Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

FIS US Equity

Fidelity National Information Services, Inc.Industrials · Services-Business Services, NEC · CIK 1136893 · FY ends Dec 31
$41.34
+0.76 (+1.87%)
USD · as of 2026-08-21 · marketstack

FIS · 10-K · period ended 2024-12-31

← all FIS documents
filed 2025-02-13 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1418 of 1,786392k characters rendered

fis-20241231

Table of Contents

UNITED STATES SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

________________________________________________________

Form 10-K

________________________________________________________

For the fiscal year ended December 31, 2024

Or

For the transition period from to

Commission File No. 001-16427

________________________________________________________

Fidelity National Information Services, Inc.

(Exact name of registrant as specified in its charter)

Georgia37-1490331

(State or other jurisdiction of incorporation or organization) (I.R.S. Employer Identification No.)

347 Riverside Avenue

Jacksonville, Florida32202

(Address of principal executive offices) (Zip Code)

(904) 438-6000

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Trading Name of each exchange

Title of each class Symbol(s) on which registered

Common Stock, par value $0.01 per share FIS New York Stock Exchange

0.625% Senior Notes due 2025 FIS25B New York Stock Exchange

1.500% Senior Notes due 2027 FIS27 New York Stock Exchange

1.000% Senior Notes due 2028 FIS28 New York Stock Exchange

2.250% Senior Notes due 2029 FIS29 New York Stock Exchange

2.000% Senior Notes due 2030 FIS30 New York Stock Exchange

3.360% Senior Notes due 2031 FIS31 New York Stock Exchange

2.950% Senior Notes due 2039 FIS39 New York Stock Exchange

Securities registered pursuant to Section 12(g) of the Act: None

(Title of Class)

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of "large accelerated filer," "accelerated filer," "smaller reporting company" and "emerging growth company" in Rule 12b-2 of the Exchange Act. (Check one):

Table of Contents

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management's assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant

included in the filing reflect the correction of an error to previously issued financial statements. ☒

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based

compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☒

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act) Yes ☐ No ☒

As of June 30, 2024, the last business day of the registrant's most recently completed second fiscal quarter, the aggregate market value of the registrant's common stock held by nonaffiliates was $41,321,625,726 based on the closing sale price of $75.36 on that date as reported by the New York Stock Exchange. For the purposes of the foregoing sentence only, all directors and executive officers of the registrant were assumed to be affiliates. The number of shares outstanding of the registrant's common stock, $0.01 par value per share, was 529,691,586 as of February 11, 2025.

The information in Part III hereof is incorporated herein by reference to the registrant’s Proxy Statement on Schedule 14A for the fiscal year ended December 31, 2024, to be filed within 120 days after the close of the fiscal year that is the subject of this Report.

FIDELITY NATIONAL INFORMATION SERVICES, INC.

2024 FORM 10-K ANNUAL REPORT

TABLE OF CONTENTS

Page

PART I

Item 1. Business 2

Item 1A. Risk Factors 12

Item 1B. Unresolved Staff Comments 26

Item 1C. Cybersecurity 27

Item 2. Properties 28

Item 3. Legal Proceedings 28

Item 4. Mine Safety Disclosures 28

PART II

Item 6. Reserved 30

Item 7A. Quantitative and Qualitative Disclosures About Market Risk 42

Item 8. Financial Statements and Supplementary Data 45

Item 9A. Controls and Procedures 101

Item 9B. Other Information 101

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 101

PART III

Item 10. Directors and Executive Officers of the Registrant 101

Item 11. Executive Compensation 101

Item 14. Principal Accounting Fees and Services 101

PART IV

Item 15. Exhibits and Financial Statement Schedules 101

1

Table of Contents

Unless stated otherwise or the context otherwise requires, all references to "FIS," "we," "our," "us," the "Company" or the "registrant" are to Fidelity National Information Services, Inc., a Georgia corporation, and its subsidiaries. Also, amounts in tables may not sum or calculate due to rounding.

PART I

Item 1. Business

Overview

About FIS

FIS is a financial technology company providing solutions to financial institutions, businesses and developers. We unlock financial technology to the world across the money lifecycle underpinning the world's financial systems. Our people are dedicated to advancing the way the world pays, banks and invests, by helping our clients to confidently run, grow and protect their businesses. Our expertise comes from decades of experience helping financial institutions and businesses of all sizes adapt to meet the needs of their customers by harnessing where reliability meets innovation in financial technology. Headquartered in Jacksonville, Florida, FIS is a member of the Fortune 500® and the Standard & Poor’s 500® Index. FIS is incorporated under the laws of the State of Georgia as Fidelity National Information Services, Inc., and our stock is traded under the trading symbol "FIS" on the New York Stock Exchange.

Growth and Strategy Objectives

Our growth has been driven by a number of factors, including growth of our customers' businesses, our internal development of new solutions that enhance our client offerings, and our sales and marketing efforts to expand our customer base and addressable markets. Acquisitions have also contributed additional solutions that complement or enhance our offerings, diversify our client base, expand our geographic coverage, and provide entry into new and attractive adjacent markets that align with our strategic objectives. We continue to strategically allocate resources to both internal and external growth initiatives to enhance the long-term value of our business.

Worldpay Sale Summary

On January 31, 2024, we completed the sale (the "Worldpay Sale") of a 55% equity interest in our Worldpay Merchant Solutions business to private equity funds managed by GTCR, LLC (such funds, the "Buyer"). FIS retained a non-controlling 45% equity interest in a new standalone joint venture, Worldpay Holdco, LLC ("Worldpay"), following the closing of the Worldpay Sale. Worldpay continues to provide merchant acquiring and related services to businesses of all sizes and across any industry globally, enabling them to accept, authorize and settle electronic payment transactions. In connection with the Worldpay Sale, FIS and Worldpay entered into commercial agreements, preserving a key value proposition for clients of both businesses and reducing potential dis-synergies. FIS and Worldpay also entered into additional agreements as described in Note 4 to the consolidated financial statements.

Competitive Strengths

We believe our competitive strengths include the following:

•Brand. FIS is a highly respected brand known globally for innovation and thought leadership in the financial services sector.

•Extensive Domain Expertise and Portfolio Breadth. FIS' significant expertise in the markets and domains we serve enables us to deliver a broad range of innovative software applications and flexible service offerings, ranging from managed processing arrangements, either at the client site or hosted at an FIS data center or in our private cloud, to traditional license and maintenance arrangements. Our expansive solution set allows us to bundle tailored or integrated services to compete effectively.

•Excellent and Long-term Relationships with Clients. A significant percentage of our business relates to solutions provided under multi-year, recurring contracts. The nature of these relationships allows us to develop close partnerships with our clients, resulting in high client retention rates. As the breadth of FIS' service offerings has

2

Table of Contents

expanded, we have found that our deep and broad access within our clients' organizations presents greater opportunities for cross-selling and up-selling solutions to our clients.

•Modern and Cloud-based Technologies. FIS leverages the modern architectures of our software applications and our ability to integrate many of our solutions with the solutions of others to provide customized solutions that respond to individualized client needs. We have made significant investment in modernizing our platforms and solutions and have moved substantially all of our server compute into our private cloud located in our strategic data centers, supplemented by public clouds in certain regions, to increase speed of delivery to clients and increase solution availability to industry-best levels.

•GlobalDistribution and Scale. We are a global leader in many of the markets we serve, supported by a large, knowledgeable talent pool of employees around the world. Our worldwide presence and global scale enable us to leverage our array of solution offerings, client relationships, and modern infrastructure to drive revenue growth and operating efficiency.

Strategy

Our mission is to deliver superior solutions to our clients and to expand our client base to generate sustained revenue and earnings growth for our shareholders. Our strategy to achieve this goal is built on the following pillars:

•Build, Buy, or Partner to Add Solutions to Win New Clients and Cross-sell to Existing Clients. We continue to invest in our solution portfolio through internal software development, as well as through acquisitions, equity investments and partnerships that complement and extend our existing solutions and capabilities, providing us with additional solutions to cross-sell to current clients and to capture the interest of new clients. By investing in solution innovation, we continue to expand our value proposition to our clients and prospects.

•Support Our Clients Through Innovation. Changing market dynamics, particularly in the areas of digital delivery, information security and regulation, are transforming the way our clients operate, which is driving incremental demand for our integrated solutions built around our intellectual property. As clients and prospects evaluate technology, business process changes and vendor risks, our depth of service capabilities enables us to become involved earlier in their planning and design process and assist them as they manage these changes.

•Drive Efficiency and Scalability. We strive to improve the efficiency of our operations through investments in new technologies, processes and infrastructure modernization. We also leverage a one-to-many operating model to drive high incremental margins on revenue growth, while also providing cost-effective solutions for our clients.

•Expand Distribution. Through our global sales force and strategic commercial partnerships, we drive growth through client additions and the expansion of existing client relationships in support of our clients' growth ambitions. Our clients range from large banks, financial institutions and other enterprises, including multi-national clients, to community or regional financial institutions and other businesses.

•Allocate Our Capital and Resources Strategically. As we make decisions with respect to building, buying or partnering to drive innovation in support of our clients, we prioritize the allocation of capital and other resources to the opportunities providing the highest client benefit and growth potential. We also continually review our portfolio of assets and businesses to assess their fit with our strategy and will, from time to time, decide to wind down or divest businesses or assets to redeploy capital to our areas of strategic focus. We believe that keeping our team and our capital strategically focused benefits our existing clients and our ability to win new clients. At the same time, to the extent our businesses generate excess cash, we strategically use it to repurchase shares, repay debt, pay dividends or for other corporate purposes.

Segment Information

FIS reports its financial performance based on the following segments: Banking Solutions ("Banking"), Capital Market Solutions ("Capital Markets") and Corporate and Other.

The Worldpay Merchant Solutions business included the former Merchant Solutions segment in addition to a business previously included in the Corporate and Other segment. The results of the Worldpay Merchant Solutions business have been recast as discontinued operations for all periods presented. Accordingly, the Company no longer reports the Merchant Solutions

3

Table of Contents

segment. The assets and liabilities of the Worldpay Merchant Solutions business disposal group are presented separately on the consolidated balance sheets, and the operating results have been reflected as discontinued operations for all periods presented. As such, the related results have been excluded from continuing operations and segment results. See Notes 1 and 3 to the consolidated financial statements for further information regarding the Worldpay Merchant Solutions disposal group and its discontinued operations. FIS' share of the net income of Worldpay is reported as equity method investment earnings (loss).

As a result of our ongoing portfolio assessments, the Company reclassified certain businesses from Capital Markets to Banking and to Corporate and Other during the quarter ended March 31, 2023, and reclassified certain non-strategic operations from Banking to Corporate and Other during the quarter ended December 31, 2023. The Company recast all prior-period segment information presented to reflect these reclassifications. See "Segment Information" below for additional discussion of our solutions and customers. See also Notes 6 and 22 to the consolidated financial statements for additional information about our segment revenue.

Our consolidated results generally do not reflect pronounced seasonality. However, quarterly revenue and margins for each segment may vary based on the timing of recognition of certain non-recurring revenue, including software licenses and termination fees.

For information about current trends in market demand, see "Item 7. Management's Discussion and Analysis of Financial Condition and Results of Operations - Business Trends and Conditions."

Revenue by Segment

The table below summarizes our revenue by reporting segment (in millions):

(1)During 2024, the Company revised its previously issued consolidated financial statements as of and for the annual periods ended December 31, 2023 and 2022, to correct certain immaterial misstatements. See Note 24 to the consolidated financial statements for information about our revision of prior-period consolidated financial statements.

Banking Solutions ("Banking")

The Banking segment is focused on serving financial institutions with core processing software, transaction processing software and complementary applications and services, many of which interact directly with core processing software. We sell these solutions on either a bundled or stand-alone basis. Clients in this segment include global financial institutions, U.S. regional and community banks, credit unions and commercial lenders, as well as government institutions and other commercial organizations. We provide our clients integrated solutions characterized by multi-year processing contracts that generate recurring revenue. The predictable nature of cash flows generated from the Banking segment provides opportunities for further investments in innovation, integration, information and security, and compliance in a cost-effective manner.

Our solutions in this segment include the following:

•Core Processing and Ancillary Applications. Our core processing software applications, including deposit and lending, customer management and other central management systems, are designed to run banking processes for our financial institution clients. Clients use these applications to maintain the primary records of their customer accounts. Our diverse selection of market-focused core processing software applications enables FIS to compete effectively in a wide range of markets. We continue to invest in our core modernization efforts to further differentiate our offerings for the long term. We also offer a number of solutions that are ancillary to the primary applications listed above, including branch automation, back-office support systems and compliance support.

•Digital, including Mobile and Online. Our comprehensive suite of retail and commercial applications enables financial institutions to streamline and integrate customer-facing operations with back-office processes, thereby improving customer experience across channels (e.g., branch, internet, mobile, ATM, and call centers). FIS' focus on real-time consumer access has driven significant market innovation in multi-channel, API-enabled embedded and multi-hosted solutions, underpinned by a strategy that provides tight integration and a seamless customer experience. Our innovative digital banking capabilities are now available to financial institutions with continually expanding

4

Table of Contents

functionality. Our digital offerings are integrated with core banking platforms offered by FIS and are also offered to customers of non-FIS core systems.

