Item 4. Controls and Procedures
ITEM 4. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
We maintain disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) of the Securities Exchange Act of 1934, as amended (the "Exchange Act")) that are designed to be effective in providing reasonable assurance that information required to be disclosed in our reports under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in the rules and forms of the SEC, and that such information is accumulated and communicated to our management to allow timely decisions regarding required disclosure.
Management does not expect that our disclosure controls and procedures or our internal control over financial reporting will prevent all errors and all fraud. A control system, no matter how well conceived and operated, can provide only reasonable, not absolute, assurance that the objectives of the control system are met. Further, the design of a control system must reflect the fact that there are resource constraints, and the benefits of controls must be considered relative to their costs. Because of the inherent limitations in all control systems, including the possibility of human error, the circumvention or overriding of controls, or fraud, no evaluation of controls can provide absolute assurance that all control issues, misstatements, errors, and instances of fraud, if any, within our organization have been or will be prevented or detected.
As of the period covered by this Quarterly Report on Form 10-Q, an evaluation was conducted under the supervision and with the participation of our management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) and Rule 15d-15(e) of the Exchange Act). Our management concluded that as of June 30, 2023, our disclosure controls and procedures were not effective because of the material weaknesses in our internal control over financial reporting identified by management as of December 31, 2021 (described below). A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that a reasonable possibility exists that a material misstatement of our annual or interim financial statements would not be prevented or detected on a timely basis.
Material Weaknesses in Control Activities
Evaluation of Disclosure Controls and Procedures
Disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) of the Exchange Act are controls and other procedures designed to ensure that information required to be disclosed in our reports under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in the rules and forms of the SEC, and that such information is accumulated and communicated to our management to allow timely decisions regarding required disclosure.
As of December 31, 2022, an evaluation was conducted under the supervision and with the participation of our management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) and Rule 15d-15(e) of the Exchange Act). Our management concluded that as of
29
June 30, 2023, our disclosure controls and procedures were not effective because of the material weaknesses in our internal control over financial reporting described below.
Management’s Report on Internal Control Over Financial Reporting
The Company’s management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act. The Company’s internal control over financial reporting is a process designed by or under the supervision of the Company’s Chief Executive Officer and Chief Financial Officer, and overseen by the Board of Directors, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with GAAP and includes policies and procedures that:
• Pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the Company’s assets;
• Provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with GAAP, and that the Company’s receipts and expenditures are being made only in accordance with the authorization of its management and directors; and
• Provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the Company’s assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting is not intended to provide absolute assurance that a misstatement of the Company’s consolidated financial statements would be prevented or detected. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.
Management conducted an evaluation of the effectiveness of the Company’s internal control over financial reporting using the criteria in Internal Control - Integrated Framework 2013 issued by the Committee of Sponsoring Organizations of the Treadway Commission (the “COSO Framework”). As a result of this evaluation, management concluded that the Company’s internal control over financial reporting was not effective as of June 30, 2023 because of the material weaknesses in internal control over financial reporting discussed below.
• Control Environment: The Company did not maintain an effective control environment based on the criteria established in the COSO framework, which resulted in deficiencies in principles associated with the control environment.
In addition, the following material weaknesses were previously identified and contributed to the material weakness in the control environment:
• Insufficient resources within the accounting and financial reporting department to review the accounting of complex financial reporting transactions including areas such as business combinations, share based compensation and the related income tax reporting
• Ineffective controls over updating and distributing accounting policies and procedures across the organization.
The control environment material weaknesses contributed to other material weaknesses within our system of internal controls over financial reporting related to the following COSO components:
• Risk Assessment: The Company did not design and implement an effective risk assessment based on the criteria established in the COSO framework and identified deficiencies in the principles associated with the risk assessment component of the COSO framework.
• Information and Communication: The Company did not have an effective information and communication process that identified and assessed the source of and controls necessary to ensure the reliability of information used in financial reporting and that communicates relevant information about roles and responsibilities for internal control over financial reporting.
• Monitoring Activities: The Company did not have effective monitoring activities to assess the operation of internal control over financial reporting, including the continued appropriateness of control design and level of documentation maintained to support control effectiveness.
30
• Control Activities: As a consequence of the material weaknesses described above, internal control deficiencies related to the design and operation of process-level controls and general information technology controls were determined to be pervasive throughout the Company’s financial reporting processes.
In addition, the following material weaknesses were previously identified and contributed to the material weakness in control activities:
• Inadequate information and technology general controls, including segregation of duties, change management, and user access, which were inadequate to support financial reporting applications and support automated controls and functionality.
