ITEM 1A. Risk Factors
UL Solutions’ business is subject to various risks and uncertainties. The following summary highlights some of the risks the Company is exposed to in the normal course of its business activities. If any of these risks actually occur, the Company’s business, financial condition and results of operations could be materially and adversely affected. This summary is not complete and the risks summarized below are not the only risks the Company faces. You should review and consider carefully the risks and uncertainties described in more detail following this summary in this Item 1A of Part I, which includes a more complete discussion of the risks summarized below, as well as a discussion of other risks related to the Company’s business and an investment in its Class A common stock.
Summary Risk Factors
•Because the Company’s success depends substantially on the value of its brand and reputation, any adverse publicity, damage to its brand or loss of reputation could impact the demand for its services, erode its market share or otherwise have a material adverse effect on its business, financial condition and results of operations.
•The Company or the third parties that it interacts with face cybersecurity risks and may fail to adequately secure or maintain the confidentiality, integrity or availability of data held as a result of a compromise of systems or data, which could result in a material adverse effect on the Company’s business, financial condition and results of operations, and it may incur increasing costs in an effort to mitigate this risk. The Company is subject to evolving and complex data privacy and data protection laws, the violation of which could result in significant fines, operational restrictions or reputational harm.
•Technological advances in artificial intelligence (“AI”) may in the future disrupt the industries in which the Company operates, which could significantly reduce the demand for the Company’s services or otherwise adversely impact the Company’s reputation and business if it is unable to successfully keep pace and navigate this evolving environment. Regulatory landscapes relating to AI may impact the Company’s ability to use AI and limit the Company’s ability to operate and expand, and actual or perceived failures to comply with regulations relating to AI could result in significant liability or reputational harm.
•The Company’s business is highly competitive. If the Company fails to compete successfully, to innovate in response to changing customer needs, new technologies or other market requirements, to develop new proprietary solutions, to increase the functionality of its current solutions or to develop its reputation as a technology leader, its business, financial condition and results of operations could be adversely affected.
•The Company maintains significant international operations and is subject to a variety of risks associated with doing business outside the United States, including difficulties associated with maintaining compliance with numerous laws and regulations, the imposition of tariffs and enhanced trade, import or export restrictions or changes in U.S. trade policy or similar government actions, general economic, social and political conditions and geopolitical tensions in countries where it operates and the need to expand into, and compete in, new jurisdictions resulting from shifts in supply chains.
•The Company may be adversely affected by global and regional economic and political instability.
•The Company conducts significant business in China, including through its joint venture with CCIC, and is therefore subject to China’s laws and regulations. These laws and regulations may change rapidly and with little notice, may be interpreted, applied or enforced inconsistently by different agencies or authorities and may be inconsistent with or restrictive of the Company’s current operations. Any new or changed regulations and policies, including in the economic policies of China, could result in a material change in the Company’s operations. The Chinese government has the power to exercise significant oversight and discretion over the conduct of the Company’s business in China at any time, without notice, including placing restrictions on its operations in China.
•The Company’s success depends upon its ability to recruit, train and retain key employees, including its senior leadership and its trained and skilled engineering, technical and professional personnel.
•The Company works with dangerous materials and in dangerous environments that could injure its employees, contractors or customers, damage its or its customers’ facilities, disrupt its or its customers’ operations and could otherwise result in significant costs, liabilities and obligations.
12
•The Company is subject to risks related to sustainability.
•A conflict of interest or perceived conflict of interest between the Company’s testing, inspection or certification services, on the one hand, and its advisory and other services, on the other hand, could adversely impact its accreditation or its reputation or expose it to legal liability.
•Changes to relevant regulatory frameworks resulting in a reduction in required inspections, tests or certifications, any requirement that the Company accept third-party test results or certifications in lieu of collecting its own data and conducting its own tests, and the harmonization of international or cross-industry benchmarks and standards, in each case, could lead to the reduction in demand for, or commoditization of, the Company’s services, which could have a material adverse effect on the Company’s business, financial condition and results of operations.
•The Company’s business depends substantially on the level of its customer satisfaction and specifically on customers maintaining their agreements with the Company and purchasing additional services from the Company, a significant decline in any of which could harm the Company’s business, financial condition and results of operations.
•Part of the Company’s growth strategy is to pursue strategic transactions, including acquisitions, and the Company may not be able to find suitable acquisition targets or achieve its desired acquisition objectives.
•Allegations of the Company’s failure to properly perform its services may expose it to potential product and other liability claims, recalls, penalties and reputational harm or could otherwise cause a material adverse effect on the Company’s business, financial condition and results of operations.
•Any failure to obtain, maintain, adequately protect or enforce the Company’s intellectual property and proprietary rights could impair the Company’s ability to protect its proprietary technology, the UL Mark and its brand.
•Any unethical conduct by the Company’s employees, agents, contractors, partners, Underwriters Laboratories Inc. (“UL Research Institutes”) or ULSE Inc. (“UL Standards & Engagement”) could result in financial penalties or affect the Company’s brand, reputation or image, any of which could have a material adverse effect on its business, financial condition and results of operations.
•Changes in, a significant delay in obtaining, failure to obtain or the withdrawal or revocation of the Company’s licenses, approvals, accreditations or other authorizations or delegations of authority would likely have a material adverse effect on the Company’s business, financial condition and results of operations.
•The Company is currently defending certain litigation, and it is likely to be subject to additional litigation in the future, any of which could be costly to defend and may harm the Company’s reputation.
•The substantial ownership of the Company’s common stock by UL Standards & Engagement, together with the dual class structure of the Company’s common stock and UL Standards & Engagement’s governance and consent rights under the Company’s Amended and Restated Certificate of Incorporation and the Stockholder Agreement, concentrates voting control with UL Standards & Engagement for the foreseeable future, which will limit the ability of the Company’s other stockholders to influence corporate matters, including the election or removal of directors and the approval or rejection of any change of control transaction.
•The Company may not be able to generate sufficient cash to service all of its indebtedness, and may be forced to take other actions to satisfy its obligations under its indebtedness, which may not be successful.
•As a result of becoming a public company, the Company has incurred, and will continue to incur, significant costs related to being a public company, and management will be required to devote substantial time to compliance with the Company’s public company responsibilities and corporate governance practices.
Risks Related to Our Industry and Business
Because our success depends substantially on the value of our brand and our reputation as a market leader in the TIC services industry, adverse publicity, damage to our brand or a loss of reputation could impact the demand for our services or erode our market share or otherwise have a material adverse effect on our business, financial condition and results of operations.
13
Our reputation and the value of our brand are critical to our business. Adverse publicity concerning the quality or effectiveness of our services, safety or non-compliance issues with products we have tested or certified, whether or not directly relating to or involving the services we performed, and other matters, including adverse publicity about, or events relating to, UL Research Institutes, UL Standards & Engagement or their research or standard-setting activities (which we cannot control), could result in the loss of our existing customer relationships, our inability to attract new customers, legal claims, government or regulatory investigations, increased insurance costs or diminished trust from AHJs, all of which could adversely affect our business, financial condition and results of operations. The value of our brand and our reputation could be severely damaged even by isolated incidents, particularly if the incidents receive considerable negative publicity or result in substantial litigation.
Any such incidents, and any resulting adverse publicity, may arise from events that are beyond our control, such as international trade disputes, regulatory changes, market fluctuations, supply chain constraints, actions taken by our customers, employees or other third parties and poor quality control in our customers’ manufacturing processes. For example, part of our business involves testing and inspecting products, facilities, processes, components and systems against various legal, regulatory, industry and customer standards and requirements, but we do not serve as an AHJ or other enforcement body in connection with such testing and inspection services. Misunderstandings regarding our role in our customers’ compliance processes or the failure by our customers or other third parties to appropriately and effectively use and act on the findings of our assessments could lead to reputational harm. In addition, from time to time, our customers and others make claims and take legal action against us, UL Research Institutes or UL Standards & Engagement. Whether or not any such claims have merit, they may adversely affect our reputation, our customers’ trust in our brand and the demand for our services. Demand for our services could also diminish significantly if any such incidents or other matters erode general confidence in us or our services, which would likely result in reputational damage or lower sales, either of which could materially and adversely affect our business, financial condition and results of operations.
The TIC industry is currently highly competitive and fragmented, and our ability to effectively compete depends heavily on our brand and reputation. Any real or perceived issues with delivering our services to our customers or our failure to provide high-quality services to our customers could adversely affect our brand and reputation. Our customers may no longer choose us over our competitors, and our relevance with key stakeholders, such as AHJs, may be diminished. This, in turn, could cause us to lose market share and our market leadership position, which could have a material adverse effect on our business, financial condition and results of operations. Further, if there is increased consolidation in the TIC industry in the future amongst our competitors, it may result in the loss of our market leadership position as competitors with greater financial, marketing and technical resources emerge. As a result, the demand for our products and services could decrease, which could have a material adverse effect on our business, financial condition and results of operations.
Technological advances in AI may in the future disrupt the industries in which we operate, which could significantly reduce the demand for our services or otherwise adversely impact our reputation, business, financial condition and results of operations if we are unable to successfully keep pace and navigate this evolving environment.
The success of our TIC business depends on sustained demand for our services, which are carried out by our employees who leverage a broad range of technological advances to perform their work. For example, the majority of our TIC services are performed by skilled technicians, engineers, scientists and regulatory experts at our various facilities or on-site at our customers’ facilities. As AI technologies continue to evolve, tasks currently performed by people, including those performed by our employees, may be augmented or replaced by automation, robotics, AI and machine learning and other technological advances. These technological advances also have the potential to enable the development of alternative competitive services or enable our customers to reduce or bypass the use of our services. If any of our customers, competitors or new market entrants develop algorithms or other AI tools capable of replicating or better competing against our services, our services and solutions could, over time, become obsolete or unnecessary, or the demand for our services could be significantly reduced, particularly if any such AI alternative proved to be more accurate, more efficient or more cost-effective than our employees. Any widespread automation of our TIC services could have a material adverse effect on our business, financial condition and results of operations. Further, the use of AI by our customers could lead to product designs which incorporate safety standards and requirements so completely that AI-designed products become the more trusted norm versus human-driven design, testing and inspection.
We use machine learning and AI technologies in our business, and we are making investments in expanding AI capabilities in our products, services and tools, including developing new product features using AI technologies. However, AI technologies are complex and rapidly evolving, and we face significant competition from other companies as well as an evolving regulatory landscape. The proliferation of new and emerging AI technologies, such as generative AI, in the S&A industry may require additional investment in the development of proprietary datasets and machine learning models, new approaches and processes to provide attribution or remuneration to creators of training data and appropriate protections and safeguards
14
for handling the use of customer data with AI technologies, which may be costly if we decide to expand AI technologies in our software product offerings.
Ultimately, our failure to incorporate AI technologies in our product offerings in a timely, effective and compliant manner may place us at a competitive disadvantage, reducing demand for our offerings and adversely affecting our business, financial condition and results of operations; however, there can be no assurance that the usage of or our investments in such technologies will always enhance our products or services or be beneficial to our business, including our efficiency or profitability.
The legislative, judicial and regulatory landscapes relating to AI are evolving and may impact our ability to use AI, and could limit our ability to operate and expand our business, cause revenue to decline and adversely affect our business. The actual or perceived failure to comply with regulatory requirements and laws relating to AI could result in significant liability or reputational harm.
Uncertainty in the legal regulatory regime relating to AI may require significant resources to modify and maintain business practices to comply with U.S. and non-U.S. laws, the nature of which cannot be determined at this time. Several jurisdictions around the globe, including Europe, China and the United States, have already proposed frameworks or proposed or enacted laws and regulations governing AI, including the EU Artificial Intelligence Act (the “EU AI Act”). The EU AI Act establishes a comprehensive, risk-based governance framework for AI in the EU market and applies to companies that develop, use and/or provide AI in the EU and – depending on the AI use case - includes requirements around transparency, conformity assessments and monitoring, risk assessments, human oversight, security, accuracy, general purpose AI and foundation models, and fines for breach.
In China, a number of regulations to govern AI have been implemented, namely the Interim Provisions on Management of Generative Artificial Intelligence Services, Administrative Provisions on Algorithm Recommendation for Internet Information Services and Provisions on Management of Deep Synthesis in Internet Information Service, respectively, which impose strict obligations on service providers, among other entities, with respect to their provision and use of generative AI, algorithmic recommendation and deep synthesis technologies. For example, service providers must file the algorithms used and complete a security assessment with the Cyberspace Administration of China (the “CAC”) before the provision of the AI service. The regulatory framework in China is expected to have a material impact on the way AI is regulated in China, and together with developing guidance and/or decisions in this area, may affect our use of AI and our ability to provide and to improve our services. Other jurisdictions may adopt similar or more restrictive legislation that may render the use of such technologies challenging.
