Equifax (EFX) 10-K risk factor changes: FY2018 vs FY2017
The 2018-12-31 10-K against the 2017-12-31 one, compared heading by heading and sentence by sentence. One of these filings carries no fiscal year tag, so its year is the calendar year of the period end.
Item 1A70 rewritten65 added29 removed230 unchanged
All filing items1,208 rewritten817 added672 removed2,283 unchanged
Summary
counted, not written
- Item 1A headings could not be compared: only 0 carried over between the two years, which usually means one filing was read wrongly, so none is reported as new or removed.
- Sentence by sentence, 817 added, 672 removed, 1,208 rewritten and 2,283 unchanged across 18 items that differ.
Sentences by item
22 items, with every count and a link to each item that changed
Underlined words on a shaded ground are new in FY2018; struck-through words were in FY2017. Sentences that are wholly new or wholly gone are labelled rather than marked.
Item 1A. RISK FACTORS
70 rewritten, 65 added, 29 removed, 230 unchanged
Security breaches like the [added: 2017] cybersecurity incident [removed: announced in September 2017] and other disruptions to our information technology infrastructure could compromise Company, consumer and customer information, interfere with our operations, cause us to incur significant costs for remediation and enhancement of our IT systems and expose us to legal liability, all of which could have a substantial negative impact on our business and reputation.
Despite our substantial investment in physical and technological security measures, employee training and contractual precautions, our information technology networks and infrastructure (or those of our third-party vendors and other service providers) are [added: potentially] vulnerable to unauthorized access to data or breaches of confidential information due to criminal conduct, attacks by hackers, employee or insider malfeasance and/or human error.
In 2017, we were the target of a cybersecurity attack that involved the theft of certain personally identifiable information of [removed: U.S.,] [added: approximately 145.5 million U.S. consumers, approximately 19,000] Canadian [added: consumers] and [added: approximately 860,000] U.K. consumers.
[removed: As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify] [added: In addition, we identified] approximately 2.4 million U.S. consumers whose name and partial [removed: driver's] [added: driver’s] license information were [removed: stolen, but who were not] [added: stolen] in the [removed: affected population of approximately 145.5 million consumers previously identified by the Company in 2017.][added: attack.]
[removed: It] [added: While the forensic analysis of the 2017 cybersecurity incident] is [added: complete, it is] possible that further analysis will identify additional consumers affected or additional types of data accessed, which could result in additional notifications and negative publicity.
Following the [added: 2017] cybersecurity incident, we began undertaking significant remediation efforts and other steps to enhance our data security [removed: infrastructure.][added: infrastructure which are ongoing.]
In connection with these efforts, we have incurred significant costs and expect to incur additional significant costs as we [added: continue to enhance our data security infrastructure and] take further steps to prevent unauthorized access to our systems and the data we maintain.
[removed: We] [added: Despite these efforts, we] cannot assure [added: you] that all potential causes of [removed: the] [added: this] incident have been identified and remediated and [added: that similar cyber incidents] will not occur [removed: again.][added: in the future.]
We must continuously [removed: monitor and] [added: plan,] develop [added: and monitor] our information technology networks and infrastructure to [removed: prevent,] [added: identify, protect,] detect, [removed: address] [added: respond to] and [removed: mitigate] [added: recover from] the risk of unauthorized access, misuse, [removed: computer viruses] [added: malware, phishing] and other events that could have a security impact.
We [removed: expect our insurance coverage will not be adequate to compensate us for all losses that may occur due to the 2017 cybersecurity incident and we] cannot ensure that our insurance policies in the future will be adequate to cover losses from any future failures.
In addition, our [removed: third-party] insurance coverage will vary from time to time in both type and amount depending on availability, cost and our decisions with respect to risk retention.
As a result of the 2017 cybersecurity incident, we are currently a party to a consolidated multi-district consumer class action lawsuit and a consolidated multi-district financial institution class action lawsuit, as well as [added: a consolidated] securities class action [removed: lawsuits,] [added: lawsuit,] shareholder derivative litigation and other lawsuits and claims [removed: allegedly] arising out of the [added: 2017] cybersecurity incident seeking monetary damages or other relief.
[removed: Additional] [added: In addition, other] lawsuits, investigations and reports related to the 2017 cybersecurity incident may be filed, commenced or issued.
The claims and investigations have resulted in the incurrence of significant external and internal legal costs and expenses and reputational damage to our business and are expected to continue throughout [removed: 2018] [added: 2019] and beyond.
[added: If such damages, costs,] fines or penalties were great enough that we could not pay them through funds generated from operating activities and/or cause a default under our revolving credit facility, we may be forced to renegotiate or obtain a waiver under our revolving credit facility and/or seek additional debt or equity financing.
[removed: The] [added: Various] governmental agencies investigating the [added: 2017] cybersecurity incident [removed: may seek] [added: are seeking] to impose injunctive relief, consent decrees, [removed: or other] [added: and] civil [removed: or criminal] penalties, which could, among other things, impact our ability to collect and use consumer information, materially increase our data security [removed: costs] [added: costs, reduce available resources to invest in technology and innovation] and/or otherwise require us to alter how we operate our [removed: business.][added: business, and put us at a competitive disadvantage.]
Any legislative or regulatory changes adopted in reaction to the [added: 2017] cybersecurity incident or other companies’ data breaches could require us to make modifications to the operation of our business that could have an adverse effect and/or increase or accelerate our compliance costs.
The [added: 2017] cybersecurity incident and the adverse publicity that followed have had a negative impact on our [removed: reputation,] [added: reputation] and [added: our relationships with our customers, and] we cannot assure [added: that] it will not have a long-term effect on our relationships with our customers, our revenue and our business.
[removed: In addition, some of our current and potential customers and] [added: Additionally, following] the [removed: contracts governing certain customer relationships, as well as] [added: 2017 cybersecurity incident,] certain of our [removed: data suppliers, require us to maintain] International Organization for Standardization (“ISO”) certifications, [removed: such as ISO 27001 certification, that] [added: which] specify requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented information security management [removed: system.][added: system, were suspended.]
[removed: If] [added: Despite our progress made toward repairing our reputation and business relationships, if] we are unable to demonstrate the security of our systems and the data we maintain and [removed: rebuild] [added: retain] the trust of our customers, consumers and data suppliers, [removed: and if further negative publicity continues,] we could experience a substantial negative impact on our business.
This data includes the widespread and voluntary contribution of credit data from most lenders in the U.S and many other markets as well as the contribution of data under proprietary contractual agreements, such as employers’ contribution of employment and income data to The Work [removed: Number,] [added: Number®,] financial institutions’ contribution of individual financial data to IXI, and telecommunications, cable and utility companies’ contribution of payment and fraud data to the National Cable, Telecommunications and Utility Exchange.
Our customers, and therefore our business and revenues, are sensitive to negative changes in general economic conditions, including the demand and availability of affordable credit and capital, the level and volatility of interest rates, inflation, employment levels, consumer confidence and housing demand, both inside and outside the U.S. Business customers [added: use our credit information and related analytical services and data to process applications for new credit cards, automobile loans, home and equity loans and other consumer loans, and to manage their existing credit relationships.]
Demand for our services tends to be correlated to general levels of economic activity and to consumer credit [removed: activity.][added: activity, which can be impacted by changes in interest rates.]
Bank and other lenders’ willingness to extend credit [removed: is] [added: are] adversely affected by elevated consumer delinquency and loan losses in a weak economy.
Our customer base suffers when financial markets experience volatility, illiquidity and [removed: disruption, which has occurred in the past and which could reoccur,] [added: disruption] and the potential for increased and continuing disruptions going forward presents considerable risks to our business and revenue.
High or rising rates of unemployment and interest, declines in income, home prices or investment values, lower consumer confidence and reduced access to credit adversely affect demand for [added: many of] our products and services, and consequently our revenue and results of operations, as consumers may postpone or reduce their spending and use of credit, and lenders may reduce the amount of credit offered or available.
Our relationships with key long-term customers may be materially diminished or [removed: terminated][added: terminated.]
There is no guarantee that we will be able to retain or renew existing agreements, maintain relationships with any of our customers or [added: business partners on acceptable terms or at all, or collect amounts owed to us from insolvent customers or business partners.]
In addition, our management is and will continue to be intensely focused on enhancing our security measures and responding to consumer and customer concerns relating to the 2017 cybersecurity incident and may not be able to devote sufficient time [added: or resources] to new product development, which could cause us to be less competitive as compared to our peers, lose out on new revenue opportunities and have an adverse effect on our growth and our business.
Recently, there also has been an increase in companies offering free or low-cost [removed: direct to consumer] [added: direct-to-consumer] credit services (such as credit scores, reports and monitoring) as part of alternative business models that use such services as a means to introduce consumers to other products and services.
Due to the 2017 cybersecurity incident and our provision of free services to consumers in connection therewith, we ceased the advertisement and sale of new products in our [removed: direct to consumer business,] [added: direct-to-consumer business from September 2017 through October 2018,] which resulted in a significant decline in revenue in that business.
Furthermore, in late January 2018, we began offering a new credit lock service, Lock & [removed: AlertTM,] [added: Alert™,] that is free for life and is aimed at empowering [added: U.S.] consumers to control access to their Equifax credit file directly and quickly from their smartphone or computer.
[removed: Additionally, if] [added: If] a significant number of consumers lock or freeze their file, our population of data is reduced which could affect our product offerings and value to our customers in our other businesses.
If [added: our systems do not meet customer requirements for response time or high availability, or] we experience system constraints or failures, or our customers do not modify and/or upgrade their systems to accept new releases of our products and services, our services to our customers could be delayed or interrupted, which could result in lost revenues or customers, lower margins, or other harm to our business and reputation.
In addition, [added: as part of our technology transformation,] we [removed: will] continue to be intensely focused on enhancing our data security infrastructure and [added: effecting our technology transformation strategy and] implementation of those enhancements could result in service interruptions.
Any significant [removed: delay or] [added: system] interruption [added: or series of minor interruptions] could result in [added: the loss of customers and/or] lost [removed: revenues or customers,] [added: revenues,] lower [removed: margins,] [added: margins] or other significant harm to our business or reputation.
See [removed: Item] [added: “Item] 1.
[removed: Business - "Governmental Regulation"] [added: Business—Governmental Regulation”] in this Form 10-K for a summary of the U.S. and foreign consumer and data protection laws and regulations to which we are subject.
Furthermore, we expect there to be an increased focus on laws and regulations related to our business because of the great public concern in the U.S. with regard to the operation of credit reporting agencies, as well as the collection, use, accuracy, correction and sharing of personal information, which was [added: in part] heightened by the 2017 cybersecurity incident.
[removed: For example, there] [added: There] are a number of legislative proposals pending before the U.S. Congress, various state legislative bodies and foreign governments concerning data protection [removed: due to our 2017 cybersecurity incident and other high-profile breaches] that could affect us and the President of the United States could act by Executive Order.
As we transition to cloud-based technologies, we may be exposed to additional cyber threats as we migrate our data from our legacy systems to cloud-based solutions.
Our increased dependence on third parties to store our cloud-based data systems may also subject us to further cyber threats.
Our $125.0 million cybersecurity insurance policy was not adequate to cover the losses we have incurred to date from the 2017 cybersecurity incident, and all future losses we incur as a result of the incident will not be covered by insurance.
While we believe it is beneficial to resolve the consolidated multi-district consumer class action and one or more of the government investigations in the U.S. through a global resolution, the complexity of achieving a multi-party resolution, especially involving multiple government agencies, makes this a difficult objective to achieve.
We may not have success in achieving a global resolution or even a resolution of any of these matters individually.
Our reputation with consumers and other stakeholders and our customer relationships were damaged following the 2017 cybersecurity incident, resulting in a negative impact on our revenue.
Additionally, certain of our payment card industry certifications were suspended.
These certifications, including the ISO 27001 certification, are critical to our business, because certain of our current and potential customers and the contracts governing certain customer relationships, as well as certain of our data suppliers, require us to maintain them as a requirement of doing business.
In 2018, significant focus was placed on remediation activities in order to obtain ISO and payment card industry re-certifications.
We have reacquired three independent ISO/IEC 27001:2013 certifications (representing our Corporate, U.K. and Canada environments) and two of our payment card industry certifications (U.K. and Canada).
In addition, we expect to obtain the
USIS and GCS payment card industry re-certification in 2019.
If we fail to maintain or regain these certifications, customers may stop doing business with us and we may not be able to win new business, which would negatively affect our revenue.
The failure to realize the anticipated benefits of our technology transformation strategy could adversely impact our business and financial results.
We expect our technology transformation strategy, including our transition to cloud-based technologies, will significantly increase our efficiency and productivity, the functionality of our products and services, as well as decrease the cost of our systems infrastructure, all of which we expect will drive growth and have a positive effect on our business, competitive position and results of operations.
This initiative is a major undertaking as we replace many of our previous operating systems with cloud-based systems.
This complex, multifaceted and extensive initiative will be expensive and may cause material unanticipated problems and expenses.
If our new systems do not operate as expected, we may have to incur significant additional costs to modify them.
Moreover, we may experience issues of customer migration, as many of our customers may choose not to utilize our products and services during and after our transition to cloud-based technologies.
We cannot assure you that our technology transformation strategy will be beneficial to the extent, or within the timeframes, expected, or that the estimated efficiency, cost savings and other improvements will be realized as anticipated or at all.
Market acceptance of cloud-based offerings is affected by a variety of factors, including information security, reliability, performance, the sufficiency of technological infrastructure to support our products and services in certain geographies, customer concerns with entrusting a third party to store and manage its data as well as the customer’s ability to access this data once a contract has expired, and consumer concerns regarding data privacy and the enactment of laws or regulations that restrict our ability to provide such services to customers.
If we are unable to correctly respond to these issues, we may experience business disruptions, damage to our reputation, negative publicity, diminished customer relationships and other adverse effects on our business.
Even if the anticipated benefits and savings are substantially realized, there may be consequences, internal control issues or business impacts that were not expected.
Our transition and migration to cloud-based technologies may increase our risk of liability and cause us to incur significant technical, legal or other costs.
Our technology transformation strategy places a significant strain on our management, operational, financial and other limited resources.
As part of our technology transformation strategy, we are transitioning and migrating our data systems from traditional data centers to cloud-based platforms.
This initiative will place significant strain on our management, personnel, operations, systems, technical performance and financial resources and internal financial control and reporting function.
In addition, many of our existing personnel do not have experience with native cloud-based technologies and, as a result, we have and will continue to hire personnel with such experience.
This effort will be time consuming and costly.
Our technology transformation strategy requires management time and resources to educate employees and implement new ways of conducting business.
The dedication of resources to our technology transformation strategy and cloud-based technologies limits the resources we have available to devote to other initiatives or growth opportunities, or to invest in the maintenance of our existing internal systems.
We cannot guarantee that our strategy is the right one or that investments in alternative technologies or other initiatives would not be a better use of our limited resources.
Additionally, as a result of our migration efforts in connection with our technology transformation strategy, we may experience a loss of continuity, loss of accumulated knowledge or loss of efficiency during transitional periods.
Reorganization and transition can require a significant amount of management and other employees’ time and focus, which may divert attention from operating activities and growing our business.
If we fail to achieve some or all of the expected benefits of these activities, it could have a material adverse effect on our competitive position, business, financial condition, results of operations and cash flows.
Our transition to cloud-based technologies could expose us to operational disruptions.
We rely on the efficient and uninterrupted operation of complex information technology systems and networks, some of which are managed internally within the Company and some of which are outsourced to third parties.
As part of our technology transformation strategy, we are upgrading the information technology systems used to operate our business and replacing them with cloud-based solutions.
This transition will require substantial changes to our software and network infrastructure, which could lead to system interruptions, affect our data systems and further expose us to operational disruptions, and cause us to lose customers, all of which could have a material adverse effect on our results of operations.
Upon implementation of the new cloud-based solutions, much of our information technology systems will consist of outsourced, cloud-based infrastructure, platform and software-as-a-service solutions not under our direct management or
The Company is in the process of notifying these additional consumers.
The actions we have taken are based on our investigation of the causes of the cybersecurity incident, but there will be additional changes needed to prevent a similar incident.
If such damages, costs,
Our revenue growth in 2017 as compared to 2016 was negatively impacted by the cybersecurity incident.
Certain of our customers have determined to defer or cancel new contracts or projects and others could consider such actions unless and until we can provide assurances regarding our ability to prevent unauthorized access to our systems and the data we maintain.
Many of our customers are requiring security audits of our systems and any negative results of such audits may cause further losses of customers.
Due to the 2017 cybersecurity incident, certain of our ISO certifications have been suspended and we will be required to take additional remediation steps to retain such certifications, which efforts may not be successful.
Additionally, certain of our payment card industry certifications have been suspended which could result in fines and loss of access to data if we are not able to complete the necessary remediation steps to retain these certifications, which would adversely affect our ability to offer certain products to customers.
use our credit information and related analytical services and data to process applications for new credit cards, automobile loans, home and equity loans and other consumer loans, and to manage their existing credit relationships.
business partners on acceptable terms or at all, or collect amounts owed to us from insolvent customers or business partners.
We expect services like our Lock & AlertTM to continue to increase, thereby eliminating the market for many consumer direct products and services.
As a result of these factors, we expect that revenue from our direct to consumer business will continue to decline.
For example, Ecuador passed a law in December 2017 that, if implemented, would effectively prohibit us from operating as a credit bureau within Ecuador unless we are selected to operate under contract to serve the public authority that the new law tasks with providing such services.
The federal banking agencies, including the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the Board of Governors of the Federal Reserve System and the CFPB, as well as many state banking agencies
In response to the 2017 cybersecurity incident, we also have been contacted by state banking regulators seeking to examine our practices as a third-party service provider to the entities that they regulate.
We also have a cost method investment in a credit information company in Brazil valued in Brazilian reais.
Economic and competition risks within Brazil, and the company’s ability to successfully implement its strategic and operating plans, have had an adverse financial impact on the value of our investment and could result in an additional impairment of the investment.
Over the past several years, we have acquired many smaller businesses in the U.S. and across the world.
Furthermore, during 2016, we acquired Veda, the leading provider of credit information and analysis in Australia and New Zealand, for cash consideration plus debt assumed of approximately $1.9 billion.
In January 2014, we acquired TDX, a debt placement service and debt management platform company in the United Kingdom for approximately $323 million.
Similarly, any divestitures will be accompanied by risks commonly encountered in the sale of businesses.
