Item 1. Business
57K characters. Original on sec.gov · Markdown
Item 1. Business
Overview
FIS is a leading provider of technology solutions for merchants, banks, and capital markets firms globally. Our employees are dedicated to advancing the way the world pays, banks and invests by applying our scale, deep expertise and data-driven insights. We help our clients use technology in innovative ways to solve business-critical challenges and deliver superior experiences for their customers. Headquartered in Jacksonville, Florida, FIS is a Fortune 500® company and is a member of Standard & Poor's 500® Index.
FIS is incorporated under the laws of the State of Georgia as Fidelity National Information Services, Inc. and our stock is traded under the trading symbol "FIS" on the New York Stock Exchange.
We have grown organically as well as through acquisitions, which have contributed critical solutions and services that complement or enhance our existing offerings, diversifying our revenue by client, geography and service offering, and opening new and profitable adjacent markets that align with our core solution strengths. FIS evaluates possible acquisitions that might contribute to our growth or performance on an ongoing basis. We also develop new solutions that enhance our client offerings. Following our acquisition of Worldpay, Inc. ("Worldpay"), on July 31, 2019, FIS is now a global leader in financial technology solutions and services for merchants, banks and capital markets. See Note 3 to the consolidated financial statements for additional discussion of the Worldpay acquisition.
FIS reports its financial performance based on the following segments: Merchant Solutions ("Merchant"), Banking Solutions ("Banking"), Capital Market Solutions ("Capital Markets") and Corporate and Other. See "Segment Information" below for additional discussion of our solutions and customers. See also Notes 2, 4 and 22 to the consolidated financial statements for additional information about our revenue.
Competitive Strengths
We believe our competitive strengths include the following:
-
Brand. FIS has built a global highly-respected brand known for innovation and thought leadership in the financial services and merchant sectors.
-
Extensive Domain Expertise and Extended Portfolio Breadth. FIS' significant expertise in the markets and domains we serve has enabled us to bring to market a broad range of innovative software applications and service offerings. This broad portfolio of solutions includes a wide range of flexible service arrangements, from managed processing arrangements, either at the client site or hosted at an FIS location, including data centers or our private cloud, to traditional license and maintenance approaches. This broad solution set allows us to bundle tailored or integrated services to compete effectively.
-
Excellent and Long-term Relationships with Clients. A significant percentage of FIS' business with our clients relates to applications and services provided under multi-year, recurring contracts. The nature of these relationships allows us to develop close partnerships with these clients, resulting in high client retention rates. As the breadth of FIS' service offerings has expanded, we have found that our deep and broad access within our clients' organizations presents greater opportunities for cross-selling and up-selling solutions to our clients.
*•*Modern and Cloud-based Technologies. FIS leverages the modern architectures of our software applications and our ability to integrate many of our services with the services of others to provide customized solutions that respond to individualized client needs. We have made significant investment in modernizing our platforms and solutions and in moving our server compute into our private cloud located in our strategic data centers, supplemented by public clouds in certain regions, to increase speed of delivery to clients and increase solution availability to industry-best levels.
*•*Global Distribution and Scale. We are a global leader in many of the markets we serve, supported by a large, knowledgeable talent pool of employees around the world. Our worldwide presence and global scale enable us to
leverage our array of solution offerings, client relationships, and modern infrastructure to drive revenue growth and operating efficiency.
Strategy
Our mission is to deliver superior solutions and services to our clients and to expand our client base to generate sustained revenue and earnings growth for our shareholders. Our strategy to achieve this goal is built on the following pillars:
-
Build, Buy, or Partner to Add Solutions to Win New Clients and Cross-sell to Existing Clients. We continue to invest in organic growth through internal software development as well as through acquisitions and equity investments that complement and extend our existing solutions and capabilities, providing us with additional solutions to cross sell existing clients and capture the interest of new clients. We also partner from time to time with other entities to provide comprehensive offerings to our clients and prospects. By investing in solution innovation, we continue to expand our value proposition to our clients and prospects.
-
Support Our Clients Through Innovation. Changing market dynamics, particularly in the areas of digital delivery, information security, and regulation, are transforming the way our clients operate, which is driving incremental demand for our integrated solutions and services built around our intellectual property. As clients and prospects evaluate technology, business process changes and vendor risks, our depth of services capabilities enable us to become involved earlier in their planning and design process and assist them as they manage through these changes.
-
Drive Efficiency and Scalability. We strive to improve the efficiency of our operations through investments in new technologies, processes and infrastructure modernization. We also leverage a one-to-many operating model for the majority of our solutions, which drives high incremental margins on revenue growth, while also providing cost-effective solutions for our clients.
-
Expand Client Relationships. Through our global sales force and strategic commercial partnerships, we drive growth through client additions and through the expansion of existing client relationships in support of our clients' growth ambitions. Our clients across our strategic global markets reach across the size spectrum from large enterprises and financial institutions, including global or multi-national clients, to small businesses and community or regional financial institutions.
