Item 1A. Risk Factors
The risk factors noted in this section and other factors noted throughout this Form 10-K, including those risks identified in Part II, Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” describe examples of risks, uncertainties and events that may cause our actual results to differ materially from those contained in any forward-looking statement. If one or more of these risks or uncertainties materialize, or if underlying assumptions prove incorrect, actual outcomes may vary materially from those included in this Form 10-K.
Risks Related to Our Business
If our security measures are breached, or unauthorized access to sensitive data is otherwise obtained, our solution may not be perceived as being secure, clients may reduce the use of or stop using our solution, our ability to attract new clients may be harmed and we may incur significant liabilities.
Our solution involves the collection, storage and transmission of confidential and proprietary information belonging to our clients, their current, former and potential employees and, in certain cases, dependents and beneficiaries of clients’ current and former employees. This information includes personal identifying information, as well as financial and payroll data. HCM software is often targeted, and we have been targeted, in cyber-attacks, including computer viruses, phishing attacks, malicious software programs (including distributed denial of services (DDoS) attacks) and other information security breaches, which could result in unauthorized access to or release, gathering, monitoring, misuse, loss or destruction of our or our clients’ sensitive data or otherwise disrupt our or our clients’ business operations. The techniques used to obtain unauthorized access to information, disable or degrade service, or sabotage systems change frequently, and are increasingly more complex and sophisticated, including due to the use of AI. If threat actors are able to circumvent our security measures and we are unable to detect or contain such intrusion into our system, our or our clients’ sensitive data (including client employees’ personal data) may be compromised. Further, in order to provide our services, certain of our employees have access to sensitive information about our clients’ employees. While we conduct background checks of our employees and limit access to systems and data, it is possible that one or more of these individuals may circumvent these controls, resulting in a security breach.
In certain limited circumstances, we utilize relationships with third parties to aid in data management and transaction processing. Certain third parties with which we do business have been subject to cyber-attacks, one of which resulted in unauthorized access to data of certain Company clients and their employees as well as Company data and employee records. These third parties may be sources of cybersecurity or other technological risks in the future, including operational errors, design or manufacturing defects, system interruptions or breaches, unauthorized disclosure of confidential information and misuse of intellectual property. Even without a direct breach of our systems, cyber-attacks on such third-party vendors or on our clients could adversely impact our business and reputation.
Although we have security measures in place to protect client information and prevent data loss and other security breaches, these measures have been in the past and in the future may be breached as a result of third-party action, employee error, third-party or employee malfeasance or other events. In addition, new computing technologies, including quantum computing, new discoveries in the field of cryptography or other developments could result in a compromise or breach of the algorithms we or our authorized third parties use or have used to encrypt and protect data. Globally, cybersecurity attacks are increasing in number and the threat actors are increasingly organized and well financed, or at times supported by state actors. In addition, geopolitical tensions or conflicts may create a heightened risk of cybersecurity attacks. Because the techniques used to obtain unauthorized access to or to sabotage systems change frequently, we may not be able to anticipate these techniques and implement adequate preventative, responsive or protective measures. As these threats continue to evolve and increase, including due to the use of AI by us and third parties, we continue to invest significant resources, and may be required to invest significant additional resources, to modify and enhance our cybersecurity controls and to investigate and remediate any security vulnerabilities. Our ability to address data or cybersecurity incidents may also depend on the timing and nature of assistance that may be provided from relevant governmental or law enforcement agencies. While we currently maintain a cyber liability insurance policy, cyber liability insurance may be inadequate or may not be available in the future on acceptable terms, or at all. In addition, our cyber liability insurance policy may cover only a portion of losses incurred in investigating or remediating an incident, if at all, and may not cover all claims made against us. Undergoing a government investigation or defending a lawsuit, regardless of merit, could be costly and divert management’s attention from our business and operations.
Any actual or perceived breach of our security could damage our reputation, cause existing clients to discontinue the use of our solution, prevent us from attracting new clients, or subject us to third-party lawsuits, regulatory investigations and fines or other actions or liabilities, any of which could adversely affect our business, operating results or financial condition.
Any damage, failure or disruption of our network infrastructure or data centers could impair our ability to effectively provide our solution, harm our reputation and adversely affect our business.
Our network infrastructure is a critical part of our business operations. Our clients access our solution through standard web browsers, smart phones, tablets and other web-enabled devices and depend on us for fast and reliable access to our solution. We serve all of our clients from our fully redundant data centers located in Oklahoma, Texas and Arizona. Our network infrastructure and data centers are vulnerable to damage, failure and disruption.
19
In the future, we may experience issues with our computing and communications infrastructure or data centers caused by the following factors:
•
human error;
•
telecommunications failures or outages from third-party providers;
•
computer viruses or cyber-attacks;
•
break-ins or other security breaches;
•
acts of terrorism, sabotage, intentional acts of vandalism or other misconduct;
•
tornadoes, fires, earthquakes, hurricanes, floods and other natural disasters;
•
insufficient supply or loss of power; and
•
other unforeseen interruptions or damages.
If our network infrastructure or our clients’ ability to access our solution is interrupted, client and employee data from recent transactions may be permanently lost, and we could be exposed to significant claims by clients, particularly if the access interruption is associated with problems in the timely delivery of funds payable to employees or tax authorities. Further, any adverse changes in service levels at our data centers resulting from damage to or failure of our data centers could result in disruptions in our services. Any significant instances of system downtime or performance problems at our data centers could negatively affect our reputation and ability to attract new clients, prevent us from gaining new or additional business from our current clients, or cause our current clients to terminate their use of our solution, any of which would adversely impact our revenues. In addition, if our network infrastructure and data centers fail to support increased capacity due to growth in our business, our clients may experience interruptions in the availability of our solution. Such interruptions may reduce our revenues, cause us to issue refunds to clients or adversely affect our retention of existing clients, any of which could have a negative impact on our business, operating results or financial condition.
If we are not able to develop enhancements and new applications, keep pace with technological developments or respond to future disruptive technologies, we might not remain competitive and our business could be adversely affected.
Our continued success will depend on our ability to adapt and innovate. In order to attract new clients and increase revenues from existing clients, we need to enhance, add new features to and improve our existing applications and introduce new applications. The success of any enhancements or new features and applications depends on several factors, including timely completion and introduction and market acceptance. We may expend significant time and resources developing and pursuing sales of a particular enhancement or application that may not result in revenues in the anticipated time frame or at all, or may not result in revenue growth sufficient to offset increased expenses. Further, changing legal and regulatory requirements may delay the development or introduction of enhancements or new applications or render certain of our applications obsolete. If we are unable to successfully develop enhancements, new features or new applications to meet client needs, our business and operating results could be adversely affected.
In addition, because our applications are designed to operate on a variety of network, hardware and software platforms using internet tools and protocols, we must continuously modify and enhance our applications to keep pace with changes in internet-related hardware, software, communication, browser and database technologies. If we are unable to respond in a timely and cost-effective manner to these rapid technological developments, our current and future applications may become less marketable and less competitive or even obsolete.
Our success is also subject to the risk of future disruptive technologies, such as AI and machine learning. The failure to develop enhancements to our applications for, or that incorporate, technologies such as natural language processing, AI, and machine learning may impact our ability to increase the efficiency of and reduce costs associated with our clients’ operations. If new technologies emerge that are able to deliver HCM solutions at lower prices, more efficiently or more conveniently, such technologies could adversely impact our ability to compete. We have made significant investments in developing, testing, deploying and supporting AI-powered tools in our solution. Continuing to develop, test, deploy and support resource-intensive AI-powered tools will require additional investment and may increase our costs. To the extent that we do not effectively address server capacity constraints or otherwise upgrade our systems and data centers to accommodate actual and anticipated changes in technology and our client base, we may experience service interruptions and performance issues, which could result in negative publicity, harm to our reputation and decreased demand for our solution, require us to pay significant penalties or fines or subject us to litigation, claims or other disputes, any of which could have an adverse effect on our business, results of operations and financial condition.
The market in which we participate is highly competitive, and if we do not compete effectively, our business, operating results or financial condition could be adversely affected.
The market for HCM software is highly competitive, rapidly evolving and fragmented. If we are unable to compete effectively, our business, operating results or financial condition could be adversely affected. We expect competition to
20
continue to remain intense as new technologies and new market entrants emerge and aggressive pricing and client retention strategies persist. Competition in the HCM solutions market is primarily based on service responsiveness, application quality and reputation, breadth of service and product offering, and price. Certain competitors have access to larger clients and major distribution agreements with consultants, software vendors and distributors and a more established global presence than we do. Certain of our competitors have in the past or may in the future:
•
adapt more rapidly to new or emerging technologies and changes in client requirements;
•
develop superior products or services, gain greater market acceptance and expand their product and service offerings more efficiently or rapidly;
•
offer products and services that we may not offer individually or at all, or bundle products and services in a manner that provides them with a price advantage;
•
offer products that can be integrated with other software or systems, whereas our single software may not allow for such integration;
•
develop and implement control processes that drive internal efficiencies, resulting in a better client experience;
•
establish and maintain partnerships with third parties that enhance and expand their product offering to business clients and employees;
•
take advantage of acquisition and other opportunities for expansion more readily;
•
maintain a lower cost basis;
•
secure contractual terms and implement other client retention strategies that increase our costs to acquire new clients;
•
adopt more aggressive or desirable pricing policies;
•
devote greater resources to the promotion, marketing and sale of their products and services; and
•
devote greater resources to the research and development of their products and services.
Our competitors offer HCM solutions that may overlap with one, several or all categories of the applications we offer. We compete with companies such as Automatic Data Processing, Inc., Dayforce, Inc., Intuit, Inc., Oracle Corporation, Paychex, Inc., Paylocity Holding Corporation, SAP SE, ServiceNow, Inc., Ultimate Kronos Group, Workday, Inc., and other international, national, regional, and local providers. Our competitors provide HCM solutions by various means. Although certain providers continue to deliver legacy enterprise software, most now offer cloud-based solutions, resulting in increased competition for clients seeking the greater flexibility and access to information provided by cloud-based offerings. Furthermore, the HCM industry has experienced an emergence of white label and embedded payroll offerings. The proliferation of white label offerings and products and technologies utilizing embedded payroll systems may adversely affect our competitive position.
In addition, some of our principal competitors offer their products or services at a lower price, which has resulted in pricing pressures. If we are unable to maintain our pricing levels, our operating results would be negatively impacted. In addition, pricing pressures and increased competition generally could hinder our ability to attract and retain clients and could result in reduced sales, reduced margins, losses or the failure of our solution to maintain widespread market acceptance, any of which could adversely affect our business, operating results or financial condition.
Our business depends on our clients’ continued use of our applications, their purchases of additional applications from us and our ability to add new clients. Any decline in our clients’ continued use of our applications or purchases of additional applications could adversely affect our business, operating results or financial condition.
In order for us to maintain or improve our operating results, it is important that our current clients continue to use our applications and purchase additional applications from us, and that we add new clients. Our annual revenue retention rate fluctuates as a result of a number of factors, including but not limited to the level of client satisfaction with our applications, pricing, the prices of competing products or services, mergers and acquisitions affecting our client base, reduced hiring by our clients or reductions in our clients’ spending levels. Many of our clients have the right to cancel their agreements with us for any or no reason by providing 30 days’ prior written notice. Moreover, from time to time, clients choose not to continue to use our applications at the same or higher level of service, if at all. Because we charge our clients on a per employee basis for certain services we provide, the performance of certain of our offerings is sensitive to changes in the labor market. Any increase or decrease in the number of employees of our clients will have a positive or negative impact, respectively, on our results of operations. As technology continues to evolve, more tasks historically performed by people have been and may continue to be replaced by automation, robotics, AI and other technological advances outside of our control, which may reduce our clients’ need for existing or future employees who are or would be potential users of our solution. If our clients reduce headcount, do not continue to use our applications, renew on less favorable terms or fail to purchase additional applications, or if we fail to add new clients, our annual revenue retention rate may decline and our business, operating results or financial condition could be adversely affected.
21
Our business, operating results or financial condition could be adversely affected if our solution fails to perform properly or our clients are not satisfied with our services.
Our solution is inherently complex and may in the future contain, or develop, undetected defects or errors. Any defects in our applications could adversely affect our reputation, impair our ability to sell our applications in the future and result in significant costs to us. The costs incurred to correct any application defects may be substantial and could adversely affect our business, operating results or financial condition. Any defects in functionality or defects that cause interruptions in the availability of our applications could result in:
•
loss or delayed market acceptance and sales of our applications;
•
termination of service agreements or loss of clients;
•
credits, refunds or other liability to clients, including reimbursements for any fees or penalties assessed by regulatory agencies;
•
breach of contract, breach of warranty or indemnification claims against us, which may result in litigation;
•
diversion of development and service resources;
•
increased scrutiny of our solution from regulatory agencies; and
•
injury to our reputation.