In addition, as a result of the 2017 cybersecurity incident and the resources and management attention required in connection therewith, there may be more limited resources available for acquisitions and management’s attention is likely to be diverted away from sourcing and developing potential acquisition and joint venture opportunities, resulting in decreased growth.
The application of many provisions in the Tax Cuts and Jobs Act of 2017 are uncertain at this time.
The impact on Equifax will not be fully known until further guidance is provided by the U.S. Treasury.
While the referendum was non-binding, the U.K. parliament has voted in favor of allowing the government to commence negotiations to determine the future terms of the U.K.’s relationship with the EU, including the terms of trade between the U.K. and the EU and other nations.
The effects of Brexit will depend on any agreements the U.K. makes to retain access to EU markets either during a transitional period or more permanently.
We are party to a $900.0 million unsecured, revolving credit facility that matures in November 2020 and an $800.0 million term loan facility that matures in November 2018 (collectively, the “Senior Credit Facilities”).
Facility or acceleration of any obligations outstanding thereunder.
Further, as a result of the cybersecurity incident we may suffer increased attrition.
An excerpt. Shown here: 40 of 70 rewritten, 40 of 65 added and all 29 removed. The counts are complete. For every sentence, read Item 1A. RISK FACTORS in the FY2018 filing and the FY2017 filing.
Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS
265 rewritten, 182 added, 227 removed, 367 unchanged
In [removed: fiscal] 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers.
Criminals exploited a [added: software vulnerability in a] U.S. website application [removed: vulnerability] to gain unauthorized access to our network.
Based on our forensic investigation, the unauthorized access [removed: of information] occurred from mid-May [added: 2017] through July 2017.
No evidence was found that the [removed: Company's] [added: Company’s] core consumer, employment and income, or commercial [removed: credit] reporting databases were accessed.
See [removed: Part I, Item] [added: “Item] 1A.
Risk [removed: Factors] [added: Factors”] and [removed: Part I, Item] [added: “Item] 3.
Legal [removed: Proceedings] [added: Proceedings” in this Form 10-K] for more information regarding these lawsuits and investigations.
We continue to cooperate with law enforcement in connection with the criminal investigation into the actors responsible for the [added: 2017] cybersecurity incident.
[removed: We have included $14.2 million of these expenses in Cost of services and $99.1 million in Selling, general] [added: general,] and administrative expenses in the accompanying Consolidated Statements of Income for the [removed: year] [added: twelve months] ended December 31, [removed: 2017.][added: 2018.]
[removed: Additionally, as] [added: As] a result of the [added: 2017] cybersecurity incident, we offered [removed: free] [added: TrustedID® Premier, a] credit file monitoring and identity theft protection [added: product, for free] to all [added: eligible] U.S. [removed: consumers.][added: consumers who signed up through January 31, 2018.]
[removed: We have] [added: Through December 31, 2017, we] recorded $50.7 million [removed: through December 31, 2017 included] [added: of product costs] in [removed: Selling,] [added: selling,] general and administrative expenses in the accompanying Consolidated Statements of Income.
As a result of the [added: 2017] cybersecurity incident, we are subject to a significant number of proceedings and investigations as described in Part I, [removed: "Item] [added: “Item] 3.
[removed: Legal Proceedings."] While we believe it is reasonably possible that we will incur losses associated with these proceedings and investigations, it is not possible to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of [removed: such] [added: the] proceedings and investigations based on the [removed: early stage] [added: various stages] of these proceedings and investigations, that alleged damages have not been [removed: specified,] [added: specified or are uncertain,] the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues.
We [added: also] expect to [added: continue to] incur increased expenses for insurance, finance, compliance activities, and to meet increased legal and regulatory requirements.
[removed: We maintain $125] [added: At the time of the 2017 cybersecurity incident, we had $125.0] million of cybersecurity insurance coverage, above a $7.5 million deductible, to limit our exposure to losses such as those related to [removed: the cybersecurity] [added: this] incident.
Global Consumer Solutions revenue is both transaction and subscription based and is derived from the sale of credit monitoring and identity theft protection products, which we deliver electronically to consumers primarily via the internet in the U.S., Canada, and the U.K. We [removed: reach consumers directly] [added: also sell consumer] and [removed: indirectly through partners.][added: credit information to resellers who combine our information with other information to provide direct-to-consumer monitoring, reports and scores.]
[removed: Due to the cybersecurity incident we ceased] advertising our consumer business in the U.S. in September 2017.
As part of our response to the [added: 2017] cybersecurity [removed: incident announced in September 2017,] [added: incident,] we [removed: began offering in the U.S.] [added: made] our [removed: TrustedID] [added: TrustedID®] Premier service, an identity theft protection and credit file monitoring product, [added: available] for free to all [added: U.S.] consumers [added: for twelve months for those] who signed up [removed: through] [added: by] January 31, 2018.
[removed: Additionally,] [added: As part of our commitment to providing long-term resources and protections for consumers,] in January 2018, the Company introduced [removed: in the U.S.,] Lock & [removed: AlertTM,] [added: Alert™,] a [removed: new] [added: mobile application enabled] service that allows [removed: customers] [added: U.S. consumers] to quickly lock and unlock their Equifax credit report for free, for life.
[removed: For consumers impacted by the cybersecurity incident in Canada and the U.K., we are providing] [added: We also provided] free credit reports and scores, credit monitoring and identity theft protection for [removed: 12] [added: twenty four] months [removed: for those] [added: to impacted] consumers [added: in Canada and the U.K. We have recorded the expenses necessary to provide this service to those] who signed [removed: up by January 31, 2018.][added: up.]
We currently have [removed: significant] operations in the following countries: Argentina, Australia, Canada, Chile, Costa Rica, Ecuador, El Salvador, Honduras, India, Mexico, New Zealand, Paraguay, Peru, Portugal, the Republic of Ireland, Spain, the U.K., Uruguay and the U.S. We also offer Equifax branded credit services in India and Russia through joint ventures, we have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and [removed: Dubai,] [added: the United Arab Emirates,] and have an investment in a consumer and commercial credit information company in Brazil.
Approximately 71% [removed: of] our revenue was generated in the U.S. during [added: both of] the twelve months ended December 31, [added: 2018 and] 2017.
Key performance indicators for the twelve months ended December 31, [removed: 2017, 2016] [added: 2018, 2017] and [removed: 2015,] [added: 2016,] include the following:
| | [removed: 2017] [added: 2018] | | | | [removed: 2016] [added: 2017] | | | | [removed: 2015] [added: 2016] | | |
| Operating revenue | $ | [removed: 3,362.2] [added: 3,412.1] | | | $ | [removed: 3,144.9] [added: 3,362.2] | | | $ | [removed: 2,663.6] [added: 3,144.9] | |
| Operating revenue change | [removed: 7] [added: 1] | | % | | [removed: 18] [added: 7] | | % | | [removed: 9] [added: 18] | | % |
| Net income attributable to Equifax | $ | [removed: 587.3] [added: 299.8] | | | $ | [removed: 488.8] [added: 587.3] | | | $ | [removed: 429.1] [added: 488.8] | |
| Diluted earnings per share | $ | [removed: 4.83] [added: 2.47] | | | $ | [removed: 4.04] [added: 4.83] | | | $ | [removed: 3.55] [added: 4.04] | |
| Cash provided by operating activities | $ | [removed: 816.0] [added: 672.2] | | | $ | [removed: 823.0] [added: 816.0] | | | $ | [removed: 769.1] [added: 823.0] | |
| Capital expenditures* | $ | [removed: (214.0] [added: (368.1] | ) | | $ | [removed: (191.5] [added: (214.0] | ) | | $ | [removed: (150.7] [added: (191.5] | ) |
*Amounts above [removed: exclude changes in] [added: include] accruals for capital expenditures.
In the United [removed: States] [added: States,] we expect [removed: 2018] [added: 2019] economic activity, as measured by GDP, to be [removed: about flat with] [added: down from the] levels seen in the second half of [removed: 2017.][added: 2018.]
We expect modest growth in consumer credit, excluding mortgage, over the course of [removed: 2018.][added: 2019.]
U.S. Mortgage market originations are expected to be [added: much weaker in the first half of 2019 and] down for the full year of [removed: 2018] [added: 2019] versus [removed: 2017.][added: 2018.]
We anticipate [removed: 2018] [added: 2019] economic activity, as measured by GDP, in Canada [removed: and Australia] to be [removed: at or] slightly below the levels seen in the second half of [removed: 2017.][added: 2018.]
In the European markets we serve, the [removed: U.K.] [added: U.K., Spain] and [removed: Spain,] [added: Portugal,] we are expecting [removed: 2018] [added: 2019] economic activity, as measured by GDP, to be at or slightly below the levels in [removed: calendar year 2017.][added: 2018.]
The [added: 2017] cybersecurity incident [removed: announced in the third quarter of 2017] is expected to [added: continue to] negatively impact revenue, principally in our [removed: U.S. businesses, and to a lesser extent in Canada] [added: USIS] and [removed: the U.K., in 2018.][added: Global Consumer Solutions businesses.]
We [added: have incurred, in 2018, and] will [removed: also] [added: continue to] incur, in [removed: 2018,] [added: 2019,] legal, consulting and other costs related to the analysis and response to the [added: 2017] cybersecurity incident.
Additionally, in 2018 and beyond, we [added: have incurred and] will [added: continue to] incur increased [removed: information technology and security] costs and capital expenditures related to [removed: actions to improve information] [added: our] technology [removed: security and network resilience globally.][added: transformation, which includes costs for enhanced data security.]
In 2018 and beyond, we [added: had and] will [added: continue to] have increases in the ongoing run-rate of [removed: IT] [added: technology] and security spending.
Equifax Inc. is a global data, analytics and technology company.
We provide information solutions and human resources business process outsourcing services for businesses, governments and consumers.
We have a large and diversified group of clients, including financial institutions, corporations, governments and individuals.
Our services are based on comprehensive databases of consumer and business information derived from numerous sources including credit, financial assets, telecommunications and utility payments, employment, income, demographic and marketing data.
We use advanced statistical techniques, machine learning and proprietary software tools to analyze available data to create customized insights, decision-making solutions and processing services for our clients.
We also provide information, technology and services to support debt collections and recovery management.
Additionally, we are a leading provider of payroll-related and human resource management business process outsourcing services in the United States of America, or U.S. For consumers, we provide products and services to help people understand, manage and protect their personal information and make more informed financial decisions.
We currently operate in four global regions: North America (U.S. and Canada), Asia Pacific (Australia, New Zealand and India), Europe (the United Kingdom, or U.K., Spain and Portugal) and Latin America (Argentina, Chile, Costa Rica, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay).
We maintain support operations in the Republic of Ireland, Chile, Costa Rica and India.
We also offer Equifax branded credit services in Russia and India through joint ventures, have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and the United Arab Emirates, and have an investment in a consumer and commercial credit information company in Brazil.
In March 2017, the U.S. Department of Homeland Security distributed a notice concerning the software vulnerability.
We undertook efforts to identify and remediate vulnerable systems; however, the vulnerability in the website application that was exploited was not identified by our security processes.
We discovered unusual network activity in late-July 2017 and upon discovery promptly investigated the activity.
Once the activity was identified as potential unauthorized access, we acted to stop the intrusion and engaged a leading, independent cybersecurity firm to conduct a forensic investigation to determine the scope of the unauthorized access, including the specific information impacted.
In 2018, the Company extended the free credit monitoring services for an additional twelve months for eligible consumers impacted by the 2017 cybersecurity incident by providing them the opportunity to enroll in Experian® IDNotify™ at no cost.
We recorded $20.4 million related to these services in selling,
Legal Proceedings” in this Form 10-K.
While we believe it is reasonably possible that we will incur losses associated with such proceedings and investigations, it is not possible at this time to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of the proceedings and investigations described in “Item 3.
Legal Proceedings” based on the various stages of these proceedings and investigations, that alleged damages have not been specified or are uncertain, the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues.
We are currently executing substantial initiatives in security and consumer support, and a company-wide transformation of our technology infrastructure, which we refer to as our technology transformation, and incurred substantial increased expenses and capital expenditures in 2018 related to these initiatives.
We expect to again incur significant expenses and capital expenditures in 2019 and 2020 related to these initiatives, although at levels slightly below those incurred in 2018.
We incurred significant legal and professional services expenses related to the lawsuits, claims and government investigations to which we are a party in 2018, and expect to continue to incur these expenses until these items are resolved.
We will recognize the expenses and capital expenditures referenced herein as they are incurred.
In 2018, we incurred elevated costs for insurance, finance and compliance activities, and expect to incur costs at these levels again in 2019.
During the twelve months ended December 31, 2018 and 2017, the Company recorded insurance recoveries of $75.0 million and $50.0 million, respectively, and received payments of $110.0 million and $15.0 million, respectively, for reimbursable costs incurred to date.
Since the announcement of the 2017 cybersecurity incident in September 2017, we have received the maximum reimbursement under the insurance policy of $125.0 million.
Due to the 2017 cybersecurity incident we ceased
We resumed advertising our U.S. paid products in the fourth quarter of 2018.
In late 2018, the Company extended the free credit file monitoring services for impacted consumers in the U.S. using the free TrustedID Premier® service by providing them the opportunity to enroll in Experian® IDNotify™ at no cost for an additional twelve months.
Similarly, for impacted consumers in Canada and the U.K., we provided free credit reports and scores, credit monitoring and identity theft protection for twenty four months.
| Operating income | $ | 448.0 | | | $ | 831.7 | | | $ | 825.1 | |
| Operating margin | 13.1 | | % | | 24.7 | | % | | 26.2 | | % |
In Australia, as measured by GDP, we anticipate 2019 economic activity to be below the levels seen in the second half of 2018 due to overall weakness in consumer credit markets.
In Latin America, our two largest markets are in Argentina and Chile.
In Argentina, the market weakened significantly in 2018.
We are expecting continued weakness in 2019 but at lower levels than in 2018.
In Chile, we are expecting economic activity in 2019 to be down slightly compared to 2018.
As a result of the 2017 cybersecurity incident, we are subject to a significant number of proceedings and investigations as described in “Item 3.
Legal Proceedings” in this Form 10-K.
The Company will continue to evaluate information as it becomes known and will record an estimate for losses at the time or times when it is both probable that a loss has been incurred and the amount of the loss is reasonably estimable.
We are a leading global provider of information solutions, employment and income verifications and human resources business process outsourcing services.
We leverage some of the largest sources of consumer and commercial data, along with advanced analytics and proprietary technology, to create customized insights which enable our business customers to grow faster, more efficiently and more profitably, and to inform and empower consumers.
Businesses rely on us for consumer and business credit intelligence, credit portfolio management, fraud detection, decisioning technology, marketing tools, debt management and human resources-related services.
We also offer a portfolio of products that enable individual consumers to manage their financial affairs and protect their identity.
Our revenue stream is diversified among businesses across a wide range of industries, international geographies and individual consumers.
The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers.
In addition, credit card numbers for approximately 209,000 U.S. and Canadian consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed.
The investigation determined that personal information of approximately 19,000 Canadian consumers was impacted and approximately 860,000 potentially affected U.K. consumers were contacted regarding access to personal information.
The forensic investigation of the cybersecurity incident was, as previously disclosed, completed in the fourth quarter of fiscal 2017.
The Company acted promptly to notify the approximately 145.5 million U.S. consumers whose personally identifiable information the Company had identified in 2017 as potentially accessed.
As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify approximately 2.4 million U.S. consumers whose name and partial driver’s license information were stolen, but who were not in the affected population of approximately 145.5 million consumers previously identified by the Company in 2017.
The Company is in the process of notifying these additional consumers.
Expenses Incurred.
Through December 31, 2017, the Company recorded $113.3 million of pretax expenses related to the cybersecurity incident.
Expenses include costs to investigate and remediate the cybersecurity incident and legal and other professional services related thereto, all of which were expensed as incurred.
We have recorded the expenses necessary to provide this service to those who signed up.
We expect to incur significant legal and other professional services expenses associated with the cybersecurity incident in future periods.
We will recognize these expenses as services are received.
Costs related to the cybersecurity incident that will be incurred in future periods will also include increased expenses and capital investments for IT and security.
We will also incur increased costs to provide free services to consumers including increased customer support costs.
As of December 31, 2017, the Company has recorded a receivable of $35.0 million and received payments of $15 million for costs incurred to date that are reimbursable and probable of recovery under our insurance coverage.
We also sell consumer and credit information to resellers who combine our information with other information to provide direct to consumer monitoring, reports and scores.
Equifax also will provide the ability for U.S. consumers to freeze and unfreeze their Equifax credit file for free through June 30, 2018.
We provide U.S. consumers with a free annual credit report in accordance with the FACT Act.
| Operating income | $ | 824.6 | | | $ | 817.9 | | | $ | 693.9 | |
| Operating margin | 24.5 | | % | | 26.0 | | % | | 26.1 | | % |
In Argentina and Chile, our two largest markets in our Latin American Region, we are expecting 2018 economic activity, again as measured by GDP, to increase from the levels in calendar year 2017.
In 2018, we will incur costs and capital expenditures for providing the free TrustedID credit file monitoring and identity theft protection, and free Lock & AlertTM, to U.S. consumers, as well as services to U.K. and Canadian consumers.
We also expect to incur increased expenses for insurance, finance, compliance activities, and to meet increased legal and regulatory requirements.
We also expect to incur increased costs to provide free services to consumers, including increased customer support costs.
Legal Proceedings." While we believe it is reasonably possible that we will incur losses associated
The Tax Cuts and Jobs Act of 2017 (“Tax Act”), as signed by the President of the United States on December 22, 2017, significantly revises U.S. tax law.
The legislation will positively impact the Company’s ongoing effective tax rate due to the reduction of the U.S. federal corporate tax rate from 35% to 21%.
The Tax Act makes major changes to the U.S. international tax system.
Under previous law, foreign earnings were subject to U.S. tax when repatriated to the U.S. Under the Tax Act, foreign earnings are generally exempt from U.S. tax.
Additionally, there is a one-time deemed repatriation tax on undistributed foreign earnings and profits (the “transition tax”).
The Tax Act imposes other U.S. taxes on “global intangible low taxed income” and “base erosion anti-abuse transactions.” Other significant changes include limitations on the deductibility of interest expense and executive compensation, and repeal of the deduction for domestic production activities.
