A Dark Vector Cognition product

Item 9A. Controls and Procedures

39K characters. Original on sec.gov · Markdown

Item 9A. Controls and Procedures

Background

Prior to the issuance of the Company’s consolidated financial statements for the fiscal year ended June 30, 2017, the audit committee (the “Audit Committee”) of the Company’s Board of Directors (the “Board”) investigated and assessed certain accounting and internal control matters at the Company, principally focused on certain revenue recognition matters. Concurrently, new members of the Company’s management, under the direction of the Audit Committee, performed a thorough analysis of the Company’s historical financial statements, accounting policies and financial reporting, as well as the Company’s disclosure controls and procedures and its internal control over financial reporting. Management concluded that our disclosure controls and procedures were not effective as of June 30, 2017 because of certain material weaknesses in our internal control over financial reporting, as described in our 2017 10-K.

The Company is committed to remediating these material weaknesses and strengthening its internal control over financial reporting, and our management has developed a comprehensive plan for this remediation and strengthening. In consultation with the Audit Committee, our management began developing this plan during the comprehensive analysis described above and continued developing it after we filed the 2017 10-K. We began to implement certain elements of the plan during fiscal years 2018 and 2019, and have continued to implement the plan during the current fiscal year. Among other actions, our actions to date have included both strengthening existing individual controls and designing and implementing new individual controls. However, before our management can conclude that these new and strengthened controls are sufficient to remediate the material weaknesses, the controls must operate effectively for a sufficient period of time. As of June 30, 2019,

sufficient time had not elapsed since we implemented the new and strengthened controls for our management to determine that they operated effectively as of that date. For this reason, although we have taken many actions to strengthen our internal control over financial reporting and the Company’s disclosure controls and procedures, our management did not conclude that any of the material weaknesses identified in the 2017 10-K had been remediated as of June 30, 2019. The actions we have taken to address these material weaknesses are described below under “Remediation Plan and Status.”

In connection with the preparation and filing of this Annual Report on Form 10-K, we have conducted the requisite evaluations of the effectiveness of our disclosure controls and procedures and of our internal control over financial reporting, both as of June 30, 2019.

Evaluation of Disclosure Controls and Procedures

Under the supervision, and with the participation, of our management, including our Chief Executive Officer (“CEO”) and Chief Financial Officer (“CFO”), we evaluated the effectiveness of our disclosure controls and procedures as defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”), as of June 30, 2019. Based on this evaluation of our disclosure controls and procedures, our CEO and CFO have concluded that our disclosure controls and procedures were not effective as of June 30, 2019 because of certain material weaknesses in our internal control over financial reporting, as further described below.

Notwithstanding the conclusion by our CEO and CFO that our disclosure controls and procedures as of June 30, 2019 were not effective, and notwithstanding the material weaknesses in our internal control over financial reporting described below, management believes that the consolidated financial statements and related financial information included in this Annual Report fairly present in all material respects our financial condition, results of operations and cash flows as of the dates presented, and for the periods ended on such dates, in conformity with accounting principles generally accepted in the United States of America (“U.S. GAAP”).

Management’s Report on Internal Control Over Financial Reporting

Management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Exchange Act Rules 13a-15(f) and 15d-15(f).

Internal control over financial reporting is a process designed by, or under the supervision of, our CEO and CFO to provide reasonable assurance regarding the reliability of financial reporting and the preparation of our consolidated financial statements for external purposes in accordance with U.S. GAAP. Management’s internal control over financial reporting includes those policies and procedures that (i) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of our assets, (ii) provide reasonable assurance that transactions are appropriately recorded to permit preparation of financial statements in accordance with U.S. GAAP and that our receipts and expenditures are made only in accordance with authorizations of management, acting under authority delegated to them by the Board, and (iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on our financial statements.

Management, including our CEO and CFO, assessed our internal control over financial reporting as of June 30, 2019. In making this assessment, management used the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission in its Internal Control - Integrated Framework (2013) (the “COSO Framework”). Based on this assessment, management has determined that we did not maintain effective internal control over financial reporting as of June 30, 2019 because of the material weaknesses described below.

A material weakness in internal controls is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis. Because of its inherent limitations, even appropriate internal control over financial reporting may not prevent or detect misstatements.

In connection with management’s assessment of the Company’s internal control over financial reporting described above, management has identified the deficiencies described below that constitute material weaknesses in our internal control over financial reporting as of June 30, 2019.

Control Environment

In our Annual Report on Form 10-K for the year ended June 30, 2017 we disclosed the identification of deficiencies in the control environment component of the COSO Framework that constituted material weaknesses, either individually or in the aggregate. These deficiencies related to all the principles associated with the control environment component of the COSO Framework.

