A Dark Vector Cognition product

Item 9A. CONTROLS AND PROCEDURES

9K characters. Original on sec.gov · Markdown

Item 9A. CONTROLS AND PROCEDURES

Evaluation of Disclosure Controls and Procedures

We carried out an evaluation, under the supervision and with the participation of our management, including the Chief Executive Officer and Chief Financial Officer, of the effectiveness of the design and operation of our disclosure controls and procedures (as defined in the Exchange Act Rule 13a-15(e)) as of the end of the period covered by this report. Based upon that evaluation, the Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures were not effective as of December 31, 2022, due to a material weakness in internal control over financial reporting described below.

Management Report on Internal Control Over Financial Reporting

Management is responsible for establishing and maintaining adequate internal control over financial reporting as required by the Sarbanes-Oxley Act of 2002 and as defined in Exchange Act Rule 13a-15(f). Our system of internal control over financial reporting is designed to provide reasonable assurance to our management and Board of Directors regarding the reliability of our financial reporting and the preparation of financial statements for external purposes in accordance with U.S. generally accepted accounting principles. Internal control over financial reporting includes those policies and procedures that (i) pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets; (ii) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with U.S. generally accepted accounting principles, and that receipts and expenditures are being made only in accordance with authorizations of management and our Board of Directors; and (iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the Company’s assets that could have a material effect on the financial statements.

A system of internal control can provide only reasonable, not absolute, assurance that the objectives of the control system are met. Management, including the Chief Executive Officer and Chief Financial Officer, under the oversight of our Board of Directors, evaluated the effectiveness of the Company's internal control over financial reporting, as of December 31, 2022, based on the framework in Internal Control — Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis.

In the fourth quarter of 2022, management identified a material weakness in internal control related to certain database changes made to an information technology (IT) system that supports the Company’s financial reporting processes. A control to review and authorize direct changes to databases that support several key operational and accounting systems did not capture the complete population of database changes and, as such did not operate effectively as designed. Management concluded that unauthorized database changes could have gone undetected, could have resulted in errors in the financial statements for the year ended 2022 and could have had a direct or indirect impact on financial reporting controls, as there were no alternate information technology general control (ITGC) or processes operating at a sufficient level of precision that would have timely detected improper -- database changes. Management believes that this control deficiency was a result of IT control processes lacking sufficient precision to support the successful operation of this ITGC and was overly dependent upon interpretation, knowledge and actions of certain individuals with IT expertise performing the control. The material weakness did not result in any identified misstatements to the financial statements, and there were no changes to previously released financial results. Based on this material weakness, the Company’s management concluded that at December 31, 2022, the Company’s internal control over financial reporting was not effective.

KPMG LLP, an independent registered public accounting firm, has issued an attestation report on our internal control over financial reporting as of December 31, 2022, which is included on page F-3.

Remediation

Subsequent to the identification of the material weakness and prior to the issuance of these financial statements on Form 10-K, the Company (i) performed a lookback review of all direct changes made to the database subject to the control operating ineffectiveness for the full year 2022 and (ii) conducted supplemental procedures and found no evidence of improper changes or changes with direct or consequential impact on internal controls over financial reporting. As a result of identifying this issue management will be implementing certain enhancements designed to strengthen IT program change management processes and will continue to conduct monthly supplemental lookback review procedures of direct database changes until improvements are fully in place. We expect that such enhancements will be completed prior to the end of 2023.

Changes in Internal Controls

Except for the material weakness identified during the quarter, as of December 31, 2022, there were no changes in our internal control over financial reporting that occurred during the most recent fiscal quarter that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting other than related to the cyber-attack as discussed below.

With respect to the cyber-attack that is discussed in Note 11 to the consolidated financial statements in this report, starting on February 20, 2022, we shut down most of our operating systems globally, including our accounting information systems, to manage the safety of our entire global systems environment. We engaged third-party cybersecurity experts to investigate and assist in the remediation. Our Board of Directors was regularly apprised of, and directors with experience in cybersecurity participated in, the critical investigation and remediation activities. Subsequently, we restored and strengthened the security of our systems and networks and enhanced the continuous monitoring of the entire information security environment. Additionally, we have continued to implement various improvements to our network and processes to mitigate the risk of recurrence and severity of such incidents in the future.

During the disruption caused by the cyber-attack, we deployed interim procedures and controls to maintain our systems of internal control over financial reporting. As a result of this cyber-attack and based on information known at this date, management determined that our disclosure controls and procedures were effective and the cyber-attack did not materially affect, nor was it reasonably likely to affect the effectiveness of the Company’s internal control over financial reporting.

We are developing a new accounting system, which is being implemented on a worldwide basis over the next several years. This system is expected to improve the efficiency of certain financial and transactional processes and reporting. This transition affects the processes that constitute our internal control over financial reporting and requires testing for operating effectiveness.

Our management has confidence in our internal controls and procedures. Nevertheless, our management, including Expeditors’ Chief Executive Officer and Chief Financial Officer, does not expect that our disclosure controls and procedures or our internal controls will prevent all errors or intentional fraud. An internal control system, no matter how well-conceived and operated, can provide only reasonable, not absolute, assurance that the objectives of such internal controls are met. Further, the design of an internal control system must reflect the fact that there are resource constraints, and the benefits of controls must be considered relative to their costs. Because of the inherent limitations in all internal control systems, no evaluation of controls can provide absolute assurance that all of our control issues and instances of fraud, if any, have been detected.

Previous: Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE · Next: Item 9B. OTHER INFORMATION