•Fraud, Risk Management and Compliance. Our decision solutions offer a spectrum of options that cover the account lifecycle from helping to identify qualified account applicants to managing existing customer accounts and fraud. Our applications enable Know Your Customer, new account decisioning and opening, account and transaction management, fraud management and collections. Our risk management solutions use our proprietary risk management models and data sources to assist in detecting fraud and assessing the risk of opening a new account. Our systems use a combination of advanced authentication procedures, predictive analytics, artificial intelligence modeling and proprietary and shared databases to assess and detect fraud risk for deposit, card and other transactions for financial institutions.

•Card and Retail Payments. Our card and retail payment technology solutions allow clients to issue VISA®, MasterCard® or other payment network-branded credit and debit cards or other electronic payment cards for use by both consumer and business accounts. Card-based volumes continue to increase, driven by both the number of transactions per month and the value of those transactions. We offer EMV (Europay, MasterCard and Visa) integrated circuit cards, often referred to as chip cards, as well as a variety of stored-value card types and loyalty programs, including our Premium Payback service that allows our financial institutions' customers to use loyalty points at a variety of merchant point-of-sale systems. Our integrated solutions range from card production and activation to processing to an extensive range of fraud management solutions and value-added loyalty programs designed to increase card usage and fee-based revenue for financial institutions and merchants. The majority of our programs are full service, including most of the operations and support necessary for an issuer to operate a credit card program. We do not make credit decisions for our card issuing clients. We are also a leading provider of prepaid card solutions, which include digital cards, gift cards and reloadable cards, with end-to-end solutions for the development, processing and administration of stored-value programs, including government benefit programs. Our closed-loop gift card solutions and loyalty programs provide merchants compelling solutions to drive consumer loyalty.

•Electronic Funds Transfer and Network. Our electronic funds transfer and debit card processing businesses offer settlement and card management solutions for financial institution card issuers. We offer a modern, core-agnostic payment hub with real-time fraud monitoring across payment rails. We own and operate several U.S. domestic debit, prepaid, ATM and credit networks that carry transactions for a variety of transaction modes. Our networks connect millions of cards and point-of-sale locations nationwide, providing consumers with secure, real-time access to their money. Also through our networks, clients such as financial institutions, retailers and independent ATM operators can capitalize on the efficiency, consumer convenience and security of electronic real-time payments, real-time account-to-account transfers, and strategic alliances, such as surcharge-free ATM network arrangements.

•Wealth and Retirement. We provide wealth and retirement solutions that help banks, trust companies, brokerage firms, insurance firms, retirement plan professionals, benefit administrators and independent advisors acquire, service and grow their client relationships. We provide solutions for client acquisition, transaction management, trust accounting and recordkeeping that can be deployed stand-alone, as part of an integrated wealth or retirement platform, or on an outsourced basis.

•Item Processing and Output Solutions. Our item processing solutions furnish financial institutions with the technology needed to capture data from checks, transaction tickets and other items; image and sort items; process exceptions through keying; and perform balancing, archiving and the production of statements. Our item processing services are performed at one of our multiple item processing centers located throughout the U.S. or on-site at client locations. Our extensive solutions include distributed (i.e., non-centralized) data capture, mobile deposit capture, check and remittance processing, fraud detection, and document and report management. Clients encompass banks and corporations of all sizes, from de novo banks to the largest financial institutions and corporations. We offer a number of output solutions that are ancillary to the primary solutions we provide, including print and mail capabilities, document composition software and solutions, and card personalization fulfillment solutions. Our print and mail solutions offer complete computer output solutions for the creation, management and delivery of print and fulfillment needs. We provide our card personalization fulfillment solutions for branded credit cards and branded and non-branded debit and prepaid cards.

5

Table of Contents

Capital Market Solutions ("Capital Markets")

The Capital Markets segment is focused on serving global financial services clients and corporations with a broad array of buy- and sell-side, treasury, risk management and lending solutions. Clients in this segment include asset managers, private equity firms, sell-side securities brokerage and trading firms, insurers, asset and auto financiers and other commercial organizations. Our solutions include a variety of mission-critical buy- and sell-side applications for recordkeeping, data and analytics, trading and financing, as well as corporate treasury and risk management applications. Capital Markets clients purchase our solutions in various ways including licensing and managing technology "in-house," using consulting and third-party service providers, as well as procuring fully outsourced end-to-end solutions. Our long-established relationships with many of these financial and commercial institutions generate significant recurring revenue. We have made, and continue to make, investments in modern platforms, advanced technologies, open APIs, machine learning and artificial intelligence, and regulatory technology to support our Capital Markets clients.

Our solutions in this segment include the following:

•Trading and Asset Services. We offer solutions that support our customers across the buy and sell sides of the capital markets industry, assisting them to control their front, middle and back office operations through integrated ecosystems. Our solutions support institutional investors, managers, broker-dealers, asset servicers and transfer agents across all asset classes including private equity, hedge, credit, and traditional. Our trading applications focus on advanced trade life-cycle management, including market making and risk management, cleared derivatives processing, securities processing and securities finance, tax processing, and regulatory compliance, including anti-money laundering (AML) and trade surveillance. Our Asset Servicing solutions support every stage of the investment process, from research and portfolio management to order and position management, valuation, risk management, corporate actions, reconciliation, investment accounting, investor accounting, transfer agency and client reporting. Our solutions improve both investment decision making and operational efficiency, while managing risk and increasing transparency across the industry.

•Lending. Our lending solutions offer full life-cycle commercial lending functionality from loan origination, commercial credit assessment and customer risk rating to loan servicing and data analytics. We also offer the leveraged and syndicated loan markets solutions that manage amendments, secondary market trading, deal management and bookrunning. In the asset finance space, we offer a single, end-to-end leasing platform that helps auto and equipment finance companies manage the entire financing process, supporting origination and pricing, credit decisioning, contract management, servicing and collections.

•Treasury and Risk. Our treasury solutions help chief financial officers and treasurers manage working capital by reducing risk and improving communication and response time between a company's buyers, suppliers, banks, and other stakeholders. Our end-to-end financial management framework helps bring together receivables, treasury, and payments for a single view of cash and risk, which helps our clients optimize business processes for enhanced liquidity management. Our risk portfolio of solutions manages market and credit risk and regulatory compliance for banks and actuarial risk for insurance firms.

Corporate and Other

The Corporate and Other segment consists of corporate overhead expense, certain leveraged functions and miscellaneous expenses that are not included in the operating segments, as well as certain non-strategic businesses that we plan to wind down or sell. The overhead and leveraged costs relate to corporate marketing, finance, accounting, human resources, legal, compliance and internal audit functions, as well as other costs, such as acquisition, integration and transformation-related expenses and amortization of acquisition-related intangibles, that are not considered when management evaluates revenue-generating segment performance. Our other operating income recorded in connection with our transaction services arrangements with Worldpay is also recorded in Corporate and Other.

Sales and Marketing

Our sales personnel have expertise in particular solutions, geographic markets and industry verticals, as well as across our various client segments. We believe that focusing our expertise on clients in specific markets and tailoring integrated solution sets to participants in those markets enables us to better serve our clients and makes our offerings more attractive to prospects. The majority of our prospects are identified via direct and/or indirect field sales, as well as inbound and outbound lead generation, telesales and virtual sales efforts.

6

Table of Contents

Our global marketing team develops and leads the execution of global, role-specific and geography-based strategic marketing plans in support of the segments' reputation and relationship building goals in addition to their revenue and profitability goals. Key components of our strategic plans include brand amplification and digital enablement; market and competitive research; voice of the customer and client engagement; thought leadership; integrated go-to-market programs; internal communications and readiness; journalists and social media engagement; industry analyst relations; client events; trade shows; high-touch client programs; demand generation campaigns; account- and deal-based marketing programs; collateral development and management across digital and online channels; and the launch of new products to market.

Patents, Copyrights, Trademarks and Other Intellectual Property

In general, we own the intellectual property and proprietary rights that are necessary to conduct our business and are important to our future success, including trademarks, trade names, trade secrets, copyrights and patents. We license certain items from third parties under arms-length agreements for varying terms, including some "open source" licenses.

We rely on a combination of contractual restrictions, internal security practices, patents, trade secrets, copyrights and applicable law to establish and protect our software, technology and expertise worldwide. We rely on trademark law to protect our rights in our brands. We intend to continue taking commercially reasonable measures to protect our intellectual property rights, including by legal action when necessary and appropriate.

Competition

The markets for our solutions are intensely competitive across both established companies and new industry entrants. Depending on the business line, our primary competitors include, but are not limited to, internal technology or software development departments within financial institutions or other large companies; global and regional companies providing banking, payment and capital markets services; embedded payment solution providers; securities exchanges; asset managers; card associations; clearing networks or associations; trust companies; independent computer services firms; companies that develop verticalized software applications; companies owned by global banks selling competitive solutions; companies that provide customized development, implementation and support services; emerging technology innovators and business process outsourcing companies. Many of these companies compete with us across multiple solutions, market segments and geographies to varying degrees based on solution strength and distribution strength. Competitive factors impacting the success of our solutions include the quality of the technology-based application or service, breadth of application features and functions, ease of delivery and integration, the ability to maintain, enhance and support the applications or solutions, price and overall client experience. We believe that we compete vigorously in each of these categories. In addition, we believe our domain expertise and the breadth and complementary nature of our portfolio of applications, services and integrated solutions enhances our competitiveness against companies with more limited offerings. Our ability to innovate and scale digital payments and solutions has been a competitive advantage as well.

Technology Development

Our technology development activities primarily relate to the modernization of our proprietary core processing software applications and the design and development of next generation digital solutions, processing systems, software applications and risk management platforms. We expect to continue our practice of investing an appropriate level of resources to maintain, enhance and extend the functionality of our proprietary systems and software applications, to develop new and innovative software applications and systems to address emerging technology trends in response to the needs of our clients and to enhance the capabilities of our outsourcing infrastructure. In addition, we intend to offer solutions compatible with new and emerging delivery channels.

As part of our technology development process, we evaluate current and emerging technology for compatibility with our existing and future software platforms. To this end, we engage with various hardware and software vendors in the evaluation of various new and existing technologies. Where appropriate, we use third-party technology components in the development of our software applications and service offerings. We typically utilize enterprise license agreements or strive to ensure that either alternative suppliers or transfer rights exist in order to ensure the continuity of supply of third-party technology components used in the development of our software applications and service offerings. As a result, we are not materially dependent upon any third-party technology components. Third-party software may be used for highly specialized business functions depending on our ability to develop the functionality internally within time and budget constraints. Additionally, third-party software may be used for routine, commonplace functions within a technology platform environment. We work with our clients to determine the appropriate timing and approach to introduce technology or infrastructure changes to our solutions.

7

Table of Contents

Government Regulation

Our solutions are subject to a broad range of complex federal, state, and international regulations and requirements, as well as requirements under the rules of self-regulatory organizations including, without limitation, federal truth-in-lending and truth-in-savings rules, federal, state and international money transmission laws, state cybersecurity protection laws, data protection and privacy laws, cyber resilience laws, artificial intelligence laws, usury laws, laws governing state trust charters, the Equal Credit Opportunity Act, the Electronic Funds Transfer Act, the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, the Bank Service Company Act, the Bank Secrecy Act, the USA Patriot Act, the United Kingdom ("U.K"). Money Laundering Regulations, the U.K. Proceeds of Crime Act, the U.K. Criminal Finances Act, the U.K. Sanctions and Anti-Money Laundering Act, the U.K. Economic Crime and Corporate Transparency Act, European Union ("E.U.") Anti-Money Laundering Directives, the Internal Revenue Code, the Employee Retirement Income Security Act, the Health Insurance Portability and Accountability Act, the Community Reinvestment Act and the Dodd-Frank Wall Street Reform and Consumer Protection Act (the "Dodd-Frank Act"), the Securities Exchange Act of 1934, the Investment Advisors Act of 1940 (the "1940 Act"), anti-corruption laws including the U.S. Foreign Corrupt Practices Act of 1977 (the "FCPA") and the U.K. Bribery Act 2010 (the "U.K. Bribery Act"), the rules and regulations of the Financial Industry Regulatory Authority ("FINRA"), the Securities and Exchange Commission ("SEC"), the Federal Financial Institutions Examination Council ("FFIEC"), the Consumer Financial Protection Bureau ("CFPB"), the Financial Conduct Authority in the U.K. ("FCA"), the Central Bank of Ireland in the Republic of Ireland ("CBI"), the Commission de Surveillance du Secteur Financier in Luxembourg ("CSSF"), the Jersey Financial Services Commission in Jersey, Channel Islands ("JFSC") and state financial services regulators (including enforcement of state cybersecurity laws). The compliance of our solutions with these and other applicable laws and regulations depends on a variety of factors, including the manner in which our clients use them. In some cases, we are directly subject to regulatory oversight and examination. In other cases, our clients are contractually responsible for determining what is required of them under applicable laws and regulations and utilize our solutions to achieve compliance with those laws and regulations. In some cases, we may be required to support our clients in achieving compliance with certain laws and regulations by virtue of the services that we provide to them. For example, under the E.U. Digital Operational Resilience Act ("DORA"), which came into force in January 2025, our E.U. financial entity clients will require us, as a third-party provider of information and communication technology services, to contract with and manage our relationships with them (and, where applicable, our relationships with critical third-party technology vendors in our supply chain) in accordance with the requirements of DORA. Failure to support our clients in achieving compliance with DORA and similar global regulatory regimes may cause us to lose revenue or clients and/or result in damage to our reputation, and may also attract scrutiny from regulators. In any event, the failure of our solutions to comply with applicable laws and regulations may result in suspension or revocation of permission-based regulatory licenses, restrictions on our ability to provide those solutions, the imposition of civil fines and/or criminal penalties, loss of client trust, and/or reputational damage. Further, regulatory authorities have the power to, among other things, enjoin "unsafe or unsound" practices, require affirmative actions to correct any violation or practice, issue administrative orders that can be judicially enforced and direct the sale of subsidiaries or other assets. We may be adversely affected by increased regulatory scrutiny or related negative publicity.