Because of the large amount of data that we collect and manage, it is possible that hardware failures or errors in our applications could result in data loss or corruption or cause the information that we collect to be incomplete or contain inaccuracies that our clients regard as significant. From time to time, our clients assert claims against us alleging that they suffered damages due to a defect, error, or other failure of our solution. We also face potential liability from our clients, and possibly third parties, in the event we fail to report information, particularly wage and earnings information, criminal records or other potentially negative information, or wrongly report such information. From time to time, we have been subject to claims and lawsuits by current and potential employees of our clients, alleging that we provided to our clients inaccurate or improper information that negatively affected the clients. Although the resolutions of these lawsuits have not had a material adverse effect on us to date, the costs of such claims, including settlement amounts or punitive damages, could be material in the future, could cause adverse publicity and reputational damage, could divert the attention of our management, could subject us to equitable remedies relating to the operation of our business and provision of services and result in significant legal expenses, all of which could have a material adverse effect on our business, financial condition and results of operations and adverse publicity, and could result in the loss of existing clients and make it difficult to attract new clients. Our errors and omissions insurance may be inadequate or may not be available in the future on acceptable terms, or at all. In addition, our policy may not cover all claims made against us, and defending a suit, regardless of its merit, could be costly and divert management’s attention. Any failures in the performance of our solution could harm our reputation and our ability to retain existing clients and attract new clients, which would have an adverse impact on our business, operating results or financial condition.
Furthermore, our business depends on our ability to satisfy our clients, both with respect to our applications and the technical support provided to help our clients use the applications that address the needs of their businesses. We use our in-house deployment personnel to implement and configure our solution and provide support to our clients. If a client is not satisfied with the quality of our solution, the applications delivered or the support provided, we could incur additional costs to address the situation, our profitability might be negatively affected, and the client’s dissatisfaction with our deployment or support service could harm our ability to sell additional applications to that client. In addition, our sales process is highly dependent on the reputation of our solution and applications and on positive recommendations from our existing clients. Any failure to maintain high-quality technical support, or a market perception that we do not maintain high-quality technical support, could adversely affect client retention, our reputation, our ability to sell our applications to existing and prospective clients, and, as a result, our business, operating results or financial condition.
We face challenges related to attracting and retaining larger clients, including demand for customized features, longer sales cycles and less predictability in completing sales.
In some cases, prospective clients, especially larger companies, expect customized features and functions unique to their business processes, or are seeking to integrate our solutions with other products. If we do not meet the demands of such prospective clients, the market for our solution will be more limited and our business could be adversely affected. Furthermore, pursing larger clients may result in a longer sales cycle and, in some cases, we may devote a significant amount of support and service resources to attract and acquire larger prospective clients with no guarantee that these prospective clients will adopt our solution.
We are dependent on the leadership of our key executives and, if we fail to retain such key executives, our business could be adversely affected.
We believe the success of our business and execution of our strategy depend, in part, on the leadership of Chad Richison, our founder, Chief Executive Officer and Chairman of the Board of Directors, and that of our other key executive officers and
22
employees. The loss of their leadership, expertise and experience could adversely impact our operations. Effective succession planning is also important to our long-term success. Changes in our management team may be disruptive to our business, and any failure to ensure effective transfer of knowledge or successfully integrate key new hires or promoted employees could adversely affect our business and results of operations. The loss of the services of any of our executive officers or other key employees, or our inability to attract highly qualified senior management and other key personnel, could harm our business. In addition, legal and regulatory developments may affect our ability to enforce post-termination obligations of certain employees with respect to non-competition, non-solicitation and protection of confidential information. Our business could be adversely affected if a key executive leaves Paycom and interferes with our client, employee and/or other business relationships. We do not maintain key man life insurance on any of our executive officers.
If we are unable to attract and retain qualified personnel, including software developers, product managers and skilled IT, sales, marketing and operational personnel, our ability to develop and market new and existing products and, in turn, increase our revenue and profitability could be adversely affected.
Our future success is dependent on our ability to continue to enhance and introduce new applications. As a result, we are heavily dependent on our ability to attract and retain qualified software developers, product managers and IT personnel with the requisite education, background and industry experience. In addition, to continue to execute our growth strategy, we must also attract and retain qualified sales, marketing and operational personnel capable of supporting a larger and more diverse client base. The technology industry is characterized by a high level of employee mobility and aggressive recruiting among competitors, and competition is particularly intense for qualified software developers, product managers and IT personnel. In addition, the nature of the office environment is changing as employers continue to offer various remote or hybrid work arrangements, which can be an important factor in a candidate’s decision on employment. We maintain an office-centric operational model. Certain companies with which we compete for talent offer work arrangements more flexible than ours, which may impact our ability to attract and retain qualified personnel if potential or current employees prefer such policies.
The competition for qualified personnel has been amplified by new immigration laws and policies that limit software companies’ ability to recruit internationally. Although such changes in immigration laws and policies have not had a significant direct impact on our workforce to date, the ensuing increase in demand for software developers and IT personnel could impair our ability to attract or retain skilled employees and/or significantly increase our costs to do so. Furthermore, identifying and recruiting qualified personnel and training them in the use of our applications requires significant time, expense and attention, and it can take a substantial amount of time before our employees are fully trained and productive. The unplanned loss of the services of a significant number of skilled employees could be disruptive to our development efforts, which may adversely affect our business by causing us to lose clients, increase operating expenses or divert management’s attention to recruit replacements for the departed employees.
Our business and operations have experienced significant growth and organizational change. If we fail to manage such growth and change effectively, we may be unable to execute our business plan, maintain high levels of service or adequately address competitive challenges.
We have experienced, and may continue to experience, significant growth in our operations, which has placed, and may continue to place, significant demands on our management, operational and financial resources. We have also experienced significant growth in the number of clients and transactions and the amount of client and employee data that our infrastructure supports. As a result, our organizational structure and recording systems and procedures are becoming more complex as we improve our operational, financial and management controls. Our success depends, in part, on our ability to manage this growth and organizational change effectively. Moreover, our international expansion efforts are exacerbating many of these challenges. To manage the effects of our growth, we must continue to improve our operational, financial and management controls and our reporting systems and procedures. The failure to effectively manage growth could result in (i) declines in the quality of, or client satisfaction with, our applications or service delivery, (ii) increases in costs, (iii) difficulties or delays in introducing new applications or (iv) other operational difficulties, any of which could adversely affect our business by impairing our ability to retain and attract clients or sell additional applications to our existing clients. In addition, our ability to expand our sales force may be constrained by the willingness and availability of qualified personnel to staff and manage new offices and our success in recruiting and training sales personnel. If our expansion efforts are unsuccessful, our business, operating results or financial condition could be adversely affected.
The failure to develop and maintain our brand cost-effectively could have an adverse effect on our business.
We believe that developing and maintaining widespread awareness of our brand in a cost-effective manner is critical to achieving widespread acceptance of our solution and is an important element in attracting new clients and retaining existing clients. Successful promotion of our brand depends largely on the effectiveness of our marketing efforts and on our ability to provide reliable and useful applications at competitive prices. Brand promotion activities, including increased spending on our national media campaigns, may not yield increased revenues, and even if they do, any increased revenues may not offset the expenses incurred in building our brand. If we fail to successfully promote and maintain our brand, or incur substantial expenses in an unsuccessful attempt to promote and maintain our brand, we may fail to attract enough new clients or retain our existing
23
clients to the extent necessary to realize a sufficient return on our brand-building efforts, which could have an adverse effect on our business.
As we continue to enhance our solution to serve clients located outside of the United States, our business is subject to risks associated with international operations.
An element of our growth strategy is to expand our operations and client base, including in markets outside of the United States. Launching into international markets and doing business internationally involves a number of risks, including but not limited to:
•
multiple, conflicting and changing laws and regulations such as privacy regulations, tax laws, export and import restrictions, employment laws, regulatory requirements and other governmental approvals, permits, and licenses;
•
failure to obtain and maintain regulatory approvals for the use of our products in various countries;
•
lack of brand recognition, including greater brand recognition of local or other global competitors who have more established operations in the markets we are seeking to enter;
•
lack of familiarity with local, regional or national politics, culture, economics, market conditions and commerce;
•
complexities and difficulties in obtaining protection for and enforcing our intellectual property rights;
•
difficulties in staffing and managing foreign operations;
•
financial risks, such as the impact of local and regional financial crises on demand for our products and exposure to foreign currency exchange rate fluctuations;
•
natural disasters, political and economic instability, including wars, terrorism and political unrest, outbreak of disease, boycotts, curtailment of trade and other business restrictions;
•
certain expenses including, among others, expenses for travel, translation and insurance; and
•
regulatory and compliance risks that relate to maintaining accurate information and control over sales and activities that may fall within the purview of the U.S. Foreign Corrupt Practices Act, its books and records provisions or its anti-bribery provisions, as well as similar laws in foreign jurisdictions.
Our expansion into international markets requires significant resources and management attention and subjects us to regulatory, economic and political risks that differ from those in the United States. Because of our inexperience with international operations, we cannot ensure that our expansion into international markets will be successful, and the impact of such expansion may adversely affect our business, operating results or financial condition.
Our business depends in part on the success of our relationships with third parties.
We rely on third-party couriers to deliver payroll checks and tax forms and on financial and accounting processing systems and various financial institutions to perform financial services in connection with our applications, such as providing automated clearing house (“ACH”) and wire transfers as part of our payroll and payroll tax payment services and facilitating our Vault Visa® Payroll Card. We also rely on third parties to provide technology and content support, manufacture time clocks and process background checks. We anticipate that we will continue to depend on various third-party relationships in order to provide these and other services. Identifying, negotiating and documenting relationships with these third parties and integrating third-party content and technology requires significant time and resources. Our agreements with third parties typically are non-exclusive and do not prohibit them from working with our competitors. In addition, these third parties may not perform as expected under our agreements, which could hinder our ability to deliver certain services to our clients and negatively affect our brand and reputation. A global economic slowdown could also adversely affect the businesses of our third-party providers, hindering their ability to provide the services on which we rely. If we are unsuccessful in establishing or maintaining our relationships with these third parties, or the services provided by third parties fail to meet our clients’ or client employees’ expectations, our ability to compete in the marketplace or to grow our revenues could be impaired and our business, operating results or financial condition could be adversely affected. Furthermore, due to our dependence on financial institutions for certain services, a systemic shutdown of the banking industry or a disruption of the Federal Reserve Bank’s services, including ACH processing, would impede our ability to provide our payroll and expense reimbursement services by delaying direct deposits and other financial transactions across the United States and could have an adverse impact on our financial results and liquidity.
We employ third-party licensed software for use in our applications and the inability to maintain these licenses or errors in the software we license could result in increased costs or reduced service levels, which could adversely affect our business.
Our applications incorporate certain third-party software obtained under licenses from other companies. For example, we rely on third-party software to support our background checks application. We anticipate that we will continue to rely on third-party software and development tools from third parties in the future. If the third-party software we currently license becomes unavailable, we may be unable to identify commercially reasonable alternatives without significant cost or difficulty, or
24
available alternatives may not meet our internal cybersecurity requirements. In addition, incorporating the software used in our applications with new third-party software may require significant work and substantial investment of our time and resources. Also, to the extent that our applications depend upon the successful operation of third-party software in conjunction with our software, any undetected errors or defects in this third-party software could prevent the deployment or impair the functionality of our applications, delay new application introductions, or result in a failure of our applications and harm our reputation.
We have licensed and deployed a third-party large language model (“LLM”) on our own internal network and AI-powered tools. This LLM processes a large amount of employee and customer data, including potentially sensitive information. Unauthorized access to or a breach of this LLM software could lead to significant legal and financial repercussions for us. Also, failure to comply with continually evolving privacy, cybersecurity, and AI regulations during our use of this LLM could lead to substantial fines and damage to our reputation. Rapid advancements in technology could quickly render our existing LLM-powered tools obsolete, requiring the licensing and training of a replacement LLM at significant cost to us. The third-party LLM we license was trained on large datasets that may contain biases, and these biases can be reflected in the output of our LLM, leading to potential harm to our employees and/or customers. The third-party LLM may also produce incorrect or inaccurate outcomes, also known as “hallucinations”. The ongoing accuracy of the output of our LLM is critical for its effectiveness, and inaccurate or unreliable outputs could lead to customer dissatisfaction and potential legal liabilities.
The use of open-source software in our applications may expose us to additional risks and harm our intellectual property rights.
Some of our applications use software and models covered by open-source licenses. Usage of open-source software can lead to greater risks than use of third-party commercial software, as open-source licensors generally do not provide warranties, maintenance and support, other contractual protections or controls on the origin of the software. Furthermore, the license terms for certain open-source software or AI models may change, requiring us to pay for a commercial license or re-engineer all or a portion of certain applications or tools, resulting in significant additional costs for us. Open-source software may also present a heightened risk of security vulnerabilities, including due to the intentional acts of malicious actors who inject such vulnerabilities into the code, or to older versions of the software not remaining current with applicable updates and patches to address vulnerabilities or other bugs. From time to time, there have been claims challenging the ownership or use of certain types of open-source software against companies that incorporate such software into their products or applications. As a result, we could be subject to suits by parties claiming ownership of what we believe to be open-source software. Similarly, open-source AI models may be trained on data of unknown or uncertain provenance, which could include copyrighted or otherwise proprietary, confidential, or private information. If our applications incorporate such models, we could face claims for copyright infringement and other violations. Litigation could be costly for us to defend, have a negative effect on our operating results and financial condition or require us to devote additional development resources to change our applications. In addition, if we were to combine our applications with open-source software in a certain manner, we could, under certain types of open-source licenses, be required to release the source code of our applications. If we inappropriately use open-source software, we may be required to redesign our applications or software, discontinue the sale of our applications or software or take other remedial actions, which could adversely impact our business, operating results or financial condition.