As a result of the current interpretation and estimated impact of the Tax Act, the Company recorded adjustments totaling a net tax benefit of $48.3 million in the fourth quarter of 2017 to provisionally account or the estimated impact.
The growth was driven by broad-based organic growth due to revenue increases in mortgage, government, healthcare, and direct to consumer reseller verticals as well as the Veda acquisition.
| Consolidated selling, general and administrative expenses | | 1,039.1 | | | | 948.2 | | | | 884.3 | | | | 90.9 | | | | 10 | % | | 63.9 | | | | 7 | % |
An excerpt. Shown here: 40 of 265 rewritten, 40 of 182 added and 40 of 227 removed. The counts are complete. For every sentence, read Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS in the FY2018 filing and the FY2017 filing.
Item 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK
9 rewritten, 0 added, 0 removed, 18 unchanged
For the year ended December 31, [removed: 2016,] [added: 2018,] a 10% weaker U.S. dollar against the currencies of all foreign countries in which we had operations during [removed: 2016] [added: 2018] would have increased our revenue by [removed: $50.2] [added: $55.9] million and our pre-tax operating profit by [removed: $16.5] [added: $10.7] million.
A 10% stronger U.S. dollar would have resulted in similar decreases to our revenue and pre-tax operating profit for [removed: 2017] [added: 2018] and [removed: 2016.][added: 2017.]
On average across our mix of international businesses, foreign currencies at December 31, [removed: 2017,] [added: 2018] were weaker against the U.S. dollar than the average foreign exchange rates that prevailed across the full year [removed: 2017.][added: 2018.]
As a result, if foreign exchange rates were unchanged throughout [removed: 2018,] [added: 2019,] foreign exchange translation would reduce growth as reported in U.S. dollars.
As foreign exchange rates change daily, there can be no assurance that foreign exchange rates will remain constant throughout [removed: 2018,] [added: 2019,] and rates could go either higher or lower.
Our exposure to market risk for changes in interest rates relates to our variable-rate commercial [removed: paper] [added: paper, Revolver, and Floating Rate Senior Note] borrowings.
At December 31, [removed: 2017,] [added: 2018,] our weighted average cost of debt was [removed: 3.4%] [added: 3.8%] and weighted-average life of debt was [removed: 4.95] [added: 5.42] years.
At December 31, [removed: 2017, 61%] [added: 2018, 89%] of our debt was fixed rate, and the remaining [removed: 39%] [added: 11%] was variable rate.
A 100 basis point increase in the weighted-average interest rate on our variable-rate debt would have increased our [removed: 2017] [added: 2018] interest expense by [removed: $10.6] [added: $3.0] million.
Item 1. BUSINESS
101 rewritten, 49 added, 38 removed, 211 unchanged
[removed: Equifax Inc. is a leading global provider of] [added: We provide] information solutions and human resources [removed: business process] [added: business-process] outsourcing services for businesses, governments and consumers.
We use advanced statistical [removed: techniques] [added: techniques, machine learning] and proprietary software tools to analyze [removed: all] available [removed: data, creating] [added: data to create] customized insights, decision-making solutions and processing services for our clients.
[removed: We] [added: For consumers, we provide products and services to] help [removed: consumers] [added: people] understand, manage and protect their personal information and make more informed financial decisions.
We also provide information, technology and services to support debt collections and recovery [removed: management.][added: management in the U.K. and, to a lesser extent, in Spain.]
Additionally, we are a leading provider of payroll-related and human resource management business process outsourcing services in the United States of [removed: America, or U.S.][added: America (U.S.).]
We currently operate in four global regions: North America (U.S. and Canada), Asia Pacific [removed: (Australia and] [added: (Australia,] New [removed: Zealand),] [added: Zealand and India),] Europe (the United [removed: Kingdom, or U.K.,] [added: Kingdom (U.K.),] Spain and Portugal) and Latin America (Argentina, Chile, Costa Rica, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay).
We maintain support operations in the Republic of [removed: Ireland.][added: Ireland, Chile, Costa Rica and India.]
We also offer [removed: Equifax branded] [added: Equifax-branded] credit services in Russia and India through joint ventures, have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and [removed: Dubai,] [added: the United Arab Emirates,] and have an investment in a consumer and commercial credit information company in Brazil.
| • | U.S. Information Solutions (USIS) — provides consumer and commercial information solutions to businesses in the U.S. including online information, decisioning technology solutions, fraud and identity management services, [added: analytical services,] portfolio management services, mortgage reporting and [removed: financial] marketing services. |
| • | International [removed: —which includes our Asia Pacific, Europe, Canada and Latin America business units,] [added: —] provides products and services similar to those available in the USIS operating segment but with variations by geographic region. We also provide information, technology and services to support debt collections and recovery management. [added: This operating segment is comprised of our Canada, Europe, Latin America and Asia-Pacific business units.] |
| • | Workforce Solutions — provides services enabling [removed: clients] [added: customers] to verify income and employment (Verification Services) [added: of people in the U.S.,] as well as [added: providing our customers services] to outsource and automate the performance of certain payroll-related and human resource management business processes, including unemployment [removed: cost] [added: claims] management, tax credits and incentives and I-9 [added: and W-2 form] management services and services to allow employers to ensure compliance with the Affordable Care Act (Employer Services). [added: Workforce Solutions is in the process of establishing Verifications Services operations in Canada and Australia.] |
| • | Global Consumer Solutions — provides products to consumers in the [removed: United States, Canada,] [added: U.S., Canada] and the U.K., enabling them to understand and monitor their credit and monitor and help protect their identity. We also sell consumer [removed: and] credit information to resellers who combine our information with other information to provide [removed: direct to consumer] [added: direct-to-consumer] monitoring, reports and scores. |
In [removed: fiscal] 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers.
Criminals exploited a [added: software vulnerability in a] U.S. website application [removed: vulnerability] to gain unauthorized access to our network.
Based on our forensic investigation, the unauthorized access [removed: of information] occurred from mid-May [added: 2017] through July 2017.
No evidence was found that the [removed: Company's] [added: Company’s] core consumer, employment and income, or commercial [removed: credit] reporting databases were accessed.
See [removed: Item] [added: “Item] 1A.
Risk [removed: Factors] [added: Factors”] and [removed: Item] [added: “Item] 3.
Legal [removed: Proceedings] [added: Proceedings” in this Form 10-K] for more information regarding these lawsuits and investigations.
We continue to cooperate with law enforcement in connection with the criminal investigation into the actors responsible for the [added: 2017] cybersecurity incident.
[removed: Upon discovery of] [added: Once] the [added: activity was identified as potential] unauthorized access, we acted [removed: immediately] to stop the intrusion and [removed: promptly] engaged a leading, independent cybersecurity firm to conduct a [removed: comprehensive] forensic investigation to determine the scope of the [removed: intrusion,] [added: unauthorized access,] including the specific [removed: data potentially] [added: information] impacted.
The Company has [removed: also] taken [removed: action] [added: actions] to provide consumers with [removed: new] tools to protect credit data.
[removed: Immediately following the announcement of the breach, the Company devoted substantial resources to consumer notifications and launched and continuously enhanced multi-faceted consumer resources, including] [added: This included] making its [removed: TrustedID] [added: TrustedID®] Premier service, an identity theft protection and credit file monitoring product, available for free to all U.S. consumers for [removed: 12] [added: twelve] months for those who signed up by January 31, 2018.
Similarly, for consumers impacted by the [added: 2017] cybersecurity incident in Canada and the U.K., we [removed: are providing] [added: provided] free credit reports and scores, credit [removed: monitoring] [added: monitoring,] and identity theft protection for [removed: 12 months for those consumers who signed up by January 31, 2018.][added: twenty four months.]
As part of our commitment to providing long-term resources and protections for consumers, in January 2018, the Company introduced Lock & [removed: AlertTM,] [added: Alert™,] a [removed: new] [added: mobile application enabled] service that allows U.S. consumers to quickly lock and unlock their Equifax credit report for free, for life.
Our [removed: long-term corporate] [added: business] strategy is driven by the following imperatives:
[removed: | • | Deliver consistently strong profitable growth and shareholder returns.] We seek to enhance shareholder value through [added: the] disciplined execution of [removed: our strategic initiatives] [added: these imperatives] and by positioning ourselves as a premier and trusted provider of high value information solutions. [removed: |]
[removed: In addition to] [added: We offer a wide array of products, ranging from] custom products for large clients, [removed: we develop software as a service based,] [added: to software-as-a-service-based] decisioning and data access technology platforms that are [removed: cost effective] [added: cost-effective] for clients of all sizes.
[removed: We also develop] predictive scores and analytics, some of which leverage multiple data assets, to help clients acquire new customers and manage their existing customer relationships.
[removed: | • | Innovate for market leadership in key domains and verticals.] We seek to increase our share of clients’ spend on information-related services through [removed: developing and introducing] [added: these] new [removed: products, pricing] [added: products and services, price] our [added: products and] services in accordance with the value they represent to our customers, [removed: increasing] [added: increase] the range of current [added: products and] services utilized by our clients, and [removed: improving] [added: improve] the quality and effectiveness of our [removed: sales organization and client] support [removed: interactions with consumers. We are also helping clients address increased requirements to comply with emerging regulations] [added: for both customers] and [removed: rules. |][added: consumers.]
| • | [removed: Invest] [added: Build a world-class Equifax team by investing] in talent to drive our strategy and [removed: foster] [added: promote] a culture of innovation. We attract top talent by [removed: continuing] [added: providing opportunities] to [removed: expand] [added: grow] and [removed: diversify] [added: lead within] our [removed: talent pipeline.] [added: company.] We regularly undertake [removed: various] talent initiatives to engage, [removed: develop,] [added: develop] and retain our top talent. |
[removed: ][added: ]
| (1) | Predominantly sold to companies who serve the [removed: direct to consumer] [added: direct-to-consumer] market and includes other small end user markets. [added: Mortgage and auto resellers are excluded from this category as they are included within their respective categories above.] |
Our largest geographic [removed: market segments] [added: global regions] are the U.S.; Asia Pacific [removed: (Australia and] [added: (Australia,] New [removed: Zealand);] [added: Zealand and India);] Europe (the U.K., Spain and Portugal); Canada; and Latin America (Argentina, Chile, Costa Rica, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay).
Revenue from international clients, including end users and resellers, amounted to 29% of our total revenue in [removed: 2017, 27%] [added: 2018, 29%] of our total revenue in [removed: 2016] [added: 2017] and [removed: 23%] [added: 27%] of our total revenue in [removed: 2015.][added: 2016.]
The data and insights are then processed through proprietary software and [added: generally] transmitted to the client’s operating system to execute the decision.
| [removed: Direct to consumer] [added: Direct-to-consumer] credit monitoring | | | | | | | | | X | | | | | | | | | | X | |
For the operating revenue, operating income and total assets for each segment see Note [removed: 13] [added: 12] of the Notes to the Consolidated Financial Statements in this report.
We also sell consumer and credit information to resellers who [added: may] combine our information with other information to provide services to the financial, mortgage, fraud and identity management, and other end-user markets.
Our Mortgage Solutions products, offered in the U.S., consist of specialized credit reports that combine information from the three major consumer credit reporting agencies (Equifax, Experian [removed: Group] and TransUnion) into a single “merged” credit report in an online format, commonly referred to as a tri-merge report.
Equifax Inc. is a global data, analytics and technology company.
In March 2017, the U.S. Department of Homeland Security distributed a notice concerning the software vulnerability.
We undertook efforts to identify and remediate vulnerable
systems; however, the vulnerability in the website application that was exploited was not identified by our security processes.
We discovered unusual network activity in late-July 2017 and upon discovery promptly investigated the activity.
Immediately following the announcement of the 2017 cybersecurity incident, the Company devoted substantial resources to notify people of the incident and to provide free services to assist people in monitoring their credit and identity information.
In late 2018, the Company extended the free credit file monitoring services for impacted consumers in the U.S. using the free TrustedID Premier® service by providing them the opportunity to enroll in Experian® IDNotify™ at no cost for an additional twelve months.
Our vision is to be a trusted global leader in data, advanced analytics and technology that creates innovative solutions and insights for our customers.
| • | Lead our industry in data security. Building on the progress we made following the 2017 cybersecurity incident, we are focused on becoming a leader in our industry in the effectiveness of our data and technology security practices. This includes building an Equifax culture that considers data and technology security, and more broadly risk management, as a primary requirement in all decisions. This also includes the extensive use of advanced data and technology security tools, techniques, services and processes in order to enhance our ability to protect the information with which we are entrusted from fraudulent access. |
| • | Transform our technology. We plan to rebuild our technology infrastructure, accelerate our migration to a public cloud environment, employ virtual private cloud deployment techniques, and rationalize and rebuild our application portfolio using cloud-focused services. This technology transformation is a significant enabler to our goal of leading our industry in data and technology security capability. Our goal is to deliver market-leading capabilities to our customers in terms of speed of bringing new products and services to market; ease of customer and partner implementation and integration; ease of consumer access to and interaction with Equifax, our systems and data; system resiliency and uptime; and ultimately cost to serve. We are approximately one year into our multi-year technology transformation, which is already broadly impacting our internal and external information technology systems. |
| • | Lead in data and analytics, to develop unparalleled analytical insights leveraging Equifax’s unique data. We use proprietary advanced analytical platforms, including capabilities in machine learning and advanced visualization tools, to leverage our unique data to develop leading analytical insights that enhance the precision of our customers’ decisioning activities. We strive to continue to advance these capabilities through ongoing data monetization activities, the acquisition of distinctive and differentiated assets, and continued advancement of capabilities in artificial intelligence and machine learning. As part of our technology transformation, we are investing to simplify our customers’ access to our leading analytical platforms, in order to speed the development of unique insights and the conversion of these insights into new products and services consumable by our customers through our delivery platforms. |
We also develop
| • | Improve the consumer user experience. Equifax understands the importance of providing consumers with user-friendly capabilities to see, understand and question their consumer credit file and information. As part of our technology transformation, we are rebuilding our digital and call center technology infrastructure to provide an experience focused on making consumers’ interactions with Equifax as effective and efficient as possible. |
| • | Foster a culture of customer centricity. We are focused on building a culture in which the customer is at the center of our decision processes, and we exceed customer expectations by delivering solutions with speed, flexibility, stability and performance. Our focus on customer centricity will enable us to be more proactive in solving problems better and faster for customers while delivering enhanced operational readiness to provide a better customer experience. |
| • | Deliver growth while enhancing profitability and shareholder returns. We strive to accelerate innovation through expanded customer focus and collaboration. We intend to leverage our unique data assets and capabilities, as well as customer expertise and data and technology assets, to help us jointly create high-value analytical products and services targeted at a broader range of customer needs. We seek to expand partnerships in order to further broaden the key customer domains and verticals that our products and services are able to serve. |
We believe there are opportunities to continue to expand in the U.S. and internationally, across the existing financial, mortgage, telecommunications, automotive, insurance, healthcare, government and other markets that we serve, as well as in new and emerging market segments.
We continue to invest, including through acquisitions and partnerships, to expand our addressable markets, and the data and capabilities we offer to solve customer challenges ranging from identity authentication to risk management.
We maintain support operations in the Republic of Ireland, Chile, Costa Rica, and India.
We also offer Equifax branded credit services in Russia and India through joint ventures, have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and the United Arab Emirates, and have an investment in a consumer and commercial credit information company in Brazil.
These business units offer products that are similar to those available in the USIS operating segment, but with variations by geographic region.
In the U.K., this includes a contract to provide these services to the U.K. government.
We also have an investment in a consumer and commercial credit information company in Brazil.
automate a variety of credit decisions.
Employers provide this data to us so that we can handle verification requests on behalf of each employer.
Workforce Solutions is in the process of building income and employment verification service businesses in Canada and Australia, including establishing The Work Number® in each country.
At present, revenues from these services in Canada and Australia are insignificant.
Country specific versions of our products are available to consumers in the U.S., Canada, and the U.K. primarily over the internet.
We resumed limited advertising of our consumer business in the U.S. in the fourth quarter of 2018.
In late 2018, the Company extended the free credit file and identity monitoring services for impacted
consumers in the U.S. using the free TrustedID® Premier service, by providing them the opportunity to enroll in Experian® IDNotify™ at no cost for an additional twelve months.
Mortgage related revenue is generally higher in the second and third quarters of the year due to the increase in consumer home purchasing during the summer in the U.S.
| • | The New York State Department of Financial Services (“NYDFS”) has enacted regulatory requirements applicable to CRAs that require registration with that agency, prohibit unfair and deceptive consumer practices and require compliance with significant portions of the NYDFS cybersecurity rules. |
| • | We may also become subject to and affected by new and proposed state privacy laws such as the California Consumer Privacy Act which takes effect in 2020 and which will impose additional data privacy requirements on many businesses operating in the state, including, potentially, with respect to employee data in addition to consumer data. A number of states, such as Maryland, Massachusetts and Washington, appear to be following California’s lead and have introduced comprehensive data privacy legislation modeled after the California Consumer Privacy Act or the European General Data Protection Regulation. |
| • | State banking and financial services regulatory agencies have asserted either express or implied authority under applicable state laws to examine us as a third-party service provider to financial institutions, and in certain cases to bring enforcement actions against us. Generally, such examinations, and related enforcement actions, are focused on assessing our safety and soundness in support of financial institutions we serve. |
| • | In Europe, we are subject to the European General Data Protection Regulation (“GDPR”). The GDPR establishes multiple data protection requirements that are more specific and comprehensive than those of the U.S. and most |
other countries where Equifax operates.
In addition, the GDPR includes data breach notification requirements and it establishes the ability of regulators to pursue substantial penalties for non-compliance.
| | |
| --- | --- |
| | |
Background.
The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers.
In addition, credit card numbers for approximately 209,000 U.S. and Canadian consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed.
The investigation determined that personal information
of approximately 19,000 Canadian consumers was impacted and approximately 860,000 potentially affected U.K. consumers were contacted regarding access to personal information.
The forensic investigation of the cybersecurity incident was, as previously disclosed, completed in the fourth quarter of fiscal 2017.
The Company acted promptly to notify the approximately 145.5 million U.S. consumers whose personally identifiable information the Company had identified in 2017 as potentially accessed.
As a result of an ongoing analysis of data stolen in the 2017 cybersecurity incident, the Company recently announced that it was able to identify approximately 2.4 million U.S. consumers whose name and partial driver’s license information were stolen, but who were not in the affected population of approximately 145.5 million consumers previously identified by the Company in 2017.