-
Allocate Our Capital and Resources Strategically. As we make decisions with respect to building, buying or partnering to drive innovation in support of our clients, we prioritize the allocation of capital and other resources to the opportunities providing the highest client benefit and growth potential. We also continually review our portfolio of assets and businesses to assess their fit with our strategy and will from time to time decide to wind down or divest businesses or assets to redeploy capital to our areas of strategic focus. We believe that keeping our team and our capital strategically focused benefits our existing clients and our ability to win new clients.
Segment Information
As a result of the Company's acquisition of Worldpay, the Company reorganized its reportable segments in the quarter ended September 30, 2019, into Merchant, Banking, Capital Markets, and Corporate and Other. Reportable segments are organized based on solution offerings and target markets. The Company regularly assesses its portfolio of assets and reclassified certain non-strategic businesses from Merchant, Banking, and Capital Markets into Corporate and Other during the year ended December 31, 2020, and recast all prior-period segment information presented. These operations represented approximately 3% of 2020 revenue.
Our consolidated results generally do not reflect pronounced seasonality. However, revenues for each segment may reflect stronger or weaker quarters given the nature of our solutions offered. The Merchant business, in particular, is historically subject to seasonal fluctuations in revenue as a result of consumer spending patterns, with Merchant revenue being strongest in the fourth quarter and weakest in the first quarter. The novel coronavirus ("COVID-19") pandemic adversely impacted revenue particularly in Merchant from mid-March through the end of 2020 and has had some impact on seasonality seen in past years.
For information about current trends in market demand, see "Item 7. Management's Discussion and Analysis of Financial Condition and Results of Operations - Business Trends and Conditions*.*"
Revenue by Segment
The table below summarizes our revenue by reporting segment (in millions):
| 2020 | 2019 | 2018 | |||||||||||||||
| Merchant Solutions | $ | 3,767 | $ | 1,942 | $ | 208 | |||||||||||
| Banking Solutions | 5,944 | 5,592 | 5,416 | ||||||||||||||
| Capital Market Solutions | 2,440 | 2,318 | 2,258 | ||||||||||||||
| Corporate and Other | 401 | 481 | 541 | ||||||||||||||
| Total Consolidated Revenue | $ | 12,552 | $ | 10,333 | $ | 8,423 |
Merchant Solutions ("Merchant")
The Merchant segment is focused on serving merchants of all sizes globally, enabling them to accept electronic payments, including card-based payments, contactless card and mobile wallet, originated at a physical point of sale, as well as card-not-present payments in eCommerce and mobile environments. Merchant services include all aspects of payment processing, including authorization and settlement, customer service, chargeback and retrieval processing, electronic payment transaction reporting and network fee and interchange management. Merchant also includes value-added services, such as security and fraud prevention solutions, advanced data analytics and information management solutions, foreign currency management and numerous funding options. Merchant serves clients in over 140 countries. Our Merchant clients are highly-diversified, including global enterprises, national retailers, and small- to medium-sized businesses. The Merchant segment utilizes broad and varied distribution channels, including direct sales forces and multiple referral partner relationships that provide us with a growing and diverse client base.
Our solutions in this segment include the following:
- Merchant Acquiring. Our merchant acquiring solutions primarily provide point-of-sale payment processing for merchants of all sizes with a focus on large multi-national enterprises. Our solutions provide payment acceptance from various payment types, including but not limited to debit, credit, EMV (Europay, MasterCard and Visa), contactless and loyalty point redemption.
*•*Integrated Payments. Our integrated payment solutions primarily leverage an independent software vendor ("ISV") partnership model where FIS provides the merchant acquiring capabilities for the ISV partner across several industry verticals and sub-verticals. These solutions also include merchant acquiring for payment facilitators ("PayFacs"), which consolidates multiple sub-merchant accounts under a master merchant identification number ("MID") account.
*•*Global eCommerce. Our global eCommerce solutions provide card-not-present merchant acquiring capabilities to merchants looking to sell their goods and services digitally. Our platforms enable both domestic and international capabilities and can provide a customizable and scalable solution to our merchants with best-in-class authorization rates.
Banking Solutions ("Banking")
The Banking segment is focused on serving all sizes of financial institutions with core processing software, transaction processing software and complementary applications and services, many of which interact directly with the core processing applications. We sell these solutions and services on either a bundled or stand-alone basis. Clients in this segment include global financial institutions, U.S. regional and community banks, credit unions and commercial lenders, as well as government institutions and other commercial organizations. Banking serves clients in more than 100 countries. We provide our clients integrated solutions characterized by multi-year processing contracts that generate highly recurring revenue. The predictable nature of cash flows generated from the Banking segment provides opportunities for further investments in innovation, integration, information and security, and compliance in a cost-effective manner. The results in this segment included the Reliance Trust Company of Delaware business through its divestiture on December 31, 2018 and the Company's Brazilian Venture business through its divestiture as part of the joint venture unwinding transaction on December 31, 2018 (see Note 19 to the consolidated financial statements).
Our solutions in this segment include the following:
-
Core Processing and Ancillary Applications. Our core processing software applications are designed to run banking processes for our financial institution clients, including deposit and lending systems, customer management, and other central management systems, serving as the system that clients use to maintain the primary records of their customer accounts. Our diverse selection of market-focused core systems enables FIS to compete effectively in a wide range of markets. We continue to invest in our core modernization efforts to further differentiate our offerings for the long term. We also offer a number of services that are ancillary to the primary applications listed above, including branch automation, back-office support systems and compliance support.
