Item 4. Controls and Procedures
30K characters. Original on sec.gov ·
Item 4. Controls and Procedures
Background
In August 2017, prior to the issuance of the Company’s consolidated financial statements for the fiscal year ended June 30, 2017, the audit committee (the “Audit Committee”) of the Company’s Board of Directors (the “Board”) commenced an investigation (the “Investigation”) into certain accounting and internal control matters at the Company, principally focused on certain revenue recognition matters. The Investigation was conducted with the assistance of outside counsel, which retained forensic accountants to assist them in their work. Following the conclusion of the Investigation, the Audit Committee directed its outside counsel and its forensic accountants to conduct additional procedures on an expanded scope of revenue recognition matters. Concurrently with these additional procedures, new members of the Company’s management, under the direction of the Audit Committee, performed a thorough analysis of the Company’s historical financial statements, accounting policies and financial reporting, as well as the Company’s disclosure controls and procedures and its internal control over financial reporting. During the course of the Investigation, the further procedures by outside counsel and the management analysis (collectively, the “Investigation, Procedures and Analysis”), the Audit Committee and management discovered accounting and financial reporting errors and certain irregularities.
The Audit Committee and management also discovered internal control deficiencies and determined that certain employees had violated the Company’s Code of Business Conduct and Ethics (“Code of Conduct”). In connection with the preparation and filing of this Quarterly Report on Form 10-Q/A, we have conducted the requisite evaluations of the effectiveness of our disclosure controls and procedures and of our internal control over financial reporting both as of March 31, 2017. These conclusions are explained below.
Evaluation of Effectiveness of Disclosure Controls and Procedures
In connection with the May 2017 original filing of our Quarterly Report on Form 10-Q for the quarter ended March 31, 2017, our Chief Executive Officer ("CEO") and former Chief Financial Officer ("CFO") had concluded that, as of March 31, 2017 (the “Evaluation Date”), our disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) under
the Securities Exchange Act of 1934, as amended (“Exchange Act”)) were effective. However, in connection with the Investigation, Procedures and Analysis, an evaluation of the effectiveness of the design and operation of our disclosure controls and procedures was reperformed under the supervision and with the participation of our management, including our current CFO. As a result of this evaluation, our CEO and current CFO concluded that our disclosure controls and procedures were not effective as of the Evaluation Date because of the material weaknesses in internal control.
Notwithstanding the conclusion by our CEO and CFO that our disclosure controls and procedures as of March 31, 2017 were not effective, and notwithstanding the material weaknesses in our internal control over financial reporting we have identified, management believes that the condensed consolidated financial statements and related financial information included in this Quarterly Report on Form 10-Q/A fairly present in all material respects our financial condition, results of operations and cash flows as of the dates presented, and for the periods ended on such dates, in conformity with accounting principles generally accepted in the United States (“U.S. GAAP”).
Internal Control Over Financial Reporting
Management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Exchange Act Rules 13a-15(f) and 15d-15(f).
Internal control over financial reporting is a process designed by, or under the supervision of, our CEO and CFO to provide reasonable assurance regarding the reliability of financial reporting and the preparation of our consolidated financial statements for external purposes in accordance with U.S. GAAP. Management’s internal control over financial reporting includes those policies and procedures that (i) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of our assets, (ii) provide reasonable assurance that transactions are appropriately recorded to permit preparation of financial statements in accordance with U.S. GAAP and that our receipts and expenditures are made only in accordance with authorizations of management, acting under authority delegated to them by the Board, and (iii) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on our financial statements.
A material weakness in internal controls is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis. Because of its inherent limitations, even appropriate internal control over financial reporting may not prevent or detect misstatements.
In connection with management’s assessment of the Company’s internal control over financial reporting described above, management has identified the deficiencies described below that constituted material weaknesses in our internal control over financial reporting as of March 31, 2017. These deficiencies led to material errors in our previously issued financial statements, which in turn led to the restatement of those previously issued condensed consolidated financial statements, as described in Note 12 to our condensed consolidated financial statements included in this Quarterly Report on Form 10-Q/A.