We are committed to remediating the underlying cause of these material weaknesses and are taking actions to enhance our internal control over financial reporting relating to the material weaknesses. However, we are still in the process of implementing our comprehensive remediation plan and we have not had sufficient time to test the effectiveness of the new and strengthened controls as of June 30, 2019. Consequently, deficiencies that constitute material weaknesses, either individually or in the aggregate, in the control environment and other components remain.

The material weaknesses noted above cannot be considered remediated until each control has been appropriately designed, has operated for a sufficient period of time, and management has concluded, through testing, that the control is operating effectively. Due to the interdependencies between the COSO Framework components, the material weakness in our control environment contributed to other material weaknesses within our system of internal control over financial reporting.

Risk Assessment

We identified deficiencies in the risk assessment component of the COSO Framework that aggregated to a material weakness. These deficiencies related to the principles associated with the risk assessment component of the COSO Framework, specifically principles within the component related to: (i) identifying, assessing, and communicating appropriate control objectives, (ii) identifying and analyzing risks to achieve these objectives, (iii) contemplating fraud risks, and (iv) identifying and assessing changes in the business that could impact the system of internal controls. As of June 30, 2019, our risk assessment component framework had not yet operated for a sufficient period of time for us to determine its effectiveness.

Control Activities

We identified deficiencies in the control activities component of the COSO Framework that aggregated to a material weakness. These deficiencies related to principles associated with the control activities component of the COSO Framework, specifically principles within the component related to (i) selecting and developing control activities that mitigate risks, (ii) selecting and developing general controls over technology and (iii) deploying control activities through policies that establish what is expected and procedures that put policies into action. We did not design or operate certain control activities to sufficiently respond to potential risks of material misstatement in the area of revenue recognition. We did not effectively select and develop certain information technology (“IT”) general controls and we also had control deficiencies at both the IT administrator and end-user levels across multiple applications relevant to financial reporting. We also had deficiencies related to segregation of duties. Deficiencies in control activities contributed to the potential for there to have been material accounting errors in substantially all financial statements account balances and disclosures.

Information and Communication

We identified deficiencies in the information and communication component of the COSO Framework that aggregated to a material weakness. These deficiencies related to principles associated with the information and communications component of the COSO Framework, specifically principles within the component related to (i) generating and using relevant quality information and (ii) internally communicating information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. We rely on manual business processes to compensate for a lack of extensive integration in our information systems. We also rely heavily on each of our various functions, such as sales, operations, accounting, legal and management, to communicate to the other functions information that the entire organization needs to operate an effective internal control environment. In certain areas, our control activity deficiencies resulted from insufficient communication of information among our internal functions.

Monitoring of Controls

We identified deficiencies in the monitoring of controls component of the COSO Framework that aggregated to a material weakness. There were deficiencies related to a principle associated with the monitoring of controls component of the COSO Framework, specifically selecting, developing and performing ongoing and/or separate evaluations. We lacked controls (i) to determine whether components of internal control were present and functioning and (ii) to detect incorrect accounting practices.

The material weaknesses noted above contributed to the following additional material weaknesses:

Revenue Recognition Accounting

We identified deficiencies in revenue recognition accounting controls that resulted in material weaknesses, either individually or in the aggregate, as we did not appropriately design, or effectively operate, internal controls over certain aspects of accurate recording, presentation, and disclosure of revenue and related costs. The following were contributing factors to the material weaknesses in revenue recognition accounting:

•Our internal controls did not consistently identify and properly account for certain key non-standard contract or arrangement terms for sales transactions.
•Our internal controls failed to consistently identify transactions where the terms of the sales arrangements with our customers were not properly documented in a form that fully reflected the final understanding between the parties as to the specific nature and terms of the agreed-upon transaction.
•Our internal controls failed to consistently identify, resolve, document, and allow for proper accounting where there were inconsistencies among the various documents underlying our sales transactions, and we did not always communicate the existence or resolution of those inconsistencies to our accounting organization to enable the proper recognition of revenue.
•Internal controls intended to establish a consistent approach for reviewing pricing and establishing supportable estimates of standalone selling price in allocating revenue between multiple performance obligations have not been implemented for a sufficient period of time to demonstrate the controls were operating effectively.