Additionally, certain privacy laws extend rights to individuals (such as the right to delete certain personal data) and regulate automated decision making, which may be incompatible with our AI features or our use of AI. These obligations may lead to regulatory fines or penalties or prevent or limit our use of AI. If we are deemed to not have sufficient rights to the data we use to train our generative AI technologies, we may be subject to litigation by the owners of the content or other materials that comprise such data, similar to the litigation that is currently pending in various U.S. courts against other developers of generative AI technologies, and in which the outcome of such litigation is uncertain. If we cannot use AI, or that use is restricted, our business may be less efficient, or we may be at a competitive disadvantage. We are implementing various initiatives that are designed to address potential AI risks; however, these initiatives may prove insufficient to mitigate potential risks.
A failure to effectively leverage emerging AI technologies in our internal operations and management of our business may adversely impact the efficiency of our operations and our ability to keep pace with our competitors and may expose us to regulatory and other risks.
As machine learning and AI technologies continue to evolve, more companies are leveraging these technologies to improve efficiencies and maximize opportunities with respect to the management of their respective businesses. We continue to evaluate the ability to leverage such technologies for our own internal operations, including, among other things, fuzzy searches, data extraction and content summarization. However, if we fail to effectively utilize and implement such technologies, or our utilization of such technologies is restricted as the regulatory environment around AI technologies evolves, our business may become less efficient or exposed to greater regulatory risk and may be at a competitive disadvantage.
Further, the introduction of AI technologies into our operations may result in new or enhanced governmental or regulatory scrutiny, confidentiality (including placing our employees’ and our customers’ sensitive or confidential information at risk) or security risks, ethical concerns, legal liability or other complications that could adversely affect our reputation, business, financial condition and results of operations. For example, AI technologies incorporated into our product offerings may use algorithms, datasets or training methodologies that may be flawed or contain deficiencies that may be difficult to detect
15
which, in turn, may create an output that is factually inaccurate, biased or otherwise flawed. If our customers or others rely on or use such output to their detriment, it may lead to adverse outcomes, which may expose us or our customers to reputational harm, competitive harm or legal liability. Additionally, the use of certain AI technologies, including generative AI, may place our and our customers’ confidential information at risk if adequate security measures are not employed.
The use or adoption of third-party AI technologies into our products and services may result in exposure to claims of copyright infringement or other intellectual property misappropriation. If we are deemed to not have sufficient rights to the data we use to train our generative AI technologies, we may be subject to litigation by the owners of the content or other materials that comprise such data, similar to the litigation that is currently pending in various U.S. courts against other developers of generative AI technologies, and in which the outcome of such litigation is uncertain.
Our business is highly competitive, and the success of our business depends, in part, on our ability to develop new proprietary technical solutions, increase the functionality of our current solutions and develop our reputation as a technology leader. If we fail to compete successfully, or if we fail to innovate in response to changing customer needs, new technologies or other market requirements, our business, financial condition and results of operations could be adversely affected.
Our success depends on our ability to continue to innovate, develop and introduce new software and techniques to support our services in order to continue to meet the requirements of our customers better than our competitors. We face competition from other providers of TIC and S&A services, as well as from new competitors such as start-ups and private equity-backed companies. We generally compete with them on the basis of quality, service, reputation, cost, capacity and turn-around time of our services and our reputation with third parties, such as retailers and regulators. If our services, supply, support, distribution, cost structure or reputation do not enable us to continue competing successfully with our current competitors, or to compete in the future with any new market entrants, our business, financial condition and results of operations could be materially adversely affected.
Our future success and competitive advantage also depend on our ability to keep pace with rapid technological changes that could make our services less competitive or obsolete and on our ability to increase customer adoption of our services, including our SaaS offerings. Our customers are continuously innovating their products and technology and generally expect us to keep pace with their innovations. We risk losing market share if we fail to adapt quickly enough to market needs in areas like AI, embedded software, functional safety and other new technologies as they evolve. Our competitors or others might develop technologies or services that are more effective or commercially attractive than our current or future offerings, or that render our technologies or services obsolete. Furthermore, if our competitors have greater resources and access to funding, they may be able to finance the development of new technologies before we are able to do so, which may allow them to enter new markets and monetize their data solutions more quickly or effectively than us or provide lower-priced or better-quality services. If we fail to successfully monetize our data or data-based offerings, invest in the right technologies or innovate as technology and our customers’ needs evolve, or if our competitors introduce superior technologies or services and we cannot make enhancements to our own, our competitive position and, in turn, our business, financial condition and results of operations, could be materially and adversely affected. Many of the markets in which we compete, including cybersecurity and connected devices, are also subject to evolving industry and information technology (“IT”) operational standards and regulations, resulting in increasing compliance requirements for us and our customers. To the extent we expand further into highly regulated industries, our services may need to address additional requirements specific to those industries.
In addition, our ability to compete may be affected by increased digital disruption of the TIC industry by evolving technology and new solutions. The TIC industry is subject to increasingly rapid technological changes, including an increased focus on data provisioning and analysis. For example, increased digitization of regulatory or product information, simulation and predictive testing of products, remote inspection or reliance on AI could replace traditional TIC services. Our failure to innovate and adapt to address these changes, either on a timely basis or at all, could result in our loss of market share or significantly reduce demand for our services.
Finally, remaining competitive in our industry requires us to maintain a favorable geographic dispersion. If our geographic placement and dispersion are, or become, suboptimal, or our competitors are able to achieve more favorable geographic dispersion, whether through organic or inorganic growth, we could lose or miss out on market share. Additionally, we compete with a number of local and regional TIC service providers who may be better suited than us to compete in local and regional markets due to their brand recognition, expertise in local and regional regulations and better access to local and regional markets and customers. If we cannot adapt or meet the needs of our customers in the various regions in which we and our customers are located, we may not be able to continue to compete successfully on a global scale.
16
We are subject to a variety of risks associated with doing business outside the United States.
We maintain significant international operations, including operations in Greater China (mainland China, Hong Kong and Taiwan), Japan, Germany, the Republic of Korea, Italy and Canada, as well as other countries. We continue to increase our global footprint. For example, since 2022, we have opened additional laboratories in Mexico, the Republic of Korea, Vietnam and Taiwan. In 2025, approximately 59.0% of our revenue was generated from customers outside the United States. Any unfavorable government policies, whether in the United States or otherwise, including increased scrutiny on companies with significant operations outside the United States, may affect our competitive position, our ability to participate in state-sponsored programs, our ability to raise capital, the hiring of personnel or the demand for our services or prevent us from offering our services. As a result, we are subject to a number of risks and complications associated with international sales, services and other operations, as well as risks associated with U.S. regulations, national security priorities or foreign policy. These include:
•difficulties associated with compliance with numerous, potentially conflicting and frequently complex and changing laws and regulations in multiple jurisdictions, such as with respect to business licensing and environmental matters, intellectual property, privacy and data protection, corrupt practices, embargoes, trade sanctions, competition, employment and licensing;
•general economic, social and political conditions in countries where we operate, including international and U.S. trade, national security and other foreign policies, currency exchange rate fluctuations and political and economic instability;
•tax and other laws that reduce our profitability or restrict our ability to use tax credits, offset gains or repatriate funds, as well as changes in local and international tax laws, including transfer pricing regulations and changes in tax treaties, which may restrict our ability to use tax credits, offset gains, repatriate funds or result in adverse tax consequences;
•any adverse changes in the regulatory environments applicable to us, which could negatively impact our business;
•foreign exchange and currency restrictions, transfer pricing regulations and adverse tax consequences, which may affect our ability to transfer capital and profits;
•inflation, deflation and stagflation in any country in which we operate;
•foreign customers with longer payment cycles than customers in the United States; and
•imposition of or increases in customs duties and other tariffs.
Further, we operate in a number of countries throughout the world, including in countries that lack developed legal systems or do not have as strong a commitment to anti-corruption and ethical behavior as is required by U.S. laws or by our corporate policies. In addition, based on the nature of our services and our structure, we interact with both governments and government-owned enterprises, including in connection with our UL-CCIC Company Limited (“UL-CCIC”) joint venture, in which 30% of the equity interest is owned by China Certification & Inspection (Group) Co., Ltd. (“CCIC”), a Chinese state-owned enterprise. Therefore, we are subject to the risk that we, our officers, directors, employees, business partners, joint venture partners or any third party that we engage to do work on our behalf may take action determined to be in violation of anti-corruption laws in the jurisdictions in which we conduct business, including the U.S. Foreign Corrupt Practices Act (the “FCPA”), the UK Bribery Act 2010 (the “Bribery Act”) and the Canadian Corruption of Foreign Public Officials Act (the “CFPOA”), which prohibit corruptly providing, offering, promising or authorizing, directly or indirectly, anything of value to foreign officials, political parties or candidates for political office for the purposes of obtaining or retaining business or securing any improper business advantage. The provisions of the Bribery Act also prohibit non-governmental commercial bribery, soliciting or accepting bribes and “facilitation payments,” or small payments to low-level government officials to expedite routine approvals. The Bribery Act also has an offense applicable to corporate entities and partnerships that carry on part of their business in the UK that fail to prevent bribery, which can take place anywhere in the world, by persons who perform services for or on behalf of them, subject to a defense of having adequate procedures in place to prevent the bribery from occurring. The offense could render parties criminally liable for the acts of their agents, joint venture partners or commercial partners, even if done without their knowledge.
U.S. public companies are required to maintain records that accurately and fairly represent their transactions and have an adequate system of internal accounting controls. We maintain internal controls, policies and procedures to promote compliance by our directors, officers, employees, business partners and third parties acting on our behalf with the FCPA, the
17
Bribery Act, the CFPOA and other applicable anti-corruption laws. However, we can make no assurance that our controls, policies and procedures, even if enhanced, have been or will be followed at all times or will effectively detect and prevent all violations of the applicable laws. Further, in connection with past and future acquisitions by us, there is a risk of successor liability relating to such laws in connection with prior actions or alleged actions of an acquired company.
Compliance with multiple, and potentially conflicting, international laws and regulations, including anti-corruption laws, may be difficult, burdensome or expensive. A violation of the FCPA, the CFPOA, the Bribery Act or any similar anti-corruption law or regulation could result in substantial fines, sanctions, disgorgement of profits or civil or criminal penalties, debarment from business dealings with certain governments or government agencies or restrictions on the marketing of our services in certain countries, injunctions or other remedial measures, which could result in material harm to our reputation, business, financial condition and results of operations. Further, detecting, investigating and resolving actual or alleged violations is expensive and can consume significant time and attention of our senior management.
Although we currently operate in a number of countries throughout the world, a shift in the location of our customers’ product development and manufacturing could result in us needing to expand into, and compete in, new jurisdictions and, as a result, to navigate new regulatory and competitive environments.
We may be adversely affected by global and regional economic and political instability.
We may be adversely affected by global and regional economic and political conditions. The uncertainty or prolonged instability of the global economic and political environment could adversely affect us. Customers may modify, delay or cancel plans to purchase our services. Any inability of current or potential customers to purchase or pay for our services due to, among other things, declining economic conditions as a result of inflation, rising interest rates, changes in spending patterns and the effects of governmental initiatives to manage economic conditions may have a negative impact on our business, financial condition and results of operations. Additionally, we may face uncertainties in the business environment or volatility in financial markets due to policy shifts in certain key markets. The U.S. government has implemented or announced significant new tariffs on products manufactured in a wide range of countries, including China, Mexico, and countries in Southeast Asia. These actions have prompted a cycle of retaliatory tariffs and potential retaliatory tariffs by a number of these countries and the United States. Actions that our customers take to adapt to new tariffs or other trade restrictions may, in turn, require us to modify our operations, which could be time-consuming and expensive and have an adverse effect on our business, financial condition and results of operations.
Further, recent U.S. intervention in Venezuela and the conflicts between Russia and Ukraine and in Israel, Gaza and surrounding areas have created increasingly volatile geopolitical and economic conditions around the world; however, we do not currently expect that these situations will have a material, direct impact on our business, financial condition and results of operations. In March of 2022, we made the decision to stop all work in Russia and Belarus and not take on or pursue any new customer orders related to those countries for the foreseeable future. However, geopolitical instability and adversity arising from global geopolitical conflicts, the imposition of sanctions, taxes or tariffs, and impacts to energy markets and supplies could adversely affect the global economy or specific international, regional and domestic markets we operate in, increase inflationary pressures, or disrupt our customers’ supply chains, which could in turn have a material adverse effect on our business, financial condition and results of operations.
Additionally, our operating cash flows, combined with access to the credit markets, provide us with significant discretionary funding capacity. However, deterioration in the global credit markets may limit our ability to access credit markets, which could adversely affect our liquidity or increase our cost of borrowing. Increases in our cost of borrowing could adversely affect our liquidity and results of operations.
Enhanced trade tariffs, import restrictions, export restrictions, regulations or other trade barriers could materially adversely affect our business, financial condition and results of operations.