• Inadequate controls over physical inventory counts.
• Inadequate controls over valuations, inclusive of appropriate valuation model inputs and appropriate forecasting for prospective financial information.
• Inadequate segregation of duties within human resources, manual journal entry posting processes, and various bank accounts of the Company to prevent and detect unauthorized transactions in a timely manner.
While these material weaknesses did not result in material misstatements of the Company’s consolidated financial statements as of and for the year ended December 31, 2022, these material weaknesses create a reasonable possibility that a material misstatement of account balances or disclosures in annual or interim consolidated financial statements may not be prevented or detected in a timely manner.
The Company’s independent registered public accounting firm, Grant Thornton LLP, which audited the 2022 consolidated financial statements included in the Form 10-K, has expressed an adverse opinion on the Company's internal control over financial reporting.
Remediation Plan and Status
Our management is committed to remediating identified control deficiencies (including both those that rise to the level of a material weakness and those that do not), fostering continuous improvement in our internal controls and enhancing our overall internal controls environment.
Through the full year of 2023, the Company initiated and will continue efforts toward implementation of certain steps in its remediation plan, including:
• Engaged a third-party CPA firm to assist with the redesign of the Sarbanes-Oxley program inclusive of entity-level controls.
• Created and staffed a controls compliance analyst charged with monitoring and facilitating compliance with the Company’s responsibilities under the Sarbanes Oxley Act of 2002 (“SOX”).
• Implemented a global risk and compliance software to assist in monitoring and documenting compliance with SOX.
• For certain processes, developed new and revised existing process narratives and identified risks inherent to those processes.
• Developed new controls and revised the design of existing controls for a significant number of relevant key controls to mitigate the aforementioned risks, inclusive of general information technology controls and entity-level controls.
• Certain business functions have been restructured or consolidated to align more closely with effective business operation as well as to enable appropriate segregation of duties.
The following remaining activities are scheduled to occur in the first half of 2023 in anticipation of conducting management’s testing that will begin in the first half of 2023 in support of issuing management’s assessment of internal control over financial reporting as of December 31, 2023:
• Conduct initial organization-wide training sessions with all control owners.
• Implementation of new business systems to support information technology general controls.
• Completion of the identification of risks arising from inappropriate segregation of duties and fraud risks.
• Completion of risk assessment and control design for the remaining populations of processes and controls.
• Implementation of controls across all financial reporting processes and information technology environments.
• Development of effective communication plans relating to, among other things, identification of deficiencies and recommendations for corrective actions. These plans will apply to all parties responsible for remediation.
• Implement periodic compliance reports are made to the Nominating and Governance Committee of the Board of Directors.
• Ongoing training with control owners, as necessary.
• Ongoing migration of certain components of a legacy information technology system onto a common information technology environment, including risk assessment, control design and implementation of new and revised controls.
31
Our management believes that these remediation actions, when fully implemented, will remediate the material weaknesses we have identified and strengthen our internal control over financial reporting. Our remediation efforts are ongoing and additional remediation initiatives may be necessary. We will continue our initiatives to implement and document the strengthening of existing, and development of new policies, procedures, and internal controls.
Remediation of the identified material weaknesses and strengthening our internal control environment will require a substantial effort throughout 2023. We will test the ongoing operating effectiveness of the new and existing controls in future periods. The material weaknesses cannot be considered completely remediated until the applicable controls have operated for a sufficient period of time and management has concluded, through testing, that these controls are operating effectively.
While we believe the steps taken to date and those planned for implementation will remediate the ineffectiveness of our internal control over financial reporting, we have not completed all remediation efforts identified herein. Accordingly, as we continue to monitor the effectiveness of our internal control over financial reporting in the areas affected by the material weaknesses described above, we have and will continue to perform additional procedures prescribed by management, including the use of manual mitigating control procedures and employing any additional tools and resources deemed necessary, to ensure that our consolidated financial statements are fairly stated in all material respects.
Changes in Internal Control Over Financial Reporting
There were no changes in our internal control over financial reporting, except for the implementation of remediation plans to address the material weaknesses discussed above, during the most recent fiscal quarter that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
32
PART II – OTHER INFORMATION
ITEM 1. LEGAL PROCEEDINGS
None.
ITEM 1A. RISK FACTORS
For a summary of the Company’s risk factors, please refer to Item 9A of our Form 10-K for the year ended December 31, 2022.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.