Control Environment
We have identified deficiencies in the control environment component of the COSO Framework that constitute material weaknesses, either individually or in the aggregate. These deficiencies related to all the principles associated with the control environment component of the COSO Framework. Contributing factors include:
| • | We had a culture of aggressively focusing on quarterly revenue without sufficient focus on compliance. Senior management did not establish and promote a control environment with an appropriate tone of compliance and control consciousness throughout the entire Company. The Company did not sufficiently promote, monitor or enforce adherence to the Code of Conduct. In the pursuit of quarterly revenue, certain of our sales, finance and operations personnel, including officers and managers, were aware of, condoned or were involved in actions that reflected an inappropriate tone at the top, that violated our Code of Conduct and our accounting policies and procedures, and that were inconsistent with a commitment to integrity and ethical values. These actions included (i) shipping products in advance of customer requested delivery dates, (ii) shipping products to storage facilities at the end of a quarter for later delivery to customers, (iii) in certain cases entering into side agreements with customers, (iv) in certain cases, shipping products before manufacturing was completed, (v) altering source documents related to some sales transactions and (vi) failing to disclose or obscuring material facts about sales transactions. As a result of those actions, we recognized revenue from numerous sales transactions in the incorrect period, although these valid sales transactions were recognized in one or more subsequent quarters in the aforementioned restatement. Some employees, including officers and managers, also failed to raise issues with material accounting consequences to the Audit Committee and our external auditors, and with respect to one transaction, appear to have attempted to minimize material facts about a sales transaction to, or obscure those facts from, the Audit Committee and our external auditors. Finally, we did not, on a consistent basis, (i) timely and thoroughly detect and address failures to comply with the Code of Conduct and (ii) train employees adequately to identify and report issues to management and the Audit Committee. |
| • | The Company did not maintain a sufficient complement of management, accounting, financial reporting, sales, operations, engineering and information technology personnel who had appropriate levels of knowledge, experience, and training in accounting and internal control matters commensurate with the nature, growth and complexity of our business. The lack of sufficient appropriately skilled and trained personnel contributed to our failure to (i) adequately identify potential risks, (ii) include in the scope of our internal controls framework certain systems relevant to financial reporting and the preparation of our consolidated financial statements, (iii) design and implement certain risk-mitigating internal controls and (iv) consistently operate certain of our internal controls. The lack of sufficient appropriately skilled and trained personnel also contributed to deficiencies in establishing and maintaining policies and procedures, establishing and enforcing standards for maintaining documents for revenue recognition purposes and establishing accountability for internal controls across the entire Company. |
Due to the interdependencies between the COSO Framework components, the weaknesses in our control environment contributed to other material weaknesses within our system of internal control over financial reporting.
Risk Assessment
We have identified deficiencies in the risk assessment component of the COSO Framework that aggregate to a material weakness. These deficiencies related to the principles associated with the risk assessment component of the COSO Framework, specifically principles within the component related to: (i) identifying, assessing, and communicating appropriate control objectives, (ii) identifying and analyzing risks to achieve these objectives, (iii) contemplating fraud risks, and (iv) identifying and assessing changes in the business that could impact our system of internal controls.
Control Activities
We have identified deficiencies in the control activities component of the COSO Framework that aggregate to a material weakness. These deficiencies related to principles associated with the control activities component of the COSO Framework, specifically principles within the component related to (i) selecting and developing control activities that mitigate risks (ii) selecting and developing general controls over technology and (iii) deploying control activities through policies that establish what is expected and procedures that put policies into action. We did not design or operate certain control activities to sufficiently respond to potential risks of material misstatement in the area of revenue recognition. We did not effectively select and develop certain information technology (“IT”) general controls and we also had control deficiencies at both the IT administrator and end-user levels across multiple applications relevant to financial reporting. We also had deficiencies related to segregation of duties. Deficiencies in control activities contributed to material accounting errors, and the potential for there to have been material accounting errors, in substantially all financial statements account balances and disclosures.