We are continuing to expand our international operations as part of our growth strategy and have experienced an increasing concentration of sales in certain regions outside the United States. There is currently significant uncertainty about the future relationship between the United States and various other countries, most significantly mainland China, with respect to trade policies, investment access, treaties, government regulations and tariffs. Tariffs, trade restrictions or trade barriers that have been, and may in the future be, placed on products we test, inspect and certify by the U.S. and foreign governments, especially mainland China, have raised, and could further raise, amounts paid for some or all of our services, which may result in the loss of customers or harm our business, financial condition and results of operations. Further tariffs may be imposed that could cover imports of components and materials used in our customers’ products, or our business may be adversely impacted by retaliatory trade measures taken by mainland China or other countries, including restricted access to components or materials used in our customers’ products or increased amounts that must be paid for their products, which could significantly reduce demand for our services, in turn materially harming our business, financial condition and results of
18
operations. Further, the continued threats of tariffs, trade restrictions and trade barriers could have a generally disruptive impact on the global economy and, therefore, negatively impact our sales. Given the relatively fluid regulatory environment in mainland China and the United States and uncertainty regarding how the U.S. or foreign governments will act with respect to tariffs, international trade agreements and policies, there could be additional tax or other regulatory changes in the future. Any such changes could directly and adversely impact our business, financial condition and results of operations. For a discussion of additional risks related to our business in China, see “—Risks Related to Conducting Business in China.”
We are subject to governmental export and import controls that could impair our ability to compete in international markets or subject us to liability if we violate the controls.
Our business is subject to U.S. export controls, including the U.S. Export Administration Regulations. Obtaining the necessary export license or other authorization for a particular sale may be time-consuming and may result in the delay or loss of sales opportunities. Furthermore, our activities are subject to U.S. economic sanctions laws and regulations administered by the U.S. Treasury Department’s Office of Foreign Assets Control that prohibit the sale or supply of most products and services to embargoed jurisdictions or sanctioned parties. Violations of U.S. sanctions or export control regulations can result in significant fines or penalties and possible incarceration for responsible employees and managers. If we fail to obtain appropriate import, export or re-export licenses or permits, we may be adversely affected through reputational harm, as well as other negative consequences, including government investigations and penalties.
Also, various countries, in addition to the United States, regulate the import and export of certain technology, including import and export licensing requirements, and have enacted laws that could limit our ability to distribute our SaaS and other technology solutions in those countries.
Future changes in export and import regulations may create delays in the introduction of our technology solutions in international markets. Any change in export or import regulations, economic sanctions or related legislation, increased export and import controls or change in the countries, governments, persons or technologies targeted by such regulations, could result in decreased use of our technology solutions by, or in our decreased ability to export or sell our technology solutions to, existing or potential customers with international operations. Any decreased use of our technology solutions or limitation on our ability to export or sell our technology solutions could adversely affect our business, financial condition and results of operations.
The success of our operations in international markets is highly dependent on the expertise of local management and operating staff, as well as the political, social, legal and economic operating conditions of each country in which we operate.
The success of our business depends on the actions of our employees. In our international locations, we are highly dependent on our local management and operating staff to serve our customers and operate our facilities in these markets in accordance with local law and best practices. If the local management or operating staff were to leave our employment, we would have to expend significant time and resources building up our management or operational expertise in these local markets. Such a transition could adversely affect our reputation in these markets and could materially and adversely affect our business, financial condition and results of operations.
Additionally, the health and safety of our employees or those working on our behalf, and the security of our physical infrastructure, may be affected due to acts of violence or vandalism by anti-social elements. Although we take protective measures to ensure the safety of our employees at our global locations of work and work-related travel, incidents of organized political demonstrations, civil unrest or random acts of rage can affect the safety of our assets and employees, impacting our business, financial condition and results of operations.
We are also subject to other inherent risks attributed to operating in a global economy. As of December 31, 2025, we leased or owned 87 sites with laboratories spread across 27 countries. If the international markets in which we compete are affected by changes in political, social, legal, economic or other factors—such as deterioration in U.S.-China relations, instability in the Korean peninsula or South China Sea, the conflict between Russia and Ukraine or conflicts in the Middle East—our business, financial condition and results of operations may be materially and adversely affected. Uncertainty as a result of such changes may last for years and could also impact our customers’ businesses and operations. Our international operations may subject us to additional risks that differ in each country in which we operate and such risks may negatively affect our results.
19
Our senior leadership team is critical to our continued success, and the loss of such personnel could have a material adverse effect on our business, financial condition and results of operations.
Our current and future success depends substantially on the continued service and performance of the members of our senior leadership team. These personnel possess business and technical capabilities that are difficult to replace. We have attempted to mitigate this risk by providing what we view as market compensation and benefits, as well as appropriate retention incentives, including long-term incentive compensation with multi-year vesting provisions intended to incentivize and retain these key personnel. If we lose key members of our senior leadership team or are unable to effect smooth transitions from one executive to another as part of our succession plan, we may not be able to effectively manage our current operations or meet ongoing and future business challenges, which could have a material adverse effect on our business, financial condition and results of operations.
Additionally, successfully executing organizational change, including management transitions and succession plans for our senior leadership, is critical to our business success. Although we have implemented disciplined, ongoing succession planning for our senior leadership and other key executives, this process does not guarantee that the services of qualified senior executives will continue to be available to us in the future.
Our success depends upon our ability to recruit, train and retain key employees—in particular, our technical personnel—including through the implementation of inclusivity and other human capital initiatives.
Our current and future success depends substantially on our employees, including highly trained and skilled engineering, technical and professional personnel. We depend on the technical and regulatory know-how of our skilled and technical personnel, and competition for their talent is intense among our competitors. Particularly in highly specialized and technical areas, it has become more difficult to retain employees and meet all of our needs for employees in a timely manner, which could affect our growth. We intend to continue to devote significant resources to recruiting, training and retaining qualified employees, including through various inclusivity and other human capital initiatives. However, our efforts may not be successful, particularly in light of the Restructuring Plan (as defined below), or our efforts may otherwise attract undesired scrutiny, which may result in additional risks, any of which may impair our ability to efficiently perform our contractual obligations, timely meet our customers’ needs and ultimately win new business, all of which could adversely affect our business, financial condition and results of operations.
In particular, the success of our TIC business relies on an adequate supply of skilled engineers. Trained and experienced technical personnel are in high demand and may be in short supply in some areas. We cannot guarantee that we will be able to recruit, attract and retain the skilled workforce of engineers necessary to continue offering our existing and future services widely or efficiently, or that labor expenses or employee turnover will not increase as a result of a shortage in the supply of skilled engineers, any of which could have a material adverse effect on our business, financial condition and results of operations.
Additionally, changes in immigration laws and policies have, in certain circumstances, made it more difficult—and may continue to make it more difficult—for us to recruit or relocate highly skilled technical, professional and management personnel to meet our business needs.
Our profitability could suffer if we are not able to timely and effectively utilize our employees or manage our cost structure.
The cost of providing our services, including the degree to which our employees are utilized, affects our profitability. The degree to which we are able to utilize our employees in a timely manner or at all is affected by a number of factors, including:
•our ability to hire, onboard and deploy new employees;
•our ability to forecast demand for our services and to maintain and deploy headcount that is aligned with demand, including employees with the right mix of skills and experience;
•our employees’ ability to obtain or retain required certifications;
•our ability to manage attrition; and
•our need to devote time and resources to training, business development and other non-chargeable activities.
20
Our greatest assets are our employees, and it is important that we spend adequate resources on their continued technical and regulatory training. If our employees are under-utilized, our profit margin and profitability could suffer. If our employees are over-utilized, it could have a material adverse effect on employee morale and attrition, which would, in turn, have a material adverse effect on our business, financial condition and results of operations.
Our profitability is also affected by the extent to which we are able to effectively manage our overall cost structure for operating expenses, such as wages and benefits, real estate expenses, overhead and capital, including our test equipment and its maintenance, and other investment-related expenditures. If we are unable to effectively manage our costs and expenses and achieve efficiencies, our competitiveness and profitability may be adversely affected.
In November 2025, we announced an expense reduction initiative to further improve our operating model and exit certain lines of business that are no longer considered strategically important to us (the “Restructuring Plan”). However, there can be no assurance that our business will be more efficient or effective than prior to implementation of the Restructuring Plan. In addition, we cannot guarantee that we will be able to implement the Restructuring Plan within the anticipated timeframe, or that the Restructuring Plan will achieve the desired and anticipated benefits within any expected timeframe. Our expectations are subject to many estimates and assumptions, and the actual savings and costs, and the timing for those savings and costs, may vary materially. For example, local law and consultation requirements, including for potential position eliminations, may extend the restructuring process further in certain countries. The implementation of the Restructuring Plan, and any additional restructuring plans we may implement in the future, may be costly and disruptive to our business or have other negative consequences, including due to unanticipated events that may occur, such as litigation, attrition beyond our planned reduction in workforce, negative impacts on employee morale and productivity, or on our ability to attract and retain highly skilled employees, all of which could adversely impact our business, financial condition and results of operations.
We are subject to various EHS obligations, and we work with dangerous materials and in dangerous environments that could injure our employees, contractors or visiting third parties, damage our or our customers’ facilities and disrupt our or our customers’ operations.
We are subject to numerous EHS laws and regulations, including those related to the emission of substances into the environment, management of hazardous materials, and workplace health and safety, among others. Various federal, state, and local authorities (including in the US, China, and other jurisdictions where we operate) have the power to enforce compliance with applicable laws and regulations and permits issued under them. Furthermore, failure to comply with these EHS laws and regulations could result in various fines, suspension or debarment from government contracting, investigations, the imposition of corrective actions or remedial obligations, revocation of permits or other restrictions on our operations, or other penalties. In certain instances, citizen groups also have the ability to bring legal proceedings against us if we are not in compliance with environmental laws. In addition, claims for damages to persons or property, including natural resources, may result from the EHS impacts of our operations. We, like other businesses, can never completely eliminate the risk of contamination or injury from certain materials that we use in our business, and we cannot guarantee that actions to mitigate these risks (including through procuring insurance) will be sufficient or otherwise successful. For example, although we maintain workers’ compensation insurance to cover costs and expenses incurred due to on-the-job injuries to our employees and public liability insurance to cover costs and expenses that may be incurred if third parties are injured on our property, such insurance may not provide adequate coverage against potential liabilities. If we have any violations of, or incur liabilities pursuant to, these laws or regulations, it may result in a material adverse effect on our business, financial condition and results of operations. Such laws also evolve, often becoming stricter over time, which can exacerbate our compliance risks.
Additionally, some of our operations involve destructive testing and the handling of hazardous materials that may pose the risk of fire, explosion, human exposure to hazardous substances or the release of hazardous substances into the environment. For example, as part of our process for certifying a number of products, we use flammable materials and conduct fire testing, such as by setting houses on fire in our large-scale fire laboratories. We also operate battery testing laboratories where we test lithium-ion batteries that contain potentially explosive materials. Such events could result from the actions of our employees, operational failures, natural disasters or terrorist attacks, and might cause injury or loss of life to our employees and others, environmental contamination and property damage. Additionally, as discussed elsewhere in this Annual Report, much of our work, including the work we complete using dangerous materials or in dangerous environments, requires certain permits and other permissions. There is a risk that we, or any of the third parties who complete work for us or are permitted to use a portion of any of our laboratories, fail to obtain or maintain the requisite permits or permissions, on time or at all. Failure to properly handle, transport or dispose of these materials or otherwise conduct our operations in accordance with EHS or other applicable laws or requirements, or any injury or property damage caused by our employees at our or our customers’ facilities, could expose us to substantial liability for administrative, civil and criminal penalties, cleanup and site restoration costs and liability associated with releases of such materials, damages to natural resources and other damages, as well as
21
potentially impair our ability to conduct our operations. Such liability is commonly on a strict, joint and several liability basis, without regard to fault. Liability may be imposed as a result of our conduct that was lawful at the time it occurred or the conduct of, or conditions caused by, prior operators or other third parties. Neighboring landowners and other third parties may file claims against us for personal injury or property damage allegedly caused by the release of pollutants into the environment. A disruption of our operations or our customers’ operations caused by these or other events could have a material adverse effect on our business, financial condition and results of operations. Finally, in connection with certain acquisitions, we could acquire, or be required to provide indemnification against, environmental liabilities that could expose us to material losses for similar EHS matters.
We are subject to risks related to sustainability.
Our business faces scrutiny related to sustainability issues, including renewable resources, environmental stewardship, supply chain management and sustainable procurement, climate change, biodiversity and sustainable land use, air quality, air quality safety, energy use and emissions, waste, water use, workplace conduct, human rights, philanthropy and support for local communities. Evolving expectations and regulations regarding such issues may result in increased costs (including, but not limited to, increased costs related to compliance, stakeholder engagement, contracting and insurance), changes in demand for certain products, enhanced compliance or disclosure obligations or other impacts to our business, financial condition and results of operations.