Our increasing focus on, and investments in, automation expose us to a number of risks.
A key part of our strategy is our focus on automation. We currently utilize automation and machine learning in certain of our products and services to deliver a better experience for our clients and their employees or customers, and we expect to automate more functions within our solution in the future. We also leverage AI internally to make certain business processes more efficient. While we believe the use of these emerging technologies can present significant benefits, it also creates risks and challenges.
The development and implementation of such advanced technologies is complex. We have invested, and intend to continue to invest, significant time and resources in our automation initiatives, some or all of which may not result in new products or enhancements to our solution or services or, even if deployed, may not materially improve client or client employee experience. Furthermore, existing and prospective clients may be hesitant to adopt products that rely on automation, particularly those that utilize AI. Data sourcing, technology, integration and process issues, programmed bias in decision-making algorithms, concerns over intellectual property, concerns over incorrect or inaccurate outputs, security concerns, and the protection of privacy could impair the adoption and acceptance of our automated solutions. There also may be real or perceived social harm, unfairness, or other outcomes that undermine public confidence in the use and deployment of AI. If our investments in automation initiatives do not result in marketable products or services, or the resulting solutions do not gain market acceptance or we otherwise do not fully realize the intended benefits of these significant investments, our operating results and financial condition may suffer.
In addition, we may incur additional compliance costs to the extent our automation initiatives utilize tools and technologies that are the subject of increasing regulatory and legal scrutiny, such as our AI-powered tools. These laws and regulations are developing and vary from one jurisdiction to another. Future legislative and regulatory action, court decisions or other governmental action may adversely impact our ability to pursue our automation strategy and, in turn, may adversely impact our operations and financial results.
25
If we fail to adequately protect our proprietary rights, our competitive advantage could be impaired and we may lose valuable assets, generate reduced revenues or incur costly litigation to protect our rights.
Our success is dependent in part upon our intellectual property. We rely on a combination of copyrights, trademarks, service marks, trade secret laws and contractual restrictions to establish and to protect our intellectual property rights in the United States and in foreign jurisdictions. However, the steps we take to protect our intellectual property may be inadequate. We will not be able to protect our intellectual property if we are unable to enforce our rights or if we do not detect unauthorized use of our intellectual property. Despite our precautions, it may be possible for unauthorized third parties to copy our applications and use information that we regard as proprietary to create products or services that compete with ours.
We may be required to spend significant resources to monitor and protect our intellectual property. We have been involved in litigation in the past and litigation may be necessary in the future to protect and enforce our intellectual property rights and to protect our trade secrets. Such litigation could be costly, time-consuming and distracting to management and could result in the impairment or loss of portions of our intellectual property. Furthermore, our efforts to enforce our intellectual property rights may be met with defenses, counterclaims and countersuits attacking the validity and enforceability of our intellectual property rights. We may not be able to secure, protect and enforce our intellectual property rights or control access to, and the distribution of, our solution and proprietary information, which could adversely affect our business.
We may be sued by third parties for alleged infringement of their proprietary rights.
Considerable intellectual property development activity exists in our industry, and we expect that companies will increasingly be subject to infringement claims as the number of applications and competitors grows and the functionality of applications in different industry segments overlaps. Our competitors, as well as a number of other entities and individuals, may own or claim to own intellectual property in technology areas relating to our solution or applications. In addition, we may increasingly be subject to trademark infringement claims as our presence grows in the marketplace. From time to time, third parties have asserted and may in the future assert that we are infringing on their intellectual property rights, and we may be found to be infringing upon such rights. A claim of infringement may also be made relating to technology that we acquire or license from third parties. However, we may be unaware of the intellectual property rights of others that may cover, or may be alleged to cover, some or all of our solution, applications or brands.
The outcome of litigation is inherently unpredictable and, as a result, any future litigation or claim of infringement could (i) cause us to enter into an unfavorable royalty or license agreement, pay ongoing royalties or require that we comply with other unfavorable terms, (ii) require us to discontinue the sale of our solution or applications, (iii) require us to indemnify our clients or third-party service providers or (iv) require us to expend additional development resources to redesign our solution or applications. Any of these outcomes could harm our business. Even if we were to prevail, any litigation regarding our intellectual property could be costly and time consuming and divert the attention of our management and key personnel from our business and operations.
We may acquire other businesses, applications or technologies, which could divert our management’s attention, result in additional dilution to our stockholders and otherwise disrupt our operations and harm our operating results.
In the future, we may seek to acquire or invest in businesses, applications or technologies that we believe complement or expand our applications, enhance our technical capabilities or otherwise offer growth opportunities. The pursuit of potential acquisitions may divert the attention of management and cause us to incur expenses in identifying, investigating and pursuing suitable acquisitions, whether or not they are ultimately consummated.
We do not have any experience in acquiring other businesses. If we acquire additional businesses, we may not be able to integrate the acquired personnel, operations and technologies successfully or to effectively manage the combined business following the acquisition. We also may not achieve the anticipated benefits from the acquired business due to a number of factors, including:
•
the inability to integrate or benefit from acquired applications or services in a profitable manner;
•
unanticipated costs or liabilities associated with the acquisition;
•
the incurrence of acquisition-related costs;
•
difficulty integrating the accounting systems, operations and personnel of the acquired business;
•
difficulty and additional expenses associated with supporting legacy products and hosting infrastructure of the acquired business;
•
difficulty converting the clients of the acquired business onto our solution, including disparities in the revenues, licensing, support or services of the acquired company;
•
diversion of management’s attention from other business concerns;
•
harm to our existing relationships with clients as a result of the acquisition;
26
•
the potential loss of key employees;
•
the use of resources that are needed in other parts of our business; and
•
the use of substantial portions of our available cash to consummate the acquisition.
In addition, a significant portion of the purchase price of any companies we acquire may be allocated to acquired goodwill and other intangible assets, which must be assessed for impairment at least annually. In the future, if our acquisitions do not yield expected returns, we may be required to take charges to our operating results based on this impairment assessment process, which could harm our results of operations. Acquisitions could also result in the incurrence of debt or issuances of equity securities, which would result in dilution to our stockholders.
Legal and Regulatory Risks
Changes in laws, government regulations and policies could have a material adverse effect on our business and results of operations.
Many of our applications are designed to assist our clients in complying with government regulations that continually change. The introduction of new regulatory requirements, or new interpretations of existing laws or regulations, could increase our cost of doing business, decrease our revenues and net income or require us to make changes to our applications. Moreover, changing regulatory requirements may make the introduction of new applications and enhancements more costly or more time-consuming than we currently anticipate or could prevent the introduction of new applications and enhancements by us altogether.
For example, a change in tax laws and regulations resulting in a decrease in the amount of taxes required to be withheld or accelerating the deadline to remit taxes to appropriate tax agencies would adversely impact our average balance of funds held for clients and, as a result, adversely impact the interest income we earn on such funds during the period between receipt and disbursement. Changes in laws, regulations or policies could also affect the extent and type of benefits employers are required, or may choose, to provide employees or the amount and type of taxes employers and employees are required to pay. Such changes could reduce or eliminate the need for certain of our existing applications or services, which would result in decreased revenues.
Further, we may spend time and money developing new applications and enhancements that, due to regulatory changes, become unnecessary prior to being released. In addition, any failure to educate and assist our clients with respect to new or revised legislation that impacts them could have an adverse effect on our reputation, and any failure to modify our applications or develop new applications in a timely fashion in response to regulatory changes could have an adverse effect on our business and results of operations. Additionally, new regulations or changes to existing regulations could be unclear, difficult to interpret or conflict with other applicable regulations. Our or our clients’ failure to comply with new or modified laws or regulations could result in financial penalties, legal proceedings or reputational harm. Finally, a negative audit or other investigations by the U.S. Government could adversely affect our ability to receive U.S. Government contracts and could result in financial or reputational harm.
In addition, federal, state and foreign government bodies or agencies have in the past adopted, and may in the future adopt, laws or regulations affecting the use of the internet as a commercial medium. Changes in these laws or regulations could require us to modify our applications. Further, government agencies or private organizations may impose taxes, fees or other charges for accessing the internet or commerce conducted via the internet. These laws or charges could limit the growth of internet-related commerce or communications generally or could result in reductions in the demand for internet-based applications such as ours.
Failure to comply with privacy, data protection and cybersecurity laws and regulations could have a materially adverse effect on our reputation, results of operations or financial condition, or have other adverse consequences.
Our applications and services are subject to various complex laws and regulations on the federal, state, local, and foreign levels, including those governing data security, privacy, and AI which have become significant compliance issues globally. The regulatory framework for privacy of personal data is rapidly evolving and is likely to remain uncertain for the foreseeable future. Many federal, state and foreign government bodies and agencies have adopted or are considering adopting laws and regulations regarding the collection, use and disclosure of personal information. In the United States, these include numerous state-level consumer privacy laws, such as California’s CCPA, Texas’ Data Privacy and Security Act, Illinois’ IBIPA, rules and regulations promulgated under the authority of the Federal Trade Commission, the Health Insurance Portability and Accountability Act of 1996, the Family Medical Leave Act of 1993, the ACA, the Financial Services Modernization Act of 1999 (the “GLBA”), the Fair Credit Reporting Act (“FCRA”), federal and state labor and employment laws, state data breach notification laws, and state cybersecurity laws such as the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act. As we continue to expand our operations outside the United States, our applications and services are or will be subject to additional laws governing data security and privacy in relevant jurisdictions, such as Canada’s PIPEDA and Mexico’s Federal Law on the Protection of Personal Data held by Private Parties, as well as the EU GDPR and United Kingdom’s
27
General Data Protection Regulation, which are applicable in the European Economic Area and the United Kingdom, respectively.
Many of these newer state-level consumer privacy laws give consumers located in those states certain rights, including the right to be informed of, opt-out of, and request deletion of the personal information that we hold, similar to those rights provided by the EU GDPR. Notably, the GLBA is enforced under the authority of the Federal Trade Commission and requires our payment card services to adhere to a privacy notice and take certain measures to protect related personal information from unauthorized use and threats to data security. The FCRA places certain requirements and duties on our business as a furnisher of information to certain consumer reporting agencies with which we share limited amounts of data. Because some of our clients are located in Mexico and other clients have establishments internationally, Canada’s PIPEDA, Mexico’s Federal Law on the Protection of Personal Data, and other foreign data privacy laws, such as the EU GDPR, may impact our processing of certain client and employee information. Failure to comply with data protection and privacy laws and regulations could result in regulatory scrutiny and increased exposure to the risk of litigation or the imposition of consent orders, injunctions against data processing or data exporting, or civil and criminal penalties, including fines, which could have an adverse effect on our results of operations or financial condition. Moreover, allegations of non-compliance with privacy laws, whether or not true, could be costly, time consuming, distracting to management, and cause reputational harm. The landscape of privacy laws applicable to our various products and services is evolving quickly. The CPRA, which expands upon the CCPA, went into effect in 2023. Numerous other states have now enacted their own consumer data privacy statutes, many of which are modeled on the CCPA, including states like Colorado, Connecticut, Delaware, Oregon, Montana, Nebraska, New Hampshire, New Jersey, Utah, Virginia, Iowa, and Tennessee. In addition, there are a number of other legislative proposals in jurisdictions across the world for comprehensive privacy laws affecting consumer and employee personal information, which could impose additional and potentially conflicting obligations in areas affecting our business. Newly-passed legislative and regulatory initiatives may adversely affect the ability of our clients to process, handle, store, use and transmit demographic and personal information from their employees, which could reduce demand for our services.
On May 21, 2024, the European Union legislators approved the EU AI Act, which establishes a comprehensive, risk-based governance framework for AI in the EU market. The EU AI Act went into effect on August 2, 2024, and the majority of the substantive requirements will go into effect on August 2, 2026. The EU AI Act, and developing interpretation and application of the EU GDPR in respect of automated decision making, together with developing guidance and/or decisions in this area, may affect our use of AI technologies and our ability to provide, improve or commercialize our business, require additional compliance measures and changes to our operations and processes, result in increased compliance costs and potential increases in civil claims against us, and could adversely affect our business, operations and financial condition.
In addition to government regulation, privacy advocates and industry groups may propose and adopt new and different self-regulatory standards. Because the interpretation and application of many privacy and data protection laws are still uncertain, it is possible that these laws may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the features of our solution. Any failure to comply with government regulations that apply to our applications, including privacy and data protection laws, could subject us to liability. In addition to the possibility of fines, lawsuits and other claims, we could be required to fundamentally change our business activities and practices or modify our solution, which could have an adverse effect on our business, operating results or financial condition. Any inability to adequately address privacy concerns and claims, even if unfounded, or inability to comply with applicable privacy or data protection laws, regulations and policies, could result in additional cost and liability to us, damage to our reputation, reductions in our sales and other adverse effects on our business, operating results or financial condition.
