Item 9A. Controls and Procedures
19K characters. Original on sec.gov · Markdown
Item 9A. Controls and Procedures
Attached as exhibits to this Form 10-K are certifications of our Chief Executive Officer and Chief Financial Officer, which are required in accordance with Rule 13a-14 of the Exchange Act. This “Controls and Procedures” section includes information concerning the internal controls and controls evaluation referred to in the certifications.
(a) Management’s Evaluation of Disclosure Controls and Procedures
Our management, with the participation of our Chief Executive Officer and Chief Financial Officer, is responsible for evaluating the effectiveness of our disclosure controls and procedures (as defined in Exchange Act Rules 13a-15(e) and 15d-15(e)) as of June 30, 2025 . Our disclosure controls and procedures are designed to provide reasonable assurance that the information required to be disclosed by us in reports that we file under the Exchange Act is accumulated and communicated to our management, including our Chief Executive Officer and Chief Financial Officer, as appropriate, to allow timely decisions regarding required disclosure and is recorded, processed, summarized and reported within the time periods specified in the rules and forms of the SEC. Based upon this evaluation, our Chief Executive Officer and Chief Financial Officer concluded that our disclosure controls and procedures were not effective at the reasonable assurance level as of June 30, 2025 due to the material weaknesses in our internal control over financial reporting described below. Notwithstanding the identified material weaknesses, management believes and has concluded that the consolidated financial statements included in this Annual Report fairly present, in all material respects, our financial condition, results of operations and cash flows for the periods presented in conformity with U.S. GAAP.
(b) Management’s Annual Report on Internal Control over Financial Reporting
Internal control over financial reporting refers to the process designed by, or under the supervision of, our Chief Executive Officer and Chief Financial Officer, and effected by our, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles, and includes those policies and procedures that:
-
pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of our assets and liabilities;
-
provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that our receipts and expenditures are being made only in accordance with authorizations of our management and directors; and
-
provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets and liabilities that could have a material effect on our consolidated financial statements.
SMCI | 2025 Form 10-K | 119
Our management is responsible for establishing and maintaining adequate internal control over financial reporting (as defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act). Our management, including our Chief Executive Officer and Chief Financial Officer, conducted an evaluation of the effectiveness of our internal control over financial reporting as of June 30, 2025. In making this assessment, our management used the criteria established in Internal Control-Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (“COSO”).
A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected in a timely basis.
We have identified the following unremediated material weaknesses in internal control over financial reporting as of June 30, 2025:
(i) information technology general controls for certain systems that support our financial reporting process were not appropriately identified, designed or implemented; (ii) controls to address segregation of duties conflicts were not properly designed and appropriately implemented; (iii) controls over the completeness and accuracy of information we produce, impacting multiple financial statement areas were not properly implemented or documented; and (iv) we did not design, implement and retain appropriate documentation of control procedures to achieve timely, complete and accurate recording and disclosures across multiple financial statement areas including the timely identification and disclosure of new related party transactions.
The above material weaknesses could have increased the risk of unauthorized access to certain information technology systems that support our financial reporting processes, manipulation of data that we use to produce our financial statements, and/or lack of complete and accurate information, which could lead to financial misstatements and affect our ability to report our information on a timely basis.
Notwithstanding the material weaknesses in internal control over financial reporting described above, management believes and has concluded that the consolidated financial statements included in this Annual Report fairly present, in all material respects, our financial position, results of operations and cash flows for the periods presented in conformity with U.S. GAAP.
(c) Inherent Limitations on Effectiveness of Controls
Because of inherent limitations, internal control over financial reporting may not prevent or detect misstatements and projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
Our independent registered public accounting firm, BDO USA, P.C., has audited our consolidated financial statements as of June 30, 2025, and for the two fiscal years then ended, included in this Annual Report which is contained in Item 8, “Financial Statements and Supplementary Data” and also as part of its audit, has issued an attestation report on our internal control over financial reporting, which is contained below.
SMCI | 2025 Form 10-K | 120
(d) Remediation Plan and Status
We have identified and are implementing actions intended to improve the effectiveness of our internal control over financial reporting and disclosure controls and procedures and will continue to do so until the remediation of the material weaknesses identified above is complete, and we are able to conclude that both our internal control over financial reporting and our disclosure controls and procedures are effective. During the year ended June 30, 2025, we began to implement changes designed to improve our internal controls over financial reporting and to remediate the material weaknesses, including, but not limited to:
- Enhancing our accounting organization’s competencies by adding additional qualified leadership personnel with strong technical accounting, external reporting and governance experience; specifically,
◦identified and hired a Vice President who is qualified to lead our technical accounting, external reporting and global internal controls compliance;
◦reassessed our accounting procedures and related documentation, and, as part of the financial reporting process, began implementing the use of supplementary checklists as well as conducting additional reviews and evaluations of transactions to improve the accuracy and reliability of our financial information.
◦replaced certain existing financial personnel with appropriate qualified personnel to ensure that procedures are implemented, adequate reviews are performed, and financial information as presented is accurate.
◦Promoted our controller to Chief Accounting Officer.
