Item 4. CONTROLS AND PROCEDURES
4K characters. Original on sec.gov · Markdown
Item 4. CONTROLS AND PROCEDURES
As of the end of the period covered by this report, an evaluation was carried out by the Company’s management, with the participation of our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) under the Securities Exchange Act of 1934). Based upon that evaluation, our Chief Executive Officer and Chief Financial Officer concluded that these disclosure controls and procedures were effective as of the end of the period covered by this report. In addition, no change in our internal control over financial reporting (as defined in Rule 13a-15(f) under the Securities Exchange Act of 1934) occurred during our most recent fiscal quarter that has materially affected, or is reasonably likely to materially affect, our internal control over financial reporting.
PART II. OTHER INFORMATION
ITEM 1. LEGAL PROCEEDINGS
CFPB Matters
In December 2021, we received a Civil Investigative Demand (a “CID”) from the Consumer Financial Protection Bureau (the “CFPB”) as part of its investigation into our consumer disputes process at our USIS business unit in order to determine whether we have followed Fair Credit Reporting Act (“FCRA”) requirements for the proper handling of consumer disputes. The CID requested the production of documents and answers to written questions. In January 2023, the CFPB informed us that its enforcement division would be investigating our previously-disclosed coding issue identified within a legacy server environment in the U.S. that impacted how some credit scores were calculated during a three-week period in 2022. In January 2025, we entered into a consent order with the CFPB to settle the investigation into our consumer disputes process at our USIS business unit and the investigation into our previously-disclosed coding issue. The consent order resolved these investigations and required the payment of a civil money penalty of $15 million. As part of the settlement, the Company agreed to modify certain business practices.
In July 2023, we received a CID from the CFPB as part of its investigation into data accuracy and dispute handling at our Workforce Solutions business unit in order to determine whether we have followed the FCRA's requirements. We received a second CID from the CFPB in March 2024 and a third CID in August 2024 as part of the same investigation. The CIDs request the production of documents and answers to written questions. We are cooperating with the CFPB in its investigation and providing responses and information on an ongoing basis. At this time, we are unable to predict the outcome of this CFPB investigation, including whether the investigation will result in any actions or proceedings against us.
Other
Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest many of these matters. Given the number of these matters, some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.
For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in this Form 10-Q.
Previous: Item 3. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK · Next: Item 1A. RISK FACTORS