Information Technology General Controls

We identified deficiencies related to IT general controls that represented a material weakness, either individually or in the aggregate. The following were contributing factors to the material weakness in information technology and general controls:

•We have a decentralized approach to developing IT policies and practices and to monitoring our IT controls. As a result, our internal procedures for granting and monitoring employee access, and managing changes to various applications and infrastructure layers relevant to our financial reporting are not consistent across those applications and infrastructure layers. In addition, some of our internally-developed applications relevant to financial reporting lack system tracking capabilities to monitor access changes or application changes. We have also authorized certain users with broad access, both as a user and as an administrator, to all parts of our primary accounting system without adequate monitoring or recording of how they used that access. As a result of these factors, we have material weaknesses related to access controls and change management. The fact that we have material weaknesses related to access controls and change management means that it is possible that our business process controls that depend on the affected information systems, or that depend on data or financial reports generated from the affected information systems, could be adversely affected due to the access control and change management issues, although we have identified no instances of any adverse effect due to these deficiencies.

The effectiveness of our internal control over financial reporting as of June 30, 2019 has been audited by Deloitte & Touche LLP, our independent registered public accounting firm, as stated in its report that is included herein.

Remediation Plan and Status

As previously disclosed, starting in the second half of fiscal year 2018 and throughout fiscal year 2019, we began to design and implement processes and procedures to remediate material weaknesses identified as of June 30, 2017.

Our management is committed to remediating identified control deficiencies (including both those that rise to the level of a material weakness and those that do not), fostering continuous improvement in our internal controls and enhancing our overall internal controls environment. Our management believes that these remediation actions, along with additional actions, when fully implemented, will remediate the material weaknesses we have identified and strengthen our internal control over financial reporting. We are committed to improving our internal control processes and intend to continue to review and improve our financial reporting controls and procedures. As we continue to evaluate and work to improve our internal control over financial reporting, we may take additional or different measures to address control deficiencies with the overall objective to

design and operate internal controls that mitigate identified risks and enable an effective system of internal control over external financial reporting.

We have taken the following actions, among others, to address previously disclosed material weaknesses:

•Restructured our sales organization, which resulted in the resignations of the Senior Vice President of International Sales, the Senior Vice President of Worldwide Sales, the Vice President, Strategic Accounts, the Vice President, Strategic Sales, the Vice President, Business Development and certain other sales personnel.
•Appointed experienced professionals to key accounting and finance and compliance leadership positions, including the appointments of a new Chief Financial Officer and a new Corporate Controller in January 2018, and the creation of, and appointments to, two newly established roles of Chief Compliance Officer and Vice President of Internal Audit in May 2018 and August 2018, respectively.
•Reviewed and amended our Code of Conduct to align with the organizational changes described above and to strengthen certain provisions regarding compliance and reporting violations of the Code of Conduct.
•Adopted an Internal Audit Charter setting forth the responsibilities of the internal audit function and establishing that the Vice President of Internal Audit reports directly to the Audit Committee and that the Audit Committee has authority to provide adequate funding for this function.
•Changed our organizational structure to narrow the scope of responsibilities of certain of our senior executives and to revise various reporting relationships, which included the appointment of a new Senior Vice President of Worldwide Sales, and a new Senior Vice President of Operations.
•Conducted training in the following areas:
–Revenue recognition training for our global sales force, various operations personnel, and certain senior executives, including our CEO, which included detailed examples of acceptable and unacceptable sales practices,
–Reviewed with our senior management team our amended Code of Conduct,
–Reviewed with our CEO enhanced processes for periodic evaluations by the CEO and the CFO of the effectiveness of our disclosure controls and procedures, and the periodic assessments by the CEO and the CFO of the effectiveness of our internal control over financial reporting, and other compliance matters, and
–Shipping and cut-off training for accounting and operations personnel that included new requirements for quarter-end procedures.
•Enhanced the sales sub-certification document that supports our CEO’s and CFO’s financial statement certifications and expanded the sub-certification participation population to the global sales force.

To date, we have taken the following actions related to material weaknesses that, as of June 30, 2019, had not yet been fully implemented or had not been in place for a sufficient period of time to demonstrate that they were having their desired effect:

•Upgraded our accounting department to include the new roles of Senior Director of Tax, Financial Audit Director and Information Technology Audit Director, as well as replaced certain of our accounting personnel with more experienced individuals, including rebuilding and expanding our revenue recognition team.
•Enhanced the financial statement risk assessment and fraud risk assessment which are a foundational element of our Sarbanes-Oxley compliance program.
•Implemented a sequence of meetings around our processes to prepare and report on the consolidated financial statements that promotes cross-functional communication and broadens the accountability for internal controls.
•Implemented new revenue recognition processes and controls to:
–Effect an appropriate cutoff of shipping activity
–Increase the alignment of invoicing with physical shipment
–Identify and account for transactions that may not have met revenue recognition criteria
–Appropriately account for the allocation of revenue among performance obligations
•Assigned accountability for certain internal controls to our Compliance Department, such as our organizational-wide quarterly sales certification process.
•Conducted a process by which employees re-certified their understanding of, and compliance with, the Company’s Code of Conduct.
•Adopted a charter for our compliance program to promote an organizational culture that encourages the highest standards of ethical business conduct and compliance with the law, exercises appropriate due diligence to prevent and detect unlawful conduct, and protects the Company’s reputation.