The Company is in the process of notifying these additional consumers.
Regaining Trust.
The Company has taken and continues to take extensive steps designed to prevent this type of incident from happening again and to earn back the trust of consumers, customers and regulators.
We have continued to analyze the data impacted, including through the use of external data providers, to identify and inform consumers who may have been impacted by this incident.
Following the cybersecurity incident, we began undertaking significant steps to enhance our data security infrastructure.
In connection with these efforts, we have incurred significant costs and expect to incur additional significant costs as we take further steps to prevent unauthorized access to our systems and the data we maintain.
The actions we have taken are based on our investigation of the causes of the cybersecurity incident, but there will be additional changes needed to prevent a similar incident.
We have also enhanced our disclosure controls and procedures and related protocols to specifically provide that cyber incidents are promptly escalated and investigated and reported to senior management, and where appropriate, to the Board of Directors.
We also engaged an independent outside consulting firm to help us with both strategic remediation activities and to review our cybersecurity framework, our controls framework and our management and employees' roles and responsibilities.
In the third and fourth quarters of 2017, our Board made strategic changes to our executive leadership team and added an independent director to our Board with highly-relevant skills in data security.
Our Board also formed a Special Committee to conduct an independent review of the cybersecurity incident, the Company’s response to it and all relevant policies and practices.
The Special Committee's investigation was undertaken with the assistance of outside professionals engaged by the Special Committee.
We believe this is a meaningful step toward fulfilling our commitment to give consumers the power to protect and control access to personal credit data.
Data is at the core of our value proposition and the protection and safeguarding of that information is paramount.
Our strategic objective is to be the global leader in information solutions that creates unparalleled insights to solve customer challenges.
Leveraging our extensive resources, we deliver differentiated decisions through a broad and diverse set of data assets, sophisticated analytics and proprietary decisioning technology.
| • | Serve as a trusted steward and advocate for consumers and our customers. This includes protecting and safeguarding the information we have using advanced data security tools, techniques and processes in order to protect consumer specific information from fraudulent access. We also strive to continuously improve the consumer and customer experience in our consumer and commercial offerings, anticipating and executing on regulatory initiatives, while simultaneously delivering industry leading security for our services. |
| • | Develop unparalleled analytical insights leveraging Equifax unique data. We continue to invest in and acquire unique sources of credit and non-credit information to enhance the variety and quality of our services while increasing clients’ confidence in information-based business decisions. Areas of focus for investment in new sources of data include, among others, positive payment data, fraud and personal identification data, real estate data and new commercial business data. We also have developed unique capabilities to integrate customer and third-party data into our solution offerings to further enhance the decisioning solutions we develop for our customers. |
We continue to invest in and develop new technology to enhance the security, functionality and cost-effectiveness of the services we offer and further differentiate our products from those offered by our competitors.
We believe there are many opportunities to expand into emerging markets both in the U.S. and internationally.
In the U.S., we have increased and broadened resources in key markets, including financial, mortgage, auto, insurance, telecommunications, healthcare and government, and we are delivering services ranging from identity authentication to risk management.
We continue to invest in growing our ventures in Russia and India and leveraging our newer product offerings across all of our geographical business units and periodically enter new country markets through acquisitions or start-up operations.
Our commercial products, such as business credit reporting and commercial risk management services, are available mostly in the U.K, with a more limited set of information solutions products sold in Portugal and Spain.
our decisioning products that facilitate pre-approved offers of credit and automate a variety of credit decisions.
Employers contract to provide this data for specified periods under the terms of contracts which range from one to five years.
Consumers can obtain credit file information about them and Equifax or FICO credit scores.
Additionally, in January 2018, the Company introduced in the U.S., Lock & AlertTM, a new
We provide U.S. consumers with a free annual credit report in accordance with the FACT Act.
| • | Most states and the District of Columbia have passed laws that give consumers the right to place a security freeze on their credit reports to prevent others from opening new accounts or obtaining new credit in their name. These laws place differing requirements on credit reporting agencies with respect to how and when to respond to such credit file freeze requests and in the fees, if any, the agencies may charge for freeze-related actions. |
| • | In Europe, we are subject to the European Union (“EU”) Data Protection Regulation ("GDPR"), which will replace the comprehensive 1995 European Union Data Protection Directive. The GDPR maintains the prohibition on the transfer of personal information from the EU to other countries whose laws do not protect personal data to an “adequate” level of privacy or security. The GDPR establishes multiple new requirements that are generally stricter and more comprehensive than those of the U.S. and most other countries where Equifax operates. In Spain and Portugal, privacy laws also regulate all credit bureau and personal solutions activities. The GDPR, among other things, will tighten data protection requirements and make enforcement more rigorous, for example, by streamlining enforcement at a European level, introducing data breach notification requirements and substantially increasing penalties for non-compliance. |
An excerpt. Shown here: 40 of 101 rewritten, 40 of 49 added and all 38 removed. The counts are complete. For every sentence, read Item 1. BUSINESS in the FY2018 filing and the FY2017 filing.
Item 3. LEGAL PROCEEDINGS
20 rewritten, 82 added, 16 removed, 37 unchanged
[removed: Following the 2017 cybersecurity incident, hundreds] [added: Hundreds] of class actions were filed [removed: by consumers] against us in [removed: federal, state] [added: federal] and [removed: Canadian] [added: state] courts relating to the [added: 2017] cybersecurity incident.
The plaintiffs in these cases, who purport to represent various classes of [removed: consumers,] [added: U.S. consumers and small businesses,] generally claim to have been harmed by alleged actions and/or omissions by Equifax in connection with the [added: 2017] cybersecurity incident and assert a variety of common law and statutory claims seeking monetary damages, injunctive relief and other related relief.
In addition, certain class actions have been filed by financial institutions [removed: who] [added: that] allege their businesses have been placed at risk due to the [added: 2017] cybersecurity incident and generally assert various common law claims such as claims for negligence and breach of contract, as well as, in some cases, statutory claims.
The financial [removed: institutions] [added: institution] class actions seek compensatory [removed: damages] [added: damages, injunctive relief] and other related relief.
Furthermore, a lawsuit has been filed [added: against us] by the City of Chicago with respect to the [added: 2017] cybersecurity incident alleging violations of state laws and local ordinances governing protection of personal data, consumer [removed: fraud and] [added: fraud,] breach notice requirements and business [removed: practices.][added: practices and seeking declaratory and injunctive relief and the imposition of fines the aggregate amount of which the complaint does not specifically quantify.]
Beginning on December 6, 2017 and pursuant to multiple subsequent orders, the U.S. Judicial Panel on Multidistrict Litigation ordered the consolidation and transfer for pre-trial proceedings with respect to the U.S. cases pending in federal court discussed [removed: above] [added: above, including the City of Chicago action, the Indian Tribal suits, and the Puerto Rico action,] to the Northern District of Georgia as the single U.S. District Court for centralized [removed: proceedings.][added: pre-trial proceedings (the “MDL Court”).]
Based on [removed: this order,] [added: these orders,] consolidated [removed: pre-trial hearings] [added: proceedings] with respect to U.S. consumer and financial institution federal class actions [added: and other lawsuits] related to the [added: 2017] cybersecurity incident have [removed: begun] [added: been conducted] in the [removed: Northern District of Georgia.][added: MDL Court.]
We dispute the allegations in the complaints described [removed: above] [added: below] and intend to defend against such claims.
[removed: In addition, we] [added: We] continue to cooperate with federal, state, city and foreign governmental agencies and officials investigating or otherwise seeking [removed: information] [added: information, testimony] and/or documents, including through Civil Investigative [removed: Demands,] [added: Demands and subpoenas,] regarding the [added: 2017] cybersecurity incident and related matters, including [removed: 49] [added: 48] state Attorneys General offices, [removed: as well as] the District of Columbia, the Federal Trade [removed: Commission,] [added: Commission (“FTC”),] the Consumer [removed: Finance] [added: Financial] Protection [removed: Bureau,] [added: Bureau (“CFPB”),] the U.S. Securities and Exchange Commission (“SEC”), the U.S. Department of Justice, [removed: the New York Department of Financial Services, the New York Department of State - Division of Consumer Protection,] other U.S. state regulators, [removed: including state banking regulators, the Financial Industry Regulatory Authority,] certain Congressional committees of both the U.S. Senate and House of Representatives, the [removed: United Kingdom’s Financial Conduct Authority (“FCA”), the Information Commissioner’s] Office [removed: in the United Kingdom and the Office] of the Privacy Commissioner of [removed: Canada.][added: Canada (“OPC”) and the U.K.’s Financial Conduct Authority (“FCA”).]
Although we are actively cooperating with [removed: these] [added: the above] investigations and inquiries, an adverse outcome to any such investigations and inquiries could subject us to fines or other obligations, which may have an adverse effect on how we operate our business or our results of operations.
In addition, we continue to cooperate with the SEC and the U.S. Attorney’s Office for the Northern District of Georgia regarding investigations into the trading activities by certain of our [added: current and former] employees in relation to the [added: 2017] cybersecurity incident.
A consolidated putative class action lawsuit alleging violations of [removed: the] [added: various] federal securities laws in connection with statements [added: and alleged omissions] regarding our cybersecurity systems and controls is pending against us and certain of our current and former [added: executives,] officers and directors in the [added: U.S. District Court for the] Northern District of Georgia.
The [removed: complaints seek] [added: consolidated complaint seeks] certification of a class of all persons who purchased or otherwise acquired Equifax securities [removed: during a set period of time] [added: from February 25, 2016 through September 15, 2017] and unspecified monetary damages, costs and attorneys’ fees.
[removed: Four] [added: A consolidated] putative shareholder derivative [removed: lawsuits have been commenced in the Northern District of Georgia] [added: action] naming certain of our current and former [added: executives,] officers and directors as defendants and naming us as a nominal [removed: defendant.][added: defendant is pending in the U.S. District Court for the Northern District of Georgia.]
Among other things, the [removed: complaints allege] [added: consolidated complaint alleges] claims for breaches of fiduciary duties, unjust enrichment, corporate [removed: waste,] [added: waste] and insider selling by certain [removed: defendants.][added: defendants, as well as certain claims under the federal securities laws.]
The [removed: Complaints seek] [added: complaint seeks] unspecified damages on behalf of the Company, plus certain equitable relief.
[added: We have appointed] a committee of independent directors empowered to evaluate and respond in our best interests to the claims and related litigation demands.
[removed: The Company continues] [added: We continue] to cooperate with the [removed: ACCC] [added: NYDFS] in its investigation.
California Bankruptcy [removed: Litigation.][added: Litigation]
A Final Fairness Hearing was held on December 11, [removed: 2017.][added: 2017 and on April 6, 2018, the Court granted final approval.]
Litigation and Investigations related to the 2017 Cybersecurity Incident
Since the 2017 cybersecurity incident, hundreds of class actions and other lawsuits have been filed against us typically alleging harm from the 2017 cybersecurity incident and seeking various remedies, including monetary and injunctive relief.
In addition, numerous governmental agencies are investigating us in connection with the 2017 cybersecurity incident, which may result in fines, settlements or other relief.
Set forth below are descriptions of the main categories of these lawsuits and investigations.
Multidistrict Litigation.
Three Indian Tribes filed suits in federal court asserting putative class actions relating to the 2017 cybersecurity incident brought on behalf of themselves and other similarly situated federally recognized Indian Tribes and Nations.
Additionally, the Commonwealth of Puerto Rico filed an action on its own behalf and on behalf of the people of Puerto Rico arising out of the 2017 cybersecurity incident.
The MDL Court has established separate tracks for the consumer and financial institution class action cases and appointed lead counsel on behalf of plaintiffs in both tracks.
Certain individual plaintiffs with cases pending in the MDL consolidated proceedings, including Puerto Rico and the City of Chicago, have sought the establishment of additional tracks and other related relief.
The MDL Court has not yet ruled on those requests.
The Company moved to dismiss the consolidated class action complaints filed by the U.S. consumer, small business and financial institution plaintiffs in their entirety.
On January 28, 2019, the MDL Court dismissed the small businesses’ consolidated class action complaint in its entirety.
The MDL Court dismissed certain claims brought by the consumer and financial institution plaintiffs, while allowing other claims by those plaintiffs to proceed.
Pursuant to case management orders issued by the MDL Court, consolidated pre-trial proceedings, including discovery between the parties, will proceed on the remaining claims of the U.S. consumer and financial institution plaintiffs.
Georgia State Court Consumer Class Actions.
Four putative class actions arising from the 2017 cybersecurity incident were filed against us in Fulton County Superior Court and Fulton County State Court in Georgia based on similar allegations and theories as alleged in the U.S. consumer class actions pending in the MDL Court and seek monetary damages, injunctive relief and other related relief on behalf of Georgia citizens.
These cases have been transferred to a single judge in the Fulton County Business Court and three of the cases were consolidated into a single action.
On July 27, 2018, the Fulton County Business Court granted the Company’s motion to stay the remaining single case, and on August 17, 2018, the Fulton County Business Court granted the Company’s motion to stay the consolidated case.
Canadian Class Actions.
Seven Canadian class actions, five of which are on behalf of a national class of approximately 19,000 Canadian consumers, have been filed against us in Ontario, Saskatchewan, Quebec and British Columbia.
Each of the proposed Canadian class actions asserts a number of common law and statutory claims seeking monetary damages and other related relief in connection with the 2017 cybersecurity incident.
The plaintiffs in each case seek
class certification/authorization on behalf of Canadian consumers whose personal information was allegedly impacted by the 2017 cybersecurity incident.
In some cases, plaintiffs also seek class certification on behalf of Canadian consumers who had contracts for subscription products with Equifax around the time of the incident.
All purported class actions are at preliminary stages, and we are opposing class certification or authorization in cases where such motions are pending.
In addition, one of the cases in Ontario as well as the Saskatchewan case have been stayed.
The Court’s order staying the Saskatchewan case is on appeal.
On January 26, 2018, we moved to dismiss TransUnion’s claims.
On June 19, 2018, the court granted in part and denied in part our motion to dismiss, dismissing Equifax Inc. from the case.
Discovery has now commenced and is scheduled to end in March 2019.
The Company moved to dismiss the consolidated class action complaint in its entirety.
On January 28, 2019, the court dismissed claims against certain individual defendants and claims challenging certain statements, but allowed other claims against Equifax and our former Chairman and Chief Executive Officer to proceed.
Pursuant to scheduling and case management orders issued by the court, pre-trial proceedings, including discovery between the parties, will proceed on the remaining claims.
Government Lawsuits.
In addition to the City of Chicago’s and Commonwealth of Puerto Rico’s lawsuits in the MDL Court, the City of San Francisco filed a lawsuit against us in Superior Court in the City of San Francisco on behalf of the People of the State of California alleging violations of California’s unfair competition law due to purported violations of statutory protections of personal data and statutory data breach requirements and seeking statutory penalties, injunctive relief, and restitution for California consumers, among other relief.
The court has stayed the City of San Francisco action until March 29, 2019.
Civil enforcement actions have been filed against us by the Attorneys General of Massachusetts and West Virginia alleging violations of commonwealth/state consumer protection laws.
The Massachusetts action is pending in Suffolk Superior Court and seeks permanent injunctive relief, civil penalties, restitution, disgorgement of profits, costs and attorneys’ fees.
The Suffolk Superior Court denied the Company’s motions to stay and dismiss the case, and the case is in discovery.
The West Virginia action is pending in the Circuit Court of Boone County and seeks civil penalties and attorneys’ fees.
Cybersecurity Incident Litigation, Claims and Government Investigations.
In addition to these federal court proceedings, four putative class actions arising from the cybersecurity incident have been filed in the Fulton County Superior Court in Georgia.
We have also appeared or notified the appropriate parties of representation in the Canadian class actions, but such actions are all at the preliminary stages.
In addition, a civil enforcement action has been filed by the Attorney General of Massachusetts and a lawsuit has been filed by the City of San Francisco, each of which are in the initial pre-trial stages.
On January 26, 2018, we moved to dismiss TransUnion’s claims, and discovery in the case has been stayed until a ruling on that motion is issued.
We dispute the allegations in these complaints and intend to defend against the claims.
Three of the complaints also allege claims for violations of certain federal securities laws.
Certain plaintiffs have filed motions seeking consolidation of the actions and appointment as lead plaintiffs.
We have appointed
It is not possible at this time to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of the above described proceedings and investigations based on the early stage of these proceedings and investigations, that alleged damages have not been specified, the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues.
Additional lawsuits and claims related to the 2017 cybersecurity incident may be asserted by or on behalf of consumers, customers, shareholders or others seeking damages or other related relief and additional inquiries from governmental agencies may be received or investigations by governmental agencies commenced.
ACCC Investigation.
The Company expects that the ACCC will commence proceedings.
If this occurs the ACCC may seek restitution, civil monetary penalties, injunctive and declaratory relief or other corrective action.
Upon issuance of a Final Order by the Court, any appeals will be due within thirty days.
Other.
An excerpt. Shown here: all 20 rewritten, 40 of 82 added and all 16 removed. The counts are complete. For every sentence, read Item 3. LEGAL PROCEEDINGS in the FY2018 filing and the FY2017 filing.
Cover and table of contents
28 rewritten, 4 added, 5 removed, 64 unchanged
For the fiscal year ended December 31, [removed: 2017][added: 2018]
Indicate by check mark whether the Registrant has submitted electronically [removed: and posted on its corporate Web site, if any,] every Interactive Data File required to be submitted [removed: and posted] pursuant to Rule 405 of Regulation S-T during the preceding 12 months (or for such shorter period that the Registrant was required to submit [removed: and post] such files).
As of June 30, [removed: 2017,] [added: 2018,] the aggregate market value of Registrant’s common stock held by non-affiliates of Registrant was approximately [removed: $16,541,237,155] [added: $15,064,356,603] based on the closing sale price as reported on the New York Stock Exchange.
At January 31, [removed: 2018,] [added: 2019,] there were [removed: 120,123,872] [added: 120,699,888] shares of Registrant’s common stock outstanding.