The principal areas of regulation impacting our business are the following:

•Oversight by Banking Regulators. As a provider of electronic data processing and back-office services to financial institutions, FIS is subject to regulatory oversight and examination by the FFIEC, an interagency body of federal banking regulators including the Federal Deposit Insurance Corporation ("FDIC"), the Office of the Comptroller of the Currency ("OCC"), the Board of Governors of the Federal Reserve System ("FRB"), the National Credit Union Administration ("NCUA") (collectively, the Federal Banking Agencies or "FBA") and the CFPB, including as part of the Multi-Regional Data Processing Servicer ("MDPS") program. The MDPS program includes technology suppliers that provide mission-critical applications for a large number of financial institutions that are regulated by multiple regulatory agencies. Periodic information technology examination assessments are performed using FFIEC Interagency guidelines to identify potential risks that could adversely affect serviced financial institutions, determine compliance with applicable laws and regulations that affect the services provided to financial institutions, and ensure the solutions we provide to financial institutions do not create systemic risk to the banking system or impact the safe and sound operation of the financial institutions for which we process. In addition, independent auditors annually review several of our operations to provide reports on internal controls for our clients. We are also subject to review and examination by state and international regulatory authorities under state and foreign laws and rules that regulate many of the same activities that are described above, including electronic data processing, payments and back-office services for financial institutions and the use of consumer information.

8

Table of Contents

Our U.S.-based wealth and retirement business holds a charter in the state of Georgia, which makes us subject to the regulatory compliance requirements of the Georgia Department of Banking and Finance. As a result, we are also authorized to provide trust services in various additional states subject to additional applicable state regulations.

•Payment Services Oversight. Our payment services businesses provide technology services to U.S. financial institutions and are, therefore, subject to oversight and examination by the FFIEC. Our payment services businesses are also subject to regulation, supervision, and enforcement authority of numerous governmental and regulatory bodies in the jurisdictions in which they operate, which include the CFPB and U.S. state regulators. These various regulatory regimes require compliance in respect of many aspects of our payment services businesses including without limitation corporate governance and oversight functions, capital requirements, liquidity, safeguarding, fee regulation adherence, technology and cyber resilience, anti-money laundering and sanctions.

•Anti-Money Laundering. The Company is subject to, both directly and indirectly, various anti-money laundering laws and regulations such as the Bank Secrecy Act in the United States and the Money Laundering Regulations and Proceeds of Crime Act in the U.K. These laws, among other requirements, impose obligations to develop and implement risk-based anti-money laundering programs, file regulatory reports on large cash transactions and suspicious activity, and collect and maintain certain records related to customers and transactions. Many U.S. states have similar laws that overlap with, and in some cases diverge from, U.S. federal and international laws. While these federal, state and international laws are broadly consistent, there may be circumstances where the requirements of a particular jurisdiction conflict with those of other jurisdictions. As these laws continue to develop and expand, our investment in compliance with these laws continues to grow, as does the cost of ongoing compliance.

•Sanctions. The Company is subject to certain U.S. federal, state and international economic and trade sanctions programs, such as those that are administered by the U.S. Treasury's Office of Foreign Assets Control (referred to as "OFAC"), which prohibit or restrict transactions to or from, or dealings with, specified countries and regions, their governments, and in certain circumstances, their nationals, and with individuals and entities that are specially-designated nationals, narcotics traffickers, and terrorists or terrorist organizations. Similar programs exist in a number of other jurisdictions, most notably those administered by the Office of Financial Sanctions Implementation ("OFSI") in the U.K., E.U. sanctions, and United Nations sanctions. We have implemented policies, procedures, and internal controls that are designed to comply with global economic sanctions programs which are increasingly complex and rapidly evolving in response to geopolitical events. Those policies and procedures require the screening of third parties with which the Company does business, including clients and vendors, and transactions where appropriate.

•Anti-Corruption. The Company is subject to applicable anti-corruption laws, including the FCPA and the U.K. Bribery Act, in the jurisdictions in which it operates. Anti-corruption laws generally prohibit offering, promising, giving, or authorizing others to give, anything of value, either directly or indirectly, to a government official or private party in order to influence official action or otherwise to gain an unfair business advantage, such as to obtain or retain business. The Company has implemented policies, procedures, training and internal controls that are designed to comply with such laws, rules and regulations.

•Privacy and Data Protection. The Company is subject to an increasing number of privacy and data protection laws, regulations and directives globally, including the General Data Protection Regulation ("GDPR") in the E.U., the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Personal Data Privacy and Online Monitoring Act ("CTDPA"), the Utah Consumer Privacy Act, the Gramm-Leach-Bliley Act ("GLBA"), the Fair Credit Reporting Act ("FCRA"), and the Health Insurance Portability and Accountability Act ("HIPAA") in the United States; the U.K.'s General Data Protection Regulation ("U.K. GDPR") and Data Protection Act 2018; the General Personal Data Protection Act ("LGPD") in Brazil; the China Personal Information Protection Law ("PIPL"); and the Japanese Act on the Protection of Personal Information ("APPI") (referred to collectively as "Privacy Laws"). Many of these Privacy Laws place restrictions on the Company's ability to efficiently transfer, access and use personal data across its business. The legislative and regulatory landscape for privacy and data protection continues to evolve.

Our financial institution clients operating in the U.S. are required to comply with privacy regulations imposed under the GLBA and numerous similar state laws. GLBA and those state laws place restrictions on the use of non-public personal information. All financial institutions must disclose detailed privacy policies to their customers and offer them the opportunity to direct the financial institution not to share information with third parties. The regulations under GLBA, however, permit financial institutions to share information with non-affiliated parties who perform services for the financial institutions. As a provider of solutions to financial institutions, we are required to comply with the

9

Table of Contents

Privacy Laws and are bound by the same limitations on disclosure of the information received from our clients as apply to the financial institutions themselves. A determination that there have been violations of Privacy Laws could expose us to significant damage awards, fines and other penalties that could, individually or in the aggregate, materially harm our business and reputation. Certain operations of the Company are also subject to the newer, comprehensive, U.S. state-level Privacy Laws that provide consumers with additional data protection rights, including the right to be informed about the personal information collected by third parties and the use of that personal information, and which also impose obligations on companies in connection with the use of personal information.

The Company is subject to the E.U.’s GDPR, which applies to all organizations processing the personal data of individuals in the E.U., regardless of where such organization is based. The GDPR has heightened our privacy and data protection compliance obligations, impacted our businesses' collection, processing and retention of personal data and imposed stricter standards for reporting data breaches.

•Oversight by Securities Regulators. Our subsidiary that conducts our broker-dealer business in the U.S. is registered as a broker-dealer with the SEC, is a member of FINRA, and is registered as a broker-dealer in numerous states. Our broker-dealer is subject to regulation and oversight by the SEC. In addition, FINRA, a self-regulatory organization that is subject to oversight by the SEC, adopts and enforces rules governing the conduct, and examines the activities, of its member firms, including our broker-dealer. State securities regulators and various exchanges, including the New York Stock Exchange, also have regulatory or oversight authority over our broker-dealer. Broker-dealers are subject to regulations that cover all aspects of the securities business, including sales methods, trade practices among broker-dealers, public and private securities offerings, use and safekeeping of customers' funds and securities, capital structure, record keeping, the financing of customers' purchases and the conduct and qualifications of directors, officers and employees. In particular, as a registered broker-dealer and member of a self-regulatory organization, we are subject to the SEC's uniform net capital rule, Rule 15c3-1. Rule 15c3-1 specifies the minimum level of net capital a broker-dealer must maintain and also requires that a significant part of a broker-dealer's assets be kept in relatively liquid form. The SEC and various self-regulatory organizations impose rules that require notification when net capital falls below certain predefined criteria, limit the ratio of subordinated debt to equity in the regulatory capital composition of a broker-dealer and constrain the ability of a broker-dealer to expand its business under certain circumstances. Additionally, the SEC's uniform net capital rule imposes certain requirements that may have the effect of prohibiting a broker-dealer from distributing or withdrawing capital and requiring prior notice to the SEC for certain withdrawals of capital.

Our subsidiaries also include an SEC-registered transfer agent. Our registered transfer agent is subject to the Securities Exchange Act of 1934 and the rules and regulations promulgated thereunder. These laws and regulations generally grant the SEC and other supervisory bodies broad administrative powers to address non-compliance with regulatory requirements. Sanctions that may be imposed for non-compliance with these requirements include the suspension of individual employees, limitations on engaging in certain activities for specified periods of time or for specified types of clients, the revocation of registrations, other censures and significant fines.

Subsidiaries engaged in activities outside the U.S. are regulated by various government agencies in the particular jurisdiction where they are chartered, incorporated and/or conduct their business activity. For example, pursuant to the U.K. Financial Services and Markets Act 2000 ("FSMA"), certain of our subsidiaries are subject to regulations promulgated and administered by the FCA. The FSMA and rules promulgated thereunder govern all aspects of the U.K. investment business, including sales, research and trading practices, provision of investment advice, use and safekeeping of client funds and securities, regulatory capital, recordkeeping, margin practices and procedures, approval standards for individuals, financial crime systems and controls, periodic reporting and settlement procedures.

•Money Transfer. Elements of our cash access and money transmission businesses are registered as a Money Services Business and are subject to various federal, state and international laws governing money transmission, including but not limited to the USA PATRIOT Act and reporting requirements of the Bank Secrecy Act, as well as various U.S. federal, state and international sanctions requirements. These businesses may also be subject to certain state and local licensing requirements. The Financial Crimes Enforcement Network, state attorneys general, and other agencies have enforcement responsibility over laws relating to money laundering, currency transmission, and licensing. In applicable states, we have obtained money transmitter licenses. However, changes to state money transmission laws and regulations, including changing interpretations and the implementation of new or varying regulatory requirements, may result in the need for additional or expanded money transmitter licenses, additional capital allocations or changes in the way in which we deliver certain solutions.

10

Table of Contents

•Consumer Reporting and Protection. Our decision solutions subsidiary, ChexSystems, maintains a database of consumer information used to provide various account opening services, including credit scoring analysis, and is subject to the Federal Fair Credit Reporting Act ("FCRA") and similar state laws. The FCRA regulates consumer reporting agencies ("CRAs"), including ChexSystems, and governs the accuracy, fairness, and privacy of information in the files of CRAs that engage in the practice of assembling or evaluating certain information relating to consumers for certain specified purposes. CRAs are required to follow reasonable procedures to ensure maximum possible accuracy of information concerning the individual to whom the report relates and, if a consumer disputes the accuracy of any information in the consumer's file, to conduct a reasonable investigation within statutory timelines. The FCRA imposes many other requirements on CRAs and users of consumer report information. Regulatory enforcement of the FCRA is under the purview of the United States Federal Trade Commission, the CFPB, and state attorneys general, acting alone or in concert with one another. CRAs are also regulated by a number of states, including New York, with consumer reporting laws that are not pre-empted by the FCRA. In furtherance of our objectives of data accuracy, fair treatment of consumers, protection of consumers' personal information, and compliance with these laws, we have made considerable investment to maintain a high level of security for our computer systems in which consumer data resides, and we maintain consumer relations call centers to facilitate accurate and timely handling of consumer requests for information and disputes. We also are focused on ensuring our operating environments safeguard and protect consumers' personal information in compliance with these laws.

Our consumer reporting and consumer-facing businesses are subject to CFPB Bulletin 2013-7 (a successor to the former Regulation AA - Unfair Deceptive Acts or Practices), which defines Unfair, Deceptive or Abusive Acts or Practices ("UDAAP"). This specific bulletin states that UDAAPs can cause significant financial injury to consumers, erode consumer confidence, and undermine fair competition in the financial marketplace. Original creditors and other covered persons and service providers under the Dodd-Frank Act involved in collecting debt related to any consumer financial product or service are subject to the prohibition against UDAAPs in the Dodd-Frank Act.

In addition, our U.K. regulated entity, Platform Securities LLP, is required to comply with the FCA’s Consumer Duty (the "Duty") in connection with its Wealth business. The Duty sets high standards of consumer protection across financial services and requires firms to put their customers' needs first.

