Equifax 10-K 2023-12-31
Filed 2024-02-22. 23 sections, 563K characters. Original on sec.gov · Markdown · JSON
Cover and table of contents
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
| ☒ | ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the fiscal year ended December 31, 2023
| OR | |||||
| ☐ | TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 |
For the transition period from to
Commission File Number 001-06605
EQUIFAX INC.
(Exact name of registrant as specified in its charter)
| Georgia | 58-0401110 | |||||||
| (State or other jurisdiction of incorporation or organization) | (I.R.S. Employer Identification No.) | |||||||
| 1550 Peachtree Street | N.W. | Atlanta | Georgia | 30309 | |||||||||||||
| (Address of principal executive offices) | (Zip Code) | ||||||||||||||||
Registrant’s telephone number, including area code: 404-885-8000
Securities registered pursuant to Section 12(b) of the Act:
| Title of each class | Trading Symbol | Name of each exchange on which registered | ||||||||||||
| Common Stock, $1.25 par value per share | EFX | New York Stock Exchange |
Securities registered pursuant to Section 12(g) of the Act: None.
Indicate by check mark if Registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Exchange Act (“Act”). ☒ Yes ☐ No
Indicate by check mark if Registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. ☐ Yes ☒ No
Indicate by check mark whether Registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. ☒ Yes ☐ No
Indicate by check mark whether the Registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T during the preceding 12 months (or for such shorter period that the Registrant was required to submit such files). Yes ☒ No ☐
Indicate by check mark whether the Registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and “emerging growth company” in Rule 12b-2 of the Exchange Act. (Check one):
| ☒ | Large accelerated filer | ☐ | Accelerated filer | ☐ | Non-accelerated filer | ☐ | Smaller reporting company | ☐ | Emerging growth company | ||||||||||||||||||||||||||||||||
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issues financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant's executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐
Indicate by check mark whether the Registrant is a shell company (as defined in Rule 12b-2 of the Act). ☐ Yes ☒ No
As of June 30, 2023, the aggregate market value of Registrant’s common stock held by non-affiliates of Registrant was approximately $28,876,038,118 based on the closing sale price as reported on the New York Stock Exchange. At January 31, 2024, there were 123,956,391 shares of Registrant’s common stock outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
Portions of Registrant’s definitive proxy statement for its 2024 annual meeting of shareholders are incorporated by reference in Part III of this Form 10-K.
TABLE OF CONTENTS
PART I
Item 1. BUSINESS
Overview
Equifax Inc. is a global data, analytics and technology company. We provide information solutions for businesses, governments and consumers, and we provide human resources business process automation and outsourcing services for employers. We have a large and diversified group of clients, including financial institutions, corporations, government agencies and individuals. Our services are based on comprehensive databases of consumer and business information derived from numerous sources including credit, financial assets, telecommunications and utility payments, employment, income, educational history, criminal justice data, healthcare professional licensure and sanctions, demographic and marketing data. We use advanced statistical techniques, machine learning and proprietary software tools to analyze available data to create customized insights, decision-making and process automation solutions and processing services for our clients. We are a leading provider of information and solutions used in payroll-related and human resource management business process services in the United States of America (“U.S.”) as well as e-commerce fraud and charge back protection services in North America. For consumers, we provide products and services to help people understand, manage and protect their personal information and make more informed financial decisions. Additionally, we also provide information, technology and services to support debt collections and recovery management.
We currently operate in four global regions: North America (U.S. and Canada), Asia Pacific (Australia, New Zealand and India), Europe (the United Kingdom (“U.K.”), Spain and Portugal) and Latin America (Argentina, Brazil, Chile, Costa Rica, Dominican Republic, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay). We maintain support operations in Chile, Costa Rica, India and Ireland. We also have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and Brazil.
Equifax was originally incorporated under the laws of the State of Georgia in 1913, and its predecessor company dates back to 1899. As used herein, the terms Equifax, the Company, we, our and us refer to Equifax Inc., a Georgia corporation, and its consolidated subsidiaries as a combined entity, except where it is clear that the terms mean only Equifax Inc.
We are organized and report our business results in three operating segments, as follows:
-
Workforce Solutions** — provides services enabling customers to verify income, employment, educational history, criminal justice data, healthcare professional licensure and sanctions of people in the U.S. (Verification Services), as well as providing our employer customers with services which include unemployment claims management, I-9 and onboarding services, Affordable Care Act compliance management, tax credits and incentives and other complementary employment-based transaction services (Employer Services). Workforce Solutions has established operations in Canada, Australia and the U.K.
-
U.S. Information Solutions (“USIS”) — provides consumer and commercial information solutions to businesses in the U.S. including online information, decisioning technology solutions, identity management services, analytical services, e-commerce fraud and charge back protection services, portfolio management services, mortgage information and marketing services. We provide products to consumers in the U.S. to enable them to understand and monitor their credit and help protect their identity. We also sell consumer credit information to resellers who may combine our information with other information to provide direct-to-consumer monitoring, reports and scores.
-
International — provides products and services similar to those available in the USIS operating segment but with variations by geographic region. We also provide information, technology and services to support debt collections and recovery management. In addition, we provide products to consumers in Canada, the U.K., Australia and Chile to enable them to understand and monitor their credit and help protect their identity. This operating segment is comprised of our Asia Pacific, Europe, Latin America and Canada business units. It also includes our joint ventures in Cambodia, Malaysia, Singapore and Brazil.
Our Business Strategy
Our vision is to be a trusted global leader in data, analytics and technology that creates innovative solutions and insights for our customers. Our business strategy is driven by the following imperatives:
-
Leverage our Equifax cloud capabilities and technology investment to accelerate innovation, new products and growth. We are executing a cloud data and technology transformation that is rebuilding our technology infrastructure, including a migration to a public cloud environment that employs virtual private cloud deployment techniques. We are rationalizing and rebuilding our application portfolio using cloud-native services. Our move to cloud-native technology is enabling the continued development of our single data fabric, which is a cloud native platform that enables Equifax to build, manage and deploy data products, as well as implementation of best-in-class cloud-based tools and capabilities. Our growth strategy is to leverage our cloud data and technology transformation to accelerate innovation and new product development; deliver market-leading capabilities to our customers; facilitate customer and partner implementation and integration; improve ease of consumer access to and interaction with Equifax; and strengthen system resiliency and uptime.
-
Leverage and expand our differentiated portfolio of data assets. We use proprietary advanced analytical platforms, including capabilities in machine learning, artificial intelligence and advanced visualization tools, to leverage our unique data to develop leading analytical insights that enhance the precision of our customers’ decisioning activities. Based on our cloud native data and technology transformation, we are investing to simplify our customers’ access to our leading analytical and decisioning platforms, in order to speed the development of unique insights and the conversion of these insights into innovative new products and services consumable by our customers through our delivery platforms. We strive to advance these capabilities and bring our customers multi-data solutions at scale by expanding our unique and differentiated data assets and analytics through organic growth, business acquisitions and partnerships.
-
Foster a culture of putting customers and consumers first. We are focused on maintaining a culture in which our customers and consumers are at the center of our decision processes, and where we exceed customer and consumer expectations by delivering solutions with speed, flexibility, stability and performance. We prioritize engagement with our customers and strive to accelerate innovation through collaboration. We seek to leverage our cloud native technology and unique data assets and capabilities, as well as customer expertise and data and technology assets, to drive the development of high-value analytical products and services designed to address a broader range of customer and consumer needs. We work to maximize the value of our differentiated data assets, analytics and decisioning to drive new products and services that provide a fuller picture of consumers and commercial entities to our customers in banking and financial services, government, employee hiring and onboarding and other service providers.
