5 unchanged sentences
In the recent past, certain of the Company’s markets experienced economic uncertainty characterized by increasing unemployment, limited availability of credit, significant inflation, and decreased consumer and business spending.
−Removed: In addition, certain geopolitical events, including the ongoing war between Russia and Ukraine, the war between Israel, Hamas and Hezbollah, and the ongoing unrest throughout the Middle East, have caused significant economic, market, political or regulatory uncertainty in some of the Company’s markets.
+Added: In addition, certain geopolitical events, including the ongoing war between Russia and Ukraine, the ongoing unrest throughout the Middle East, and conflict and political instability in parts of South America have caused significant economic, market, political or regulatory uncertainty in some of the Company’s markets.
Any decline in the economic condition or employment levels of the U.S.
or of any of the foreign countries in which the Company does business, or in the economic condition of any region of any of the foregoing, or in any specific industry served by the Company may severely reduce the demand for the Company’s services and thereby significantly decrease the Company’s revenues and profits.
−Removed: Further, continued or intensifying economic, political or regulatory uncertainty in the Company’s markets could reduce demand for the Company’s services.
+Added: Further, continued or intensifying economic, political or regulatory uncertainty in the Company’s markets or backlash against U.S.-based companies could reduce demand for the Company’s services.
The Company ’ s business depends on a strong reputation and anything that harms its reputation will likely harm its results.
7 unchanged sentences
companies operating in foreign countries, legal and cultural differences in the conduct of business, potential adverse tax consequences, and difficulty in staffing and managing international operations.
+Added: Furthermore, the Company’s operations may be adversely impacted by conflicts between the U.S.
+Added: government and those of other jurisdictions in which the Company operates.
These factors may have a material adverse effect on the performance of the Company’s business.
5 unchanged sentences
With operations in many states and multiple foreign countries, the Company is subject to numerous risks outside of the Company’s control, including risks arising from natural disasters, such as fires, earthquakes, hurricanes, floods, tornadoes, unusual weather conditions, pandemics and other global health emergencies, terrorist acts or disruptive global political events, or similar disruptions that could materially adversely affect the Company’s business and financial performance.
−Removed: Historically, the Company’s operations are heavily dependent on the ability of employees and consultants to travel from business to business and from location to location.
+Added: Historically, the Company’s operations are dependent on the ability of employees and consultants to travel from business to business and from location to location.
Any public health emergencies, including a real or potential global pandemic such as those caused by the avian flu, SARS, Ebola, coronavirus, or even a particularly virulent flu, could decrease demand for the Company’s services and the Company’s ability to offer them.
−Removed: Uncharacteristic or significant weather conditions may increase in frequency or severity due to climate change, which may increase the Company’s expenses, exacerbate other risks to the Company, and affect travel and the ability of businesses to remain open, which could lead to a decreased ability to offer the Company’s services and materially adversely affect the Company’s results of operations.
+Added: Uncharacteristic or significant weather conditions may increase in frequency or severity due to climate change, which may increase the Company’s expenses, exacerbate other risks to the Company, including from impacts to key suppliers, and affect travel and the ability of businesses to remain open, which could lead to a decreased ability to offer the Company’s services and materially adversely affect the Company’s results of operations.
In addition, these events could result in delays in placing employees and consultants, the temporary disruption in the transport of employees and consultants overseas and domestically, the inability of employees and consultants to reach or have transportation to clients directly affected by such events, and disruption to the Company’s information systems.
Although it is not possible to predict such events or their consequences, these events could materially adversely affect the Company’s reputation, business and financial condition.
−Removed: Failure to meet, and increasing scrutiny of, and evolving expectations for, sustainability and ESG commitments and initiatives could harm the Company ’ s reputation, or otherwise adversely impact our business, financial condition or results of operations.
−Removed: The Company has public sustainability and environmental, social and governance (“ESG”) commitments, including environmental targets designed to have a positive impact on the climate.
+Added: Failure to meet evolving and increasingly contradictory expectations for action or inaction on sustainability and ESG commitments and initiatives could harm the Company’s reputation, or otherwise adversely impact the business, financial condition or results of operations.
+Added: The Company has public sustainability and environmental, social and governance (“ESG”) commitments, including environmental targets validated by the Science Based Target initiative (“SBTi”), designed to have a positive impact on the climate.
The Company’s ability to achieve these goals is subject to a multitude of risks that may be outside of the Company’s control.
−Removed: The Company’s failure or perceived failure to achieve ESG-related goals or maintain ESG-related practices that meet evolving stakeholder expectations could harm the Company’s reputation, adversely impact the Company’s ability to attract and retain employees or clients, and expose the Company to increased scrutiny from the investment community and enforcement authorities.
−Removed: The Company’s reputation also may be harmed by the perceptions that clients, employees and other stakeholders have about the Company’s action or inaction on social, ethical or political issues.