While we may at times engage in voluntary initiatives (such as voluntary disclosures, certifications or goals, among others) to improve our sustainability profile or to respond to stakeholder expectations, such initiatives may be costly and may not have the desired effect. Expectations around our management of sustainability matters continue to evolve rapidly, in many instances due to factors that are out of our control. For example, our sustainability-related actions or statements (including published targets) are based on data, assumptions, and methodologies that continue to evolve and may ultimately be determined to be erroneous or subject to misinterpretation. We may ultimately be unable to complete certain initiatives or targets, either on the timelines initially announced or at all, or otherwise address stakeholder expectations. Such expectations vary and, at times, can conflict. Both advocates and opponents of certain sustainability matters are increasingly resorting to various forms of activism, including media campaigns and litigation, to advance their perspectives. Any failure to successfully navigate stakeholder expectations may result in reputational damage (including with ratings), litigation or other stakeholder engagement, or other adverse effects to our business, financial condition and results of operations. For example, as stakeholder perceptions of sustainability evolve, there have been increasing allegations of greenwashing against companies making significant environmental claims due to a variety of perceived deficiencies in performance. Additionally, developing alternative offerings that satisfy the market’s evolving expectations on greenhouse gas emissions and other climate related concerns may require us to incur significant costs, and we cannot guarantee that markets will adopt the standards and solutions we develop, either at the pace we expect or at all. As a result, the effects of climate change could have a long-term adverse effect on our business, financial condition and results of operations.
Certain organizations that provide corporate governance and other corporate risk information to investors and stockholders have developed, and others may in the future develop, scores and ratings to evaluate companies and investment funds based on ESG or sustainability metrics. Potential investors and stockholders may consider a company’s sustainability scores in making an investment decision. In addition, investors, particularly institutional investors, use these scores to benchmark companies against their peers, and if a company is perceived as lagging, these investors may engage with such companies to improve sustainability disclosure or performance and may also make voting decisions, or take other actions, to hold these companies and their boards of directors accountable. This may require us to incur significant additional costs or negatively impact our stock price or access to and cost of capital. Similarly, to the extent sustainability matters negatively impact our reputation, they may also impede our ability to compete effectively to attract and retain employees or customers, which may adversely impact our business, financial condition and results of operations. Certain of our customers also have their own sustainability requirements, which are subject to change, and any failure to meet such requirements may adversely impact our ability to do business with them. We may be especially subject to scrutiny on such matters given our efforts to portray our operations and services as a tool to help assess and manage certain sustainability risk.
In addition, we expect there will likely be increasing levels of regulation, disclosure-related and otherwise, with respect to ESG matters, and we expect to be subject to risks associated with societal efforts to mitigate or otherwise respond to climate change. Increasing concern over climate change may result in more regional, federal and global legal and regulatory requirements, changes in investor and other stakeholder expectations and impacts on our suppliers, any of which could result in increased costs we incur. For example, various policymakers (including the SEC, the EU and the State of California) have adopted and may, in the future, further adopt requirements for climate- or other ESG-related disclosures and other actions. These requirements are not uniform across jurisdictions and may be inconsistently applied, which can increase the complexity and cost of compliance, and increase the risk of enforcement or litigation relating to our disclosures and
22
initiatives. While certain of these requirements are limited to listed companies, others (such as several laws adopted in California and the EU) apply to companies that meet certain financial and operational thresholds. These requirements and evolving other stakeholder expectations will likely lead to increased costs, as well as scrutiny that could heighten all of the risks identified in this risk factor. Additionally, many of our customers, business partners and suppliers may be subject to similar expectations, which may augment our existing risks or create new risks, including risks that may not be known to us.
Public perceptions that the products we use or the services we use and deliver are not environmentally friendly, environmentally safe or ethical could adversely impact the demand for our services and our business, financial condition and results of operations.
Public perception that the products we use or services we use and deliver are not environmentally friendly or safe or that they are harmful to humans, animals, or the environment, whether justified or not, could reduce demand for our services, increase regulation or government restrictions or actions, result in fines or penalties, impair our reputation, involve us in litigation, damage our brand reputation and otherwise have a material adverse effect on our business, financial condition and results of operations. For example, we contract with companies that conduct testing on animals. If such companies fail to comply with the Animal Welfare Act or other laws and regulations governing the treatment of animals used in research, we could be subject to fines, penalties or adverse publicity, and our business, financial condition and results of operations could be adversely affected.
A conflict of interest or perceived conflict of interest between our testing, inspection or certification services, on the one hand, and our advisory and other services, on the other hand, could adversely impact our accreditations or credentials or our reputation or expose us to legal liability.
Through our advisory services, we provide sustainability, quality, risk management and other solutions for our customers’ products and their product development, supply chains and organizations, as well as regulatory market access services. Conflicts of interest may arise where we provide certain advisory services or solutions for products or customers to which we are also providing testing, inspection or certification services. To maintain certain of our accreditations or credentials, we must meet impartiality requirements from applicable regulations, scheme rules and/or standards that govern these conflicts of interest. For example, ISO/IEC 17065 prohibits a certification body and any part of the same legal entity from being the designer, manufacturer, installer, distributor, implementer, provider or maintainer of a certified product, process or service. Although we have systems in place designed to ensure compliance with ISO/IEC 17065 and other impartiality requirements, such conflicts of interest, or a perceived conflict of interest, between our testing, inspection or certification services and our advisory services could impact our accreditations or credentials. Meeting the impartiality requirements may require expending significant resources to implement operating firewalls and otherwise comply. Costs to comply are exacerbated by the fact that various accreditors around the world have offered differing interpretations of the standards governing impartiality and conflicts of interest, and requirements from certain regulators are stricter than others. If our testing, inspection or certification services are determined not to meet the necessary impartiality requirements due to our simultaneous advisory offerings, we could lose our accreditations (e.g., ISO/IEC 17025, ISO/IEC 17020, ISO/IEC 17065), credentials or be forced to divest conflicting businesses. Our reputation could also be harmed, and we could be exposed to significant liability. If any of the foregoing events occur, it would likely have a material adverse effect on our business, financial condition and results of operations.
Adverse changes to applicable regulatory frameworks or an increase in the acceptance of self-declaration of conformity that results in a corresponding decrease in third-party certification could reduce demand for our TIC services, which could have a material adverse effect on our business, financial condition and results of operations.
Our business is primarily driven by private sector requirements and government regulations that currently require independent third-party testing and certification of a significant number of products. For example, much of the demand for third-party certification of professionally installed products, including lighting, HVAC, building materials and electrical cable and products—which make up a significant portion of our TIC revenue—is driven primarily by state and local governments as enforced through the use of model codes. In addition, many large retailers currently require that the products they sell be third-party certified, and AHJs demand certification of certain products as well. Any significant adverse change to any regulations governing TIC services, or any significant adverse change in private sector preferences or demands, could have a material adverse effect on our business, financial condition and results of operations.
Additionally, the regulatory regime for TIC services varies by country and product type. For example, some countries allow for self-declaration of conformity to applicable requirements for certain products. If regulations in the United States or other countries are changed, including, for example, as a result of enhanced judicial scrutiny of federal regulatory regimes following the overturning of the Chevron doctrine in the U.S. Supreme Court’s decision in Loper Bright Enterprises v.
23
Raimondo, to allow for additional self-declaration, or if large retailers were to start accepting self-declared products, the need for third-party certifications could decrease over time, thus reducing demand for our TIC services. A substantial increase in the self-declaration of conformity and any corresponding decreased demand for our TIC services would likely have a material adverse effect on our business, financial condition and results of operations.
If we are unable to increase capacity at our existing facilities or build new facilities in a timely and cost-effective manner, we may not achieve our expected revenue growth or profitability or such revenue growth and profitability, if any, could be delayed.
Our growth strategy depends on expanding our capacity, which may include building new facilities and expanding our existing facilities. For example, we are in the process of constructing a new laboratory in Singapore and expanding laboratories in the United States, Germany and Republic of Korea. The construction or expansion of modern and safe facilities requires significant expenditures. Delays in construction of such facilities, or in the review, zoning and licensing process for any new facility, could impair or delay our ability to develop that facility or increase the cost so substantially that the facility becomes unattractive to us. Any failure to procure and maintain the necessary licenses, or adhere to applicable zoning or other local use requirements, would adversely affect ongoing development, construction and the continuing operation of our facilities. Additionally, even when we maintain the necessary licenses and are in compliance with applicable regulations, we may be unable to maintain or expand our operations at existing facilities, or otherwise execute on our growth strategy, due to negative publicity or resistance from non-governmental organizations or local communities. Suspensions and closures of our facilities could materially impact our business, financial condition and results of operations. Any new facilities that are constructed and begin operations may not meet our return expectations due to schedule delays, cost overruns or revenue shortfalls, or they may not generate the capacity that we anticipate or result in the receipt of revenue in the originally anticipated time period, or at all. For example, we have experienced, and may continue to experience in the future, laboratory equipment shortages as a result of global supply chain disruptions. We may not maintain revenue growth or profitability, or such growth, if any, could be delayed if we are not successful in continuing to expand our capacity. Additionally, if future demand trends warrant capacity in geographic areas that we have not targeted for new growth, we may be unable to capitalize on opportunities in a timely manner.
Our failure to meet contractual schedule requirements, meet a required performance standard, meet our internal contractual performance projections or otherwise perform adequately on a project could adversely affect our business, financial condition and results of operations.
Under some of our agreements, we can incur liquidated or other damages if we do not achieve project completion by a scheduled date. In addition, our costs generally increase from schedule delays and could exceed our projections for a particular project. Project performance can be affected by a number of factors beyond our control, including unavoidable delays from governmental inaction, inability to obtain financing, weather conditions, unavailability of materials or site inaccessibility, changes in the project scope of services requested by our customers, industrial accidents, environmental hazards, labor disruptions and other factors. Any defects or errors, or failures to meet our customers’ expectations, in our projects or services could result in claims for damages against us and could adversely affect our reputation. Material performance problems for existing and future agreements could cause actual results of operations to differ from anticipated results of operations and could cause us to suffer damage to our reputation within our industries and among our customers.
For certain of our services, we face a long selling cycle to secure new agreements, and securing such agreements often requires significant resource commitments, which result in long lead times before we receive revenues from new relationships.
For the majority of our services, our selling cycle is managed by our sales teams and represents the time from initial contact to signed agreement. This type of sale is usually completed between one week and two months in most service areas. However, in some of our service areas, our selling cycle can also involve becoming an approved supplier for third-party services. Doing so is a business development process that can take between six months and one year, depending on the service, resulting in what we consider a long selling cycle. We occasionally incur significant business development expenses, and expend significant resources, during a longer selling cycle, and we may not succeed in winning a new customer’s business, in which case we receive no revenue and may receive no reimbursement for such expenses. Even if we succeed in developing a relationship with a potential new customer, we may not be successful in obtaining contractual commitments after the selling cycle or in maintaining contractual commitments after the implementation cycle, which may have an adverse effect on our business, financial condition and results of operations.
24
The growth of our business may be adversely affected if we do not implement our growth strategies and initiatives successfully or if we are unable to manage our growth or operations effectively.
We have expanded, and are continuing to expand, our operations, suite of services and customer relationships, which has placed, and will continue to place, significant demands on our management and our operational, IT and financial infrastructures. Additionally, our ability to grow in the future will depend on a number of factors, including our ability to develop and expand new and existing customer relationships, continue providing and expanding the services we offer, hire and train qualified personnel, grow in existing markets and expand into new or future markets, develop and operationalize new service offerings and sustain operational excellence and efficiencies across our business lines. Achieving and sustaining growth requires the successful execution of our growth strategies, which may require the implementation of enhancements to customer-facing, operational and financial systems, expanded sales and marketing capacity, continuous updates to technology and improvements to processes and systems and additional or new organizational resources. Given these challenges, we may be unable to manage our expanding operations effectively, or to maintain our growth, which could have a material adverse effect on our business, financial condition and results of operations.
Part of our growth strategy is to pursue strategic transactions, including acquisitions, and we may not be able to find suitable acquisition targets or achieve our desired acquisition objectives.
As part of our strategy, we have in the past and plan in the future to seek to grow our business through acquisitions, and any such acquisitions may be significant. Any future growth through acquisitions will depend in part upon the continued availability of suitable acquisition candidates at favorable prices and upon advantageous terms and conditions, which may not be available to us, as well as sufficient funds from our cash on hand, cash flow from operations, existing debt facilities and additional indebtedness to fund these acquisitions.
Not only is the identification of such suitable acquisition candidates difficult and competitive, but these transactions, including the acquisitions completed in recent years, also involve numerous risks, including the diversion of management’s attention and their ability to:
•successfully integrate acquired facilities, companies, products, systems or personnel into our existing business;
•minimize any potential interruption to our ongoing business;
•successfully enter categories and markets in which we may have limited or no prior experience;
•achieve expected synergies and obtain the desired financial or strategic benefits;
•detect and address any financial or control deficiencies of the acquired company;
•retain key relationships with founders, management and other employees, contractors, customers, partners, accreditors and suppliers of acquired companies, as well as our own management, employees, contractors, customers, partners and suppliers; and
•maintain uniform compliance standards, controls, procedures and policies throughout acquired companies.
