10-K filed March 31, 1999).
4.3Second Supplemental Indenture dated as of June 28, 2007, between Equifax Inc. and The Bank of New York Trust Company, N.A. (under which Equifax's 7.00% Senior Notes due 2037 were issued), to the 1998 Indenture (incorporated by reference to Exhibit 4.1 to Equifax's Form 8-K filed June 29, 2007).
4.4Fourth Supplemental Indenture dated as of December 17, 2012, between Equifax Inc. and The Bank of New York Mellon Trust Company, N.A. (under which Equifax's 3.30% Senior Notes due 2022 were issued), to the 1998 Indenture (incorporated by reference to Exhibit 4.2 to Equifax's Form 8-K filed December 11, 2012).
4.5Third Amended and Restated Credit Agreement dated as of December 19, 2012, among Equifax Inc., Equifax Limited, Equifax Canada Co. (formerly known as Equifax Canada, Inc.), Equifax Luxembourg S.A.R.L., the lenders named therein and Bank of America, N.A. as Administrative Agent (incorporated by reference to Exhibit 4.2 to Equifax's Form 8-K filed December 20, 2012).
4.6Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee (incorporated by reference to Exhibit 4.1 to Equifax's Form 8-K filed May 12, 2016).
4.7First Supplemental Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee, including the form of 2021 Note as Exhibit A (incorporated by reference to Exhibit 4.2 to Equifax’s Form 8-K filed May 12, 2016).
4.8Second Supplemental Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee, including the form of 2026 Note as Exhibit A (incorporated by reference to Exhibit 4.3 to Equifax’s Form 8-K filed May 12, 2016).
Except as set forth in the preceding Exhibits 4.1 through 4.8, instruments defining the rights of holders of long-term debt securities of Equifax have been omitted where the total amount of securities authorized does not exceed 10% of the total assets of Equifax and its subsidiaries on a consolidated basis. Equifax agrees to furnish to the SEC, upon request, a copy of such instruments with respect to issuances of long-term debt of Equifax and its subsidiaries.
Management Contracts and Compensatory Plans or Arrangements
10.1Form of Director/Executive Officer Indemnification Agreement (incorporated by reference to Exhibit 10.1 to Equifax’s Form 8-K filed May 14, 2009).
10.2Form of Change in Control Agreement adopted in 2008 (Tier I or Tier II) (incorporated by reference to Exhibit 10.3 to Equifax’s Form 8-K filed September 26, 2008).
10.3Form of Change in Control Agreement adopted in 2013 (Tier I or Tier II) (incorporated by reference to Exhibit 10.2 to Equifax’s Form 10-K filed February 22, 2013).
10.4Equifax Inc. Non-Employee Director Stock Option Plan and Form of Non-Employee Director Stock Option Agreement (incorporated by reference to Exhibit 10.16 to Equifax’s Form 10-K filed March 31, 1999).
10.5Equifax Inc. Supplemental Executive Retirement Plan (incorporated by reference to Exhibit 10.7 to Equifax’s Form 10-K filed March 29, 2001).
10.6Supplemental Retirement Plan for Executives of Equifax Inc. (incorporated by reference to Exhibit 10.6(a) to Equifax’s Form 10-K filed February 24, 2016).
10.7Trust Agreement for Supplemental Retirement Plan for Executives of Equifax Inc. dated as of September 16, 2011, between Equifax Inc. and Wells Fargo Bank, N.A. (incorporated by reference to Exhibit 10.6(b) to Equifax’s Form 10-K filed February 23, 2012).
10.8Equifax Inc. Executive Life and Supplemental Retirement Benefit Plan (incorporated by reference to Exhibit 10.8 to Equifax’s Form 10-K filed March 29, 2001).
10.9Equifax Inc. Key Management Long-Term Incentive Plan, as amended and restated effective as of May 2, 2013 (incorporated by reference to Appendix C to Equifax’s definitive proxy statement on Schedule 14A filed March 20, 2013).
10.10Equifax Inc. 2008 Omnibus Incentive Plan, as amended and restated effective May 2, 2013 (incorporated by reference to Appendix C to Equifax's definitive proxy statement on Schedule 14A filed March 20, 2013).
10.11Form of Non-Qualified Stock Option Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.9 to Equifax's form 10-K filed February 22, 2013).
10.12Form of Qualified Performance-Based Restricted Stock Unit Award Agreement (Senior Leadership Team) under the Equifax Inc. 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.26 to Equifax’s Form 10-K filed February 22, 2013).
10.13Form of Qualified Performance-Based Restricted Stock Unit Award Agreement (CEO) under the Equifax Inc. 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.27 to Equifax’s Form 10-K filed February 22, 2013).
10.14Form of Employee Restricted Stock Unit Award Agreement under the Equifax Inc. 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.28 to Equifax’s Form 10-K filed February 22, 2013).
10.15Form of Non-Employee Director Restricted Stock Unit Award Agreement (incorporated by reference to Exhibit 10.17 to Equifax’s Form 10-K filed February 26, 2009).
10.16Form of Total Share Return Performance Share Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.29 to Equifax’s Form 10-K filed February 28, 2014).
10.17Form of Total Share Return Performance Share Award Agreement (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (incorporated by reference to Exhibit 10.30 to Equifax’s Form 10-K filed February 28, 2014).
10.18Equifax Inc. 2008 Omnibus Incentive Plan (U.K. Sub-Plan for U.K. Participants) (incorporated by reference to Exhibit 10.10 to Equifax’s Form 10-K filed February 26, 2009).
