fis-20251231
Table of Contents
UNITED STATES SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
________________________________________________________
Form 10-K
________________________________________________________
For the fiscal year ended December 31, 2025
Or
For the transition period from to
Commission File No. 001-16427
________________________________________________________
Fidelity National Information Services, Inc.
(Exact name of registrant as specified in its charter)
Georgia37-1490331
(State or other jurisdiction of incorporation or organization) (I.R.S. Employer Identification No.)
347 Riverside Avenue
Jacksonville, Florida32202
(Address of principal executive offices) (Zip Code)
(904) 438-6000
(Registrant’s telephone number, including area code)
Securities registered pursuant to Section 12(b) of the Act:
Trading Name of each exchange
Title of each class Symbol(s) on which registered
Common Stock, par value $0.01 per share FIS New York Stock Exchange
1.500% Senior Notes due 2027 FIS27 New York Stock Exchange
1.000% Senior Notes due 2028 FIS28 New York Stock Exchange
2.250% Senior Notes due 2029 FIS29 New York Stock Exchange
2.000% Senior Notes due 2030 FIS30 New York Stock Exchange
3.360% Senior Notes due 2031 FIS31 New York Stock Exchange
2.950% Senior Notes due 2039 FIS39 New York Stock Exchange
Securities registered pursuant to Section 12(g) of the Act: None
(Title of Class)
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of "large accelerated filer," "accelerated filer," "smaller reporting company" and "emerging growth company" in Rule 12b-2 of the Exchange Act. (Check one):
Table of Contents
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management's assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant
included in the filing reflect the correction of an error to previously issued financial statements. ☒
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based
compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☒
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act) Yes ☐ No ☒
As of June 30, 2025, the last business day of the registrant's most recently completed second fiscal quarter, the aggregate market value of the registrant's common stock held by nonaffiliates was $42,560,250,917 based on the closing sale price of $81.41 on that date as reported by the New York Stock Exchange. For the purposes of the foregoing sentence only, all directors and executive officers of the registrant were assumed to be affiliates. The number of shares outstanding of the registrant's common stock, $0.01 par value per share, was 514,403,688 as of February 20, 2026.
The information in Part III hereof is incorporated herein by reference to the registrant’s Proxy Statement on Schedule 14A for the fiscal year ended December 31, 2025, to be filed within 120 days after the close of the fiscal year that is the subject of this Report.
FIDELITY NATIONAL INFORMATION SERVICES, INC.
2025 FORM 10-K ANNUAL REPORT
TABLE OF CONTENTS
Page
PART I
Item 1. Business 2
Item 1A. Risk Factors 13
Item 1B. Unresolved Staff Comments 29
Item 1C. Cybersecurity 29
Item 2. Properties 30
Item 3. Legal Proceedings 30
Item 4. Mine Safety Disclosures 30
PART II
Item 6. Reserved 32
Item 7A. Quantitative and Qualitative Disclosures About Market Risk 45
Item 8. Financial Statements and Supplementary Data 47
Item 9A. Controls and Procedures 98
Item 9B. Other Information 98
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 98
PART III
Item 10. Directors and Executive Officers of the Registrant 98
Item 11. Executive Compensation 98
Item 14. Principal Accounting Fees and Services 98
PART IV
Item 15. Exhibits and Financial Statement Schedules 98
1
Table of Contents
Unless stated otherwise or the context otherwise requires, all references to "FIS," "we," "our," "us," the "Company" or the "registrant" are to Fidelity National Information Services, Inc., a Georgia corporation, and its subsidiaries. Also, amounts in tables may not sum or calculate due to rounding.
PART I
Item 1. Business
Overview
About FIS
FIS is a financial technology company providing solutions to financial institutions, businesses and developers. We unlock financial technology to the world across the money lifecycle underpinning the world's financial systems. Our people are dedicated to advancing the way the world pays, banks and invests, by helping our clients to confidently run, grow and protect their businesses. Our expertise comes from decades of experience helping financial institutions and businesses of all sizes adapt to meet the needs of their customers by harnessing where reliability meets innovation in financial technology. Headquartered in Jacksonville, Florida, FIS is a member of the Fortune 500® and the Standard & Poor’s 500® Index. FIS is incorporated under the laws of the State of Georgia as Fidelity National Information Services, Inc., and our stock is traded under the trading symbol "FIS" on the New York Stock Exchange.
Growth and Strategy Objectives
Our growth continues to be driven by the expansion of our clients' businesses, our internal development of innovative solutions, our focused sales and marketing efforts and our deepening reach across global financial ecosystems. Strategic acquisitions and partnerships have further enhanced our offerings, diversified our client portfolio, and expanded our reach into new and attractive markets aligned with our long-term objectives. As we advance our transformation into a platform company, we are embedding artificial intelligence ("AI") across our solutions and operations. We have shifted to a functional operating model, streamlining decision-making, fostering closer collaboration across the organization and with our clients. By reallocating resources toward high-value, integrated client experiences and modernizing our technology infrastructure, we are strengthening our competitive position and operational resilience.
Worldpay Sale and Issuer Solutions Acquisition
On January 31, 2024, we completed the sale (the "2024 Worldpay Sale") of a 55% equity interest in our Worldpay Merchant Solutions business to private equity funds managed by GTCR, LLC (such funds, the "Buyer"). FIS retained a non-controlling 45% equity interest in a new standalone joint venture, Worldpay Holdco, LLC ("Worldpay"), following the closing of the 2024 Worldpay Sale. In connection with the 2024 Worldpay Sale, FIS and Worldpay entered into commercial agreements, preserving a key value proposition for clients of both businesses and reducing potential dis-synergies. FIS and Worldpay also entered into additional agreements as described in Note 4 to the consolidated financial statements.
On April 17, 2025, FIS entered into definitive agreements to (i) buy the Issuer Solutions business (the "Issuer Solutions Business") from Global Payments Inc. ("Global Payments") ("the Issuer Solutions Acquisition") and (ii) sell its remaining equity interest in Worldpay to Global Payments (the "2026 Worldpay Minority Interest Sale"). The transaction closed on January 9, 2026. We funded the Issuer Solutions Acquisition through a combination of approximately $7.7 billion of new debt and the 2026 Worldpay Minority Interest Sale.
Competitive Strengths
We believe our competitive strengths include the following:
•Brand. FIS is a highly respected brand known globally for innovation and thought leadership in the financial services sector.
•Extensive Domain Expertise and Portfolio Breadth. FIS' significant expertise in the markets and domains we serve enables us to deliver a broad range of innovative software applications and flexible service offerings, ranging from managed processing arrangements, either at the client site or hosted at an FIS data center or in our private cloud,
2
Table of Contents
to traditional license and maintenance arrangements. Our component-based platform offers clients an extensive solution set with modern, streamlined capabilities.
•Excellent and Long-term Relationships with Clients. A significant percentage of our business relates to solutions provided under multi-year, recurring contracts. The nature of these relationships allows us to develop close partnerships with our clients, resulting in high client retention rates. As the breadth of FIS' service offerings has expanded, we have found that our deep and broad access within our clients' organizations presents greater opportunities for cross-selling and up-selling solutions to our clients.
•Data and Cloud-based Technologies. FIS harnesses advanced analytics, AI, and real-time data insights across our platforms to deliver differentiated solutions that enhance decision-making, improve operational efficiency, and create personalized client experiences. By integrating emerging technologies such as machine learning, cloud-native architectures, and API-driven ecosystems, we strengthen our ability to innovate rapidly, scale securely, and maintain a leadership position in a dynamic financial services landscape.
•GlobalDistribution and Scale. We are a global leader in many of the markets we serve, supported by a large, knowledgeable talent pool of employees around the world. Our worldwide presence and global scale enable us to leverage our array of solution offerings, client relationships, and modern infrastructure to drive revenue growth and operating efficiency.
Strategy
Our mission is to deliver superior solutions to our clients and to expand our client base to generate sustained revenue and earnings growth for our shareholders. Our strategy to achieve this goal is built on the following pillars:
•Build, Buy, or Partner to Add Solutions to Win New Clients and Cross-sell to Existing Clients. We continue to execute a disciplined build, buy and partner model embedded in product development, technology investment and go-to market execution. By investing in solution innovation, we expand our value proposition to our clients and prospects.
•Support Our Clients Through Innovation. Changing market dynamics, particularly in the areas of digital delivery, information security and AI are transforming the way our clients operate and compete. These dynamics are driving increased demand for integrated, modular solutions built on our intellectual property. Our depth of service capabilities and platform provider model position us to engage earlier in clients' planning and design processes, collaborate with fintechs and third-party developers, and deliver innovation solutions that help clients navigate change, enhance resilience and accelerate growth.
•Drive Efficiency and Scalability. We strive to improve the efficiency of our operations through investments in new technologies, processes and infrastructure modernization. We also leverage a one-to-many operating model to drive high incremental margins on revenue growth, while also providing cost-effective solutions for our clients.
•Expand Distribution. Through our global sales force and strategic commercial partnerships, we drive growth through client additions and the expansion of existing client relationships in support of our clients' growth ambitions. Our clients range from large banks, financial institutions and other enterprises, including multi-national clients, to community or regional financial institutions and other businesses.
•Allocate Our Capital and Resources Strategically. As we make decisions with respect to building, buying or partnering to drive innovation in support of our clients, we prioritize the allocation of capital and other resources to the opportunities providing the highest client benefit and growth potential. We also continually review our portfolio of assets and businesses to assess their fit with our strategy and will, from time to time, decide to wind down or divest businesses or assets to redeploy capital to our areas of strategic focus. We believe that keeping our team and our capital strategically focused benefits our existing clients and our ability to win new clients. At the same time, to the extent our businesses generate excess cash, we strategically use it to repurchase shares, repay debt, pay dividends or for other corporate purposes.
3
Table of Contents
Segment Information
FIS reports its financial performance based on the following segments: Banking Solutions ("Banking"), Capital Market Solutions ("Capital Markets") and Corporate and Other.
The Worldpay Merchant Solutions business included the former Merchant Solutions segment in addition to a business previously included in the Corporate and Other segment. The results of the Worldpay Merchant Solutions business have been recast as discontinued operations for all periods presented. As such, the related results have been excluded from continuing operations and segment results, and the Company no longer reports the Merchant Solutions segment. See Notes 1 and 3 to the consolidated financial statements for further information regarding the Worldpay Merchant Solutions disposal group and its discontinued operations. FIS' share of the net income of Worldpay is reported as equity method investment earnings (loss).
Our consolidated results generally do not reflect pronounced seasonality. However, quarterly revenue and margins for each segment may vary based on the timing of recognition of certain non-recurring revenue, including software licenses and termination fees.
For information about current trends in market demand, see "Item 7. Management's Discussion and Analysis of Financial Condition and Results of Operations - Business Trends and Conditions."
Revenue by Segment
The table below summarizes our revenue by reporting segment (in millions):
Banking Solutions ("Banking")
The Banking segment is focused on serving financial institutions with core processing software, transaction processing software and complementary applications and services, many of which interact directly with core processing software. We sell these solutions on either a bundled or stand-alone basis. Clients in this segment include global financial institutions, U.S. regional and community banks, credit unions and commercial lenders, as well as government institutions and other commercial organizations. We provide our clients integrated solutions characterized by multi-year processing contracts that generate recurring revenue. The predictable nature of cash flows generated from the Banking segment provides opportunities for further investments in innovation, integration, information and security, and compliance in a cost-effective manner.
Our solutions in this segment include the following:
•Core Processing and Ancillary Applications. Our core processing software applications, including deposit and lending, customer management and other central management systems, are designed to run banking processes for our financial institution clients. Clients use these applications to maintain the primary records of their customer accounts. Our diverse selection of market-focused core processing software applications enables FIS to compete effectively in a wide range of markets. We continue to invest in our core modernization efforts to further differentiate our offerings for the long term. We also offer a number of solutions that are ancillary to the primary applications listed above, including branch automation, back-office support systems and compliance support.
•Digital, including Mobile and Online. Our comprehensive suite of retail and commercial applications enables financial institutions to streamline and integrate customer-facing operations with back-office processes, thereby improving customer experience across channels (e.g., branch, internet, mobile, ATM, and call centers). FIS' focus on real-time consumer access has driven significant market innovation in multi-channel, API-enabled embedded and multi-hosted solutions, underpinned by a strategy that provides tight integration and a seamless customer experience. Our innovative digital banking capabilities are now available to financial institutions with continually
4
Table of Contents
expanding functionality. Our digital offerings are integrated with core banking platforms offered by FIS and are also offered to customers of non-FIS core systems.
•Fraud, Risk Management and Compliance. Our decision solutions offer a spectrum of options that cover the account lifecycle from helping to identify qualified account applicants to managing existing customer accounts and fraud. Our applications enable Know Your Customer, new account decisioning and opening, account and transaction management, fraud management and collections. Our risk management solutions use our proprietary risk management models and data sources to assist in detecting fraud and assessing the risk of opening a new account. Our systems use a combination of advanced authentication procedures, predictive analytics, AI modeling and proprietary and shared databases to assess and detect fraud risk for deposit, card and other transactions for financial institutions.