•Debt Collection. Our collection services are subject to the Federal Fair Debt Collection Practices Act and various state collection laws and licensing requirements. The Federal Trade Commission, as well as state attorneys general and other agencies, have enforcement responsibility over the collection laws, as well as the various credit reporting laws.

The foregoing list of laws and regulations to which our Company is subject is not exhaustive, and the regulatory framework governing our operations changes continuously. Enactment of new laws and regulations may increasingly affect the operations of our business, directly and indirectly, which could result in substantial regulatory compliance costs, litigation expense, adverse publicity, and/or loss of revenue.

Human Capital Management

Employee Population

As of December 31, 2024, we had more than 50,000 employees, including over 32,000 employees principally employed outside of the U.S. None of our U.S. workforce currently is unionized. Approximately 6,000 of our employees, primarily in Brazil and Europe, are represented by labor unions or works councils as of December 31, 2024.

Health and Safety

The health and safety of our employees is a key priority. We have implemented a comprehensive wellness program focused on all aspects of employee wellness – physical, mental, social, and financial. Initiatives under this program are designed to promote healthy lifestyle habits.

We continue to operate FIS Cares, a global employee-funded giving program designed to help our employees in times of need. We remain committed to providing a safe working environment that minimizes health risks and prioritizes physical safety.

11

Table of Contents

Corporate Culture

Our culture stems from embracing our corporate values as we work together to win as one team, lead with integrity and strive to "be the change" for our employees, clients and communities. We believe that inclusion and belonging are at the core of our corporate values. Our focus on continuous learning and a respectful, inclusive environment helps us use our collective strengths to innovate and deliver the best solutions for our clients and partners. The Chief Executive Officer and the Chief People Officer regularly update our Board of Directors on human capital management and culture.

Talent Management

Along with our clients and communities, our employees are primary stakeholders in our organization, and so we place a strategic priority on developing our talent and fostering a culture aligned with our corporate values and in which employees receive the support needed to grow and develop their skills and capabilities.

Our talent development program provides an enterprise-wide, systematic foundation for career development tied to learning paths that enable skills development. Our talent practices are based on a future-focused development approach to equip FIS leaders with the skills required to enable business growth and exceed the needs of our clients. Our employees have a learning roadmap to ‘Build our Leaders of Tomorrow’ which is supported by access to an extensive selection of online self-paced learning resources, virtual instructor-led and face-to-face development offerings, and targeted development programs for high-potential and senior management employees. We engage in executive-level succession planning and provide extensive opportunities to apply for open roles within our organization. Our talent development practices are underpinned by a comprehensive talent planning and feedback culture.

Available Information

Our website address is www.fisglobal.com. We make our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, and Current Reports on Form 8-K, and any amendments to those reports, available, free of charge, on that website as soon as reasonably practicable after we file or furnish them to the SEC. Our Corporate Governance Policy and Code of Business Conduct and Ethics are also available on our website and are available in print, free of charge, to any shareholder who mails a request to the Corporate Secretary, Fidelity National Information Services, Inc., 347 Riverside Avenue, Jacksonville, FL 32202 USA. Other corporate governance-related documents can be found at our website as well. However, the information found on our website is not a part of this or any other report.

Item 1A. Risk Factors

In addition to the normal risks of business, we are subject to significant risks and uncertainties, including those listed below and others described elsewhere in this Annual Report on Form 10-K. Any of the risks described herein, as well as risks currently unknown or immaterial, could result in a significant adverse effect on our business, financial condition or results of operations.

Risks Related to Our Business and Operations

Security breaches, privacy breaches, cyberattacks, unintentional disclosures of confidential information, third-party breaches, service outages, or a failure to comply with information security laws or regulations, contractual provisions, or industry security requirements by us, our vendors, clients, or technology partners could harm our business by disrupting delivery of services, exposing sensitive or confidential information, or damaging our reputation, any of which could result in a breach of one or more client contracts or regulatory investigations, enforcement actions, fines or litigation.

Cybersecurity is fundamental to our complex, global business. We and our vendors, service providers, technology partners, and clients electronically receive, process, store and transmit sensitive and confidential information of our business partners, clients and such clients' customers. We collect consumer personal data, such as names and addresses, Social Security Numbers, driver’s license numbers, financial account numbers, transactional history, cardholder data and payment history records. Such information is necessary to support our clients' transaction processing and to conduct our check authorization and collection businesses. We also collect personal data from our employees and contractors as necessary to support those relationships, comply with legal obligations, manage our workforce, and provide compensation and benefits. Our information systems and networks are dependent upon hardware, software, communication infrastructure and other technological components that are both developed by us and provided by third parties. These components sometimes require patches, updates, or remediation of known or potential vulnerabilities. Implementation challenges in timely completing these tasks can lead to security vulnerabilities that expose us, our systems and data to potential compromise or interruption. Our information systems are also

12

Table of Contents

vulnerable to human error as well as malicious insider threats. Finally, the systems we rely on, which include hardware and software manufactured, developed or operated by third-party vendors and service providers, have in the past been subject to, and may in the future be subject to, cyber attacks or security incidents due to employee error or malfeasance, software bugs, hardware malfunctions or other security vulnerabilities.

The uninterrupted operation of information systems operated by us, our vendors and service providers, and other third parties, as well as the confidentiality of the customer or consumer information that resides on such systems, is critical to the successful operation of our Company. For that reason, security or privacy breaches are some of the principal operational risks we face as a provider of services to financial institutions and businesses. Like other such providers, we are a regular target of attempts to identify and exploit system vulnerabilities and/or penetrate or bypass our security measures to gain unauthorized access to our networks and systems. If we fail to maintain an adequate security infrastructure, adapt to emerging security threats (such as the use of artificial intelligence by threat actors in furtherance of cyber attacks), regularly identify security vulnerabilities, prevent unauthorized access, identity theft or other cybersecurity risks (e.g., distributed denial of service, ransomware, and other cyber attacks), manage vendor or supply chain cybersecurity risks, adequately train users of our information systems, or implement sufficient security standards and technology to protect against security or privacy breaches, then the confidentiality, integrity or availability of the information we secure could be compromised. Unauthorized access to, or abuse of authorized access to, our computer systems or databases or our vendors' computer systems or databases could result in the theft or publication of confidential information and personal data, the deletion or modification of records, disruption of service delivery, installation of malware, and the potential need to pay ransom or otherwise cause interruptions in our operations. These issues could give rise to legal actions from clients and/or such clients' customers, regulatory investigations or enforcement activity, losses and expenses associated with such events, and damage to our reputation. Because we serve a diverse client base with different technology and service needs, we must continue to enhance our ability to manage the risks from the resulting diversity in potential security attacks.

As a provider of services to financial institutions and businesses, we are bound by many of the same limitations on disclosure of the information we receive from clients that apply to the clients themselves. If we fail to comply with these regulations and industry security requirements, including those imposed by the payment card industry through its digital security standards and other rules, we could be exposed to damages from legal actions from clients and/or their customers, governmental proceedings, public disclosure and consumer notification requirements, and the imposition of significant fines or prohibitions on providing services. We operate in a highly regulated environment and are subject to a myriad of complex, evolving regulations and standards, including cybersecurity and privacy laws, regulations and industry standards. In addition, if more restrictive privacy laws, data protection rules or industry security requirements are adopted in the future on the federal or state level, or by a non-U.S. jurisdiction in or from which we serve clients, or by a specific industry body, those changes could have an adverse impact on our Company through increased costs or by imposing changes or inefficiencies on business processes.

A material privacy or security incident would trigger SEC disclosure obligations and could trigger other applicable disclosure requirements, or be disclosed publicly, even if there is no legally required disclosure. Incident disclosure may increase the risks of private lawsuits or government enforcement action related to incidents, increase attention from malicious actors, and lead to greater regulatory scrutiny. The occurrence of any such incidents, and the related responses (if any) by regulators or third parties, may result in adverse publicity and reputational harm to us.

If we are unable, or appears to be unable, to prevent cybersecurity or privacy breaches, we risk reputational damage. Our existing clients could lose confidence in our information systems and consequently choose to terminate their agreements with us. Such reputational harm could also inhibit our ability to attract new clients; potentially increase government, regulatory, or media scrutiny; or give rise to new regulatory requirements that adversely affect our ability to do business in one or more parts of the world.

If we fail to innovate or adapt our solutions to changes in technology or in the marketplace, or if our ongoing efforts to upgrade or implement our technology are not successful, we could lose clients, or our clients could lose customers, and we could have difficulty attracting new clients for our solutions.

The markets for our solutions are characterized by constant technological changes, frequent introductions of new solutions and evolving industry standards. Our future success will be significantly affected by our ability to enhance our current solutions and develop and introduce new solutions and services that address the increasingly sophisticated needs of our clients and their customers. In addition, as more of our revenue and market demand shifts to software as a service ("SaaS"), business process as a service ("BPaaS"), cloud, and new emerging technologies, the need to keep pace with rapid technology changes becomes more acute. These initiatives carry the risks associated with any new solution development effort, including cost overruns,

13

Table of Contents

delays in delivery and implementation, and performance issues. There can be no assurance that we will be successful in developing, marketing and selling new solutions or enhancements that meet these changing demands. If we are not successful in these efforts, we could lose clients, or our clients could lose customers, and we could have difficulty attracting new clients for our solutions. Any of these developments could have an adverse impact on our future revenue and/or business prospects.

We operate in a competitive business environment; if we are unable to compete effectively, our business, financial condition or results of operations may be adversely affected.

The market for our solutions is intensely competitive. Our competitors in Banking and Capital Markets vary in size and in the scope and breadth of the solutions and services they offer. Some of our competitors have substantial resources. We face direct competition from third parties, and because many of our larger potential clients have historically developed their key applications in-house and, therefore, view their system requirements from a make-versus-buy perspective, we also often compete against our potential clients' in-house capacities. In addition, the markets in which we compete have recently attracted increasing competition from smaller start-ups with emerging technologies which are receiving increasing investments, as well as global banks (and businesses controlled by combinations of global banks) and global internet companies that are introducing competitive solutions and services into the marketplace, particularly in the payments area. Emerging technologies and increased competition may also have the effect of unbundling bank solutions and may result in displacing solutions that we are currently providing from our legacy systems. International competitors are also now targeting and entering the U.S. market with greater force. There can be no assurance that we will be able to compete successfully against current or future competitors or that the competitive pressures we face in the markets in which we operate will not materially adversely affect our business, financial condition, or results of operations.

Global economic, political and other conditions, including business cycles and consumer confidence, as well as geopolitical conflicts, may adversely affect our clients or trends in consumer spending, which may adversely impact the demand for our services and our revenue and profitability.

A significant portion of our revenue is derived from transaction processing fees. The global transaction processing industries depend heavily upon the overall level of consumer, business and government spending. Any change in economic factors, including a sustained deterioration in general economic conditions or consumer confidence, particularly in the U.S., or inflation and increases in interest rates in key countries in which we operate may adversely affect consumer spending, consumer debt levels and credit and debit card usage, and as a result, adversely affect our financial performance by reducing the number or average purchase amount of transactions that we service. In addition, the direct and indirect effects of geopolitical conflicts, such as the Russia-Ukraine war and conflicts in the Middle East, have adversely affected global economic activity and transaction processing volumes (particularly in our former Merchant segment). Worsening, or future, geopolitical conflicts could materially adversely affect global economic activity and our transaction volumes in the future.

When there is a slowdown or downturn in the economy, a drop in stock market levels or trading volumes, or an event that disrupts the financial markets, our business, financial condition or results of operations may suffer for a number of reasons. Customers may react to worsening conditions by reducing or delaying their capital expenditures in general or by specifically reducing or delaying their information technology spending. In addition, customers may seek to curtail trading operations or to lower their costs by renegotiating vendor contracts. Moreover, competitors may respond to market conditions and attempt to lure away our customers by lowering prices on existing solutions or by offering new, lower-cost solutions. Any further protective trade policies or actions taken by the U.S. may also result in other countries reducing, or making more expensive, services permitted to be provided by U.S.-based companies. If any of these circumstances remain in effect for an extended period of time, there could be a material adverse effect on our business, financial condition or results of operations.

Our business, financial condition or results of operations could be adversely affected by business interruptions, errors or failures in connection with our or third-party information technology and communication systems and other software and hardware used in connection with our business, or by design errors in the software solutions we offer, or more generally, by the unavailability of third-party vendors' services that we need to operate our business effectively.

Many of our services are based on sophisticated software and computing systems, and we may encounter delays when developing new technology solutions and services. Further, the technology solutions underlying our services have occasionally contained, and may in the future contain, undetected errors or defects when first introduced or when new versions are released. In addition, we may experience difficulties in installing or integrating our technologies on platforms used by our clients, or our clients may cancel a project after we have expended significant effort and resources to complete an installation. Finally, our systems and operations have been, and in the future could be, exposed to damage or interruption from fire, floods, severe weather events, natural disasters, power loss, telecommunications failure, unauthorized entry and computer viruses. Defects in

14

Table of Contents

our technology solutions or those of our third-party partners or elsewhere in the global cyber environment, errors or delays in the processing of electronic transactions, or other difficulties have resulted, and in the future could result, in (i) interruption of business operations; (ii) delay in market acceptance; (iii) additional development and remediation costs; (iv) diversion of technical and other resources; (v) loss of clients; (vi) negative publicity; or (vii) exposure to liability claims. Any one or more of the foregoing could have an adverse effect on our business, financial condition or results of operations. We cannot be certain that control measures, including system redundancies, security controls, and application development and testing controls, will be successful in preventing disruption or limiting our exposure.