Furthermore, privacy concerns may cause our clients’ employees to resist providing the personal data necessary to allow our clients and their employees to use our applications and services effectively. Even the perception of privacy concerns, whether or not valid, may inhibit market adoption of our applications and services in certain industries.
Certain of our products and services use data-driven insights to help our clients manage their businesses more efficiently. Our business increasingly relies on AI and machine learning to model and create these insights. Use of these methods has recently come under increased regulatory scrutiny. New laws, guidance and court decisions in this area may limit our ability to use AI tools, or require us to make changes to our application or services that may decrease our operational efficiency, result in an increase to operating costs and hinder our ability to improve our services. For example, rules on the use of automated decision-making under enacted and proposed data protection laws may require us to disclose the existence of automated decision-making to the data subject with an explanation of the logic used in such decision-making, and may require us to implement certain safeguards, including the right to obtain human intervention and to contest any decision. Regulatory and legislative authorities in the United States and other countries have proposed similar types of legislation that imposes or would impose restrictions on the development of generative AI and machine learning. Our ability to provide data-driven insights using generative AI or machine learning may be constrained by current or future regulatory requirements, statutes or ethical considerations that could restrict or impose burdensome and costly requirements on our ability to leverage data in innovative ways. As we continue to pursue such new technologies, our failure to adequately address legal risks relating to the use of generative AI and machine learning in our applications could result in litigation or private action that could result in liability for the Company. Any actual or alleged noncompliance with these new laws and regulations, or failure to meet client expectations
28
with respect to the use of generative AI and machine learning, could also result in negative publicity or harm to our reputation, subject us to investigations and expose us to significant fines, penalties and other damages.
The adoption of new, or adverse interpretations of existing U.S. state, U.S. federal, or foreign money transmitter, money services business, or payment services statutes or regulations could subject us to additional regulation and related expenses and require changes to our business.
The adoption of new money transmitter, money services business, or payment services statutes or regulations in jurisdictions, changes in regulators’ interpretation of existing U.S. state, U.S. federal, or foreign money transmitter, money services business, or payments services statutes or regulations, or disagreements by regulatory authorities with our interpretation of such statutes or regulations, have subjected us to registration or licensing and could limit business activities until we are appropriately licensed. These occurrences could also require changes to the manner in which we conduct certain aspects of our business or invest client funds, which could adversely impact the amount of interest income we receive from investing client funds before such funds are remitted to the appropriate taxing authorities and accounts designated by our clients.
As the Paycom National Trust Bank now manages U.S. client money movement activity, these transmissions are federally exempt from state money transmitter regulation, and we have surrendered all historically maintained state money transmitter licenses. Outside of the United States, we maintain certain “money services business” registrations and intend to apply for, where necessary, money services business, money transmitter, payment services provider, or similarly named applicable licenses.
Should other U.S. state, U.S. federal, or foreign regulators make a determination that we have operated as an unlicensed money services business, money transmitter, or payment services provider, we could be subject to civil and criminal fines, penalties, costs of registration, legal fees, reputational damage or other negative consequences, any of which may have an adverse effect on our business operating results or financial condition.
While we maintain we are not a money services business or money transmitter in the United States and other jurisdictions, our operations in certain jurisdictions in and outside of the U.S. are subject to AML laws and regulations, including, for example, the BSA. Among other things, the BSA requires certain financial institutions, including banks and money services businesses, to develop and implement risk-based AML programs, report large cash transactions and suspicious activity, and maintain transaction records. We have adopted an AML compliance program to mitigate the risk of our application being used for illegal or illicit activity and to help detect and prevent fraud. Our AML compliance program is designed to foster trust in our application and services. However, there can be no assurance that our employees, consultants, or agents will not take actions in violation of our policies for which we may be ultimately responsible, or that our policies and procedures will be adequate or will be determined to be adequate by regulators. Any violation of applicable AML laws or regulations could limit certain of our business activities until they are satisfactorily remediated and could result in civil and criminal penalties, including fines, which could damage our reputation and have a materially adverse effect on our results of operations and financial condition.
Further, bank regulators continue to impose additional and stricter requirements on banks to ensure they are meeting their BSA obligations, and banks are increasingly viewing money services businesses and third-party senders to be higher risk customers for money laundering. Thus, our banking partners that assist in processing our money movement transactions may limit the scope of services they provide to us or may impose additional material requirements on us. These regulatory restrictions on banks and changes to banks’ internal risk-based policies and procedures may result in a decrease in the number of banks willing to do business with us, may require us to materially change the manner in which we conduct some aspects of our business, may decrease our revenues and earnings and could have a material adverse effect on our results of operations or financial condition.
Adverse tax laws or regulations could be enacted or existing laws could be applied to us or our clients, which could increase the costs of our solution and applications and could adversely affect our business, operating results or financial condition.
As a vendor of services, we are ordinarily held responsible by taxing authorities for collecting and paying any applicable sales or other similar taxes. Additionally, the application of tax laws to services provided electronically like ours is evolving. New income, sales, use or other tax laws, statutes, rules, regulations or ordinances could be enacted at any time (possibly with retroactive effect), and could be applied solely or disproportionately to services and applications provided over the internet. These enactments could adversely affect our sales activity, due to the inherent cost increase the taxes would represent, and ultimately could adversely affect our business, operating results or financial condition.
Each jurisdiction has different rules and regulations governing sales and use taxes, and these rules and regulations are subject to varying interpretations that change over time. We review these rules and regulations periodically and, when we believe we are subject to sales and use taxes in a particular jurisdiction, we may voluntarily engage the applicable tax authorities in order to determine how to comply with that jurisdiction’s rules and regulations. We cannot ensure that we will not be subject to sales and use taxes or related penalties for past sales in jurisdictions where we currently believe no such taxes are required.
29
In addition, existing tax laws, statutes, rules, regulations or ordinances could be interpreted, changed, modified or applied adversely to us (possibly with retroactive effect), which could require us or our clients to pay additional tax amounts, as well as require us or our clients to pay fines or penalties and substantial interest for past amounts. If we are unsuccessful in collecting such taxes from our clients, we could be held liable for such costs, thereby adversely affecting our business, operating results or financial condition. Additionally, the imposition of such taxes on us would effectively increase the cost of our software and services we provide to clients and would likely have a negative impact on our ability to retain existing clients or to gain new clients in the jurisdictions in which such taxes are imposed.
Compliance with employment-related laws and regulations could increase our cost of doing business and violations of such laws and regulations could subject us to fines and lawsuits.
Our operations are subject to a variety of federal, state, local and international employment-related laws and regulations, including, but not limited to, the U.S. Fair Labor Standards Act, which governs such matters as minimum wages, the Family Medical Leave Act, overtime pay, compensable time, recordkeeping and other working conditions, Title VII of the Civil Rights Act, the Employee Retirement Income Security Act, the Americans with Disabilities Act, the National Labor Relations Act, regulations of the Equal Employment Opportunity Commission, regulations of the Office of Civil Rights, regulations of the Department of Labor, regulations of state attorneys general, federal and state wage and hour laws, and a variety of similar laws enacted by the federal and state governments that govern these and other employment-related matters. As our employees are located in a number of states and countries, compliance with evolving laws and regulations could substantially increase our cost of doing business. In recent years, we have been subject to threatened and filed lawsuits, including class action lawsuits, alleging violations of federal and state law regarding workplace and employment matters, overtime wage policies, discrimination and similar matters. We may incur damages and expenses resulting from lawsuits of this type, which could have a material adverse effect on our business, financial condition or results of operations. We are currently subject to employee-related legal proceedings in the ordinary course of business. While we believe that we have adequate reserves for those losses that we believe are probable and can be reasonably estimated, the ultimate results of legal proceedings and claims cannot be predicted with certainty.
While none of our employees are currently represented by a union, our employees have the right under the National Labor Relations Act to form or affiliate with a union. If a significant portion of our employees were to become unionized, our labor costs could increase and our business could be negatively affected by other requirements and expectations that could increase our costs, change our employee culture, impact corporate flexibility and disrupt our business. Additionally, our responses to any union organizing efforts could negatively impact perception of our brand and have adverse effects on our business, including on our financial results. These responses could also expose us to legal risk, causing us to incur costs related to defending legal and regulatory actions, potential penalties and restrictions or reputational harm.
Our background check business is subject to significant governmental regulation, and changes in law or regulation, or a failure to correctly identify, interpret, comply with and reconcile the laws and regulations to which it is subject, could materially adversely affect our revenue or profitability.
We offer a background screening application called Enhanced Background Checks. In the course of providing background checks, we search and report public and non-public consumer information and records, including criminal records, employment and education history, credit history, driving records and drug screening results. Consequently, we are subject to extensive, evolving and often complex laws and governmental regulations, such as the FCRA, the Drivers’ Privacy Protection Act, state consumer reporting agency laws, state licensing and registration requirements, and various other foreign, federal, state and local laws and regulations. These laws and regulations set forth restrictions and process requirements concerning what may be reported about an individual, when, to whom, and for what purposes, and how the subjects of background checks are to be treated. Compliance with these laws and regulations requires significant expense and resources, which could increase significantly as these laws and regulations evolve. Such increase in restrictions and compliance costs could negatively affect our ability to provide other services expected by our clients and adversely affect our offerings and revenue.
Changes in law, regulation, or administrative enforcement and interpretations or other limitations and prohibitions related to the provision of consumer information and records could materially adversely affect our revenue and profitability. For example, numerous state and local authorities have implemented “ban the box” and “fair chance” hiring laws that limit or prohibit employers from inquiring or using a candidate’s criminal history to make employment decisions, and many of these authorities have in recent years amended these laws to increase the restrictions on the use of such information. In addition, redaction of personal identifying information in criminal records (such as date of birth), and court rules or lawsuits that limit or restrict access to identifiers in criminal records, may negatively impact our ability to perform complete criminal background checks. The enactment of new restrictive legislation and the requirements, restrictions, and limitations imposed by changing interpretations and court decisions on such laws and regulations could prevent our customers from using the full functionality of our background screening application, which may reduce demand for such solution.
Furthermore, we face potential liability from individuals, classes of individuals, clients or regulatory bodies for claims based on the nature, content or accuracy of our background check services and the information we use and report. Our potential exposure to lawsuits or government investigations may increase depending in part on our clients’ compliance with these laws
30
and regulations and applicable employment laws in their procurement and use of our background checks as part of their hiring process, which is generally outside of our control. Our potential liability includes claims of non-compliance with the FCRA, U.S. state consumer reporting agency laws or regulations, foreign regulations or applicable employment laws, as well as other claims of defamation, invasion of privacy, negligence, copyright, patent or trademark infringement. In some cases, we may be subject to strict liability.
Industry and Financial Risks
Our financial results may fluctuate due to many factors, some of which may be beyond our control.
Our results of operations, including our revenues, costs of revenues, administrative expenses, operating income, cash flow and deferred revenue, may vary significantly in the future, and the results of any one period should not be relied upon as an indication of future performance. Fluctuations in our financial results may negatively impact the value of our common stock. Our financial results may fluctuate as a result of a variety of factors, many of which are outside of our control, and as a result, may not fully reflect the underlying performance of our business. Factors that may cause our financial results to fluctuate from period to period include, without limitation:
•
our ability to attract new clients or sell additional applications to our existing clients;
•
the number of new clients and their employees, as compared to the number of existing clients and their employees in a particular period;
•
the mix of clients between small, mid-sized and large organizations;
•
the extent to which we retain existing clients and the expansion or contraction of our relationships with them;
•
the mix of applications sold during a period;
•
changes in our pricing policies or those of our competitors;
•
seasonal factors affecting payroll processing, demand for our applications or potential clients’ purchasing decisions;
•
the amount and timing of operating expenses, including those related to the maintenance and expansion of our business, operations and infrastructure;
•
the timing and success of new applications introduced by us and the timing of expenses related to the development of new applications and technologies;
•
the timing and success of current and new competitive products and services offered by our competitors;
•
economic conditions affecting our clients, including their ability to outsource HCM solutions and hire employees;
•
changes in laws, regulations or policies affecting our clients’ legal obligations and, as a result, demand for certain applications;
•
changes in the competitive dynamics of our industry, including consolidation among competitors or clients;
•
our ability to manage our existing business and future growth, including expenses related to our data centers and the expansion of such data centers and the addition of new offices;
•
the effects and expenses of acquisition of third-party technologies or businesses and any potential future charges for impairment of goodwill resulting from those acquisitions;
•
business disruptions caused by widespread public health crises, natural disasters, such as tornadoes, hurricanes, fires, earthquakes and floods (including as a result of climate change), acts of war, terrorism, or other catastrophic events;
•
network outages or security breaches; and
•
general economic, industry and market conditions.
Certain of our operating results and financial metrics may be difficult to predict as a result of seasonality.
We have historically experienced seasonality in our revenues. A significant portion of our recurring revenues relate to the annual processing of payroll tax filing forms such as Form W-2 and Form 1099 and the annual processing and filing of ACA-related forms. These forms are typically processed in the first quarter of the year and, as a result, positively impact first quarter recurring revenues. In addition, unscheduled payroll runs at the end of the year (such as bonuses) have a positive impact on our recurring revenues in the fourth quarter. Although we expect the magnitude of seasonal fluctuations in our revenues to decrease in the future to the extent clients utilize more of our non-payroll applications, seasonal fluctuations in certain of our operating results and financial metrics may make such results and metrics difficult to predict.