•Card and Retail Payments. Our card and retail payment technology solutions allow clients to issue VISA®, MasterCard® or other payment network-branded credit and debit cards or other electronic payment cards for use by both consumer and business accounts. Card-based volumes continue to increase, driven by both the number of accounts on file and the number and value of transactions per month. We offer EMV (Europay, MasterCard and Visa) integrated circuit cards, often referred to as chip cards, as well as a variety of stored-value card types and loyalty programs, including our Premium Payback service that allows our financial institutions' customers to use loyalty points at a variety of merchant point-of-sale systems. Our integrated solutions range from card production and activation to processing to an extensive range of fraud management solutions and value-added loyalty programs designed to increase card usage and fee-based revenue for financial institutions and merchants. Many of our programs are full service, including most of the operations and support necessary for an issuer to operate a credit card program; however, we do not make credit decisions for our card issuing clients. We also provide specialized solutions such as virtual card, accounts payable and expense management, commercial processing and real-time alerts. We are also a leading provider of prepaid card solutions, which include digital cards, gift cards and reloadable cards, with end-to-end solutions for the development, processing and administration of stored-value programs, including government benefit programs. Our closed-loop gift card solutions and loyalty programs provide merchants compelling solutions to drive consumer loyalty.
•Electronic Funds Transfer and Network. Our electronic funds transfer and debit card processing businesses offer settlement and card management solutions for financial institution card issuers. We offer a modern, core-agnostic payment hub with real-time fraud monitoring across payment rails. We own and operate several U.S. domestic debit, prepaid, ATM and credit networks that carry transactions for a variety of transaction modes. Our networks connect millions of cards and point-of-sale locations nationwide, providing consumers with secure, real-time access to their money. Also through our networks, clients such as financial institutions, retailers and independent ATM operators can capitalize on the efficiency, consumer convenience and security of electronic real-time payments, real-time account-to-account transfers, and strategic alliances, such as surcharge-free ATM network arrangements.
•Wealth and Retirement. We provide wealth and retirement solutions that help banks, trust companies, brokerage firms, insurance firms, retirement plan professionals, benefit administrators and independent advisors acquire, service and grow their client relationships. We provide solutions for client acquisition, transaction management, trust accounting and recordkeeping that can be deployed stand-alone, as part of an integrated wealth or retirement platform, or on an outsourced basis.
•Item Processing and Output Solutions. Our item processing solutions furnish financial institutions with the technology needed to capture data from checks, transaction tickets and other items; image and sort items; process exceptions through keying; and perform balancing, archiving and the production of statements. Our item processing services are performed at one of our multiple item processing centers located throughout the U.S. or on-site at client locations. Our extensive solutions include distributed (i.e., non-centralized) data capture, mobile deposit capture, check and remittance processing, fraud detection, and document and report management. Clients encompass banks and corporations of all sizes, from de novo banks to the largest financial institutions and corporations. We offer a number of output solutions that are ancillary to the primary solutions we provide, including print and mail capabilities, document composition software and solutions, and card personalization fulfillment solutions. Our print and mail solutions offer complete computer output solutions for the creation, management and delivery of print and fulfillment needs. We provide our card personalization fulfillment solutions for branded credit cards and branded and non-branded debit and prepaid cards.
5
Table of Contents
Capital Market Solutions ("Capital Markets")
The Capital Markets segment is focused on serving global financial services clients and multi-national corporations with a broad array of buy- and sell-side, treasury, risk management and lending solutions. Clients in this segment include asset managers, private equity firms, sell-side securities brokerage and trading firms, insurers, asset and auto financiers and other commercial organizations. Our solutions include a variety of mission-critical buy- and sell-side applications for recordkeeping, data and analytics, trading and financing, as well as corporate treasury and risk management applications. Capital Markets clients purchase our solutions in various ways including licensing and managing technology "in-house," using consulting and third-party service providers, as well as procuring fully outsourced end-to-end solutions. Our long-established relationships with many of these financial and commercial institutions generate significant recurring revenue. We have made, and continue to make, investments in modern platforms, advanced technologies, open APIs, machine learning and AI, and regulatory technology to support our Capital Markets clients.
Our portfolios in this segment include the following:
•Trading and Asset Services. We offer solutions that support our customers across the buy and sell sides of the capital markets industry, assisting them to control their front, middle and back office operations through integrated ecosystems. Our solutions support institutional investors, managers, broker-dealers, asset servicers and transfer agents across all asset classes including private equity, hedge, credit, and traditional. Our Trading solutions focus on advanced trade life-cycle management, including market making and risk management, cleared derivatives processing, securities processing and securities finance, tax processing, and regulatory compliance, including anti-money laundering (AML) and trade surveillance. Our Asset Servicing solutions support every stage of the investment process, from research and portfolio management to order and position management, valuation, risk management, corporate actions, reconciliation, investment accounting, investor accounting, transfer agency and client reporting. Our solutions improve both investment decision making and operational efficiency, while managing risk and increasing transparency across the industry.
•Lending. Our lending solutions offer full life-cycle commercial lending functionality from loan origination, commercial credit assessment and customer risk rating to loan servicing and data analytics. We also offer leveraged and syndicated loan markets solutions that manage amendments, secondary market trading, deal management and bookrunning. In the asset finance space, we offer a single, end-to-end leasing platform that helps auto and equipment finance companies manage the entire financing process, supporting origination and pricing, credit decisioning, contract management, servicing and collections.
•Treasury and Risk. Our treasury solutions help chief financial officers and treasurers manage working capital by reducing risk and improving communication and response time between a company's buyers, suppliers, banks, and other stakeholders. Our end-to-end financial management framework helps bring together receivables, treasury, and payments for a single view of cash and risk, which helps our clients optimize business processes for enhanced liquidity management. Our risk portfolio of solutions manages market and credit risk and regulatory compliance for banks and actuarial risk for insurance firms.
Corporate and Other
The Corporate and Other segment consists of corporate overhead expense, certain leveraged functions and miscellaneous expenses that are not included in the operating segments, as well as certain non-strategic businesses. The overhead and leveraged costs relate to corporate marketing, finance, accounting, human resources, legal, compliance and internal audit functions, as well as other costs, such as acquisition, integration and transformation-related expenses and amortization of acquisition-related intangibles, that are not considered when management evaluates revenue-generating segment performance. Our other operating income recorded in connection with our transition services arrangements with Worldpay is also recorded in Corporate and Other.
Sales and Marketing
Our sales personnel have expertise in particular solutions, geographic markets and industry verticals, as well as across our various client segments. We believe that focusing our expertise on clients in specific markets and tailoring integrated solution sets to participants in those markets enables us to better serve our clients and makes our offerings more attractive to prospects. The majority of our prospects are identified via direct and/or indirect field sales, as well as inbound and outbound lead generation, telesales and virtual sales efforts.
6
Table of Contents
Our global marketing team develops and leads the execution of global, role-specific and geography-based strategic marketing plans in support of the segments' reputation and relationship building goals in addition to their revenue and profitability goals. Key components of our strategic plans include brand amplification and digital enablement; market and competitive research; voice of the customer and client engagement; thought leadership; integrated go-to-market programs; internal communications and readiness; journalists and social media engagement; industry analyst relations; client events; trade shows; high-touch client programs; demand generation campaigns; account- and deal-based marketing programs; collateral development and management across digital and online channels; and the launch of new products to market.
Patents, Copyrights, Trademarks and Other Intellectual Property
In general, we own the intellectual property and proprietary rights that are necessary to conduct our business and are important to our future success, including trademarks, trade names, trade secrets, copyrights and patents. We license certain items from third parties under arms-length agreements for varying terms, including some "open source" licenses.
We rely on a combination of contractual restrictions, internal security practices, patents, trade secrets, copyrights and applicable law to establish and protect our software, technology and expertise worldwide. We rely on trademark law to protect our rights in our brands. We intend to continue taking commercially reasonable measures to protect our intellectual property rights, including by legal action when necessary and appropriate.
Competition
The markets for our solutions are intensely competitive across both established companies and new industry entrants. Depending on the business line, our primary competitors include, but are not limited to, internal technology or software development departments within financial institutions or other large companies; global and regional companies providing banking, payment and capital markets solutions and services; embedded payment solution providers; securities exchanges; asset managers; card associations; clearing networks or associations; trust companies; independent computer services firms; companies that develop verticalized software applications; companies owned by global banks selling competitive solutions; companies that provide customized development, implementation and support services; emerging technology innovators and business process outsourcing companies. Many of these companies compete with us across multiple solutions, market segments and geographies to varying degrees based on solution strength and distribution strength. Competitive factors impacting the success of our solutions include the quality of the technology-based application or service, breadth of application features and functions, ease of delivery and integration, the ability to maintain, enhance and support the applications or solutions, price and overall client experience. We believe that we compete vigorously in each of these categories. FIS is positioned to lead through rapid innovation, ecosystem partnerships, and the integration of new technologies. We actively monitor and respond to market trends, leveraging our domain expertise to enhance our platform of solutions.
Technology Development
Our technology development activities primarily relate to enhancing our proprietary core processing software applications and to designing and developing next-generation digital solutions, processing systems, software applications and risk management platforms, including componentized products with unified API-enabled access implemented on a cloud foundation. These development activities include modernizing our online product offerings for treasury services, digital banking, capital markets services, and our next-generation core banking platform. We expect to continue investing an appropriate level of resources to maintain, enhance and extend the functionality of our proprietary systems and software applications, to develop new and innovative software applications and systems to address emerging technology trends in response to the needs of our clients, and to enhance the resilience of our enterprise systems and the capabilities of our outsourcing infrastructure.
As part of our technology development process, we evaluate current and emerging technologies for compatibility with our existing and future software platforms and apply those that best support the evolving needs of our clients. In particular, we are strengthening our integration across software ecosystems, creating a consolidated enterprise data infrastructure, enhancing AI capabilities and readiness, and selectively pursuing outsourcing opportunities in technology and operations to support resiliency, agility and cost control. We are expanding AI capabilities of our key solutions through a combination of in-house development and partnership with industry leaders, with a focus on agentic capabilities and the development of select use cases in collaboration with clients.
7
Table of Contents
Government Regulation
Our solutions are subject to a broad range of complex federal, state, and international regulations and requirements, as well as requirements under the rules of self-regulatory organizations including, without limitation, federal truth-in-lending and truth-in-savings rules, federal, state and international money transmission laws, state cybersecurity protection laws, data protection and privacy laws, cyber resilience laws, AI laws, usury laws, environmental, climate change, and sustainability laws and requirements, laws governing state trust charters, the Equal Credit Opportunity Act, the Electronic Funds Transfer Act, the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, the Bank Service Company Act, the Bank Secrecy Act, the USA Patriot Act, the United Kingdom ("U.K."). Money Laundering Regulations, the U.K. Proceeds of Crime Act, the U.K. Criminal Finances Act, the U.K. Sanctions and Anti-Money Laundering Act, the U.K. Economic Crime and Corporate Transparency Act, the European Union ("E.U.") Anti-Money Laundering Directives, the Internal Revenue Code, the Employee Retirement Income Security Act, the Health Insurance Portability and Accountability Act, the Community Reinvestment Act and the Dodd-Frank Wall Street Reform and Consumer Protection Act (the "Dodd-Frank Act"), the Securities Exchange Act of 1934, the Investment Advisors Act of 1940 (the "1940 Act"), anti-corruption laws including the U.S. Foreign Corrupt Practices Act of 1977 (the "FCPA") and the U.K. Bribery Act 2010 (the "U.K. Bribery Act"), the rules and regulations of the Financial Industry Regulatory Authority ("FINRA"), the Securities and Exchange Commission ("SEC"), the Federal Financial Institutions Examination Council ("FFIEC"), the Consumer Financial Protection Bureau ("CFPB"), the Financial Conduct Authority in the U.K. ("FCA"), the Central Bank of Ireland in the Republic of Ireland ("CBI"), the Commission de Surveillance du Secteur Financier in Luxembourg ("CSSF"), the Jersey Financial Services Commission in Jersey, Channel Islands ("JFSC") and state financial services regulators (including enforcement of state cybersecurity laws). The compliance of our solutions with these and other applicable laws and regulations depends on a variety of factors, including the manner in which our clients use them. In some cases, we are directly subject to regulatory oversight and examination. In other cases, our clients are contractually, or as a matter of law, responsible for determining what is required of them under applicable laws and regulations and utilize our solutions to achieve compliance with those laws and regulations. In some cases, we may be required to support our clients in achieving compliance with certain laws and regulations by virtue of the services that we provide to them. For example, under the E.U. Digital Operational Resilience Act ("DORA"), which came into force in January 2025, our E.U. financial entity clients require us, as a designated "critical third-party provider" of information and communication technology services, to contract with and manage our relationships with them (and, where applicable, our relationships with critical third-party technology vendors in our supply chain) in accordance with the requirements of DORA. Failure to support our clients in achieving compliance with DORA and similar global regulatory regimes may cause us to lose revenue or clients and/or result in damage to our reputation, and may also attract scrutiny from regulators. In any event, the failure of our solutions to comply with applicable laws and regulations may result in suspension or revocation of permission-based regulatory licenses, restrictions on our ability to provide those solutions, the imposition of civil fines and/or criminal penalties, loss of client trust, and/or reputational damage. Further, regulatory authorities have the power to, among other things, enjoin "unsafe or unsound" practices, require affirmative actions to correct any violation or practice, issue administrative orders that can be judicially enforced and direct the sale of subsidiaries or other assets. We may be adversely affected by increased regulatory scrutiny or related negative publicity.