Further, most of the solutions we offer are very complex software systems that are regularly updated. No matter how careful the design and development, complex software often contains errors and defects when first introduced and when major new updates or enhancements are released. If errors or defects are discovered in current or future solutions, then we may not be able to correct them in a timely manner, if at all. In our development of updates and enhancements to our software solutions, we may make a major design error that causes the solution to operate incorrectly or less efficiently. The failure of software to perform properly could result in the Company and its clients being subjected to losses or liability, including censures, fines, or other sanctions by the applicable regulatory authorities, and we could be liable to parties who are financially harmed by those errors. In addition, such errors could cause the Company to lose revenue, lose clients or suffer damage to its reputation.

In addition, we generally depend on a number of third parties, both in the United States and internationally, to supply elements of our systems, computers, research and market data, connectivity, communication network infrastructure, other equipment and related support and maintenance. We cannot be certain that any of these third parties will be able to continue providing these services to meet our evolving needs effectively. If our vendors, or in certain cases vendors of our customers, fail to meet their obligations, provide poor or untimely service or suffer operational disruptions, and we are unable to make alternative arrangements for the provision of these services, then we may in turn fail to provide our services or to meet our obligations to our customers, and our business, financial condition or results of operations could be adversely affected.

Entity mergers or consolidations and business failures in the banking and financial services industry could adversely affect our business by eliminating some of our existing and potential clients and making us more dependent on a more limited number of clients.

There has been, and may continue to be, substantial consolidation activity in the banking and financial services industry. In addition, certain financial institutions that experienced negative operating results, including some of our clients, have failed, leading to further consolidation. These consolidations, including those spurred by failures, reduce our number of potential clients and may reduce our number of existing clients, which could adversely affect our revenue, even if the events do not reduce the aggregate activities of the consolidated entities. Further, if our clients or our partners across any of our businesses fail, merge with or are acquired by other entities that are not our clients or our partners, or that use fewer of our services, they may discontinue or reduce use of our services. It is also possible that larger financial institutions resulting from consolidations would have greater leverage in negotiating terms or could decide to perform in-house some or all of the services we currently provide or could provide. Any of these developments could have an adverse effect on our business, financial condition or results of operations.

Failure to obtain new clients or renew client contracts on favorable terms could adversely affect our business, financial condition or results of operations.

We may face pricing pressure in obtaining and retaining our clients. Larger clients may use their negotiating leverage to seek price reductions from us when they renew a contract, when a contract is extended, or when the client's business has significant volume changes. Larger clients may also reduce services if they decide to move services in-house. Further, our smaller and mid-size clients may also exert pricing pressure, particularly upon renewal, due to competition or other economic needs or pressures being experienced by the client. On some occasions, this pricing pressure results in lower revenue from a client than we had anticipated based on our previous agreement with that client. This reduction in revenue could adversely affect our business, financial condition or results of operations.

Bank failures or sustained financial market disruptions could adversely affect our business, financial condition and results of operations.

We regularly maintain domestic cash deposits in banks that are not subject to insurance protection against loss or exceed the deposit limits. We also maintain cash deposits in foreign banks where we operate, some of which are not insured or are only partially insured. The failure of a bank, or events involving limited liquidity, defaults, non-performance or other adverse conditions in the financial or credit markets impacting financial institutions at which we maintain balances, or concerns or

15

Table of Contents

rumors about such events, may lead to disruptions in access to our bank deposits or otherwise adversely impact our liquidity and financial performance. There can be no assurance that our deposits in excess of the insurance limits will be backstopped by the U.S. or applicable foreign government, or that any bank or financial institution with which we do business will be able to obtain needed liquidity from other banks, government institutions or otherwise in the event of a failure or liquidity crisis.

Our clients, including those of our clients that are banks, may be similarly adversely affected by any bank failure or other event affecting financial institutions. Any resulting adverse effects to our clients' liquidity or financial performance could reduce the demand for our services or affect our allowance for credit losses and collectability of trade receivables. A significant change in the liquidity or financial position of our clients could cause unfavorable trends in receivable collections and cash flows and may necessitate additional allowances for anticipated losses. Any such additional allowances could materially and adversely affect our business, financial condition or results of operations.

In addition, instability, liquidity constraints or other distress in the financial markets, including the effects of bank failures, defaults, non-performance or other adverse developments that affect financial institutions, could impair the ability of one or more of the banks participating in our current or any future credit facilities to honor their commitments. This could have an adverse effect on our business if we were not able to replace those commitments or to locate other sources of liquidity on acceptable terms.

The Company is subject to regulation, supervision, and enforcement authority of numerous governmental and regulatory bodies in the jurisdictions in which it operates.

Because the Company is a technology service provider to U.S. financial institutions, it is subject to regular oversight and examination by the FBA, each agency of which is a member of the FFIEC, an interagency body of federal banking regulators. The FBA have broad discretion in the implementation, interpretation and enforcement of banking and consumer protection laws and use the FFIEC's uniform principles, standards and report forms in their review of bank service providers like FIS. A failure to comply with these laws, or a failure to meet the supervisory expectations of the banking regulators, could result in adverse action against the Company. The regulators have the authority to, among other things, enjoin "unsafe or unsound" practices; require affirmative actions to correct any violation or practice; issue administrative orders that can be judicially enforced; direct the sale of subsidiaries or other assets; and assess civil money penalties.

The Company is also subject to ongoing supervision by regulatory and governmental bodies across the world, including economic and conduct regulators, such as OFAC, BIS and FinCEN in the U.S., the FCA, OFSI and OTSI in the U.K., and regulatory and governmental bodies responsible for issuing anti-money laundering, anti-bribery, and global economic sanctions and export control regulations. These various regulatory regimes require compliance across many aspects of our activities. Among other things, such regulatory and financial crime compliance obligations require certain capital requirements; safeguarding, training, authorization, supervision and oversight of personnel, systems, processes, controls, and documentation; and reporting to government entities. As we continue to grow our global business around the world, we will become subject to additional countries' regulations governing critical third-party service providers, financial crime and other regulatory areas. Our failure to comply with any of these requirements could result in the suspension or revocation of a license, loss of consumer confidence, and/or the imposition of civil or criminal penalties.

We also have business operations that store, process or transmit consumer information or have direct relationships with consumers. As such, we are obligated to comply with regulations, including, but not limited to, the FCRA, the Federal Fair Debt Collection Practices Act and applicable privacy requirements, and we are subject to examination and oversight by the CFPB. In addition, our wealth and retirement business holds a charter in the state of Georgia, which obligates us to comply with regulatory compliance requirements of the Georgia Department of Banking and Finance. Our U.S. wealth and retirement business is required to hold certain levels of regulatory capital as defined by the state banking regulator in Georgia. In the U.K., our Platform Securities and broker-dealer businesses are regulated by the FCA and are also subject to further regulatory capital requirements.

The Consumer Financial Protection Bureau ("CFPB") continues to establish rules and regulations for regulating financial and non-financial institutions and providers to those institutions to ensure adequate protection of consumer privacy and to ensure consumers are not impacted by deceptive business practices, as well as to provide examination and supervisory authority over consumer reporting agencies, including ChexSystems. These rules and regulations govern our clients or potential clients and also govern certain of our businesses. These regulations have resulted, and may further result, in the need for us to make capital investments to modify our solutions to facilitate our clients' and potential clients' compliance, as well as to deploy additional processes or reporting to comply with these regulations. In the future, we may need to incur additional expenses to ensure continued compliance with applicable laws and regulations and to investigate, defend and/or remedy actual or alleged violations. Further, requirements of these regulations have resulted, and could further result, in changes in our business

16

Table of Contents

practices, our clients' business practices and those of other marketplace participants that may alter the delivery of services to consumers, which have impacted, and could further impact, the demand for our solutions and services, as well as alter the types or volume of transactions that we process on behalf of our clients. As a result, these requirements, or proposed or future requirements, could have an adverse impact on our financial condition, revenue, results of operations, prospects for future growth and overall business.

The New York Department of Financial Services has enacted rules that require covered financial institutions to establish and maintain cybersecurity programs. Other states also have data security laws that vary in several respects, including with regard to specificity and detail of requirements and the extent to which such requirements apply to the data we collect from individuals. These rules subject us to additional regulation and require us to adopt additional business practices that could also require additional capital expenditures or impact our operating results. Changes to state money transmission laws and regulations, including changing interpretations and the implementation of new or varying regulatory requirements, may result in the need for additional money transmitter licenses. These changes could result in increased costs of compliance, as well as fines or penalties.

One of our subsidiaries is an SEC-registered broker-dealer in the U.S. and is subject to the financial and operational rules of FINRA, and others are authorized by the FCA to conduct certain regulated business in the U.K. Our transfer agent business is also regulated by the SEC and other regulators around the world. Domestic and foreign regulatory and self-regulatory organizations, such as the SEC, FINRA, and the FCA, can, among other things, fine, censure, issue cease-and-desist orders against, and suspend or expel a broker-dealer or its officers or employees for failure to comply with the many laws and regulations that govern brokerage activities. Regulations affecting the brokerage industry may change, which could adversely affect our business, financial condition or results of operations.

We are exposed to certain risks relating to the execution services provided by our brokerage operations to our customers and counterparties, which include other broker-dealers, active traders, hedge funds, asset managers, and other institutional and non-institutional clients. These risks include, but are not limited to, customers or counterparties failing to pay for or deliver securities, trading errors, the inability or failure to settle trades, and trade execution system failures. As trading in the U.S. securities markets has become more automated, the potential impact of a trading error or a rapid series of errors caused by a computer or human error or a malicious act has increased. In our other businesses, we generally can disclaim liability for trading losses that may be caused by our software, but in our brokerage operations, we may not be able to limit our liability for trading losses or failed trades, even when we are not at fault. As a result, we may suffer losses that are disproportionately large compared to the relatively modest profit contributions of our brokerage operations.

Moreover, the legislative and regulatory landscape continues to evolve, and we expect that it may cover alternative payment types, including digital and crypto currencies. Any failure to comply with such laws and regulations could expose us to liability, regulatory scrutiny and/or reputational damage. Financial crimes laws may be interpreted and applied inconsistently from country to country and may impose inconsistent or conflicting requirements. Complying with varying jurisdictional requirements could increase the costs and complexity of compliance, including associated recordkeeping costs, or could require us to change our business practices in a manner adverse to our business.

Further, our business may be constrained by current and future laws and regulations governing the development, use and deployment of artificial intelligence (including machine learning) ("AI") technologies. These laws and regulations are continuously and rapidly evolving, and there is no single global regulatory framework for AI, creating further uncertainties regarding compliance with such laws and regulations. As a result, our ability to leverage AI could be restricted by burdensome and costly regulatory requirements.

Additionally, in some markets in which we operate, our clients will require us to support them in achieving compliance with increasingly complex and prescriptive regulatory requirements relating to digital operational resilience. For example, under DORA, our E.U. financial entity clients will require us, as a third-party provider of information and communication technology services, to contract with and manage our relationships with such clients (and, where applicable, our relationships with critical third-party technology vendors in our supply chain) in accordance with the requirements of DORA. Failure to support our clients in achieving compliance with DORA and similar global regulatory regimes may cause us to lose revenue, clients, and/or result in damage to our reputation, and may also attract scrutiny from regulators.

If we fail to comply with relevant laws or regulations, then we risk reputational damage, potential civil and criminal sanctions, fines or other action imposed by regulatory or governmental authorities, including the potential suspension or revocation of the permission-based regulatory licenses which authorize the Company to provide core services to customers. Regulatory authorities subject our businesses, from time to time, to regulatory investigations, reviews, examinations and

17

Table of Contents

proceedings (both formal and informal), some of which have the potential to result in settlements, fines, penalties, injunctions or other adverse consequences to us. This could result in an adverse effect on FIS' business, reputation and customer relationships, which in turn could adversely affect its financial position and performance.

Many of our clients are subject to a regulatory environment and to industry standards that may change in a manner that reduces the types or volume of solutions or services we provide or may reduce the types or number of transactions in which our clients engage, and therefore reduce our revenue.

Our clients are subject to many, varied and evolving government regulations and industry standards with which our solutions must comply. Our clients must ensure that our solutions and related services work within the extensive and evolving regulatory and industry requirements applicable to them. Federal, state, foreign or industry authorities could adopt laws, rules or regulations affecting our clients' businesses that could lead to increased operating costs and could reduce the convenience and functionality of our solutions, possibly resulting in reduced market acceptance. In addition, action by regulatory authorities relating to credit availability, data usage, privacy, or other related regulatory developments could have an adverse effect on our clients and, therefore, could have a material adverse effect on our financial condition, revenue, results of operations, prospects for future growth and overall business. Elimination of regulatory requirements could also adversely affect the sales of our solutions designed to help clients comply with complex regulatory environments.