+Added: The Company’s failure or perceived failure to achieve ESG- or climate-related goals or maintain ESG-related practices that meet evolving and sometimes contradictory regulatory and stakeholder expectations could harm the Company’s reputation, adversely impact the Company’s ability to attract and retain employees or clients, and expose the Company to increased scrutiny from the media, lawmakers, the investment community and regulators.
+Added: The Company’s reputation also may be harmed by the perceptions that clients, employees and other stakeholders, lawmakers and the media have about the Company’s action or inaction on social, ethical or political issues.
Damage to the Company’s reputation and loss of brand equity may reduce demand for the Company’s services and thus have an adverse effect on future financial results and reduce the stock price, as well as require additional resources to rebuild the Company’s reputation and restore the value of the brands.
−Removed: At the same time, regulators have increasingly expressed or pursued opposing views, legislation and investment expectations with respect to sustainability initiatives.
+Added: Increasingly, lawmakers, regulators and stakeholders have expressed or pursued ESG legislation and investment expectations with opposing positions and impacts.
In recent years anti-ESG and anti-DEI sentiment has gained momentum across the U.S., with several dozen states, Congress and the Executive Branch having proposed or enacted “anti-ESG” and “anti-DEI” policies, legislation, executive orders or initiatives or issued related legal opinions.
−Removed: Conflicting regulations and a lack of harmonization of ESG legal and regulatory environments across the jurisdictions in which we operate may create enhanced compliance risks and costs.
−Removed: We may also face increasing scrutiny from our clients, candidates, employees and other stakeholders relating to the appropriate role of ESG practices and disclosures.
−Removed: Failure to prepare for and meet evolving standards and expectations could result in regulatory penalties, investor backlash and diminished shareholder confidence.
+Added: Meanwhile other states, countries and regions have introduced or enacted broader ESG disclosure or performance compliance obligations.
+Added: Conflicting regulations, legal and regulatory uncertainty, and a lack of ESG harmonization of legal and regulatory environments across the jurisdictions in which the Company operates has created and, in the future may continue to create, enhanced compliance risks and costs.
+Added: The Company may also face increasing scrutiny from its clients, candidates, employees, stakeholders, lawmakers and the media relating to the appropriate role of ESG practices and disclosures.
+Added: Failure to prepare for and meet evolving standards and expectations could result in client dissatisfaction, regulatory penalties, investor backlash and diminished shareholder confidence.
Related to the Company’s Operations
11 unchanged sentences
There are many competitors, some of which have greater resources than the Company, and new competitors are entering the market all the time.
+Added: The increased availability and maturation of AI tools may enable clients to use advanced automation capabilities in lieu of services provided by the Company’s contract talent personnel.
Therefore, there can be no assurance that the Company will be able to retain clients or market share in the future.
3 unchanged sentences
The Company’s ability to control the workplace environment is limited.
−Removed: As the employer of record of its temporary employees, the Company incurs a risk of liability to its temporary employees for various workplace events, including claims of physical injury, discrimination, harassment or failure to protect confidential personal information.
+Added: As the employer of record of its temporary employees, the Company incurs a risk of liability to its temporary employees for various workplace events, including claims of physical injury, discrimination, harassment or failure to protect confidential or personal information.
In addition, in order to facilitate remote working arrangements, some of the Company’s temporary workers are accessing client workspaces from their personal devices through cloud-based systems, which could increase cybersecurity risks to the Company’s clients.
If cybersecurity incidents were to occur in such a way, the Company may face legal and contractual liability, reputational damage, loss of business, and other expenses.
−Removed: The Company also incurs a risk of liability to its clients resulting from allegations of damages caused by temporary employees acting on phishing emails, cyber attacks, and other errors, omissions or theft by its temporary employees, or allegations of compromise of client confidential information.
+Added: The Company also incurs a risk of liability to its clients resulting from allegations of damages caused by temporary employees acting on phishing emails, facilitating, allowing or failing to stop cyberattacks, and other errors, omissions or theft by its temporary employees, or allegations of compromise of client confidential information.
In some cases, the Company has agreed to indemnify its clients in respect of these types of claims.
8 unchanged sentences
The business of Protiviti consists of providing business consulting and internal audit services.
−Removed: Protiviti risks liability from allegations of damages caused by errors, omissions or misconduct by its employees working on consulting engagements or from damages caused by its employees acting on phishing emails and cyber attacks, or allegations of compromise of client confidential information.
+Added: Protiviti risks liability from allegations of damages caused by errors, omissions or misconduct by its employees or allegations of compromised client confidential or personal information while working on consulting engagements, or from damages caused by its employees acting on phishing emails and facilitating, allowing or failing to stop cyberattacks while working in a client’s environment.
In some cases, the Company has agreed to indemnify its clients in respect of these types of claims.