The principal areas of regulation impacting our business are the following:
•Oversight by Banking Regulators. As a provider of electronic data processing and back-office services to financial institutions, FIS is subject to regulatory oversight and examination by the FFIEC, an interagency body of federal banking regulators including the Federal Deposit Insurance Corporation ("FDIC"), the Office of the Comptroller of the Currency ("OCC"), the Board of Governors of the Federal Reserve System ("FRB"), the National Credit Union Administration ("NCUA") (collectively, the Federal Banking Agencies or "FBA") and the CFPB, including as part of the Multi-Regional Data Processing Servicer ("MDPS") program. The MDPS program includes technology suppliers that provide mission-critical applications for a large number of financial institutions that are regulated by multiple regulatory agencies. Periodic information technology examination assessments are performed using FFIEC Interagency guidelines to identify potential risks that could adversely affect serviced financial institutions, determine compliance with applicable laws and regulations that affect the services provided to financial institutions, and ensure the solutions we provide to financial institutions do not create systemic risk to the banking system or impact the safe and sound operation of the financial institutions for which we process. In addition, independent auditors annually review several of our operations to provide reports on internal controls for our clients. We are also subject to review and examination by state and international regulatory authorities under state and foreign laws and rules that regulate many of the same activities that are described above, including electronic data processing, payments and back-office services for financial institutions and the use of consumer information.
8
Table of Contents
Our U.S.-based wealth and retirement business holds a charter in the state of Georgia, which makes us subject to the regulatory compliance requirements of the Georgia Department of Banking and Finance. As a result, we are also authorized to provide trust services in various additional states subject to additional applicable state regulations.
•Payment Services Oversight. Our payment services businesses provide technology services to U.S. financial institutions and are, therefore, subject to oversight and examination by the FFIEC. Our payment services businesses are also subject to regulation, supervision, and enforcement authority of numerous governmental and regulatory bodies in the jurisdictions in which they operate, which include the CFPB and U.S. state regulators. These various regulatory regimes require compliance in respect of many aspects of our payment services businesses including without limitation corporate governance and oversight functions, capital requirements, liquidity, safeguarding, fee regulation adherence, technology and cyber resilience, anti-money laundering and sanctions.
•Anti-Money Laundering. The Company is subject to, both directly and indirectly, various anti-money laundering laws and regulations such as the Bank Secrecy Act in the United States and the Money Laundering Regulations and Proceeds of Crime Act in the U.K. These laws, among other requirements, impose obligations to develop and implement risk-based anti-money laundering programs, file regulatory reports on large cash transactions and suspicious activity, and collect and maintain certain records related to customers and transactions. Many U.S. states have similar laws that overlap with, and in some cases diverge from, U.S. federal and international laws. While these federal, state and international laws are broadly consistent, there may be circumstances where the requirements of a particular jurisdiction conflict with those of other jurisdictions. As these laws continue to develop and expand, our investment in compliance with these laws continues to grow, as does the cost of ongoing compliance.
•Sanctions. The Company is subject to certain U.S. federal, state and international economic and trade sanctions programs, such as those that are administered by the U.S. Treasury's Office of Foreign Assets Control (referred to as "OFAC"), which prohibit or restrict transactions to or from, or dealings with, specified countries and regions, their governments, and in certain circumstances, their nationals, and with individuals and entities that are specially-designated nationals, narcotics traffickers, and terrorists or terrorist organizations. Similar programs exist in a number of other jurisdictions, most notably those administered by the Office of Financial Sanctions Implementation ("OFSI") in the U.K., E.U. sanctions, and United Nations sanctions. We have implemented policies, procedures, and internal controls that are designed to comply with global economic sanctions programs which are increasingly complex and rapidly evolving in response to geopolitical events. Those policies and procedures require the screening of third parties with which the Company does business, including clients and vendors, and transactions where appropriate.
•Anti-Corruption. The Company is subject to applicable anti-corruption laws, including the FCPA and the U.K. Bribery Act, in the jurisdictions in which it operates. Anti-corruption laws generally prohibit offering, promising, giving, or authorizing others to give, anything of value, either directly or indirectly, to a government official or private party in order to influence official action or otherwise to gain an unfair business advantage, such as to obtain or retain business. The Company has implemented policies, procedures, training and internal controls that are designed to comply with such laws, rules and regulations.
•Privacy and Data Protection. The Company is subject to an increasing number of privacy and data protection laws, regulations and directives globally, including the General Data Protection Regulation ("GDPR") in the E.U., the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), and various consumer privacy acts in other U.S. states that have followed, the Gramm-Leach-Bliley Act ("GLBA"), the Fair Credit Reporting Act ("FCRA"), and the Health Insurance Portability and Accountability Act ("HIPAA") in the United States; the U.K.'s General Data Protection Regulation ("U.K. GDPR") and Data Protection Act 2018; the General Personal Data Protection Act ("LGPD") in Brazil; the China Personal Information Protection Law ("PIPL"); and the Japanese Act on the Protection of Personal Information ("APPI") (referred to collectively as "Privacy Laws"). Many of these Privacy Laws place restrictions on the Company's ability to efficiently transfer, access and use personal data across its business. The legislative and regulatory landscape for privacy and data protection continues to evolve.
9
Table of Contents
Our financial institution clients operating in the U.S. are required to comply with privacy regulations imposed under the GLBA and numerous similar state laws. GLBA and those state laws place restrictions on the use of non-public personal information. All financial institutions must disclose detailed privacy policies to their customers and offer them the opportunity to direct the financial institution not to share information with third parties. The regulations under GLBA, however, permit financial institutions to share information with non-affiliated parties who perform services for the financial institutions. As a provider of solutions to financial institutions, we are required to comply with the Privacy Laws and are bound by the same limitations on disclosure of the information received from our clients as apply to the financial institutions themselves. A determination that there have been violations of Privacy Laws could expose us to significant damage or compensation awards, fines and other penalties that could, individually or in the aggregate, materially harm our business and reputation. Certain operations of the Company are also subject to newer, comprehensive, U.S. state-level privacy laws that provide consumers with additional data protection rights, including the right to be informed about the personal information collected by third parties and the use of that personal information, and which also impose obligations on companies in connection with the use of personal information.
The Company is subject to the E.U.’s GDPR, which applies to all organizations processing the personal data of individuals in the E.U., regardless of where such organization is based. The GDPR has heightened our privacy and data protection compliance obligations, impacted our businesses' collection, processing and retention of personal data and imposed stricter standards for reporting personal data breaches.
•Oversight by Securities Regulators. Our subsidiary that conducts our broker-dealer business in the U.S. is registered as a broker-dealer with the SEC, is a member of FINRA, and is registered as a broker-dealer in numerous states. Our broker-dealer is subject to regulation and oversight by the SEC. In addition, FINRA, a self-regulatory organization that is subject to oversight by the SEC, adopts and enforces rules governing the conduct, and examines the activities, of its member firms, including our broker-dealer. State securities regulators and various exchanges, including the New York Stock Exchange, also have regulatory or oversight authority over our broker-dealer. Broker-dealers are subject to regulations that cover all aspects of the securities business, including sales methods, trade practices among broker-dealers, public and private securities offerings, use and safekeeping of customers' funds and securities, capital structure, record keeping, the financing of customers' purchases and the conduct and qualifications of directors, officers and employees. In particular, as a registered broker-dealer and member of a self-regulatory organization, we are subject to the SEC's uniform net capital rule, Rule 15c3-1. Rule 15c3-1 specifies the minimum level of net capital a broker-dealer must maintain and also requires that a significant part of a broker-dealer's assets be kept in relatively liquid form. The SEC and various self-regulatory organizations impose rules that require notification when net capital falls below certain predefined criteria, limit the ratio of subordinated debt to equity in the regulatory capital composition of a broker-dealer and constrain the ability of a broker-dealer to expand its business under certain circumstances. Additionally, the SEC's uniform net capital rule imposes certain requirements that may have the effect of prohibiting a broker-dealer from distributing or withdrawing capital and requiring prior notice to the SEC for certain withdrawals of capital.
Our subsidiaries also include an SEC-registered transfer agent. Our registered transfer agent is subject to the Securities Exchange Act of 1934 and the rules and regulations promulgated thereunder. These laws and regulations generally grant the SEC and other supervisory bodies broad administrative powers to address non-compliance with regulatory requirements. Sanctions that may be imposed for non-compliance with these requirements include the suspension of individual employees, limitations on engaging in certain activities for specified periods of time or for specified types of clients, the revocation of registrations, other censures and significant fines.
Subsidiaries engaged in activities outside the U.S. are regulated by various government agencies in the particular jurisdiction where they are chartered, incorporated and/or conduct their business activity. For example, pursuant to the U.K. Financial Services and Markets Act 2000 ("FSMA"), certain of our subsidiaries are subject to regulations promulgated and administered by the FCA. The FSMA and rules promulgated thereunder govern all aspects of the U.K. investment business, including sales, research and trading practices, provision of investment advice, use and safekeeping of client funds and securities, regulatory capital, recordkeeping, margin practices and procedures, approval standards for individuals, financial crime systems and controls, periodic reporting and settlement procedures.
•Money Transfer. Our cash access and money transmission business is a Canadian FINTRAC-regulated Money Services Business (MSB) and a Payment Service Provider (PSP) and is governed by federal or national
10
Table of Contents
regulations, including but not limited to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) which is overseen by FINTRAC and requires MSBs to implement an AML compliance program (including appointing a compliance officer), conduct KYC and customer due diligence, and maintain records and report suspicious transactions, large cash transactions, and electronic funds transfers, and the Retail Payment Activities Act (RPAA) which is administered by the Bank of Canada and applies to PSPs performing retail payment activities (e.g., holding end-user funds, processing payments), which requires registration and adherence to operational risk and safeguarding standards. This business may also be subject to provincial, state or other local licensing requirements, which have been obtained where applicable, and the Company has processes for monitoring changing legal and regulatory requirements.
•Consumer Reporting and Protection. Our decision solutions subsidiary, ChexSystems, maintains a database of consumer information used to provide various account opening services, including credit scoring analysis, and is subject to the Federal Fair Credit Reporting Act ("FCRA") and similar state laws. The FCRA regulates consumer reporting agencies ("CRAs"), including ChexSystems, and governs the accuracy, fairness, and privacy of information in the files of CRAs that engage in the practice of assembling or evaluating certain information relating to consumers for certain specified purposes. CRAs are required to follow reasonable procedures to ensure maximum possible accuracy of information concerning the individual to whom the report relates and, if a consumer disputes the accuracy of any information in the consumer's file, to conduct a reasonable investigation within statutory timelines. The FCRA imposes many other requirements on CRAs and users of consumer report information. Regulatory enforcement of the FCRA is under the purview of the United States Federal Trade Commission, the CFPB, and state attorneys general, acting alone or in concert with one another. CRAs are also regulated by a number of states, including New York, with consumer reporting laws that are not pre-empted by the FCRA. In furtherance of our objectives of data accuracy, fair treatment of consumers, protection of consumers' personal information, and compliance with these laws, we have made considerable investment to maintain a high level of security for our computer systems in which consumer data resides, and we maintain consumer relations call centers to facilitate accurate and timely handling of consumer requests for information and disputes. We also are focused on ensuring our operating environments safeguard and protect consumers' personal information in compliance with these laws.
Our consumer-facing businesses are subject to federal and state consumer protection laws governing unfair, deceptive or abusive acts or practices ("UDAAP").
In addition, our U.K. regulated entity, Platform Securities LLP, is required to comply with the FCA’s Consumer Duty (the "Duty") in connection with its Wealth business. The Duty sets high standards of consumer protection across financial services and requires firms to put their customers' needs first.
•Debt Collection. Our collection services are subject to the Federal Fair Debt Collection Practices Act and various state collection laws and licensing requirements. The Federal Trade Commission, as well as state attorneys general and other agencies, have enforcement responsibility over the collection laws, as well as the various credit reporting laws.
•Digital Operational Resilience. In November 2025, the European Supervisory Authorities ("ESAs") designated the Company as a Critical Third-Party Provider ("CTPP") of Information and Communication Technology ("ICT") Services under DORA. This designation places us under the direct supervision and oversight of the ESAs with respect to DORA compliance and the management of operational and cyber risks for our clients in the European financial sector.
•AI Regulation. Lawmakers and regulators around the world are considering legislation or rules to govern the use and deployment of AI. The EU AI Act, Regulation (EU) 2024/1689, is now in effect and has requirements for risk assessment, data quality, logging, transparency and restrictions on cognitive behavioral interference or automated decision making. In the U.S., Executive Orders have directed federal agencies to consider the risks and rewards of AI in forthcoming regulations. Many U.S. states have also considered legislation to regulate AI that may affect the Company or its business.