Constantly evolving global privacy, data protection, cybersecurity, cyber resilience, and AI laws and regulations require the Company to adopt new business practices, update contractual provisions in existing and new contracts, and constantly update our global Privacy and Data Protection Program and our global Information Security Program, which may require transitional and incremental expenses and may impact our future operating results.

The Company is subject to numerous global privacy, data protection, cybersecurity, cyber resilience, and AI laws and regulations, which are continuing to change in ways that impose increasingly complex and costly compliance obligations on us and that have had, and are expected to continue to have, a significant impact on our operations. Failure to comply with new and evolving laws and regulations in these areas could result in significant penalties, damage to our reputation, and loss of business. We have incurred, and will continue to incur, costs to comply with these new laws and regulations. There are also several additional laws being considered by state legislatures, the U.S. Congress, and governments around the world. As a result, we expect that a more substantial compliance effort with varying regimes in different jurisdictions will continue to be necessary in the future, which has the potential to further increase the cost and complexity of our business. Moreover, privacy, data protection, cybersecurity, cyber resilience, and AI laws may be interpreted and applied inconsistently from country to country and may impose inconsistent or conflicting requirements. Complying with varying jurisdictional requirements could increase the costs and complexity of compliance and associated recordkeeping costs or require us to change our business practices in a manner adverse to our business and to incur additional costs. Data localization requirements in evolving privacy, data protection, cybersecurity, cyber resilience, and AI laws could also increase the cost and alter the approach to housing data around the world. In addition, our businesses are increasingly subject to laws and regulations relating to digital transformation, surveillance, encryption, and data onshoring in the jurisdictions in which we operate. For example, under DORA, E.U. regulators are increasingly seeking to mitigate cyber threats and enhance digital resilience within the financial system through new regulations targeting the provision of critical third-party technology services. Compliance with these laws and regulations may require us to change our technology for information security, operational infrastructure, policies, and procedures, which could be time-consuming and costly and may result in additional regulatory burdens for the Company. Furthermore, compliance with these laws and regulations may indirectly impact us in circumstances where we act as a third-party service provider to clients, who are themselves subject to these laws and regulations and who will expect us to take appropriate steps to support them in achieving compliance.

High profile digital banking security breaches or information system failures could impact consumer payment behavior patterns in the future and reduce our transaction volumes.

We are unable to predict whether or when high profile digital banking security breaches or other information system failures will occur and, if they occur, whether consumers will reduce their digital banking service. If consumers reduce digital banking services, and we are not able to adapt to offer our clients alternative technologies, then our revenue and related earnings could be adversely affected.

18

Table of Contents

Misappropriation of and infringement on our intellectual property and proprietary rights, or a finding that our patents are invalid, could impair our competitive position.

Our ability to compete depends in some part upon our proprietary solutions and technology. Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our solutions or to obtain and use information that we regard as proprietary or challenge the validity of our patents with governmental authorities. Policing unauthorized use of our proprietary rights is difficult. We cannot make any assurances that the steps we have taken will prevent misappropriation of, or infringement upon, technology or that the agreements entered into for that purpose will be enforceable. Effective patent, trademark, service mark, copyright, and trade secret protection may not be available in every country in which our applications and services are made available. Misappropriation of our intellectual property or potential litigation concerning such matters could have an adverse effect on our business, financial condition or results of operations. As we increase our international business, we are subject to further risks of misappropriation of, or infringement on, our intellectual property in countries which have laws that are less protective of intellectual property or are enforced in a less protective manner.

If our applications or services are found to infringe the proprietary rights of others, then we may be required to change our business practices and may also become subject to significant costs and monetary penalties.

As our information technology applications and services develop, we are increasingly subject to infringement claims. Any claims, whether with or without merit, could (i) be expensive and time-consuming to defend; (ii) result in an injunction or other equitable relief which could cause us to cease making, licensing or using applications that incorporate the challenged intellectual property; (iii) require us to redesign our applications, if feasible; (iv) divert management's attention and resources; and (v) require us to enter into royalty or licensing agreements in order to obtain the right to use necessary technologies or pay damages resulting from any infringing use.

Some of our solutions contain "open source" software, and any failure to comply with the terms of one or more of these open source licenses could adversely affect our business.

We use a limited amount of software licensed by its authors or other third parties under so-called "open source" licenses, and we may continue to use such software in the future. Some of these licenses contain requirements that we make available source code for modifications or derivative works we create based upon the open source software and that we license such modifications or derivative works under the terms of a particular open source license or other license granting third parties certain rights of further use. By the terms of certain open source licenses, we could be required to release the source code of our proprietary software if we combine our proprietary software with open source software in a certain manner. Additionally, the terms of many open source licenses have not been interpreted by U.S. or other courts, and there is a risk that these licenses could be construed in a manner that could impose unanticipated conditions or restrictions on our ability to commercialize our solutions. In addition to risks related to license requirements, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or controls on the origin of the software. We have established processes to help alleviate these risks, including a review process for screening requests from our development organizations for the use of open source, but we cannot be sure that all open source is submitted for approval prior to use in our solutions. In addition, many of the risks associated with the use of open source cannot be eliminated, and could, if not properly addressed, adversely affect our business.

Using and/or incorporating AI technologies into our business poses additional risks and uncertainties that have the potential to harm our reputation and could have a material adverse effect on our business, financial condition or results of operations.

Incorporating AI technologies into our business offers significant potential to enhance the value of the solutions and services we provide to our clients. If we are unsuccessful in identifying opportunities to expand our portfolio with AI capabilities to strengthen or maintain our market position or enhance our customers' experiences, we may have a competitive disadvantage in developing new products and operating our business. However, AI algorithms may produce unfair, unintended, inaccurate, biased or discriminatory outcomes which could be difficult to detect or explain. Further, the training data underlying third-party AI models may also inadvertently breach intellectual property, privacy or other rights and result in the unauthorized use of confidential information. The integration of AI introduces a variety of risks and uncertainties that may harm our reputation, expose us to lawsuits from consumers or other third parties, introduce security vulnerabilities to our information systems, or have other unintended consequences if we are not successful in mitigating such risks. AI systems may have unintended societal impacts and negative outcomes, such as algorithmic errors that result in inadvertent discrimination or bias. Ensuring that our AI systems are used ethically and in a way that aligns with societal values is critical to maintaining trust with our clients, their customers, and regulators, and will likely be required under laws and regulations governing AI systems.

19

Table of Contents

Additionally, AI systems, whether developed internally or integrated from third-party suppliers, may be susceptible to security vulnerabilities. If these systems are targeted or exploited by cyberattacks, we may face financial and operational costs related to recovery and remediation, required public disclosure, as well as potential reputational damage. The increased sophistication of bad actors raises the risk of significant disruptions, which could impact our operations, as well as customer trust.

The regulatory landscape surrounding AI is evolving quickly, and the jurisdictions in which we operate are increasingly implementing new, complex and sometimes conflicting compliance requirements. For instance, the E.U. AI Act imposes a number of requirements (some of which take effect in August 2025, August 2026 and August 2027) that differ depending on the type and use of a particular AI system, but which will at a minimum include extensive documentation and transparency requirements. These regulatory changes introduce additional risks, including the possibility of failing to meet compliance obligations, which could result in substantial fines, penalties or other regulatory actions.

AI systems are also dependent on strong model governance, which includes the continuous monitoring, auditing and updating of models to reflect the continuous changes in laws, regulations, or legal precedent, and is paramount to managing these ethical and operational concerns. If we do not maintain an adequate model governance function, we may face regulatory risk, lawsuits, security vulnerabilities or other sources of liability and potentially diminish trust in our brand.

Lack of system integrity, fraudulent payments, credit quality, and undetected errors related to funds settlement or the availability of clearing services could result in a financial loss.

We settle funds on behalf of financial institutions, other businesses and consumers and receive funds from clients, card issuers, payment networks and consumers on a daily basis for a variety of transaction types. Transactions facilitated by us include debit card, credit card, electronic bill payment transactions, banking payments and check clearing that supports consumers, financial institutions and other businesses. These payment activities rely upon the technology infrastructure that facilitates the verification of activity with counterparties, the facilitation of the payment and the detection or prevention of fraudulent payments. A compromise of our continuity of operations, integrity of processing, or ability to detect or prevent fraudulent payments could result in a financial loss to us. In addition, we rely on various financial institutions to provide treasury services in support of funds settlement for certain of our solutions. An inability to obtain such treasury services in the future could have a material adverse effect on our business, financial condition or results of operations. Furthermore, if one of our clients, for which we facilitate settlement, defaults on settlement or suffers a fraudulent event due to a deficiency in their controls, then we may suffer a financial loss if the client does not have sufficient capital to cover the loss.

Our business is subject to the risks of international operations, including movements in foreign currency exchange rates.

Our international operations represented approximately 22% of our total 2024 revenue and are largely conducted in currencies other than the U.S. Dollar, including the British Pound Sterling, Euro, Brazilian Real, Australian Dollar, Swedish Krona, Swiss Franc and Indian Rupee. Our business, financial condition or results of operations could be adversely affected due to a variety of factors, including the following:

•changes in a specific country or region's political and cultural climate or economic condition, including a change in governmental regime;

•unexpected or unfavorable changes in foreign laws, regulatory requirements and related interpretations;

•difficulty of effective enforcement of contractual provisions in local jurisdictions;

•inadequate intellectual property protection in foreign countries;

•trade-protection measures, import or export licensing requirements, such as Export Administration Regulations promulgated by the U.S. Department of Commerce, and fines, penalties or suspension or revocation of export privileges;

•trade sanctions imposed by the U.S. or other governments with jurisdictional authority over our business operations;

•the effects of applicable and potentially adverse foreign tax law changes;

•significant adverse changes in foreign currency exchange rates;

•lesser enforcement of intellectual property laws and protections internationally;

•longer accounts receivable cycles;

•managing a geographically dispersed workforce;

•trade treaties, tariffs or agreements that could increase our costs or otherwise adversely affect our ability to do business in affected countries; and

•compliance with the FCPA and OFAC regulations and other applicable anti-corruption and sanctions laws and regulations, particularly in emerging markets.

20

Table of Contents

Our clients may pay us in foreign currencies. Conducting business in currencies other than the U.S. Dollar subjects us to foreign currency exchange rate fluctuations that can negatively impact our results, period to period, including relative to analyst estimates or guidance. Our primary exposure to movements in foreign currency exchange rates relates to the British Pound Sterling, Euro, Brazilian Real, Australian Dollar, Swedish Krona, Swiss Franc and Indian Rupee. The U.S. Dollar value of our net investments in foreign operations, the periodic conversion of foreign-denominated earnings to the U.S. Dollar (our reporting currency), and our results of operations and, in some cases, cash flows, could be adversely affected in a material manner by movements in foreign currency exchange rates. These risks could cause an adverse effect on our business, financial condition or results of operations. For more information on our exposure to foreign currency risk, see "Foreign Currency Risk" in "Item 7A. Quantitative and Qualitative Disclosures About Market Risk."

Failure to comply with anti-bribery and anti-corruption laws could subject us to penalties and other adverse consequences.

We are subject to the FCPA, the U.K. Bribery Act, and other anti-bribery and anti-corruption laws in various countries around the world. The FCPA, the U.K. Bribery Act and similar applicable laws generally prohibit companies, as well as their officers, directors, employees and third-party intermediaries, business partners and agents, from making improper payments or providing other improper things of value to government officials or other persons for the purpose of obtaining or retaining business abroad or otherwise obtaining favorable treatment. The FCPA also requires that U.S. public companies maintain books and records that fairly and accurately reflect transactions and maintain an adequate system of internal accounting controls.

We conduct business in foreign countries, including a number of countries with developing economies, and many of our employees, third-party intermediaries and agents in such countries may have direct or indirect interactions with officials and employees of government agencies, state-owned or affiliated entities and other third parties. We may be held liable if they take actions in violation of these laws, even if we do not explicitly authorize them. Although our policies and procedures require compliance with these anti-bribery and anti-corruption laws and are designed to facilitate such compliance, we do business in many countries and cannot make any assurances that our employees, contractors or agents somewhere in the world will not take actions in violation of applicable laws or our policies, for which we may ultimately be held responsible.

In the event that we believe or have reason to believe that our employees, contractors or agents have or may have violated such laws, we may be required to investigate (or to have outside counsel investigate) the relevant facts and circumstances. Detecting, investigating and resolving actual or alleged violations can be an extensive process and require a significant diversion of time, resources and attention from senior management. Further, we cannot assure that any such investigation will successfully uncover all relevant facts and circumstances. Any violation of the FCPA, the U.K. Bribery Act or other applicable anti-bribery or anti-corruption laws could result in whistleblower complaints, adverse media coverage, investigations, loss of export privileges, and criminal or civil sanctions, penalties and fines, any of which could adversely affect our business, financial condition or results of operations.

We have businesses in emerging markets that may experience significant economic volatility.

We have operations in emerging markets, primarily in Latin America, India, Southeast Asia, the Middle East and Africa. These emerging market economies tend to be more volatile than the more established markets we serve in North America and Europe, which could add volatility to our future revenue and earnings.