31
We are subject to certain operating and financial covenants that may restrict our business and financing activities and may adversely affect our cash flow and our ability to operate our business.
We maintain a Revolving Credit Facility, which can be accessed as needed to supplement our operating cash flow and cash balances. Although we do not currently have any outstanding indebtedness, pursuant to the Credit Agreement (as defined herein) that governs the Revolving Credit Facility, we may not, subject to certain exceptions:
•
create or permit the existence of additional liens on our assets;
•
incur additional debt;
•
change the nature of our business;
•
make investments in and acquisitions of (or acquisitions of substantially all of the assets of) any person;
•
permit certain fundamental changes, including a merger;
•
dispose of assets;
•
make any distributions during an event of default, or any other distributions in excess of $50 million in any fiscal year without demonstrating pro forma compliance with certain financial covenants;
•
enter into transactions with affiliates other than in the ordinary course of business on an arm’s-length basis;
•
enter into certain transactions, including swap agreements and sale and leaseback transactions; or
•
pay dividends or distributions of our capital stock.
In addition, we are required to maintain as of the end of each fiscal quarter a consolidated interest coverage ratio of not less than 3.0 to 1.0 and a consolidated leverage ratio of not greater than 3.0 to 1.0. The operating and financial covenants in the Credit Agreement, as well as any future financing agreements that we may enter into, may restrict our ability to finance our operations, engage in business activities or expand or fully pursue our business strategies. If we borrow in the future, we may be required to use a substantial portion of our cash flows to pay principal and interest on our debt, which would reduce the amount of money available for operations, working capital, expansion, or other general corporate purposes.
Our ability to meet our expenses and debt obligations and comply with the operating and financial covenants may be affected by financial, business, economic, regulatory and other factors beyond our control. We may be unable to control many of these factors and comply with these covenants. A breach of any of the covenants under our Credit Agreement could result in an event of default, which could result in the acceleration of any outstanding indebtedness or foreclosure on our assets pledged to secure the indebtedness.
If we are unable to maintain effective internal control over financial reporting, investors may lose confidence in the accuracy and completeness of our financial reports and the market price of our common stock may be negatively affected.
As a public company, we are required to maintain internal control over financial reporting to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements. Management must evaluate and furnish a report on the effectiveness of our internal control over financial reporting as of the end of each fiscal year, and our auditors must attest to the effectiveness of our internal control over financial reporting.
If we have a material weakness in our internal control over financial reporting, we may not detect errors on a timely basis and our financial statements may be materially misstated. If we identify material weaknesses in our internal control over financial reporting or if our independent registered public accounting firm is unable to express an opinion as to the effectiveness of our internal control over financial reporting, investors may lose confidence in the accuracy and completeness of our financial reports and/or we could become subject to investigations by the New York Stock Exchange (the “NYSE”), the SEC, or other regulatory authorities, and the market price of our common stock could be negatively affected.
Our actual operating results may differ significantly from our guidance.
We have released, and may continue to release, guidance in our earnings conference calls, earnings releases, or otherwise, regarding our future performance, which represents our estimates as of the date of release. This guidance, which includes forward-looking statements, has been and will be based on projections prepared by our management. These projections are not prepared with a view toward compliance with published guidelines of the American Institute of Certified Public Accountants, and neither our registered public accountants nor any other independent expert or outside party compiles or examines the projections. Accordingly, no such person expresses any opinion or any other form of assurance with respect to the projections.
Projections are based upon a number of assumptions and estimates that, while presented with numerical specificity, are inherently subject to significant business, economic, and competitive uncertainties and contingencies, many of which are beyond our control. Projections are also based upon specific assumptions with respect to future business decisions, some of which will change. The principal reason that we release guidance is to provide a basis for our management to discuss our
32
business outlook with analysts and investors. We do not accept any responsibility for any projections or reports published by any third parties.
Guidance is necessarily speculative in nature, and it can be expected that some or all of the assumptions underlying the guidance furnished by us will vary significantly from actual results. Accordingly, our guidance is only an estimate of what management believes is realizable as of the date of release. Actual results have in the past, and may in the future, vary from our guidance, and the variations may be material. In light of the foregoing, investors are urged not to rely upon our guidance in making an investment decision regarding our common stock.
Any failure to successfully implement our operating strategy or the occurrence of any of the events or circumstances set forth in this “Risk Factors” section in this Form 10-K could result in the actual operating results being different from our guidance, and the differences may be adverse and material.
Risks Related to Ownership of Our Securities
The issuance of additional stock in connection with acquisitions, our stock incentive plans, warrants or otherwise will dilute all other stockholders.
Our certificate of incorporation authorizes us to issue up to 100 million shares of common stock and up to 10 million shares of preferred stock with such rights and preferences as may be determined by our board of directors. Subject to compliance with applicable rules and regulations, we may issue all of these shares that are not already outstanding without any action or approval by our stockholders. We intend to continue to evaluate strategic acquisitions in the future. We may pay for such acquisitions, in part or in full, through the issuance of additional equity securities.
Any issuance of shares in connection with an acquisition, the exercise of stock options or warrants, the award of shares of restricted stock or otherwise would dilute the percentage ownership held by our existing stockholders.
Anti-takeover provisions in our charter documents and Delaware law may delay or prevent an acquisition of our company.
Our certificate of incorporation, bylaws and Delaware law contain provisions that may have the effect of delaying or preventing a change in control of us or changes in our management. These provisions, alone or together, could delay or prevent hostile takeovers and changes in control or changes in our management.
Any provision of our certificate of incorporation, bylaws or Delaware law that has the effect of delaying or deterring a change in control could limit the opportunity for our stockholders to receive a premium for their shares of our common stock, and could affect the price that some investors are willing to pay for our common stock.
Our certificate of incorporation contains an exclusive forum provision that may discourage lawsuits against us and our directors and officers.
Our certificate of incorporation provides that, unless we consent in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware (or if no Court of Chancery located within the State of Delaware has jurisdiction, the Federal District Court for the District of Delaware) will be the sole and exclusive forum for any derivative action or proceeding brought on our behalf, any action asserting a claim of breach of fiduciary duty owed by any of our directors, officers or other employees to us or our stockholders, any action asserting a claim against us or any of our directors, officers or other employees arising pursuant to any provision of Delaware law or our certificate of incorporation or our bylaws (as either may be amended from time to time) or any action asserting a claim against us or any of our directors, officers or other employees governed by the internal affairs doctrine. This exclusive forum provision applies to state and federal law claims, although our stockholders will not be deemed to have waived our compliance with the federal securities laws and the rules and regulations thereunder. In addition, this exclusive forum selection provision will not apply to claims under the Exchange Act. Moreover, Section 22 of the Securities Act creates concurrent jurisdiction for federal and state courts over all suits brought to enforce any duty or liability created by the Securities Act or the rules and regulations thereunder. Accordingly, there is uncertainty as to whether a court would enforce our forum selection provision as written in connection with claims arising under the Securities Act. This forum selection provision may limit our stockholders’ ability to obtain a favorable judicial forum for disputes with us. It is also possible that, notwithstanding the forum selection clause included in our certificate of incorporation, a court could rule that such a provision is inapplicable or unenforceable.
We may not continue to pay dividends at the same rate or at all.
Our payment of dividends, as well as the rate at which we pay dividends, are solely at the discretion of our Board of Directors. Further, dividend payments, if any, are subject to our financial results and the availability of statutory surplus. These factors could result in a change to our dividend policy.
33
General Risks
Adverse economic and market conditions could affect our business, operating results or financial condition.
Our business depends on the overall demand for HCM applications and on the economic health of our current and prospective clients. If economic conditions in the United States or in global markets deteriorate, clients may cease their operations, eliminate or reduce unscheduled payroll runs (such as bonuses), reduce headcount, delay or reduce their spending on HCM and other outsourcing services or attempt to renegotiate their contracts with us. In addition, global and regional macroeconomic developments, such as changes in global trade policies and tariffs, increased unemployment, decreased income, uncertainty related to future economic activity, reduced access to credit, increased interest rates, inflation, volatility in capital markets, and decreased liquidity, among other possible factors, could negatively affect our ability to conduct business. Furthermore, the impact of such macroeconomic developments may be exacerbated by geopolitical events and ongoing military conflicts throughout the world. An economic decline could result in reductions in sales of our applications, decreased revenue from unscheduled payroll runs and fees charged on a per-employee basis, longer sales cycles, slower adoption of new technologies and increased price competition, any of which could adversely affect our business, operating results or financial condition. In addition, HCM spending levels may not increase following any recovery.
Further, as part of our payroll and payroll tax filing services, we collect and then remit client funds to taxing authorities and accounts designated by our clients. During the interval between receipt and disbursement, we typically invest such funds in money market funds, demand deposit accounts, certificates of deposit, U.S. treasury securities and commercial paper. These investments are subject to general market, interest rate, credit and liquidity risks, and such risks may be exacerbated during periods of unusual financial market volatility. Any loss of or inability to access such funds could have an adverse impact on our cash position and results of operations and could require us to obtain additional sources of liquidity, which may not be available on terms that are acceptable to us, if at all. Furthermore, although increased interest rates may have a negative impact on certain clients, increased interest rates have resulted in increased interest earned on funds held for clients and additional income earned on our corporate funds. Changes in interest rates will impact potential earnings of future investments. A stable or rising interest rate environment would sustain the additional interest earned on funds held for clients and interest earned on our corporate funds, whereas a decreasing interest rate environment would compress the additional interest earnings and potentially adversely affect our operating results.
In recent years, there have been several instances when there has been uncertainty regarding the ability of Congress and the President collectively to reach agreement on federal budgetary and spending matters. A period of failure to reach agreement on these matters, particularly if accompanied by an actual or threatened government shutdown, may have an adverse impact on the U.S. economy. Additionally, because certain of our clients rely on government resources to fund their operations, a prolonged government shutdown may affect such clients’ ability to make timely payments to us, which could adversely affect our operations results or financial condition.
Item 1B. Unresolved Staff Comments
None.
34
Item 1C. Cybersecurity
Risk Management and Strategy
Overview
We recognize that our clients entrust us with highly sensitive data. We also recognize our attendant responsibility to safeguard the accessibility, confidentiality, and integrity of this data. Our information security program consists of policies, procedures, systems, controls and technology designed to help us prevent, identify, detect and mitigate cybersecurity risks. Our processes are informed by cybersecurity events we have observed within the Company, across our industry, and across the cybersecurity landscape. We utilize the risk management framework for risk assessments as defined by the ISO 27001 Information Security Management Standard. We have integrated cybersecurity risk management into our overall risk management framework by conducting annual enterprise risk management assessments and IT risk management assessments, implementing periodic key risk indicator tracking, and holding periodic meetings among multiple department stakeholders to address cybersecurity risks. We review our information security policies at least annually and in connection with certain process changes to ensure that they meet the needs of the organization and the goals and objectives of the information security program.
Prevention, Identification, Detection and Mitigation Activities
We routinely undertake activities to prevent, identify, detect and mitigate risks from cybersecurity threats, including but not limited to the following:
•
Procedures and guidelines designed to ensure that information security is a key consideration in the requirements for both new information systems and enhancements to existing systems and assets;
•
IT environment risk assessments conducted at regular intervals and in connection with certain events, such as implementation of a new system, service or vendor;
•
Tabletop and simulation exercises to discuss roles and responsibilities of team members in the event of a cybersecurity incident and to test and modify the plan as needed;
•
Ongoing security penetration testing and threat modeling of our network and web application;
•
Automated tools and manual review processes to ensure ongoing compliance with technical standards and identify configuration issues and technical vulnerabilities;
•
Encryption of all communications with our servers, which are configured to utilize only high-grade encryption algorithms; and
•
Ongoing employee training related to information security and data privacy policies and standards, including periodic phishing, vishing, and social engineering exercises.
We also have implemented and continue to maintain policies, procedures, systems, controls and technology to oversee and identify the cybersecurity risks associated with our use of third-party service providers. For example, we conduct thorough cybersecurity risk assessments of all third-party service providers prior to engagement and ongoing monitoring to ensure compliance with our robust cybersecurity requirements. The monitoring includes periodic audits of third-party systems and vendors. We engage third-party consultants and auditors in connection with assessing, identifying and managing material risks from cybersecurity threats. Our collaboration with these third parties includes independent audits, threat assessments, and consultation on security enhancements.
Infrastructure; Network and Physical Security
Our IT infrastructure is secured and monitored using a number of leading practices and tools across physical and logical security. This security is also continually monitored by our information security department. We strictly regulate and limit all access to servers and networks at each of our facilities. Local network access is restricted by domain authentication, using stringent access control lists. Remote network access is restricted by a defense-in-depth approach that includes redundant firewalls, preventing unauthorized access from external networks to systems within our local network. We also employ (i) network and endpoint intrusion detection, intrusion prevention, and data loss prevention sensors throughout our infrastructure, (ii) systems that monitor our infrastructure and alert our continuously staffed security operations center of potential cybersecurity issues, and (iii) a seasoned process for managing and installing patches for third-party applications.