Information and Communication
We have identified deficiencies in the information and communication component of the COSO Framework that aggregate to a material weakness. These deficiencies related to principles associated with the information and communications component of the COSO Framework, specifically principles within the component related to (i) generating and using relevant quality information, (ii) internally communicating information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control and (iii) communicating with external parties regarding matters affecting the functioning of internal control. We rely on manual business processes to compensate for a lack of extensive integration in our information systems. We also rely heavily on each of our various functions, such as sales, operations, accounting, legal and management, to communicate to the other functions information that the entire organization needs to operate an effective internal control environment. In certain areas, our control activity deficiencies resulted from insufficient communication of information among our internal functions as well as from officers and managers to both the Audit Committee and our external auditors.
Monitoring of Controls
We have identified deficiencies in the monitoring of controls component of the COSO Framework that aggregate to a material weakness. There were deficiencies related to principles associated with the monitoring of controls component of the COSO Framework, specifically principles within the component related to (i) selecting, developing and performing ongoing and/or separate evaluations and (ii) evaluating and communicating deficiencies in a timely manner. We lacked controls (i) to determine whether components of internal control were present and functioning, (ii) to mitigate the risk of management overriding internal controls and (iii) to detect incorrect accounting practices. Consequently, we did not identify internal control deficiencies, or did not raise such deficiencies in a timely manner to those parties responsible for internal controls. In addition, we did not always ensure that these deficiencies were remediated thoroughly and timely.
The material weaknesses noted above contributed to the following additional material weaknesses:
Revenue Recognition Accounting
We have identified deficiencies in revenue recognition accounting controls that resulted in material errors constituting material weaknesses, either individually or in the aggregate, as we did not appropriately design, or effectively operate, internal controls over certain aspects of accurate recording, presentation, and disclosure of revenue and related costs. The following were contributing factors to the material weaknesses in revenue recognition accounting:
| • | The Company’s internal controls did not consistently identify and properly account for key non-standard contract or arrangement terms for sales transactions that involved multiple elements (such as when the price of a system includes an extended warranty period and/or our agreement to provide services to our customer). Specifically, the Company’s internal controls failed to identify, accumulate and assess the accounting impact of situations in which we recognized revenue before all the elements necessary to establish “delivery” had occurred. |
| • | With respect to sales transactions near quarter-end, our internal controls failed to consistently identify transactions where the terms of the sales arrangements with our customers were not properly documented in a form that fully reflected the final understanding between the parties as to the specific nature and terms of the agreed-upon transaction. |
| • | Our internal controls failed to consistently identify, resolve, document in our accounting system and allow for proper accounting where there were inconsistencies among the various documents underlying our sales transactions, and we did not always communicate the existence or resolution of those inconsistencies to our accounting organization to enable the proper recognition of revenue. |
| • | We lacked a control to ensure a consistent approach for reviewing our pricing and establishing supportable estimates of best estimated selling prices in allocating revenue between multiple elements. Consequently, we did not always correctly calculate the portions of the total revenue recognized from sales transactions allocated among the various elements. |
Information Technology General Controls
We have identified deficiencies related to IT general controls that represent a material weakness, either individually or in the aggregate. The following were contributing factors:
| • | We have a decentralized approach to developing IT policies and practices and to monitoring our IT controls. As a result, our internal procedures for granting and monitoring employee access, and managing changes to various applications and infrastructure layers relevant to our financial reporting are not consistent across those applications and infrastructure layers. In addition, some of our internally-developed applications relevant to financial reporting lack logging capabilities to monitor access changes or application changes. We have also authorized certain users with broad access, both as a user and as an administrator, to all parts of our primary accounting system without adequate monitoring or recording of how they used that access. As a result of these factors, we have material weaknesses related to access controls and change management. The fact that we had material weaknesses related to access controls and change management means that it is possible that our business process controls that depend on the affected information systems, or that depend on data or financial reports generated from affected information systems, could be adversely affected due to the access control and change management issues, although we have identified no instances of any adverse effect due to these deficiencies. |
Remediation Plan and Status
Our management is committed to remediating identified control deficiencies (including both those that rise to the level of a material weakness and those that do not), fostering continuous improvement in our internal controls and enhancing our overall internal controls environment. Our management believes that these remediation actions, along with additional actions, when fully implemented, will remediate the material weaknesses we have identified and strengthen our internal control over financial reporting. We are committed to improving our internal control processes and intend to continue to review and improve our financial reporting controls and procedures. As we continue to evaluate and work to improve our internal control over financial reporting, we may take additional measures to address control deficiencies with the overall objective to design and operate internal controls that mitigate identified risks and enable an effective system of internal control over external financial reporting.
