Item 9A. Controls and Procedures

14K characters. Original on sec.gov · Markdown

Item 9A. Controls and Procedures

Evaluation of Disclosure Controls and Procedures

Under the supervision, and with the participation, of our management, including our Chief Executive Officer (“CEO”) and Chief Financial Officer (“CFO”), we evaluated the effectiveness of our disclosure controls and procedures as defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”), as of June 30, 2020. Based on this evaluation, our CEO and CFO have concluded that our disclosure controls and procedures were not effective as of June 30, 2020 because of a material weakness in our internal control over financial reporting, as further described below.

Notwithstanding the material weakness, management believes that the consolidated financial statements and related financial information included in this Annual Report on Form 10-K present fairly, in all material respects, our financial condition, results of operations and cash flows as of and for the periods presented in accordance with U.S. generally accepted accounting principles (“U.S. GAAP”).

Management’s Report on Internal Control Over Financial Reporting

Management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Exchange Act Rules 13a-15(f) and 15d-15(f).

Internal control over financial reporting is a process designed by, or under the supervision of, our CEO and CFO to provide reasonable assurance regarding the reliability of financial reporting and the preparation of our consolidated financial statements for external purposes in accordance with U.S. GAAP. Management’s internal control over financial reporting includes those policies and procedures that (i) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of our assets, (ii) provide reasonable assurance that transactions are appropriately recorded to permit preparation of financial statements in accordance with U.S. GAAP and that our receipts and expenditures are made only in accordance with authorizations of management, acting under authority delegated to them by the Board, and (iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on our financial statements.

Management, including our CEO and CFO, assessed our internal control over financial reporting as of June 30, 2020. In making this assessment, management used the criteria set forth by the Committee of Sponsoring Organizations of the Treadway Commission in its Internal Control - Integrated Framework (2013) (the “COSO Framework”). Based on this assessment, management has determined that we did not maintain effective internal control over financial reporting as of June 30, 2020 because of the material weakness described below.

A material weakness in internal controls is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis. Because of its inherent limitations, even appropriate internal control over financial reporting may not prevent or detect misstatements.

Information Technology (“IT”) General Controls

We identified deficiencies related to IT general controls that aggregated to a material weakness. The following were contributing factors to the material weakness in IT general controls:

•We have authorized certain IT users with broad access to all parts of our primary accounting system without adequate monitoring or recording of how they used that access. In addition, access control deficiencies and change management deficiencies were noted on other systems relevant to financial reporting. Some of our internally-developed systems relevant to financial reporting lack system tracking capabilities to monitor access changes or application changes. In some cases, IT general controls were not designed effectively, and in others, were designed effectively but did not operate effectively or for a sufficient period of time. Business process controls that depend on the affected information systems, or that depend on data or financial reports generated from the affected information

systems to be accurate and complete, could be adversely affected, although we have identified no instances of any adverse effect due to these deficiencies.

The effectiveness of our internal control over financial reporting as of June 30, 2020 has been audited by Deloitte & Touche LLP, our independent registered public accounting firm, as stated in its report that is included herein.

Remediation Plan

We have remediated the material weaknesses related to each of the five COSO components of internal control (Control Environment; Risk Assessment; Control Activities; Information & Communication; Monitoring of Controls) and revenue recognition accounting controls by completing our remediation plan, as previously disclosed in our Annual Report on Form 10-K for the year ended June 30, 2019.

Our management is committed to remediating identified control deficiencies (including both those that rise to the level of a material weakness and those that do not), fostering continuous improvement in our internal controls and enhancing our overall internal controls environment. Our management believes that the actions below will remediate the material weakness we have identified and strengthen our internal control over financial reporting. As we continue to evaluate and work to improve our internal control over financial reporting, we may take additional or different measures to address control deficiencies with the overall objective to provide reasonable assurance regarding the reliability of financial reporting and the preparation of our consolidated financial statements through an effective system of internal control over financial reporting.

To date, we have taken the following actions related to the material weakness that, as of June 30, 2020, had not yet been fully implemented or had not been in place for a sufficient period of time to demonstrate that they were having their desired effect:

•Re-designed the logical access roles associated with our primary ERP application and re-provisioned those roles to enforce segregation of duties and align user access commensurate with their business process role and job responsibilities;
•Implemented a third-party application to facilitate improved processes and controls related to provisioning privileged access roles and the monitoring of those roles; and
•For one of our boundary applications (fulfillment and warehouse management), implemented a new program change management control.

Our management believes that meaningful progress has been made on the remaining remediation efforts. Management regards successful completion of our remaining remediation actions as an important priority. The remaining remediation activities include:

•Strengthening access controls related to boundary systems;
•Strengthening provisioning of privileged access roles;
•Monitoring instances in which individuals are granted broad access; and
•Implementing new change management controls related to boundary systems.

Changes in Internal Control over Financial Reporting

Other than the remediation efforts described above, there were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the three months ended June 30, 2020 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.

REPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM

To the Stockholders and the Board of Directors of Super Micro Computer, Inc.

Opinion on Internal Control over Financial Reporting

We have audited the internal control over financial reporting of Super Micro Computer, Inc. and subsidiaries (the “Company”) as of June 30, 2020, based on criteria established in Internal Control - Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In our opinion, because of the effect of the material weakness identified below on the achievement of the objectives of the control criteria, the Company has not maintained effective internal control over financial reporting as of June 30, 2020, based on criteria established in Internal Control - Integrated Framework (2013) issued by COSO.

We have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year ended June 30, 2020, of the Company and our report dated August 28, 2020, expressed an unqualified opinion on those financial statements.

Basis for Opinion

The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Management’s Report on Internal Control Over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.

We conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.

Definition and Limitations of Internal Control over Financial Reporting

A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.

Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.

Material Weakness

A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the company’s annual or interim financial statements will not be prevented or detected on a timely basis. The following material weakness has been identified and included in management's assessment:

Information Technology (“IT”) General Controls

The Company identified deficiencies related to IT general controls that aggregated to a material weakness. The following were contributing factors to the material weakness in IT general controls:

•The Company authorized certain IT users with broad access to all parts of the primary accounting system without adequate monitoring or recording of how they used that access. In addition, access control deficiencies and change management deficiencies were noted on other systems relevant to financial reporting. Some of the Company’s

internally-developed systems relevant to financial reporting lack system tracking capabilities to monitor access changes or application changes. In some cases IT general controls were not designed effectively, and in others, were designed effectively but did not operate effectively or for a sufficient period of time. Business process controls that depend on the affected information systems, or that depend on data or financial reports generated from the affected information systems to be accurate and complete, could be adversely affected, although the Company has identified no instances of any adverse effect due to these deficiencies.

This material weakness was considered in determining the nature, timing, and extent of audit tests applied in our audit of the consolidated financial statements as of and for the year ended June 30, 2020, of the Company, and this report does not affect our report on such financial statements.

/s/ Deloitte & Touche LLP

San Jose, California

August 28, 2020

Previous: Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure · Next: Item 9B. Other Information