-
Execute strategic acquisitions that expand our data portfolio and capabilities and drive revenue growth. A critical lever of our strategy is inorganic growth through accretive and strategic acquisitions that drive incremental annual revenue growth. Our acquisition priorities are clear and focused
Showing the first 8K of 66K characters. Open the full section
Item 1A. RISK FACTORS
All of the risks and uncertainties described below and the other information included in this Form 10-K should be considered and read carefully. The risks described below are not the only ones facing us. The occurrence of any of the following risks or additional risks and uncertainties not presently known to us or that we currently believe to be immaterial could materially and adversely affect our business, financial condition or results of operations. This Form 10-K also contains forward-looking statements and estimates that involve risks and uncertainties. Our actual results could differ materially from those anticipated in the forward-looking statements as a result of specific factors, including the risks and uncertainties described below.
Technology and Data Security Risks
Security breaches and other disruptions to our information technology infrastructure could compromise Company, consumer and customer information, interfere with our operations, cause us to incur significant costs for remediation and enhancement of our IT systems and expose us to legal liability, all of which could have a substantial negative impact on our business and reputation.
We are a global data, analytics and technology company. In the ordinary course of business, we collect, process, transmit and store sensitive data, including intellectual property, proprietary business information and personal information of consumers, employees and strategic partners. The secure operation of our information technology networks and systems, and of the processing and maintenance of this information, is critical to our business operations and strategy. Because our products and services involve the storage and transmission of personal information of consumers, we are routinely the target of attempted cyber and other security threats by outside third parties, including technically sophisticated and well-resourced bad actors attempting to access or steal the data we store. Additionally, we could experience service disruptions or a loss of access to critical data or systems due to ransomware or other destructive attacks. Insider or employee cyber and security threats are also a significant concern for all companies, including ours. Despite our substantial investment in physical and technological security measures, employee training and contractual precautions, our information technology networks and infrastructure (or those of our third-party vendors and other service providers) are potentially vulnerable to unauthorized access to data, loss of access to systems or breaches of confidential information due to criminal conduct, attacks by hackers, employee or insider malfeasance and/or human error.
The techniques used to obtain unauthorized access, disable or degrade service or sabotage systems are constantly evolving and often are not recognized until launched against a target, or even some time after. We may be unable to anticipate these techniques, implement adequate preventative measures or remediate any intrusion on a timely or effective basis even if our security measures are appropriate, reasonable, and/or comply with applicable legal requirements. Certain efforts may be state-sponsored and supported by significant financial and technological resources, making them even more sophisticated and difficult to detect. Further, we are in the process of transforming our applications and infrastructure technologies, and this transition to cloud-based technologies may expose us to additional cyber threats as we migrate our data from our legacy systems to cloud-based solutions hosted by third parties. Although we have developed systems and processes that are designed to protect our data and customer data and to prevent data loss and other security breaches, and expect to continue to expend significant additional resources to bolster these protections, these security measures cannot provide absolute security.
We previously experienced a material cybersecurity incident in 2017 and if we experience additional breaches of our security measures, including from incidents that we fail to detect for a period of time, sensitive data may be accessed, stolen, disclosed or lost. Any such access, disclosure or other loss of information could subject us to business interruption, significant litigation, regulatory fines or penalties, any of which could have a material adverse effect on our cash flows, competitive position, financial condition or results of operations. While we maintain cybersecurity insurance, we cannot ensure that our insurance policies in the future will be adequate to cover losses from any security breaches.
Security breaches and attacks, and the adverse publicity that may follow, can have a negative impact on our reputation and our relationship with our customers. For example, our reputation with consumers and other stakeholders and our customer relationships were damaged following the cybersecurity incident in 2017, resulting in a negative impact on our revenue for a period of time. If we experience another material cybersecurity incident or are otherwise unable to demonstrate the security of our systems and the data we maintain and retain the trust of our customers, consumers and data suppliers, we could experience a substantial negative impact on our business.
If we fail to achieve and maintain key industry or technical certifications, our customers and business partners may stop doing business with us and we may not be able to win new business, which would negatively affect our revenue.
We are required by customers and business partners to obtain various industry or technical certifications. Such certifications are critical to our business because certain of our current and potential customers and the contracts governing certain customer relationships, as well as certain of our data suppliers, require us to maintain them as a requirement of doing business. For example, as a result of a prior material cybersecurity incident, we lost certain key certifications which caused certain customers and business partners to stop or pause doing business with us and temporarily limited our ability to win new business. We had to spend significant resources on remediation activities in order to obtain these key re-certifications. If we fail to achieve or maintain key industry or technical certifications as a result of another cybersecurity incident or for other reasons, customers and business partners may stop doing business with us and we may not be able to win new business, which would negatively affect our revenue.
Strategy and Market Demand Risks
The failure to realize the anticipated benefits of our technology transformation strategy could adversely impact our business and financial results.
We expect our technology transformation strategy, including our transition to cloud-based technologies, will significantly increase our efficiency, our productivity, and the stability and functionality of our products and services, as well as decrease the cost of our overall systems infrastructure, all of which we expect will drive growth and have a positive effect on our business, competitive position and results of operations. This initiative is a major undertaking as we replace many of our previous operating systems with cloud-based systems. This complex, multifaceted and extensive initiative is expensive and has caused, and may cause in the future, unanticipated problems and expenses. If the transition causes errors or adversely impacts system processes, our new systems do not operate as expected, or the data we transition to the cloud changes in a material way, we may have to incur significant additional costs to make modifications and could lose customers and we may suffer reputational harm as a result. Moreover, we have experienced issues with customer migration, as some of our customers may not migrate to cloud-based technologies on a timely basis or at all or may choo
Showing the first 8K of 62K characters. Open the full section
Item 1B. UNRESOLVED STAFF COMMENTS
None.
Item 1C. CYBERSECURITY
Risk Management and Strategy
We are a global data, analytics and technology company. In the ordinary course of business, we collect, process, transmit and store sensitive data, including intellectual property, proprietary business information and personal information of consumers, employees and strategic partners. The secure operation of our information technology networks and systems, and of the processing and maintenance of this information, is critical to our business operations and strategy.
Equifax has invested significantly to develop and maintain an information security program with processes, technology and controls to protect the information, systems and resources of the Company. We have a Security team operating under the leadership of our Chief Information Security Officer (“CISO”), including approximately 400 cybersecurity professionals. The key elements of our information security program, including our cybersecurity risk management strategy, are described below.
Security Controls Framework
Equifax has implemented a unified security and privacy controls framework as our primary mechanism to establish strategic priorities related to cybersecurity, assess cybersecurity risk across the enterprise, comply with regulatory requirements and enhance security program maturity. Our unified security and privacy controls framework is based upon the National Institute of Standards and Technology's Cybersecurity Framework (NIST CSF) and Privacy Framework (NIST PF).
Cybersecurity Incident Detection and Response Process
Our information security program is based on five key functions as set forth in the NIST CSF: (i) identify; (ii) protect; (iii) detect; (iv) respond; and (v) recover. As part of that program, we maintain an incident detection and response process that is designed to ensure we appropriately identify, investigate, respond to, and recover from, cybersecurity incidents in order to protect our information, systems and resources. As part of our process, we maintain operational plans for incident response and recovery activities. We regularly review our incident response process and conduct multiple incident response exercises each year, including sessions with management, to test and assess our preparedness to respond to a cybersecurity incident.