10.19Form of Non-Qualified Stock Option Agreement under the Equifax Inc. 2008 Omnibus Incentive Plan (U.K. approved option version) (incorporated by reference to Exhibit 10.11 to Equifax’s Form 10-K filed February 26, 2009).
10.20Form of Non-Qualified Stock Option Agreement under the Equifax Inc. 2008 Omnibus Incentive Plan (U.K. unapproved option version) (incorporated by reference to Exhibit 10.12 to Equifax’s Form 10-K filed February 26, 2009).
10.21Equifax Inc. Executive Deferred Compensation Plan, as amended through December 31, 2008 (incorporated by reference to Exhibit 10.13 to Equifax’s Form 10-K filed February 26, 2009).
10.22Equifax Inc. Director Deferred Compensation Plan, as amended through December 31, 2008 (incorporated by reference to Exhibit 10.14 to Equifax’s Form 10-K filed February 26, 2009).
10.23Equifax Grantor Trust dated as of January 1, 2003, between Equifax Inc. and Wachovia Bank, N.A., Trustee, relating to supplemental deferred compensation and phantom stock benefits (incorporated by reference to Exhibit 10.30 to Equifax’s Form 10-K filed March 28, 2003).
10.24Equifax Inc. Director and Executive Stock Deferral Plan, as amended and restated effective January 1, 2015, as amended (incorporated by reference to Exhibit 10.23 to Equifax's Form 10-K filed February 22, 2017).
10.25Equifax 2005 Executive Deferred Compensation Plan, as amended and restated effective January 1, 2015 (incorporated by reference to Exhibit 10.1 to Equifax’s Form 10-Q filed July 28, 2016).
10.26Amendment No. 1 to Equifax 2005 Executive Deferred Compensation Plan, effective January 1, 2016 (incorporated by reference to Exhibit 10.2 to Equifax’s Form 10-Q filed July 28, 2016).
10.27*Amendment No. 2 to Equifax 2005 Executive Deferred Compensation plan, effective January 1, 2016.
10.28Amended and Restated Employment Agreement dated as of September 23, 2008, between Equifax Inc. and Richard F. Smith (incorporated by reference to Exhibit 10.1 to Equifax’s Form 8-K filed September 26, 2008).
10.29Letter agreement dated December 21, 2012, between Equifax Inc. and Richard F. Smith modifying the Amended Restated Employment Agreement dated as of September 23, 2008 (amendment to comply with Section 409A of Internal Revenue Code) (incorporated by reference to Exhibit 10.22 to Equifax’s Form 10-K filed February 22, 2013).
10.30Agreement dated September 25, 2017, between Equifax Inc. and Richard F. Smith (incorporated by reference to Exhibit 10.1 to Equifax's Form 10-Q filed November 9, 2017).
10.31Deferred Share Award Agreement dated as of September 19, 2005, between Equifax Inc. and Richard F. Smith (incorporated by reference to Exhibit 10.2 to Equifax’s Form 10-Q filed November 7, 2005).
10.32Form of Restricted Stock Unit Award Agreement (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.1 to Equifax's Form 10-Q filed April 27, 2017).
10.33Form of Restricted Stock Unit Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.2 to Equifax's Form 10-Q filed April 27, 2017).
10.34Form of Non-Qualified Stock Option Award Agreement (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.3 to Equifax's Form 10-Q filed April 27, 2017).
10.35Form of Non-Qualified Stock Option Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.4 to Equifax's Form 10-Q filed April 27, 2017).
10.36Form of Performance Share Award Agreement (TSR) (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.5 to Equifax's Form 10-Q filed April 27, 2017).
10.37Form of Performance Share Award Agreement (TSR) (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.6 to Equifax's Form 10-Q filed April 27, 2017).
10.38Form of Performance Share Award Agreement (EPS) (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.7 to Equifax's Form 10-Q filed April 27, 2017).
10.39Form of Performance Share Award Agreement (EPS) (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.8 to Equifax's Form 10-Q filed April 27, 2017).
Material Contracts
10.40Commercial Paper Dealer Agreement dated May 22, 2007, between Equifax Inc. and Bank of America Securities LLC (incorporated by reference to Exhibit 10.1 to Equifax’s Form 8-K filed May 23, 2007).
10.41Commercial Paper Dealer Agreement dated May 22, 2007, between Equifax Inc. and SunTrust Capital Markets Securities, Inc. (incorporated by reference to Exhibit 10.2 to Equifax’s Form 8-K filed May 23, 2007).
Other Exhibits and Certifications
11.1Calculation of earnings per share. (The calculation of earnings per share is in Part II, Item 8, Note 1 to the Consolidated Financial Statements and is omitted in accordance with Section (b)(11) of Item 601 of the Notes to Regulation S-K).
12.1*Computation of ratio of earnings to fixed charges
21.1*Subsidiaries of Equifax Inc.
23.1*Consent of Independent Registered Public Accounting Firm.
24.1*Powers of Attorney (included on signature page).
31.1*Rule 13a-14(a) Certification of Chief Executive Officer.
31.2*Rule 13a-14(a) Certification of Chief Financial Officer.
32.1*Section 1350 Certification of Chief Executive Officer.
32.2*Section 1350 Certification of Chief Financial Officer.
101.INSXBRL Instance Document.
101.SCHXBRL Taxonomy Extension Schema Document.
101.CALXBRL Taxonomy Extension Calculation Linkbase.
101.LABXBRL Taxonomy Extension Label Linkbase.
101.PREXBRL Taxonomy Extension Presentation Linkbase.
101.DEFXBRL Taxonomy Extension Definition Linkbase.
  • Filed herewith