-
Digital, including Internet, Mobile and eBanking. Our comprehensive suite of retail delivery applications enables financial institutions to integrate and streamline customer-facing operations and back-office processes, thereby improving customer interaction across all channels (e.g., branch offices, internet, ATM, mobile, and call centers). FIS' focus on consumer access has driven significant market innovation in this area, with multi-channel and multi-host solutions and a strategy that provides tight integration of services and a seamless customer experience. We have been providing our large regional banking customers in the U.S. with Digital One, an integrated digital banking platform, and are now adding functionality and offering Digital One to our community bank clients. Digital One is integrated into several of the core banking platforms offered by FIS and is also offered to customers of non-FIS core banking systems.
-
Fraud, Risk Management and Compliance. Our decision solutions offer a spectrum of options that cover the account lifecycle from helping to identify qualified account applicants to managing existing customer accounts and fraud. Our applications include know-your-customer, new account decisioning and opening, account and transaction management, fraud management and collections. Our risk management services use our proprietary risk management models and data sources to assist in detecting fraud and assessing the risk of opening a new account. Our systems use a combination of advanced authentication procedures, predictive analytics, artificial intelligence modeling and proprietary and shared databases to assess and detect fraud risk for deposit transactions for financial institutions.
-
Electronic Funds Transfer and Network. Our electronic funds transfer and debit card processing businesses offer settlement and card management solutions for financial institution card issuers. We provide traditional ATM-based debit network access through NYCE, other branded networks, and emerging real-time payment alternatives. Our networks connect millions of cards and point-of-sale locations nationwide, providing consumers with secure, real-time access to their money. Also through our networks, clients such as financial institutions, retailers and independent ATM operators can capitalize on the efficiency, consumer convenience and security of electronic real-time payments, real-time account-to-account transfers, and strategic alliances such as surcharge-free ATM network arrangements.
-
Card and Retail Payment. Our card and retail payment technology and services allow clients to issue VISA®, MasterCard® or other payment network branded credit and debit cards or other electronic payment cards for use by both consumer and business accounts. Card transactions continue to increase as a percentage of total point-of-sale payments, which fuels continuing demand for card-related services. We offer EMV integrated circuit cards, often referred to as smart cards or chip cards, as well as a variety of stored-value card types and loyalty/reward programs, including our Premium Payback service that allows our financial institution customers to use loyalty points at a variety of merchant point-of-sale systems. Our integrated services range from card production and activation to processing to an extensive range of fraud management services and value-added loyalty programs designed to increase card usage and fee-based revenue for financial institutions and merchants. The majority of our programs are full service, including most of the operations and support necessary for an issuer to operate a credit card program. We do not make credit decisions for our card issuing clients. We are also a leading provider of prepaid card services, which include digital cards, gift cards and reloadable cards, with end-to-end solutions for development, processing and administration of stored-value programs, including government benefit programs. Our closed-loop gift card solutions and loyalty programs provide merchants compelling solutions to drive consumer loyalty.
-
Wealth and Retirement. We provide wealth and retirement solutions that help banks, trust companies, brokerage firms, insurance firms, retirement plan professionals, benefit administrators and independent advisors acquire, service and grow their client relationships. We provide solutions for client acquisition, transaction management, trust accounting and recordkeeping that can be deployed stand-alone or as part of an integrated wealth or retirement platform, or on an outsourced basis.
*•*Item Processing and Output Services. Our item processing services furnish financial institutions with the technology needed to capture data from checks, transaction tickets and other items; image and sort items; process exceptions through keying; and perform balancing, archiving and the production of statements. Our item processing services are performed at one of our multiple item processing centers located throughout the U.S. or on-site at client locations. Our extensive solutions include distributed (i.e., non-centralized) data capture, mobile deposit capture, check and remittance processing, fraud detection, and document and report management. Clients encompass banks and corporations of all sizes, from de novo banks to the largest financial institutions and corporations. We offer a number of output services that are ancillary to the primary solutions we provide, including print and mail capabilities, document composition software and solutions, and card personalization fulfillment services. Our print and mail services offer complete computer output solutions for the creation, management and delivery of print and fulfillment needs. We provide our card personalization fulfillment services for branded credit cards and branded and non-branded debit and prepaid cards.
Capital Market Solutions ("Capital Markets")
The Capital Markets segment is focused on serving global financial services clients with a broad array of buy- and sell-side solutions. Clients in this segment operate in more than 100 countries and include asset managers, buy- and sell-side securities brokerage and trading firms, insurers, private equity firms, and other commercial organizations. Our buy- and sell-side solutions include a variety of mission-critical applications for recordkeeping, data and analytics, trading, financing and risk management. Capital Markets clients purchase our solutions and services in various ways including licensing and managing technology "in-house," using consulting and third-party service providers, as well as procuring fully outsourced end-to-end solutions. Our long-established relationships with many of these financial and commercial institutions generate significant recurring revenue. We have made, and continue to make, investments in modern platforms; advanced technologies, such as cloud delivery, open APIs, machine learning and artificial intelligence; and regulatory technology to support our Capital Markets clients.