As part of our incident detection and response process, we have established internal teams to investigate and escalate notification of cybersecurity incidents. Pursuant to this process, cybersecurity incidents are reported to appropriate personnel within Equifax (including the CISO and the CEO) and to the Board of Directors based on incident severity. We track incidents through resolution, conduct post-incident analysis and update our processes and procedures if areas for improvement are identified. On a monthly basis, a summary of prior period cybersecurity investigation escalations is reviewed by management, including our head of Internal Audit, our CISO, our Chief Financial Officer and our Chief Legal Officer.
To inform our incident detection and response process, our cyber intelligence operations team regularly performs exercises to simulate real threat scenarios that would be carried out by a perpetrator by utilizing the actual tools and methodologies that would be deployed in such an attack (so called “red team” activities).
Risk Management
*•*Cybersecurity Incorporated into Enterprise Risk Management Program. We have implemented an enterprise risk management (“ERM”) program that operates under the leadership of our Chief Privacy and Compliance Officer. Each business unit and corporate support unit has primary responsibility for assessing and mitigating risks within its respective areas of responsibility, and the ERM team is responsible for oversight and reporting to management and the Board.
Under our ERM program, we conduct an annual enterprise risk assessment, which produces an enterprise risk scorecard. Cybersecurity is one of nine primary risk categories identified within the scorecard. The cybersecurity risk rating is based on a detailed enterprise security risk assessment performed by the Security team. The enterprise risk scorecard is reviewed with management and the Board of Directors on an annual basis.
*•*Security Risk Assessment. The Security team performs an annual enterprise security risk assessment of the information security program that is provided to management, the Board of Directors and other relevant parties. The security risk assessment provides a detailed understanding of the information security program in order to inform decisions and support risk response. The security risk assessment process evaluates the program’s control domains through various analyses and testing methods to determine the overall level of risk present within the environment over the period evaluated. The risk assessment identifies risks and considers observations from multiple business process- and system-level assessments.
We leverage NIST guidance to inform our process for conducting the security risk assessment. The risk management program and processes can be described in four steps: (i) frame risk; (ii) assess risk; (iii) respond to risk; and (iv) monitor risk.
*•*Third Party Risk Management. We have a governance process in place to oversee our third-party vendors who have access to our network or who hold or store personal information on our behalf (“risk vendors”). Our risk vendor contracts contain provisions requiring our suppliers to maintain a program that meets our information security standards. We periodically assess risk vendor compliance with our information security program requirements. One such requirement is the obligation that our risk vendors must notify Equifax within a designated time period upon identifying certain cybersecurity events.
*•*M&A Due Diligence and Integration Process. Our Security team has implemented a due diligence and integration process for entities we acquire through mergers and acquisitions (“M&A”). This process is designed to protect our information systems, align acquired entities with our security controls, and comply with applicable legal and regulatory requirements, without interrupting critical business processes. Our M&A security integration status is reported regularly to management and the Technology Committee and annually to the Board of Directors.
*•*Employee Training and Awareness. In order to help bolster our cybersecurity defenses and mitigate the risk presented by insider or employee cyber and security threats, Equifax has incorporated employee training into our security program. On an annual basis, all employees are required to complete mandatory security training. In addition, each Equifax employee receives training customized to his or her role or function, and has visibility into his or her individual security performance. We continually measure and assess key employee behaviors, including secure browsing and sensitive data handling. In order to promote a Company-wide focus on data security and reinforce overall security program goals, Equifax includes an individual security performance measure as one of the metrics used to evaluate the performance of all bonus-eligible employees under our annual incentive compensation program.
*•*Cybersecurity Insurance. We maintain cybersecurity insurance under our errors and omissions/professional liability policy, which provides coverage for certain costs related to cybersecurity incidents.
Review and Assessment of Information Security Program
We conduct regular audits of our information security program, including third party assessments and review by our internal audit department.
*•*Third Party Assessments of Security Program Maturity. Equifax has a formal process in place to annually assess our security program maturity, which is a measure of our ability to adapt to cyber threats and manage risk over time. Under the oversight of the Technology Committee of the Board of Directors, Equifax engages a third party research and advisory firm to conduct an annual analysis of the maturity of our security program and identify potential initiatives to enhance maturity. On an annual basis, the Technology Committee reviews the results of this analysis with management, including a review of Company performance against relevant benchmarks.
*•*Controls Testing. Equifax has a formal process in place to periodically assess the effectiveness of controls in our security controls framework. These controls assessments are performed by the Security team. Results are regularly reported to management and the Technology Committee and annually to the Board of Directors.
*•*Internal Audit Review. Our internal audit department is responsible for providing the Audit and Technology Committees and management with an independent assessment and assurance regarding the design and effectiveness of the risk management framework related to cybersecurity. As part of the assessment of our cybersecurity program, the internal audit department has a “red team” that regularly performs testing to simulate real threat scenarios that would be carried out by a perpetrator. On a quarterly basis, our head of Internal Audit provides an update to management and the Audit and Technology Committees of the Board on audit activities pursuant to the IT and security portions of the
internal audit plan. Our head of Internal Audit reviews the IT and security audit reports issued, including a summary of IT and security audit findings by inherent risk and residual risk rating.
Cybersecurity Risks to our Business
As a global data, analytics and technology company, our products and services involve the storage and transmission of personal information of consumers. As a result, we are routinely the target of attempted cyber and other security threats presented by outside third parties, as well as security threats presented by employees and other insiders.
In 2017, we experienced a material cybersecurity incident following a criminal attack on our systems that involved the theft of personal information of U.S., Canadian and U.K. consumers. If we experience additional significant compromises of our security measures, including from incidents that we fail to detect for a period of time, sensitive data may be accessed, stolen, disclosed, altered or lost. Any such access, disclosure, alteration or other loss of information could subject us to significant litigation, regulatory fines or penalties, any of which could have a material adverse effect on our cash flows, competitive position, financial condition or results of operations.
Cybersecurity incidents, and the adverse publicity that may follow, can have a negative impact on our reputation and our relationship with our customers. For example, our reputation with consumers and other stakeholders and our customer relationships were damaged following the cybersecurity incident in 2017, resulting in a negative impact on our revenue for a period of time. If we experience another material cybersecurity incident or are otherwise unable to demonstrate the security of our systems and the data we maintain and retain the trust of our customers, consumers and data suppliers, we could experience a substantial negative impact on our business.
For additional information related to the cybersecurity-related risks relevant to our business, see “Risk Factors—Technology and Data Security Risks—Security breaches and other disruptions to our information technology infrastructure could compromise Company, consumer and customer information, interfere with our operations, cause us to incur significant costs for remediation and enhancement of our IT systems and expose us to legal liability, all of which could have a substantial negative impact on our business and reputation” in Part I, Item 1A. of this annual report on Form 10-K.
Governance
Board Oversight of Cybersecurity
The Equifax Board of Directors monitors our “tone at the top” and risk culture and oversees principal risks facing the Company. On an annual basis, the Board reviews an enterprise risk assessment prepared by management that describes the principal risks and monitors the steps management is taking to map and mitigate these risks. The Board then sets the general level of risk appropriate for the Company through business strategy reviews. Risks are assessed throughout the business, focusing on nine primary risk categories, including cybersecurity.