(c) Financial Statement Schedules. See Item 15(a)(2).

Item 16. FORM 10-K SUMMARY

None.

SIGNATURES

Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on March 1, 2018.

EQUIFAX INC.
(Registrant)
By:/s/ Paulino R. Barros, Jr.
Paulino R. Barros, Jr.
Interim Chief Executive Officer

We, the undersigned directors and executive officers of Equifax Inc., hereby severally constitute and appoint John W. Gamble, Jr. and Nuala M. King, and each of them singly, our true and lawful attorneys with full power to them and each of them to sign for us, and in our names in the capacities indicated below, any and all amendments to this Annual Report on Form 10-K filed with the SEC, hereby ratifying and confirming our signatures as they may be signed by our said attorneys to any and all amendments to said Annual Report on Form 10-K.

Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the registrant and in the capacities indicated on March 1, 2018.

/s/ Paulino R. Barros, Jr.
Paulino R. Barros, Jr.
Interim Chief Executive Officer
(Principal Executive Officer)
/s/ John W. Gamble, Jr.
John W. Gamble, Jr.
Corporate Vice President and Chief Financial Officer
(Principal Financial Officer)
/s/ Nuala M. King
Nuala M. King
Senior Vice President and Corporate Controller
(Principal Accounting Officer)
/s/ Mark L. Feidler
Mark L. Feidler
Director and Chairman
/s/ Robert D. Daleo
Robert D. Daleo
Director
/s/ Walter W. Driver, Jr.
Walter W. Driver, Jr.
Director
/s/ G. Thomas Hough
G. Thomas Hough
Director
/s/ L. Phillip Humann
L. Phillip Humann
Director
/s/ Robert D. Marcus
Robert D. Marcus
Director
/s/ Siri S. Marshall
Siri S. Marshall
Director
/s/ Scott A. McGregor
Scott A. McGregor
Director
/s/ John A. McKinley
John A. McKinley
Director
/s/ Elane B. Stock
Elane B. Stock
Director
/s/ Mark B. Templeton
Mark B. Templeton
Director

SCHEDULE II — VALUATION AND QUALIFYING ACCOUNTS

2017

Column AColumn BColumn CColumn DColumn E
Additions
DescriptionBalance at Beginning of PeriodCharged to Costs and ExpensesCharged to Other AccountsDeductionsBalance at End of Period
(In millions)
Reserves deducted in the balance sheet from the assets to which they apply:
Trade accounts receivable$7.8$5.0$—$(3.7)$9.1
Deferred income tax asset valuation allowance307.3(6.1)8.192.5401.8
$315.1$(1.1)$8.1$88.8$410.9

2016

Column AColumn BColumn CColumn DColumn E
Additions
DescriptionBalance at Beginning of PeriodCharged to Costs and ExpensesCharged to Other AccountsDeductionsBalance at End of Period
(In millions)
Reserves deducted in the balance sheet from the assets to which they apply:
Trade accounts receivable$7.5$2.2$—$(1.9)$7.8
Deferred income tax asset valuation allowance222.9(233.7)23.8294.3307.3
$230.4$(231.5)$23.8$292.4$315.1

2015

Column AColumn BColumn CColumn DColumn E
Additions
DescriptionBalance at Beginning of PeriodCharged to Costs and ExpensesCharged to Other AccountsDeductionsBalance at End of Period
(In millions)
Reserves deducted in the balance sheet from the assets to which they apply:
Trade accounts receivable$7.2$4.3$—$(4.0)$7.5
Deferred income tax asset valuation allowance121.4(1.5)(13.0)116.0222.9
$128.6$2.8$(13.0)$112.0$230.4