To date, we have taken the following remediation actions:
| • | Restructured our sales organization, which resulted in the resignations of the Senior Vice President of International Sales, the Senior Vice President of Worldwide Sales, the Vice President, Strategic Accounts, the Vice President, Strategic Sales, the Vice President, Business Development and certain other sales personnel. |
| • | Appointed experienced professionals to key accounting and finance and compliance leadership positions, including the appointments of a new Chief Financial Officer and a new Corporate Controller in January 2018, and the creation of, and appointments to, two newly established roles of Chief Compliance Officer and Vice President of Internal Audit in May 2018 and August 2018, respectively. |
| • | Reviewed and amended our Code of Conduct to align with the organizational changes described above and to strengthen certain provisions regarding compliance and reporting. |
| • | Adopted an Internal Audit Charter setting forth the responsibilities of the internal audit function and establishing that the Vice President of Internal Audit reports directly to the Audit Committee and that the Audit Committee has authority to provide adequate funding for this function. |
| • | Changed our organizational structure to narrow the scope of responsibilities of certain of our senior executives and to revise various reporting relationships, which included the appointment of a new Senior Vice President of Worldwide Sales, and a new Senior Vice President of Operations. |
| • | Conducted training in the following areas: |
| − | Revenue recognition training for our global sales force, various operations personnel, and certain senior executives, including our CEO, which included detailed examples of acceptable and unacceptable sales practices, |
| − | Reviewing with our senior management team our amended Code of Conduct, |
− Reviewing with our CEO enhanced processes for periodic evaluations by the CEO and the CFO of the effectiveness of our disclosure controls and procedures, and the periodic assessments by the CEO and the CFO of the effectiveness of our internal control over financial reporting, and other compliance matters, and
− Shipping and cut-off training for accounting and operations personnel that included new requirements for quarter-end procedures.
| • | Upgraded our accounting department to include the new roles of Senior Director of Tax, Financial Audit Director and Information Technology Audit Director, as well as replaced certain of our accounting personnel with more experienced individuals, including rebuilding and expanding our revenue recognition team. |
| • | Enhanced the sales sub-certification document that supports our CEO’s and CFO’s financial statement certifications and expanded the sub-certification participation population to the global sales force. |
Our management believes that meaningful progress has been made on the remaining remediation efforts. Although timetables vary, management regards successful completion of our remaining remediation actions as an important priority. Some of the more significant remaining remediation activities include:
| • | Developing and implementing an ongoing compliance training program regarding significant accounting and financial reporting matters, as well as broad compliance matters, for accounting, financial reporting, sales and operations personnel, as well as for our CEO, our other corporate executives and the Board. |
| • | Integrating the responsibility for internal controls across business functions to ensure accountability for internal controls beyond the accounting and finance team. |
| • | Continuing to assess current staffing levels and competencies to ensure the optimal complement of personnel with appropriate qualifications and skill sets. |
| • | Reevaluating and revising our Sarbanes-Oxley compliance program (our “SOX Program”), and making improvements to our SOX Program governance, risk assessment processes, testing methodologies and corrective action mechanisms. |
| • | Redesigning and implementing necessary changes to the existing system of internal controls in the context of the revised and more comprehensive risk assessment. |
| • | Assigning accountability for certain internal controls to our Compliance Department, such as our organizational-wide quarterly sales certification process. |
| • | Reevaluating the boundary applications that interface with our primary accounting and reporting application and redesigning logical access and program change controls to enhance the reliability of information used to conduct other internal controls. |
| • | Continuing to re-assess risks and controls related to the accurate recording, presentation, and disclosure of revenue and related costs |
Changes in Internal Control over Financial Reporting
There were no changes in our internal control over financial reporting identified in connection with the evaluation required by Rule 13a-15(d) and 15d-15(d) of the Exchange Act that occurred during the three months ended March 31, 2017 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
Inherent Limitations on Effectiveness of Controls
Management, including our Chief Executive Officer, does not expect that our disclosure controls and procedures or our internal control over financial reporting will prevent all errors and all fraud. A control system, no matter how well conceived and operated, can provide only reasonable, not absolute, assurance that the objectives of the control system are met. Further, the design of a control system must reflect the fact that there are resource constraints, and the benefits of controls must be considered relative to their costs. Because of the inherent limitations in all control systems, no evaluation of controls can provide absolute assurance that all control issues, misstatements, errors, and instances of fraud, if any, within our organization have been or will be prevented or detected. These inherent limitations include the realities that judgments in decision-making can be faulty and that breakdowns can occur because of simple error or mistake. Controls also can be circumvented by the individual acts of some persons, by collusion of two or more people, or by management override of the controls. The design of any system of controls is based in part on certain assumptions about the likelihood of future events, and there can be no assurance that any design will succeed in achieving its stated goals under all potential future conditions. Projections of any evaluation of controls effectiveness to future periods are subject to risks. Over time, internal controls may become inadequate as a result of changes in conditions, or through the deterioration of the degree of compliance with policies or procedures.