In addition, the Audit and Technology Committees of the Board coordinate on risk management oversight with respect to cybersecurity, including through quarterly joint meetings that cover the following topics:
-
Regular reports from the internal audit department regarding the security and technology portions of the internal audit plan
-
Regular reports from our CISO and Chief Technology Officer regarding the cybersecurity control environment, including remediation updates, control posture analyses and other recurring items
-
Regular reports from our Chief Privacy and Compliance Officer regarding our global privacy, risk management and compliance programs, including matters related to cybersecurity
The Technology Committee of the Board oversees our information security program, including:
-
Reviewing with management our technology investments and infrastructure associated with risk management, including policies relating to information security, disaster recovery and business continuity
-
Receiving quarterly reports directly from our CISO, including updates on our enterprise cybersecurity threat level
-
Overseeing the engagement of outside advisors to review our cybersecurity program
-
Reviewing the results of our annual information security program maturity assessment performed by a third party
-
Reviewing the results of our annual security program risk assessment prepared by management
Management Oversight of Cybersecurity Risk
Our information security program is managed through implementation, monitoring and continuous improvement of the security program with active participation of management as described below.
-
Senior Leadership Team. The Equifax senior leadership team, consisting of our CEO and his direct reports (“SLT”), sets the tone for strategic growth, effective operations and risk mitigation at the management level. The SLT supports the management of the information security program through proper resource allocation and decision-making involving high risk issues. The SLT has overall managerial responsibility for confirming that the information security program functions in a manner that meets the needs of Equifax.
-
Chief Information Security Officer. Equifax has a CISO who is a member of the SLT and reports directly to our CEO. Our CISO has more than two decades of experience in cybersecurity-related roles, including serving as CISO at other large, multinational companies. Our CISO is responsible for oversight of the global Security team and the implementation and execution of the information security program. Our CISO helps ensure that the program is strategically aligned to Equifax’s business strategy and is responsible for reporting on the effectiveness of the program to the SLT and the Board of Directors.
-
Global Security Team. The Equifax global Security team is responsible for supporting the CISO in the execution of the information security program to meet the program’s objectives. The Security team is directly responsible for the day to day program activities such as planning, implementation, monitoring and reporting on operational capabilities.
Item 2. PROPERTIES
Our executive offices are located at 1550 Peachtree Street, N.W., Atlanta, Georgia. Our other properties are geographically distributed to meet sales and operating requirements worldwide. We consider these properties to be both suitable and adequate to meet our current operating requirements. We ordinarily lease office space for conducting our business and are obligated under approximately 55 leases and other rental arrangements for our field locations. We owned 5 office buildings at December 31, 2023, including our executive offices, one campus which houses our Alpharetta, Georgia technology center, a building utilized by our Workforce Solutions operations located in St. Louis, Missouri, as well as two buildings utilized by our Latin America operations.
For additional information regarding our obligations under leases, see Note 6 and Note 12 of the Notes to Consolidated Financial Statements in Item 8 of this Form 10-K. We believe that suitable additional space will be available to accommodate our future needs.
Item 3. LEGAL PROCEEDINGS
Remaining Matters Related to 2017 Cybersecurity Incident
Canadian Class Actions. Five putative Canadian class actions, four of which are on behalf of a national class of approximately 19,000 Canadian consumers, are pending against us in Ontario, British Columbia and Alberta. Each of the proposed Canadian class actions asserts a number of common law and statutory claims seeking monetary damages and other related relief in connection with a material cybersecurity incident in 2017. In addition to seeking class certification on behalf of Canadian consumers whose personal information was allegedly impacted by the 2017 cybersecurity incident, in some cases, plaintiffs also seek class certification on behalf of a larger group of Canadian consumers who had contracts for subscription products with Equifax around the time of the incident or earlier and were not impacted by the incident. The Ontario class action has been certified in part but is otherwise at a preliminary stage. All other purported class actions are at preliminary stages or stayed.
FCA Investigation. The U.K.’s Financial Conduct Authority (“FCA”) opened an enforcement investigation against our U.K. subsidiary, Equifax Limited, in October 2017 in connection with the 2017 cybersecurity incident. We received a notice with the FCA's findings on October 13, 2023, and paid a penalty of $13.5 million to resolve the matter.
CFPB Matters
In December 2021, we received a Civil Investigative Demand (a “CID”) from the CFPB as part of its investigation into our consumer disputes process in order to determine whether we have followed the FCRA's requirements for the proper handling of consumer disputes. The CID requests the production of documents and answers to written questions. We are cooperating with the CFPB in its investigation and providing responses and information on an ongoing basis.
In January 2023, the CFPB informed us that its enforcement division will be investigating our previously-disclosed coding issue identified within a legacy server environment in the U.S. that impacted how some credit scores were calculated during a three-week period in 2022. We are cooperating with the CFPB in its investigation.
In July 2023, we received a CID from the CFPB as part of its investigation into data accuracy and dispute handling at our Workforce Solutions business unit in order to determine whether we have followed the FCRA's requirements. The CID requests the production of documents and answers to written questions. We are cooperating with the CFPB in its investigation and providing responses and information on an ongoing basis.
At this time, we are unable to predict the outcome of these CFPB investigations, including whether the investigations will result in any actions or proceedings against us.
Other
Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest many of these matters. Given the number of these matters, some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.
For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in Item 8 of this report.
Item 4. MINE SAFETY DISCLOSURES
Not applicable.
PART II
Item 5. MARKET FOR THE REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
Equifax’s common stock is traded on the New York Stock Exchange under the symbol “EFX.” As of January 31, 2024, Equifax had approximately 2,494 holders of record; however, Equifax believes the number of beneficial owners of common stock exceeds this number.
Shareholder Return Performance Graph
The graph below compares Equifax’s five-year cumulative total shareholder return with that of the Standard & Poor’s Composite Stock Index (S&P 500) and a peer group index, the S&P 500 Banks Index (Industry Group). The graph assumes that the value of the investment in our Common Stock and each index was $100 on the last trading day of 2018 and that all quarterly dividends were reinvested without commissions. Our past performance may not be indicative of future performance.
COMPARATIVE FIVE-YEAR CUMULATIVE TOTAL RETURN AMONG EQUIFAX INC., S&P 500 INDEX AND S&P 500 BANKS INDEX (INDUSTRY GROUP)

| Fiscal Year Ended December 31, | |||||||||||||||||||||||||||||||||||
| Initial | 2019 | 2020 | 2021 | 2022 | 2023 | ||||||||||||||||||||||||||||||
| Equifax Inc. | 100.00 | 150.46 | 207.07 | 314.39 | 208.70 | 265.53 | |||||||||||||||||||||||||||||
| S&P 500 Index | 100.00 | 128.88 | 149.83 | 190.13 | 153.16 | 190.27 | |||||||||||||||||||||||||||||
| S&P 500 Banks Index (Industry Group) | 100.00 | 126.77 | 111.79 | 146.34 | 121.83 | 123.96 |
The table below contains information with respect to purchases made by or on behalf of Equifax of its common stock during the fourth quarter ended December 31, 2023:
Issuer Purchases of Equity Securities
| Period | Total Number of Shares Purchased (1) | Average Price Paid Per Share (2) | Total Number of Shares Purchased as Part of Publicly-Announced Plans or Programs | Maximum Number (or Approximate Dollar Value) of Shares that May Yet Be Purchased Under the Plans or Programs (3) | ||||||||||||||||||||||
| October 1 - October 31, 2023 | 914 | $ | — | — | $ | 520,168,924 | ||||||||||||||||||||
| November 1 - November 30, 2023 | 18,716 | $ | — | — | $ | 520,168,924 | ||||||||||||||||||||
| December 1 - December 31, 2023 | 8,763 | $ | — | — | $ | 520,168,924 | ||||||||||||||||||||
| Total | 28,393 | $ | — | — | $ | 520,168,924 |
(1) The total number of shares purchased includes, if applicable: (a) shares purchased pursuant to our publicly-announced share repurchase program (the "Repurchase Program"); and (b) shares surrendered, or deemed surrendered, in satisfaction of the exercise price and/or to satisfy tax withholding obligations in connection with the exercise of employee stock options and vesting of restricted stock, totaling 914 shares for the month of October 2023, 18,716 shares for the month of November 2023 and 8,763 shares for the month of December 2023.