5 unchanged sentences
There can be no assurance that the Company will be able to attract and retain the personnel that are essential to its success.
−Removed: A failure to retain key management personnel could disrupt the Company’s succession strategy, hindering a smooth transition to new leadership and potentially disrupting the Company’s operations.
+Added: A failure to retain key management personnel could disrupt the Company’s operations and its succession strategy, hindering a smooth transition to new leadership and potentially disrupting the Company’s operations.
The Company ’ s results of operations and ability to grow could be materially negatively affected if it cannot successfully keep pace with technological changes impacting the development and implementation of its services and the evolving needs of its clients.
The Company’s success depends on its ability to keep pace with rapid technological changes affecting both the development and implementation of its services and the staffing needs of its clients.
−Removed: Technological advances such as artificial intelligence, machine learning and automation are impacting industries served by all the Company’s lines of business.
+Added: Technological advances such as AI, machine learning and automation are impacting industries served by all of the Company’s lines of business.
In addition, the Company’s business relies on a variety of technologies, including those that support hiring and tracking, order management, billing, and client data analytics.
If the Company does not sufficiently invest in new technology and keep pace with industry developments, appropriately implement new technologies, or evolve its business at sufficient speed and scale in response to such developments, or if it does not make the right strategic investments to respond to these developments, the Company’s services, results of operations, and ability to develop and maintain its business could be negatively affected.
−Removed: The Company uses artificial intelligence in its services which may result in operational challenges, legal liability, reputational concerns, and privacy and competitive risks.
−Removed: The Company currently uses and intends to leverage its own and third parties’ artificial intelligence (“AI”) processes and algorithms and its own evolving and third parties’ cognitive, analytical and artificial intelligence applications in its daily operations for Protiviti and talent solutions, including by deploying generative AI into the Company’s talent solutions search operations.
−Removed: Protiviti expanded its service offerings to include AI risk analysis, policy creation, governance, and technology selection and architecture.
−Removed: The use of AI by talent solutions and provision of AI related services by Protiviti may result in operational challenges, legal liability, reputational concerns, and privacy and competitive risks which could result in adverse effects to the Company’s financial condition, results or reputation.
+Added: The Company uses AI in its provision of services which may result in operational challenges, legal liability, reputational concerns, and privacy, security and competitive risks.
+Added: The Company currently uses and intends to continue using its proprietary AI processes, algorithms and applications, as well as those of third parties in its daily operations for Protiviti and talent solutions, including by deploying generative AI into the Company’s talent solutions search operations.
+Added: Protiviti has expanded its service offerings to include AI risk analysis, policy creation, governance, and technology selection and architecture.
+Added: The use of AI by talent solutions and provision of AI related services by Protiviti may result in operational challenges, legal liability, reputational concerns, and privacy, security and competitive risks which could result in adverse effects to the Company’s financial condition, results or reputation.
Generative AI products and services leverage existing and widely available technologies, such as Chat GPT-4 and its successors, or alternative large language models or other processes.
2 unchanged sentences
AI algorithms use machine learning and predictive analytics, which may lead to flawed, biased, and inaccurate candidate and lead generation search results.
−Removed: Datasets in AI training, development or operations may be insufficient, of poor quality, reflect unwanted forms of bias, or raise other legal concerns (such as concerns regarding copyright protections or data protection).
+Added: Datasets used for AI training, development or operations may be insufficient, of poor quality, reflect unwanted forms of bias, or raise other legal concerns (such as concerns relating to intellectual property infringement or data protection).
Inappropriate or controversial data practices by, or practices reflecting inherent biases of, data scientists, engineers and end-users of the Company’s systems could lead to mistrust, rejection or skepticism of the Company’s services by clients and candidates.
Further, unauthorized use or misuse of AI by the Company’s employees, vendors or others may result in disclosure of confidential company and customer data, reputational harm, privacy law violations, and legal liability.
−Removed: The Company’s use of AI may also lead to novel and urgent cybersecurity risks, including access to or the misuse of personal data, all of which may adversely affect its operations and reputation.
+Added: The Company’s use of
+Added: AI may also lead to novel and urgent cybersecurity risks, including access to or the misuse of personal data, all of which may adversely affect its operations and reputation.
+Added: In addition, the Company increasingly relies on third-party technology vendors that regularly deploy new and enhanced AI-enabled features, tools and platforms, often at a rapid pace and with limited advance notice.
+Added: These technologies in some cases may be made broadly available to employees, including through embedded features in existing enterprise software or low-code or no-code development environments that enable employees to build or customize AI-enabled tools.
+Added: As a result, the Company may have limited ability to fully evaluate, test, restrict, monitor or govern the security, data handling practices, model behavior, or downstream uses of such AI technologies before or after deployment.