-
In June 2025, we launched a global learning management and communication system, to develop and roll out appropriate compliance and other mandatory training courses, across various areas, including Finance, Compliance, Information Technology and Sales, to our global workforce to ensure that our personnel stay current on a wide variety of areas;
-
Established and implemented a standard policy for manual journal entry creation and posting, including clear documentation criteria, review and approval requirements based on the risk profile of the financial statement line item impacted, with automated workflow mapping that more extensively utilizes the functionality and automation solutions available in our ERP system. This includes more rigorous enforcement of user roles and access controls to ensure oversight and prevent unauthorized entries. We believe these actions have remediated the material weakness we previously identified relating to the review and approval of manual journal entries and the prevention of any unauthorized access to post journal entries;
-
Completed a risk-based review of our overall IT architecture, including the composition of our IT organization and applications, to ensure that all systems that support our financial reporting processes were appropriately identified to be part of the population over which we design and maintain ITGCs. In addition, we also either designed additional controls or have executed on existing controls diligently, including expanding the applications that are included within the scope of our Information Technology General Controls, with an increased emphasis on provisioning, change management and privileged and firefighter access related processes, thereby strengthening the design and implementation and operating effectiveness (for certain applications) of our overall information technology related processes and controls;
-
Re-evaluated and established and/or amended additional key entity level controls covering a wide variety of areas including but not limited to our global SOX program, fraud risk assessment, hiring practices and global corporate trainings to align closely with our overall strategies and the overall COSO framework; and
-
Began implementing a full redesign of our ERP system security role structure and segregation of duties (“SOD”) rulesets. This redesign is foundational to both remediating the SOD-related material weakness and building a sustainable, compliant access model. As part of this reset, we are adopting a leading practice, template driven approach, that will bring standardization to our ruleset and eliminate SOD conflicts and/or mitigate them as appropriate.
Implementing and maintaining an effective financial reporting system is a continuous effort that requires us to anticipate and react to changes in our business and in the economic and regulatory environments, and to expend significant resources to maintain a financial reporting system that is adequate to satisfy our reporting obligations. As we continue to evaluate and take actions to improve our internal control over financial reporting, we may take additional actions to address control deficiencies or modify certain of the remediation measures described above.
While we have made progress to enhance our internal control over financial reporting, we are still in the process of implementing these processes, procedures and controls. We will require additional time to complete implementation and to assess and ensure the long-term sustainability of these procedures. We believe the above actions will be effective in remediating the material weaknesses described above, and we will continue to devote significant time and attention to these remedial efforts. However, the material weaknesses cannot be considered remediated until the applicable remedial controls operate for a sufficient period of time and management has concluded that these controls are operating effectively.
SMCI | 2025 Form 10-K | 121
(e) Changes in Internal Control over Financial Reporting
Except for the changes in the internal controls to remediate a material weakness over the review and approval of manual journal entries and other changes as part of our plans to remediate the above mentioned material weaknesses as discussed above, there was no change in our internal control over financial reporting that occurred during the quarter ended June 30, 2025 that has materially affected, or is reasonably likely to materially affect, our internal control over financial reporting.
However, as noted above, we will be implementing changes to our internal control over financial reporting to address the material weaknesses described above.
SMCI | 2025 Form 10-K | 122
Report of Independent Registered Public Accounting Firm
Stockholders and Board of Directors
Super Micro Computer, Inc.
San Jose, California
Opinion on Internal Control over Financial Reporting
We have audited Super Micro Computer, Inc.’s (the “Company’s”) internal control over financial reporting as of June 30, 2025, based on criteria established in Internal Control – Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (the “COSO criteria”). In our opinion, the Company did not maintain, in all material respects, effective internal control over financial reporting as of June 30, 2025, based on the COSO criteria.
We do not express an opinion or any other form of assurance on management’s statements referring to any corrective actions taken by the Company after the date of management’s assessment.
We also have audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (“PCAOB”), the consolidated balance sheets of the Company as of June 30, 2025 and 2024, the related consolidated statements of operations, comprehensive income, stockholders’ equity, and cash flows for each of the years then ended, and the related notes (collectively referred to as the “consolidated financial statements”) and our report dated August 28, 2025 expressed an unqualified opinion thereon.
Basis for Opinion
The Company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Item 9A, Management’s Annual Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Company’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Company in accordance with U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.
We conducted our audit of internal control over financial reporting in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, and testing and evaluating the design and operating effectiveness of internal control based on the assessed risk. Our audit also included performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.
A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the Company’s annual or interim financial statements will not be prevented or detected on a timely basis. Material weaknesses were identified and described in management’s assessment regarding the following: (1) information technology general controls for certain systems that support the Company's financial reporting process were not appropriately identified, designed or implemented; (2) controls to address segregation of duties conflicts were not properly designed and appropriately implemented; (3) controls over the completeness and accuracy of information produced by the entity impacting multiple financial statement areas were not properly implemented or documented; and (4) management did not design, implement and retain appropriate documentation of control procedures to achieve timely, complete and accurate recording and disclosures across multiple financial statement areas including the timely identification and disclosure of new related party transactions. These material weaknesses were considered in determining the nature, timing, and extent of audit tests applied in our audit of the 2025 consolidated financial statements, and this report does not affect our report dated August 28, 2025 on those consolidated financial statements.
SMCI | 2025 Form 10-K | 123
Definition and Limitations of Internal Control over Financial Reporting
A company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
/s/ BDO USA, P.C.
San Jose, California
August 28, 2025
SMCI | 2025 Form 10-K | 124
Previous: Item 9. Changes in and Disagreements with Accountants on Accounting and Financial Disclosure · Next: Item 9B. Other Information