Our solutions in this segment include the following:
-
Securities Processing and Finance. Our offerings help financial institutions to increase the efficiency, transparency and control of their back-office trading operations, post-trade processing and settlement including derivative solutions, risk management, securities lending, syndicated lending, tax processing, and regulatory compliance. The breadth of our offerings also facilitates advanced business intelligence and market data distribution based on our extensive market data access.
-
Global Trading. Our trading solutions provide trade execution, data and network solutions to financial institutions, corporations and municipalities in North America, Europe and other global markets across a variety of asset classes. Our trade execution and network solutions help both buy- and sell-side firms improve execution quality, decrease overall execution costs and address today's trade connectivity challenges.
-
Asset Management and Insurance. We offer solutions that help institutional investors, insurance companies, hedge funds, private equity firms, fund administrators and securities transfer agents improve both investment decision-making and operational efficiency, while managing risk and increasing transparency. Our asset management solutions support every stage of the investment process, from research and portfolio management, to valuation, risk management, compliance, investment accounting, transfer agency and client reporting. Our insurance solutions help support front-office and back-office functions including actuarial risk calculations, policy administration and financial and investment accounting and reporting for a variety of insurance lines, including life and health, annuities and pensions, property and casualty, and reinsurance.
-
Corporate Liquidity. Our corporate liquidity solutions help chief financial officers and treasurers manage working capital by reducing risk and improving communication and response time between a company's buyers, suppliers, banks and other stakeholders. Our end-to-end collaborative financial management framework helps bring together receivables, treasury and payments for a single view of cash and risk, which helps our clients optimize business processes for enhanced liquidity management.
Corporate and Other
The Corporate and Other segment consists of corporate overhead expense, certain leveraged functions and miscellaneous expenses that are not included in the operating segments, as well as certain non-strategic businesses that we plan to wind down or sell. The overhead and leveraged costs relate to corporate marketing, corporate finance and accounting, human resources,
legal, and amortization of acquisition-related intangibles and other costs, such as acquisition and integration expenses, that are not considered when management evaluates revenue-generating segment performance.
Sales and Marketing
We have experienced sales personnel with expertise in particular solutions and markets as well as across our various client segments—Merchant, Banking and Capital Markets. We believe that focusing our expertise on clients in specific markets (e.g., global financial institutions, North American financial institutions, North American merchants, etc.) and tailoring integrated solution sets of particular value to participants in those markets enables us to leverage opportunities to cross-sell and up-sell. We target the majority of our potential clients via direct and/or indirect field sales, as well as inbound and outbound lead generation, telesales and virtual sales efforts.
Our global marketing team develops and leads the execution of the Merchant, Banking and Capital Markets strategic marketing plans in support of the segments' reputation and relationship building goals in addition to their revenue and profitability goals. Key components of our strategic plans include brand management and digital enablement; market and competitive research; capturing client preferences; thought leadership; integrated go-to-market programs; internal communications and readiness; journalist, social media and industry analyst relations; client events; trade shows; high-touch client programs; demand generation campaigns; account- and deal-based marketing programs; collateral development and management across digital and online channels; and the commercialization of new products to market.
Patents, Copyrights, Trademarks and Other Intellectual Property
In general, we own the intellectual property and proprietary rights that are necessary for the conduct of our business and important to our future success, including trademarks, trade names, trade secrets, copyrights and patents. We license certain items from third parties under arms-length agreements for varying terms, including some "open source" licenses. Although we acquired the trademarks and trade names used by SunGard as part of our 2015 acquisition of SunGard and its subsidiaries, we note that following the split-off of the Availability Services ("AS") business by SunGard in 2014, AS has the right to use the Sungard Availability Services name, which does not include the right to use the SunGard name or its derivatives.
We rely on a combination of contractual restrictions, internal security practices, patents, trade secrets, copyrights and applicable law to establish and protect our software, technology and expertise worldwide. We rely on trademark law to protect our rights in our brands. We intend to continue taking appropriate measures to protect our intellectual property rights, including by legal action when necessary and appropriate.
Competition
The markets for our solutions and services are intensely competitive. Depending on the business line, in our Merchant, Banking and Capital Markets segments, our primary competitors include internal technology or software development departments within financial institutions or other large companies, merchant acquirers, global eCommerce providers, global and regional companies providing payment services, third-party payment processors, securities exchanges, asset managers, card associations, clearing networks or associations, trust companies, independent computer services firms, companies that develop and deploy software applications, companies owned by global banks selling new competitive solutions, companies that provide customized development, implementation and support services, emerging technology innovators, and business process outsourcing companies. Many of these companies compete with us across multiple solutions, markets and geographies. Some of these competitors possess greater financial, sales and marketing resources than we do. Competitive factors impacting the success of our services across our segments include the quality of the technology-based application or service, application features and functions, ease of delivery and integration, the ability to maintain, enhance and support the applications or services, price and overall relationship management. We believe we compete favorably in each of these categories. In addition, we believe our domain expertise, combined with our ability to offer multiple applications, services and integrated solutions to individual clients, enhances our competitiveness against companies with more limited offerings. Our ability to innovate and scale digital payments and services during the COVID-19 pandemic has been a competitive advantage as well.