(2) Average price paid per share for shares purchased as part of the Repurchase Program (includes brokerage commissions).
(3) We purchased no common shares during the twelve months ended December 31, 2023. At December 31, 2023, the amount authorized for future share repurchases under the Repurchase Program was $520.2 million.
Information relating to compensation plans under which the Company’s equity securities are authorized for issuance will be included in the section captioned “Equity Compensation Plan Information” in our 2024 Proxy Statement and is incorporated herein by reference.
Item 6. RESERVED
Not applicable.
Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS
The following Management’s Discussion and Analysis (“MD&A”) is intended to help the reader understand the results of operations and financial condition of Equifax Inc. MD&A is provided as a supplement to and should be read in conjunction with our consolidated financial statements and the accompanying Notes to Financial Statements in Item 8 of this Form 10-K. This section discusses the results of our operations for the year ended December 31, 2023 compared to the year ended December 31, 2022 and the year ended December 31, 2022 compared to the year ended December 31, 2021. All percentages have been calculated using unrounded amounts for each of the periods presented.
As used herein, the terms Equifax, the Company, we, our and us refer to Equifax Inc., a Georgia corporation, and its consolidated subsidiaries as a combined entity, except where it is clear that the terms mean only Equifax Inc.
All references to earnings per share data in MD&A are to diluted earnings per share, or EPS, unless otherwise noted. Diluted EPS is calculated to reflect the potential dilution that would occur if stock options or other contracts to issue common stock were exercised and resulted in additional common shares outstanding.
BUSINESS OVERVIEW
Equifax Inc. is a global data, analytics and technology company. We provide information solutions for businesses, governments and consumers, and we provide human resources business process automation and outsourcing services for employers. We have a large and diversified group of clients, including financial institutions, corporations, government agencies and individuals. Our services are based on comprehensive databases of consumer and business information derived from numerous sources including credit, financial assets, telecommunications and utility payments, employment, income, educational history, criminal justice data, healthcare professional licensure and sanctions, demographic and marketing data. We use advanced statistical techniques, machine learning and proprietary software tools to analyze available data to create customized insights, decision-making and process automation solutions and processing services for our clients. We are a leading provider of information and solutions used in payroll-related and human resource management business process services in the U.S. as well as e-commerce fraud and charge back protection services in North America. For consumers, we provide products and services to help people understand, manage and protect their personal information and make more informed financial decisions. Additionally, we also provide information, technology and services to support debt collections and recovery management.
We currently operate in four global regions: North America (U.S. and Canada), Asia Pacific (Australia, New Zealand and India), Europe (the U.K., Spain and Portugal) and Latin America (Argentina, Brazil, Chile, Costa Rica, Dominican Republic, Ecuador, El Salvador, Honduras, Mexico, Paraguay, Peru and Uruguay). We maintain support operations in Chile, Costa Rica, India and Ireland. We also have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and Brazil.
Recent Events and Company Outlook
As further described above, we operate in the U.S., which represented 77% of our revenue in 2023, and internationally in 20 countries. Our products and services span a wide variety of vertical markets including financial services, mortgage, talent solutions, federal, state and local governments, automotive, telecommunications, e-commerce and many others.
Demand for our services tends to be correlated to general levels of economic activity and to consumer credit and small business commercial credit decisioning and portfolio review, marketing, identity validation and fraud protection activity, employee hiring and onboarding activity, and activity in provisioning support services in the U.S. by government agencies. Demand is also enhanced by our initiatives to expand our products, capabilities and markets served.
For 2024, our planning assumes that U.S. economic activity, as measured by GDP, is expected to grow but at a slower rate of growth than experienced in 2023. Our plan assumes the U.S. mortgage market, as measured by credit inquiries, is expected to decline by about 16% in 2024 versus 2023. The U.S. mortgage market, particularly the mortgage refinance portion of the U.S. mortgage market, can be significantly impacted by U.S. interest rates which impact mortgage rates available to consumers. In the international markets in which we operate, in particular in Australia, the U.K. and Canada, our planning also assumes economic activity, as measured by GDP, to grow in 2024 but at slower rates than in 2023.
Segment and Geographic Information
Segments. The Workforce Solutions segment consists of the Verification Services and Employer Services business lines. Verification Services revenue is transaction-based and is derived primarily from employment and income verification, as well as criminal justice data. Employer Services revenue is derived from our provision of certain human resources business process outsourcing services that include both transaction and subscription based product offerings. These services include unemployment claims management, I-9 and onboarding services, Affordable Care Act compliance management, tax credits and incentives and other complementary employment-based transaction services. Workforce Solutions has established operations in Canada, Australia and the U.K.
The USIS segment consists of three service lines: Online Information Solutions, Mortgage Solutions, and Financial Marketing Services. Online Information Solutions and Mortgage Solutions revenue is principally transaction-based and is derived from our sales of products such as consumer and commercial credit reporting and scoring, identity management, fraud detection, modeling services and consumer credit monitoring services. USIS also markets certain decisioning software services which facilitate and automate a variety of consumer and commercial credit-oriented decisions. Online Information Solutions also includes our U.S. consumer credit monitoring solutions business. Financial Marketing Services revenue is principally project and subscription based and is derived from our sales of batch credit and consumer wealth information such as those that assist clients in acquiring new customers, cross-selling to existing customers and managing portfolio risk.
The International segment consists of Asia Pacific, Europe, Canada and Latin America. Canada’s services are similar to our USIS offerings. Asia Pacific, Europe and Latin America are made up of varying mixes of service lines that are generally consistent with those in our USIS reportable segment. We also provide information and technology services to support lenders and other creditors in the collections and recovery management process.
Geographic Information. We currently have operations in the following countries: Argentina, Australia, Brazil, Canada, Chile, Costa Rica, Dominican Republic, Ecuador, El Salvador, Honduras, India, Ireland, Mexico, New Zealand, Paraguay, Peru, Portugal, Spain, the U.K., Uruguay and the U.S. We also have investments in consumer and/or commercial credit information companies through joint ventures in Cambodia, Malaysia, Singapore and Brazil. Approximately 77% and 78% of our revenue was generated in the U.S. during the twelve months ended December 31, 2023 and 2022, respectively.
Seasonality. We experience seasonality in certain of our revenue streams. Revenue generated by the online consumer information services component of our USIS operating segment is typically the lowest during the first quarter, when consumer lending activity is at a seasonal low. Revenue generated from the Employer Services business unit within the Workforce Solutions opera
Showing the first 8K of 108K characters. Open the full section
Item 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK
In the normal course of our business, we are exposed to market risk, primarily from changes in foreign currency exchange rates and interest rates that could impact our results of operations and financial position. We manage our exposure to these market risks through our regular operating and financing activities and, when deemed appropriate, through the use of derivative financial instruments, such as interest rate swaps, to hedge certain of these exposures. We use derivative financial instruments as risk management tools and not for speculative or trading purposes.
Foreign Currency Exchange Rate Risk
A substantial majority of our revenue, expense and capital expenditure activities are transacted in U.S. dollars. However, we do transact business in other currencies, primarily the Australian dollar, the Canadian dollar, the British pound, the Brazilian real, the Chilean peso, the Argentine peso and the Euro. For most of these foreign currencies, we are a net recipient, and, therefore, benefit from a weaker U.S. dollar and are adversely affected by a stronger U.S. dollar relative to the foreign currencies in which we transact significant amounts of business.