+Added: Governance, monitoring and security controls designed to manage the use of AI technologies, including controls related to data access, data retention, model training, prompt inputs and outputs, explainability, auditability and third-party risk management, are evolving and may not mature at the same pace as the deployment of new AI capabilities by vendors.
+Added: This disparity may increase the risk of unauthorized or unintended use of AI, data leakage, regulatory non-compliance, intellectual property infringement, security vulnerabilities, or inconsistent application of Company policies.
+Added: The Company may also incur additional costs and operational complexity through attempts to retrofit controls, implement safeguards, restrict access, or discontinue use of certain AI tools after deployment.
+Added: Any failure to effectively manage these risks could adversely affect the Company’s business, results of operations, financial condition or reputation.
Uncertainty in the legal regulatory regime relating to AI may require significant resources to modify and maintain business practices to comply with U.S.
1 unchanged sentence
Several jurisdictions around the globe, including Europe and certain U.S.
−Removed: states, have already proposed or enacted laws governing AI.
−Removed: For example, the European Union passed the Artificial Intelligence Act in 2024 which contains stringent AI regulations and laws, and the Company expects other jurisdictions will adopt similar legislation.
−Removed: Other jurisdictions may decide to adopt similar or more restrictive legislation that may render the use of such technologies challenging, impossible or financially prohibitive.
+Added: states, have already proposed or enacted laws governing the use, development and training of AI.
+Added: For example, the European Union passed the Artificial Intelligence Act in 2024 which contains prescriptive AI regulations and laws, and the Company expects other jurisdictions will adopt similar legislation.
+Added: Such other jurisdictions may decide to adopt similar or more restrictive legislation, and jurisdictions that have already enacted legislation could elect to enact additional legislation, any of which could render the use of AI challenging, impossible or financially prohibitive.
The demand for the Company ’ s services related to regulatory compliance may decline.
−Removed: The operations of both the talent solutions business and Protiviti include services related to Sarbanes-Oxley, Anti-Money Laundering Act of 2020 reviews and other regulatory compliance services.
+Added: The operations of both the talent solutions business and Protiviti include services related to Sarbanes-Oxley, Anti-Money Laundering Act of 2020 reviews, the Bank Secrecy Act of 1970, as amended, and related anti-money laundering regulations, the Dodd-Frank Wall Street Reform and Consumer Protection Act (the “Dodd-Frank Act”), the Foreign Corrupt Practices Act of 1977 and other regulatory compliance services.
There can be no assurance that there will be ongoing demand for these services.
Similarly, from time-to-time proposals are considered by the U.S.
−Removed: Congress to further delay or, in some cases, remove the requirements of Sarbanes-Oxley for a number of public companies.
−Removed: These or other similar modifications of the regulatory requirements could decrease demand for Protiviti’s services.
+Added: Congress to further delay or, in some cases, remove the requirements of Sarbanes-Oxley and the Dodd-Frank Act for a number of public and private companies.
+Added: Furthermore, the enforcement priorities of U.S.
+Added: regulators fluctuate from time to time, which may lead to periods of decreased demand for certain of the Company’s regulatory compliance services.
+Added: These or other similar modifications of the regulatory requirements could decrease demand for Protiviti’s and talent solution’s services.
Long-term contracts do not comprise a significant portion of the Company ’ s revenue.
3 unchanged sentences
If the Company does not effectively manage billable rates, the Company ’ s financial results could suffer.
−Removed: Accurate and strategic pricing represents a key factor in our financial results.
+Added: Accurate and strategic pricing represents a key factor in the Company’s financial results.
If billable rates are too low, the Company’s service revenues may not cover operational costs, whereas if billable rates are too high, the Company risks hindering client retention and limits competitiveness.
−Removed: Demand for the Company ’ s services from government and public sector clients may decrease over time.
−Removed: During the global pandemic, the Company reported increased business from services rendered to the public sector due to, among other developments, the volume of unemployment claims and housing assistance claims, as well as the demands faced by public school districts.
−Removed: With the end of the pandemic, many government projects ended and the Company’s government sector business has shifted to different projects with public sector clients.
−Removed: It is unknown whether the shift in projects with state, local and other public sector clients will ultimately maintain the same level of business or to what extent business with the public sector may decrease as the effects of the pandemic lessen or change over time.
Legal and Regulatory Risks
The Company and certain subsidiaries are defendants in several lawsuits that could cause the Company to incur substantial liabilities .
−Removed: The Company and certain subsidiaries are defendants in several certified or putative class and representative action lawsuits brought by or on behalf of the Company’s current and former employees alleging violations of federal and state law with respect to certain wage and hour related matters, as well as claims by job applicants challenging the Company’s compliance with the Fair Credit Reporting Act.
+Added: The Company and certain subsidiaries are defendants in several certified or putative class and representative action lawsuits brought by or on behalf of the Company’s current and former employees alleging violations of federal and state law with respect to certain wage and hour related matters.