Our management believes that meaningful progress has been made on the remaining remediation efforts. Management regards successful completion of our remaining remediation actions as an important priority. Some of the more significant remaining remediation activities include:

•Developing and implementing an ongoing compliance training program regarding significant accounting and financial reporting matters, as well as broad compliance matters, for accounting, financial reporting, sales and operations personnel, as well as for our CEO, our other corporate executives and the Board.
•Integrating the responsibility for internal controls across business functions to assign accountability for internal controls beyond the accounting and finance team.
•Increasing standardization and automation within accounting processes to improve the reliability of information used by existing accounting personnel.
•Implementing a governance committee for our Sarbanes-Oxley compliance program and assigning individual accountability for internal controls.
•Redesigning and implementing necessary changes to the existing system of internal controls in the context of the revised and more comprehensive risk assessment.
•Updating selected policies and assigning accountable policy owners related to revenue recognition.
•Reevaluating the boundary applications that interface with our primary accounting and reporting application and redesigning logical access and program change controls to enhance the reliability of information used to conduct other internal controls.
•Implementing and/or enhancing IT general controls and segregation of duties controls:
–Monitoring instances in which individuals are granted broad access
–Strengthening provisioning of privileged access roles
–Developing change management capabilities in certain boundary applications and implementing new change management controls
•Identifying and properly accounting for non-standard terms, including increased information sharing between Sales and other departments on sales transactions
•Identifying and resolving instances in which customer contracts and purchase orders have conflicting terms, including the new processes to ensure customer master data is complete, accurate and updated as needed on a timely basis
•Enhancing procedures to ensure contracts create enforceable rights and obligations, including standardizing the method by which we accept customer purchase orders.
•Developing a system of daily reports related to revenue recognition that enable ongoing monitoring for non-standard transactions and the appropriate allocation of revenue among performance obligations.
•Testing of sufficient instances of the performance of controls to determine operational effectiveness.

Changes in Internal Control Over Financial Reporting

Other than the ongoing remediation efforts described above, there were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the three months ended June 30, 2019 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM

To the shareholders and the Board of Directors of Super Micro Computer, Inc.

Opinion on Internal Control over Financial Reporting

We have audited the internal control over financial reporting of Super Micro Computer, Inc. and subsidiaries (the “Company”) as of June 30, 2019, based on criteria established in Internal Control - Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In our opinion, because of the effect of the material weaknesses identified below on the achievement of the objectives of the control criteria, the Company has not maintained effective internal control over financial reporting as of June 30, 2019, based on criteria established in Internal Control - Integrated Framework (2013) issued by COSO.

We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year June 30, 2019, of the Company and our report dated December 19, 2019, expressed an unqualified opinion on those financial statements and included an explanatory paragraph regarding the Company’s change in method of accounting for revenue in fiscal year 2019 due to the adoption of Accounting Standards Codification 606, Revenue from Contracts with Customers.

Basis for Opinion

The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Management’s Report on Internal Control Over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.

Definition and Limitations of Internal Control over Financial Reporting

A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.

Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.

Material Weaknesses

A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the company’s annual or interim financial statements will not be prevented or detected on a timely basis. The following material weaknesses have been identified and included in management's assessment:

Control Environment

The Company has identified deficiencies in the control environment component of the COSO Framework that constituted material weaknesses, either individually or in the aggregate. These deficiencies related to all the principles associated with the control environment component of the COSO Framework. The Company is still in the process of implementing its comprehensive remediation plan and has not had sufficient time to test the effectiveness of certain remediation actions as of June 30, 2019. Consequently, deficiencies that constitute material weaknesses, either individually or in the aggregate, in the control environment and other components remain.

Due to the interdependencies between the COSO Framework components, the material weakness in the control environment contributed to other material weaknesses within the Company’s system of internal control over financial reporting.

Risk Assessment

The Company identified deficiencies in the risk assessment component of the COSO Framework that aggregated to a material weakness. These deficiencies related to the principles associated with the risk assessment component of the COSO Framework, specifically principles within the component related to: (i) identifying, assessing, and communicating appropriate control objectives, (ii) identifying and analyzing risks to achieve these objectives, (iii) contemplating fraud risks, and (iv) identifying and assessing changes in the business that could impact the system of internal controls. As of June 30, 2019, the Company’s risk assessment component framework had not yet operated for a sufficient period of time to determine its effectiveness.