The foregoing list of laws and regulations to which our Company is subject is not exhaustive, and the regulatory framework governing our operations changes continuously. Enactment of new laws and regulations may increasingly affect the operations of our business, directly and indirectly, which could result in substantial regulatory compliance costs, litigation expense, adverse publicity, and/or loss of revenue.
11
Table of Contents
Human Capital Management
Employee Population
As of December 31, 2025, we had more than 44,000 employees, including over 27,000 employees principally employed outside of the U.S. None of our U.S. workforce currently is unionized. Approximately 2,000 of our employees, primarily in Brazil and Europe, are represented by labor unions or works councils as of December 31, 2025.
Health and Safety
The health and safety of our employees is a key priority. We have implemented a comprehensive wellness program focused on all aspects of employee wellness – physical, mental, social, and financial. Initiatives under this program are designed to promote healthy lifestyle habits.
We continue to operate FIS Cares, a global employee-funded giving program designed to help our employees in times of need. We remain committed to providing a safe working environment that minimizes health risks and prioritizes physical safety.
Corporate Culture
Our culture stems from embracing our corporate values as we work together to win as one team, lead with integrity and strive to "be the change" for our employees, clients and communities. Our culture is not just a set of values on a wall; it is a daily operating system. We embed behaviors, decision-making norms, and expectations into how we work, and we hold leaders accountable for modeling these behaviors consistently. Inclusion and belonging remain at the heart of our values. We foster a respectful, inclusive environment that enables innovation and collaboration, ensuring we deliver the best solutions for our clients and partners. The Chief Executive Officer and Chief People Officer regularly update our Board of Directors on human capital management and culture, reinforcing its strategic importance.
Culture is measurable, observable, and operational. We do not rely solely on lagging engagement scores. Instead, we use regular pulse surveys focused on specific topics that matter most. This approach gives us real-time insight into colleague sentiment, enabling leaders to respond quickly and make informed decisions that strengthen trust, alignment, and a supportive work environment.
Talent Management
Our employees are primary stakeholders in our success, and we place a strategic priority on developing talent and creating an environment where individuals can thrive. Our approach is future-focused and designed to equip leaders and teams with the skills needed to enable business growth and exceed client expectations.
Our talent development program provides an enterprise-wide, systematic foundation for career development tied to learning paths that enable skills development. Traditional leadership programs are being replaced by customized, digital-first development experiences tailored to individual needs. We will offer micro-learning, peer coaching, and customized development opportunities that meet leaders where they are, when they need it. Our learning roadmap, ‘Building Our Leaders of Tomorrow,’ is supported by self-paced online resources, virtual instructor-led sessions, and targeted programs for high-potential and senior leaders. We engage in executive-level succession planning and provide extensive opportunities to apply for open roles within our organization. Our talent development practices are underpinned by a comprehensive talent planning and feedback culture. We have moved beyond annual performance ratings to a model built on clarity and continuous feedback. Employees benefit from clear goals, real-time coaching, and shared accountability, ensuring they understand what success looks like and how they are tracking throughout the year.
12
Table of Contents
Available Information
Our website address is www.fisglobal.com. We make our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, and Current Reports on Form 8-K, and any amendments to those reports, available, free of charge, on that website as soon as reasonably practicable after we file or furnish them to the SEC. Our Corporate Governance Policy and Code of Business Conduct and Ethics are also available on our website and are available in print, free of charge, to any shareholder who mails a request to the Corporate Secretary, Fidelity National Information Services, Inc., 347 Riverside Avenue, Jacksonville, FL 32202 USA. Other corporate governance-related documents can be found at our website as well. However, the information found on our website is not a part of this or any other report.
Item 1A. Risk Factors
In addition to the normal risks of business, we are subject to significant risks and uncertainties, including those listed below and others described elsewhere in this Annual Report on Form 10-K. Any of the risks described herein, as well as risks currently unknown or immaterial, could result in a significant adverse effect on our business, financial condition or results of operations.
Risks Related to Our Business and Operations
Security breaches, privacy breaches, cyberattacks, unintentional disclosures of confidential information, breaches of third party service providers, service outages, or a failure to comply with information security laws or regulations, contractual provisions, or industry security requirements by us, our vendors, clients, or technology partners could harm our business by disrupting delivery of services, exposing sensitive or confidential information, or damaging our reputation, any of which could result in a breach of one or more client contracts or regulatory investigations, enforcement actions, fines or litigation.
Cybersecurity is fundamental to our complex, global business. We and our vendors, service providers, technology partners, and clients electronically receive, process, store and transmit sensitive and confidential information of our business partners, clients and such clients' customers. We collect consumer personal data, such as names and addresses, Social Security Numbers, driver’s license numbers, financial account numbers, transactional history, cardholder data and payment history records. Such information is necessary to support our clients' transaction processing and to conduct our check authorization and collection businesses. We also collect personal data from our employees and contractors as necessary to support those relationships, comply with legal obligations, manage our workforce, and provide compensation and benefits. Our information systems and networks are dependent upon hardware, software, communication infrastructure and other technological components and services that are developed and managed by us or provided by third parties. These components require regular monitoring, patches, updates, or remediation of known or potential vulnerabilities. Implementation challenges in timely completing these tasks can lead to security vulnerabilities that expose us, our systems and data to potential compromise or interruption. Our information systems are also vulnerable to human error, including employees sending information to inadvertent recipients as well as employees inappropriately using AI tools, as well as malicious insider threats. Finally, the systems we rely on, which include hardware and software manufactured, developed or operated by third-party vendors and service providers, have in the past been subject to, and may in the future be subject to, cyberattacks or other security incidents due to employee error or malfeasance, software bugs, hardware malfunctions or other security vulnerabilities.
The uninterrupted trustworthy operation of information systems operated by us, our vendors and service providers, and other third parties, as well as the confidentiality of the customer or consumer information that resides on such systems, is critical to the successful operation of our Company. For that reason, compromises to the confidentiality, integrity or availability of our information systems or information are some of the principal operational risks we face as a provider of services to financial institutions and businesses. Like other such providers, we are a regular target of attempts to identify and exploit system vulnerabilities and/or penetrate or bypass our security measures to gain unauthorized access to our networks and systems. If we fail to maintain an adequate security infrastructure, adapt to emerging security threats (such as the use of AI by threat actors in furtherance of cyberattacks), the targeting of vendors who serve large numbers of customers for supply chain attacks, and business email compromises seeking fraudulent wire transfers regularly identify security vulnerabilities, prevent unauthorized access, identity theft or other cybersecurity risks (e.g., distributed denial of service, ransomware, and other cyberattacks), manage vendor or supply chain cybersecurity risks, adequately train users of our information systems, or implement sufficient security standards and technology to protect against security or privacy breaches, then the confidentiality, integrity or availability of the information we secure could be compromised. Unauthorized access to, or abuse of authorized access to, our computer systems or databases or our vendors' computer
13
Table of Contents
systems or databases could result in the theft or publication of confidential information and personal data, the deletion or modification of records, disruption of service delivery, installation of malware, and the potential need to pay ransom or otherwise cause interruptions in our operations. These issues could give rise to legal actions from clients and/or such clients' customers, regulatory investigations or enforcement activity, losses and expenses associated with such events, and damage to our reputation. Because we serve a diverse client base with different technology and service needs, we must continue to enhance our ability to manage the risks from the resulting diversity in potential security attacks.
FIS provides a number of systemically critical services, including the settlement of funds for financial institutions, other businesses and consumers and receives funds from clients, card issuers, payment networks and consumers on a daily basis for a variety of transaction types. Transactions facilitated by us include debit card, credit card, electronic bill payment, banking payments and check clearing that support consumers, financial institutions and other businesses. Attempted or successful targeting of these systems by attackers may result in interruption of services, misuse of account information, or unauthorized transfer of funds.
As a provider of services to financial institutions and businesses, we are bound by many of the same limitations on disclosure of the information we receive from clients that apply to the clients themselves. If we fail to comply with these regulations and industry security requirements, including those imposed by the payment card industry through its digital security standards and other rules, we could be exposed to damages from legal actions from clients and/or their customers, governmental proceedings, public disclosure and consumer notification requirements, and the imposition of significant fines or prohibitions on providing services. We operate in a highly regulated environment and are subject to a myriad of complex, evolving regulations and standards, including cybersecurity and privacy laws, regulations and industry standards. This environment imposes comprehensive data privacy compliance obligations in relation to our collection and use of data relating to an identifiable living individual or "personal data," including a principle of accountability and the obligation to demonstrate compliance through policies, procedures, training and audit, as well as regulating cross-border transfers of personal data. In addition, if more restrictive privacy laws, data protection rules or industry security requirements are adopted in the future on the federal or state level, or by a non-U.S. jurisdiction in or from which we serve clients, or by a specific industry body, those changes could have an adverse impact on our Company through increased costs or by imposing changes or inefficiencies on business processes.
A material privacy or security incident would trigger SEC disclosure obligations and could trigger other applicable disclosure requirements under state-level or non-U.S. laws or regulations, or be disclosed publicly, even if there is no legally required disclosure. Incident disclosure may increase the risks of private lawsuits or government enforcement action related to incidents, increase attention from malicious actors, and lead to greater regulatory scrutiny. The occurrence of any such incidents, and the related responses (if any) by regulators or third parties, may result in adverse publicity and reputational harm to us.
If we are unable, or appear to be unable, to prevent cybersecurity or privacy breaches, we risk reputational damage. Our existing clients could lose confidence in our information systems and consequently choose to terminate their agreements with us. Such reputational harm could also inhibit our ability to attract new clients; potentially increase government, regulatory, or media scrutiny; or give rise to new regulatory requirements that adversely affect our ability to do business in one or more parts of the world.
If we fail to innovate or adapt our solutions to changes in technology or in the marketplace, or if our ongoing efforts to upgrade or implement our technology are not successful, we could lose clients, or our clients could lose customers, and we could have difficulty attracting new clients for our solutions.
The markets for our solutions are characterized by constant technological changes, frequent introductions of new solutions and evolving industry expectations. Our future success will be significantly affected by our ability to enhance our current solutions and develop and introduce new solutions and services that address the increasingly sophisticated needs of our clients and their customers. In addition, as more of our revenue and market demand shifts to software as a service ("SaaS"), business process as a service ("BPaaS"), cloud, and new emerging technologies, the need to keep pace with rapid technology changes becomes more acute. These initiatives carry the risks associated with any new solution development effort, including cost overruns, delays in delivery and implementation, and performance issues. There can be no assurance that we will be successful in developing, marketing and selling new solutions or enhancements that meet these changing demands. If we are not successful in these efforts, we could lose clients, or our clients could lose customers, and we could have difficulty attracting new clients for our solutions. Any of these developments could have an adverse impact on our future revenue and/or business prospects.
14
Table of Contents
We operate in a competitive business environment; if we are unable to compete effectively, our business, financial condition or results of operations may be adversely affected.
The market for our solutions is intensely competitive. Our competitors in Banking and Capital Markets vary in size and in the scope and breadth of the solutions and services they offer. Some of our competitors have substantial resources. We face direct competition from third parties, and because many of our larger potential clients have historically developed their key applications in-house and, therefore, view their system requirements from a make-versus-buy perspective, we also often compete against our potential clients' in-house capacities. In addition, the markets in which we compete have recently attracted increasing competition from smaller start-ups with emerging technologies which are receiving increasing investments, as well as global banks (and businesses controlled by combinations of global banks) and global internet companies that are introducing competitive solutions and services into the marketplace, particularly in the payments area. Emerging technologies and increased competition may also have the effect of unbundling bank solutions and may result in displacing solutions that we are currently providing from our legacy systems. International competitors are also now targeting and entering the U.S. market with greater force. There can be no assurance that we will be able to compete successfully against current or future competitors or that the competitive pressures we face in the markets in which we operate will not materially adversely affect our business, financial condition, or results of operations.
Global economic, political and other conditions, including business cycles and consumer confidence, as well as geopolitical conflicts, may adversely affect our clients or trends in consumer spending, which may adversely impact the demand for our services and our revenue and profitability.
A significant portion of our revenue is derived from transaction processing fees. The global transaction processing industries depend heavily upon the overall level of consumer, business and government spending. Any change in economic factors, including a sustained deterioration in general economic conditions or consumer confidence, particularly in the U.S., or inflation and increases in interest rates in key countries in which we operate may adversely affect consumer spending, consumer debt levels and payment card usage, and as a result, adversely affect our financial performance by reducing the number or average purchase amount of transactions that we service. In addition, the direct and indirect effects of geopolitical conflicts, such as the Russia-Ukraine war and conflicts in the Middle East, have adversely affected global economic activity and transaction processing volumes. Worsening, or future, geopolitical conflicts could materially adversely affect global economic activity and our transaction volumes in the future.
When there is a slowdown or downturn in the economy, a drop in stock market levels or trading volumes, or an event that disrupts the financial markets, our business, financial condition or results of operations may suffer for a number of reasons. Customers may react to worsening conditions by reducing or delaying their capital expenditures in general or by specifically reducing or delaying their information technology spending. Additionally, credit card issuers may reduce credit limits and become more selective in their card issuance practices, which would lower purchase volumes. In addition, customers may seek to curtail trading operations or to lower their costs by renegotiating vendor contracts. Moreover, competitors may respond to market conditions and attempt to lure away our customers by lowering prices on existing solutions or by offering new, lower-cost solutions. Any further protective trade policies or actions taken by the U.S. may also result in other countries reducing, or making more expensive, services permitted to be provided by U.S.-based companies. If any of these circumstances remain in effect for an extended period of time, there could be a material adverse effect on our business, financial condition or results of operations.