The various claims made in one or more of such lawsuits include, among other things, the misclassification of certain employees as exempt employees under applicable law, failure to comply with wage statement requirements, failure to compensate certain employees for time spent performing activities related to the interviewing process (including attending the interviews themselves), and other related wage and hour violations.
Such suits seek, as applicable, unspecified amounts for unpaid overtime compensation, penalties and other damages, as well as attorneys’ fees.
−Removed: The Company is defending several claims brought under the California Labor Code Private Attorney General Act (“PAGA”) and which authorizes individuals to file lawsuits to seek civil penalties on behalf of themselves and other employees for alleged labor code violations.
+Added: The Company is defending several claims brought under the California Labor Code Private Attorney
+Added: General Act (“PAGA”) and which authorizes individuals to file lawsuits to seek civil penalties on behalf of themselves and other employees for alleged labor code violations.
It is not possible to predict the outcome of these lawsuits.
26 unchanged sentences
Further, lawsuits or other proceedings related to the Company’s compliance with government regulations or licensing requirements could materially adversely affect the Company.
−Removed: For example, the Company is currently named as a defendant in litigation challenging its compliance with the Fair Credit Reporting Act and PAGA litigation in California alleging wage and hour and other labor code compliance issues.
+Added: For example, the Company is currently named as a defendant in PAGA litigation in California alleging wage and hour and other labor code compliance issues.
It is not possible to predict the outcome of such litigation;
15 unchanged sentences
Similar economic sanctions are imposed by the European Union and other jurisdictions.
−Removed: The Company’s international operations subject it to these and other laws and regulations, which are
−Removed: complex, restrict the Company’s business dealings with certain countries, governments, entities and individuals, and are constantly changing.
+Added: The Company’s international operations subject it to these and other laws and regulations, which are complex, restrict the Company’s business dealings with certain countries, governments, entities and individuals, and are constantly changing.
Penalties for noncompliance with these complex laws and regulations can be significant and include substantial fines, sanctions, or civil and/or criminal penalties, and violations can result in adverse publicity, which could harm the Company’s business, financial condition or results of operations.
21 unchanged sentences
For example, the Organization of Economic Cooperation and Development (“OECD”), an international association of many countries, has introduced a framework to impose a 15% global minimum corporate tax, referred to as Pillar Two, effective for tax years beginning in 2024.
−Removed: Currently, there are no laws enacted incorporating Pillar Two in the U.S., however, certain countries in which the Company operates have adopted, or are in the process of adopting legislation to implement Pillar Two.
−Removed: In the U.S., various proposals to raise corporate income taxes are periodically considered such as the Inflation Reduction Act, which introduced a 15% Corporate Alternative Minimum Tax beginning in 2023.
−Removed: These enacted changed in tax laws, treaties or regulations, or their interpretation or enforcement could impact our current or future tax positions while the proposed changes in tax laws, treaties or regulations, or their interpretation or enforcement, could have a material adverse impact on our current or future tax positions.
+Added: On January 5, 2026, the OECD released new guidance establishing the Side-by-Side (“SbS”) program under the Pillar Two global minimum tax framework.
+Added: The SbS program includes a Simplified Effective Tax Rate Safe Harbor, an extended Transitional Country-by-Country Reporting Safe Harbor, and a Substance-based Tax Incentive Safe Harbor.
+Added: These enacted and proposed changes in tax laws, treaties or regulations, or their interpretation or enforcement could have a material adverse impact on the Company’s current or future tax positions.
Risks Related to the Company’s Information Technology, Cybersecurity and Data Protection
−Removed: Company and third-party computer, technology and communications hardware and software systems are vulnerable to damage, unauthorized access, and disruption that could expose the Company to material operational, financial and reputational damage (including the unauthorized access to, or exposure of, personal and confidential information and intellectual property).
−Removed: The Company’s ability to manage its operations using these systems successfully is critical to its success and largely depends upon the efficient and uninterrupted operation of its and third parties’ computer, technology and communications systems, some of which are managed and run by third-party vendors.
−Removed: The Company’s primary systems (and, as a result, its operations) are vulnerable to damage or interruption from power outages, computer, technology and telecommunications failures, computer viruses, security breaches, catastrophic events, and errors in usage by the Company’s or its vendors’ employees and contractors.
−Removed: In addition, the Company’s systems contain personal and confidential information and intellectual property, including information of importance to the Company and its employees, vendors, contractors and clients.
−Removed: Cyberattacks, including attacks motivated by the desire for monetary gain or embarrassment, geopolitics, and grievances against the business services industry in general or against the Company in particular, could potentially disable or damage its systems or the systems of its vendors or clients, or allow unauthorized access to, or exposure of, intellectual property and personal or confidential information, including information about employees, vendors, candidates, contractors and clients.
