Item 4. Controls and Procedures
ITEM 4. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
We maintain disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) of the Securities Exchange Act of 1934, as amended (the "Exchange Act")) that are designed to be effective in providing reasonable assurance that information required to be disclosed in our reports under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in the rules and forms of the SEC, and that such information is accumulated and communicated to our management to allow timely decisions regarding required disclosure.
Management does not expect that our disclosure controls and procedures or our internal control over financial reporting will prevent all errors and all fraud. A control system, no matter how well conceived and operated, can provide only reasonable, not absolute, assurance that the objectives of the control system are met. Further, the design of a control system must reflect the fact that there are resource constraints, and the benefits of controls must be considered relative to their costs. Because of the inherent limitations in all control systems, including the possibility of human error, the circumvention or overriding of controls, or fraud, no evaluation of controls can provide absolute assurance that all control issues, misstatements, errors, and instances of fraud, if any, within our organization have been or will be prevented or detected.
As of the period covered by this Quarterly Report on Form 10-Q, an evaluation was conducted under the supervision and with the participation of our management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) and Rule 15d-15(e) of the Exchange Act). Our management concluded that as of June 30, 2024, our disclosure controls and procedures were not effective because of the material weaknesses in our internal control over financial reporting identified by management as of December 31, 2023 (described below). A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that a reasonable possibility exists that a material misstatement of our annual or interim financial statements would not be prevented or detected on a timely basis.
Material Weaknesses in Control Activities
Evaluation of Disclosure Controls and Procedures
Disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) of the Exchange Act are controls and other procedures designed to ensure that information required to be disclosed in our reports under the Exchange Act is recorded, processed, summarized, and reported within the time periods specified in the rules and forms of the SEC, and that such information is accumulated and communicated to our management to allow timely decisions regarding required disclosure.
As of June 30, 2024, an evaluation was conducted under the supervision and with the participation of our management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) and Rule 15d-15(e) of the Exchange Act). Our management concluded that as of June 30, 2024, our disclosure controls and procedures were not effective because of the material weaknesses in our internal control over financial reporting described below.
Management's Report on Internal Control Over Financial Reporting
The Company's management is responsible for establishing and maintaining adequate internal control over financial reporting, as such term is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act. The Company's internal control over financial reporting is a process designed by or under the supervision of the Company's Chief Executive Officer and Chief Financial Officer, and overseen by the Board of Directors, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with GAAP and includes policies and procedures that:
• Pertain to the maintenance of records that, in reasonable detail, accurately, and fairly reflect the transactions and dispositions of the Company's assets;
25
• Provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with GAAP, and that the Company's receipts and expenditures are being made only in accordance with the authorization of its management and directors; and
• Provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the Company's assets that could have a material effect on the financial statements.
Because of its inherent limitations, internal control over financial reporting is not intended to provide absolute assurance that a misstatement of the Company's Consolidated Financial Statements would be prevented or detected. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.
A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.
Management conducted an evaluation of the effectiveness of the Company's internal control over financial reporting using the criteria in Internal Control - Integrated Framework 2013 issued by the Committee of Sponsoring Organizations of the Treadway Commission (the “COSO Framework”). As a result of this evaluation, management concluded that the Company's internal control over financial reporting was not effective as of June 30, 2024 because of the material weaknesses in internal control over financial reporting discussed below.
• Control Environment: The Company did not maintain an effective control environment based on the criteria established in the COSO framework, which resulted in deficiencies in principles associated with the control environment.
In addition, the following material weaknesses were previously identified and contributed to the material weakness in the control environment:
• Insufficient resources within the accounting and financial reporting department to review the accounting of complex financial reporting transactions including areas such as business combinations, share based compensation, and the related income tax reporting
• Ineffective controls over updating and distributing accounting policies and procedures across the organization.
The control environment material weaknesses contributed to other material weaknesses within our system of internal controls over financial reporting related to the following COSO components:
• Risk Assessment: The Company did not design and implement an effective risk assessment based on the criteria established in the COSO framework and identified deficiencies in the principles associated with the risk assessment component of the COSO framework.
• Information and Communication: The Company did not have an effective information and communication process that identified and assessed the source of and controls necessary to ensure the reliability of information used in financial reporting and that communicates relevant information about roles and responsibilities for internal control over financial reporting.
• Monitoring Activities: The Company did not have effective monitoring activities to assess the operation of internal control over financial reporting, including the continued appropriateness of control design and level of documentation maintained to support control effectiveness.
• Control Activities: As a consequence of the material weaknesses described above, internal control deficiencies related to the design and operation of process-level controls and general information technology controls were determined to be pervasive throughout the Company's financial reporting processes.
In addition, the following material weaknesses were previously identified and contributed to the material weakness in control activities:
• Inadequate information and technology general controls, including segregation of duties, change management, and user access, which were inadequate to support financial reporting applications and support automated controls and functionality.