Our business, financial condition or results of operations could be adversely affected by business interruptions, errors or failures in connection with our or third-party information technology and communication systems and other software and hardware used in connection with our business, or by design errors in the software solutions we offer, or more generally, by the unavailability of third-party services that we need to operate our business effectively.
Many of our services are based on sophisticated software and computing systems, and we may encounter delays when developing new technology solutions and services. Further, the technology solutions underlying our services have occasionally contained, and may in the future contain, undetected errors or defects when first introduced or when new versions are released. In addition, we may experience difficulties in installing or integrating our technologies on platforms used by our clients, or our clients may cancel a project after we have expended significant effort and resources to complete an installation. Finally, our systems and operations have been, and in the future could be, exposed to damage or interruption from fire, floods, severe weather events, natural disasters, power loss, telecommunications failure, unauthorized entry and computer viruses. Defects in our technology solutions or those of our third-party partners or elsewhere in the global cyber environment, errors or delays in the processing of electronic transactions, or other difficulties have resulted, and in the future could result, in (i) interruption of business operations; (ii) delay in market acceptance;
15
Table of Contents
(iii) additional development and remediation costs; (iv) diversion of technical and other resources; (v) loss of clients; (vi) negative publicity; or (vii) exposure to liability claims. Any one or more of the foregoing could have an adverse effect on our business, financial condition or results of operations. We cannot be certain that control measures, including system redundancies, security controls, and application development and testing controls, will be successful in preventing disruption or limiting our exposure.
Further, most of the solutions we offer are very complex software systems that are regularly updated. No matter how careful the design and development, complex software often contains errors and defects when first introduced and when major new updates or enhancements are released. If errors or defects are discovered in current or future solutions, then we may not be able to correct them in a timely manner, if at all. In our development of updates and enhancements to our software solutions, we may make a major design error that causes the solution to operate incorrectly or less efficiently. The failure of software to perform properly could result in the Company and its clients being subjected to losses or liability, including censures, fines, or other sanctions by the applicable regulatory authorities, and we could be liable to parties who are financially harmed by those errors. In addition, such errors could cause the Company to lose revenue, lose clients or suffer damage to its reputation.
In addition, we generally depend on a number of third parties, both in the United States and internationally, to supply elements of our systems, computers, research and market data, connectivity, communication network infrastructure, other equipment and related support and maintenance. We cannot be certain that any of these third parties will be able to continue providing these services to meet our evolving needs effectively. If our vendors, or in certain cases vendors of our customers, fail to meet their obligations, provide poor or untimely service or suffer operational disruptions, and we are unable to make alternative arrangements for the provision of these services, then we may in turn fail to provide our services or to meet our obligations to our customers, and our business, financial condition or results of operations could be adversely affected. In addition, we rely on various financial institutions to provide treasury services in support of funds settlement for certain of our solutions. An inability to obtain such treasury services in the future could have a material adverse effect on our business, financial condition or results of operations.
Entity mergers or consolidations and business failures in the banking and financial services industry could adversely affect our business by eliminating some of our existing and potential clients and making us more dependent on a more limited number of clients.
There has been, and may continue to be, consolidation activity in the banking and financial services industry. In addition, certain financial institutions that experienced negative operating results, including some of our clients, have failed, leading to further consolidation. These consolidations, including those spurred by failures, reduce our number of potential clients and may reduce our number of existing clients, which could adversely affect our revenue, even if the events do not reduce the aggregate activities of the consolidated entities. Further, if our clients or our partners across any of our businesses fail, merge with or are acquired by other entities that are not our clients or our partners, or that use fewer of our services, they may discontinue or reduce use of our services. It is also possible that larger financial institutions resulting from consolidations would have greater leverage in negotiating terms or could decide to perform in-house some or all of the services we currently provide or could provide. Any of these developments could have an adverse effect on our business, financial condition or results of operations.
Failure to obtain new clients or renew client contracts on favorable terms could adversely affect our business, financial condition or results of operations.
We may face pricing pressure in obtaining and retaining our clients. Larger clients may use their negotiating leverage to seek price reductions from us when they renew a contract, when a contract is extended, or when the client's business has significant volume changes. Larger clients may also reduce services if they decide to move services in-house. Further, our smaller and mid-size clients may also exert pricing pressure, particularly upon renewal, due to competition or other economic needs or pressures being experienced by the client. On some occasions, this pricing pressure results in lower revenue from a client than we had anticipated based on our previous agreement with that client. This reduction in revenue could adversely affect our business, financial condition or results of operations.
Bank failures or sustained financial market disruptions could adversely affect our business, financial condition and results of operations.
We regularly maintain domestic cash deposits in banks that are not subject to insurance protection against loss or exceed the deposit limits. We also maintain cash deposits in foreign banks where we operate, some of which are not
16
Table of Contents
insured or are only partially insured. The failure of a bank, or events involving limited liquidity, defaults, non-performance or other adverse conditions in the financial or credit markets impacting financial institutions at which we maintain balances, or concerns or rumors about such events, may lead to disruptions in access to our bank deposits or otherwise adversely impact our liquidity and financial performance. There can be no assurance that our deposits in excess of the insurance limits will be backstopped by the U.S. or applicable foreign government, or that any bank or financial institution with which we do business will be able to obtain needed liquidity from other banks, government institutions or otherwise in the event of a failure or liquidity crisis.
Our clients, including those of our clients that are banks, may be similarly adversely affected by any bank failure or other event affecting financial institutions. Any resulting adverse effects to our clients' liquidity or financial performance could reduce the demand for our services or affect our allowance for credit losses and collectability of trade receivables. A significant change in the liquidity or financial position of our clients could cause unfavorable trends in receivable collections and cash flows and may necessitate additional allowances for anticipated losses. Any such additional allowances could materially and adversely affect our business, financial condition or results of operations.
In addition, instability, liquidity constraints or other distress in the financial markets, including the effects of bank failures, defaults, non-performance or other adverse developments that affect financial institutions, could impair the ability of one or more of the banks participating in our current or any future credit facilities to honor their commitments. This could have an adverse effect on our business if we were not able to replace those commitments or to locate other sources of liquidity on acceptable terms.
The Company is subject to regulation, supervision, and enforcement authority of numerous governmental and regulatory bodies in the jurisdictions in which it operates.
Because the Company is a technology service provider to U.S. financial institutions, it is subject to regular oversight and examination by the FBA, each agency of which is a member of the FFIEC, an interagency body of federal banking regulators. The FBA have broad discretion in the implementation, interpretation and enforcement of banking and consumer protection laws and use the FFIEC's uniform principles, standards and report forms in their review of bank service providers like FIS. A failure to comply with these laws, or a failure to meet the supervisory expectations of the banking regulators, could result in adverse action against the Company. The regulators have the authority to, among other things, enjoin "unsafe or unsound" practices; require affirmative actions to correct any violation or practice; issue administrative orders that can be judicially enforced; direct the sale of subsidiaries or other assets; and assess civil money penalties.
The Company is also subject to ongoing supervision by regulatory and governmental bodies across the world, including economic and conduct regulators, such as OFAC, BIS and FinCEN in the U.S., the FCA, OFSI and OTSI in the U.K., and regulatory and governmental bodies responsible for issuing anti-money laundering, anti-bribery, and global economic sanctions and export control regulations. These various regulatory regimes require compliance across many aspects of our activities. Among other things, such regulatory and financial crime compliance obligations require certain capital requirements; safeguarding, training, authorization, supervision and oversight of personnel, systems, processes, controls, and documentation; and reporting to government entities. As we continue to grow our global business around the world, we will become subject to additional countries' regulations governing critical third-party service providers, financial crime and other regulatory areas. Our failure to comply with any of these requirements could result in the suspension or revocation of a license, loss of consumer confidence, and/or the imposition of civil or criminal penalties.
We also have business operations that store, process or transmit consumer information or have direct relationships with consumers. As such, we are obligated to comply with regulations, including, but not limited to, the FCRA, the Federal Fair Debt Collection Practices Act and applicable privacy requirements, and we are subject to examination and oversight by the CFPB. In addition, our wealth and retirement business holds a charter in the state of Georgia, which obligates us to comply with regulatory compliance requirements of the Georgia Department of Banking and Finance. Our U.S. wealth and retirement business is required to hold certain levels of regulatory capital as defined by the state banking regulator in Georgia. In the U.K., our Platform Securities and broker-dealer businesses are regulated by the FCA and are also subject to further regulatory capital requirements.
The Consumer Financial Protection Bureau ("CFPB") continues to update and enforce rules and regulations for regulating financial and non-financial institutions and providers to those institutions to ensure adequate protection of consumer privacy and to ensure consumers are not impacted by deceptive business practices, as well as to provide examination and supervisory authority over consumer reporting agencies, including ChexSystems. These rules and regulations govern our clients or potential clients and also govern certain of our businesses. These regulations have resulted, and may further result, in the need for us to make capital investments to modify our solutions to facilitate our
17
Table of Contents
clients' and potential clients' compliance, as well as to deploy additional processes or reporting to comply with these regulations. In the future, we may need to incur additional expenses to ensure continued compliance with applicable laws and regulations and to investigate, defend and/or remedy actual or alleged violations. Further, requirements of these regulations have resulted, and could further result, in changes in our business practices, our clients' business practices and those of other marketplace participants that may alter the delivery of services to consumers, which have impacted, and could further impact, the demand for our solutions and services, as well as alter the types or volume of transactions that we process on behalf of our clients. As a result, these requirements, or proposed or future requirements, could have an adverse impact on our financial condition, revenue, results of operations, prospects for future growth and overall business.
The New York Department of Financial Services has enacted rules that require covered financial institutions to establish and maintain cybersecurity programs. Other states also have data security laws that vary in several respects, including with regard to specificity and detail of requirements and the extent to which such requirements apply to the data we collect from individuals. These rules subject us to additional regulation and require us to adopt additional business practices that could also require additional capital expenditures or impact our operating results. Changes to state money transmission laws and regulations, including changing interpretations and the implementation of new or varying regulatory requirements, may result in the need for additional money transmitter licenses. These changes could result in increased costs of compliance, as well as fines or penalties.
One of our subsidiaries is an SEC-registered broker-dealer in the U.S. and is subject to the financial and operational rules of FINRA, and others are authorized by the FCA to conduct certain regulated business in the U.K. Our transfer agent business is also regulated by the SEC and other regulators around the world. Domestic and foreign regulatory and self-regulatory organizations, such as the SEC, FINRA, and the FCA, can, among other things, fine, censure, issue cease-and-desist orders against, and suspend or expel a broker-dealer or its officers or employees for failure to comply with the many laws and regulations that govern brokerage activities. Regulations affecting the brokerage industry may change, which could adversely affect our business, financial condition or results of operations.
Portions of FIS' European operations are in scope for regulatory oversight by European Supervisory Agencies (ESAs) as defined by DORA. FIS' designation as a Critical Third-Party Provider under DORA subjects us to additional and new regulatory oversight processes in the E.U. These changes could result in increased costs to compliance.
Other countries are also developing regulatory frameworks that govern critical third-party providers to the financial services sector, which may result in increased costs of compliance. For example, in the U.K., HM Treasury has powers to designate critical third-party providers to the financial services sector, subjecting them to additional regulatory oversight and obligations regarding reporting, incident management and testing.
We are exposed to certain risks relating to the execution services provided by our brokerage operations to our customers and counterparties, which include other broker-dealers, active traders, hedge funds, asset managers, and other institutional and non-institutional clients. These risks include, but are not limited to, customers or counterparties failing to pay for or deliver securities, trading errors, the inability or failure to settle trades, and trade execution system failures. As trading in the U.S. securities markets has become more automated, the potential impact of a trading error or a rapid series of errors caused by a computer or human error or a malicious act has increased. In our other businesses, we generally can disclaim liability for trading losses that may be caused by our software, but in our brokerage operations, we may not be able to limit our liability for trading losses or failed trades, even when we are not at fault. As a result, we may suffer losses that are disproportionately large compared to the relatively modest profit contributions of our brokerage operations.
Moreover, the legislative and regulatory landscape continues to evolve, and we expect that it may cover alternative payment types, including digital and crypto currencies. The regulatory environment for crypto assets, stablecoins, and digital currencies is rapidly evolving, with increased oversight from U.S. agencies such as the SEC, CFTC, and FinCEN, as well as global counterparts. Recent developments, including the European Union’s Markets in Crypto-Assets (MiCA) regulation, U.S. legislation such as the GENIUS Act, and other legislative initiatives, signal a trend toward increased oversight, more robust compliance obligations, and a move toward harmonized global standards. FIS closely monitors regulatory changes, to ensure any existing or new business models, product offerings, and risk and compliance programs adapt to new regulatory requirements. Any failure to comply with such laws and regulations could expose us to liability, regulatory scrutiny and/or reputational damage. Financial crimes laws may be interpreted and applied inconsistently from country to country and may impose inconsistent or conflicting requirements. Complying with varying jurisdictional requirements could increase the costs and complexity of compliance, including associated recordkeeping costs, or could require us to change our business practices in a manner adverse to our business.