−Removed: The Company’s security tools, controls and practices, including those relating to identity and access management, credential
−Removed: strength, and the security tools, controls and practices of its vendors and clients, may not prevent or detect access, damage or disruption to Company or third-party computer, technology, and communications hardware and software systems or the unauthorized access to, or exposure of, intellectual property or personal or confidential information.
−Removed: A failure to prevent or detect unauthorized access to Company or third-party systems could expose the Company to material operational, financial and reputational damage.
−Removed: There are many approaches through which such systems could be damaged or disrupted, or information exposed or accessed, including through system vulnerabilities, configuration errors, vendor vulnerabilities, social engineering, cyberattacks, improperly obtaining and using user credentials, malfeasance, or the misuse of authorized user access.
−Removed: Periodic and continuous assessments are conducted by the Company to identify security risks, vulnerabilities, weaknesses or gaps, and a risk-based approach is then employed to address them, recognizing that not all system and software updates can be made and not all risks or vulnerabilities, weaknesses or gaps can be eliminated in an economical or timely manner.
+Added: Company and third-party computer, technology and communications hardware and software systems and assets (“IT Assets”) are vulnerable to damage, unauthorized access and disruption that could expose the Company to material operational, financial and reputational damage (including the unauthorized access to, or exposure of, personal and confidential information and intellectual property).
+Added: The Company’s ability to manage its operations using IT Assets successfully is critical to its success and largely depends upon the efficient and uninterrupted operation of its and third parties’ IT Assets, some of which are managed and run by third-party vendors.
+Added: The Company’s primary IT Assets (and, as a result, its operations) are vulnerable to damage or interruption from power outages, computer, technology and telecommunications failures, computer viruses, security breaches, cyberattacks, catastrophic events, and errors in usage by the Company’s or its vendors’ employees and contractors.
+Added: In addition, the Company’s IT Assets contain personal and confidential information and intellectual property, including information of importance to the Company and its employees, vendors, contractors and clients.
+Added: Cyberattacks, including attacks motivated by the desire for monetary gain or embarrassment, geopolitics, and grievances against the business services industry in general or against the Company in particular, could potentially disable or damage the Company’s IT Assets or those of its vendors or clients, or allow unauthorized access to, or exposure of, intellectual property and personal or confidential information, including information about employees, vendors, candidates, contractors and clients.
+Added: The Company’s security tools, controls and practices, including those relating to identity and access management, credential strength, and the security tools, controls and practices of its vendors and clients, may not prevent or detect access, damage or disruption to Company or third-party IT Assets or the unauthorized access to, or exposure of, intellectual property or personal or confidential information.
+Added: A failure to prevent or detect unauthorized access to Company or third-party IT Assets could expose the Company to material operational, financial and reputational damage.
+Added: There are many approaches through which such IT Assets or the information stored thereon could be damaged, disrupted, exposed or accessed, including through system vulnerabilities, configuration errors, vendor vulnerabilities, social engineering, cyberattacks (including cyberattacks through the use of AI), improper acquisition and use of user credentials, malfeasance, or the misuse of authorized user access.
+Added: Periodic and continuous assessments are conducted by the Company on its IT Assets to identify security risks, vulnerabilities, weaknesses or gaps, and a risk-based approach is then employed to address them.
This risk-based approach prioritizes risks, vulnerabilities, weaknesses and gaps based on, among other factors, budgetary constraints, impact, likelihood of mitigation and the broader risk landscape.
−Removed: No security program can offer a guarantee against all potential incidents.
−Removed: On an increasing frequency, the Company and its third-party vendors experience security incidents that have resulted in unauthorized access to the Company’s or its third-party vendors’ computer, technology and communications hardware and software systems.
−Removed: To date, no such incidents have been determined to have had a material impact on the Company.
−Removed: The Company has transitioned a significant number of the Company’s employee population to remote work.
−Removed: This transition to remote working has also increased the Company’s vulnerability to risks related to the Company’s computer, technology, and communications hardware and software systems and has exacerbated certain related risks, including risks of phishing and other cybersecurity attacks.
+Added: No security program can offer a guarantee against all potential cyberattacks or other cybersecurity-related incidents.
+Added: The Company and its third-party vendors experience cybersecurity attacks with increasing frequency, including incidents that have resulted in unauthorized access to the Company’s or its third-party vendors’ IT Assets.
+Added: To date, no such incidents have been determined to have had a material impact on the Company, but there is no guarantee that such incidents will not have a material impact on the Company in the future.
+Added: The Company has transitioned a significant number of its employee population to remote work.
+Added: This transition has also increased the Company’s vulnerability to cybersecurity-related risks related to the Company’s IT Assets and has exacerbated certain related risks, including risks of phishing and other cybersecurity attacks.
The damage or disruption to Company or third-party systems, or unauthorized access to, or exposure of, intellectual property or personal or confidential information, could harm the Company’s operations, reputation and brand, resulting in a loss of business or revenue.