Control Activities

The Company identified deficiencies in the control activities component of the COSO Framework that aggregated to a material weakness. These deficiencies related to principles associated with the control activities component of the COSO Framework, specifically principles within the component related to (i) selecting and developing control activities that mitigate risks, (ii) selecting and developing general controls over technology and (iii) deploying control activities through policies that establish what is expected and procedures that put policies into action. The Company did not design or operate certain control activities to sufficiently respond to potential risks of material misstatement in the area of revenue recognition. The Company did not effectively select and develop certain information technology (“IT”) general controls and also had control deficiencies at both the IT administrator and end-user levels across multiple applications relevant to financial reporting. The Company also had deficiencies related to segregation of duties. Deficiencies in control activities contributed to the potential for there to have been material accounting errors in substantially all financial statements account balances and disclosures.

Information and Communication

The Company identified deficiencies in the information and communication component of the COSO Framework that aggregated to a material weakness. These deficiencies related to principles associated with the information and communications component of the COSO Framework, specifically principles within the component related to (i) generating and using relevant quality information and (ii) internally communicating information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. The Company relies on manual business processes to compensate for a lack of extensive integration in their information systems. The Company also relies heavily on each of the various functions, such as sales, operations, accounting, legal and management, to communicate to the other functions information that the entire organization needs to operate an effective internal control environment. In certain areas, control activity deficiencies resulted from insufficient communication of information among internal functions.

Monitoring of Controls

The Company identified deficiencies in the monitoring of controls component of the COSO Framework that aggregated to a material weakness. There were deficiencies related to a principle associated with the monitoring of controls component of the COSO Framework, specifically selecting, developing and performing ongoing and/or separate evaluations. The Company lacked controls (i) to determine whether components of internal control were present and functioning and (ii) to detect incorrect accounting practices.

The material weaknesses noted above contributed to the following additional material weaknesses:

Revenue Recognition Accounting

The Company identified deficiencies in revenue recognition accounting controls that resulted in material weaknesses, either individually or in the aggregate, as the Company did not appropriately design, or effectively operate, internal controls

over certain aspects of accurate recording, presentation, and disclosure of revenue and related costs. The following were contributing factors to the material weaknesses in revenue recognition accounting:

•Internal controls did not consistently identify and properly account for certain key non-standard contract or arrangement terms for sales transactions.
•Internal controls failed to consistently identify transactions where the terms of the sales arrangements with customers were not properly documented in a form that fully reflected the final understanding between the parties as to the specific nature and terms of the agreed-upon transaction.
•Internal controls failed to consistently identify, resolve, document, and allow for proper accounting where there were inconsistencies among the various documents underlying sales transactions, and the Company did not always communicate the existence or resolution of those inconsistencies to the accounting organization to enable the proper recognition of revenue.
•Internal controls intended to establish a consistent approach for reviewing pricing and establishing supportable estimates of standalone selling price in allocating revenue between multiple performance obligations have not been implemented for a sufficient period of time to demonstrate the controls were operating effectively.

Information Technology General Controls

The Company identified deficiencies related to IT general controls that represented a material weakness, either individually or in the aggregate. The following were contributing factors to the material weakness in information technology and general controls:

•The Company has a decentralized approach to developing IT policies and practices and to monitoring our IT controls. As a result, the Company’s internal procedures for granting and monitoring employee access and managing changes to various applications and infrastructure layers relevant to financial reporting are not consistent across those applications and infrastructure layers. In addition, some of the Company’s internally-developed applications relevant to financial reporting lack system tracking capabilities to monitor access changes or application changes. The Company has also authorized certain users with broad access, both as a user and as an administrator, to all parts of the primary accounting system without adequate monitoring or recording of how they used that access. As a result of these factors, the Company has material weaknesses related to access controls and monitoring for changes to applications. The fact that the Company had material weaknesses related to access controls and change management means that it is possible that business process controls that depend on the affected information systems, or that depend on data or financial reports generated from affected information systems, could be adversely affected due to the access control and change management issues, although the Company has identified no instances of any adverse effect due to these deficiencies.

These material weaknesses were considered in determining the nature, timing, and extent of audit tests applied in our audit of the consolidated financial statements as of and for the year ended June 30, 2019, of the Company, and this report does not affect our report on such financial statements.

/s/ Deloitte & Touche LLP

San Jose, California

December 19, 2019

Previous: Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure · Next: Item 9B. Other Information