Companies, businesses or operations acquired or joint ventures created may not be profitable or may not achieve revenue and profitability levels that justify the investments made. Recent and future acquisitions could also result in the incurrence of indebtedness, subject to the restrictions contained in the documents governing our then-existing indebtedness.
Recent and future acquisitions could also result in the assumption of contingent liabilities, litigation risk, unfavorable commercial contract or lease terms, material expenses related to certain intangible assets, environmental liabilities, increased operating expenses and compliance issues under international laws and regulations, including antitrust laws, sanctions laws, labor laws, anti-corruption laws, the FCPA and similar anti-bribery laws, which could adversely affect our business, financial condition and results of operations. In addition, to the extent that the economic benefits associated with any of our acquisitions diminish in the future, we may be required to record additional write-downs of goodwill, intangible assets or other assets associated with such acquisitions, which could adversely affect our business, financial condition and results of operations. Our ability to realize the benefits we anticipate from our strategic transactions, including acquisition activities, anticipated cost savings and additional sales opportunities, will largely depend upon whether we are able to integrate such businesses efficiently and effectively. If we are unable to successfully integrate the operations of acquired businesses into our business or on the timeline we expect, we may be unable to realize the sales growth, cost synergies and other anticipated
25
benefits we expect to achieve as a result of such transactions and our business, financial condition and results of operations could be adversely affected.
Pursuant to our Amended Charter and the Stockholder Agreement, until UL Standards & Engagement no longer beneficially owns at least 25% of the voting power of our then-outstanding voting stock, neither we nor any of our subsidiaries is permitted to, without the prior written consent of UL Standards & Engagement, among other things, (1) enter into any new material line of business, excluding TIC and S&A activities, (2) merge or consolidate with or into another entity, other than in connection with an internal restructuring or reorganization or any strategic transaction we undertake in the course of our business that does not exceed 15% of our equity market capitalization, in each case except where there is no change to the relative ownership or voting percentages of our stockholders or any other rights, (3) acquire stock or assets or enter into joint ventures involving consideration or obligations exceeding 15% of our equity market capitalization, (4) issue securities (i) at a price below fair market value, other than an underwritten public offering for cash, (ii) with rights that are senior to the rights of the holders of our Class B common stock, (iii) that would result in dilution of greater than 10% of our then-outstanding common stock, or (iv) that would result in UL Standards & Engagement beneficially owning less than a majority of our then-outstanding securities, or (5) incur indebtedness for borrowed money that would cause a downgrade of our debt securities from any of Moody’s Investor Service, Inc., Standard & Poor’s Ratings Group and Fitch Ratings, Inc. (collectively, the “Rating Agencies”) below investment grade.
Our Amended Charter and the Stockholder Agreement grant certain consent rights to UL Standards & Engagement, which, among other things, may affect our ability to pursue strategic transactions, subject to certain exceptions and ownership requirements. We cannot guarantee that UL Standards & Engagement will exercise its consent rights in a way that aligns with the interests of our other stockholders. UL Standards & Engagement’s interests may not be the same as, or may conflict with, the interests of our other stockholders. Actions that UL Standards & Engagement takes with respect to us, as a controlling or significant stockholder, may not be favorable to us or our other stockholders. For example, if UL Standards & Engagement exercises its consent rights in a way that prevents us from taking advantage of business or strategic opportunities, our business, financial condition and results of operations may be adversely impacted.
We operate across a number of industries that have inherent safety risks.
We provide TIC services to companies across a number of industries with a variety of inherent safety risks, such as the energy and utilities, buildings and construction, chemicals and materials and healthcare and life sciences industries. Such safety risks can give rise to serious and potentially catastrophic environmental or technological incidents. Our customers use our TIC services to assess their products, facilities, processes, components and systems. The results of such services may be incorrect or incomplete, whether as a result of poorly designed or flawed tests or inspections, malfunctioning testing equipment, the failure of our employees to adequately perform testing or properly record data or otherwise. If an accident or incident occurs involving products, facilities, processes, components or systems that we tested, inspected or certified, and causes personal injuries or property damage, particularly if the injuries or damage could have been prevented by correct or complete results, we may be subject to negligence or other legal claims or suffer damage to our reputation and, as a result, lose existing or future agreements with customers. In addition, any investigation into or claim related to such an incident could take a significant period of time to conclude, which could create a drain on our resources. Furthermore, we operate in industries that have stringent performance requirements. Incorrect or incomplete assessments of the performance of customers in those industries could give rise to negligence or other legal claims or cause damage to our reputation and, as a result, we could lose existing or future agreements with those customers. Even if our TIC services are carried out competently, we may face claims simply because we tested the product, facility, process, component or system in question.
The current liability regime in the United States and other markets generally minimizes our exposure to product liability claims because, among other factors, we are typically not considered to be directly in the stream of commerce of the products we test. We have also historically been able to contractually limit our liability, including through the use of indemnification provisions in our agreements with customers. If the law regarding products liability were to change unfavorably or if we were unable to contractually limit the scope of our potential liability, our business, financial condition and results of operations could be materially adversely affected.
Although we attempt to contractually limit our liability and make clear the limited scope of our engagements, there can be no assurance that we will be able to protect ourselves against claims or damage to our reputation resulting from an accident, disaster or other incident or litigation giving rise to substantial media coverage, particularly if any such publicity suggests substantial failures, real or alleged, by us in discharging our responsibilities. Serious damage to our reputation could result in us losing existing and future agreements or make it more difficult for us to compete effectively. Any of the foregoing events could significantly damage our reputation or otherwise have a material adverse effect on our business, financial condition and results of operations.
26
Our reports, certificates, certification marks and name are at risk of being falsified, counterfeited, forged, tampered with or otherwise misused, which could result in costly legal proceedings and damage to our brand and reputation and materially impact our business.
Our core business involves the assessment of products, facilities, processes, components and systems against various legal, regulatory and industry requirements—typically standards and regulations governing quality, safety, performance, sustainability and social responsibility. We act as an independent body and issue reports, certificates and a right to use certification marks generally representing that products, facilities, processes, components and systems conform to applicable requirements.
Because obtaining certification is often vital for our customers and can enhance the marketability of their products, we are exposed to the risk that our reports or certifications could be falsified or tampered with, or that counterfeit reports, certifications or certification marks could be used, infringing our trademarks or copyrights. For example, a customer or other third party could falsely claim that their products or services have been certified by us or misrepresent or misconvey the content or nature of our reports, certifications or other assessments. The production of forged or counterfeit reports, certificates or certification marks can result from employee conduct or, more commonly, external sources, such as fraudulent behavior by a customer or third party aiming to meet regulatory requirements or the requirements of their customers or to gain market access. We endeavor to contractually restrict customers from using our reports, certificates, certification marks and name, but we are not always successful, including as a result of breaches of contract by those customers.
The fraudulent creation or use of our reports, certifications, certification marks or name could lead to the introduction of dangerous products into the marketplace, result in civil and criminal legal proceedings against us or brought by us, threaten our ability to maintain or renew the accreditations, approvals, permits, delegations of authority, official recognition and other authorizations we need to pursue certain activities that are important to our business, result in the withdrawal of certain products from the market or damage our reputation and the TIC industry in general. It could also adversely and significantly impact our reputation, brand, business, financial condition and results of operations.
Our earnings and profitability may vary based on the mix of our agreements and may be adversely affected by our failure to accurately estimate and manage costs, time and resources.
We generate revenue under various types of agreements, which include time-and-materials and fixed-price agreements. We use time-and-materials agreements for certain of our advisory services. While charges under a fixed-price agreement are based on a fixed price, charges under a time-and-materials agreement are calculated by multiplying an agreed hourly rate by the number of hours incurred, and customers are typically invoiced on a monthly basis. For time-and-materials agreements, there is usually an estimated number of hours or a budget, and the term of the agreement is typically as long as it takes to complete a particular project or set of tasks, although it can also be open-ended if the agreement is a straight hourly agreement. In some cases, we may also charge customers on what we refer to as a cost-plus basis—using a reasonable mark-up, as determined by us, on expenses we incur in providing our services.
Our earnings and profitability may vary materially depending on changes in the proportionate amount of revenues derived from each type of agreement, the percentage of completion, the nature of services or solutions provided, as well as the achievement of performance objectives and the stage of performance at which the right to receive fees, particularly under incentive fee agreements, is finally determined. To varying degrees, each of our agreement types involves some risk that we could underestimate the costs and resources necessary to fulfill the agreement. Our profitability is adversely affected when we incur costs on cost-plus and time-and-materials agreements that we cannot bill to our customers. While fixed-price agreements allow us to benefit from cost savings, these agreements also increase our exposure to the risk of cost overruns.
Revenue derived from fixed-price agreements represented the majority of our total revenue for the year ended December 31, 2025. When making proposals on fixed-price agreements, we rely heavily on our estimates of costs, scope and timing for completing the associated projects, as well as assumptions regarding technical issues. In each case, our failure to accurately estimate costs, scope or the resources and technology needed to perform our agreements or to effectively manage and control our costs during the performance of work could result, and in some instances has resulted, in reduced profits or in losses. More generally, any increased or unexpected costs or unanticipated delays in connection with the performance of our agreements, including costs and delays caused by contractual disputes or other factors outside of our control, such as performance failures of our subcontractors, natural disasters or other force majeure events, could make our agreements less profitable than expected or unprofitable.
27
Our focus on new growth areas for our business entails risks, including those associated with new relationships, customers, talent needs, capabilities and services.
We are focused on growing our presence in our addressable markets by offering TIC services and S&A solutions to both established and emerging industry verticals to which we do not offer services currently, extending into opportunity-rich adjacent markets and acquiring and integrating transformative, disruptive technologies. These efforts entail inherent risks associated with innovation, potential failure to help our customers respond to the challenges they face, shortages of necessary talent and our ability to comply with uncertain evolving legal standards. Some of our targeted growth areas in established and emerging industry verticals and adjacent markets subject us to new risks that we may not be equipped to address. As we attempt to develop new capabilities and service offerings in new markets, and to attract new customers, these efforts could harm our results of operations due to, among other things, a diversion of our focus and resources and actual costs, opportunity costs of pursuing these opportunities in lieu of others and a failure to reach a profitable return on our investments in new technologies, capabilities and businesses, including expenses on research and development investments. If we fail to develop new capabilities, our ability to procure new agreements could be negatively impacted, which would negatively impact our business, financial condition and results of operations.
Although we closely monitor the quality of our services, attempt to contractually limit our liability and make clear the limited scope of our engagements, carefully review technical and operational decisions and maximize communication between our engineers and global leadership, there can be no assurance that we will be able to protect ourselves against claims or damage to our reputation resulting from an accident, disaster or other incident or litigation giving rise to substantial media coverage, particularly if any such publicity suggests substantial failures, real or alleged, by us in discharging our responsibilities. Serious damage to our reputation could result in us losing existing and future agreements or make it more difficult for us to compete effectively, any of which would have a negative impact on our business, financial condition and results of operations. Any of the foregoing events could significantly damage our reputation or otherwise have a material adverse effect on our business, financial condition and results of operations.
Our operations are subject to a variety of business continuity hazards and risks—for example, man-made disasters, climate change, weather and climate-related events, contagious diseases, terrorist activity or our reliance on the use of materials and services from a few locations or suppliers—any of which could interrupt our business operations or otherwise adversely affect our financial condition and results of operations.
Our operations, and the operations of our vendors and service providers, are subject to business continuity hazards and risks that include explosions, fires, earthquakes, inclement weather and other natural disasters, utility or other mechanical failures, labor difficulties or other workforce disruptions, disruption of our communications, terrorist attacks, political unrest, security breaches, and pandemics, epidemics or other public health crises.
The global outbreak of any new pandemic or contagious disease may in the future have negative impacts on our business, including, but not limited to, reductions in our laboratory capacities and increased costs and protective measures with respect to the health and safety of employees working in our laboratories, a decline in customer demand, delays in the delivery of certain products and equipment we use internally and of customer samples to our laboratories, as a result of global supply chain disruptions, excess turnover among our employees and postponed or canceled planned investments in response to changes in our business. Extreme weather conditions may also disrupt the productivity of our facilities, the operation of our supply chain or impact demand for our services. Climate change may also contribute to various chronic changes in the physical environment, such as sea-level rise or changes in ambient temperature or precipitation patterns, which may also adversely impact our operations or those of our customers or suppliers. While we may take various actions to mitigate our business risks associated with climate change, this may require us to incur substantial costs and may not be successful due to, among other things, the uncertainty associated with the longer-term projections associated with managing climate risk.