It could also subject the Company to government sanctions, litigation from candidates, contractors, clients and employees, and legal liability under its contracts, resulting in increased costs or loss of revenue.
−Removed: The Company may also incur additional expenses, including the cost of remediating incidents or improving security measures, the cost of identifying and retaining replacement vendors, increased costs of insurance, or unexpected costs of ransomware payments.
−Removed: Cybersecurity threats continue to increase in frequency and sophistication, thereby increasing the difficulty of detecting and defending against them.
−Removed: Furthermore, the potential risk of security breaches and cyberattacks may increase as the Company introduces new service offerings.
−Removed: Any future events impacting the Company or its third-party vendors that damage or interrupt the Company’s or its third-party vendors’ computer, technology, and communications hardware and software systems or expose intellectual property or data or other confidential information could have a material adverse effect on our operations, reputation and financial results.
−Removed: Changes in data privacy and protection laws and regulations in respect of control of personal information (and the failure to comply with such laws and regulations) could increase the Company ’ s costs or otherwise adversely impact its operations, financial results, and reputation.
+Added: The Company may also incur additional expenses, including the cost of remediating cybersecurity incidents or improving security measures, identifying and retaining replacement vendors, increased insurance premiums, or ransomware payments.
+Added: Cybersecurity threats continue to increase in frequency and sophistication (including through the use of AI), thereby increasing the difficulty of detecting and defending against them.
+Added: Furthermore, the potential risk of cybersecurity breaches and cyberattacks may increase as the Company introduces new service offerings and deploys new AI technologies.
+Added: Any future events impacting the Company or its third-party vendors that damage or interrupt the Company’s or its third-party vendors’ IT Assets or expose intellectual property or data or other confidential information stored thereon could have a material adverse effect on the Company’s operations, reputation and financial results.
+Added: Changes in data privacy and protection laws and regulations relating to the use and control of personal information (and the failure to comply with such laws and regulations) could increase the Company ’ s costs or otherwise adversely impact its operations, financial results, and reputation.
In the ordinary course of business, the Company collects, uses and retains personal information from its clients, employees, candidates and contractors, including, without limitation, full names, government-issued identification numbers, addresses, phone numbers, birthdates and payroll-related information.
The possession and use of personal information in conducting the Company’s business subjects it to a variety of complex and evolving domestic and foreign laws and regulations regarding data privacy.
−Removed: For example, the European Union’s General Data Protection Regulation (“GDPR”), which became effective in May 2018, imposes specific operational requirements for entities processing personal information, including requirements for data transfers to certain countries outside the European Union, and strong enforcement authorities and mechanisms.
−Removed: Complying with the enhanced obligations imposed by the GDPR and other current and future laws and regulations relating to data storage, use, transfer, residency, privacy and protection has increased and may continue to increase the Company’s operating costs and require significant management time and attention, while any failure by the Company or its subsidiaries to comply with applicable laws could result in governmental enforcement actions, fines and other penalties that could potentially have an adverse effect on the Company’s operations, financial results and reputation.
+Added: For example, the European Union’s General Data Protection Regulation (“GDPR”), which became effective in May 2018, imposes specific operational requirements on entities that process personal information (including requirements relating to data transfers to certain countries outside the European Union) and strong enforcement mechanisms.
+Added: In the United States, the California Consumer Privacy Act (the “CCPA”), which became effective in January 2020, limits the collection and use of personal data and mandates that covered companies provide new disclosures to California consumers and afford such consumers new data privacy rights.
+Added: Under the CCPA, a data breach affecting California residents’ personal information because of a failure to maintain reasonable security procedures and practices can trigger a private right of action lawsuit, and as a result data breach litigation is likely to increase.
+Added: Many other U.S.
+Added: states have enacted their own privacy laws that are in some ways similar to, and in other ways different from, the CCPA’s requirements.
+Added: Compliance with the GDPR, the CCPA and other current and future laws and regulations relating to data storage, use, transfer, residency, privacy and protection has increased and may continue to increase the Company’s operating costs and may require significant management time and attention.
+Added: Further, any actual or perceived failure by the Company or its subsidiaries to comply with applicable laws could result in litigation, reputational harm, governmental enforcement actions or fines, and other penalties that could potentially have an adverse effect on the Company’s operations, financial results and reputation.
+Added: Risks Related to the Intellectual Property
+Added: The Company may not be able to adequately protect its intellectual property (“IP”) or may be found to infringe upon the IP rights of others, which could harm the value of the Company’s brand and adversely affect its business.
+Added: The Company utilizes IP, including patents, trademarks, copyrights and trade secrets, in its business, including in the software and AI the Company uses, and in its customer lists.
+Added: A combination of patent, copyright, trademark and trade secret laws in the jurisdictions in which the Company operates are critical to protecting these IP rights.