Portions of Registrant’s definitive proxy statement for its [removed: 2018] [added: 2019] annual meeting of shareholders are incorporated by reference in Part III of this Form 10-K.
| [Item [removed: 1.](#s6E566B2A6AE650F6AAB851E14FD45438)] [added: 1.](#s6CEF638C65FE5BDCBA68F0FF81CF4185)] | [removed: [Business](#s6E566B2A6AE650F6AAB851E14FD45438)] [added: [Business](#s6CEF638C65FE5BDCBA68F0FF81CF4185)] | [removed: [2](#s6E566B2A6AE650F6AAB851E14FD45438)] [added: [2](#s6CEF638C65FE5BDCBA68F0FF81CF4185)] |
| [Item [removed: 1A.](#s468ABF5E487F5008BA195DF9D606BFEB)] [added: 1A.](#s2CD171311EAB51079D318CDF03CE8730)] | [Risk [removed: Factors](#s468ABF5E487F5008BA195DF9D606BFEB)] [added: Factors](#s2CD171311EAB51079D318CDF03CE8730)] | [removed: [14](#s468ABF5E487F5008BA195DF9D606BFEB)] [added: [15](#s2CD171311EAB51079D318CDF03CE8730)] |
| [Item [removed: 1B.](#s524449EAAF395CB7A9C6DC46184737FE)] [added: 1B.](#s711B2A9D35DD5EAEB35AAC83B81B938C)] | [Unresolved Staff [removed: Comments](#s524449EAAF395CB7A9C6DC46184737FE)] [added: Comments](#s711B2A9D35DD5EAEB35AAC83B81B938C)] | [removed: [24](#s524449EAAF395CB7A9C6DC46184737FE)] [added: [26](#s711B2A9D35DD5EAEB35AAC83B81B938C)] |
| [Item [removed: 2.](#s930B58F790B550F0B5FBC3D14C9884FD)] [added: 2.](#s82245D1210C55515BBBC0D18598C41AF)] | [removed: [Properties](#s930B58F790B550F0B5FBC3D14C9884FD)] [added: [Properties](#s82245D1210C55515BBBC0D18598C41AF)] | [removed: [24](#s930B58F790B550F0B5FBC3D14C9884FD)] [added: [26](#s82245D1210C55515BBBC0D18598C41AF)] |
| [Item [removed: 3.](#s6FD17AF03F9C55A18CC79437A1877E9A)] [added: 3.](#s7A87BF89CE525F14A7F6526015997D0B)] | [Legal [removed: Proceedings](#s6FD17AF03F9C55A18CC79437A1877E9A)] [added: Proceedings](#s7A87BF89CE525F14A7F6526015997D0B)] | [removed: [25](#s6FD17AF03F9C55A18CC79437A1877E9A)] [added: [27](#s7A87BF89CE525F14A7F6526015997D0B)] |
| [Item [removed: 4.](#s697EB92089FC5B3C803F959FBBE132DE)] [added: 4.](#sD8270E2A71CF5CCA9B0CB2E8F55FC74B)] | [Mine Safety [removed: Disclosures](#s697EB92089FC5B3C803F959FBBE132DE)] [added: Disclosures](#sD8270E2A71CF5CCA9B0CB2E8F55FC74B)] | [removed: [27](#s697EB92089FC5B3C803F959FBBE132DE)] [added: [30](#sD8270E2A71CF5CCA9B0CB2E8F55FC74B)] |
| [Item [removed: 5.](#sBC075F6B2E31563CA883A8028A6C2C1D)] [added: 5.](#sDF04D797833255AE8F025E73FACAF4B2)] | [Market for the Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity [removed: Securities](#sBC075F6B2E31563CA883A8028A6C2C1D)] [added: Securities](#sDF04D797833255AE8F025E73FACAF4B2)] | [removed: [28](#sBC075F6B2E31563CA883A8028A6C2C1D)] [added: [31](#sDF04D797833255AE8F025E73FACAF4B2)] |
| [Item [removed: 6.](#s01CCCB71746A5C0F97BCEBA6A0D0D52A)] [added: 6.](#s2BB1D1B5D5F652908717EE3CB68179A6)] | [Selected Financial [removed: Data](#s01CCCB71746A5C0F97BCEBA6A0D0D52A)] [added: Data](#s2BB1D1B5D5F652908717EE3CB68179A6)] | [removed: [31](#s01CCCB71746A5C0F97BCEBA6A0D0D52A)] [added: [33](#s2BB1D1B5D5F652908717EE3CB68179A6)] |
| [Item [removed: 7.](#sC86C4ECEF084508080DA533647A6308A)] [added: 7.](#s7518C0CC2CD752F3A7ECBE9A10F1F47C)] | [Management’s Discussion and Analysis of Financial Condition and Results of [removed: Operations](#sC86C4ECEF084508080DA533647A6308A)] [added: Operations](#s7518C0CC2CD752F3A7ECBE9A10F1F47C)] | [removed: [34](#sC86C4ECEF084508080DA533647A6308A)] [added: [35](#s7518C0CC2CD752F3A7ECBE9A10F1F47C)] |
| [Item [removed: 7A.](#s05A23922E4875F4DB7B04D65DBC533CF)] [added: 7A.](#s4DA5A674B09D5FD6993698C7E762149C)] | [Quantitative and Qualitative Disclosures About Market [removed: Risk](#s05A23922E4875F4DB7B04D65DBC533CF)] [added: Risk](#s4DA5A674B09D5FD6993698C7E762149C)] | [removed: [59](#s05A23922E4875F4DB7B04D65DBC533CF)] [added: [58](#s4DA5A674B09D5FD6993698C7E762149C)] |
| [Item [removed: 8.](#s23AE7BFD70EB59BBB3A416EC7D5D2392)] [added: 8.](#s6C3FC24D24D852A7AA832F84A40C917C)] | [Financial Statements and Supplementary [removed: Data](#s23AE7BFD70EB59BBB3A416EC7D5D2392)] [added: Data](#s6C3FC24D24D852A7AA832F84A40C917C)] | [removed: [60](#s23AE7BFD70EB59BBB3A416EC7D5D2392)] [added: [59](#s6C3FC24D24D852A7AA832F84A40C917C)] |
| [Item [removed: 9.](#s900ECDCF4ACA5B94A8B1302251DD015B)] [added: 9.](#s2991760D6A245FB9B1A4B5B1FF17F61F)] | [Changes in and Disagreements with Accountants on Accounting and Financial [removed: Disclosure](#s900ECDCF4ACA5B94A8B1302251DD015B)] [added: Disclosure](#s2991760D6A245FB9B1A4B5B1FF17F61F)] | [removed: [109](#s900ECDCF4ACA5B94A8B1302251DD015B)] [added: [115](#s2991760D6A245FB9B1A4B5B1FF17F61F)] |
| [Item [removed: 9A.](#s1969D00021215CD3B21960A74CC7518B)] [added: 9A.](#sAB03EB669A325238AD3B99C26A605024)] | [Controls and [removed: Procedures](#s1969D00021215CD3B21960A74CC7518B)] [added: Procedures](#sAB03EB669A325238AD3B99C26A605024)] | [removed: [109](#s1969D00021215CD3B21960A74CC7518B)] [added: [115](#sAB03EB669A325238AD3B99C26A605024)] |
| [Item [removed: 9B.](#sb0639ef512c44c1a9c29fd0837fceca9)] [added: 9B.](#s716C0559AED952B5A1B379A639136798)] | [Other [removed: Information](#sb0639ef512c44c1a9c29fd0837fceca9)] [added: Information](#s716C0559AED952B5A1B379A639136798)] | [removed: [110](#sb0639ef512c44c1a9c29fd0837fceca9)] [added: [115](#s716C0559AED952B5A1B379A639136798)] |
| [PART [removed: III](#s5CBA16667AAE560FABA7C9700CCB18A1)] [added: III](#sBB0F13ACA1145B7E9F12F08725D75C28)] | | |
| [Item [removed: 10.](#sB8AD25D9A0DA5E35AAA4B215F7077291)] [added: 10.](#s1E777C4C0B8453059A4FE08AA3CD3EAF)] | [Directors, Executive Officers and Corporate [removed: Governance](#sB8AD25D9A0DA5E35AAA4B215F7077291)] [added: Governance](#s1E777C4C0B8453059A4FE08AA3CD3EAF)] | [removed: [110](#sB8AD25D9A0DA5E35AAA4B215F7077291)] [added: [116](#s1E777C4C0B8453059A4FE08AA3CD3EAF)] |
| [Item [removed: 11.](#s24891C96B2CB5057988EF8DF94F2F40B)] [added: 11.](#s5073E0983CDD57EA978AD7D0CF09AB4D)] | [Executive [removed: Compensation](#s24891C96B2CB5057988EF8DF94F2F40B)] [added: Compensation](#s5073E0983CDD57EA978AD7D0CF09AB4D)] | [removed: [111](#s24891C96B2CB5057988EF8DF94F2F40B)] [added: [117](#s5073E0983CDD57EA978AD7D0CF09AB4D)] |
| [Item [removed: 12.](#s14A7BC9F4594566990A652B5840FFDC1)] [added: 12.](#sB9815A93D5EA5AA8BAA0BBBBAB198D8D)] | [Security Ownership of Certain Beneficial Owners and Management and Related Stockholder [removed: Matters](#s14A7BC9F4594566990A652B5840FFDC1)] [added: Matters](#sB9815A93D5EA5AA8BAA0BBBBAB198D8D)] | [removed: [111](#s14A7BC9F4594566990A652B5840FFDC1)] [added: [117](#sB9815A93D5EA5AA8BAA0BBBBAB198D8D)] |
| [Item [removed: 13.](#sFC5A547F57C35C23AA8C4C694D6DC57D)] [added: 13.](#s0A851A2EF1AB5C2B824EC2A04E3DA2F4)] | [Certain Relationships and Related Transactions, and Director [removed: Independence](#sFC5A547F57C35C23AA8C4C694D6DC57D)] [added: Independence](#s0A851A2EF1AB5C2B824EC2A04E3DA2F4)] | [removed: [111](#sFC5A547F57C35C23AA8C4C694D6DC57D)] [added: [117](#s0A851A2EF1AB5C2B824EC2A04E3DA2F4)] |
| [Item [removed: 14.](#sBB9E46681CCF5E55AE6785BC400CA444)] [added: 14.](#sE2B193B4A76E59249FE2796F2E708134)] | [Principal Accountant Fees and [removed: Services](#sBB9E46681CCF5E55AE6785BC400CA444)] [added: Services](#sE2B193B4A76E59249FE2796F2E708134)] | [removed: [112](#sBB9E46681CCF5E55AE6785BC400CA444)] [added: [117](#sE2B193B4A76E59249FE2796F2E708134)] |
| [PART [removed: IV.](#s084DC0EDC34251EC96276A067C8C9837)] [added: IV.](#s2ABECBA3E34A543CB8E790618C6BF60C)] | | |
| [Item [removed: 15.](#s85B96C1D0439566CB805B5525C794CB5)] [added: 15.](#s061D18C1DB9B57FEBC27D052355974AF)] | [Exhibits and Financial Statement [removed: Schedules](#s85B96C1D0439566CB805B5525C794CB5)] [added: Schedules](#s061D18C1DB9B57FEBC27D052355974AF)] | [removed: [113](#s85B96C1D0439566CB805B5525C794CB5)] [added: [118](#s061D18C1DB9B57FEBC27D052355974AF)] |
| [Item [removed: 16.](#s775e3425ebc947beb4e6b53de2fb00fe)] [added: 16.](#s6A28015A6CE5506DAD9336C10F49055E)] | [Form 10-K [removed: Summary](#s775e3425ebc947beb4e6b53de2fb00fe)] [added: Summary](#s6A28015A6CE5506DAD9336C10F49055E)] | [removed: [116](#s775e3425ebc947beb4e6b53de2fb00fe)] [added: [121](#s6A28015A6CE5506DAD9336C10F49055E)] |
10-K 1 efx10k20181231.htm 10-K
| [PART I](#sB3485942E1925276A581D62C40DEC0E2) | | |
| [PART II](#sE096ABAC29A95906B78BA7CA21F44096) | | |
| | [Signatures](#s664C52B84DAC5804825E9E2E05518D78) | [121](#s664C52B84DAC5804825E9E2E05518D78) |
10-K 1 efx10k20171231.htm 10-K
| | | | (Do not check if a smaller reporting company) | | | | | |
| [PART I](#sE25B6872C3C05E888A8FCDB8EA45B509) | | |
| [PART II](#s3CCEB7D3D1695005B229551C19E49143) | | |
| | [Signatures](#s2684C68915C2577DB21B7C4C84AB13E4) | [116](#s2684C68915C2577DB21B7C4C84AB13E4) |
Item 2. PROPERTIES
3 rewritten, 0 added, 1 removed, 4 unchanged
We ordinarily lease office space for conducting our business and are obligated under approximately [removed: 80] [added: 100] leases and other rental arrangements for our field locations.
We owned 8 office buildings at December 31, [removed: 2017,] [added: 2018,] including our executive offices, one campus which houses our Alpharetta, Georgia data center, a building utilized by our Workforce Solutions operations located in St. Louis, Missouri, as well as three buildings utilized by our Latin America operations located in Mexico City, Mexico and Asuncion, Paraguay.
For additional information regarding our obligations under leases, see Note 6 of the Notes to Consolidated Financial Statements in this [removed: report.][added: Form 10-K.]
We also own 23.5 acres adjacent to the Alpharetta, Georgia data center.
Item 5. MARKET FOR THE REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
15 rewritten, 0 added, 20 removed, 20 unchanged
Equifax’s common stock is traded on the New York Stock Exchange under the symbol “EFX.” As of January 31, [removed: 2018,] [added: 2019,] Equifax had approximately [removed: 2,206] [added: 3,330] holders of record; however, Equifax believes the number of beneficial owners of common stock exceeds this number.
The graph assumes that the value of the investment in our Common Stock and each index was $100 on the last trading day of [removed: 2012] [added: 2013] and that all quarterly dividends were reinvested without commissions.
[removed: ][added: ]
| | Initial | | | [removed: 2013 | | |] 2014 | | | 2015 | | | 2016 | | | 2017 | | [added: | 2018 | |]
| Equifax Inc. | 100.00 | | | [removed: 129.52 | | |] 153.68 | | | 214.06 | | | 226.90 | | | 228.22 | | [added: | 143.32 | |]
| S&P 500 Index | 100.00 | | | [removed: 132.39 | | |] 150.51 | | | 152.59 | | | 169.24 | | | 205.24 | | [added: | 150.33 | |]
| S&P 500 Banks Index (Industry Group) | 100.00 | | | [removed: 132.25 | | |] 149.79 | | | 148.23 | | | 178.13 | | | 214.75 | | [added: | 148.30 | |]
The table below contains information with respect to purchases made by or on behalf of Equifax of its common stock during the fourth quarter ended December 31, [removed: 2017:][added: 2018:]
| October 1 - October 31, [removed: 2017] [added: 2018] | | [removed: 48,395] [added: 540] | | | $ | — | | | — | | | $ | 590,092,166 | |
| November 1 - November 30, [removed: 2017] [added: 2018] | | [removed: 450] [added: 295] | | | $ | — | | | — | | | $ | 590,092,166 | |
| December 1 - December 31, [removed: 2017] [added: 2018] | | [removed: 958] [added: 7,044] | | | $ | — | | | — | | | $ | 590,092,166 | |
| Total | | [removed: 49,803] [added: 7,879] | | | $ | — | | | — | | | $ | 590,092,166 | |
| (1) | The total number of shares purchased [removed: includes:] [added: includes, if applicable:] (a) shares purchased pursuant to our publicly-announced share repurchase program, or Program; and (b) shares surrendered, or deemed surrendered, in satisfaction of the exercise price and/or to satisfy tax withholding obligations in connection with the exercise of employee stock options and vesting of restricted stock, totaling [removed: 48,395] [added: 540] shares for the month of October [removed: 2017, 450] [added: 2018, 295] shares for the month of November [removed: 2017] [added: 2018] and [removed: 958] [added: 7,044] shares for the month of December [removed: 2017.] [added: 2018.] |
| (3) | [removed: Under the Program, we repurchased 0.5 million] [added: We did not repurchase any] common shares during the twelve months ended December 31, [removed: 2017 for $77.1 million.] [added: 2018.] At December 31, [removed: 2017,] [added: 2018,] the amount authorized for future share repurchases under the Program was $590.1 million. |
Information relating to compensation plans under which the Company’s equity securities are authorized for issuance is included in the section captioned “Equity Compensation Plan Information” in our [removed: 2018] [added: 2019] Proxy Statement and is incorporated herein by reference.
The table below sets forth the high and low sales prices per share of Equifax common stock, as reported on the New York Stock Exchange, for each quarter in the last two fiscal years and dividends declared per share:
| | | | | | | | | | | | |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| | High Sales Price | | | | Low Sales Price | | | | Dividends (1) | | |
| 2017 | | | | | | | | | | | |
| First Quarter | $ | 137.76 | | | $ | 116.31 | | | $ | 0.39 | |
| Second Quarter | $ | 144.00 | | | $ | 131.62 | | | $ | 0.39 | |
| Third Quarter | $ | 147.02 | | | $ | 89.59 | | | $ | 0.39 | |
| Fourth Quarter | $ | 120.77 | | | $ | 105.31 | | | $ | 0.39 | |
| 2016 | | | | | | | | | | | |
| First Quarter | $ | 114.67 | | | $ | 91.72 | | | $ | 0.33 | |
| Second Quarter | $ | 128.41 | | | $ | 113.09 | | | $ | 0.33 | |
| Third Quarter | $ | 136.97 | | | $ | 127.85 | | | $ | 0.33 | |
| Fourth Quarter | $ | 134.56 | | | $ | 110.87 | | | $ | 0.33 | |
| | |
| --- | --- |
| (1) | Equifax’s Senior Credit Facilities, as defined in Note 5 of the Notes to Consolidated Financial Statements in this Form 10-K, restricts our ability to pay cash dividends on our capital stock or repurchase capital stock if a default exists or would result according to the terms of the credit agreement. |
We anticipate continuing the payment of quarterly cash dividends.
The actual amount of such dividends is subject to declaration by our Board of Directors and will depend upon future earnings, results of operations, capital requirements, our financial condition and other relevant factors.
There can be no assurance that the Company will continue to pay quarterly cash dividends at current levels or at all.
Item 6. SELECTED FINANCIAL DATA
21 rewritten, 5 added, 11 removed, 32 unchanged
The summary of operations data for the years ended December 31, [added: 2018,] 2017, [added: and] 2016, [removed: 2015,] and the balance sheet data as of December 31, [removed: 2017] [added: 2018] and [removed: 2016,] [added: 2017,] have been derived from our audited Consolidated Financial Statements included in this report.