18
Table of Contents
Further, our business may be constrained by current and future laws and regulations governing the development, use and deployment of AI (including machine learning) technologies. These laws and regulations are continuously and rapidly evolving, and there is no single global regulatory framework for AI, creating further uncertainties regarding compliance with such laws and regulations. As a result, our ability to leverage AI could be restricted by burdensome and costly regulatory requirements.
Additionally, in some markets in which we operate, our clients require us to support them in achieving compliance with increasingly complex and prescriptive regulatory requirements relating to digital operational resilience. For example, under DORA, our E.U. financial entity clients require us, as a designated Critical Third-Party Provider of information and communication technology services, to contract with and manage our relationships with such clients (and, where applicable, our relationships with other critical third-party technology vendors in our supply chain) in accordance with the requirements of DORA. Failure to support our clients in achieving compliance with DORA and similar global regulatory regimes may cause us to lose revenue, clients, and/or result in damage to our reputation, and may also attract scrutiny from regulators.
If we fail to comply with relevant laws or regulations, then we risk reputational damage, potential civil and criminal sanctions, fines or other action imposed by regulatory or governmental authorities, including the potential suspension or revocation of the permission-based regulatory licenses which authorize the Company to provide core services to customers. Regulatory authorities subject our businesses, from time to time, to regulatory investigations, reviews, examinations and proceedings (both formal and informal), some of which have the potential to result in settlements, fines, penalties, injunctions or other adverse consequences to us. This could result in an adverse effect on FIS' business, reputation and customer relationships, which in turn could adversely affect its financial position and performance.
Many of our clients are subject to a regulatory environment and to industry standards that may change in a manner that reduces the types or volume of solutions or services we provide or may reduce the types or number of transactions in which our clients engage, and therefore reduce our revenue.
Our clients are subject to many, varied and evolving government regulations and industry standards with which our solutions must comply. Our clients must ensure that our solutions and related services work within the extensive and evolving regulatory and industry requirements applicable to them. Federal, state, foreign or industry authorities could adopt laws, rules or regulations affecting our clients' businesses that could lead to increased operating costs and could reduce the convenience and functionality of our solutions, possibly resulting in reduced market acceptance. In addition, action by regulatory authorities relating to credit availability, data usage, privacy, or other related regulatory developments could have an adverse effect on our clients and, therefore, could have a material adverse effect on our financial condition, revenue, results of operations, prospects for future growth and overall business. Elimination of regulatory requirements could also adversely affect the sales of our solutions designed to help clients comply with complex regulatory environments.
Constantly evolving global privacy, data protection, cybersecurity, cyber resilience, and AI laws and regulations require the Company to adopt new business practices, update contractual provisions in existing and new contracts, and constantly update our global Privacy and Data Protection Program and our global Information Security Program, which may require transitional and incremental expenses and may impact our future operating results.
The Company is subject to numerous global privacy, data protection, cybersecurity, cyber resilience, and AI laws and regulations, which are continuing to change in ways that impose increasingly complex and costly compliance obligations on us and that have had, and are expected to continue to have, a significant impact on our operations. Failure to comply with applicable data protection laws, as well as new and evolving laws and regulations in these areas, could result in significant penalties, damage to our reputation, and loss of business. Additionally, a breach of applicable data protection laws may result in regulatory investigations, reputational damage, orders to cease or change our data processing activities, enforcement notices, assessment notices (for a compulsory audit) and/or civil claims (including class actions). We have incurred, and will continue to incur, costs to comply with these evolving laws and regulations. There are several additional laws being considered by state legislatures, the U.S. Congress, and governments around the world. As a result, we expect that a more substantial effort to comply with varying regimes in different jurisdictions will continue to be necessary in the future, which has the potential to further increase the cost and complexity of our business. Moreover, privacy, data protection, cybersecurity, cyber resilience, and AI laws may be interpreted and applied inconsistently from country to country and may impose inconsistent or conflicting requirements. Complying with varying jurisdictional requirements could increase the costs and complexity of compliance and associated recordkeeping costs or require us to change our business practices in a manner adverse to our business and to incur additional costs. Since we are subject to the supervision
19
Table of Contents
of relevant data protection authorities under multiple legal regimes, we could be fined under those regimes independently in respect of the same breach. Data localization requirements in evolving privacy, data protection, cybersecurity, cyber resilience, and AI laws could also increase the cost and alter the approach to housing data around the world. In addition, our businesses are increasingly subject to laws and regulations relating to digital transformation, surveillance, encryption, and data onshoring in the jurisdictions in which we operate. For example, through requirements established under DORA and Network and Information Security Directive 2, Directive (EU) 2022/2555, (NIS2), E.U. regulators are increasingly seeking to mitigate cyber threats and enhance digital resilience within the financial and technological ecosystem through new regulations targeting the provision of critical third-party technology services. Compliance with these laws and regulations may require us to change our technology for information security, operational infrastructure, policies, and procedures, which could be time-consuming and costly and may result in additional regulatory burdens for the Company. Furthermore, compliance with these laws and regulations may indirectly impact us in circumstances where we act as a third-party service provider to clients, who are themselves subject to these laws and regulations and who will expect us to take appropriate steps to support them in achieving compliance.
High profile digital banking security breaches or information system failures could impact consumer payment behavior patterns in the future and reduce our transaction volumes.
We are unable to predict whether or when high profile digital banking security breaches or other information system failures will occur and, if they occur, whether consumers will reduce their digital banking service. If consumers reduce digital banking services, and we are not able to adapt to offer our clients alternative technologies, then our revenue and related earnings could be adversely affected.
BRICS countries are working to reduce their reliance on the U.S. dollar and Western financial infrastructure due to sanctions, wars, and tariffs. BRICS is an international organization currently comprised of 11 countries, including Brazil, Russia, India, China, South Africa, Saudi Arabia, Egypt, United Arab Emirates, Ethiopia, Indonesia, and Iran. Intelligence sources, along with peer assessments and other observers, suggest that cyber actors from some of the BRICS countries may conduct attacks on payment infrastructure, including third-party fintech services, to undermine trust in the Western financial infrastructure.
Misappropriation of and infringement on our intellectual property and proprietary rights, or a finding that our patents are invalid, could impair our competitive position.
Our ability to compete depends in some part upon our proprietary solutions and technology. Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our solutions or to obtain and use information that we regard as proprietary or challenge the validity of our patents with governmental authorities. In addition, use of AI technologies may result in the release of confidential or proprietary information which could limit our ability to protect, or prevent us from protecting, our intellectual property rights. Policing unauthorized use of our proprietary rights is difficult. We cannot make any assurances that the steps we have taken will prevent misappropriation of, or infringement upon, technology or that the agreements entered into for that purpose will be enforceable. Effective patent, trademark, service mark, copyright, and trade secret protection may not be available in every country in which our applications and services are made available. Misappropriation of our intellectual property or potential litigation concerning such matters could have an adverse effect on our business, financial condition or results of operations. As we increase our international business, we are subject to further risks of misappropriation of, or infringement on, our intellectual property in countries which have laws that are less protective of intellectual property or are enforced in a less protective manner.
If our applications or services are found to infringe the proprietary rights of others, then we may be required to change our business practices and may also become subject to significant costs and monetary penalties.
As our information technology applications and services develop, we are increasingly subject to infringement claims. Any claims, whether with or without merit, could (i) be expensive and time-consuming to defend; (ii) result in an injunction or other equitable relief which could cause us to cease making, licensing or using applications that incorporate the challenged intellectual property; (iii) require us to redesign our applications, if feasible; (iv) divert management's attention and resources; and (v) require us to enter into royalty or licensing agreements in order to obtain the right to use necessary technologies or pay damages resulting from any infringing use.
20
Table of Contents
Some of our solutions contain "open source" software, and any failure to comply with the terms of one or more of these open source licenses could adversely affect our business.
We use a limited amount of software licensed by its authors or other third parties under so-called "open source" licenses, and we may continue to use such software in the future. Some of these licenses contain requirements that we make available source code for modifications or derivative works we create based upon the open source software and that we license such modifications or derivative works under the terms of a particular open source license or other license granting third parties certain rights of further use. By the terms of certain open source licenses, we could be required to release the source code of our proprietary software if we combine our proprietary software with open source software in a certain manner. Additionally, the terms of many open source licenses have not been interpreted by U.S. or other courts, and there is a risk that these licenses could be construed in a manner that could impose unanticipated conditions or restrictions on our ability to commercialize our solutions. In addition to risks related to license requirements, usage of open source software can lead to greater risks than use of third-party commercial software, as open source licensors generally do not provide warranties or controls on the origin of the software. We have established processes to help alleviate these risks, including a review process for screening requests from our development organizations for the use of open source, but we cannot be sure that all open source is submitted for approval prior to use in our solutions. In addition, many of the risks associated with the use of open source cannot be eliminated, and could, if not properly addressed, adversely affect our business.
Using and/or incorporating AI technologies into our business poses additional risks and uncertainties that have the potential to harm our reputation and could have a material adverse effect on our business, financial condition or results of operations.
Incorporating AI technologies into our business offers significant potential to enhance the value of the solutions and services we provide to our clients. If we are unsuccessful in identifying opportunities to expand our portfolio with AI capabilities to strengthen or maintain our market position or enhance our customers' experiences, we may have a competitive disadvantage in developing new products and operating our business. However, AI algorithms may produce unfair, unintended, inaccurate, biased or discriminatory outcomes which could be difficult to detect or explain. Further, the training data underlying third-party AI models may also inadvertently breach intellectual property, privacy or other rights and result in the unauthorized use of confidential information. The integration of AI introduces a variety of risks and uncertainties that may harm our reputation, expose us to lawsuits from consumers or other third parties, introduce security vulnerabilities to our information systems, or have other unintended consequences if we are not successful in mitigating such risks. AI systems may have unintended societal impacts and negative outcomes, such as algorithmic errors that result in inadvertent discrimination or bias. Ensuring that our AI systems are used ethically and in a way that aligns with societal values is critical to maintaining trust with our clients, their customers, and regulators, and will likely be required under laws and regulations governing AI systems. Additionally, AI systems, whether developed internally or integrated from third-party suppliers, may be susceptible to security vulnerabilities. If these systems are targeted or exploited by cyberattacks, we may face financial and operational costs related to recovery and remediation, required public disclosure, as well as potential reputational damage. The increased sophistication of bad actors raises the risk of significant disruptions, which could impact our operations, as well as customer trust.
The regulatory landscape surrounding AI is evolving quickly, and the jurisdictions in which we operate are increasingly implementing new, complex and sometimes conflicting compliance requirements. For instance, the E.U. AI Act imposes a number of requirements (some of which took effect in August 2025 and will take effect in August 2026 and August 2027) that differ depending on the type and use of a particular AI system, but which will at a minimum include extensive documentation and transparency requirements. Meanwhile, several U.S. states have adopted AI-specific frameworks or are considering applying existing consumer and data protection laws to regulate AI. These regulatory changes introduce additional risks, including the possibility of failing to meet compliance obligations, which could result in substantial fines, penalties or other regulatory actions.
AI systems are also dependent on strong model governance, which includes the continuous monitoring, auditing and updating of models to reflect the continuous changes in laws, regulations, or legal precedent, and is paramount to managing these ethical and operational concerns. If we do not maintain an adequate model governance function, we may face regulatory risk, lawsuits, security vulnerabilities or other sources of liability and potentially diminish trust in our brand.
21
Table of Contents
Lack of system integrity, fraudulent payments, credit quality, and undetected errors related to funds settlement or the availability of clearing services could result in a financial loss.
We settle funds on behalf of financial institutions, other businesses and consumers and receive funds from clients, card issuers, payment networks and consumers on a daily basis for a variety of transaction types. Transactions facilitated by us include debit card, credit card, electronic bill payment transactions, banking payments and check clearing that supports consumers, financial institutions and other businesses. These payment activities rely upon the technology infrastructure that facilitates the verification of activity with counterparties, the facilitation of the payment and the detection or prevention of fraudulent payments. A compromise of our continuity of operations, integrity of processing, or ability to detect or prevent fraudulent payments has resulted, and could in the future result, in a financial loss to us. Furthermore, if one of our clients, for which we facilitate settlement, defaults on settlement or suffers a fraudulent event due to a deficiency in their controls, then we may suffer a financial loss if the client does not have sufficient capital to cover the loss.
Our business is subject to the risks of international operations, including movements in foreign currency exchange rates.