Acts of war or terrorism, international conflicts, political instability, natural disasters, power or communications failures, or widespread outbreak of an illness could negatively affect various aspects of our business, including our workforce and our business partners, make it more difficult and expensive to meet our obligations to our customers, and result in reduced revenue from our customers.

Our global operations are susceptible to global events, including threats or acts of war, such as the Russia-Ukraine war and the Israel-Hamas conflict, threats or acts of terrorism, international conflicts, political instability, natural disasters, and power or communications failures. We are also susceptible to a widespread outbreak of an illness or other health issue, such as the COVID-19 pandemic. These events can spread to different locations across the globe and can have an adverse effect on the global economy, reducing consumer and corporate spending upon which our revenue depends. Individual employees can become ill, quarantined, or otherwise unable to work and/or travel due to health reasons or governmental restrictions. Some of our operations are in countries where the effects of a widespread illness could be magnified due to health care systems that are less well-developed than in the U.S. The occurrence of any of these events could have an adverse effect on our business, financial condition or results of operations.

21

Table of Contents

The direct and indirect effects of climate change, including increased legal and regulatory requirements and stakeholder expectations, could adversely affect our business.

We may be subject to increased costs, regulations, reporting or other requirements, standards or expectations regarding sustainability and climate change-driven impacts on our business. While we seek to mitigate our business risks associated with climate change, this may require us to incur substantial costs and some of these risks may persist. Changing market dynamics, global policy developments, heightened focus from governmental, media, community, industry and investor stakeholders, and increasing frequency and impact of extreme weather events all have the potential to disrupt our business or the businesses of our customers, vendors and technology partners. Further, there is increased scrutiny, including by governments, regulators, investors, employees, clients and other stakeholders, on sustainability matters, which has resulted in new or additional legal and regulatory requirements and may require increased compliance and operational costs. In addition, if we fail to comply with applicable legal requirements and maintain practices that meet our stakeholders' evolving expectations, it could harm our reputation, adversely affect our ability to attract and retain clients and expose us to increased scrutiny from investors and regulatory authorities. Any of these developments could adversely affect our business, financial condition or results of operations.

Failure to attract and retain talent, including senior management and highly skilled technology personnel, could harm our ability to grow.

Our future success depends upon our ability to attract and retain talent in a competitive market, including senior management personnel and highly-skilled technology personnel. The competitive nature of this market is also affected by wage inflation, which generally increases the cost of talent. Because the development of our solutions and services requires knowledge, skills and abilities to create, develop and implement our software solutions in new areas on a continuing basis, we are competing for talented people with such knowledge, skills and abilities in new and developing technologies. Competition for such technical personnel is intense, as is the competition for senior management to lead these efforts, and our failure to hire and retain talented personnel could have a material adverse effect on our business, financial condition or results of operations.

Our future growth will also require sales and marketing, financial, legal and administrative personnel to develop and support new solutions and services, to enhance and support current solutions and services and to expand operational and financial systems. There can be no assurance that we will be able to attract and retain the necessary personnel to accomplish our growth strategies, and we may experience constraints that could adversely affect our ability to satisfy client demand in a timely fashion.

Our ability to maintain compliance with applicable laws, rules and regulations and to manage and monitor the risks facing our business relies upon the ability to maintain skilled compliance, legal, security, risk and audit professionals. Competition for such skill sets is intense, and our failure to hire and retain talented personnel could have an adverse effect on our internal control environment and impact our operating results.

Our senior management team has significant experience in the financial services industry, and the loss of this leadership could have an adverse effect on our business, operating results and financial condition. Further, the loss of this leadership may have an adverse impact on senior management's ability to provide effective oversight and strategic direction for all key functions within the Company, which could impact our future business, financial condition or results of operations.

We are the subject of various legal proceedings that could have an adverse effect on us.

We are involved in various litigation matters, including in some instances class-action cases and patent infringement litigation. If we are unsuccessful in our defense of litigation matters, we may be forced to pay damages and/or change our business practices, any of which could have an adverse effect on our business, financial condition or results of operations.

Unfavorable resolution of tax contingencies or unfavorable future tax law changes could adversely affect our tax expense.

Our tax returns and positions are subject to review and audit by federal, state, local and international taxing authorities. An unfavorable outcome to a tax audit could result in higher tax expense and could negatively impact our effective tax rate, financial position, results of operations and cash flows in the current and/or future periods. On December 15, 2022, the EU Member States formally adopted the EU’s Pillar Two Directive, which generally provides for a minimum effective tax rate of 15%, as established by the Organization for Economic Co-operation and Development Pillar Two Framework that was supported by over 130 countries worldwide. A significant number of countries are also implementing similar legislation. We are monitoring developments, including in countries that have enacted legislation, and do not currently expect a material adverse impact to the financial statements. We will continue to evaluate Pillar Two legislation and other future tax law changes

22

Table of Contents

that could result in negative impacts. In addition, tax-law amendments in the U.S. and other jurisdictions could significantly impact how U.S. multinational corporations are taxed. Although we cannot predict whether or in what form such legislation will pass, if enacted it could have an adverse effect on our business, financial condition or results of operations.

A material weakness in our internal controls could have a material adverse effect on us.

Effective internal controls are necessary for us to provide reasonable assurance with respect to our financial reports and to adequately mitigate the risk of fraud. If we cannot provide reasonable assurance with respect to our financial reports and adequately mitigate the risk of fraud, our reputation and results of operations could be harmed. Internal control over financial reporting may not prevent or detect misstatements because of its inherent limitations, including the possibility of human error, the circumvention or overriding of controls, or fraud. Therefore, even effective internal controls can provide only reasonable assurance with respect to the preparation and fair presentation of financial statements. In addition, projections of any evaluation of effectiveness of internal control over financial reporting to future periods are subject to the inherent risk that the control may become inadequate because of changes in conditions or because the degree of compliance with the policies or procedures may deteriorate.

A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the Company's annual or interim financial statements will not be prevented or detected on a timely basis. A material weakness in our internal control over financial reporting could adversely impact our ability to provide timely and accurate financial information. If we are unable to report financial information timely and accurately or to maintain effective disclosure controls and procedures, our business, financial condition or results of operations could be adversely affected.

Risks Related to Business Combinations and Ventures

We may not achieve the anticipated benefits of our recently completed Worldpay Sale, and we may also be exposed to new risks following the sale.

We may not achieve the anticipated benefits of our Worldpay Sale, which we completed in January 2024. The anticipated strategic, financial, and operational gains may not materialize, and costs or revenue dis-synergies could exceed expectations. Additionally, we have entered into ongoing arrangements with Worldpay for transition services which have required, and are expected to continue to require, significant resources and could offset the impact of our cost-saving initiatives. While we retain a 45% equity interest in Worldpay, we do not have control of Worldpay, exposing us to certain risks including risks related to Worldpay’s operations and merchant acquiring business.

As a result of the Worldpay Sale, our revenue sources are less diversified, which could increase our exposure to adverse developments affecting financial institutions. Additionally, our common stock now represents a smaller company, with proportionally increased exposure to our remaining business risks.

Strategic transactions, including acquisitions and divestitures, involve significant risks and uncertainties that could adversely affect our business, financial condition, results of operations and cash flows.

Strategic acquisitions and divestitures we have made in the past, and may make in the future, present significant risks and uncertainties that could adversely affect our business, financial condition, results of operations and cash flows. These risks include the following:

•difficulty in evaluating potential acquisitions, including the risk that our due diligence does not identify or fully assess valuation issues, potential liabilities or other acquisition risks;

•difficulty and expense in integrating newly acquired businesses and operations, including combining solution and service offerings, and in entering into new markets in which we are not experienced, in an efficient and cost-effective manner while maintaining adequate standards, controls and procedures, and the risk that we may encounter significant unanticipated costs or other problems associated with integration;

•difficulty and expense in consolidating, integrating, and rationalizing IT infrastructure and integrating acquired software;

•challenges in achieving strategic objectives, cost savings and other benefits expected from acquisitions;

•risk that our markets do not evolve as anticipated and that the strategic acquisitions and divestitures do not prove to be those needed to be successful in those markets;

•risk that acquired systems expose us to cybersecurity and other data security risks;

23

Table of Contents

•costs to reach appropriate standards to protect against cybersecurity and other data security risks, or the timelines to achieve such standards, may exceed those estimated in diligence;

•risk that acquired companies are subject to new regulatory regimes or oversight where we have limited experience, which may result in additional compliance costs and potential regulatory penalties;

•risk that we assume or retain, or that companies we have acquired have assumed or retained or otherwise become subject to, significant liabilities that exceed the limitations of any applicable indemnification provisions or the financial resources of any indemnifying parties;

•risk that indemnification related to businesses divested or spun-off that we may be required to provide or otherwise bear may be significant and could negatively impact our business;

•risk of exposure to potential liabilities arising out of applicable state and federal fraudulent conveyance laws and legal distribution requirements from spin-offs in which we or companies we have acquired were involved;

•risk that we may be responsible for unanticipated U.S. federal income tax liabilities related to acquisitions or divestitures;

•risk that we are not able to complete strategic divestitures within expected time frames or on satisfactory terms and conditions, including obtaining enforceable non-competition arrangements applicable to certain of our business lines;

•potential loss of key employees or customers of the businesses acquired or to be divested; and

•risk of diverting the attention of senior management from our existing operations.

We have substantial goodwill and other intangible assets recorded as a result of acquisitions, and a severe or extended economic downturn could cause these assets to become impaired, requiring write-downs that would reduce our operating income.

As of December 31, 2024, goodwill aggregated to $17.3 billion, or 51% of total assets, and intangible assets aggregated to $1.3 billion, or 4% of total assets. Current accounting rules require goodwill to be assessed for impairment at least annually or whenever changes in circumstances indicate potential impairment and require intangible assets with finite useful lives to be reviewed for impairment whenever events or changes in circumstances indicate that the carrying amount may not be recoverable. Factors that may be considered a change in circumstance include significant underperformance relative to historical or projected future operating results, a significant decline in our stock price and market capitalization, and negative industry or economic trends. If worldwide or U.S. economic conditions decline significantly with prolonged negative impacts to bank spending and consumer behavior, or if other business or market changes significantly impact our outlook, then the remaining carrying amount of our goodwill and other intangible assets may no longer be recoverable, and we may be required to record an impairment charge, which would have a negative impact on our results of operations. We will continue to monitor the fair value of our reporting units and other intangible assets as well as our market capitalization and the impact of any prolonged economic downturn on our business to determine the likelihood of impairment.

Risks Related to Our Indebtedness

Our existing debt levels and future levels under existing facilities and debt service requirements may adversely affect us, including our financial condition or business flexibility, and prevent us from fulfilling our obligations under our outstanding indebtedness.

As of December 31, 2024, we had total debt of approximately $11.3 billion. Our level of debt, or any increase in our debt level, could adversely affect our business, financial condition, operating results and operational flexibility, including as follows: (i) the debt level may cause us to have difficulty borrowing money in the future for working capital, capital expenditures, acquisitions or other purposes; (ii) our debt level may limit operational flexibility and our ability to pursue business opportunities and implement certain business strategies; (iii) some of our debt has a variable rate of interest, which exposes us to the risk of increased interest rates; (iv) we have a higher level of debt than some of our competitors or potential competitors, which may cause a competitive disadvantage and may reduce flexibility in responding to changing business and economic conditions, including increased competition and vulnerability to general adverse economic and industry conditions; (v) there are significant debt maturities or maturities that may need to be refinanced, potentially at higher rates; and (vi) failure to satisfy our obligations under our outstanding debt or failure to comply with the financial or other restrictive covenants contained in the indenture governing our senior notes or in our credit facility could result in an event of default that could cause all of our debt to become due and payable.

24

Table of Contents

We have exposure to fluctuations in the Euro-USD exchange rates, which could negatively affect our cost to service or refinance our Euro-denominated debt securities.

At December 31, 2024, the Company had outstanding approximately €4.0 billion aggregate principal amount of Euro-denominated senior notes and approximately €0.1 billion aggregate principal amount of Euro-denominated commercial paper, or the combined equivalent of approximately $4.3 billion aggregate principal amount. A vast majority of this EUR denominated indebtedness has been economically converted into USD through derivative instruments (see "Financial Instruments" in note 15 to the consolidated financial statements).

If our cash flows generated in foreign currencies are insufficient to settle our foreign currency denominated indebtedness, then we may need to exchange U.S. Dollars or funds in other currencies to make such payments, which could result in increased costs to us in the event of adverse changes in currency exchange rates. We have utilized and expect to continue to utilize foreign currency forward contracts and other hedges in an effort to mitigate currency risk, but we cannot make assurances that such hedging arrangements will be effective or will remain available to us on acceptable terms, or at all. In addition, we cannot predict economic and market conditions (including prevailing interest rates and foreign currency exchange rates) at the applicable times when our various series of Euro-denominated indebtedness are scheduled to mature, nor can there be any assurance that we would be able to refinance any series of our Euro-denominated indebtedness on acceptable terms at any such time, all of which could have an adverse financial impact on us.

Rising interest rates could increase our borrowing costs.