The summary of operations data for the years ended December 31, [removed: 2014] [added: 2015] and [removed: 2013,] [added: 2014,] and the balance sheet data as of December 31, [removed: 2015, 2014] [added: 2016, 2015] and [removed: 2013,] [added: 2014,] have been derived from our audited Consolidated Financial Statements not included in this report.
| | [removed: 2017] [added: 2018] (1) (2) | | | | [removed: 2016] [added: 2017] (3) [added: (4)] | | | | [removed: 2015 (4)(5)] [added: 2016 (5)] | | | | [removed: 2014] [added: 2015] (6) [added: (7)] | | | | [removed: 2013(7)(8)] [added: 2014 (8)] | | |
| Operating revenue | $ | [removed: 3,362.2] [added: 3,412.1] | | | $ | [removed: 3,144.9] [added: 3,362.2] | | | $ | [removed: 2,663.6] [added: 3,144.9] | | | $ | [removed: 2,436.4] [added: 2,663.6] | | | $ | [removed: 2,303.9] [added: 2,436.4] | |
| Consolidated income from continuing operations | [removed: 598.0] [added: 306.3] | | | | [removed: 495.1] [added: 598.0] | | | | [removed: 434.8] [added: 495.1] | | | | [removed: 374.0] [added: 434.8] | | | | [removed: 341.5] [added: 374.0] | | |
| Net income attributable to Equifax | $ | [removed: 587.3] [added: 299.8] | | | $ | [removed: 488.8] [added: 587.3] | | | $ | [removed: 429.1] [added: 488.8] | | | $ | [removed: 367.4] [added: 429.1] | | | $ | [removed: 351.8] [added: 367.4] | |
| Dividends paid to Equifax shareholders | $ | [removed: 187.4] [added: 187.9] | | | $ | [removed: 157.6] [added: 187.4] | | | $ | [removed: 137.8] [added: 157.6] | | | $ | [removed: 121.2] [added: 137.8] | | | $ | [removed: 106.7] [added: 121.2] | |
| Net income [removed: from continuing operations] attributable to Equifax | $ | [removed: 4.83] [added: 2.47] | | | $ | [removed: 4.04] [added: 4.83] | | | $ | [removed: 3.55] [added: 4.04] | | | $ | [removed: 2.97] [added: 3.55] | | | $ | [removed: 2.69] [added: 2.97] | |
| Cash dividends declared per share | $ | 1.56 | | | $ | [removed: 1.32] [added: 1.56] | | | $ | [removed: 1.16] [added: 1.32] | | | $ | [removed: 1.00] [added: 1.16] | | | $ | [removed: 0.88] [added: 1.00] | |
| Weighted-average shares outstanding (diluted) | [removed: 121.5] [added: 121.4] | | | | [removed: 121.1] [added: 121.5] | | | | [removed: 120.9] [added: 121.1] | | | | [removed: 123.5] [added: 120.9] | | | | [removed: 123.7] [added: 123.5] | | |
| Total assets | $ | [removed: 7,233.4] [added: 7,153.2] | | | $ | [removed: 6,664.0] [added: 7,233.4] | | | $ | [removed: 4,501.5] [added: 6,664.0] | | | $ | [removed: 4,661.0] [added: 4,501.5] | | | $ | [removed: 4,522.5] [added: 4,661.0] | |
| Short-term debt and current maturities | [removed: 965.3] [added: 4.9] | | | | [removed: 585.4] [added: 965.3] | | | | [removed: 49.3] [added: 585.4] | | | | [removed: 380.4] [added: 49.3] | | | | [removed: 296.5] [added: 380.4] | | |
| Long-term debt, net of current portion | [removed: 1,739.0] [added: 2,630.6] | | | | [removed: 2,086.8] [added: 1,739.0] | | | | [removed: 1,138.4] [added: 2,086.8] | | | | [removed: 1,145.7] [added: 1,138.4] | | | | [removed: 1,145.5] [added: 1,145.7] | | |
| Total debt, net | [removed: 2,704.3] [added: 2,635.5] | | | | [removed: 2,672.2] [added: 2,704.3] | | | | [removed: 1,187.7] [added: 2,672.2] | | | | [removed: 1,526.1] [added: 1,187.7] | | | | [removed: 1,442.0] [added: 1,526.1] | | |
| Total equity | [removed: 3,239.0] [added: 3,155.7] | | | | [removed: 2,721.3] [added: 3,239.0] | | | | [removed: 2,350.4] [added: 2,721.3] | | | | [removed: 2,234.6] [added: 2,350.4] | | | | [removed: 2,341.0] [added: 2,234.6] | | |
| [removed: (1)] [added: (3)] | [removed: Through] [added: During the year ended] December 31, 2017, the Company recorded $164.0 million of [removed: pretax] [added: pre-tax] expenses related to the [added: 2017] cybersecurity incident and insurance recoveries of $50.0 million for net expenses of $114.0 million. [removed: We included $14.2 million of these expenses in Cost of services and $99.8 million in Selling, general and administrative expenses in the accompanying Consolidated Statements of Income for the year ended December 31, 2017.] Expenses include costs to investigate and remediate the [added: 2017] cybersecurity incident and legal and other professional services related thereto, all of which were expensed as incurred. Additionally, as a result of the [added: 2017] cybersecurity incident, we offered free credit file monitoring and identity theft protection to all U.S. consumers. We [removed: have] recorded the expenses necessary to provide this [added: service to those who signed up during 2017. For additional information, see Note 6 of the Notes to the Consolidated Financial Statements in this report.] |
| [removed: (2)] [added: (4)] | The Tax Cuts and Jobs Act of 2017 (“Tax Act”), as signed by the President of the United States on December 22, 2017, significantly [removed: revises] [added: revised] U.S. tax law. The legislation [removed: will] positively [removed: impact] [added: impacted] the Company’s ongoing effective tax rate due to the reduction of the U.S. federal corporate tax rate from 35% to 21%. The Tax Act [removed: makes] [added: made] major changes to the U.S. international tax system. Under previous law, foreign earnings were subject to U.S. tax when repatriated to the U.S. Under the Tax Act, foreign earnings are generally exempt from U.S. tax. Additionally, there is a one-time deemed repatriation tax on undistributed foreign earnings and profits (the “transition tax”). The Tax Act imposes other U.S. taxes on “global intangible low taxed income” and “base erosion anti-abuse transactions.” Other significant changes [removed: include] [added: included] limitations on the deductibility of interest expense and executive compensation, and repeal of the deduction for domestic production activities. As a result of the current interpretation and estimated impact of the Tax Act, the Company recorded adjustments totaling a net tax benefit of $48.3 million in the fourth quarter of 2017 to provisionally account for the estimated impact. Refer to Note 7 of the Notes to the Consolidated Financial Statements in this Form 10-K for additional information. We also prospectively applied the provisions of ASU 2016-09 [removed: "Compensation] [added: “Compensation] - Stock Compensation (Topic [removed: 718),"] [added: 718),”] related to the recognition of windfall tax benefits in the Consolidated Statement of Income which resulted in the recognition of $26.7 million of tax benefits for the year ended December 31, 2017. |
| [removed: (3)] [added: (5)] | In the first quarter of 2016, we completed the acquisition of 100% of the ordinary voting shares of Veda for cash consideration plus debt assumed of approximately $1.9 billion. [removed: The acquisition provides a strong platform for Equifax to offer data and analytic services and further broaden the Company's geographic footprint. Additionally, on August 23, 2016, the Company completed the acquisition of 100% of the assets and certain liabilities of unemployment tax and claims management specialists Barnett & Associates ("Barnett"), as well as the verifications business, Computersoft, LLC ("Computersoft").] For the year ended December 31, 2016, we recorded $40.2 million ($28.2 million, net of tax) for Veda acquisition related amounts. Of this amount, $30.1 million relates to transaction and integration costs in operating income, $9.2 million is recorded in other income and is the impact of foreign currency changes on the transaction structure, including the economic hedges, $0.2 million is recorded in depreciation and amortization, and $0.7 million is recorded in interest expense. [removed: For additional information, see Note 3 of the Notes to the Consolidated Financial Statements in this report.] |
| [removed: (4)] [added: (6)] | In the first quarter of 2015, we recorded a $20.7 million restructuring charge ($13.2 million, net of tax) all of which was recorded in [removed: Selling,] [added: selling,] general and administrative expenses on our Consolidated Statements of Income. This charge resulted from our continuing efforts to realign our internal resources to support the Company’s strategic objectives and increase the integration of our global operations. [removed: For additional information, see Note 12 of the Notes to Consolidated Financial Statements in this report.] |
| [removed: (5)] [added: (7)] | During the second quarter of 2015, the management of Boa Vista Servicos S.A. [removed: ("BVS"),] [added: (“BVS”),] in which we hold a 15% cost method investment, updated the financial projections of BVS. The updated projections, along with the continued weakness in the Brazilian consumer and small commercial credit markets were considered indicators of impairment. As a result of these changes, and the associated near-term changes in cash flow expected from the business, we recorded a 46.0 million Brazilian Reais ($14.8 million) impairment of our investment. [removed: For additional information, see Note 2 of the Notes to Consolidated Financial Statements in this report.] |
| [removed: (6)] [added: (8)] | During the first quarter of 2014, we acquired 100% of the stock of TDX, a data, technology and services company in the United Kingdom that specializes in debt collections and recovery management through the use of analytics, data exchanges and technology platforms. The results of this acquisition have been included in our USIS and International operating segments subsequent to the acquisition. [removed: We also purchased Forseva, a provider of end-to-end, cloud-based credit-management software solutions. The results of this acquisition have been included in our USIS operating segment subsequent to the acquisition.] |
| Operating expenses | 2,964.1 | | | | 2,530.5 | | | | 2,319.8 | | | | 1,963.6 | | | | 1,794.5 | | |
| Operating income | 448.0 | | | | 831.7 | | | | 825.1 | | | | 700.0 | | | | 641.9 | | |
| | 2018 (1) (2) | | | | 2017 (3) (4) | | | | 2016 (5) | | | | 2015 (6) (7) | | | | 2014 (8) | | |
| (1) | During the year ended December 31, 2018, the Company recorded $401.2 million of pre-tax expenses related to the 2017 cybersecurity incident and insurance recoveries of $75.0 million for net expenses of $326.2 million. Costs related to the 2017 cybersecurity incident are defined as incremental costs to transform our information technology infrastructure and data security; legal fees and professional services costs to investigate the 2017 cybersecurity incident and respond to legal, government and regulatory claims; as well as costs to provide the free product and related support to the consumer. |
| (2) | During the fourth quarter of 2018, we recorded a restructuring charge of $46.1 million all of which is recorded in selling, general, and administrative expenses in our Consolidated Statements of Income. The restructuring charge primarily relates to a reduction in headcount to support the Company’s strategic objectives and increase the integration of our global operations. For additional information, see Note 11 of the Notes to the Consolidated Financial Statements in this report. |
| Operating expenses | 2,537.6 | | | | 2,327.0 | | | | 1,969.7 | | | | 1,798.2 | | | | 1,692.7 | | |
| Operating income | 824.6 | | | | 817.9 | | | | 693.9 | | | | 638.2 | | | | 611.2 | | |
| Discontinued operations, net of tax (7) | — | | | | — | | | | — | | | | — | | | | 18.4 | | |
| Discontinued operations attributable to Equifax | — | | | | — | | | | — | | | | — | | | | 0.15 | | |
| Net income attributable to Equifax | $ | 4.83 | | | $ | 4.04 | | | $ | 3.55 | | | $ | 2.97 | | | $ | 2.84 | |
service to those who signed up.
For additional information, see Note 6 of the Notes to the Consolidated Financial Statements in this report.
| (7) | During the first quarter of 2013, we divested two non-strategic business lines, Equifax Settlement Services, which was part of our Mortgage business within the USIS operating segment, and Talent Management Services, which was part of our Employer Services business within our Workforce Solutions operating segment, for a total of $47.5 million. We have presented the Equifax Settlement Services and Talent Management Services operations as discontinued operations for all periods presented. |
| (8) | During the fourth quarter of 2013, the management of BVS, in which we hold a 15% cost method investment, revised its near-term outlook and its operating plans to reflect reduced near-term market expectations for credit information services in Brazil and increased investment needed to achieve its strategic objectives. As a result of these changes, and the |
associated near-term changes in cash flow expected from the business, we recorded a 40 million Brazilian Reais ($17.0 million) impairment of our original investment of 130 million Brazilian Reais.
For additional information, see Note 2 of the Notes to Consolidated Financial Statements in this report.
Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA
617 rewritten, 397 added, 281 removed, 1,053 unchanged
| [Report of Independent Registered Public Accounting Firm on Internal Control over Financial [removed: Reporting](#s1113DA15E19A5244B525426934303EC8)] [added: Reporting](#sFC1FA9956B145D9FB76C8948508BB353)] | [removed: [61](#s1113DA15E19A5244B525426934303EC8)] [added: [60](#sFC1FA9956B145D9FB76C8948508BB353)] |
| [Report of Independent Registered Public Accounting [removed: Firm](#s312DE077CC6A507782302BA8D5261E45)] [added: Firm](#s249321F8CA2D5976ADC29AF302C59958)] | [removed: [62](#s312DE077CC6A507782302BA8D5261E45)] [added: [61](#s249321F8CA2D5976ADC29AF302C59958)] |
| [Consolidated Statements of Income for each of the three years in the period ended December 31, [removed: 2017](#s7AA66B24C4A853FBBC140B891CA5EECD)] [added: 2018](#s314E4ECBE013591796B4BD347FF2D7AE)] | [removed: [63](#s7AA66B24C4A853FBBC140B891CA5EECD)] [added: [62](#s314E4ECBE013591796B4BD347FF2D7AE)] |
| [Consolidated Statements of Comprehensive Income for each of the three years in the period ended December 31, [removed: 2017](#sC91CC07A4E645FE2923FE380678F6EEB)] [added: 2018](#sCBCAF4DDFC6B56D285941ECEDCCF81C3)] | [removed: [64](#sC91CC07A4E645FE2923FE380678F6EEB)] [added: [63](#sCBCAF4DDFC6B56D285941ECEDCCF81C3)] |
| [Consolidated Balance Sheets at December 31, [removed: 2017] [added: 2018] and [removed: 2016](#sF523F303454956D4B04873E809CCEF66)] [added: 2017](#s1617D262E13D5F6FB40B83017CC8D82C)] | [removed: [65](#sF523F303454956D4B04873E809CCEF66)] [added: [64](#s1617D262E13D5F6FB40B83017CC8D82C)] |
| [Consolidated Statements of Cash Flows for each of the three years in the period ended December 31, [removed: 2017](#sD9408B2FD86D57F7A5D839F2EF742746)] [added: 2018](#sCB095CAC1AF45BAAA4852F7C53A6AE94)] | [removed: [66](#sD9408B2FD86D57F7A5D839F2EF742746)] [added: [65](#sCB095CAC1AF45BAAA4852F7C53A6AE94)] |
| [Consolidated Statements of Shareholders’ Equity and Other Comprehensive Income for each of the three years in the period ended December 31, [removed: 2017](#s62D3F1514FC95F10B448528D61D532F8)] [added: 2018](#s7B86D143DEBF580BAF8038EB0477CF2A)] | [removed: [67](#s62D3F1514FC95F10B448528D61D532F8)] [added: [66](#s7B86D143DEBF580BAF8038EB0477CF2A)] |
[removed: | [Notes to Consolidated Financial Statements](#s82949FC1A1E7556F87CDD25B01673553) | [69](#s82949FC1A1E7556F87CDD25B01673553) |][added: NOTES TO CONSOLIDATED FINANCIAL STATEMENTS]
We have audited Equifax Inc.’s internal control over financial reporting as of December 31, [removed: 2017,] [added: 2018,] based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (“2013 framework”) (the COSO criteria).
In our opinion, Equifax Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of December 31, [removed: 2017,] [added: 2018,] based on the COSO criteria.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of December 31, [removed: 2017] [added: 2018] and [removed: 2016,] [added: 2017,] the related consolidated statements of income, comprehensive [removed: income,] [added: income (loss),] cash flows, and shareholders’ equity and other comprehensive [removed: income] [added: income(loss)] for each of the three years in the period ended December 31, [removed: 2017,] [added: 2018,] and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) (collectively referred to as the [removed: "consolidated] [added: “consolidated] financial [removed: statements")] [added: statements”)] and our report dated [removed: March 1, 2018] [added: February 21, 2019] expressed an unqualified opinion thereon.
[removed: March 1,] [added: |] 2018 [added: | | March 31, | | | | June 30, | | | | September 30, | | | | December 31, | | |]
We have audited the accompanying consolidated balance sheets of Equifax Inc. (the Company) as of December 31, [removed: 2017] [added: 2018] and [removed: 2016,] [added: 2017,] the related consolidated statements of income, comprehensive [removed: income,] [added: income(loss),] cash flows, and shareholders’ equity and other comprehensive [removed: income] [added: income(loss)] for each of the three years in the period ended December 31, [removed: 2017,] [added: 2018,] and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) (collectively referred to as the “consolidated financial statements”).