+Added: However, these laws may not be adequate to protect the Company’s IP from being challenged, invalidated, infringed, diluted or misappropriated.
+Added: While the Company enters into confidentiality agreements with employees, consultants and partners, such agreements may not be effective in preventing unauthorized disclosure or use of its proprietary information.
+Added: If such disclosures occur, the Company may not have adequate remedies.
+Added: Moreover, while it is the Company’s policy to protect and vigorously defend its IP rights, it cannot predict whether steps taken by it will be adequate to prevent misappropriation of these rights or the use by others of the Company’s IP.
+Added: IP disputes and proceedings and infringement claims may result in a significant distraction for management and significant expense, which may not be recoverable regardless of whether the Company is successful.
+Added: Such proceedings may be protracted with no certainty of success, and an adverse outcome could subject the Company to liabilities, force it to cease use of certain trademarks or other IP, or force it to enter into license agreements on terms which may not be favorable to the Company.
+Added: Any one of these occurrences may have an adverse effect on the Company’s business, profitability, results of operation and financial condition.
+Added: The Company uses open-source software in connection with its software development, which could negatively affect its ability to operate its business and subject the Company to litigation or other actions.
+Added: The Company uses and may continue to use open-source software in connection with the development and operation of its platforms.
+Added: Open-source software is generally licensed under open-source licenses, which could subject the Company to unfavorable conditions, including requiring it to make publicly available the source code for any modifications or derivative works the Company develops using the open-source software.
+Added: The Company may face claims demanding the release of software it developed that incorporates open-source software, which could include its source code, or otherwise seeking to enforce the terms of underlying license.
+Added: Litigation could be costly for the Company to defend and could require it to devote additional research and development resources to change the Company’s platforms.
+Added: Further, open-source licensors typically do not provide warranties or controls regarding the origin or security of the software and related support from the licensor is often unavailable.
+Added: Therefore, the Company cannot be sure that the authors of the open-source software it uses will implement or offer updates to address security risks or will not abandon further development and maintenance.
+Added: Many risks associated with usage of open-source software cannot be eliminated, and may, if not effectively addressed, negatively affect the Company’s operations, reputation and financial results.
Risks Associated With the Effects of Climate Change
−Removed: The Company may be adversely affected by global climate change or by legal, regulatory or market responses to such change.
−Removed: The physical effects of climate change could have a material adverse effect on our operations and business.
+Added: T he Company may be adversely affected by global climate change or by legal, regulatory or market responses to such change.
+Added: The physical effects of climate change could have a material adverse effect on the Company’s operations and business.
To the extent climate change causes changes in weather patterns, certain regions where the Company operates could experience increases in storm intensity, extreme temperatures, wildfires, rising sea-levels and/or drought.
−Removed: Over time, these conditions could result in increases in our operating costs or business interruptions.
−Removed: For example, our headquarters is located in an area of California where the incidence of wildfire has increased over time and may continue to increase.
−Removed: In addition, in 2023 the Company established certain emissions targets and other environmental goals and submitted them for validation to the Science
−Removed: Based Target initiative (“SBTi”).
−Removed: Failure to achieve such goals, or a perception (whether valid or invalid) of our failure to achieve such goals, could result in market, reputational, regulatory or liability risks, client dissatisfaction, reduced revenue and profitability, or shareholder lawsuits.
−Removed: If the Company is unable to achieve our environmental goals, our business and reputation may be adversely affected.
−Removed: There can be no assurance that climate change will not have a material adverse effect on our properties, operations or business.
+Added: Over time, these conditions could result in increases in the Company’s operating costs or business interruptions.
+Added: For example, the Company’s headquarters are located in areas of California where the incidence of wildfire has increased over time and may continue to increase.
+Added: In addition, in 2023 the Company established certain emissions targets and other environmental goals and submitted them for validation to the SBTi.
+Added: Failure to achieve such goals, or a perception (whether valid or invalid) of failure to achieve such goals, could result in market, reputational, regulatory or liability risks, client dissatisfaction, reduced revenue and profitability, or shareholder
+Added: If the Company is unable to achieve its environmental goals, the Company’s business and reputation may be adversely affected.
+Added: There can be no assurance that climate change will not have a material adverse effect on the Company’s properties, operations or business.
General Risks
Failure to maintain adequate financial and management processes and controls could lead to errors in the Company ’ s financial reporting.
−Removed: Failure to maintain adequate financial and management processes and controls could lead to errors in the Company’s financial reporting.
If the Company’s management is unable to certify the effectiveness of its internal controls or if its independent registered public accounting firm cannot render an opinion on the effectiveness of its internal control over financial reporting, or if material weaknesses in the Company’s internal controls are identified, the Company could be subject to regulatory scrutiny and a loss of public confidence.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.