Research and Development
Our research and development activities primarily relate to the modernization of our proprietary core systems and the design and development of next generation digital solutions, processing systems, software applications and risk management platforms. We expect to continue our practice of investing an appropriate level of resources to maintain, enhance and extend the functionality of our proprietary systems and software applications, to develop new and innovative software applications and
systems to address emerging technology trends in response to the needs of our clients and to enhance the capabilities of our outsourcing infrastructure. In addition, we intend to offer services compatible with new and emerging delivery channels.
As part of our research and development process, we evaluate current and emerging technology for compatibility with our existing and future software platforms. To this end, we engage with various hardware and software vendors in the evaluation of various infrastructure components. Where appropriate, we use third-party technology components in the development of our software applications and service offerings. In the case of nearly all of our third-party software, enterprise license agreements exist for the third-party component and either alternative suppliers exist or transfer rights exist to ensure the continuity of supply. As a result, we are not materially dependent upon any third-party technology components. Third-party software may be used for highly specialized business functions, which we may not be able to develop internally within time and budget constraints. Additionally, third-party software may be used for commodity-type functions within a technology platform environment. We work with our clients to determine the appropriate timing and approach to introducing technology or infrastructure changes to our applications and services. During the years ended December 31, 2020, 2019 and 2018, we incurred research and development costs that were non-capitalizable of approximately 3% to 4% of revenue.
Government Regulation
Our services are subject to a broad range of complex federal, state, and international regulations and requirements, as well as requirements under the rules of self-regulatory organizations including, without limitation, federal truth-in-lending and truth-in-savings rules, state money transmission laws, state cybersecurity protection laws, data protection and privacy laws, usury laws, laws governing state trust charters, the Equal Credit Opportunity Act, the Electronic Funds Transfer Act, the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, the Bank Service Company Act, the Bank Secrecy Act, the USA Patriot Act, the Internal Revenue Code, the Employee Retirement Income Security Act, the Health Insurance Portability and Accountability Act, the Community Reinvestment Act and the Dodd-Frank Wall Street Reform and Consumer Protection Act (the "Dodd-Frank Act"), the Securities Exchange Act of 1934, the Investment Advisors Act of 1940 (the "1940 Act"), anti-corruption laws including the U.S. Foreign Corrupt Practices Act and U.K. Bribery Act, the rules and regulations of the Financial Industry Regulatory Authority ("FINRA"), the Securities and Exchange Commission ("SEC"), the Federal Financial Institutions Examination Council ("FFIEC"), the Consumer Financial Protection Bureau ("CFPB"), the Financial Conduct Authority in the U.K. ("FCA") and the Payment Systems Regulator in the U.K. ("PSR"), De Nederlandsche Bank ("DNB") in the Netherlands, the Ministry of Economy, Trade and Industry in Japan ("METI") and state financial services regulators (including enforcement of state cybersecurity laws). The compliance of our services and applications with these and other applicable laws and regulations depends on a variety of factors, including the manner in which our clients use them. In some cases, we are directly subject to regulatory oversight and examination. In other cases, our clients are contractually responsible for determining what is required of them under applicable laws and regulations and utilize our solutions and services to achieve compliance with those laws and regulations. In either case, the failure of our services to comply with applicable laws and regulations may result in suspension or revocation of the permission-based regulatory licenses, restrictions on our ability to provide those services, the imposition of civil fines and/or criminal penalties, and/or reputational damage. Further, regulatory authorities have the power to, among other things, enjoin "unsafe or unsound" practices, require affirmative actions to correct any violation or practice, issue administrative orders that can be judicially enforced and direct the sale of subsidiaries or other assets. We may be adversely affected by increased regulatory scrutiny or related negative publicity.
The principal areas of regulation impacting our business are the following:
- Oversight by Banking Regulators. As a provider of electronic data processing and back-office services to financial institutions, FIS is subject to regulatory oversight and examination by the FFIEC, including the Federal Deposit Insurance Corporation ("FDIC"), the Office of the Comptroller of the Currency ("OCC"), the Board of Governors of the Federal Reserve System ("FRB"), the National Credit Union Administration ("NCUA") and the CFPB as part of the Multi-Regional Data Processing Servicer ("MDPS") program. The MDPS program includes technology suppliers that provide mission critical applications for a large number of financial institutions that are regulated by multiple regulatory agencies. Periodic information technology examination assessments are performed using FFIEC Interagency guidelines to identify potential risks that could adversely affect serviced financial institutions, determine compliance with applicable laws and regulations that affect the services provided to financial institutions and ensure the services we provide to financial institutions do not create systemic risk to the banking system or impact the safe and sound operation of the financial institutions we process. In addition, independent auditors annually review several of our operations to provide reports on internal controls for our clients. We are also subject to review and examination by state and international regulatory authorities under state and foreign laws and rules that regulate many of the same activities that are described above, including electronic data processing, payments and back-office services for financial institutions and the use of consumer information.
Our U.S.-based wealth and retirement business holds a charter in the state of Georgia which makes us subject to the regulatory compliance requirements of the Georgia Department of Banking and Finance. As a result, we are also authorized to provide trust services in various additional states subject to additional applicable state regulations.