Our exposure to market risk for changes in interest rates relates to our short-term commercial paper borrowings and Revolving Credit Facility. In the future, we may have additional borrowings under existing or new variable-rate debt. Increases in interest rates on variable-rate debt would increase our interest expense. A rising interest rate environment could increase the cost of refinancing existing debt and incurring new debt, which could have an adverse effect on our financing costs.

Credit ratings, if lowered below investment grade, would adversely affect our cost of funds and liquidity.

The Company maintains investment grade credit ratings from the major U.S. rating agencies on its senior unsecured debt (S&P BBB, Moody's Baa2, Fitch BBB), as well as its commercial paper program (S&P A-2, Moody's P-2, Fitch F2). Failure to maintain investment grade rating levels could adversely affect the Company's cost of funds and liquidity and access to certain capital markets but would not have an adverse effect on our ability to access our existing Revolving Credit Facility. Please note that a security rating is not a recommendation to buy, sell or hold securities, that it may be subject to revision or withdrawal at any time by the assigning rating organization, and that each rating should be evaluated independently of any other rating.

Statement Regarding Forward-Looking Information

The statements contained in this Form 10-K or in our other documents or in oral presentations or other management statements that are not purely historical are forward-looking statements within the meaning of the U.S. federal securities laws. Statements that are not historical facts, as well as other statements about our expectations, beliefs, intentions, or strategies regarding the future, or other characterizations of future events or circumstances, are forward-looking statements. Forward-looking statements include statements about anticipated financial outcomes, including any earnings outlook or projections, projected revenue or expense synergies or dis-synergies, business and market conditions, outlook, foreign currency exchange rates, deleveraging plans, expected dividends and share repurchases of the Company, the Company's sales pipeline and anticipated profitability and growth, plans, strategies and objectives for future operations, strategic value creation, risk profile and investment strategies, any statements regarding future economic conditions or performance and any statements with respect to the future impacts of the Worldpay Sale or any agreements or arrangements entered into in connection with such transaction. These statements may be identified by words such as "expect," "anticipate," "intend," "plan," "believe," "will," "should," "could," "would," "project," "continue," "likely," and similar expressions, and include statements reflecting future results or outlook, statements of outlook and various accruals and estimates. These statements relate to future events and our future results and involve a number of risks and uncertainties. Forward-looking statements are based on management's beliefs as well as assumptions made by, and information currently available to, management.

Actual results, performance or achievement could differ materially from these forward-looking statements. The risks and uncertainties to which forward-looking statements are subject include the following, without limitation:

•changes in general economic, business and political conditions, a recession, intensified or expanded international hostilities, acts of terrorism, increased rates of inflation or interest, changes in either or both the United States and international lending, capital and financial markets or currency fluctuations;

25

Table of Contents

•the risk that acquired businesses will not be integrated successfully or that the integration will be more costly or more time-consuming and complex than anticipated;

•the risk that cost savings and synergies anticipated to be realized from acquisitions may not be fully realized or may take longer to realize than expected or that costs may be greater than anticipated;

•the risks of doing business internationally;

•the effect of legislative initiatives or proposals, statutory changes, governmental or applicable regulations and/or changes in industry requirements, including privacy, data protection, cybersecurity, cyber resilience and AI laws and regulations;

•our ability to comply with climate change legal and regulatory requirements and to maintain practices that meet our stakeholders' evolving expectations;

•the risks of reduction in revenue from the elimination of existing and potential customers due to consolidation in, or new laws or regulations affecting, the banking, retail and financial services industries or due to financial failures or other setbacks suffered by firms in those industries;

•changes in the growth rates of the markets for our solutions;

•the amount, declaration and payment of future dividends is at the discretion of our Board of Directors and depends on, among other things, our investment opportunities, results of operations, financial condition, cash requirements, future prospects, and other factors that may be considered relevant by our Board of Directors, including legal and contractual restrictions;

•the amount and timing of any future share repurchases is subject to, among other things, our share price, our other investment opportunities and cash requirements, our results of operations and financial condition, our future prospects and other factors that may be considered relevant by our Board of Directors and management;

•failures to adapt our solutions to changes in technology or in the marketplace;

•internal or external security or privacy breaches of our systems, including those relating to unauthorized access, theft, corruption or loss of personal information and computer viruses and other malware affecting our software or platforms, and the reactions of customers, card associations, government regulators and others to any such events;

•the risk that implementation of software, including software updates, for customers or at customer locations or employee error in monitoring our software and platforms may result in the corruption or loss of data or customer information, interruption of business operations, outages, exposure to liability claims or loss of customers;

•the risk that partners and third parties may fail to satisfy their legal obligations to us;

•risks associated with managing pension cost, cybersecurity issues, IT outages experienced by us or by third parties and data privacy;

•our ability to navigate the opportunities and risks associated with using and/or incorporating AI technologies into our business;

•the reaction of current and potential customers to communications from us or regulators regarding information security, risk management, internal audit or other matters;

•competitive pressures on pricing related to the decreasing number of community banks in the U.S., the development of new disruptive technologies competing with one or more of our solutions, increasing presence of international competitors in the U.S. market and the entry into the market by global banks and global companies with respect to certain competitive solutions, each of which may have the impact of unbundling individual solutions from a comprehensive suite of solutions we provide to many of our customers;

•the failure to innovate in order to keep up with new emerging technologies, which could impact our solutions and our ability to attract new, or retain existing, customers;

•an operational or natural disaster at one of our major operations centers;

•failure to comply with applicable requirements of payment networks or changes in those requirements;

•fraud by bad actors; and

•other risks detailed elsewhere in the "Risk Factors" section and other sections of this report and in our other filings with the SEC.

Other unknown or unpredictable factors also could have a material adverse effect on our business, financial condition, results of operations and prospects. Accordingly, readers should not place undue reliance on these forward-looking statements. These forward-looking statements are inherently subject to uncertainties, risks and changes in circumstances that are difficult to predict. Except as required by applicable law or regulation, we do not undertake (and expressly disclaim) any obligation and do not intend to publicly update or review any of these forward-looking statements, whether as a result of new information, future events or otherwise.

Item 1B. Unresolved Staff Comments

None.

26

Table of Contents

Item 1C. Cybersecurity

Cybersecurity is fundamental to FIS' complex, global business. As part of our business, FIS and its vendors, technology partners, and clients electronically receive, process, store and transmit a wide range of confidential information, including sensitive customer information and consumer personal data. Our operations extend to managing payment systems, cash access and prepaid card systems. Cyberattacks on information technology systems and the vendors and technological supply chain they rely on continue to grow in frequency, complexity and sophistication. This is a trend we expect to continue. Cyberattacks have garnered significant attention from individuals, businesses, governmental entities and the media drawing the focus of a large ecosystem of criminal threat actors. The objectives of these cyberattacks include, among other things, gaining unauthorized access to systems to disrupt operations, steal information, seek ransom payments from victims, perpetrate financial fraud, or sell stolen information. Perpetrators of cyberattacks attempt to exploit technical, human, social, and organizational vulnerabilities to gain unauthorized access. There is a growing trend of identifying and exploiting vulnerabilities in widely used technologies or vendor systems, allowing a single compromise or failure to extend unauthorized access to numerous systems.

FIS takes actions to assess, identify, and manage risks from cybersecurity threats to our information systems and those of our vendors and technology partners. A significant focus of our ongoing efforts is how we identify these vulnerabilities and prevent and respond to cyberattacks. Our processes include the activities of the FIS Cyber Fusion Center, which provides 24x7x365 cybersecurity threat monitoring and response. They also include structured defense-in-depth initiatives, such as perimeter security, remote access security, endpoint security, application security and identity management. In addition, we engage in extensive information security training of our employees who use and access our information systems.Our process for identification and management of risks from cybersecurity threats includes regular communication with cyber experts, engagement of cybersecurity partners to review our systems, regular audits of our information security by third-party assessors and consultants, and regular interactions with vendors and technology partners to oversee and identify material risks associated with the information systems utilized by such persons.

Our process of identifying and remediating cybersecurity risks has been integrated into our overall risk management system and processes.It is overseen by our Chief Information Security Officer and Chief Risk Officer, who report to our Board of Directors and its Risk and Technology Committee on a quarterly basis. The Chief Information Security Officer provides ongoing oversight for the management of cybersecurity risks across the firm leveraging a series of qualitative and quantitative risk assessment routines. Risk escalations are facilitated through the enterprise risk management framework, including the Company's Enterprise Risk Committee and the Board of Directors via the Risk and Technology Committee. Facilitated via regular updates on cybersecurity risk, our Board of Directors takes an active role in overseeing, managing, and setting risk tolerances for our cybersecurity program.Our Chief Information Security Officer has over 15 years of technology and cybersecurity experience, including previous senior leadership roles at major financial institutions and possesses industry certifications such as the Certified Information Systems Security Professional (CISSP).Additional leaders and key contributors composing the cybersecurity leadership team possess specific expertise, certifications, and previous work experience aligned to their assigned responsibilities. Our Enterprise Risk Committee, responsible for providing oversight for cybersecurity risks, is a cross-functional representation of senior leadership with requisite experience and expertise to provide risk oversight, including the Chief Risk Officer, Chief Legal Officer, Chief Technology Officer, Chief Compliance Officer, Chief Privacy Officer, and FIS Business Presidents.

FIS remains focused on making additional strategic investments in information security to protect our clients and our information systems from risks from cybersecurity threats. This includes both capital expenditures and operating expenses on hardware, software, staff and consulting services. These investments in the past have been and are reasonably likely to continue to be material to our results of operations. Further, notwithstanding our investments and other processes and efforts described above and elsewhere in this Annual Report on Form 10-K, we cannot guarantee that FIS will not be the subject of a cyberattack that would have a material effect on its financial condition or results of operations. See "Risk Factors" in Item 1A.

The continued growth in the frequency, complexity and sophistication of cyberattacks presents both a threat and an opportunity for FIS. Using expertise we have gained from our ongoing focus and investment, we have developed and we offer fraud, security, risk management and compliance solutions to target this growth opportunity in the financial services industry. We also use certain of these solutions to manage our own risks.

27

Table of Contents

We have not identified any previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. For a full discussion of risks from cybersecurity threats, see the section entitled "Risk Factors" in Item 1A.

Item 2. Properties

FIS' corporate headquarters is located at 347 Riverside Avenue, Jacksonville, Florida. In addition, FIS owns or leases support centers, data processing facilities and other facilities at approximately 85 locations. We believe our facilities and equipment are generally well maintained and are in good operating condition. We believe that the equipment we own and our various facilities are adequate for our present and foreseeable business needs.

Item 3. Legal Proceedings

The Company is involved in various pending and threatened litigation matters related to its business and operations, some of which include claims for punitive or exemplary damages. The Company believes no such currently pending or threatened actions are likely to have a material adverse effect on its consolidated financial position. With respect to litigation in which the Company is involved generally, please note the following:

•These matters raise difficult and complicated factual and legal issues and are subject to many uncertainties and complexities.

•The Company reviews all of its litigation on an ongoing basis and follows the authoritative provision for accounting for contingencies when making accrual and disclosure decisions. A liability must be accrued if (a) it is probable that a liability has been incurred and (b) the amount of loss can be reasonably estimated. If one of these criteria has not been met, disclosure is required when there is at least a reasonable possibility that a material loss may be incurred. When assessing reasonably possible and probable outcomes, the Company bases decisions on the assessment of the ultimate outcome following all appeals. Legal fees associated with defending litigation matters are expensed as incurred.

See Note 18 to the consolidated financial statements for information about certain legal matters and indemnifications and warranties.

Item 4. Mine Safety Disclosures

Not applicable.

PART II

Item 5. Market for Registrant's Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Our common stock trades on the New York Stock Exchange under the ticker symbol "FIS." As of January 31, 2025, there were approximately 9,024 shareholders of record of our common stock.

In January 2025, the Board of Directors approved a quarterly dividend of $0.40 per share beginning with the first quarter of 2025. A regular quarterly dividend of $0.40 per common share is payable on March 25, 2025, to shareholders of record as of the close of business on March 11, 2025. We currently expect to continue to pay quarterly dividends at a target payout ratio consistent with our capital allocation strategy, without regard to our equity method investment earnings (loss) attributable to our interest retained in Worldpay post-separation. However, the amount, declaration and payment of future dividends is at the discretion of the Board of Directors and depends on, among other things, our investment opportunities (including potential mergers and acquisitions), results of operations, financial condition, cash requirements, future prospects, and other factors, including legal and contractual restrictions, that may be considered relevant by our Board of Directors. Additionally, the payment of cash dividends may be limited by covenants in certain debt agreements.

Item 12 of Part III contains information concerning securities authorized for issuance under our equity compensation plans.

In January 2021, our Board of Directors approved a share repurchase program under which it authorized the Company to repurchase up to 100 million shares of our common stock. In August 2024, our Board of Directors approved a separate, incremental share repurchase program authorizing the repurchase of up to $3.0 billion in aggregate value of shares of our

28

Table of Contents

Source: SEC EDGAR (public domain) · 10-K for the period ended 2024-12-31, filed 2025-02-13 · accession 0001136893-25-000014

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 19 headings are on that chain and 18 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.