Item 9A. CONTROLS AND PROCEDURES

7K characters. Original on sec.gov · Markdown

Item 9A. CONTROLS AND PROCEDURES

Evaluation of Disclosure Controls and Procedures

Under the supervision and with the participation of our Chief Executive Officer and Chief Financial Officer, we evaluated the effectiveness of the design and operation of our disclosure controls and procedures (as defined in the Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”)) as of December 31, 2025.

Based upon this evaluation, and as a result of actions taken to remediate the previously reported material weaknesses, the Chief Executive Officer and Chief Financial Officer have concluded that our disclosure controls and procedures were effective as of December 31, 2025.

Accordingly, management believes that the consolidated financial statements included in this Annual Report on Form 10-K fairly present, in all material respects, our financial position, results of operations, and cash flows as of and for the periods presented, in accordance with U.S. GAAP.

Management Report on Internal Control Over Financial Reporting

Management is responsible for establishing and maintaining adequate internal control over financial reporting as required by the Sarbanes-Oxley Act of 2002 and as defined in Exchange Act Rules 13a-15(f) and 15d-15(f). Our system of internal control over financial reporting is designed to provide reasonable assurance to our management and Board of Directors regarding the reliability of our financial reporting and the preparation of financial statements for external purposes in accordance with U.S. GAAP. Internal control over financial reporting includes those policies and procedures that (i) pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets; (ii) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with U.S. GAAP, and that receipts and expenditures are being made only in accordance with authorizations of management and our Board of Directors; and (iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the Company’s assets that could have a material effect on the financial statements.

Management, including the Chief Executive Officer and Chief Financial Officer, under the oversight of our Board of Directors, assessed the effectiveness of the Company's internal control over financial reporting, as of December 31, 2025. In making this assessment, management used the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) in Internal Control — Integrated Framework (2013). Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions or that the degree of compliance with the policies or procedures may deteriorate. Based on this assessment, management has concluded that, as of December 31, 2025, our internal control over financial reporting was effective.

Remediation of Previously Reported Material Weaknesses

A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis. As previously disclosed in our Annual Report on Form 10-K for the year ended December 31, 2024, we identified material weaknesses in our internal controls over financial reporting in the areas of logical access and change management to certain IT systems.

These control deficiencies related to personnel without specific training and experience to fulfill internal control responsibilities related to information technology general controls over systems and processes resulting in an ineffective design of controls necessary to ensure the reliability of information used in financial reporting.

In light of the previously reported material weaknesses, management performed additional analysis and other procedures to ensure that our consolidated financial statements were prepared in accordance with U.S. GAAP. The control deficiencies did not result in any identified misstatements to the consolidated financial statements, and there were no changes to previously released financial results.

With respect to the previously reported material weaknesses, management with the oversight of the Audit Committee of the Board of Directors, completed the remediation plan described in our prior filings. Key actions include:

Engaged PwC US Consulting, LLP to assist management with our entity-wide risk assessment, assessment of control design, and remediation process;

Maintained a continuous process of ongoing entity wide risk assessments to identify relevant process risk points, IT systems and the information used in the operation of controls;

Hired additional qualified personnel to support the remediation process and the design and implementation of IT controls;

Implemented additional third-party industry-standard software solutions that aid in tracking changes to databases and related applications and improve controls over system access and monitoring;

Implemented systems, procedures, and controls designed to strengthen IT change management and logical access processes; and

Conducted ongoing training of personnel to fulfill internal control responsibilities relative to information technology.

Changes in Internal Controls

Except for remediation of the material weaknesses noted above, there were no changes in our internal control over financial reporting that occurred during the most recent fiscal quarter that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

An internal control system, no matter how well-conceived and operated, can provide only reasonable, not absolute, assurance that the objectives of such internal controls are met. Further, the design of an internal control system must reflect the fact that there are resource constraints, and the benefits of controls must be considered relative to their costs. Because of the inherent limitations in all internal control systems, no evaluation of controls can provide absolute assurance that all of our control issues and instances of fraud, if any, have been detected.

Previous: Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE · Next: Item 9B. OTHER INFORMATION