We are required to translate, or express in U.S. dollars, the assets and liabilities of our foreign subsidiaries that are denominated or measured in foreign currencies at the applicable year-end rate of exchange on our Consolidated Balance Sheets and income statement items of our foreign subsidiaries at the average rates prevailing during the year. We record the resulting translation adjustment, and gains and losses resulting from the translation of intercompany balances of a long-term investment nature within other comprehensive income, as a component of our shareholders’ equity. Foreign currency transaction gains and losses, which have historically been immaterial, are recorded on our Consolidated Statements of Income. We generally do not mitigate the risks associated with fluctuating exchange rates, although we may from time to time through forward contracts or other derivative instruments hedge a portion of our translational foreign currency exposure or exchange rate risks associated with material transactions which are denominated in a foreign currency.
For the year ended December 31, 2023, a 10% weaker U.S. dollar against the currencies of all foreign countries in which we had operations during 2023 would have increased our revenue by $116.0 million and our pre-tax operating profit by $9.9 million. For the year ended December 31, 2022, a 10% weaker U.S. dollar against the currencies of all foreign countries in which we had operations during 2022 would have increased our revenue by $105.8 million and our pre-tax operating profit by $8.2 million. A 10% stronger U.S. dollar would have resulted in similar decreases to our revenue and pre-tax operating profit for 2023 and 2022.
On average across our mix of international businesses, foreign currencies at December 31, 2023 were weaker against the U.S. dollar than the average foreign exchange rates that prevailed across the full year 2022. As a result, if foreign exchange rates were unchanged throughout 2023, foreign exchange translation would increase growth as reported in U.S. dollars. As foreign exchange rates change daily, there can be no assurance that foreign exchange rates will remain constant throughout 2024, and rates could go either higher or lower.
Interest Rate Risk
Our exposure to market risk for changes in interest rates relates to our variable-rate commercial paper, Revolver and term loan borrowings. We attempt to achieve the lowest all-in weighted-average cost of debt while simultaneously taking into account the mix of our fixed- and variable-rate debt and the average life and scheduled maturities of our debt. At December 31, 2023, our weighted average cost of debt was 4.2% and weighted-average life of debt was 4.9 years. At December 31, 2023, 84% of our debt was fixed rate and the remaining 16% was variable rate. Occasionally, we use derivatives to manage our exposure to changes in interest rates by entering into interest rate swaps. A 100 basis point increase in the weighted-average interest rate on our variable-rate debt would have increased our 2023 interest expense by $8.9 million.
Based on the amount of outstanding variable-rate debt, we have exposure to interest rate risk. In the future, if our mix of fixed-rate and variable-rate debt were to change due to additional borrowings under existing or new variable-rate debt, we could have additional exposure to interest rate risk. The nature and amount of our long-term and short-term debt, as well as the proportionate amount of fixed-rate and variable-rate debt, can be expected to vary as a result of future business requirements, market conditions and other factors.
Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA
Report of Independent Registered Public Accounting Firm
To the Shareholders and the Board of Directors of Equifax Inc.
Opinion on Internal Control Over Financial Reporting
We have audited Equifax Inc.’s internal control over financial reporting as of December 31, 2023, based on criteria established in Internal Control—Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (“2013 framework”) (the COSO criteria). In our opinion, Equifax Inc. (the Company) maintained, in all material respects, effective internal control over financial reporting as of December 31, 2023, based on the COSO criteria.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated balance sheets of the Company as of December 31, 2023 and 2022, the related consolidated statements of income, comprehensive income, cash flows and shareholders’ equity and accumulated other comprehensive loss for each of the three years in the period ended December 31, 2023, and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) and our report dated February 22, 2024 expressed an unqualified opinion thereon.
Basis for Opinion
The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting included in the accompanying Management’s Annual Report on Internal Control Over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects.
Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.
Definition and Limitations of Internal Control Over Financial Reporting
A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
/s/ Ernst & Young LLP
Atlanta, Georgia
February 22, 2024
Report of Independent Registered Public Accounting Firm
To the Shareholders and the Board of Directors of Equifax Inc.
Opinion on the Consolidated Financial Statements
We have audited the accompanying consolidated balance sheets of Equifax Inc. (the Company) as of December 31, 2023 and 2022, the related consolidated statements of income, comprehensive income, cash flows, and shareholders’ equity and accumulated other comprehensive loss for each of the three years in the period ended December 31, 2023, and the related notes and financial statement schedule listed in the Index at Item 15(a)(2) (collectively referred to as the “consolidated financial statements”). In our opinion, the consolidated financial statements present fairly, in all material respects, the financial position of the Company at December 31, 2023 and 2022, and the results of its operations and its cash flows for each of the three years in the period ended December 31, 2023, in conformity with U.S. generally accepted accounting principles.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the Company's internal control over financial reporting as of December 31, 2023, based on criteria established in Internal Control-Integrated Framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (2013 framework) and our report dated February 22, 2024 expressed an unqualified opinion thereon.
Basis for Opinion
These consolidated financial statements are the responsibility of the Company's management. Our responsibility is to express an opinion on the Company’s consolidated financial statements based on our audits. We are a public accounting firm regis
Showing the first 8K of 234K characters. Open the full section
Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE
None.
Item 9A. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our Chief Executive Officer and Chief Financial Officer, evaluated the effectiveness of Equifax’s disclosure controls and procedures as of the end of the period covered by this report. Based on that evaluation, our Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures as of the end of the period covered by this report (i) were appropriately designed to provide reasonable assurance of achieving their objectives and (ii) were effective and provided reasonable assurance that the information required to be disclosed by Equifax in reports filed under the Exchange Act is (a) recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms and (b) accumulated and communicated to Equifax’s management, including our Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions regarding required disclosure.
Management’s Annual Report on Internal Control Over Financial Reporting
Our management is responsible for establishing and maintaining adequate internal control over financial reporting. Internal control over financial reporting is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act as a process designed by, or under the supervision of, our Chief Executive Officer and Chief Financial Officer and effected by our Board of Directors, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles and includes those policies and procedures that:
-
pertain to the maintenance of records that in reasonable detail accurately and fairly reflect transactions and dispositions of our assets;
-
provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that our receipts and expenditures are being made only in accordance with authorizations of our management and directors; and
-
provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
Our management assessed the effectiveness of Equifax’s internal control over financial reporting as of December 31, 2023 using the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) in Internal Control-Integrated Framework (2013 Framework). Based on this assessment using those criteria, our management concluded that, as of December 31, 2023, Equifax’s internal control over financial reporting was effective. Management reviewed the results of its assessment with the Audit Committee of its Board of Directors. The effectiveness of Equifax’s internal control over financial reporting as of December 31, 2023 has been audited by Ernst & Young LLP, Equifax’s independent registered public accounting firm, as stated in their report, which appears in “Item 8. Financial Statements and Supplementary Data” of this Form 10-K on page 56.
Changes in Internal Control Over Financial Reporting
There have been no changes in internal control over financial reporting identified in connection with the foregoing that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
Item 9B. OTHER INFORMATION
Rule 10b5-1 Trading Plans of Directors and Executive Officers
The following table describes any contracts, instructions or written plans for the sale or purchase of Equifax securities and intended to satisfy the affirmative defense conditions of Rule 10b5-1(c) of the Exchange Act that were adopted by our directors and executive officers during the quarter ended December 31, 2023:
| Name and Title | Date of Adoption of Rule 10b5-1 Trading Plan | Scheduled Expiration Date of Rule 10b5-1 Trading Plan(1) | Aggregate Number of Securities to Be Purchased or Sold | |||||||||||||||||
| Mark Begor, Chief Executive Officer | 11/06/23 | 11/18/24 | Sale of up to 233,204 shares of common stock in multiple transactions |
(1) A trading plan may also expire on such earlier date that all transactions under the trading plan are completed.