Incident Response
We maintain plans to address any cybersecurity incidents, including but not limited to a Crisis Management Plan, an Incident Response Plan, an Information Security Incident Management Policy and a Business Resiliency Policy. Information security continuity is embedded in our business continuity management system to minimize the risk that continuity operations could result in a compromise to our security standards. We conduct business continuity, crisis communications and disaster recovery exercises at least annually to test and modify the plan, as needed. The activities related to the business continuity management system are routinely reported to executive management as part of our IT security team’s ongoing metrics
35
reporting. In addition, reports related to activities and outcomes are provided to the audit committee of the Board of Directors on a quarterly basis.
Certifications and Audits
We maintain the following ISO certifications related to our information systems:
•
ISO 9001:2015 (standard for the implementation of quality management processes);
•
ISO 22301:2019 (standard for implementing and managing an effective business continuity management system);
•
ISO/IEC 27001:2022 (security standard for information security management systems, covering our production, quality assurance and implementation environments);
•
ISO/IEC 27701:2019 (standard for establishing, implementing, maintaining and continually improving a privacy information management system); and
•
ISO/IEC 42001:2023 (standard for establishing, implementing, maintaining and continually improving an AIMS).
We voluntarily obtain third-party security examinations relating to our internal controls over financial reporting in accordance with SOC 1. Our SOC 1 examination is conducted every six months by an independent international auditing firm, and addresses, among other areas, our physical and environmental safeguards for production data centers, data availability and integrity procedures, change management procedures and logical security procedures. We also obtain third-party examinations relating to our internal controls over security and privacy in accordance with SOC 2. Our SOC 2 examination is conducted every year and addresses, among other areas, internal controls around security, availability, and processing integrity. We publish SOC 1 reports semiannually and SOC 2 and SOC 3 reports annually.
Impact of Risks from Cybersecurity Threats
We have experienced cybersecurity incidents in the ordinary course of business and will continue to experience risks from cybersecurity threats that could have a material adverse effect on our business strategy, results of operations, or financial condition. Although prior cybersecurity incidents have not had a material adverse effect on us, our business strategy, results of operations, or financial condition to date, any actual or perceived breach of our security could damage our reputation, cause existing clients to discontinue the use of our solution, prevent us from attracting new clients, or subject us to third-party lawsuits, regulatory investigations and fines or other actions or liabilities, any of which could materially adversely affect us, our business strategy, results of operations, or financial condition.
Governance
Both management and the Board of Directors are actively involved in the oversight of risks from cybersecurity threats. Our information security program is designed to ensure that management and the Board of Directors are adequately informed about, and provided with the tools necessary to monitor, (i) material risks from cybersecurity threats and (ii) our efforts related to the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Role of the Board of Directors
The Board of Directors has delegated to the audit committee primary responsibility for overseeing enterprise risk management, including oversight of risks from cybersecurity threats.The audit committee receives quarterly reports and updates from our Senior Director of IT and Information Security with respect to cybersecurity risk management. Such reports cover the Company’s information security program, including its current status, capabilities, objectives and plans, as well as the evolving cybersecurity threat landscape.
Role of Management
The Senior Director of IT and Information Security oversees the activities of our IT and information security teams and is responsible for ensuring that both new implementations and ongoing operations comply with the policies, procedures, and guidelines of our information security program. Our Senior Director of IT and Information Security has been with Paycom for over a decade and has worked in technology development, improvement, infrastructure, and security for over 12 years. The Senior Director of IT and Information Security is supported by our Director of Information Security, who has worked in technology development, improvement, infrastructure, and security for over a decade. The Director of Information Security is responsible for the growth and implementation of the information security and data privacy programs and oversees the operations of the information security team. The Director of Information Security also provides oversight for information security and privacy policies and controls, oversees compliance activities, and provides metrics and guidance to executive management regarding the program. The aforementioned leaders and teams have a breadth of experience and manage programs related to governance, risk, and compliance; data privacy and security; vulnerability management; security operations; and application security.
36
The Senior Director of IT and Information Security is regularly informed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques. This ongoing knowledge acquisition is crucial for the effective prevention, detection, mitigation, and remediation of cybersecurity incidents. Our information systems are routinely reviewed for compliance with information security policies and standards. Outcomes of reviews and audits are reported to the Director of Information Security and the Senior Director of IT and Information Security. Relevant information about security nonconformities, incidents, and events are reported to the working group described below and to the Board of Directors. As discussed above, the Senior Director of IT and Information Security reports to the audit committee and the Board of Directors on cybersecurity matters at least quarterly.
In addition, we have established a working group composed of senior leaders from various departments, including operations, finance, IT, information security, internal audit, and legal. This working group’s responsibilities include (i) ensuring that information security goals and objectives are identified, meet organizational and business requirements, and are integrated into relevant processes, (ii) reviewing the effectiveness of the information security program, (iii) providing clear direction and highly visible management support for security initiatives, (iv) providing resources required for information security projects and initiatives, (v) overseeing programs to maintain information security awareness, including training and team-specific guidance, and (vi) coordinating the information security aspects of supplier relationships.
Item 2. Properties
Our corporate headquarters is an approximately 815,000-square-foot campus located on over 150 acres of Company-owned property in Oklahoma City, Oklahoma. We also have an operations facility on approximately 14 acres of Company-owned property in Grapevine, Texas. We operate fully redundant data centers in Oklahoma, Texas and Arizona.
As of December 31, 2025, we lease facilities in 29 states and in certain international locations. We believe that these facilities are suitable for our current operations and, upon the expiration of the terms of the leases, we believe we could renew these leases or find suitable space elsewhere on acceptable terms.
Item 3. Legal Proceedings
From time to time, we are involved in various disputes, claims, suits, investigations and legal proceedings arising in the ordinary course of business, including commercial, intellectual property and employment-related matters, as well as stockholder derivative actions, class action lawsuits and other matters. The litigation matters described below involve issues or claims that may be of particular interest to our stockholders, regardless of whether any of these matters are material to our business or financial condition based upon the standard set forth in the SEC’s rules. We believe we have substantial defenses in each matter, and we intend to vigorously defend against the claims brought by plaintiffs in these lawsuits.
Between November 2023 and January 2024, Company stockholders filed four federal securities lawsuits against the Company, Chad Richison, and Craig Boelte (the “Defendants”). On April 23, 2024, the United States District Court for the Western District of Oklahoma (the “Western District Court”) consolidated three of these lawsuits (styled Ventrillo, et al. v. Paycom Software, Inc., et al., Case No. 5:23-cv-01019-F; Caloto, et al. v. Paycom Software, Inc., et al., Case No. 5:24-cv-00019-F; and Minarik, et al. v. Paycom Software, Inc., et al., Case No. 5:24-cv-00014-F) and dismissed for procedural reasons the fourth complaint (styled Schoenrock, et al. v. Paycom Software, Inc., et al., Case No. 5:24-cv-00012-F). The consolidated action is styled In re Paycom Software, Inc. Securities Litigation, Case No. 5:23-cv-01019-F (the “Consolidated Securities Class Action”).
On July 8, 2024, the lead plaintiff filed an amended complaint in the Consolidated Securities Class Action on behalf of a class of acquirers of Company securities between February 8, 2022 and October 31, 2023. In the amended complaint, the lead plaintiff asserts claims under Section 10(b) and 20(a) of the Exchange Act, alleging that the Defendants made materially false and misleading statements and failed to disclose facts regarding the impact of Beti on the Company’s services and revenues. The lead plaintiff is seeking remedies on behalf of the putative class that include, but are not limited to, compensatory damages, reimbursement of out-of-pocket costs, and injunctive relief.
The Defendants filed their Motion to Dismiss Plaintiff’s Consolidated Complaint on September 6, 2024. The parties have fully briefed the Motion to Dismiss and are awaiting a decision from the Western District Court.
In January and May 2024, three derivative lawsuits were filed by Company stockholders against the Company and the members of the Board of Directors for purported breaches of fiduciary duties, aiding and abetting, unjust enrichment, and waste of corporate assets based on similar allegations as in the Consolidated Securities Class Action. On May 23, 2024, the three derivative actions were consolidated into one master case, styled In re Paycom Software, Inc. Stockholder Derivative Litigation, Case No. 5:24-cv-00240-F, in the Western District Court (the “Consolidated Derivative Action”). The plaintiffs seek to recover unspecified monetary damages on behalf of the Company. The Western District Court has stayed all proceedings and deadlines in the Consolidated Derivative Action pending resolution of Defendants’ Motion to Dismiss in the Consolidated Securities Class Action.
We believe that the resolution of current pending legal matters will not have a material adverse effect on our business, financial condition, results of operations or cash flows. Nonetheless, we cannot predict the outcome of these proceedings, as
37
legal matters are subject to inherent uncertainties, and there exists the possibility that the ultimate resolution of these matters could have a material adverse effect on our business, financial condition, results of operations or cash flows.
Item 4. Mine Safety Disclosures
None.
38
PART II
Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities
Our common stock is traded on the NYSE under the symbol “PAYC.” As of February 10, 2026, there were approximately 2,862 holders of record of our common stock. This number is based on the actual number of holders registered at such date and does not include holders whose shares are held in “street name” by brokers and other nominees.
Dividends
In May 2023, our Board of Directors adopted a dividend policy under which we intend to continue to pay quarterly cash dividends on our common stock.
The following table summarizes quarterly dividends paid during 2025.
(1)
All unvested equity incentive awards currently outstanding are entitled to receive dividends or dividend equivalents, provided that such dividends or dividend equivalents are withheld by the Company and distributed to the applicable holder upon vesting of the award. Dividends declared, as reported in the consolidated statements of stockholders’ equity, includes dividends and dividend equivalents payable to holders of unvested equity incentive awards and, as a result, exceeds the amount of total cash dividends paid presented in this column.
OnFebruary 10, 2026, our Board of Directors declared a quarterly cash dividend of $0.375 per share of common stock payable on March 23, 2026 to stockholders of record at the close of business on March 9, 2026.
The declaration, timing and amount of each quarterly cash dividend are subject to the approval of the Board of Directors, including a determination that the dividend policy and the declaration of dividends thereunder are in the best interests of our stockholders and are in compliance with applicable law. The Board of Directors retains the power to modify, suspend, or cancel the dividend policy in any manner and at any time that it may deem necessary or appropriate.
39
Performance Graph
Notwithstanding any statement to the contrary in any of our filings with the SEC, the following performance graph shall not be deemed “filed” with the SEC for purposes of Section 18 of the Exchange Act or “soliciting material” under the Exchange Act and shall not be incorporated by reference into any such filings irrespective of any general incorporation language contained in such filing.
The following graph compares the cumulative total stockholder return on our common stock with the cumulative total return of the S&P 500 Index and the S&P 500 Software & Services Index during the five-year period commencing on December 31, 2020 and ending on December 31, 2025. The graph assumes that $100 was invested in our common stock and in each of the comparative indices at the beginning of the period, and assumes the reinvestment of any dividends. Historical stock price performance should not be relied upon as an indication of future stock price performance.
Purchases of Equity Securities
The number of shares of common stock repurchased by us during the three months ended December 31, 2025 is set forth below:
(1)
Pursuant to a stock repurchase plan announced on November 20, 2018, we were authorized to purchase (in the aggregate) up to $150.0 million of our common stock in open market purchases, privately negotiated transactions or by other means. On May 13, 2021, we announced that our Board of Directors increased the availability under the existing stock repurchase plan to $300.0 million and extended the expiration date to May 13, 2023. On June 7, 2022, we announced that our Board of Directors increased the availability under the existing stock repurchase plan to $550.0 million and extended the expiration date to June 7, 2024. On August 15, 2022, we announced that our Board of Directors increased the availability under the existing stock repurchase plan to $1.1 billion and extended the expiration date to August 15, 2024. On July 31, 2024, we announced that our Board of Directors increased the availability under the existing stock repurchase plan to $1.5 billion and extended the expiration date to August 15, 2026.
(2)
Includes 3,527 shares withheld to satisfy tax withholding obligations for certain individuals upon the vesting of equity incentive awards.
(3)
Includes 8,583 shares withheld to satisfy tax withholding obligations for certain individuals upon the vesting of equity incentive awards.
Item 6. Reserved
40
Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations
This Management’s Discussion and Analysis of Financial Condition and Results of Operations is intended to provide a reader of our financial statements with management’s perspective on our financial condition, results of operations, liquidity, and certain other factors that may affect our future results. The following discussion and analysis of our financial condition and results of operations should be read in conjunction with the audited consolidated financial statements (prepared in accordance with accounting principles generally accepted in the United States (“U.S. GAAP”)) and related notes included elsewhere in this Annual Report on Form 10-K (this “Form 10-K”). The following discussion contains forward-looking statements that are subject to risks and uncertainties. See “Cautionary Statements” for a discussion of the uncertainties, risks, and assumptions associated with those statements. Actual results could differ materially from those discussed in or implied by forward-looking statements as a result of various factors, including those discussed below and elsewhere in this Form 10-K, particularly in the section entitled “Risk Factors.” Unless we state otherwise or the context otherwise requires, the terms “we,” “us,” “our” and the “Company” refer to Paycom Software, Inc. and its consolidated subsidiaries. All amounts presented in tables, other than per share amounts, are in millions unless otherwise noted.
