Item 4. Controls and Procedures
7K characters. Original on sec.gov · Markdown
Item 4. Controls and Procedures
Smurfit Westrock’s management evaluated the effectiveness of the design and operation of its disclosure controls and procedures (as
such term is defined in Rules 13a-15(e) and 15d-15(e) under the Exchange Act) as of the end of the period covered by this Quarterly
Report on Form 10-Q. Disclosure controls and procedures include, without limitation, controls and procedures designed to ensure that
information required to be disclosed by the Company in the reports that it files or submits under the Exchange Act is accumulated and
communicated to the Company’s management, including its principal executive and principal financial officers, or persons performing
similar functions, as appropriate to allow timely decisions regarding required disclosure. Disclosure controls and procedures are
designed by the Company to ensure that it records, processes, summarizes and reports in a timely manner the information it must
disclose in reports that it files with or submits to the SEC. Anthony Smurfit, President & Group Chief Executive Officer, and Ken
Bowles, Executive Vice President & Group Chief Financial Officer, reviewed and participated in management’s evaluation of the
disclosure controls and procedures.
Based on this evaluation, Anthony Smurfit, President & Group Chief Executive Officer, and Ken Bowles, Executive Vice President &
Group Chief Financial Officer concluded that as of the end of the period covered by this Quarterly Report on Form 10-Q, Smurfit
Westrock’s disclosure controls and procedures were not effective as a result of the material weakness in our internal control over
financial reporting described below.
Previously Reported Material Weakness in Internal Control over Financial Reporting
A material weakness is a control deficiency, or combination of deficiencies, in internal control over financial reporting such that there
is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a
timely basis.
As discussed elsewhere in this Quarterly Report on Form 10-Q, on July 5, 2024, we completed the Combination between Smurfit
Kappa and WestRock. Prior to the Combination, Smurfit Kappa, as a public limited company incorporated in Ireland and listed on the
London Stock Exchange and on the Euronext Dublin Market, was not subject to Section 404 of the Sarbanes Oxley Act of 2002
(“SOX”), while WestRock, as a U.S. publicly traded company incorporated in Delaware and listed on the New York Stock Exchange,
was subject to Section 404 of SOX. Upon the completion of the Combination, Smurfit Kappa and WestRock became wholly-owned
subsidiaries of Smurfit Westrock.
As a result of the Combination, Smurfit Westrock’s management is in the process of integrating Smurfit Kappa and WestRock’s
legacy internal control frameworks. In connection with Smurfit Westrock’s assessment of its internal control over financial reporting
for the purposes of complying with Section 302 of SOX, we previously identified and reported a material weakness relating to the
company’s selection and development of control activities intended to mitigate the risks to achieving its objectives. This relates to
certain processes and controls principally at historical Smurfit Kappa that were not subject to the requirements of Section 404 of SOX
prior to the Combination.
This material weakness resulted in:
- A lack of formalization of an existing control process for documenting evidence of management review and performance of
control procedures, including the level of precision in the execution of controls and procedures to ascertain completeness and
accuracy of information produced by the Company.
- Existing controls related to the preparation and review of manual journal entries not designed to adequately mitigate the
associated risks.
- The need to augment General IT Controls, specifically as they pertain to (i) logical access controls to ensure appropriate
segregation of duties and that adequately restrict user and privileged access to financial applications, programs, and data to
appropriate Company personnel and (ii) program change management controls to ensure that information technology
program and data changes affecting financial IT applications and underlying accounting records are identified, tested,
authorized and implemented appropriately.
Notwithstanding the identified material weakness, management believes that the Condensed Consolidated Financial Statements and
related financial information included in this Quarterly Report on Form 10-Q fairly present, in all material respects, our financial
position, results of operations and cash flows as of and for the periods presented.
Remediation Plan
The process of designing, implementing and testing remediation measures is underway in respect of this material weakness and to
improve our internal control over financial reporting. These remediation measures include a number of ongoing actions which have
been prioritized in a material weakness remediation strategy that aligns to the most impactful controls:
- designing and implementing policies and guidance related to the operation of controls – this has been largely implemented
with testing planned and ongoing to validate the operating effectiveness;
- developing appropriate controls over the review of manual journal entries – automated approval workflows for manual
journal entries have now been implemented at relevant material locations, as has an additional risk-based interim manual
control. Testing to validate the effectiveness of these controls is planned and ongoing; and
- enhancing and expanding across the organization the general IT processes and controls – this has been largely implemented
with testing planned and ongoing to validate the operating effectiveness.
In addition, control operators continue to participate in SOX training and live support sessions, with a specific focus on the priority
areas documented in the material weakness remediation strategy.
The implementation of our remediation measures is underway, and requires validation and testing of the design and operating
effectiveness of internal controls over a sustained period. Until testing is completed, we cannot ensure that the measures taken by us to
date, and actions that we may take in the future, will be sufficient to remediate these deficiencies or that they will prevent or avoid
potential future deficiencies.
Changes in Internal Control over Financial Reporting
Other than the changes that may continue to result from the integration following the Combination and remediation actions described
above, there has been no change in Smurfit Westrock’s internal control over financial reporting (as such term is defined in Rules
13a-15(f) and 15d-15(f) under the Exchange Act) during the three months ended September 30, 2025 that has materially affected, or is
reasonably likely to materially affect, Smurfit Westrock’s internal control over financial reporting.
PART II - OTHER INFORMATION
Item 1. Legal Proceedings
The information called for by this item is incorporated herein by reference to “Note 16. Commitments and Contingencies” of the
Condensed Consolidated Financial Statements (included in Part I, Item 1).
Previous: Item 3. Quantitative and Qualitative Disclosures About Market Risk · Next: Item 1A. Risk Factors