During the quarter ended December 31, 2023, none of our directors or executive officers terminated a Rule 10b5-1 trading plan or adopted or terminated a non-Rule 10b5-1 trading arrangement (as defined in Item 408(c) of Regulation S-K).
PART III
Item 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE
Except for the information about our executive officers shown below, the information required by this Item 10 is incorporated herein by reference from the information contained in our Proxy Statement to be filed with the SEC in connection with the solicitation of proxies for our 2024 Annual Meeting of Shareholders (the “2024 Proxy Statement”) under the sections entitled “Proposal 1 Election of Directors,” “Section 16(a) Beneficial Ownership Reporting Compliance” and “Board Leadership and Corporate Governance—Committees of the Board of Directors.”
We have adopted a written Code of Ethics and Business Conduct applicable to all our employees, including our principal executive officer, principal financial officer, and principal accounting officer and controller, and to members of our Board of Directors. Our Code of Ethics and Business Conduct is available on our investor relations website: www.equifax.com/about-equifax/corporate-governance. We will disclose amendments to certain provisions of our Code of Ethics and Business Conduct, or waivers of such provisions granted to executive officers and directors, on this website.
Executive Officers
Information regarding the executive officers of Equifax Inc. is set forth below.
Mark W. Begor (65) has been our Chief Executive Officer and a member of the Board of Directors since April 2018. Prior thereto, he was a Managing Director in the Industrial and Business Services group at Warburg Pincus, a global private equity investment firm, since June 2016. Prior to Warburg Pincus, Mr. Begor spent 35 years at General Electric Company (“GE”), a global industrial and financial services company, in a variety of operating and financial roles. During his career at GE, Mr. Begor served in a variety of roles leading multibillion dollar units of the company, including President and CEO of GE Energy Management from 2014 to 2016, President and CEO of GE Capital Real Estate from 2011 to 2014, and President and CEO of GE Capital Retail Finance (Synchrony Financial) from 2002 to 2011. Mr. Begor served on the Fair Isaac Corporation (FICO) board of directors from 2016 to 2018. He currently serves on the board of directors of NCR Atleos Corp.
Sunil Bindal (49) has been our Executive Vice President, Chief Corporate Development Officer since October 2020. Prior to joining Equifax, Mr. Bindal served as Senior Vice President, Global Head of Mergers and Acquisitions and Corporate Development, at Total System Services since July 2018. Prior thereto, he served as Vice President of Corporate Development at Broadridge Financial Solutions since August 2015. Prior thereto, he served as Director, Technology Mergers and Acquisitions, of Credit Suisse since July 2006.
Carla Chaney (53) has been our Executive Vice President, Chief Human Resources Officer since April 2019. Prior thereto, she served as Executive Vice President, Human Resources and Communications of Graphic Packaging Holding Company and Graphic Packaging International, since February 2012. Prior thereto, she held a variety of leadership roles with Exide Technologies and Newell Rubbermaid, Inc., since 2004.
Jamil Farshchi (46) has been our Executive Vice President, Chief Information Security Officer since February 2018 and our acting Chief Technology Officer since February 2024. Prior to joining Equifax, Mr. Farshchi served as Chief Information Security Officer at The Home Depot since April 2015. Prior thereto, he was the first Global Chief Information Security Officer at Time Warner Inc., from August 2014 to March 2015. Prior thereto, he was the Vice President of Global Information Security at Visa Inc. from August 2011 to August 2014. Mr. Farshchi has also held senior roles at Los Alamos National Laboratory, Sitel Corporation, Nextwave Broadband and NASA. He currently serves on the board of directors of UKG Inc.
John W. Gamble, Jr. (61) has been our Executive Vice President, Chief Financial Officer and Chief Operations Officer since February 2021. Prior thereto, he was Corporate Vice President and Chief Financial Officer since May 2014. Prior to that, Mr. Gamble was Executive Vice President and Chief Financial Officer of Lexmark International, Inc., a global provider of document solutions, enterprise content management software and services, printers and multifunction printers, from September 2005 until May 2014.
Todd Horvath (50) has been our Executive Vice President, President, U.S. Information Solutions since March 2023. Prior to joining Equifax, Mr. Horvath served in roles of increasing responsibility at Fiserv from 2017-2023, most recently serving as Co-Head of the Fiserv Banking Organization. Prior to that, Mr. Horvath served in various international leadership roles at Automatic Data Processing from 2001-2017. Prior thereto, he was General Director, Venezuela Operations at Sharp Image Gaming in 2001.
Julia A. Houston (53) has been our Executive Vice President, Chief Strategy and Marketing Officer since March 2021. Prior thereto, she was our Chief Transformation Officer since October 2017. Prior thereto, she was Senior Vice President, U.S. Legal, since October 2013. Prior to joining Equifax, Ms. Houston was Senior Vice President, General Counsel and Corporate Secretary at Convergys Corporation, from 2011 to 2013. Prior thereto, she served in roles of increasing responsibility at Mirant Corporation from 2004 to 2010, ultimately serving as Senior Vice President, General Counsel, Chief Compliance Officer and Corporate Secretary.
John J. Kelley III (63) has been our Executive Vice President, Chief Legal Officer and Corporate Secretary since January 2013. Prior to joining Equifax, Mr. Kelley was a senior partner in the Corporate Practice Group of the law firm of King & Spalding LLP.
Cecilia Mao (49) has been our Chief Product Officer since May 2020 and was appointed as Executive Vice President, Chief Product Officer in February 2024. Prior to joining Equifax, Ms. Mao served as Vice President of Product at Oracle Data Cloud from December 2016 to May 2020, where she led teams in business strategy, product management and delivery for identity, data management platform and digital data products. Prior thereto, she held various product management roles on decision and analytics for over a decade at FICO and Verisk Analytics, Inc.
Lisa Nelson (60) has been our Executive Vice President, President, International since June 2021. Prior thereto, she served as Group Managing Director, Equifax Australia and New Zealand, since August 2019. Prior thereto, she served as President and General Manager, Equifax Canada, since January 2015. Prior thereto, she served as Senior Vice President, Enterprise Alliance Leader of Equifax U.S. Information Solutions, since November 2011. Prior to joining Equifax, she served as Vice President, Global Scoring Solutions of FICO, since August 2004.
Rodolfo O. Ploder (63) has been our Executive Vice President, President, Workforce Solutions since November 2015. Prior thereto, he served as President, U.S. Information Solutions, since April 2010. Prior thereto, he served as President, International, from January 2007 to April 2010. Prior thereto, he was Group Executive, Latin America from February 2004 to January 2007.
Harald Schneider (50) has been our Chief Data & Analytics Officer since May 2022 and was appointed as Executive Vice President, Chief Data & Analytics Officer in February 2024. Prior to joining Equifax, Mr. Schneider served as Global Head of Data Products at Visa Inc. from August 2018 to May 2022. Prior thereto, he served as Chief Analytics Officer at Tandem Bank in the U.K. from September 2016 to April 2018. Prior thereto, he held various international data and business leadership roles at Capital One Financial Corporation, Citigroup Inc. and Pardus Capital Management.
Item 11. EXECUTIVE COMPENSATION
The information required by this Item 11 is incorporated herein by reference from the information contained in our 2024 Proxy Statement under the sections entitled “Executive Compensation” and “Director Compensation.”