- Oversight by Securities Regulators. Our subsidiary that conducts our broker-dealer business in the U.S. is registered as a broker-dealer with the SEC, is a member of FINRA, and is registered as a broker-dealer in numerous states. Our broker-dealer is subject to regulation and oversight by the SEC. In addition, FINRA, a self-regulatory organization that is subject to oversight by the SEC, adopts and enforces rules governing the conduct, and examines the activities, of its member firms, including our broker-dealer. State securities regulators, the Municipal Securities Rulemaking Board, and various exchanges, including the New York Stock Exchange, also have regulatory or oversight authority over our broker-dealer. Broker-dealers are subject to regulations that cover all aspects of the securities business, including sales methods, trade practices among broker-dealers, public and private securities offerings, use and safekeeping of customers’ funds and securities, capital structure, record keeping, the financing of customers’ purchases and the conduct and qualifications of directors, officers and employees. In particular, as a registered broker-dealer and member of a self-regulatory organization, we are subject to the SEC’s uniform net capital rule, Rule 15c3-1. Rule 15c3-1 specifies the minimum level of net capital a broker-dealer must maintain and also requires that a significant part of a broker-dealer’s assets be kept in relatively liquid form. The SEC and various self-regulatory organizations impose rules that require notification when net capital falls below certain predefined criteria, limit the ratio of subordinated debt to equity in the regulatory capital composition of a broker-dealer and constrain the ability of a broker-dealer to expand its business under certain circumstances. Additionally, the SEC’s uniform net capital rule imposes certain requirements that may have the effect of prohibiting a broker-dealer from distributing or withdrawing capital and requiring prior notice to the SEC for certain withdrawals of capital.
Our subsidiaries also include an SEC-registered transfer agent. Our registered transfer agent is subject to the Securities Exchange Act of 1934 and the rules and regulations promulgated thereunder. These laws and regulations generally grant the SEC and other supervisory bodies broad administrative powers to address non-compliance with regulatory requirements. Sanctions that may be imposed for non-compliance with these requirements include the suspension of individual employees, limitations on engaging in certain activities for specified periods of time or for specified types of clients, the revocation of registrations, other censures and significant fines.
Subsidiaries engaged in activities outside the U.S. are regulated by various government agencies in the particular jurisdiction where they are chartered, incorporated and/or conduct their business activity. For example, pursuant to the U.K. Financial Services and Markets Act 2000 ("FSMA"), certain of our subsidiaries are subject to regulations promulgated and administered by the FCA. The FSMA and rules promulgated thereunder govern all aspects of the U.K. investment business, including sales, research and trading practices, provision of investment advice, use and safekeeping of client funds and securities, regulatory capital, recordkeeping, margin practices and procedures, approval standards for individuals, anti-money laundering, periodic reporting and settlement procedures.
-
Payment Services Oversight. Our payment services business is a technology service provider to U.S. financial institutions and is, therefore, subject to oversight and examination by the FFIEC. Our payment services businesses are also subject to regulation, supervision, and enforcement authority of numerous governmental and regulatory bodies in the jurisdictions in which they operate, which include the CFPB, the DNB in the Netherlands, the METI in Japan, and the FCA and the PSR in the U.K. These various regulatory regimes require compliance in respect of many aspects of our payment services business including without limitation corporate governance and oversight functions, capital requirements, liquidity, safeguarding, fee regulation adherence, technology and cyber resilience, anti-money laundering and sanctions. Because the PSR is an economic regulator in the U.K., it has the power to issue directions in relation to the functioning of the card acquiring market in the U.K. Further, the European Commission is conducting a review of the Regulation of the European Parliament and the Council on interchange fees for card-based payment transactions ("IFR") to examine the appropriateness of the levels of interchange fees, the level of entry of new players, new technology and the impact of innovative business models on the market. The European Union ("E.U.") has overall authority to enforce and establish new standards or guidance which may require banks and authorized payments providers in our Merchant business to modify current pricing and fee structures, and the E.U. could choose to exercise such authority prior to or after conclusion of such review.
-
Privacy and Data Protection. The Company is subject to an increasing number of privacy and data protection laws, regulations and directives globally (referred to collectively as "Privacy Laws"), many of which place restrictions on the
Company's ability to efficiently transfer, access and use personal data across its business. The legislative and regulatory landscape for privacy and data protection continues to evolve.
Our financial institution clients operating in the U.S. are required to comply with privacy regulations imposed under the Gramm-Leach-Bliley Act (referred to as "GLBA") and numerous similar state laws. GLBA and those state laws place restrictions on the use of non-public personal information. All financial institutions must disclose detailed privacy policies to their customers and offer them the opportunity to direct the financial institution not to share information with third parties. The regulations under GLBA, however, permit financial institutions to share information with non-affiliated parties who perform services for the financial institutions. As a provider of services to financial institutions, we are required to comply with the privacy laws and are bound by the same limitations on disclosure of the information received from our clients as apply to the financial institutions themselves. A determination that there have been violations of privacy laws could expose us to significant damage awards, fines and other penalties that could, individually or in the aggregate, materially harm our business and reputation.
