Item 4. Controls and Procedures
Item
4. Controls and Procedures
Evaluation
of Disclosure Controls and Procedures
We
maintain disclosure controls and procedures (as that term is defined in Rules 13a-15(e) and 15d-15(e) under the Exchange Act) that are
designed to ensure that information required to be disclosed in our reports under the Exchange Act is recorded, processed, summarized,
and reported within the time periods specified in the SEC’s rules and forms, and that such information is accumulated and communicated
to our management, including our chief executive officer and chief financial officer, as appropriate, to allow timely decisions regarding
required disclosures. In designing disclosure controls and procedures, our management necessarily was required to apply its judgment
in evaluating the cost-benefit relationship of possible disclosure controls and procedures. The design of any disclosure controls and
procedures also is based in part upon certain assumptions about the likelihood of future events, and there can be no assurance that any
design will succeed in achieving its stated goals under all potential future conditions. Any controls and procedures, no matter how well
designed and operated, can provide only reasonable, not absolute, assurance of achieving the desired control objectives.
Our
management, with the participation of our chief executive officer and chief financial officer, has evaluated the effectiveness of the
design and operation of our disclosure controls and procedures as of the end of the period covered by this report. Based upon that evaluation
and subject to the foregoing, our chief executive officer and chief financial officer concluded that, our disclosure controls and procedures
were not effective due to the material weaknesses in internal control over financial reporting described below.
Management’s
Report on Internal Control Over Financial Reporting
Management
of our Company and its consolidated subsidiaries is responsible for establishing and maintaining adequate internal control over financial
reporting. The Company’s internal control over financial reporting is a process designed under the supervision of its chief executive
and chief financial officers and effected by the Company’s Board of Directors, management, and other personnel, to provide reasonable
assurance regarding the reliability of financial reporting and the preparation of its consolidated financial statements for external
reporting purposes in accordance with U.S. generally accepted accounting principles.
Because
of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. In addition, projections
of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in
conditions or that the degree of compliance with the policies or procedures may deteriorate.
Material
Weakness in Internal Control over Financial Reporting
Management
assessed the effectiveness of the Company’s internal control over financial reporting as of March 31, 2024, based on the framework
established in Internal Control—Integrated Framework (2013) issued by the Committee of Sponsoring Organizations (“COSO”)
of the Treadway Commission. Based on this assessment, management has determined that the Company’s internal control over financial
reporting was not effective.
33
A
material weakness, as defined in the standards established by the Sarbanes-Oxley Act of 2002 (the “Sarbanes-Oxley Act”),
is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility
that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis.
Management
identified the following control deficiencies during the year ended December 31, 2023 that constituted material weaknesses:
●
Ineffective
design, implementation, and operation of controls over program change management, user access and vendor management to ensure:
(i)
information
technology (“IT”) program and data changes affecting the Company’s financial IT applications and underlying accounting
records, are identified, tested, authorized, and implemented appropriately to validate that data produced by its relevant IT systems
were complete and accurate. Automated process-level and manual controls that are dependent upon the information derived from such
financially relevant systems were also determined to be ineffective as a result of such deficiency;
(ii)
appropriate
restrictions that would adequately prevent users from gaining inappropriate access to the financially relevant systems; and
(iii)
key
third-party service provider Systems and Organizational Controls (“SOC”) reports were obtained and reviewed.
●
Business
process controls across the entity’s financial reporting processes were not effectively designed and implemented to properly
address the risk of material misstatement from:
(i)
insufficient
evidence to verify the completeness and accuracy of manually generated Information Produced by the Entity (“IPE”) and
system generated IPE; and
(ii)
insufficient
evidence of formal review and approval procedures of key information utilized in the performance of the control.
Management
is in the process of remediating these identified material weaknesses.
Management’s
Plan to Remediate the Material Weakness
To
remediate the identified material weaknesses, our management, with oversight from our audit committee, implemented a remediation plan.
The Company has taken the following remediation steps during the year ended December 31, 2023:
(i)
engaged
an independent third-party consulting firm to conduct internal control walkthroughs and testing and to provide assistance with deficiency
remediation;
(ii)
prepared
risk assessments of our financial statement accounts in accordance with the COSO 2013 Framework;
(iii)
developed
risk and control matrices for critical internal control processes supporting internal control over financial reporting;
(iv)
created
key process flowcharts, including documentation of key and compensating controls;
(v)
assessed
the design and operating effectiveness of our controls;
(vi)
identified
control gaps and weaknesses in the design and operating effectiveness of our controls;
(vii)
implemented
a ticketing system for user provisioning, modifications, and termination;
(viii)
formalized
information technology change management processes and retention of audit documentation;
(ix)
established
policies and procedures related to system backups and monitoring, software development life cycle and cybersecurity;
(x)
started
to formalize user access and change management reviews as well as SOC report reviews for in-scope third-party systems; and
(xi)
summarized
our control deficiencies identified to date.
Management
continues to implement measures designed to ensure that control deficiencies contributing to the material weaknesses are remediated,
such that these controls are designed, implemented, and operating effectively. The other remediation actions planned include:
(i)
continue
to formalize accounting and financial reporting policies and procedures including entity-level controls and segregation of duties
review and analysis;
(ii)
maintain
evidence of the completeness and accuracy of manually generated IPE and system generated IPE;
(iii)
enhance
documentation and evidence of review of controls; and
(iv)
continue
to formalize user access and change management reviews as well as SOC report reviews for in-scope third-party systems.
The
remediation plan, once fully implemented and determined to be operating effectively, is expected to result in the remediation of the
identified material weaknesses in internal controls over financial reporting. We are committed to maintaining a strong internal control
environment and believe that these remediation efforts will represent significant improvements in our control environment. Our management
will continue to monitor and evaluate the relevance of our risk-based approach and the effectiveness of our internal controls and procedures
over financial reporting on an ongoing basis and is committed to taking further action and implementing additional enhancements or improvements,
as necessary.
These
material weaknesses did not result in a misstatement of the company’s financial statements; however, they could have resulted in
misstatements of interim or annual consolidated financial statements and disclosures that would result in a material misstatement that
would not be prevented or detected.
Changes
in Internal Control over Financial Reporting
As
discussed above, we are implementing certain measures to remediate the material weaknesses identified in the design and operation of
our internal control over financial reporting. Other than those measures, there have been no changes in our internal control over financial
reporting (as defined in Rule 13a-15(f) and 15d-15(f) under the Exchange Act) during the three months ended March 31, 2024 that materially
affected our internal control over financial reporting as of that date.
34
PART
II – OTHER INFORMATION
ITEM
1. LEGAL PROCEEDINGS
In
the ordinary course of our operations, we become involved in ordinary routine litigation incidental to the business. Material proceedings
are described under Note 10, “Commitments and Contingencies” to the unaudited condensed consolidated financial statements
included in this Quarterly Report on Form 10-Q.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.