The circumstances listed above have also had and may in the future have adverse effects on our customers and our suppliers. For example, the sale of labels bearing the UL Mark is material to our certification business, and we currently fulfill label orders submitted to us through one supplier in the United States. Although we have identified alternate third parties to provide this service, we cannot guarantee we would be able to contract with any such alternate third parties within a reasonable amount of time or at all, or upon similar pricing and volume terms, nor can we be assured that any such third party would be capable of producing our labels in sufficient volume and quality. Any event, including those listed above, other circumstances that result in a prolonged business disruption or shutdown to one or more of their facilities, or the facilities of our other vendors and service providers, or a deterioration in our relationship with them, or any of our other vendors or service providers, in each case, could create conditions that prevent, or significantly and adversely affect, our sales, increase our expenses, create potential liabilities or damage our reputation, any of which could have an adverse effect on our business, financial condition and results of operations.
28
Risks Related to Conducting Business in China
Changes in U.S. and Chinese regulations could have a material adverse effect on our business, financial condition, results of operations and our ability to raise capital.
The U.S. government has taken certain actions that impact companies with connections to the United States or China, including imposing several rounds of tariffs affecting certain products manufactured in China and imposing certain sanctions and restrictions in relation to certain Chinese companies, entities and individuals. Such actions may have an impact on our business operations. By way of example, subsequent to the August 2025 adoption by the United States Federal Communications Commission (“FCC”) of the Rule “Promoting the Integrity and Security of Telecommunication Certification Bodies, Measurement Facilities and the Equipment Authorization Program,” UL-CCIC withdrew as an FCC-recognized accredited testing laboratory under the FCC’s Equipment Authorization Program. Although this withdrawal did not have a material impact on our business, it is unknown whether and to what extent new legislation, executive orders, laws or regulations will be adopted, or the effect that any such actions would have on companies with significant connections to the United States or to China, our industry or on us, including on UL-CCIC. As we have business operations both in the United States and China, any unfavorable government policies on cross-border investments or other transactions or international trade, including increased scrutiny on U.S. companies with significant China-based operations, capital controls or tariffs, may affect our competitive position, our ability to participate in state-sponsored programs, our ability to raise capital, the hiring of personnel or the demand for our services or prevent us from offering our services in China or contracting with Chinese customers.
Further, ongoing tensions between the United States and China continue to pose a risk of either the United States or China imposing further economic or trade sanctions, expanding the scope of companies, entities and individuals which are subject to such sanctions, heightening export controls, or imposing regulations that restrict or otherwise interfere with the conduct of business in either the United States or China, which could restrict our ability to do business in the United States or China. For instance, with respect to the United States, the Bureau of Industry and Security of the U.S. Department of Commerce has added a number of Chinese parties to its Entity List and the Office of Foreign Asset Control of the U.S. Department of the Treasury has designated a number of Chinese parties to its Specially Designated Nationals list. Such restrictions would prevent us, including UL-CCIC, where applicable, from selling certain products or providing certain services to entities on the list without a license issued subject to the Export Administration Regulations, or from conducting any business with those entities. Further, if additional parties in China, including current customers and suppliers of our business, are added to the Entity List, or to other lists of restricted or prohibited persons maintained by the U.S. government, that could negatively affect our business, including the business of UL-CCIC.
Additionally, in 2021 China enacted the Law on Countering Foreign Sanctions, under which foreign persons (individuals and companies), as well as certain affiliated organizations and responsible personnel, can be subjected to countermeasures for directly or indirectly participating in a foreign country’s “discriminatory restrictive measures” against Chinese entities, which could include adherence to U.S. or other foreign sanctions or, in some circumstances, export or other trade controls. Countermeasures authorized under the law include the seizure of property, barring transactions with individuals within the territory of China or entities incorporated under Chinese laws, denial of visas, deportation, and any other necessary measures. This law expands on and supplements the Ministry of Commerce of the People’s Republic of China’s (“MOFCOM”) September 2020 Provisions of the Unreliable Entity List (“UEL”) and January 2021 Rules on Counteracting Unjustified Extra-territorial Application of Foreign Legislation, which created a private right of action under which Chinese entities can sue for damages they allege resulted from a company adhering to “discriminatory foreign measures.”Similar to U.S. additions to the Entity List, if the MOFCOM added UL-CCIC customers to its UEL or other Chinese sanctions lists, that could affect those customers’ abilities to import key components or export end product to other markets.
If any new legislation, executive orders, tariffs, sanctions, export controls, laws or regulations are implemented, if existing trade agreements are renegotiated or if the U.S. or Chinese governments take further retaliatory actions in response to the recent bilateral tensions, such changes could have a material adverse effect on our business, financial condition and results of operations, and the market price of our Class A common stock.
Our business is subject to complex and rapidly evolving laws and regulations in China. The Chinese government may exercise significant oversight and discretion over the conduct of our, including UL-CCIC’s, business there and may intervene in or influence our operations, which could result in a material adverse change in our, including UL-CCIC’s, operations.
As a U.S.-headquartered global company that conducts significant business in China, our Chinese operations are subject to China’s laws and regulations, which can be complex and evolve rapidly and with little or no notice to us. These laws and
29
regulations may be interpreted, applied or enforced with uncertainty and inconsistently by different agencies or authorities, or inconsistently with our current policies and practices. New and evolving laws, regulations and other government directives in China may also be costly to comply with. Such compliance, any associated inquiries or investigations or any other government actions or the inconsistent interpretation, application or enforcement of laws or regulations could impact our China operations in the following ways:
•delay or impede our development;
•result in negative publicity, decrease demand for our services or increase our operating costs;
•require significant management time and attention;
•require us to obtain additional licenses, permits, approvals or certificates;
•require us to exit certain industries or stop conducting business with certain customers; or
•subject us to remedies, administrative penalties and even criminal liabilities, including fines assessed for our current or historical operations, or demands or orders that we refrain from contracting with customers in China or modify or even cease our business practices in China.
Because Chinese administrative and court authorities have significant discretion in interpreting and implementing statutory provisions and contractual terms, it may be difficult to evaluate the outcome of administrative and court proceedings and the level of legal protection we may obtain. These uncertainties may affect our judgment on the relevance of legal requirements in China and our ability to enforce our contractual rights or tort claims there. In addition, third parties might exploit regulatory uncertainties through unmerited or frivolous legal actions or threats to extract payments or benefits from us.
Furthermore, the Chinese legal system is based in part on government policies and internal rules, some of which are not published on a timely basis or at all and may have a retroactive effect. As such, we may not be aware of our violation of any of these policies and rules until after such violation occurs. In addition, administrative and court proceedings in China in which we may become involved in the future may be protracted, resulting in substantial costs and diversion of resources and requiring significant management time.
Regulatory developments in China may also lead to additional regulatory review in China over our activities there. For example, in recent years, the Chinese government has published new policies that significantly affect certain industries, such as the education and internet industries, and we cannot rule out the possibility that the Chinese government will release new or revised regulations or policies concerning or impacting our industry. Any such new or revised regulations or policies could limit our service offerings, restrict the scope of our operations in China, require us to seek permission from Chinese authorities to continue to operate our businesses or cause the suspension or termination of our business in China entirely, all of which would materially adversely affect our business, financial condition and results of operations. We may have to adjust, modify or completely change our business operations in response to adverse regulatory changes or policy developments, and we cannot guarantee that any remedial action adopted by us can be completed in a timely, cost-efficient or liability-free manner, or at all.
Furthermore, the Chinese government has exercised and continues to exercise substantial control over the Chinese economy through regulation and state ownership and has the power to exercise significant oversight and discretion over the conduct of our business in China. This risk is heightened with respect to UL-CCIC because UL-CCIC is minority owned by CCIC, a Chinese state-owned enterprise, and, while we maintain the controlling interest in UL-CCIC, UL-CCIC’s ability to operate in China may be materially and adversely affected by the Chinese government’s significant oversight and discretion over the conduct of UL-CCIC’s business. Government actions in the future could significantly affect economic conditions in China and could require us, including UL-CCIC, to materially change our operating activities in China or other jurisdictions, or require us to divest ourselves of any interests we hold in Chinese assets. Our business may be subject to government and regulatory interference in the provinces in which we operate, and we may incur increased costs necessary to comply with existing and newly adopted laws and regulations or penalties for failure to comply.
30
If our relationship with CCIC were to be negatively impacted, if we are unable to renew our joint venture with CCIC in the future, or if the joint venture were to be terminated, our business, financial condition and results of operations would be materially adversely affected.
On October 28, 2022, we entered into an amended and restated joint venture agreement with CCIC pursuant to which we own a direct 70% equity interest in UL-CCIC. The amended and restated agreement expires in January 2033. If, in the future, we are unable to renew the agreement on existing or more favorable terms, or at all, or if the joint venture were to be terminated, our reputation, business, financial condition and results of operations would likely be materially adversely impacted, and we may be unable to find an alternative partner for our China-based business. We also have a separate contract with CCIC pursuant to which CCIC’s staff conducts on-going certification inspections for our TIC safety certification business in China. In 2025, CCIC was responsible for approximately 36% of our global on-going certification inspections. If we were to lose our contract with CCIC, or if CCIC were to stop providing inspection services for us in the future, our business would be impacted significantly, and any negative impacts on our relationship with CCIC, including UL-CCIC, would have a material adverse effect on our business, financial condition and results of operations. As a minority joint-venture partner, CCIC has certain protective rights, whether contractually or pursuant to applicable local laws and regulations, and may have economic or business interests or goals that are not consistent with ours, or may, as a result of financial or other difficulties, be unable or unwilling to fulfill their obligations as a minority joint-venture partner.
Furthermore, we may be exposed to certain commercial and reputational risks as a result of CCIC being a state-owned enterprise and thus controlled by the Chinese government. For example, CCIC may make politically motivated business decisions that do not align with our commercial interests. In addition, CCIC could conduct business with other companies, organizations or institutions that attract unfavorable political attention in the United States, which could harm our reputation. Any such actions could negatively impact our relationship with CCIC, which would materially and adversely affect our business, financial condition and results of operations.
If the government of China determines that UL-CCIC’s ownership structure, or the ownership structure of our other Chinese subsidiaries, does not comply with any current or future regulatory restrictions, we, including UL-CCIC, could be subject to severe penalties, or we could be forced to relinquish our interests in UL-CCIC’s or our other Chinese subsidiaries’ operations.
The industry sector in which we operate in China is currently not subject to foreign ownership restrictions, and hence we, through our wholly owned subsidiary, UL LLC, are able to hold a direct equity interest in UL-CCIC. However, it is possible that Chinese foreign ownership rules applicable to our sector may change in the future, which could adversely impact our ownership of UL-CCIC or of our other Chinese subsidiaries, and, as a result, have a material adverse effect on our business in China. For example, we may have to reduce our interest in UL-CCIC if tighter ownership limits are imposed, or divest our stake in UL-CCIC altogether should the sector become prohibited from foreign investment.
Our joint venture agreement with CCIC has not been tested in a court of law. If disputes with CCIC arise, or the ownership structure, joint venture terms or business of UL-CCIC are challenged and found to be unenforceable or in violation of any existing or future Chinese laws or regulations, we may not be able to enforce our rights under the joint venture agreement. Furthermore, if the interpretation of any such Chinese laws or regulations changes, our rights under the joint venture agreement may be similarly unenforceable. If a violation of relevant laws or regulations is found, the relevant regulatory authorities would have broad discretion to take action in dealing with such violations by, among other things:
•revoking our, including UL-CCIC’s, business or operating licenses;
•shutting down our, including UL-CCIC’s, servers, blocking our, including UL-CCIC’s, website or discontinuing or placing restrictions or onerous conditions on our operation through any transactions involving UL-CCIC or any of our other Chinese subsidiaries;
•imposing fines, confiscating the income of UL-CCIC or any of our other Chinese subsidiaries, blocking the offshore remittance of the profits and earnings of UL-CCIC or of any of our other Chinese subsidiaries or imposing other requirements with which we, including UL-CCIC, may not be able to comply;
•requiring us to restructure UL-CCIC’s ownership or governance structure or operations, which in turn could materially affect our ability to consolidate, derive economic interests from or exert control over UL-CCIC or our other Chinese subsidiaries; or
31
•restricting or prohibiting our use of the proceeds of any financing outside of China to finance our business and operations in China, and taking other regulatory or enforcement actions that could be harmful to our, including UL-CCIC’s, business.
If Chinese authorities were to take any of these actions, or if they were to disallow the ownership structure of UL-CCIC or any of our other Chinese subsidiaries, it could cause a material disruption to, or material adverse change in, our business operations, including the business operations of UL-CCIC, and severely damage our reputation in China, which could in turn have a material adverse effect on our business, financial condition and results of operations.
Changes in the economic policies of the government of China could have a significant impact upon the business we may be able to conduct in China and our profitability.