In July 2016, the European Commission formally approved and adopted the EU-US Privacy Shield, providing a compliance framework for organizations to transfer personal data regarding citizens of the E.U. to the U.S. On July 16, 2020, the Court of Justice of the European Union ("CJEU") published its decision in the case of Data Protection Commissioner v Facebook Ireland Ltd, Maximilian Schrems (known as the "Schrems II" case). In Schrems II, the CJEU completely invalidated the EU-US Privacy Shield, but the Standard Contractual Clauses ("SCC's") remain valid. While we had certified certain lines of business under the Privacy Shield, we have chosen to adopt E.U. SCC's published by the European Commission as the primary basis for the export of data from the E.U. to the U.S. and were not significantly affected by this decision. The European Data Protection Board ("EDPB") is working on regulatory guidance in light of Schrems II, but such guidance has not yet been finalized.
The E.U.'s General Data Protection Regulation ("GDPR"), which became effective on May 25, 2018, applies to all organizations processing the personal data of individuals in the E.U., regardless of where such organization is based. The GDPR has heightened our data protection compliance obligations, impacted our businesses' collection, processing and retention of personal data and imposed stricter standards for reporting data breaches. The GDPR also imposes significant penalties for non-compliance.
The Company is also subject to the California Consumer Privacy Act ("CCPA"), which came into effect on January 1, 2020, and provides California residents additional data protection rights including the right to be informed about the personal information collected by third parties and the use of that personal information. Further, certain operations of the Company became subject to the Brazilian General Personal Data Protection Act in August 2020. The Company has adopted a comprehensive global privacy program to assess and manage these evolving risks and continues to monitor new data privacy laws throughout the jurisdictions in which we do business, including data localization requirements in applicable jurisdictions.
In addition, our businesses are increasingly subject to laws and regulations relating to surveillance, encryption and data onshoring in the jurisdictions in which we operate. Compliance with these laws and regulations may require us to change our technology for information security, operational infrastructure, policies and procedures, which could be time-consuming and costly.
- Money Transfer. Elements of our cash access and money transmission businesses are registered as a Money Services Business and are subject to the USA Patriot Act and reporting requirements of the Bank Secrecy Act and U.S. Treasury Regulations. These businesses may also be subject to certain state and local licensing requirements. The Financial Crimes Enforcement Network, state attorneys general, and other agencies have enforcement responsibility over laws relating to money laundering, currency transmission, and licensing. In applicable states, we have obtained money transmitter licenses. However, changes to state money transmission laws and regulations, including changing interpretations and the implementation of new or varying regulatory requirements, may result in the need for additional or expanded money transmitter licenses, additional capital allocations or changes in the way in which we deliver certain services.
We are also subject to certain economic and trade sanctions programs that are administered by the U.S. Treasury's Office of Foreign Assets Control (referred to as "OFAC"), which prohibit or restrict transactions to or from or dealings with specified countries, their governments, and in certain circumstances, their nationals, and with individuals and entities that are specially-designated nationals of those countries, narcotics traffickers, and terrorists or terrorist organizations. Similar anti-money laundering laws apply to movements of currency and payments through electronic
transactions and to dealings with persons specified in lists maintained by the country equivalents to OFAC in several other countries. We have implemented policies, procedures, and internal controls that are designed to comply with the regulations and economic sanctions programs administered by OFAC, as well as all other applicable anti-money laundering laws and regulations.
- Consumer Reporting and Protection. Our decision solutions subsidiary, ChexSystems, maintains a database of consumer information used to provide various account opening services including credit scoring analysis and is subject to the Federal Fair Credit Reporting Act ("FCRA") and similar state laws. The FCRA regulates consumer reporting agencies ("CRAs"), including ChexSystems, and governs the accuracy, fairness, and privacy of information in the files of CRAs that engage in the practice of assembling or evaluating certain information relating to consumers for certain specified purposes. CRAs are required to follow reasonable procedures to assure maximum possible accuracy of information concerning the individual about whom the report relates and if a consumer disputes the accuracy of any information in the consumer’s file, to conduct a reasonable investigation within statutory timelines. The FCRA imposes many other requirements on CRAs and users of consumer report information. Regulatory enforcement of the FCRA is under the purview of the United States Federal Trade Commission, the CFPB, and state attorneys general, acting alone or in concert with one another. In furtherance of our objectives of data accuracy, fair treatment of consumers, protection of consumers' personal information, and compliance with these laws, we have made considerable investment to maintain a high level of security for our computer systems in which consumer data resides, and we maintain consumer relations call centers to facilitate accurate and timely handling of consumer requests for information and handling disputes. We also are focused on ensuring our operating environments safeguard and protect consumer's personal information in compliance with these laws.
Our consumer reporting and consumer-facing businesses are subject to CFPB Bulletin 2013-7 (a successor to the former Regulation AA - Unfair Deceptive Acts or Practices), which defines Unfair, Deceptive or Abusive Acts or Practices ("UDAAP"). This specific bulletin states that UDAAPs can cause significant financial injury to consumers, erode consumer confidence, and undermine fair competition in the financial marketplace. Original creditors and other covered persons and service providers under the Dodd-Frank Act involved in collecting debt related to any consumer financial product or service are subject to the prohibition against UDAAPs in the Dodd-Frank Act.