Overview
We are a leading provider of a comprehensive, cloud-based human capital management solution delivered as Software-as-a-Service. We provide functionality and data analytics that businesses need to manage the complete employment lifecycle, from recruitment to retirement. Our solution requires virtually no customization and is based on a core system of record maintained in a single database for all human capital management (“HCM”) functions, including payroll, talent acquisition, talent management, human resources (“HR”) management and time and labor management applications. Our user-friendly software allows for easy adoption of our solution by employees, enabling self-management of their HCM activities in the cloud, which reduces the administrative burden on employers and increases employee productivity.
Substantially all of our revenues are generated from (i) fixed amounts charged per billing period plus a fee per employee or transaction processed and (ii) fixed amounts charged per billing period. Our billing period varies by client and is typically based on when each client pays its employees, which may be weekly, bi-weekly, semi-monthly or monthly. Over time, an increasing number of clients will be billed on a monthly basis for certain HCM applications and services, regardless of the client’s payroll cycle. We serve a diverse client base in terms of size and industry. Our revenues are primarily generated through our sales force that solicits new clients and our client relations representatives (“CRRs”) who sell additional applications to existing clients.
Our principal marketing efforts include national and local advertising campaigns, email campaigns, social and digital media campaigns, search engine marketing methods, sponsorships, tradeshows, print advertising and outbound marketing including personalized direct mail campaigns. In addition, we generate leads and build recognition of our brand and thought leadership with relevant and informative content, such as white papers, blogs, podcast episodes and webinars.
Throughout our history, we have built strong relationships with our clients. As the HCM needs of our clients evolve, we believe that we are well-positioned to expand the HCM spending of our clients, and we believe this opportunity is significant. To be successful, we must continue to demonstrate the operational and economic benefits of our solution, as well as effectively hire, train, motivate and retain qualified personnel.
Growth Outlook, Opportunities and Challenges
As a result of our significant revenue growth and geographic expansion, we are presented with a variety of opportunities and challenges. Our payroll application is the foundation of our solution, and all of our clients are required to utilize this application in order to access our other applications. Consequently, we have historically generated the majority of our revenues from our payroll applications, although our revenue mix has evolved and will continue to evolve as we develop and add new non-payroll applications to our solution.
We believe our strategy of focusing on incorporating artificial intelligence (“AI”) and automation across our full solution is an important differentiator for attracting new clients and key to long-term client satisfaction and client retention. Our software vision is that people should not perform payroll-related and HCM-related tasks that systems can automate. We have designed our software so users do not have to be system experts or even need training to access information. For example, our industry-first command-driven AI engine, IWant, provides an easy, automated avenue for seeking information about employee data without having to navigate through the software.
Our continued growth depends on attracting new clients by continuing to leverage our sales force productivity, penetrating existing markets and expanding into new markets, targeting a high degree of client employee usage across our solution, and introducing new applications to our existing client base. Client adoption of new applications and, historically, client employee usage of both new and existing applications have been significant factors in our recurring revenue growth. We believe our ability to continue to develop new applications and to improve existing applications will enable us to increase recurring revenues in the future. In addition, we plan to open additional sales offices in the future to further expand our market presence.
41
The market for HCM software is highly competitive, rapidly evolving and fragmented. We expect competition to remain intense as new market entrants and disruptive technologies emerge and aggressive pricing and client retention strategies persist. These market pressures can directly affect our recurring revenue growth and our ability to attract and retain clients. We believe our long-term focused investments in automation, client ROI achievement, and world-class service can strengthen our recurring revenue growth and annual revenue retention rate.
Our target client size is organizations with 50 to 10,000 or more employees. While we continue to serve a diversified client base ranging from small businesses to organizations with many thousands of employees, the average size of our clients has grown significantly as we have organically grown our operations and increased the number of applications we offer. We believe larger employers, such as organizations with greater than 1,000 employees, represent a substantial opportunity to increase our revenues per client, with limited incremental cost to us. With the launch of our Global HCM solution and expansion of payroll services into certain international markets, we expect that our ability to serve organizations with international employees makes our solution more attractive to larger companies, many of which have a global presence. Because we charge our clients on a per employee basis for certain services we provide, any increase or decrease in the number of employees of our clients will have a positive or negative impact, respectively, on our results of operations. As a result, the performance of certain of our offerings is sensitive to changes in the labor market. In addition, a multitude of macroeconomic pressures, such as inflation and changes in interest rates, impact our clients’ hiring practices to varying degrees and, in turn, impact our revenues.
We believe the challenges of managing the ever-changing complexity of payroll and HR will continue to drive companies to turn to outsourced providers for help with their HCM needs. The HCM industry historically has been driven, in part, by legislation and regulatory action, including COBRA, changes to the minimum wage laws or overtime rules, and legislation from federal, state or municipal taxation authorities.
Growing our business has resulted in, and will continue to result in, substantial investments in sales professionals, operating expenses, system development and programming costs (including those related our full solution automation and AI initiatives) and general and administrative expenses, which have increased and will continue to increase our expenses. Historically, our revenue growth and geographic expansion have driven increases in (i) facility costs related to data centers, the expansion of our corporate headquarters, operations facilities and additional sales office leases and (ii) salaries and benefits and stock-based compensation expense. Automating our core business systems is creating new efficiencies that have led to reductions in headcount and, as a result, contributed to a decrease in certain employee-related expenses during the year ended December 31, 2025. Due to lower headcount, we expect that certain employee-related expenses will be lower in 2026 as compared to 2025.
Key Metrics
In addition to the U.S. GAAP and non-GAAP metrics discussed elsewhere in this Form 10-K, we also monitor the following metrics to evaluate our business, measure our performance and identify trends affecting our business:
Year Ended December 31,
Key performance indicators:
Annual revenue retention rate(1) 91 % 90 % 90 %
•
Clients. When we calculate the number of clients at period end, we treat client accounts with separate taxpayer identification numbers (or, in certain circumstances, separate client codes) as separate clients, which often separates client accounts that are affiliated with the same parent organization. We track the number of our clients to provide an accurate gauge of the size of our business. Unless we state otherwise or the context otherwise requires, references to clients throughout this Form 10-K refer to this metric.
•
Clients (based on parent company grouping). When we calculate the number of clients based on parent company grouping at period end, we combine client accounts that have identified the same person(s) as their decision-maker regardless of whether the client accounts have separate taxpayer identification numbers (or, in certain circumstances, separate client codes), which often combines client accounts that are affiliated with the same parent organization. We track the number of our clients based on parent company grouping to provide an alternate measure of the size of our business and clients.
•
Sales Teams. We monitor our sales professionals by the number of sales teams at period end. For the purposes of this metric, CRRs and emerging markets representatives are considered one sales team. Each outside sales team typically consists of a sales manager and approximately seven other sales professionals. Certain larger metropolitan areas can
42
support more than one outside sales team. We believe the number of sales teams is an indicator of potential revenues for future periods.
•
Annual Revenue Retention Rate. Our annual revenue retention rate tracks the percentage of revenues that we retain from our existing clients. We monitor this metric because it is an indicator of client satisfaction and revenues for future periods.
We calculate annual revenue retention rate for any 12-month period (a “Measurement Period”) as follows:
Recurring and Other Revenues – TTM Revenue Attrition
Recurring and Other Revenues
The trailing 12-month value of revenue from clients lost during the Measurement Period (“TTM Revenue Attrition”) is equal to the actual recurring fees paid by such lost clients during the 12 months preceding the respective dates on which they last processed payroll with us. The point at which a client is deemed “lost” is determined based on the terms of our standard services agreement with clients. As described in Note 2 “Summary of Significant Accounting Policies”, for the year ended December 31, 2024, we changed the presentation of revenues on the consolidated statements of comprehensive income to disaggregate interest on funds held for clients and combine recurring and other revenues. Reclassifications for the presentation of revenue did not impact the calculation of our annual retention rate.
Components of Results of Operations
Sources of Revenues
Revenues consist of recurring and other revenues, and interest on funds held for clients. We expect our revenues to increase as we introduce new applications, expand our client base and renew and expand relationships with existing clients.
Recurring and Other Revenues
Recurring revenues are derived primarily from our payroll, talent acquisition, talent management, HR management and time and labor management applications, fees charged for form filings and delivery of client payroll checks and reports, and revenues associated with background checks and income and employment verification services. The client’s use of our applications routinely fluctuates based upon factors that include the number of payrolls run and changes in the client’s employee population.
Substantially all of our revenues are generated from (i) fixed amounts charged per billing period plus a fee per employee or transaction processed and (ii) fixed amounts charged per billing period. Our billing period varies by client and is typically based on when each client pays its employees, which may be weekly, bi-weekly, semi-monthly or monthly. Over time, an increasing number of clients will be billed on a monthly basis for certain HCM applications and services, regardless of the client’s payroll cycle. Because recurring revenues are based, in part, on fees for use of our applications and the delivery of checks and reports that are levied on a per-employee basis, our recurring revenues can fluctuate in relation to changes to client employee count. Furthermore, because the timing of revenue recognition is driven by the processing of the client’s payroll, it can vary based upon changes in client payroll dates and the impact that weekends or public holidays may have in prompting a client to accelerate or delay the processing of payroll.
Recurring revenues include revenues relating to the annual processing of payroll tax filing forms and Affordable Care Act (“ACA”) form filing requirements and revenues from processing unscheduled payroll runs (such as bonuses) for our clients. These payroll forms are typically processed in the first quarter of the year, and many of our clients are subject to ACA form filing requirements in the first quarter, which positively impacts first quarter revenues and margins. We anticipate our revenues will continue to exhibit this seasonal pattern related to ACA form filings for so long as the ACA (or replacement legislation) includes employer reporting requirements. In addition, our recurring revenues during the fourth quarter are positively impacted by unscheduled payroll runs for our clients that occur before the end of the year. Nonetheless, we expect the magnitude of these seasonal fluctuations in our revenues to decrease to the extent clients utilize more of our non-payroll applications.
Other revenues consist of implementation fees for the deployment of our solution and revenues from sales of time clocks as part of our time and attendance services. Non-refundable implementation fees are charged to new clients at contract inception. These fees generally range from 10% to 30% of the annualized value of the transaction. Implementation fees are deferred and recognized as revenue over the life of the client, which is estimated to be 10 years. Revenues from the sale of time clocks are recognized when control is transferred to the client upon delivery of the product.
Interest on Funds Held For Clients
We earn interest income on funds held for clients. Funds held for clients are amounts collected from clients in advance of either the applicable due date for payroll tax submissions or the applicable disbursement date for employee payment services. These collections from clients are typically disbursed from one to 30 days after receipt, with some funds being held for up to 120 days. We typically invest funds held for clients in money market funds, demand deposit accounts, certificates of deposit,
43
commercial paper and U.S. treasury securities until they are paid to the applicable tax or regulatory agencies or to client employees. As we introduce new applications, expand our client base and renew and expand relationships with existing clients, we expect our average funds held for clients balance and, accordingly, interest earned on funds held for clients, will increase; however, the amount of interest we earn is positively or negatively impacted by changes in interest rates.
Cost of Revenues
Cost of revenues consists of expenses related to hosting and supporting our applications, hardware costs, systems support and technology and depreciation and amortization. These costs include employee-related expenses (including non-cash stock-based compensation expenses) and other expenses related to client support, bank charges for processing automated clearing house transactions, certain implementation expenses, delivery charges and paper costs. They also include our cost for time clocks sold and ongoing technology and support costs related to our systems. The amount of depreciation and amortization of property and equipment allocated to cost of revenues is determined based upon an estimate of assets used to support our operations.
Administrative Expenses
Administrative expenses consist of sales and marketing expenses, research and development expenses, general and administrative expenses and depreciation and amortization expenses. Sales and marketing expenses consist primarily of employee-related expenses for our direct sales and marketing staff (such as the amortization of commissions and bonuses and non-cash stock-based compensation expenses), marketing expenses and other related costs. Research and development expenses consist primarily of employee-related expenses (including non-cash stock-based compensation expenses) for our development staff, net of capitalized software costs for internally developed software. General and administrative expenses consist of employee-related expenses for finance and accounting, legal, human resources and management information systems personnel (including non-cash stock-based compensation expenses), legal costs, professional fees and other corporate expenses. Depreciation and amortization expenses consist of (i) the amount of depreciation and amortization of property and equipment allocated to administrative expenses (based upon an estimate of assets used to support our selling, general and administrative functions) and (ii) amortization of intangible assets.
Interest Expense
Interest expense includes interest on our long-term debt. Prior to the repayment of our long-term debt in November 2023, we capitalized interest costs incurred for indebtedness related to construction in progress. See Note 6 “Long-Term Debt” for discussion of the repayment of our debt.
Other Income, net
Other income, net includes interest earned on our own funds, any gain or loss on the sale or disposal of fixed assets, any costs associated with the early repayment of debt, any loss on the extinguishment of debt, and any gain on the modification of the naming rights agreement.