In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at December 31, [removed: 2017] [added: 2018] and [removed: 2016,] [added: 2017,] and the results of its operations and its cash flows for each of the three years in the period ended December 31, [removed: 2017,] [added: 2018,] in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the [removed: Company's] [added: Company’s] internal control over financial reporting as of December 31, [removed: 2017,] [added: 2018,] based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) and our report dated [removed: March 1, 2018] [added: February 21, 2019] expressed an unqualified opinion thereon.
| | 2017 | | | | [removed: 2016] | | | [added: 2016] | [removed: 2015] | | | [added: | |]
| Operating revenue | $ | [removed: 3,362.2] [added: 3,412.1] | | | $ | [removed: 3,144.9] [added: 3,362.2] | | | $ | [removed: 2,663.6] [added: 3,144.9] | |
| Cost of services (exclusive of depreciation and amortization below) | [removed: 1,210.7] [added: 1,440.4] | | | | [removed: 1,113.4] [added: 1,210.7] | | | | [removed: 887.4] [added: 1,113.4] | | |
| Selling, general and administrative expenses | [removed: 1,039.1] [added: 1,213.3] | | | | [removed: 948.2] [added: 1,032.0] | | | | [removed: 884.3] [added: 941.0] | | |
| Depreciation and amortization | [removed: 287.8] [added: 310.4] | | | | [removed: 265.4] [added: 287.8] | | | | [removed: 198.0] [added: 265.4] | | |
| Interest expense | [removed: (92.8] [added: (103.5] | | ) | | [removed: (92.1] [added: (92.8] | | ) | | [removed: (63.8] [added: (92.1] | | ) |
| Consolidated income before income taxes | [removed: 746.6] [added: 356.3] | | | | [removed: 728.2] [added: 746.6] | | | | [removed: 636.6] [added: 728.2] | | |
| Provision for income taxes | [removed: (148.6] [added: (50.0] | | ) | | [removed: (233.1] [added: (148.6] | | ) | | [removed: (201.8] [added: (233.1] | | ) |
| Consolidated net income | [removed: 598.0] [added: 306.3] | | | | [removed: 495.1] [added: 598.0] | | | | [removed: 434.8] [added: 495.1] | | |
| Less: Net income attributable to noncontrolling interests including redeemable noncontrolling interests | [removed: (10.7] [added: (6.5] | | ) | | [removed: (6.3] [added: (10.7] | | ) | | [removed: (5.7] [added: (6.3] | | ) |
| Net income attributable to Equifax | $ | [removed: 587.3] [added: 299.8] | | | $ | [removed: 488.8] [added: 587.3] | | | $ | [removed: 429.1] [added: 488.8] | |
| Net income attributable to Equifax | $ | [removed: 4.89] [added: 2.49] | | | $ | [removed: 4.10] [added: 4.89] | | | $ | [removed: 3.61] [added: 4.10] | |
| Weighted-average shares used in computing basic earnings per share | [removed: 120.1] [added: 120.4] | | | | [removed: 119.3] [added: 120.1] | | | | [removed: 118.7] [added: 119.3] | | |
| Net income attributable to Equifax | $ | [removed: 4.83] [added: 2.47] | | | $ | [removed: 4.04] [added: 4.83] | | | $ | [removed: 3.55] [added: 4.04] | |
| Weighted-average shares used in computing diluted earnings per share | [removed: 121.5] [added: 121.4] | | | | [removed: 121.1] [added: 121.5] | | | | [removed: 120.9] [added: 121.1] | | |
| Dividends per common share | $ | 1.56 | | | $ | [removed: 1.32] [added: 1.56] | | | $ | [removed: 1.16] [added: 1.32] | |
CONSOLIDATED STATEMENTS OF COMPREHENSIVE INCOME [added: (LOSS)]
| | [removed: 2017 | | | |] [added: 2018] | | | | [added: 2017] | | | | 2016 | | | [removed: | | | | | | | | | 2015 | | | | | | | | | | |]
| Net income | $ | [removed: 587.3] [added: 299.8] | | | $ | [removed: 10.7] [added: 6.5] | | | $ | [removed: 598.0] [added: 306.3] | | | $ | [removed: 488.8] [added: 587.3] | | | $ | [removed: 6.3] [added: 10.7] | | | $ | [removed: 495.1] [added: 598.0] | | | $ | [removed: 429.1] [added: 488.8] | | | $ | [removed: 5.7] [added: 6.3] | | | $ | [removed: 434.8] [added: 495.1] | |
| Foreign currency translation adjustment | [removed: 158.7] [added: (224.7] | | [added: )] | | [removed: 3.3] [added: 5.8] | | | | [removed: 162.0] [added: (218.9] | | [added: )] | | [removed: (24.6] [added: 158.7] | | [removed: )] | | [removed: (3.0] [added: 3.3] | | [removed: )] | | [removed: (27.6] [added: 162.0] | | [removed: )] | | [removed: (67.1] [added: (24.6] | | ) | | [removed: (7.1] [added: (3.0] | | ) | | [removed: (74.2] [added: (27.6] | | ) |
| Change in unrecognized prior service cost and actuarial gains (losses) related to our pension and other postretirement benefit plans, net | [removed: 8.4] [added: 10.4] | | | | — | | | | [removed: 8.4] [added: 10.4] | | | | [removed: (20.1] [added: 8.4] | | [removed: )] | | — | | | | [removed: (20.1] [added: 8.4] | | [removed: )] | | [removed: 17.5] [added: (20.1] | | [added: )] | | — | | | | [removed: 17.5] [added: (20.1] | | [added: )] |
| Change in cumulative gain (loss) from cash flow hedging transactions, net | [removed: (0.2] [added: —] | | [removed: )] | | — | | | | [removed: (0.2] [added: —] | | [removed: )] | | [removed: 0.6] [added: (0.2] | | [added: )] | | — | | | | [removed: 0.6] [added: (0.2] | | [added: )] | | [removed: 0.2] [added: 0.6] | | | | — | | | | [removed: 0.2] [added: 0.6] | | |
| Comprehensive income (loss) | $ | [removed: 754.2] [added: 85.5] | | | $ | [removed: 14.0] [added: 12.3] | | | $ | [removed: 768.2] [added: 97.8] | | | $ | [removed: 444.7] [added: 754.2] | | | $ | [removed: 3.3] [added: 14.0] | | | $ | [removed: 448.0] [added: 768.2] | | | $ | [removed: 379.7] [added: 444.7] | | | $ | [removed: (1.4] [added: 3.3] | [removed: )] | | $ | [removed: 378.3] [added: 448.0] | |
| | [added: 2018 | | | | | | | | | | | |] 2017 | | | | [added: | | | | | | | |] 2016 | | | [added: | | | | | | | |]
| Cash and cash equivalents | $ | [removed: 336.4] [added: 223.6] | | | $ | [removed: 129.3] [added: 336.4] | |
| [Notes to Consolidated Financial Statements](#sA34EA2FFCA87526CAE10A43E3755F1E0) | [68](#sA34EA2FFCA87526CAE10A43E3755F1E0) |
February 21, 2019
| Total operating expenses | 2,964.1 | | | | 2,530.5 | | | | 2,319.8 | | |
| Operating income | 448.0 | | | | 831.7 | | | | 825.1 | | |
| Other income (expense), net | 11.8 | | | | 7.7 | | | | (4.8 | | ) |
| | 2018 | | | | 2017 | | |
| Net income | — | | | — | | | | — | | | | 299.8 | | | | — | | | | — | | | | — | | | | 6.5 | | | | 306.3 | | |
| Other comprehensive income (loss) | — | | | — | | | | — | | | | — | | | | (207.3 | | ) | | — | | | | — | | | | 5.8 | | | | (201.5 | | ) |
| Cumulative adjustment from change in accounting principle (Note 2) | — | | | — | | | | — | | | | 4.2 | | | | — | | | | — | | | | — | | | | — | | | | 4.2 | | |
| Purchases of redeemable noncontrolling interests | — | | | — | | | | (5.5 | | ) | | — | | | | (7.0 | | ) | | — | | | | — | | | | (16.7 | | ) | | (29.2 | | ) |
| Balance, December 31, 2018 | 120.6 | | | $ | 236.6 | | | $ | 1,356.6 | | | $ | 4,717.8 | | | $ | (626.3 | ) | | $ | (2,571.0 | ) | | $ | (5.9 | ) | | $ | 47.9 | | | $ | 3,155.7 | |
CONSOLIDATED STATEMENTS OF SHAREHOLDERS’ EQUITY AND OTHER COMPREHENSIVE INCOME(LOSS)
Non-consolidated equity investments are recorded at fair value when readily determinable or at cost, less any impairment, plus or minus changes resulting from observable price changes in orderly transactions when the fair value of the investment is not readily determinable.
statements, as well as reported amounts of revenues and expenses during the reporting period.
In accordance with ASC 606, “Revenue from Contracts with Customers,” we recognize revenue when a performance obligation has been satisfied by transferring a promised good or service to a customer and the customer obtains control of the good or service.
In order to recognize revenue, we note that the two parties must have an agreement that creates enforceable rights, the performance obligations must be distinct and the transaction price can be determined.
Our revenue is derived from the provision of information services to our customers on a transactional basis, in which distinct services are delivered over time as the customer simultaneously receives and consumes the benefits of the services delivered.
To measure our performance over time, the output method is utilized to measure the value to the customer based on the transfer to date of the services promised, with no rights of return once consumed.
In these cases, revenue on transactional contracts with a defined price but an undefined quantity is recognized utilizing the right to invoice expedient resulting in revenue being recognized when the service is provided and billed.
Additionally, multi-year contracts with an defined price but an undefined quantity that utilize tier pricing would be defined as a series of distinct performance obligations satisfied over time utilizing the same method of measurement, the output method, with no rights of return once consumed.
This measurement method is applied on a monthly basis resulting in revenue being recognized when the service is provided and billed.
Multi-year subscription contracts are analyzed to determine the full contract transaction price over the term of the contract and the subsequent price is ratably recognized over the full term of the contract.
We sell certain offerings that contain multiple performance obligations.
If we determine that the arrangement does not contain separate distinct obligations, the performance obligations are bundled together until a distinct obligation is achieved.
The direct costs of installation of a customer are capitalized and amortized over the useful life of the identifiable asset.
In certain instances within our debt collections and recovery management services in our International operating segment and within our Workforce Solutions operating segment, variable consideration is constrained due to the fact that the revenue is contingent on a particular outcome.
collected assuming all other revenue recognition criteria are met.
Judgments and Uncertainties – Each performance obligation within a contract must be considered separately to ensure that appropriate accounting is performed for these distinct goods or services.
These considerations include assessing the price at which the element is sold compared to its standalone selling price; concluding when the element will be delivered; evaluating collectability; and determining whether any contingencies exist in the related customer contract that impact the prices paid to us for the services.
Contract Balances – The contract balances are generated when revenue recognized varies from billing in a given period.
A contract asset is created when an entity transfers a good or service to a customer and recognizes more revenue than what has been billed.
As of December 31, 2018, the contract asset balance was $7.3 million.
A contract liability is created when an entity transfers a good or service to a customer and recognizes less than what has been billed.
Deferred revenue is recognized when we have an obligation to transfer goods or services to a customer and have already received consideration from the customer.
We generally expect to recognize our deferred revenue as revenue within twelve months of being recorded based on the terms of the contracts.
Remaining Performance Obligation – We have elected to disclose only the remaining performance obligations for those contracts with an expected duration of greater than 1 year and do not disclose the value of remaining performance obligations for contracts in which we recognize revenue at the amount to which we have the right to invoice.
We expect to recognize as revenue the following amounts related to our remaining performance obligations as of December 31, 2018, inclusive of the foreign exchange impact:
| Performance Obligation | | Balance | | |
| Less than 1 year | | $ | 44.4 | |
| 1 to 3 years | | 63.4 | | |
| | |
| --- | --- |
| Total operating expenses | 2,537.6 | | | | 2,327.0 | | | | 1,969.7 | | |
| Operating income | 824.6 | | | | 817.9 | | | | 693.9 | | |
| Other income, net | 14.8 | | | | 2.4 | | | | 6.5 | | |
| Impairment of cost method investment | — | | | | — | | | | 14.8 | | |
| Cash received from divestitures | — | | | | — | | | | 2.9 | | |
| Balance, December 31, 2014 | 119.4 | | | $ | 236.6 | | | $ | 1,201.7 | | | $ | 3,554.8 | | | $ | (435.4 | ) | | $ | (2,351.7 | ) | | $ | (5.9 | ) | | $ | 34.5 | | | $ | 2,234.6 | |
| Net income | — | | | — | | | | — | | | | 429.1 | | | | — | | | | — | | | | — | | | | 5.7 | | | | 434.8 | | |
| Other comprehensive loss | — | | | — | | | | — | | | | — | | | | (49.4 | | ) | | — | | | | — | | | | (7.1 | | ) | | (56.5 | | ) |
| Tax effects of stock-based compensation plans | — | | | — | | | | 30.0 | | | | — | | | | — | | | | — | | | | — | | | | — | | | | 30.0 | | |
| Contributions from noncontrolling interests | — | | | — | | | | — | | | | — | | | | — | | | | — | | | | — | | | | 1.5 | | | | 1.5 | | |
| Purchase of noncontrolling interests | — | | | — | | | | 0.1 | | | | — | | | | — | | | | — | | | | — | | | | 0.2 | | | | 0.3 | | |
| Other* | — | | | — | | | | 11.5 | | | | — | | | | — | | | | — | | | | — | | | | — | | | | 11.5 | | |
| Treasury stock purchased under share repurchase program ($143.88 per share) | (0.5 | ) | | — | | | | — | | | | — | | | | — | | | | (77.1 | | ) | | — | | | | — | | | | (77.1 | | ) |
| * | At December 31, 2015, the paid-in capital includes the $11.5 million holdback related to the accelerated share repurchase program discussed in Note 1. At December 31, 2015, the paid-in capital reflects the $11.5 million settlement of the accelerated share repurchase program discussed in Note 1. |
Revenue is recognized when persuasive evidence of an arrangement exists, collectibility of arrangement consideration is reasonably assured, the arrangement fees are fixed or determinable and delivery of the product or service has been completed.
A significant portion of our revenue is derived from the provision of information services to our customers on a transaction basis, in which case revenue is recognized, assuming all other revenue recognition criteria are met, when the services are provided.
If at the outset of an arrangement, we determine that the arrangement fee is not fixed or determinable, revenue is deferred until the arrangement fee becomes fixed or determinable, assuming all other revenue recognition criteria have been met.
The determination of certain of our tax management services revenue requires the use of estimates, principally related to transaction volumes in instances where these volumes are reported to us by our clients on a monthly basis in arrears.
In these instances, we estimate transaction volumes based on average actual volumes reported in the past.
Differences between our estimates and actual final volumes reported are recorded in the period in which actual volumes are reported.
We have not experienced significant variances between our estimates and actual reported volumes in the past.
We monitor actual volumes to ensure that we will continue to make reasonable estimates in the future.
If we determine that we are unable to make reasonable future estimates, revenue may be deferred until actual customer data is obtained.
We have certain offerings that are sold as multiple element arrangements.
For certain customer contracts, the total arrangement fee is allocated to the undelivered elements.
If we are unable to unbundle the arrangement into separate units of accounting, we apply one of the accounting policies described above.
The direct costs of set up of a customer are capitalized and amortized as a cost of service during the term of the related customer contract.
We have some multiple element arrangements that include software.
We recognize the elements for which we have established vendor specific objective evidence at fair value upon delivery, in accordance with the applicable guidance.
Deferred revenue consists of amounts billed in excess of revenue recognized on sales of our information services relating generally to the deferral of subscription fees and arrangement consideration from elements not meeting the criteria for having stand-alone value discussed above.
Deferred revenues are subsequently recognized as revenue in accordance with our revenue recognition policies.
Accelerated Share Repurchase Program.
On October 24, 2014, we entered into an accelerated share repurchase (“ASR”) program to repurchase shares of our common stock under our approved share repurchase program.
Under the ASR program, the number of shares to be repurchased is based generally on the daily volume weighted average price of our common stock during the term of the ASR program.
On October 24, 2014, we paid $115 million in exchange for an initial delivery of 1.4
million shares to us, subject to a 10%, or $11.5 million, holdback.
The maximum number of shares to be received or delivered under the contracts was 3.2 million.
The ASR program was accounted for as an initial treasury stock transaction and a forward stock purchase contract.
An excerpt. Shown here: 40 of 617 rewritten, 40 of 397 added and 40 of 281 removed. The counts are complete. For every sentence, read Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA in the FY2018 filing and the FY2017 filing.
Item 9A. CONTROLS AND PROCEDURES
7 rewritten, 1 added, 5 removed, 16 unchanged
Our management, with the participation of our [removed: Interim] Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of Equifax’s disclosure controls and procedures as of the end of the period covered by this report.
Based on that evaluation, our [removed: Interim] Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures as of the end of the period covered by this report (i) were appropriately designed to provide reasonable assurance of achieving their objectives and (ii) were effective and provided reasonable assurance that the information required to be disclosed by Equifax in reports filed under the Exchange Act is (a) recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms and (b) accumulated and communicated to Equifax’s management, including our [removed: Interim] Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions regarding required disclosure.
Internal control over financial reporting is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act as a process designed by, or under the supervision of, our [removed: Interim] Chief Executive Officer and Chief Financial Officer and effected by our Board of Directors, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles and includes those policies and procedures that:
Our management assessed the effectiveness of Equifax’s internal control over financial reporting as of December 31, [removed: 2017] [added: 2018] using the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) in Internal Control-Integrated Framework (2013 Framework).
Based on this assessment using those criteria, our management concluded that, as of December 31, [removed: 2017,] [added: 2018,] Equifax’s internal control over financial reporting was effective.
[added: Management] reviewed the results of its assessment with the Audit Committee of its Board of Directors.
The effectiveness of Equifax’s internal control over financial reporting as of December 31, [removed: 2017] [added: 2018] has been audited by Ernst & Young LLP, Equifax’s independent registered public accounting firm, as stated in their report, which appears in [removed: Part II, Item 8 of this Form 10-K on page 61.][added: “Item 8.]
Financial Statements and Supplementary Data” of this Form 10-K on page 60.
As discussed in Note 6 of the Notes to the Consolidated Financial Statements in this Form 10-K, on September 7, 2017, we announced a cybersecurity incident.
Our review of the circumstances and resulting impact on our internal controls over financial reporting (ICFR) identified two significant deficiencies in our IT General Controls environment, in the third quarter of 2017.
As of December 31, 2017, management has remediated the two significant deficiencies.
Incorporating these results, our management, with the participation of our Interim Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of Equifax's disclosure controls and procedures as of the end of the period covered by this report.
Management
Item 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE
14 rewritten, 13 added, 14 removed, 34 unchanged
Except for the information about our executive officers shown below, the information required by this Item 10 is incorporated herein by reference from the information contained in our Proxy Statement to be filed with the SEC in connection with the solicitation of proxies for our [removed: 2018] [added: 2019] Annual Meeting of Shareholders (the [removed: “2018] [added: “2019] Proxy Statement”) under the sections entitled “Proposal 1 Election of Directors,” “Section 16(a) Beneficial Ownership Reporting Compliance” and “Board Leadership and [removed: Corporation Governance Committees] [added: Corporate Governance—Committees] of the Board of Directors.”
Dann Adams [removed: (60)] [added: (61)] has been President, Global Consumer Solutions, since November 2015.
Prior thereto, he served as [added: Senior Vice] President, [removed: International,] [added: Corporate Development,] since April 2010.
Jamil Farshchi [removed: (40) was appointed as] [added: (41) has been] our Chief Information Security Officer [removed: on] [added: since] February [removed: 26,] 2018.