Item 12. SECURITY OWNERSHIP OF CERTAIN BENEFICIAL OWNERS AND MANAGEMENT AND RELATED STOCKHOLDER MATTERS
The information required by this Item 12 is incorporated herein by reference from the information contained in our 2024 Proxy Statement under the sections entitled “Security Ownership of Management and Certain Beneficial Owners” and “Executive Compensation Equity Compensation Plan Information.”
Item 13. CERTAIN RELATIONSHIPS AND RELATED TRANSACTIONS AND DIRECTOR INDEPENDENCE
The information required by this Item 13 is incorporated herein by reference from the information contained in our 2024 Proxy Statement under the sections entitled “Board Leadership and Corporate Governance Director Independence, ” “Related Person Transaction Policy” and “Certain Relationships and Related Person Transactions of Directors, Executive Officers, and 5 Percent Shareholders.”
Item 14. PRINCIPAL ACCOUNTANT FEES AND SERVICES
The information required by this Item 14 is incorporated herein by reference from the information contained in our 2024 Proxy Statement under the section entitled “Proposal 3 Ratification of Appointment of Ernst & Young LLP as Independent Registered Public Accounting Firm for 2024.”
PART IV
Item 15. EXHIBITS AND FINANCIAL STATEMENT SCHEDULES
**(a)**List of Documents Filed as a Part of This Report:
(1) Financial Statements. The following financial statements are included in Item 8 of Part II:
-
Consolidated Balance Sheets — December 31, 2023 and 2022;
-
Consolidated Statements of Income for the Years Ended December 31, 2023, 2022 and 2021;
-
Consolidated Statements of Comprehensive Income for the Years Ended December 31, 2023, 2022 and 2021;
-
Consolidated Statements of Cash Flows for the Years Ended December 31, 2023, 2022 and 2021;
-
Consolidated Statements of Shareholders’ Equity and Accumulated Other Comprehensive Loss for the Years Ended December 31, 2023, 2022 and 2021; and
-
Notes to Consolidated Financial Statements.
(2) Financial Statement Schedules.
- Schedule II — Valuation and Qualifying Accounts
All other schedules for which provision is made in the applicable accounting regulation of the SEC are not required under the related instructions or are inapplicable and, therefore, have been omitted.
(3) Exhibits. See exhibits listed under Part (b) below.
**(b)**Exhibits:
- Filed herewith
**Schedules and exhibits to this agreement have been omitted pursuant to Item 601(a)(5) of Regulation S-K. A copy of any omitted schedule and/or exhibit will be furnished as a supplement to the Securities and Exchange Commission upon request.
(c) Financial Statement Schedules. See Item 15(a)(2).
Item 16. FORM 10-K SUMMARY
None.
SIGNATURES
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on February 22, 2024.
| EQUIFAX INC. | |||||
| (Registrant) | |||||
| By: | /s/ Mark W. Begor | ||||
| Mark W. Begor | |||||
| Chief Executive Officer |
We, the undersigned directors and executive officers of Equifax Inc., hereby severally constitute and appoint John W. Gamble, Jr. and James M. Griggs, and each of them singly, our true and lawful attorneys with full power to them and each of them to sign for us, and in our names in the capacities indicated below, any and all amendments to this Annual Report on Form 10-K filed with the SEC, hereby ratifying and confirming our signatures as they may be signed by our said attorneys to any and all amendments to said Annual Report on Form 10-K.
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the registrant and in the capacities indicated on February 22, 2024.
| /s/ Mark W. Begor | |||||
| Mark W. Begor | |||||
| Chief Executive Officer | |||||
| (Principal Executive Officer) | |||||
| /s/ John W. Gamble, Jr. | |||||
| John W. Gamble, Jr. | |||||
| Executive Vice President, Chief Financial Officer and Chief Operations Officer | |||||
| (Principal Financial Officer) | |||||
| /s/ James M. Griggs | |||||
| James M. Griggs | |||||
| Chief Accounting Officer and Corporate Controller | |||||
| (Principal Accounting Officer) | |||||
| /s/ Mark L. Feidler | |||||
| Mark L. Feidler | |||||
| Director and Non-Executive Chairman | |||||
| /s/ Karen L. Fichuk | |||||
| Karen L. Fichuk | |||||
| Director | |||||
| /s/ G. Thomas Hough | |||||
| G. Thomas Hough | |||||
| Director | |||||
| /s/ Robert D. Marcus | |||||
| Robert D. Marcus | |||||
| Director | |||||
| /s/ Scott A. McGregor | |||||
| Scott A. McGregor | |||||
| Director | |||||
| /s/ John A. McKinley | |||||
| John A. McKinley | |||||
| Director | |||||
| /s/ Melissa D. Smith | |||||
| Melissa D. Smith | |||||
| Director | |||||
| /s/ Audrey Boone Tillman | |||||
| Audrey Boone Tillman | |||||
| Director | |||||
SCHEDULE II — VALUATION AND QUALIFYING ACCOUNTS
2023
| Column A | Column B | Column C | Column D | Column E | ||||||||||||||||||||||||||||
| Additions | ||||||||||||||||||||||||||||||||
| Description | Balance at Beginning of Period | Charged to Costs and Expenses | Charged to Other Accounts | Deductions | Balance at End of Period | |||||||||||||||||||||||||||
| (In millions) | ||||||||||||||||||||||||||||||||
| Reserves deducted in the balance sheet from the assets to which they apply: | ||||||||||||||||||||||||||||||||
| Trade accounts receivable | $ | 19.1 | $ | 11.4 | $ | — | $ | (13.8) | $ | 16.7 | ||||||||||||||||||||||
| Deferred income tax asset valuation allowance | 185.1 | (26.9) | 2.7 | 17.6 | 178.5 | |||||||||||||||||||||||||||
| $ | 204.2 | $ | (15.5) | $ | 2.7 | $ | 3.8 | $ | 195.2 |
2022
| Column A | Column B | Column C | Column D | Column E | ||||||||||||||||||||||||||||
| Additions | ||||||||||||||||||||||||||||||||
| Description | Balance at Beginning of Period | Charged to Costs and Expenses | Charged to Other Accounts | Deductions | Balance at End of Period | |||||||||||||||||||||||||||
| (In millions) | ||||||||||||||||||||||||||||||||
| Reserves deducted in the balance sheet from the assets to which they apply: | ||||||||||||||||||||||||||||||||
| Trade accounts receivable | $ | 13.9 | $ | 8.5 | $ | — | $ | (3.3) | $ | 19.1 | ||||||||||||||||||||||
| Deferred income tax asset valuation allowance | 192.0 | (15.4) | (9.7) | 18.2 | 185.1 | |||||||||||||||||||||||||||
| $ | 205.9 | $ | (6.9) | $ | (9.7) | $ | 14.9 | $ | 204.2 |
2021
| Column A | Column B | Column C | Column D | Column E | ||||||||||||||||||||||||||||
| Additions | ||||||||||||||||||||||||||||||||
| Description | Balance at Beginning of Period | Charged to Costs and Expenses | Charged to Other Accounts | Deductions | Balance at End of Period | |||||||||||||||||||||||||||
| (In millions) | ||||||||||||||||||||||||||||||||
| Reserves deducted in the balance sheet from the assets to which they apply: | ||||||||||||||||||||||||||||||||
| Trade accounts receivable | $ | 12.9 | $ | 0.3 | $ | — | $ | 0.7 | $ | 13.9 | ||||||||||||||||||||||
| Deferred income tax asset valuation allowance | 382.7 | (12.7) | (198.0) | 20.0 | 192.0 | |||||||||||||||||||||||||||
| $ | 395.6 | $ | (12.4) | $ | (198.0) | $ | 20.7 | $ | 205.9 |