Provision for Income Taxes
Our consolidated financial statements include a provision for income taxes incurred for the anticipated tax consequences of the reported results of operations using the asset and liability method. Under this method, we recognize deferred tax assets and liabilities for the expected future tax consequences of temporary differences between the financial reporting and tax basis of assets and liabilities, as well as for any operating loss and tax credit carryforwards. Deferred tax assets and liabilities are measured using the tax rates expected to apply to taxable income for the years in which those tax assets and liabilities are expected to be realized or settled. We recognize a valuation allowance to reduce deferred tax assets to the net amount we believe is more likely than not to be realized.
44
Results of Operations
The following table sets forth selected consolidated statements of income data and such data as a percentage of total revenues for each of the periods indicated, as well as year-over-year changes with respect to each line item. Refer to “Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations” in the Annual Report on Form 10-K for the year ended December 31, 2024, filed with the Securities and Exchange Commission (the “SEC”) on February 20, 2025, for a discussion of results of operations for the year ended December 31, 2024 compared to the year ended December 31, 2023.
Year Ended December 31,
Revenues
Cost of revenues
Administrative expenses
Revenues
Recurring and Other Revenues
The increase in recurring and other revenues for the year ended December 31, 2025 from the year ended December 31, 2024 was the result of the addition of new clients, increased revenue from sales of additional applications and services to existing clients, additions and increased usage of existing products and services, and the realization of pricing strategies. Client attrition, particularly among smaller clients, partially offset the favorable impact of these revenue drivers.
Interest on Funds Held For Clients
The impact of lower interest rates during the year ended December 31, 2025 as compared to the prior year was partially offset by an increase in average funds held for client balances, but nonetheless resulted in decreased interest earned on funds held for clients for the year ended December 31, 2025 as compared to the year ended December 31, 2024. The average daily balance of funds held for clients was $2.7 billion and $2.4 billion the years ended December 31, 2025 and 2024, respectively.
Expenses
Cost of Revenues
During the year ended December 31, 2025, operating expenses decreased from the prior year by $4.3 million, primarily due to an $8.2 million decrease in employee-related expenses, which was partially offset by a $2.5 million increase in shipping and supplies fees and a $1.1 million increase in banking related fees. Depreciation and amortization expense increased $15.2 million primarily due to the development of additional technology, purchases of other related fixed assets, and the impact of our corporate headquarters expansion that was placed into service in April 2024, which increases were partially offset by the impact of an increase in the estimated useful lives of servers and network equipment.
45
Administrative Expenses
Sales and marketing
During the year ended December 31, 2025, sales and marketing expenses increased from the prior year by $48.4 million due to a $40.4 million increase in marketing and advertising expense and an $8.0 million increase in employee-related expenses. Based on positive results from our advertising campaigns, we plan to continue to invest in our marketing program and may adjust spending levels in future periods as we see opportunities for favorable returns on our investments.
Research and development
During the year ended December 31, 2025, research and development expenses increased $40.8 million from the prior year primarily due to an increase in employee-related expenses.
As a result of reduced headcount, we expect research and development employee-related expenses to be lower in 2026 as compared to 2025. As is customary for our business, we expect fluctuations in research and development expense as a percentage of revenue on a quarter-to-quarter basis due to seasonal revenue trends, the introduction of new products, the amount and timing of research and development costs that may be capitalized and the timing of onboarding new hires and restricted stock vesting events.
Expenditures for software developed or obtained for internal use are capitalized and amortized over a three-year period on a straight-line basis. The nature of the development projects underway during a particular period directly impacts the timing and extent of these capitalized expenditures and can affect the amount of research and development expenses in such period. The table below sets forth the amounts of capitalized and expensed research and development costs for the years ended December 31, 2025 and 2024:
Year Ended December 31,
Capitalized portion of research and development $ 152.9 $ 125.7 22%
Expensed portion of research and development 283.4 242.6 17%
Total research and development costs $ 436.3 $ 368.3 18%
General and administrative
During the year ended December 31, 2025, general and administrative expenses increased $120.4 million from the prior year primarily due to a $117.5 million reversal of previously recognized stock-based compensation expense related to the forfeiture of a restricted stock award upon Chad Richison’s transition to Co-Chief Executive Officer in February 2024 and a $2.0 million increase in other employee-related expenses.
Non-Cash Stock-Based Compensation Expense
The following table presents the non-cash stock-based compensation expense that is included within the specified line items in our consolidated statements of comprehensive income:
Year Ended December 31,
Total non-cash stock-based compensation expense $ 118.7 $ (22.9 ) -619%
Depreciation and Amortization
During the year ended December 31, 2025, depreciation and amortization expense increased from the prior year primarily due to the development of additional technology, purchases of other related fixed assets, and the impact of our corporate headquarters expansion that was placed into service in April 2024, which increases were partially offset by the impact of an increase in the estimated useful lives of servers and network equipment.
Interest Expense
During the year ended December 31, 2025, interest expense was flat compared to the prior year.
Other Income, net
The increase in other income, net for the year ended December 31, 2025, as compared to the prior year, was primarily attributable to a $35.6 million gain that resulted from the July 2025 amendment to the naming rights agreement. See Note 4
46
“Goodwill and Intangible Assets, Net”. Additionally, increases in interest earned on our corporate funds due to higher operating cash balances contributed to the increase. For the years ended December 31, 2025 and 2024, we earned interest on our corporate funds of $17.9 million and $17.3 million, respectively.
Provision for Income Taxes
The provision for income taxes is based on a current estimate of the annual effective income tax rate adjusted to reflect the impact of discrete items. Our effective income tax rate was 27% and 23% for the years ended December 31, 2025 and 2024.
Liquidity and Capital Resources
Our principal sources of capital and liquidity are our operating cash flow and cash and cash equivalents. Our cash and cash equivalents consist primarily of demand deposit accounts and money market funds. Additionally, we maintain a $1.0 billion senior secured revolving credit facility (the “Revolving Credit Facility”), which can be accessed as needed to supplement our operating cash flow and cash balances. As of December 31, 2025, we did not have any outstanding borrowings under the Revolving Credit Facility.
We fund our operations primarily from cash flows generated from operations. We are funding our ongoing capital expenditures from available cash. Further, to date, all cash dividends and purchases under our stock repurchase plan have been funded from available cash, although we may determine that it is appropriate to fund future stock repurchases or other capital requirements from a combination of available cash and borrowings under the Revolving Credit Facility. We believe our existing cash and cash equivalents, cash generated from operations and available sources of liquidity will be sufficient to maintain operations, make necessary capital expenditures, pay dividends and opportunistically repurchase shares for at least the next 12 months. In addition, based on our strong profitability and continued growth, we expect to meet our longer-term liquidity needs with cash flows from operations and, as needed, financing arrangements.
Credit Agreement. We are party to a credit agreement (as amended from time to time, the “Credit Agreement”) with JPMorgan Chase Bank, N.A., as a lender, swingline lender and issuing bank, the lenders from time to time party thereto (collectively with JPMorgan Chase Bank, N.A., the “Lenders”), and JPMorgan Chase Bank, N.A., as the administrative agent. The Credit Agreement provides for the Revolving Credit Facility in the aggregate principal amount of up to $1.0 billion. In addition, we may request an incremental facility of up to an additional $500.0 million, subject to obtaining additional lender commitments and approvals and satisfying certain other conditions. All loans under the Credit Agreement will mature on July 29, 2027 (the “Scheduled Maturity Date”). Subject to certain conditions set forth in the Credit Agreement, we may borrow, prepay and reborrow under the Revolving Credit Facility and terminate or reduce the Lenders’ commitments at any time prior to the Scheduled Maturity Date.
We are required to pay a quarterly commitment fee on the daily amount of the undrawn portion of the revolving commitments under the Revolving Credit Facility at a rate per annum of (i) 0.20% if the Company’s consolidated leverage ratio is less than 1.0 to 1.0; (ii) 0.225% if the Company’s consolidated leverage ratio is greater than or equal to 1.0 to 1.0 but less than 2.0 to 1.0; (iii) 0.25% if the Company’s consolidated leverage ratio is greater than or equal to 2.0 to 1.0 but less than 3.0 to 1.0; or (iv) 0.275% if the Company’s consolidated leverage ratio is greater than or equal to 3.0 to 1.0.
Under the Credit Agreement, we are required to maintain as of the end of each fiscal quarter a consolidated interest coverage ratio of not less than 3.0 to 1.0 and a consolidated leverage ratio of not greater than 3.0 to 1.0.
Stock Repurchase Plan and Withholding Shares to Cover Taxes. In August 2022, our Board of Directors authorized a stock repurchase plan allowing for the repurchase up to $1.1 billion of shares of our common stock in open market transactions at prevailing market prices, in privately negotiated transactions (including accelerated share repurchases) or by other means in accordance with federal securities laws, including Rule 10b5-1 programs. The stock repurchase plan was set to expire on August 15, 2024. In July 2024, our Board of Directors increased and extended the stock repurchase plan, such that $1.5 billion is available for repurchases through August 15, 2026. As of December 31, 2025, there was $1.11 billion available for repurchases under our stock repurchase plan. Our stock repurchase plan may be suspended or discontinued at any time. The actual timing, number and value of shares repurchased depends on a number of factors, including the market price of our common stock, general market and economic conditions, shares withheld for taxes associated with the vesting of equity incentive awards and other corporate considerations.
During the year ended December 31, 2025, we repurchased an aggregate of 1,730,720 shares of our common stock at an average cost of $213.81 per share, including 184,752 shares withheld to satisfy tax withholding obligations for certain individuals upon the vesting of equity incentive awards. Our payment of the taxes on behalf of those individuals resulted in an aggregate cash expenditure of $44.5 million and, as such, we generally subtract the amounts attributable to such withheld shares from the aggregate amount available for future purchases under our stock repurchase plan.
Dividends on Common Stock. For a discussion of our dividends, see “Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities.”
47
Cash Flow Analysis
Our cash flows from operating activities have historically been significantly impacted by profitability, implementation revenues received but deferred, our investment in sales and marketing to drive growth, and research and development. Our ability to meet future liquidity needs will be driven by our operating performance and the extent of continued investment in our operations. Failure to generate sufficient revenues and related cash flows could have a material adverse effect on our ability to meet our liquidity needs and achieve our business objectives.
We completed an expansion of our corporate headquarters, which was placed into service in the second quarter of 2024. Our capital expenditures will fluctuate based on our strategic initiatives. Depending on certain growth opportunities, we may choose to accelerate investments in sales and marketing, acquisitions, technology and services. Actual future capital requirements will depend on many factors, including our future revenues, cash from operating activities and the level of expenditures in all areas of our business.
In addition, we purchased the naming rights to the downtown Oklahoma City arena that is currently home to the Oklahoma City Thunder National Basketball Association franchise. Under the terms of the naming rights agreement, we committed to make escalating annual sponsorship fee payments from 2021 to 2035. The payments are due in the fourth quarter of each year. In July 2025, the naming rights agreement was amended to provide, among other things, that the agreement and our obligation to make the previously disclosed annual sponsorship fee payments thereunder will terminate on the earlier of (i) September 30, 2028 or (ii) the date of the last event hosted or presented at the current arena (subject to earlier termination in certain limited circumstances), with a reduction in the sponsorship fee if the term of the agreement ends prior to September 30, 2028 and in certain other limited circumstances. The amendment did not otherwise impact our obligation to make the previously disclosed annual sponsorship fee payments for the remainder of the amended agreement term.
On July 4, 2025, H.R. 1, the “One Big Beautiful Bill Act” (the “OBBBA”) was signed into law, bringing significant amendments to the U.S. tax code. The OBBBA allows an immediate deduction for domestic research and development expenditures and reinstates 100% bonus depreciation. Our cash tax remittances decreased in the second half of 2025, and we anticipate that continued reductions will positively impact cash flows in future periods.
As part of our payroll and payroll tax filing services, we collect funds from our clients for employment taxes and payroll obligations, which we remit to the appropriate tax agencies and accounts designated by our clients. We typically invest these funds in money market funds, demand deposit accounts, certificates of deposit, commercial paper and U.S. treasury securities from which we earn interest income during the period between receipt and disbursement of such funds.
Our cash flows from investing and financing activities are influenced by the amount of funds held for clients, which can vary significantly from quarter to quarter. The balance of the funds we hold depends on our clients’ payroll calendars. As a result, the balance changes from period to period in alignment with the timing of each payroll cycle.
Our cash flows from financing activities are also affected by the extent to which we use available cash to purchase shares of common stock under our stock repurchase plan as well as equity incentive award vesting events that result in net share settlements and the Company paying withholding taxes on behalf of certain employees. Additionally, we intend to continue to pay a quarterly cash dividend, subject to the discretion of the Board of Directors.
The following table summarizes the consolidated statements of cash flows for the years ended December 31, 2025 and 2024:
Year Ended December 31,
Net cash provided by (used in):
Operating Activities
Cash provided by operating activities for the year ended December 31, 2025 primarily consisted of payments received from our clients and interest earned on funds held for clients. Cash used in operating activities primarily consisted of personnel-related expenditures to support the growth and infrastructure of our business. These payments included costs of operations, advertising and other sales and marketing efforts, information technology infrastructure development, product research and development and security and administrative costs. Compared to the year ended December 31, 2024, our operating cash flows for the year ended December 31, 2025 were positively impacted by changes in working capital.
48
Investing Activities