• Inadequate controls over physical inventory counts.
• Inadequate controls over valuations, inclusive of appropriate valuation model inputs and appropriate forecasting for prospective financial information.
26
• Inadequate segregation of duties within human resources, manual journal entry posting processes, and various bank accounts of the Company to prevent and detect unauthorized transactions in a timely manner.
While these material weaknesses did not result in material misstatements of the Company's Condensed Consolidated Financial Statements as of and for the year ended December 31, 2023, and management does not believe that these material weaknesses resulted in material misstatements as of June 30, 2024, these material weaknesses create a reasonable possibility that a material misstatement of account balances or disclosures in annual or interim consolidated financial statements may not be prevented or detected in a timely manner.
The Company's independent registered public accounting firm, Grant Thornton LLP, which audited the 2023 consolidated financial statements included in the Form 10-K, has expressed an adverse opinion on the Company's internal control over financial reporting.
Remediation Plan and Status
Our management is committed to remediating identified control deficiencies (including both those that rise to the level of a material weakness and those that do not), fostering continuous improvement in our internal controls, and enhancing our overall internal controls environment.
We initiated many of our control remediation efforts in fiscal 2022, and these efforts have continued through 2024, including:
• Engaged a third-party specialist CPA firm to consult with management in redesigning and documenting of our internal controls over financial reporting, including our entity-level controls, to be compliant with Sarbanes Oxley Act of 2002 ("SOX").
• Hired a dedicated controls compliance manager charged with monitoring and facilitating compliance with the Company's responsibilities under SOX in coordination with the third-party specialist.
• Implemented a global risk and compliance software to assist in monitoring and documenting compliance with SOX.
• Made significant progress related to our control design and assessment, including the identification of risks arising from inappropriate segregation of duties and fraud risks and the development of new controls and revised the design of existing controls to mitigate the aforementioned risks, inclusive of entity-level controls.
• For certain processes, developed new and revised existing process narratives and flowcharts and identified risks inherent to those processes.
• Conducted training sessions with control owners.
• Restructured or consolidated certain business functions to align more closely with effective business operation as well as to enable appropriate segregation of duties.
• Implemented new business systems, including an enterprise resource planning software system, to support information technology general controls, appropriate segregation of duties, appropriate journal entry posting processes, change management, and user access.
• Added personnel to the accounting and financial reporting department with technical accounting experience to act as internal resources for reviewing complex financial reporting transactions, including areas such as business combinations, share based compensation, and income tax reporting.
• Continue to engage third party specialists to assist management with complex financial transactions and valuations, including valuation model techniques and inputs such as forecasted, prospective financial information.
The following remaining activities are scheduled to occur during our fiscal year 2024 in support of issuing management's assessment of internal control over financial reporting as of December 31, 2024:
• Testing design and operating effectiveness of newly implemented controls across all financial reporting processes and information technology environments.
• Finalization of risk assessments, control design, and implementation of new and revised controls, inclusive of general information technology controls and entity-level controls, as necessary.
• Ongoing training with control owners.
• Developing effective communication plans to all parties responsible for remediation relating to, among other things, identification of deficiencies and recommendations for corrective actions.
• Providing periodic compliance reports to the Audit Committee of the Board of Directors.
Our management believes that these remediation actions, when fully implemented, will remediate the material weaknesses we have identified and strengthen our internal control over financial reporting. However, our remediation efforts are ongoing and
27
additional remediation initiatives may be necessary. We will continue to implement and document the strengthening of existing and the development of new policies, procedures, and internal controls.
Remediation of the identified material weaknesses and strengthening our internal control environment has required and will continue to require a substantial effort throughout 2024. We will test the ongoing operating effectiveness of the new and existing controls in future periods. The material weaknesses cannot be considered completely remediated until the applicable controls have operated for a sufficient period of time and management has concluded, through testing, that these controls are operating effectively.
While we believe the steps taken to date and those planned for implementation will remediate the ineffectiveness of our internal control over financial reporting, we have not completed all remediation efforts identified herein. Accordingly, as we continue to monitor the effectiveness of our internal control over financial reporting in the areas affected by the material weaknesses described above, we have and will continue to perform additional procedures prescribed by management, including the use of manual mitigating control procedures and employing any additional tools and resources deemed necessary, to ensure that our Consolidated Financial Statements are fairly stated in all material respects.
Changes in Internal Control Over Financial Reporting
There were no changes in our internal control over financial reporting, except for the implementation of remediation plans to address the material weaknesses discussed above, during the most recent fiscal quarter that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting.
28
PART II – OTHER INFORMATION
ITEM 1. LEGAL PROCEEDINGS
None.
ITEM 1A. RISK FACTORS
For a summary of the Company's risk factors, please refer to Item 9A of our Form 10-K for the year ended December 31, 2023.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.