Item 1A. Risk Factors
ITEM 1A. RISK FACTORS
There have been no material changes from the risk factors disclosed in Item 1A of our Annual Report on Form 10–K for the year ended August 31, 2020, except for the risk factor set forth below, which updates the risk factor with the same title included in such Annual Report on Form 10–K.
We utilize information technology systems to support our business. The ongoing multiyear implementation of an enterprise wide resource planning system, reliance upon multiple legacy business systems, security breaches or other disruptions to our information technology systems or assets could interfere with our operations, compromise security of our customers' or suppliers' information and expose us to liability that could adversely impact our business and reputation.
Our operations rely on certain key information technology ("IT") systems, many of which are legacy in nature or may depend on third–party services to provide critical connections of data, information and services for internal and external users.
Over the past several years, we have been implementing a new enterprise resource planning system ("ERP"), and we expect this ERP implementation to continue for the next several years. This ERP implementation has and will continue to require significant capital and human resources to deploy. Changes we have experienced in the implementation timeline and the scope of the implementation likely have impacted the capital and operating expense amounts required to complete the implementation and there can be no assurance that the actual costs for completing the ERP implementation will not exceed our current estimates or that the ERP will not take longer to implement than we currently expect. In addition, potential flaws in implementing the ERP or in the failure of any portion/module of the ERP to meet our needs or provide appropriate controls may pose risks to our ability to operate successfully and efficiently and with an effective system of internal controls.
There may be other challenges and risks to both our aging and current IT systems over time due to any number of causes, such as catastrophic events, availability of resources, power outages, security breaches or cyber–based attacks. These challenges and risks could result in legal claims or proceedings, liability or penalties, disruption in operations, loss of valuable data, increased costs and damage to our reputation, all of which could adversely affect our business. Our ongoing IT investments include those relating to cybersecurity, including technology, hired expertise and cybersecurity risk mitigation actions. However, in connection with the COVID-19 pandemic, a number of our employees have transitioned to working remotely. As a result, more of our employees are working from locations where our cybersecurity programs may be less effective and robust.
Like many companies, we continue to experience an increase in the number of sophisticated attempts by external parties to access and/or disrupt our networks without authorization. For example, we recently learned of a credible cybersecurity threat to our IT systems. Upon learning of the cybersecurity threat, we launched an investigation and undertook immediate action, including employing protocols to mitigate the impact of the threat, and engaging internal and third–party information technology security and forensics experts to assess any impact on our IT systems. We also utilized additional
54
Table of Contents
security measures to help safeguard the integrity of our IT systems’ infrastructure and the data contained therein. Although our systems were not breached, no data was lost or exposed, and our operations were not significantly interrupted from this incident, there is no guarantee that a future incident would not have a greater impact on our operations, our data or our reputation.
In addition, we are subject to laws and regulations in the United States and other jurisdictions regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer and security of personal data. These laws and regulations pose increasingly complex compliance challenges and will require us to incur costs to achieve and maintain compliance; some of those costs may be significant. Any violation of such laws and regulations, including as a result of a security or privacy breach, could subject us to legal claims, regulatory penalties and damage to our reputation.
ITEM 6. EXHIBITS
Exhibit Description
31.1
Certification of the Chief Executive Officer Pursuant to Section 302 of the Sarbanes-Oxley Act of 2002.
31.2
Certification of the Chief Financial Officer Pursuant to Section 302 of the Sarbanes-Oxley Act of 2002.
32.1
Certification of the Chief Executive Officer Pursuant to 18 U.S.C. Section 1350, as Adopted Pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
32.2
Certification of the Chief Financial Officer Pursuant to 18 U.S.C. Section 1350, as Adopted Pursuant to Section 906 of the Sarbanes-Oxley Act of 2002.
101.INS XBRL Instance Document (the instance document does not appear in the Interactive Data File because its XBRL tags are embedded within the Inline XBRL document).
101.SCH XBRL Taxonomy Extension Schema Document.
101.CAL XBRL Taxonomy Extension Calculation Linkbase Document.
101.DEF XBRL Taxonomy Extension Definition Linkbase Document.
101.LAB XBRL Taxonomy Extension Labels Linkbase Document.
101.PRE XBRL Taxonomy Extension Presentation Linkbase Document.
104 Cover Page Interactive Data File (Formatted as Inline XBRL and contained in Exhibit 101).
55
Table of Contents
SIGNATURES
Pursuant to the requirements of the Securities Exchange Act of 1934, as amended, the registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized.
CHS Inc.
(Registrant)
Date: July 8, 2021 By: /s/ Olivia Nelligan
Olivia Nelligan
Executive Vice President and Chief Financial Officer
56
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.