-
Debt Collection. Our collection services are subject to the Federal Fair Debt Collection Practices Act and various state collection laws and licensing requirements. The Federal Trade Commission, as well as state attorneys general and other agencies, have enforcement responsibility over the collection laws, as well as the various credit reporting laws.
-
Anti-Corruption. FIS is subject to applicable anti-corruption laws, such as the U.S. Foreign Corrupt Practices Act and the U.K. Bribery Act, in the jurisdictions in which it operates. Anti-corruption laws generally prohibit offering, promising, giving, or authorizing others to give anything of value, either directly or indirectly, to a government official or private party in order to influence official action or otherwise gain an unfair business advantage, such as to obtain or retain business. FIS has implemented policies, procedures, training and internal controls that are designed to comply with such laws, rules and regulations.
The foregoing list of laws and regulations to which our Company is subject is not exhaustive, and the regulatory framework governing our operations changes continuously. Enactment of new laws and regulations may increasingly affect the operations of our business, directly and indirectly, which could result in substantial regulatory compliance costs, litigation expense, adverse publicity, and/or loss of revenue.
Information Security
Globally, attacks on information technology systems continue to grow in frequency, complexity and sophistication. This is a trend we expect to continue. Such attacks have become a point of focus for individuals, businesses and governmental entities. The objectives of these attacks include, among other things, gaining unauthorized access to systems to facilitate financial fraud, disrupt operations, cause denial of service events, corrupt data, and steal non-public information. These circumstances present both a threat and an opportunity for FIS. As part of our business, we electronically receive, process, store and transmit a wide range of confidential information, including sensitive customer information and personal consumer data. We also operate payment, cash access and prepaid card systems.
FIS remains focused on making strategic investments in information security to protect our clients and our information systems. This includes both capital expenditures and operating expenses on hardware, software, personnel and consulting services. We also participate in industry and governmental initiatives to improve information security for our clients. Through
the expertise we have gained with this ongoing focus and involvement, we have developed fraud, security, risk management and compliance solutions to target this growth opportunity in the financial services industry.
For more information on Information Security, see "Item 7. Management's Discussion and Analysis of Financial Condition and Results of Operations."
Human Capital Management
Employee Population
As of December 31, 2020, we had more than 62,000 employees, including approximately 38,000 employees principally employed outside of the U.S. None of our U.S. workforce currently is unionized. Approximately 9,000 of our employees, primarily in Brazil and the U.K., are represented by labor unions or works councils.
Health and Safety
The health and safety of our employees is a key priority. At the beginning of the COVID-19 pandemic, we activated our company-wide Pandemic Plan. We equipped more than 95% of our workforce with the necessary technology and connectivity to work remotely. We instituted safety protocols and procedures throughout our facilities for essential employees who continued to work on site. In addition, we expanded our employee benefits to include telemedicine, paid time off for employees impacted by COVID-19 to deal with personal illness or have time off to care for family members, and to expand FIS Cares globally to assist our colleagues in need. The Company also offers webinars and other online resources to enable employees to focus on their physical, emotional, and social well-being.
Corporate Culture
Our culture stems from embracing our corporate values as we work together to win as one team, lead with integrity and strive to be the change for our colleagues, clients and communities. The Company believes that inclusion and diversity are at the core of our corporate values. The diversity of our workforce helps us use our collective strengths to innovate and deliver the best products and solutions for our clients. Our Board of Directors and senior leaders are united in championing inclusion and diversity within our workforce through their leadership in prioritizing equality and diversity in our human resource decision making throughout the Company. The Company sponsors Inclusion Networks, which are led by employees who share common backgrounds and experiences. These groups support their members while promoting the Company's overall goal of fostering an inclusive work environment. Current FIS Inclusion Networks include Women, Black, Latinx, Disability, LGBTQ+, Rising Professionals, Veterans, and Working Families, and we have added a governance layer of an Inclusion and Diversity Council which includes participation and leadership by senior executives of the Company. The Chief Executive Officer and the Chief People Officer regularly update the Company's Board of Directors on human capital management and inclusion and diversity initiatives.
Talent Management
Our colleagues are primary stakeholders in our organization, and we are strategic in attracting talent that adds to our collective strengths to innovate and deliver an exemplary client experience. We have an inclusive culture where employees receive the development needed to grow their careers and deliver high-quality outcomes. Our practices include a comprehensive performance feedback culture that includes quarterly performance reviews, access to a variety of online and self-paced learning resources, as well as virtual and face-to-face development offerings, targeted development programs for high-potential and senior management employees, opportunities to apply for open roles to move within the Company and executive-level succession planning.
Available Information
Our website address is www.fisglobal.com. We make our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, and Current Reports on Form 8-K, and any amendments to those reports, available, free of charge, on that website as soon as reasonably practicable after we file or furnish them to the SEC. Our Corporate Governance Policy and Code of Business Conduct and Ethics are also available on our website and are available in print, free of charge, to any shareholder who mails a request to the Corporate Secretary, Fidelity National Information Services, Inc., 601 Riverside Avenue, Jacksonville, FL 32204 USA. Other corporate governance-related documents can be found at our website as well. However, the information found on our website is not a part of this or any other report.
Previous: Cover and table of contents · Next: Item 1A. Risk Factors