PART II: OTHER INFORMATION
Item 1. Legal Proceedings
From time to time, we have been involved in various legal proceedings arising from the normal course of business activities.
On September 4, 2015, a complaint was filed against us, our Chief Executive Officer, and our former Chief Financial Officer in the U.S. District Court for the Northern District of California (Deason v. Super Micro Computer, Inc., et al., No. 15-cv-04049). The complaint claimed that the defendants violated Section 10(b) of the Securities Exchange Act of 1934 because of alleged misrepresentations and/or omissions in public statements which supposedly were revealed when we announced on August 31, 2015 that the filing of our Annual Report on Form 10-K for fiscal 2015 would be delayed to allow us to complete an investigation into certain marketing expenses. On January 12, 2018, after an initial round of successful motion to dismiss briefing leading to Plaintiff filing an amended complaint, we and the named individual defendants filed another motion to dismiss on the grounds that the amended complaint failed to state a claim because it did not plead falsity or scienter. On June 27, 2018, the Court granted our motion to dismiss without leave to amend and entered judgment in favor of us and the other
defendants. On July 24, 2018, Plaintiff filed a notice of appeal to the 9th Circuit Court of Appeals; however, Plaintiff subsequently filed a voluntary notice dismissing the appeal and, thus, ending the litigation on November 1, 2018.
On February 8, 2018, two putative class action complaints were filed against us, our Chief Executive Officer and our former Chief Financial Officer in the U.S. District Court for the Northern District of California (Hessefort v. Super Micro Computer, Inc., et al., No. 18-cv-00838 and United Union of Roofers v. Super Micro Computer, Inc., et al., No. 18-cv-00850). The complaints contain similar allegations, claiming that the defendants violated Section 10(b) of the Securities Exchange Act due to alleged misrepresentations and/or omissions in public statements regarding recognition of revenue. The court subsequently appointed New York Hotel Trades Council & Hotel Association of New York City, Inc. Pension Fund as lead plaintiff and it filed an amended complaint naming our Senior Vice President of Investor Relations, as an additional defendant. The court approved the parties’ agreement to permit a further amendment of the complaint, which was filed on January 22, 2019. We believe the allegations filed are without merit, and intend to vigorously defend against the lawsuit.
Between late 2015 and 2017, we cooperated with the SEC in its investigation of marketing expenses that contained certain irregularities discovered by our management, which irregularities were disclosed on August 31, 2015. In addition, we have received subpoenas from the SEC in connection with the matters underlying our inability to timely file our Form 10-K for the fiscal year ending June 30, 2017. We also received a subpoena from the SEC following the false and widely-discredited reporting in October 2018 by Bloomberg Businessweek concerning our products. We are cooperating fully to comply with these government requests.
Due to the inherent uncertainties of legal proceedings, we cannot predict the outcome of these proceedings at this time, and we can give no assurance that they will not have a material adverse effect on our financial position or results of operations.
Previous: Item 3. Quantitative and Qualitative Disclosure About Market Risk · Next: Item 1A. Risk Factors