Gamble, Jr. [removed: (55)] [added: (56)] has been Corporate Vice President and Chief Financial Officer since May 2014.
Hartman [removed: (58)] [added: (59)] has been President, International, since November 2015.
Prior thereto, he served as Senior Vice President, [removed: Corporate Development,] [added: Global Product of Global Payments Inc.] since [removed: July] 2010.
Houston [removed: (47)] [added: (48)] has been Chief Transformation Officer since October 2017.
Prior thereto, she served [removed: was] [added: in roles of increasing responsibility at Mirant Corporation from 2004 to 2010, ultimately serving as] Senior Vice President, General Counsel, Chief Compliance Officer and Corporate [removed: Secretary at Mirant Corporation, from 2004 to 2010.][added: Secretary.]
Kelley III [removed: (57)] [added: (58)] has been Corporate Vice President and Chief Legal Officer since January 2013.
[removed: King (64)] [added: Rushing (62)] has been [removed: Senior] [added: Corporate] Vice President and [removed: Controller] [added: Chief Human Resources Officer] since [removed: May] 2006.
[removed: Loughran, III (50)] [added: Sid Singh (41)] has been President, U.S. Information Solutions, since [removed: July 2017.][added: February 11, 2019.]
Ploder [removed: (57)] [added: (58)] has been President, Workforce Solutions, since November 2015.
Wilbanks [removed: (50)] [added: (51)] has been Chief Marketing Officer since August 2017.
Mark W.
Begor (60) has been Chief Executive Officer and a member of the Board of Directors since April 2018.
Prior thereto, he was a Managing Director in the Industrial and Business Services group at Warburg Pincus, a global private equity investment firm, since June 2016.
Prior to Warburg Pincus, Mr. Begor spent 35 years at General Electric Company (“GE”), a global industrial and financial services company, in a variety of operating and financial roles.
During his career at GE, Mr. Begor served in a variety of roles leading multibillion dollar units of the company, including President and CEO of GE Energy Management from 2014 to 2016, President and CEO of GE Capital Real Estate from 2011 to 2014, and President and CEO of GE Capital Retail Finance (Synchrony Financial) from 2002 to 2011.
Mr. Begor served on the Fair Isaac Corporation (FICO) Board of Directors from 2016 to 2018.
Bryson Koehler (43) has been our Chief Technology Officer since June 2018.
Prior to joining Equifax, Mr. Koehler served as Chief Technology Officer of IBM Watson and Cloud Platform since November 2016.
Prior to that, Mr. Koehler was Chief Technology and Information Officer of The Weather Channel Companies, before it was acquired in 2015 by IBM.
Before that, he served as Senior Vice President of Global Revenue & Guest Technology at the Intercontinental Hotels Group.
Mr. Singh served as group president of Integrated Solutions & Vertical Markets at Global Payments Inc., since February 2013.
Prior thereto, he served as Vice President and Regional Head, Asia Pacific of Global Payments Inc. since 2006.
Prior thereto, he held senior management positions with HSBC and Citibank.
Paulino do Rego Barros, Jr. (61) has been Interim Chief Executive Officer since September 2017.
Prior thereto, he led the Company’s Asia-Pacific business since July 2017.
Prior thereto, he was President, U.S. Information Solutions, since November 2015.
Prior thereto, he served as President of PB&C Global Investments, LLC, an international consulting and investment firm.
Prior thereto, he was President of Global Operations for AT&T.
Nuala M.
Prior thereto, she was Vice President and Corporate Controller from March 2004 to April 2006.
Prior to joining Equifax, Ms. King served as Corporate Controller for UPS Capital from March 2001 until March 2004.
Joseph M.
Prior thereto, he was Chief Marketing Officer since March 2015.
Prior thereto, he served as President, Global Consumer Solutions since January 2010.
Prior thereto, he was Senior Vice President Corporate Development from April 2006 to December 2009.
Prior to joining Equifax, he held various executive roles at BellSouth Corporation from May 2001 to April 2006, including most recently Managing Director Corporate Strategy and Planning from May 2005 to April 2006.
Rushing (61) has been Corporate Vice President and Chief Human Resources Officer since 2006.
Item 11. EXECUTIVE COMPENSATION
1 rewritten, 0 added, 0 removed, 0 unchanged
The information required by this Item 11 is incorporated herein by reference from the information contained in our [removed: 2018] [added: 2019] Proxy Statement under the sections entitled “Executive Compensation” and “Director Compensation.”
Item 12. SECURITY OWNERSHIP OF CERTAIN BENEFICIAL OWNERS AND MANAGEMENT AND RELATED STOCKHOLDER MATTERS
1 rewritten, 0 added, 0 removed, 0 unchanged
The information required by this Item 12 is incorporated herein by reference from the information contained in our [removed: 2018] [added: 2019] Proxy Statement under the sections entitled “Security Ownership of Management and Certain Beneficial Owners” and “Executive Compensation Equity Compensation Plan Information.”
Item 13. CERTAIN RELATIONSHIPS AND RELATED TRANSACTIONS AND DIRECTOR INDEPENDENCE
1 rewritten, 0 added, 0 removed, 0 unchanged
The information required by this Item 13 is incorporated herein by reference from the information contained in our [removed: 2018] [added: 2019] Proxy Statement under the sections entitled “Board Leadership and Corporate Governance Director Independence, ” “Related Person Transaction Policy” and “Certain Relationships and Related Person Transactions of Directors, Executive Officers, and 5 Percent Shareholders.”
Item 14. PRINCIPAL ACCOUNTANT FEES AND SERVICES
1 rewritten, 0 added, 0 removed, 1 unchanged
The information required by this Item 14 is incorporated herein by reference from the information contained in our [removed: 2018] [added: 2019] Proxy Statement under the section entitled “Proposal 3 Ratification of Appointment of Ernst & Young LLP as Independent Registered Public Accounting Firm for [removed: 2018.”][added: 2019.”]
Item 15. EXHIBITS AND FINANCIAL STATEMENT SCHEDULES
27 rewritten, 6 added, 4 removed, 105 unchanged
| • | Consolidated Balance Sheets — December 31, [removed: 2017] [added: 2018] and [removed: 2016;] [added: 2017;] |
| • | Consolidated Statements of Income for the Years Ended December 31, [removed: 2017, 2016] [added: 2018, 2017] and [removed: 2015;] [added: 2016;] |
| • | Consolidated Statements of Comprehensive Income for the Years Ended December 31, [removed: 2017, 2016] [added: 2018, 2017] and [removed: 2015;] [added: 2016;] |
| • | Consolidated Statements of Cash Flows for the Years Ended December 31, [removed: 2017, 2016] [added: 2018, 2017] and [removed: 2015;] [added: 2016;] |
| • | Consolidated Statements of Shareholders’ Equity and Other Comprehensive Income for the Years Ended December 31, [removed: 2017, 2016] [added: 2018, 2017] and [removed: 2015;] [added: 2016;] and |
| [removed: 4.6] [added: 4.7] | | [Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee (incorporated by reference to Exhibit 4.1 to [removed: Equifax's] [added: Equifax’s] Form 8-K filed May 12, 2016).](http://www.sec.gov/Archives/edgar/data/33185/000119312516588951/d165110dex41.htm) |
| [removed: 4.7] [added: 4.8] | | [First Supplemental Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee, including the form of 2021 Note as Exhibit A (incorporated by reference to Exhibit 4.2 to Equifax’s Form 8-K filed May 12, 2016).](http://www.sec.gov/Archives/edgar/data/33185/000119312516588951/d165110dex42.htm) |
| [removed: 4.8] [added: 4.9] | | [Second Supplemental Indenture, dated as of May 12, 2016, between Equifax Inc. and U.S. Bank National Association, as Trustee, including the form of 2026 Note as Exhibit A (incorporated by reference to Exhibit 4.3 to Equifax’s Form 8-K filed May 12, 2016).](http://www.sec.gov/Archives/edgar/data/33185/000119312516588951/d165110dex43.htm) |
| | | Except as set forth in the preceding Exhibits 4.1 through [removed: 4.8,] [added: 4.12,] instruments defining the rights of holders of long-term debt securities of Equifax have been omitted where the total amount of securities authorized does not exceed 10% of the total assets of Equifax and its subsidiaries on a consolidated basis. Equifax agrees to furnish to the SEC, upon request, a copy of such instruments with respect to issuances of long-term debt of Equifax and its subsidiaries. |
| [removed: 10.27*] [added: 10.27] | | [Amendment No. 2 to Equifax 2005 Executive Deferred Compensation plan, effective January 1, [removed: 2016.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit1027-12312017.htm)] [added: 2016 (incorporated by reference to Exhibit 10.27 to Equifax’s Form 10-K filed March 1, 2018)](http://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit1027-12312017.htm)] |
| [removed: 10.28] [added: 10.36] | | [removed: [Amended and Restated Employment Agreement] [added: [Employment Agreement,] dated [removed: as of September 23, 2008,] [added: March 27, 2018,] between [removed: Equifax Inc.] [added: the Company] and [removed: Richard F. Smith] [added: Mark W. Begor] (incorporated by reference to Exhibit 10.1 to Equifax’s Form 8-K filed [removed: September 26, 2008).](http://www.sec.gov/Archives/edgar/data/33185/000110465908060752/a08-24408_1ex10d1.htm)] [added: March 28, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000119312518098631/d558281dex101.htm)] |
| [removed: 10.30] [added: 4.6] | | [removed: [Agreement] [added: [Credit Agreement,] dated [added: as of] September [removed: 25, 2017,] [added: 27, 2018, by and] between Equifax [removed: Inc.] [added: Inc., Equifax Limited, Equifax Canada Co., Equifax Australia Holdings Pty Limited,] and [removed: Richard F. Smith] [added: SunTrust Bank as administrative agent] (incorporated by reference to Exhibit 10.1 to [removed: Equifax's] [added: Equifax’s] Form [removed: 10-Q] [added: 8-K] filed [removed: November 9, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000119312517293765/d420554dex101.htm)] [added: October 1, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000003318518000035/revolvingcreditagreementex.htm)] |
| [removed: 10.32] [added: 10.28] | | [Form of Restricted Stock Unit Award Agreement (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.1 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit101-20170331.htm) |
| [removed: 10.33] [added: 10.29] | | [Form of Restricted Stock Unit Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.2 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit102-20170331.htm) |
| [removed: 10.34] [added: 10.30] | | [Form of Non-Qualified Stock Option Award Agreement (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.3 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit103-20170331.htm) |
| [removed: 10.35] [added: 10.31] | | [Form of Non-Qualified Stock Option Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.4 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit104-20170331.htm) |
| [removed: 10.36] [added: 10.32] | | [Form of Performance Share Award Agreement (TSR) (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.5 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit105-20170331.htm) |
| [removed: 10.37] [added: 10.33] | | [Form of Performance Share Award Agreement (TSR) (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.6 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit106-20170331.htm) |
| [removed: 10.38] [added: 10.34] | | [Form of Performance Share Award Agreement (EPS) (CEO) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.7 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit107-20170331.htm) |
| [removed: 10.39] [added: 10.35] | | [Form of Performance Share Award Agreement (EPS) (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after February 2017) (incorporated by reference to Exhibit 10.8 to [removed: Equifax's] [added: Equifax’s] Form 10-Q filed April 27, 2017).](http://www.sec.gov/Archives/edgar/data/33185/000003318517000015/exhibit108-20170331.htm) |
| 21.1* | | [Subsidiaries of Equifax [removed: Inc.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit211-12312017.htm)] [added: Inc.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit211-12312018.htm)] |
| 23.1* | | [Consent of Independent Registered Public Accounting [removed: Firm.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit231consent-12312017.htm)] [added: Firm.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit231consent-12312018.htm)] |
| 24.1* | | [Powers of Attorney (included on signature [removed: page).](#s2684C68915C2577DB21B7C4C84AB13E4)] [added: page).](#s664C52B84DAC5804825E9E2E05518D78)] |
| 31.1* | | [Rule 13a-14(a) Certification of Chief Executive [removed: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit311-12312017.htm)] [added: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit311-12312018.htm)] |
| 31.2* | | [Rule 13a-14(a) Certification of Chief Financial [removed: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit312-12312017.htm)] [added: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit312-12312018.htm)] |
| 32.1* | | [Section 1350 Certification of Chief Executive [removed: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit321-12312017.htm)] [added: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit321-12312018.htm)] |
| 32.2* | | [Section 1350 Certification of Chief Financial [removed: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit322-12312017.htm)] [added: Officer.](https://www.sec.gov/Archives/edgar/data/33185/000003318519000007/exhibit322-12312018.htm)] |
| 4.10 | | [Third Supplemental Indenture, dated as of May 25, 2018, between Equifax Inc. and the Trustee, including the form of 2021 Note as Exhibit A (incorporated by reference to Exhibit 4.1 to Equifax’s Form 8-K filed May 25, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000119312518175418/d595030dex41.htm) |
| 4.11 | | [Fourth Supplemental Indenture, dated as of May 25, 2018, between Equifax Inc. and the Trustee, including the form of 2023 Note as Exhibit A (incorporated by reference to Exhibit 4.2 to Equifax’s Form 8-K filed May 25, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000119312518175418/d595030dex42.htm) |
| 4.12 | | [Fifth Supplemental Indenture, dated as of May 25, 2018, between Equifax Inc. and the Trustee, including the form of Floating Rate Note as Exhibit A (incorporated by reference to Exhibit 4.2 to Equifax’s Form 8-K filed May 25, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000119312518175418/d595030dex42.htm) |
| 10.37 | | [Form of Restricted Stock Unit Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after March 2018) (incorporated by reference to Exhibit 10.2 to Equifax’s Form 10-Q filed April 26, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000003318518000020/exhibit102-20180331.htm) |
| 10.38 | | [Form of Non-Qualified Stock Option Award Agreement (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after March 2018) (incorporated by reference to Exhibit 10.3 to Equifax’s Form 10-Q filed April 26, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000003318518000020/exhibit103-20180331.htm) |
| 10.39 | | [Form of Performance Share Award Agreement (TSR) (Senior Leadership Team) under the Equifax Inc. Amended and Restated 2008 Omnibus Incentive Plan (for awards granted in or after March 2018) (incorporated by reference to Exhibit 10.4 to Equifax’s Form 10-Q filed April 26, 2018).](http://www.sec.gov/Archives/edgar/data/33185/000003318518000020/exhibit104-20180331.htm) |
| 10.29 | | [Letter agreement dated December 21, 2012, between Equifax Inc. and Richard F. Smith modifying the Amended Restated Employment Agreement dated as of September 23, 2008 (amendment to comply with Section 409A of Internal Revenue Code) (incorporated by reference to Exhibit 10.22 to Equifax’s Form 10-K filed February 22, 2013).](http://www.sec.gov/Archives/edgar/data/33185/000114420413010696/v332542_ex10-22.htm) |
| 10.31 | | [Deferred Share Award Agreement dated as of September 19, 2005, between Equifax Inc. and Richard F. Smith (incorporated by reference to Exhibit 10.2 to Equifax’s Form 10-Q filed November 7, 2005).](http://www.sec.gov/Archives/edgar/data/33185/000110465905053131/a05-18314_1ex10d2.htm) |
| 11.1 | | [Calculation of earnings per share. (The calculation of earnings per share is in Part II, Item 8, Note 1 to the Consolidated Financial Statements and is omitted in accordance with Section (b)(11) of Item 601 of the Notes to Regulation S-K).](#s89FDA9B9F6195AACAADB979B0E0341B2) |
| 12.1* | | [Computation of ratio of earnings to fixed charges](https://www.sec.gov/Archives/edgar/data/33185/000003318518000011/exhibit121-12312017.htm) |
Item 16. FORM 10-K SUMMARY
7 rewritten, 13 added, 21 removed, 85 unchanged
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on [removed: March 1, 2018.][added: February 21, 2019.]
| | [removed: Interim] Chief Executive Officer |
Gamble, Jr. and [removed: Nuala] [added: James] M.
[removed: King,] [added: Griggs,] and each of them singly, our true and lawful attorneys with full power to them and each of them to sign for us, and in our names in the capacities indicated below, any and all amendments to this Annual Report on Form 10-K filed with the SEC, hereby ratifying and confirming our signatures as they may be signed by our said attorneys to any and all amendments to said Annual Report on Form 10-K.
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the registrant and in the capacities indicated on [removed: March 1, 2018.][added: February 21, 2019.]
| [removed: Interim] Chief Executive Officer | |
| Director and [added: Non-Executive] Chairman | |
| By: | /s/ Mark W. Begor |
| | Mark W. Begor |
| /s/ Mark W. Begor | |
| Mark W. Begor | |
| /s/ James M. Griggs | |
| James M. Griggs | |
| Chief Accounting Officer and Corporate Controller | |
| /s/ Robert W. Selander | |
| Robert W. Selander | |
2018
| Trade accounts receivable | | $ | 9.1 | | | $ | 5.6 | | | $ | — | | | $ | (3.8 | ) | | $ | 10.9 | |
| Deferred income tax asset valuation allowance | | 401.8 | | | | (164.0 | | ) | | (12.3 | | ) | | 206.4 | | | | 431.9 | | |
| | | $ | 410.9 | | | $ | (158.4 | ) | | $ | (12.3 | ) | | $ | 202.6 | | | $ | 442.8 | |
| | |
| By: | /s/ Paulino R. Barros, Jr. |
| | Paulino R. Barros, Jr. |
| /s/ Paulino R. Barros, Jr. | |
| Paulino R. Barros, Jr. | |
| /s/ Nuala M. King | |
| Nuala M. King | |
| Senior Vice President and Corporate Controller | |
| /s/ Robert D. Daleo | |
| Robert D. Daleo | |
| Director | |
| /s/ Walter W. Driver, Jr. | |
| Walter W. Driver, Jr. | |
| /s/ L. Phillip Humann | |
| L. Phillip Humann | |
| /s/ Mark B. Templeton | |
| Mark B. Templeton | |
2015
| Trade accounts receivable | | $ | 7.2 | | | $ | 4.3 | | | $ | — | | | $ | (4.0 | ) | | $ | 7.5 | |
| Deferred income tax asset valuation allowance | | 121.4 | | | | (1.5 | | ) | | (13.0 | | ) | | 116.0 | | | | 222.9 | | |
| | | $ | 128.6 | | | $ | 2.8 | | | $ | (13.0 | ) | | $ | 112.0 | | | $ | 230.4 | |