We have historically derived a significant portion of our revenues from our operations in China, and expect to do so in the future. Accordingly, our business, financial condition and results of operations may be influenced to a significant degree by economic, political, legal and social conditions in China. In recent years, the Chinese government has implemented measures emphasizing market forces for economic reform, the reduction of state ownership of productive assets and the establishment of sound corporate governance in business enterprises. However, a significant portion of productive assets in China are still owned by the Chinese government. The Chinese government continues to play a significant role in regulating industrial development. It also exercises significant control over China’s economic growth through the allocation of resources, controlling payment of foreign currency-denominated obligations, setting monetary policies, restricting the inflow and outflow of foreign capital and providing preferential treatment to particular industries or companies.
China’s economy differs from the economies of developed countries in many respects, including with respect to the amount of government involvement, level of development, growth rate, control of foreign exchange and allocation of resources. Although China’s economy has experienced significant growth over the past four decades, growth has been uneven across different regions and among various economic sectors. The Chinese government has implemented various measures to encourage economic development and guide the allocation of resources. Some of these measures may benefit the overall Chinese economy, but may have a negative effect on us, including UL-CCIC. For example, our financial condition and results of operations may be adversely affected by government control over capital investments or changes in tax regulations that are currently applicable to us. In addition, in the past the Chinese government implemented certain measures, including interest rate increases, to control the pace of economic growth. These measures may cause decreased economic activity in China, which may adversely affect our business, financial condition and results of operations.
China’s economy is still not yet a fully market-oriented economy and is subject to five-year and annual plans adopted by the government that set national economic development goals. Policies of the Chinese government can have significant effects on the economic conditions within China.A change in policies by the Chinese government could adversely affect our interests through, among other factors, changes in laws, regulations or the interpretation thereof, restrictions on currency conversion, imports or sources of supplies and the expropriation or nationalization of private and foreign-owned enterprises. Although the Chinese government has been pursuing economic reform policies for decades, there is no assurance that the government will continue to pursue such policies or that such policies will not be significantly altered, especially in the event of social or political disruption, or other circumstances affecting China’s political, economic and social environment.
As the Chinese economy has become increasingly linked with the global economy, China is affected in various respects by downturns and recessions of major economies around the world. The various economic and policy measures enacted by the Chinese government to forestall economic downturns or bolster China’s economic growth could materially affect our business, financial condition and results of operations.
Compliance with China’s new laws, regulations and guidelines relating to data privacy and protection, and any other similar future laws and regulations, could materially affect our business.
China has implemented a number of laws and regulations relating to data protection, including China’s Personal Information Protection Law (the “PIPL”). The PIPL creates a comprehensive set of data privacy and protection requirements that apply to the processing of personal information. We, including UL-CCIC, are subject to the PIPL. The PIPL also includes a list of rules which must be complied with prior to the transfer of personal information outside of China, such as compliance with a security assessment or certification by an agency designated by the relevant authorities or entering into standard form model contracts approved by the CAC with the overseas recipient, unless an exemption under the CAC’s Provisions for Promoting and Regulating Cross-Border Data Flows applies, such as the transfer being necessary for the performance of a contract which the individual is a party to or necessary for cross-border human resources management or the number of individuals whose personal information is transferred is less than 100,000 since January 1st of the current year. Notably, the PIPL applies
32
extraterritorially, similar to the GDPR. Failure to comply with the PIPL can result in fines of up to RMB 50 million or 5% of the prior year’s total annual revenue. Other potential penalties include a fine of up to RMB one million to the person(s) in charge (e.g., directors or management that oversee a company’s operations) or employees that are directly responsible for the processing of personal information (e.g., a data protection officer) and, in serious cases, individuals and entities may be exposed to criminal liabilities under other local Chinese law, such as the Criminal Law of China. The PIPL also prohibits responsible personnel for violations of the PIPL from holding high level management or data protection officer positions in relevant enterprises.
Under China’s Cybersecurity Law, any collection, use, transfer and storage of personal information of a Chinese citizen through a network by the network operator should be based on the three principles of legitimacy, justification and necessity and requires the consent of the data subject. In addition, China’s Cybersecurity Law requires operators of critical information and infrastructure (“CIIOs”) to store personal information and important data collected and generated from the critical information infrastructure within China and export outside of China is prohibited unless a security assessment is passed or an exemption can be relied on. Non-compliance with China’s Cybersecurity Law can result in fines of up to RMB 10 million for violations that cause particularly serious consequences and RMB 1 million for the violator’s directly responsible personnel and potentially five times the illegal gains where the illegal gains exceed RMB 100,000.
Where China’s Cybersecurity Law imposes network security obligations, China’s Data Security Law, which applies extra-territorially, regulates data activities and imposes data security and classification obligations, as well as specific obligations on data processors that process important data and on CIIOs. For example, the Data Security Law requires important data to be stored locally in China, unless a security assessment is passed.
We, including UL-CCIC, may need to make adjustments to our data processing practices if we are deemed to process important data or a CIIO. Penalties for breach under the Data Security Law can result in monetary fines of up to RMB one million for entities, with additional fines for responsible individuals. An entity whose violations result in “serious consequences” may face fines of up to RMB 10 million and the potential suspension of the business and revocation of its business license. Furthermore, if a violation amounts to a crime under Chinese law, the offender will be held criminally liable for committing the crime.
Government agencies in China promulgated several regulations and released a number of draft regulations for public comment, which are designed to provide further implemental guidance in accordance with the laws mentioned above. We cannot predict what impact these laws and regulations or the increased costs of compliance, if any, will have on our operations in China.
The interpretation, application and enforcement of these laws, rules and regulations evolve from time to time and their scope may continually change, through new legislation, amendments to existing legislation and changes in enforcement. Compliance could increase the cost to us of providing our service offerings, require significant changes to our operations or even prevent us from providing certain service offerings in jurisdictions in which we currently operate or in which we may operate in the future. Despite our efforts to comply with applicable laws, regulations and other obligations relating to privacy, data protection and information security, it is possible that our practices or offerings could fail to meet all of the requirements imposed on us by such laws and related implementing regulations. Any failure on our part to comply with such laws or regulations or any other obligations relating to privacy, data protection or information security, or any compromise of security that results in unauthorized access, use or release of personally identifiable information or other data, or the perception or allegation that any of the foregoing types of failure or compromise has occurred, could damage our reputation, discourage new and existing counterparties from contracting with us or result in investigations, fines, suspension or other penalties by Chinese government authorities and private claims or litigation, any of which could materially adversely affect our business, financial condition and results of operations.
Foreign exchange restrictions may limit our ability to transfer cash between us and UL-CCIC or our other Chinese subsidiaries, across borders and to U.S. investors and affect the value of our stock.
UL-CCIC and our other Chinese subsidiaries are subject to certain regulatory controls on foreign exchange in China, including the convertibility of the renminbi into foreign currencies and the remittance of currency in and out of China, which may affect our ability to transfer cash between us and such entities and across borders (including to U.S. investors).
With respect to UL-CCIC, it has been our practice to periodically distribute UL-CCIC earnings via dividend to us and CCIC in proportion to our respective contributions to UL-CCIC’s registered capital. Such dividends to us are declared in renminbi and in our case settled in U.S. dollars. In the years ended December 31, 2025, 2024 and 2023, the dividends distributed from UL-CCIC to us, before withholding taxes, were $39 million, $34 million, and $32 million, respectively. In addition, we and
33
UL-CCIC have various normal course business interactions and exchange cash flows based on the agreements in place between us. These agreements generate payments to us in the form of payments for management fees relating to corporate support services, royalties and service fulfillment fees. Agreements between UL-CCIC and CCIC also generate payments from UL-CCIC to CCIC. The size and rate of any future distributions of UL-CCIC’s earnings will depend on the continued performance of UL-CCIC’s business.
Under Chinese foreign exchange regulations, cash generated from UL-CCIC may not be used to pay dividends without State Administration for Foreign Exchange (“SAFE”) approval. We must also obtain SAFE approval to use cash generated from our China-based operations, including UL-CCIC, to pay debts in a currency other than renminbi owed to entities outside China, or to make capital expenditure payments outside China in a currency other than renminbi. These restrictions may in the future limit or prevent us from distributing earnings from UL-CCIC or our other Chinese subsidiaries to us and ultimately to our investors in the United States.
Similarly, our ability to transfer funds from outside of China to UL-CCIC or our other Chinese subsidiaries is subject to foreign exchange controls that may require the approval of, or registration with, Chinese government authorities, including SAFE. For example, if we finance UL-CCIC using debt from us or lenders outside of China, the loan would be subject to statutory limits and would need to be registered with the local branch of SAFE. If we finance UL-CCIC using capital contributions, these capital contributions may require registration with other governmental authorities in China, including registration with the Chinese State Administration for Market Regulation and SAFE or their local branches and the reporting of foreign investment information with the MOFCOM or its local branch.
In light of Chinese regulations on dividends, loans, capital contributions and other transfers between China-based entities and parent companies outside of China, we may not meet the necessary government requirements or obtain the required government approvals on a timely basis, if at all. Failure to meet such requirements or obtain such approvals may negatively impact our ability to distribute earnings from UL-CCIC or any of our other Chinese subsidiaries to us and U.S. investors or to fund or settle amounts under our joint venture agreement with CCIC. Any of the foregoing risks could materially and adversely affect our business, financial condition and results of operations.
Risks Related to Information Technology and Our Software
We and our partners, service providers and other third parties that we interact with face cybersecurity risks and may fail to adequately secure or maintain the confidentiality, integrity or availability of the data held or detect any related threats, which could result in significant liability and reputational harm, and we may incur increasing costs in an effort to mitigate those risks.
Our business’ operations and reputation depend on its ability to maintain the confidentiality, integrity and availability of data and systems related to its customers, employees, suppliers, proprietary technologies, processes, and intellectual property. We and our business and commercial partners, and other third parties with which we interact rely extensively on third-party service providers’ IT systems, including cloud-based systems and on-premises servers (i.e., data centers), to record and process data and manage our operations, among other matters. Additionally, we collect, process, transmit and store data about our partners, customers, suppliers and others, including financial information and personal information, as well as other confidential or sensitive information.
We and our service providers and partners have experienced, and may in the future experience, failures of, or disruptions to, IT systems and data breaches, and attempted and successful cyber-attacks, such as ransomware attacks, and data breaches. For example, on February 13, 2021, we discovered that we were the target of a ransomware attack affecting certain IT systems and the data maintained on such systems. While we resolved the incident in a manner that restored the functions of our core and other IT systems and the integrity of the data maintained on them, as part of that resolution we relied on certain assurances (e.g., that recommended mitigation steps from the U.S. Department of Commerce’s National Institute of Standards and Technology and MITRE cybersecurity frameworks regarding passwords and threat detection are industry standard or best practice), some of which cannot be independently verified. We are unaware of any material notices, claims or enforcement actions in connection with our response to this incident, although they are possible.
The inadvertent disclosure of or unauthorized access to IT systems, networks and data, including personal information, confidential information or sensitive information, and actual data security breaches, cyber-attacks, or other security incidents have and could in the future result in or expose us to a risk of loss or misuse of personal, confidential or sensitive information, and significant costs to us, which may include, among others, fines and penalties, costs related to remediation, contractual claims from customers, potential costs and liabilities arising from governmental, regulatory or third-party investigations, proceedings or litigation and diversion of management attention, all of which could have a material adverse
34
effect on our reputation, business, financial condition and results of operations. In addition, undiscovered compromises or vulnerabilities in our IT systems or services have and could expose us to hackers or other unscrupulous third parties who develop and deploy viruses and other malicious software programs that have and could attack our services and businesses.
Actual or perceived data security vulnerabilities in our services could harm our reputation and lead customers and partners to reduce or delay future services or use competing services. Cyber-attacks on us or our third-party suppliers, vendors, service providers, or other business or commercial partners can vary in scope and intent from economically-driven attacks to malicious attacks targeting key operating systems with the intent to disrupt, disable or otherwise cripple operations and service offerings. This has and can include any combination of phishing attacks, malware, ransomware attacks, insider threats or viruses targeted at our key systems. Furthermore, mitigating the risk of future cyber-attacks, data breaches or IT systems failures has resulted, and could in the future result, in additional operating and capital costs in IT systems technology, personnel, monitoring, insurance coverage, lost sales, mitigation, remediation and other investments.
We have taken steps to protect the confidentiality, integrity and availability of our data, but we cannot guarantee that these steps will be effective. Successful cyber-attacks have and may continue to target us directly, or indirectly target or impact us through our third-party suppliers, vendors, service providers, or other business or commercial partners. Such data security breaches, cyber-attacks, and other security incidents could occur in the future either at their location or ours, or within their systems or our systems, and affect confidential, personal or sensitive information. The breadth and scope of this threat has grown over time, and the techniques and sophistication used to conduct cyber-attacks, including AI, as well as the sources and targets of the attacks, change frequently. Given the unpredictability of the timing, nature and scope of cyber-attacks and other security incidents, we cannot guarantee that the technologies we use will adequately secure the data we maintain, including confidential, personal or sensitive information, against such attacks, and we cannot entirely eliminate the risk of improper or unauthorized access to or disclosure of such data, cyber-attacks, or other security incidents that impact the confidentiality, integrity or availability of such data, or our systems and operations.