Our international operations represented approximately 23% of our total 2025 revenue and are largely conducted in currencies other than the U.S. Dollar, including the British Pound Sterling, Euro, Swedish Krona, Australian Dollar, Brazilian Real, Swiss Franc, Canadian Dollar and Indian Rupee. Our business, financial condition or results of operations could be adversely affected due to a variety of factors, including the following:
•changes in a specific country or region's political and cultural climate or economic condition, including a change in governmental regime;
•unexpected or unfavorable changes in foreign laws, regulatory requirements and related interpretations;
•difficulty of effective enforcement of contractual provisions in local jurisdictions;
•inadequate intellectual property protection in foreign countries;
•trade-protection measures, import or export licensing requirements, such as Export Administration Regulations promulgated by the U.S. Department of Commerce, and fines, penalties or suspension or revocation of export privileges;
•trade sanctions imposed by the U.S. or other governments with jurisdictional authority over our business operations;
•the effects of applicable and potentially adverse foreign tax law changes;
•significant adverse changes in foreign currency exchange rates;
•lesser enforcement of intellectual property laws and protections internationally;
•longer accounts receivable cycles;
•managing a geographically dispersed workforce;
•trade treaties, tariffs or agreements that could increase our costs or otherwise adversely affect our ability to do business in affected countries; and
•compliance with the FCPA and OFAC regulations and other applicable anti-corruption and sanctions laws and regulations, particularly in emerging markets.
Our clients may pay us in foreign currencies. Conducting business in currencies other than the U.S. Dollar subjects us to foreign currency exchange rate fluctuations that can negatively impact our results, period to period, including relative to analyst estimates or guidance. Our primary exposure to movements in foreign currency exchange rates relates to the British Pound Sterling, Euro, Brazilian Real, Australian Dollar, Swedish Krona, Swiss Franc and Indian Rupee. The U.S. Dollar value of our net investments in foreign operations, the periodic conversion of foreign-denominated earnings to the U.S. Dollar (our reporting currency), and our results of operations and, in some cases, cash flows, could be adversely affected in a material manner by movements in foreign currency exchange rates. These risks could cause an adverse effect on our business, financial condition or results of operations. For more information on our exposure to foreign currency risk, see "Foreign Currency Risk" in "Item 7A. Quantitative and Qualitative Disclosures About Market Risk."
Failure to comply with anti-bribery and anti-corruption laws could subject us to penalties and other adverse consequences.
We are subject to the FCPA, the U.K. Bribery Act, and other anti-bribery and anti-corruption laws in various countries around the world. The FCPA, the U.K. Bribery Act and similar applicable laws generally prohibit companies, as well as their officers, directors, employees and third-party intermediaries, business partners and agents, from making improper payments or providing other improper things of value to government officials or other persons for the purpose of obtaining or retaining business abroad or otherwise obtaining favorable treatment. The FCPA also requires that U.S. public
22
Table of Contents
companies maintain books and records that fairly and accurately reflect transactions and maintain an adequate system of internal accounting controls.
We conduct business in foreign countries, including a number of countries with developing economies, and many of our employees, third-party intermediaries and agents in such countries may have direct or indirect interactions with officials and employees of government agencies, state-owned or affiliated entities and other third parties. We may be held liable if they take actions in violation of these laws, even if we do not explicitly authorize them. Although our policies and procedures require compliance with these anti-bribery and anti-corruption laws and are designed to facilitate such compliance, we do business in many countries and cannot make any assurances that our employees, contractors or agents somewhere in the world will not take actions in violation of applicable laws or our policies, for which we may ultimately be held responsible.
In the event that we believe or have reason to believe that our employees, contractors or agents have or may have violated such laws, we may be required to investigate (or to have outside counsel investigate) the relevant facts and circumstances. Although we maintain multiple reporting channels in which employees, contractors and other individuals can report concerns without retaliation, detecting, investigating and resolving actual or alleged violations can be an extensive process and require a significant diversion of time, resources and attention from senior management. Further, we cannot assure that any such investigation will successfully uncover all relevant facts and circumstances. Any violation of the FCPA, the U.K. Bribery Act or other applicable anti-bribery or anti-corruption laws could result in whistleblower complaints, adverse media coverage, investigations, loss of export privileges, and criminal or civil sanctions, penalties and fines, any of which could adversely affect our business, financial condition or results of operations.
We have businesses in emerging markets that may experience significant economic volatility.
We have operations in emerging markets, primarily in Latin America, India, Southeast Asia, the Middle East and Africa. These emerging market economies tend to be more volatile than the more established markets we serve in North America and Europe, which could add volatility to our future revenue and earnings.
Acts of war or terrorism, international conflicts, political instability, natural disasters, power or communications failures, or widespread outbreak of an illness could negatively affect various aspects of our business, including our workforce and our business partners, make it more difficult and expensive to meet our obligations to our customers, and result in reduced revenue from our customers.
Our global operations are susceptible to global events, including threats or acts of war, such as the Russia-Ukraine war and conflicts or tensions in the Middle East, threats or acts of terrorism, international conflicts, political instability, natural disasters, and power or communications failures. We are also susceptible to a widespread outbreak of an illness or other health issue or pandemic. These events can spread to different locations across the globe and can have an adverse effect on the global economy, reducing consumer and corporate spending upon which our revenue depends. Individual employees can become ill, quarantined, or otherwise unable to work and/or travel due to health reasons or governmental restrictions. Some of our operations are in countries where the effects of a widespread illness could be magnified due to health care systems that are less well-developed than in the U.S. The occurrence of any of these events could have an adverse effect on our business, financial condition or results of operations.
The direct and indirect effects of climate change, including increased legal and regulatory requirements and stakeholder expectations, could adversely affect our business.
We are subject to dynamic, and sometimes conflicting, laws, regulations and other directives that govern a wide array of issues related to sustainability and we may be subject to increased costs, regulations, reporting or other requirements, standards or expectations regarding sustainability and climate change-driven impacts on our business. While we seek to mitigate our business risks associated with climate change, this may require us to incur substantial costs and some of these risks may persist. Changing market dynamics, global and domestic policy developments, heightened focus from governmental, media, community, industry and other stakeholders, and increasing frequency and impact of extreme weather events, such as flooding or windstorms, all have the potential to disrupt our business or the businesses of our customers, vendors and technology partners. Further, there is increased scrutiny, including by governments, regulators, investors, employees, clients and other stakeholders, on sustainability matters, which has resulted in new or additional legal and regulatory requirements and may require increased compliance and operational costs. In addition, if we fail or are perceived to fail to comply with applicable legal requirements and maintain practices that meet our stakeholders' evolving and potentially divergent expectations, it could harm our reputation, adversely affect our ability to attract and retain clients
23
Table of Contents
and expose us to increased scrutiny from investors and regulatory authorities. Any of these developments could adversely affect our business, financial condition or results of operations.
Failure to attract and retain talent, including senior management and highly skilled technology personnel, could harm our ability to grow.
Our future success depends upon our ability to attract and retain talent in a competitive market, including senior management personnel and highly-skilled technology personnel. The competitive nature of this market is also affected by wage inflation, which generally increases the cost of talent. Because the development of our solutions and services requires knowledge, skills and abilities to create, develop and implement our software solutions in new areas on a continuing basis, we are competing for talented people with such knowledge, skills and abilities in new and developing technologies. Competition for such technical personnel is intense, as is the competition for senior management to lead these efforts, and our failure to hire and retain talented personnel could have a material adverse effect on our business, financial condition or results of operations.
Our future growth will also require sales and marketing, financial, legal and administrative personnel to develop and support new solutions and services, to enhance and support current solutions and services and to expand operational and financial systems. There can be no assurance that we will be able to attract and retain the necessary personnel to accomplish our growth strategies, and we may experience constraints that could adversely affect our ability to satisfy client demand in a timely fashion.
Our ability to maintain compliance with applicable laws, rules and regulations and to manage and monitor the risks facing our business relies upon the ability to maintain skilled compliance, legal, security, risk and audit professionals. Competition for such skill sets is intense, and our failure to hire and retain talented personnel could have an adverse effect on our internal control environment and impact our operating results.
Our senior management team has significant experience in the financial services industry, and the loss of this leadership could have an adverse effect on our business, operating results and financial condition. Further, the loss of this leadership may have an adverse impact on senior management's ability to provide effective oversight and strategic direction for all key functions within the Company, which could impact our future business, financial condition or results of operations.
In addition, as we continue to implement our business strategy and transform the organization, cost-control initiatives have resulted in a reduced workforce and reduced capacity in some areas of our business. As we seek to implement these changes to improve efficiency, adjustments to reduced staffing levels may affect our ability to conduct our operations and other functions effectively. If we fail to effectively manage these organizational and/or strategic changes, our financial condition, results of operations and reputation, as well as our ability to successfully attract, motivate and retain key employees, could be harmed.
We are the subject of various legal proceedings that could have an adverse effect on us.
We are involved in various litigation matters, including from time-to-time class-action cases and patent infringement litigation. If we are unsuccessful in our defense of litigation matters, we may be forced to pay damages and/or change our business practices, any of which could have an adverse effect on our business, financial condition or results of operations.
Unfavorable resolution of tax contingencies or unfavorable future tax law changes could adversely affect our tax expense.
Our tax returns and positions are subject to review and audit by federal, state, local and international taxing authorities. An unfavorable outcome to a tax audit could result in higher tax expense and could negatively impact our effective tax rate, financial position, results of operations and cash flows in the current and/or future periods. On December 15, 2022, the E.U. Member States formally adopted the E.U.’s Pillar Two Directive, which generally provides for a minimum effective tax rate of 15%, as established by the Organization for Economic Co-operation and Development Pillar Two Framework that was supported by over 130 countries worldwide. A significant number of countries are also implementing similar legislation. We are monitoring developments, including in countries that have enacted legislation, and do not currently expect a material adverse impact to the financial statements. We will continue to evaluate Pillar Two legislation and other future tax law changes that could result in negative impacts. In addition, tax-law amendments in the U.S. and other jurisdictions could significantly impact how U.S. multinational corporations are taxed. Although we cannot predict whether
24
Table of Contents
or in what form such legislation will pass, if enacted it could have an adverse effect on our business, financial condition or results of operations.
A material weakness in our internal controls could have a material adverse effect on us.
Effective internal controls are necessary for us to provide reasonable assurance with respect to our financial reports and to adequately mitigate the risk of fraud. If we cannot provide reasonable assurance with respect to our financial reports and adequately mitigate the risk of fraud, our reputation and results of operations could be harmed. Internal control over financial reporting may not prevent or detect misstatements because of its inherent limitations, including the possibility of human error, the circumvention or overriding of controls, or fraud. Therefore, even effective internal controls can provide only reasonable assurance with respect to the preparation and fair presentation of financial statements. In addition, projections of any evaluation of effectiveness of internal control over financial reporting to future periods are subject to the inherent risk that the control may become inadequate because of changes in conditions or because the degree of compliance with the policies or procedures may deteriorate.
A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the Company's annual or interim financial statements will not be prevented or detected on a timely basis. A material weakness in our internal control over financial reporting could adversely impact our ability to provide timely and accurate financial information. If we are unable to report financial information timely and accurately or to maintain effective disclosure controls and procedures, our business, financial condition or results of operations could be adversely affected.
Risks Related to Business Combinations and Ventures
Strategic transactions, including acquisitions and divestitures, involve significant risks and uncertainties that could adversely affect our business, financial condition, results of operations and cash flows.
Strategic acquisitions and divestitures we have made in the past (including the Issuer Solutions Acquisition and the 2026 Worldpay Minority Sale), and may make in the future, present significant risks and uncertainties that could adversely affect our business, financial condition, results of operations and cash flows. These risks include the following:
•difficulty in evaluating potential acquisitions, including the risk that our due diligence does not identify or fully assess valuation issues, potential liabilities, regulatory or legal non-compliance issues, or other acquisition risks;
•difficulty and expense in integrating newly acquired businesses and operations, including combining solution and service offerings, and in entering into new markets in which we are not experienced, in an efficient and cost-effective manner while maintaining adequate standards, controls and procedures, and the risk that we may encounter significant unanticipated costs or other problems associated with integration;
•difficulty and expense in consolidating, integrating, and rationalizing IT infrastructure, integrating acquired software, and remediating regulatory or legal non-compliance in acquired entities;
•challenges in achieving strategic objectives, cost savings, revenue growth, and other benefits expected from acquisitions on the time frame anticipated or at all;
•risk that any strategic transaction has an adverse effect on existing business relationships with suppliers and customers, or costs or dis-sysnergies exceed expectations;
•risk that our markets do not evolve as anticipated and that the strategic acquisitions and divestitures do not prove to be those needed to be successful in those markets;
•risk that acquired systems expose us to cybersecurity and other data security risks;
•costs to reach appropriate standards to protect against cybersecurity and other data security risks, or the timelines to achieve such standards, may exceed those estimated in diligence;
•risk that acquired companies are subject to new regulatory regimes or oversight where we have limited experience, which may result in additional compliance costs, remediation expenses, and potential regulatory penalties;
•risk that we assume or retain, or that companies we have acquired have assumed or retained or otherwise become subject to, significant liabilities that exceed the limitations of any applicable indemnification provisions or the financial resources of any indemnifying parties;
•risk that indemnification related to businesses divested or spun-off that we may be required to provide or otherwise bear may be significant and could negatively impact our business;
•risk of exposure to potential liabilities arising out of applicable state and federal fraudulent conveyance laws and legal distribution requirements from spin-offs in which we or companies we have acquired were involved;
25
Table of Contents
•risk that we may be responsible for unanticipated U.S. federal income tax liabilities related to acquisitions or divestitures;
•risk that we are not able to complete strategic divestitures within expected time frames or on satisfactory terms and conditions, including obtaining enforceable non-competition arrangements applicable to certain of our business lines;
•potential loss of key employees or customers of the businesses acquired or to be divested; and
•risk of diverting the attention of senior management from our existing operations.
