A Dark Vector Cognition product

Item 4. Controls and Procedures

7K characters. Original on sec.gov · Markdown

Item 4. Controls and Procedures

Smurfit Westrock’s management evaluated the effectiveness of the design and operation of its disclosure controls and procedures (as

such term is defined in Rules 13a-15(e) and 15d-15(e) under the Exchange Act) as of the end of the period covered by this Quarterly

Report on Form 10-Q. Disclosure controls and procedures include, without limitation, controls and procedures designed to ensure that

information required to be disclosed by the Company in the reports that it files or submits under the Exchange Act is accumulated and

communicated to the Company’s management, including its principal executive and principal financial officers, or persons performing

similar functions, as appropriate to allow timely decisions regarding required disclosure. Disclosure controls and procedures are

designed by the Company to ensure that it records, processes, summarizes and reports in a timely manner the information it must

disclose in reports that it files with or submits to the SEC. Anthony Smurfit, President & Group Chief Executive Officer, and Ken

Bowles, Executive Vice President & Group Chief Financial Officer, reviewed and participated in management’s evaluation of the

disclosure controls and procedures.

Based on this evaluation, Anthony Smurfit, President & Group Chief Executive Officer, and Ken Bowles, Executive Vice President &

Group Chief Financial Officer concluded that as of the end of the period covered by this Quarterly Report on Form 10-Q, Smurfit

Westrock’s disclosure controls and procedures were not effective as a result of the material weakness in our internal control over

financial reporting described below.

Previously Reported Material Weakness in Internal Control over Financial Reporting

A material weakness is a control deficiency, or combination of deficiencies, in internal control over financial reporting such that there

is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a

timely basis.

As discussed elsewhere in this Quarterly Report on Form 10-Q, on July 5, 2024, we completed the Combination between Smurfit

Kappa and WestRock. Prior to the Combination, Smurfit Kappa, as a public limited company incorporated in Ireland and listed on the

London Stock Exchange and on the Euronext Dublin Market, was not subject to Section 404 of the Sarbanes Oxley Act of 2002

(“SOX”), while WestRock, as a U.S. publicly traded company incorporated in Delaware and listed on the New York Stock Exchange,

was subject to Section 404 of SOX. Upon the completion of the Combination, Smurfit Kappa and WestRock became wholly-owned

subsidiaries of Smurfit Westrock.

As a result of the Combination, Smurfit Westrock’s management is in the process of integrating Smurfit Kappa and WestRock’s

legacy internal control frameworks. In connection with Smurfit Westrock’s assessment of its internal control over financial reporting

for the purposes of complying with Section 302 of SOX, we previously identified and reported a material weakness relating to the

company’s selection and development of control activities intended to mitigate the risks to achieving its objectives. This relates to

certain processes and controls principally at historical Smurfit Kappa that were not subject to the requirements of Section 404 of SOX

prior to the Combination.

This material weakness resulted in:

  • A lack of formalization of an existing control process for documenting evidence of management review and performance of

control procedures, including the level of precision in the execution of controls and procedures to ascertain completeness and

accuracy of information produced by the Company.

  • Existing controls related to the preparation and review of manual journal entries not designed to adequately mitigate the

associated risks.

  • The need to augment General IT Controls, specifically as they pertain to (i) logical access controls to ensure appropriate

segregation of duties and that adequately restrict user and privileged access to financial applications, programs, and data to

appropriate Company personnel and (ii) program change management controls to ensure that information technology

program and data changes affecting financial IT applications and underlying accounting records are identified, tested,

authorized and implemented appropriately.

Notwithstanding the identified material weakness, management believes that the Condensed Consolidated Financial Statements and

related financial information included in this Quarterly Report on Form 10-Q fairly present, in all material respects, our financial

position, results of operations and cash flows as of and for the periods presented.

Remediation Plan

The process of designing, implementing and testing remediation measures is underway in respect of this material weakness and to

improve our internal control over financial reporting. These remediation measures include a number of ongoing actions which have

been prioritized in a material weakness remediation strategy that aligns to the most impactful controls:

  • designing and implementing policies and guidance related to the operation of controls – this has been largely implemented

with testing planned and ongoing to validate the operating effectiveness;

  • developing appropriate controls over the review of manual journal entries – automated approval workflows for manual

journal entries have now been implemented at relevant material locations, as has an additional risk-based interim manual

control. Testing to validate the effectiveness of these controls is planned and ongoing; and

  • enhancing and expanding across the organization the general IT processes and controls – this has been largely implemented

with testing planned and ongoing to validate the operating effectiveness.

In addition, control operators continue to participate in SOX training and live support sessions, with a specific focus on the priority

areas documented in the material weakness remediation strategy.

The implementation of our remediation measures is underway, and requires validation and testing of the design and operating

effectiveness of internal controls over a sustained period. Until testing is completed, we cannot ensure that the measures taken by us to

date, and actions that we may take in the future, will be sufficient to remediate these deficiencies or that they will prevent or avoid

potential future deficiencies.

Changes in Internal Control over Financial Reporting

Other than the changes that may continue to result from the integration following the Combination and remediation actions described

above, there has been no change in Smurfit Westrock’s internal control over financial reporting (as such term is defined in Rules

13a-15(f) and 15d-15(f) under the Exchange Act) during the three months ended September 30, 2025 that has materially affected, or is

reasonably likely to materially affect, Smurfit Westrock’s internal control over financial reporting.

PART II - OTHER INFORMATION

Item 1. Legal Proceedings

The information called for by this item is incorporated herein by reference to “Note 16. Commitments and Contingencies” of the

Condensed Consolidated Financial Statements (included in Part I, Item 1).

Previous: Item 3. Quantitative and Qualitative Disclosures About Market Risk · Next: Item 1A. Risk Factors