We may experience a compromise of our systems or data, either due to a failure to adequately protect our information technology systems and network infrastructure or otherwise, which could cause a material adverse effect on our business, financial condition and results of operations, such as damage to our brand and reputation, legal claims, increased cost of insurance and remediation costs.
We have experienced, and may in the future experience failures of, or disruptions to, IT systems leading to the accidental or unauthorized destruction, loss, alteration, disclosure of or access to data transmitted, stored or otherwise processed by us. Such failures could include misconfiguration of identity and access management controls, misconfiguration of firewalls, failure to update and patch software on a timely basis, falling victim to social engineering schemes (such as phishing or vishing) or negligent or intentional employee or contractor acts or omissions. We take measures designed to prevent the compromise of our systems and data, including looking to the National Institute of Standards and Technology (“NIST”) Framework to serve as a benchmark for our program and provide guidance, using an endpoint detection and response solution and adding immutability to our backups; however, we cannot ensure these measures will prevent any such compromise. Further, while we have developed a cybersecurity risk management program that is intended to protect the confidentiality, integrity and availability of our critical systems and information, there can be no assurance that such program, including our policies, controls or procedures, will be fully implemented, complied with or effective in protecting our systems and information. A compromise of our systems or data may lead to the inadvertent disclosure of or unauthorized access to IT systems, networks and data, including confidential, personal or sensitive information, and could also result in or expose us to a risk of loss or misuse of confidential, personal or sensitive information, and result in significant costs to us, which may include, among others, fines and penalties, costs related to remediation, contractual claims from customers, potential costs and liabilities arising from governmental, regulatory or third-party investigations, proceedings or litigation and diversion of management attention, all of which could have a material adverse effect on our reputation, business, financial condition and results of operations.
We may experience an incident leading to an outage of our IT systems or network infrastructure which may impact our operations, including our ability to deliver services to customers, which may result in damage to our brand and reputation, lost sales, legal claims, contractual obligations, and increased insurance costs.
Outages of our IT systems or network infrastructure, attempts to overload our servers with denial-of-service, ransomware attacks, cyber-attacks, computer viruses or malicious code, break-ins, social engineering attacks (such as phishing or vishing), unintentional incidents causing loss of data, or similar incidents or other IT failures, have and may in the future cause damage to our key systems or cause us to experience: (i) interruption or delays in our services, (ii) misappropriation of personal information regarding our employees, customers or partners, (iii) the inability to deliver services to customers or operate the services, and (iv) loss of critical data, all of which has and could interrupt our operations, adversely impact our reputation and
35
brand and expose us to increased risks of governmental and regulatory investigation and enforcement actions, private litigation and other liability, any of which could adversely affect our business, financial condition and results of operations.
The services we provide are often critical to our customers and partners’ businesses. Certain of our agreements require us to comply with certain data security obligations, which could include ongoing operation of our IT systems and network infrastructure without interruptions, maintaining network security and backup data, ensuring our network is virus-free and maintaining business continuity planning procedures. Any failure to meet such contractual obligations, whether or not a result of or related to the services we provide, or an incident leading to an outage of our IT systems or network infrastructure could damage our reputation or result in a claim for substantial damages against us. Our liability for such outages, breaches of data security requirements or similar incidents may require us to indemnify our customers or our partners, and could result in reputational damage or a loss of customers, partners and revenue.
We may experience a compromise of our systems or data or an incident leading to unauthorized access to, disclosure or loss of confidential, personal or sensitive information, which may result in damage to our brand and reputation, lost sales, legal claims, contractual obligations, and increased insurance costs and may impact our financial performance.
While we invest in systems and processes that are designed to detect and prevent compromises of our systems or data, including cyber-attacks and other security incidents, and we conduct periodic tests of our security systems and processes, we may not succeed in anticipating or adequately protecting against or preventing all such incidents from occurring, and we and our partners and third parties with whom we interact may still experience such incidents. Any such actual or perceived incidents have, and in the future could, expose us to additional regulatory scrutiny and result in a violation of applicable data privacy laws and other laws, litigation exposure, regulatory fines, penalties or intervention, loss of confidence, reputational damage, reimbursement or other compensatory costs, and additional compliance costs, and could adversely impact our business, financial condition and results of operations. Our existing general liability and cybersecurity insurance may not cover, or may cover only a portion of, any potential claims or expenses related to such incidents that affect us or may not be adequate to indemnify us for all or any portion of liabilities that may be imposed. In addition, such insurance may not be available to us on economically reasonable terms in the future. Any imposition of liability that is not covered by insurance or is in excess of insurance coverage would increase our operating expenses and reduce our net income, or increase our net loss.
Furthermore, our IT systems have been, and may in the future be, subject to ransomware attacks and similar incidents or disruptions. In addition to the other risks described above, as a result of such attacks, we could be subject to demands, claims, and litigation by private parties and investigations, related actions, and penalties by government authorities. Moreover, we have and could incur significant costs, including costs associated with paying the ransom, negotiating the ransom, notifying affected persons and entities and otherwise complying with a multitude of foreign, federal, state, and local laws and regulations. As such incidents continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any information security vulnerabilities or incidents.
Partial or total destruction of our databases, technology support or technology solutions would have a material adverse effect on our business, financial condition and results of operations.
We maintain databases containing information on many of our available tests, which represent an integral part of our technological advantage. To limit the risk of a partial or total destruction, the main databases are kept in clusters of high availability datacenters interconnected via high-speed communication lines. To further ensure availability, we systematically apply immutable off-site back-ups of the databases. However, if the databases were to be corrupted, damaged or destroyed, it could have an adverse effect on our business, financial position and results of operations.
If we fail to manage our SaaS hosting network infrastructure capacity, or if our infrastructure experiences a significant disruption, our existing customers may experience service outages and our new customers may experience delays in the deployment of our solutions, which could lead to litigation and have a material adverse effect on our reputation, business, financial condition and results of operations.
We have a high volume of users, transactions and data that our hosting infrastructure supports. We seek to maintain sufficient excess capacity in our SaaS hosting network infrastructure to meet the needs of all of our customers. We also seek to maintain excess capacity to facilitate the rapid provision of new customer deployments and the expansion of existing customer deployments. However, the provision of new hosting infrastructure requires significant lead time. If we do not accurately predict our infrastructure capacity requirements, our existing customers may experience service outages that may subject us to financial penalties, financial liabilities and customer losses. If our hosting infrastructure capacity fails to keep
36
pace with increased sales, customers may experience delays as we seek to obtain additional capacity, which could have a material adverse effect on our reputation, business, financial condition and results of operations.
Additionally, any disruption of or interference with our SaaS hosting network infrastructure, including the services and operations of the public cloud providers, could harm our reputation, business and results of operations. We have experienced, and may in the future experience, disruptions in our computing and communications infrastructure. Factors that may cause such disruptions that may harm our reputation include:
•human error;
•security breaches;
•telecommunications outages from third-party providers;
•computer viruses;
•acts of terrorism, sabotage, or other intentional acts of vandalism, including cyber-attacks;
•unforeseen interruption or damages experienced in moving hardware to a new location;
•fire, earthquake, flood, and other natural disasters; and
•power loss.
Although we maintain a comprehensive disaster recovery plan, store data in more than one geographically distinct location, and perform real-time mirroring of data to disaster recovery locations, we do not currently offer immediate access to disaster recovery locations in the event of a disaster or major outage. Thus, in the event of any factor causing disruption, including those described above, or certain other failures of our computing infrastructure, customers may not be able to access their data for 24 hours or more, and there is a remote chance that customer data from recent transactions may be permanently lost or otherwise compromised. In addition, we may not have adequate insurance coverage to compensate for losses from a major interruption. Moreover, some of our agreements include performance guarantees and service level standards that obligate us to provide credits, refunds or termination rights in the event of a significant disruption in our SaaS hosting network infrastructure or other technical problems that relate to the functionality or design of our solutions.
The legislative, judicial and regulatory landscapes relating to data collection, use and processing are challenging to comply with and are evolving and impact our ability to collect, use and process data, including personal information, and could limit our ability to operate and expand our business, cause revenue to decline and adversely affect our business. The actual or perceived failure to comply with data privacy laws and regulations could result in significant liability or reputational harm.
The domestic and international regulatory environment regarding data privacy and data security is increasingly evolving and demanding, including new and changing requirements, which could cause us to incur substantial costs. Failure of our services or solutions to adapt to changes in the regulatory environment in an efficient, cost-effective manner could have a material adverse effect on our business, financial condition and results of operations. In the United States, various laws and regulations apply to the collection, processing, disclosure and security of certain types of data, including the Federal Trade Commission Act, the Health Insurance Portability and Accountability Act (“HIPAA”) and state equivalents, and various state laws relating to data privacy and data security, including the California Consumer Privacy Act (the “CCPA”) and the California Privacy Rights Act (the “CPRA”) . As such, the U.S. Federal Trade Commission, U.S. Department of Health & Human Services, many state attorneys general and many courts interpret the various existing federal and state data privacy and consumer protection laws, and therefore enforce various standards for the collection, disclosure, processing, use, storage and security of data, including personal information. For example, HIPAA is a federal law protecting patient health information and creating standards for entities subject to HIPAA, either as a covered entity or a business associate, and the Controlling the Assault of Non-Solicited Pornography and Marketing Act (“CAN-SPAM Act”) is a federal law that imposes certain obligations on businesses that send commercial emails, such as a requirement to include in every commercial email an “unsubscribe link.” In addition, the CCPA created individual data privacy rights for California residents and places increased data privacy and security obligations on entities handling certain personal information of California-resident consumers and households. The CCPA, and other similar state comprehensive laws that have been passed since, require covered companies to provide disclosures to consumers of the relevant states about such companies’ data collection, use and disclosure practices,
37
provide such consumers with rights to access, correct and delete their personal information and to opt-out of certain processing of personal information.
In the United States, both Congress and state legislatures, along with federal regulatory authorities, have continued to increase their attention on the collection and use of data about individuals. Although data privacy legislation has been introduced in the U.S. Congress to address data privacy more generally, despite significant legislative activity, to date there has not been any significant successful effort at enacting any such legislation; nevertheless, in the event of any such legislation, it would create additional regulatory and compliance obligations, legal risk exposure, and could significantly impact our business, financial condition and results of operations. Other states in addition to California have also enacted comprehensive consumer data privacy laws that create rights and impose corresponding obligations on covered companies relating to the access to, deletion of and disclosure of personal information collected by covered businesses about residents of the respective states. Currently, over a dozen states have enacted consumer privacy laws that are in effect. Similar other laws have been proposed in other states and at the federal level, and if passed, we could be subject to such laws regardless of whether we have operations or a physical presence in the applicable state. Although these new laws largely focus on consumers (other than the CCPA), these new and potential laws reflect a trend toward more stringent data privacy legislation in the United States, and we anticipate that similar laws will continue to be proposed at both the state and federal level. These new laws may impose obligations similar to or more stringent than those we are subject to under other data protection laws. Further, any such laws may also have potentially conflicting requirements that would make compliance challenging, as well as potentially resulting in further uncertainty and requiring us to incur additional costs and expenses in an effort to comply.
In the European Economic Area (the “EEA”) we are subject to the GDPR and any additional requirements in the national implementing laws of countries in the EEA, and in the UK, we are subject to the UK data protection regime consisting primarily of the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018, in each case in relation to our access, collection, control, processing, sharing, disclosure and other use of data relating to an identifiable living individual, or personal information. The GDPR and UK GDPR both apply extra-territorially and impose a strict data protection compliance regime with onerous requirements on controllers and processors of personal information. Where we act as a controller, these include, for example: (i) accountability and transparency requirements (detailed disclosures about how personal information is collected and processed), and enhanced requirements for obtaining valid consent (or demonstrating that another appropriate legal basis is in place or otherwise exists to justify data processing activities); (ii) obligations to consider and implement data protection requirements as any new services are developed and to limit the amount of personal information processed; (iii) obligations to comply with data protection rights of data subjects (including the right to access and the right to be “forgotten”); (iv) reporting of personal information breaches to the supervisory authority without undue delay (and no later than 72 hours); and (v) complying with the principle of accountability and the obligation to demonstrate compliance through policies, procedures, training and audit. We generally act as a processor when we process personal information on behalf of our customers. Where we act as a processor and process personal information on behalf of our customers or partners, we are required to execute mandatory data processing clauses with our customers/partners, notify our customers/partners of any personal information breaches involving customer personal information, assist our customers/partners with any data subject rights requests and any data protection impact assessments, and maintain a record of data processing, among other requirements under the GDPR and the UK GDPR.