We have substantial goodwill and other intangible assets recorded as a result of acquisitions, and a severe or extended economic downturn could cause these assets to become impaired, requiring write-downs that would reduce our operating income.
As of December 31, 2025, goodwill aggregated to $17.8 billion, or 53% of total assets, and intangible assets aggregated to $1.0 billion, or 3% of total assets. Current accounting rules require goodwill to be assessed for impairment at least annually or whenever changes in circumstances indicate potential impairment and require intangible assets with finite useful lives to be reviewed for impairment whenever events or changes in circumstances indicate that the carrying amount may not be recoverable. Factors that may be considered a change in circumstance include significant underperformance relative to historical or projected future operating results, a significant decline in our stock price and market capitalization, and negative industry or economic trends. If worldwide or U.S. economic conditions decline significantly with prolonged negative impacts to bank spending and consumer behavior, or if other business or market changes significantly impact our outlook, then the remaining carrying amount of our goodwill and other intangible assets may no longer be recoverable, and we may be required to record an impairment charge, which would have a negative impact on our results of operations. We will continue to monitor the fair value of our reporting units and other intangible assets as well as our market capitalization and the impact of any prolonged economic downturn on our business to determine the likelihood of impairment.
Risks Related to Our Indebtedness
Our existing debt levels and future levels under existing facilities and debt service requirements may adversely affect us, including our financial condition or business flexibility, and prevent us from fulfilling our obligations under our outstanding indebtedness.
As of December 31, 2025, we had total debt of approximately $13.1 billion. Our level of debt, or any increase in our debt level, could adversely affect our business, financial condition, operating results and operational flexibility, including as follows: (i) the debt level may cause us to have difficulty borrowing money in the future for working capital, capital expenditures, acquisitions or other purposes; (ii) our debt level may limit operational flexibility and our ability to pursue business opportunities and implement certain business strategies; (iii) some of our debt has a variable rate of interest, which exposes us to the risk of increased interest rates; (iv) we have a higher level of debt than some of our competitors or potential competitors, which may cause a competitive disadvantage and may reduce flexibility in responding to changing business and economic conditions, including increased competition and vulnerability to general adverse economic and industry conditions; (v) there are significant debt maturities or maturities that may need to be refinanced, potentially at higher rates; and (vi) failure to satisfy our obligations under our outstanding debt or failure to comply with the financial or other restrictive covenants contained in the indenture governing our senior notes or in our credit facilities could result in an event of default that could cause all of our debt to become due and payable, and cross-default provisions in our credit agreements could cause a default on one facility to trigger defaults across multiple financing arrangements, potentially accelerating repayment obligations beyond the initially defaulted facility.
On January 9, 2026, FIS incurred debt of approximately $7.7 billion to finance the cash portion of the Issuer Solutions Acquisition. Accordingly, the indebtedness of FIS and its subsidiaries following completion of the Issuer Solutions Acquisition is substantially greater than FIS' indebtedness prior to completion of the acquisition. FIS' substantially increased indebtedness could have the effect, among other things, of reducing FIS' flexibility to respond to changing business and economic conditions. In addition, the amount of cash required to pay interest on FIS' increased indebtedness levels will increase, and thus the demands on FIS' cash resources will be greater than the amount of cash flows required to service the indebtedness of FIS prior to the acquisition. The increased levels of indebtedness following completion of the acquisition could reduce funds available to engage in investments in product development, fund working capital, capital expenditures, acquisitions and other general corporate purposes, and may create competitive disadvantages for FIS relative to other companies with lower debt levels. If FIS does not achieve the expected benefits from the acquisition, then FIS' ability to service its indebtedness, and thereby reduce its leverage levels, may be adversely impacted.
26
Table of Contents
We have exposure to fluctuations in the Euro-USD exchange rates, which could negatively affect our cost to service or refinance our Euro-denominated debt securities.
At December 31, 2025, the Company had outstanding approximately €3.4 billion aggregate principal amount of Euro-denominated senior notes and approximately €0.1 billion aggregate principal amount of Euro-denominated commercial paper, or the combined equivalent of approximately $4.1 billion aggregate principal amount. A vast majority of this EUR denominated indebtedness has been economically converted into USD through derivative instruments (see "Financial Instruments" in note 15 to the consolidated financial statements).
If our cash flows generated in foreign currencies are insufficient to settle our foreign currency denominated indebtedness, then we may need to exchange U.S. Dollars or funds in other currencies to make such payments, which could result in increased costs to us in the event of adverse changes in currency exchange rates. We have utilized and expect to continue to utilize foreign currency forward contracts and other hedges in an effort to mitigate currency risk, but we cannot make assurances that such hedging arrangements will be effective or will remain available to us on acceptable terms, or at all. In addition, we cannot predict economic and market conditions (including prevailing interest rates and foreign currency exchange rates) at the applicable times when our various series of Euro-denominated indebtedness are scheduled to mature, nor can we predict the impact of governmental monetary, trade or tax policy changes that could cause disproportionate foreign exchange rate movements. We cannot provide any assurance that we would be able to refinance any series of our Euro-denominated indebtedness on acceptable terms at any such time, all of which could have an adverse financial impact on us.
Rising interest rates could increase our borrowing costs.
Our exposure to market risk for changes in interest rates relates to our short-term commercial paper borrowings and revolving credit facilities. Interest rates have increased significantly from recent historical levels and may remain elevated for an extended period. In response to the current interest rate environment, we may need to rebalance our variable debt instruments, potentially increasing our reliance on certain facilities while reducing others. In the future, we may have additional borrowings under existing or new variable-rate debt. Increases in interest rates on variable-rate debt would increase our interest expense. A sustained higher interest rate environment could increase the cost of refinancing existing debt and incurring new debt, create challenges in accessing certain credit markets, and limit our flexibility in managing our debt portfolio composition, which could have an adverse effect on our financing costs and overall financial condition.
Credit ratings, if lowered below investment grade, would adversely affect our cost of funds and liquidity.
The Company maintains investment grade credit ratings from the major U.S. rating agencies on its senior unsecured debt (S&P BBB, Moody's Baa2, Fitch BBB), as well as its commercial paper program (S&P A-2, Moody's P-2, Fitch F2). Failure to maintain investment grade rating levels could adversely affect the Company's cost of funds and liquidity and access to certain capital markets but would not have an adverse effect on our ability to access our existing revolving credit facilities. Please note that a security rating is not a recommendation to buy, sell or hold securities, that it may be subject to revision or withdrawal at any time by the assigning rating organization, and that each rating should be evaluated independently of any other rating.
Statement Regarding Forward-Looking Information
The statements contained in this Form 10-K or in our other documents or in oral presentations or other management statements that are not purely historical are forward-looking statements within the meaning of the U.S. federal securities laws. Statements that are not historical facts, as well as other statements about our expectations, beliefs, intentions, or strategies regarding the future, or other characterizations of future events or circumstances, are forward-looking statements. Forward-looking statements include statements about anticipated financial outcomes, including any earnings outlook or projections, projected revenue or expense synergies or dis-synergies, business and market conditions, outlook, foreign currency exchange rates, deleveraging plans, expected dividends and share repurchases of the Company, the Company's sales pipeline and anticipated profitability and growth, plans, strategies and objectives for future operations, strategic value creation, risk profile and investment strategies, any statements regarding future economic conditions or performance and any statements with respect to the future impacts of the recently completed acquisition of the Issuer Solutions Business, which has been rebranded as FIS Total IssuingTM Solutions. These statements may be identified by words such as "expect," "anticipate," "intend," "plan," "believe," "will," "should," "could," "would," "project," "continue," "likely," and similar expressions, and include statements reflecting future results or outlook, statements of outlook and various accruals and estimates. These statements relate to future events and our future results and involve a number of risks and uncertainties.
27
Table of Contents
Forward-looking statements are based on management's beliefs as well as assumptions made by, and information currently available to, management.
Actual results, performance or achievement could differ materially from these forward-looking statements. The risks and uncertainties to which forward-looking statements are subject include the following, without limitation:
•changes in general economic, business and political conditions, a recession, intensified or expanded international hostilities, acts of terrorism, fluctuation in rates of inflation or interest, effects of announced or future tariff increases and any resulting regulatory changes in global trade relations and changes in consumer or business confidence;
•changes in either or both the United States and international lending, capital and financial markets or currency fluctuations;
•the risk that acquired businesses, including FIS Total IssuingTM Solutions, will not be integrated successfully, will not provide the expected benefits, or that the integration will be more costly or more time-consuming and complex than anticipated;
•the risk that cost savings and synergies anticipated to be realized from acquisitions, including the Issuer Solutions Acquisition, may not be fully realized or may take longer to realize than expected or that costs may be greater than anticipated;
•the risks of doing business internationally;
•the effect of legislative initiatives or proposals, statutory changes, governmental or applicable regulations and/or changes in industry requirements, including privacy, data protection, cybersecurity, cyber resilience and AI laws and regulations;
•our ability to comply with climate change legal and regulatory requirements and to maintain practices that meet our stakeholders' evolving expectations;
•the risks of reduction in revenue from the elimination of existing and potential customers due to consolidation in, or new laws or regulations affecting, the banking, retail and financial services industries or due to financial failures or other setbacks suffered by firms in those industries;
•changes in the growth rates of the markets for our solutions;
•the amount, declaration and payment of future dividends is at the discretion of our Board of Directors and depends on, among other things, our investment opportunities, results of operations, financial condition, cash requirements, future prospects, and other factors that may be considered relevant by our Board of Directors, including legal and contractual restrictions;
•the amount and timing of any future share repurchases is subject to, among other things, our share price, our other investment opportunities and cash requirements, our results of operations and financial condition, our future prospects and other factors that may be considered relevant by our Board of Directors and management;
•failures to adapt our solutions to changes in technology or in the marketplace;
•internal or external security or privacy breaches of our systems, including those relating to unauthorized access, theft, corruption or loss of personal information and computer viruses and other malware affecting our software or platforms, and the reactions of customers, card associations, government regulators and others to any such events;
•the risk that implementation of software, including software updates, for customers or at customer locations or employee error in monitoring our software and platforms may result in the corruption or loss of data or customer information, interruption of business operations, outages, exposure to liability claims or loss of customers;
•the risk that partners and third parties may fail to satisfy their legal obligations to us;
•risks associated with managing pension cost, cybersecurity issues, IT outages experienced;
•our ability to navigate the opportunities and risks associated with using and/or incorporating AI technologies into our business;
•the reaction of current and potential customers to communications from us or regulators regarding information security, risk management, internal audit or other matters;
•competitive pressures on pricing related to the decreasing number of community banks in the U.S., the development of new disruptive technologies competing with one or more of our solutions, increasing presence of international competitors in the U.S. market and the entry into the market by global banks and global companies with respect to certain competitive solutions, each of which may have the impact of unbundling individual solutions from a comprehensive suite of solutions we provide to many of our customers;
•the failure to innovate in order to keep up with new emerging technologies, which could impact our solutions and our ability to attract new, or retain existing, customers;
•an operational or natural disaster at one of our major operations centers;
•failure to comply with applicable requirements of payment networks or changes in those requirements;
•fraud by bad actors; and
28
Table of Contents
•other risks detailed elsewhere in the "Risk Factors" section and other sections of this report, and in our other filings with the SEC.
Other unknown or unpredictable factors also could have a material adverse effect on our business, financial condition, results of operations and prospects. Accordingly, readers should not place undue reliance on these forward-looking statements. These forward-looking statements are inherently subject to uncertainties, risks and changes in circumstances that are difficult to predict. Except as required by applicable law or regulation, we do not undertake (and expressly disclaim) any obligation and do not intend to publicly update or review any of these forward-looking statements, whether as a result of new information, future events or otherwise.
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Cybersecurity Risk Management and Strategy
Cybersecurity is fundamental to FIS' complex, global business. As part of our business, FIS and its vendors, technology partners, and clients electronically receive, process, store and transmit a wide range of confidential information, including sensitive customer information and consumer personal data. Our operations extend to managing payment systems, cash access and prepaid card systems. Cyberattacks on information technology systems and the vendors and technological supply chain they rely on continue to grow in frequency, complexity and sophistication. This is a trend we expect to continue. Cyberattacks have garnered significant attention from individuals, businesses, governmental entities and the media drawing the focus of a large ecosystem of criminal threat actors. The objectives of these cyberattacks include, among other outcomes, gaining unauthorized access to systems to disrupt operations, steal information, seek ransom payments from victims, perpetrate financial fraud, or sell stolen information. Perpetrators of cyberattacks attempt to exploit technical, human, social, and organizational vulnerabilities to gain unauthorized access. There is a growing trend of identifying and exploiting vulnerabilities in widely used technologies or vendor systems, allowing a single compromise or failure to extend unauthorized access to numerous systems. We have also noted increasing trends of targeting payment systems, including credit, debit, and prepaid card systems, for purposes of eliciting unauthorized or fraudulent transactions.