Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

XBP US Equity

XBP Global Holdings, Inc.Industrials · Services-Business Services, NEC · CIK 1839530 · FY ends Dec 31
$2.91
+0.03 (+0.87%)
USD · as of 2026-08-21 · marketstack

XBP · 10-K · period ended 2025-12-31

← all XBP documents
filed 2026-03-31 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1541 of 2,583492k characters rendered

XBP Global Holdings, Inc._December 31, 2025

Table of Contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

WASHINGTON, D.C. 20549

FORM 10-K

(Mark One)

For the fiscal year ended December 31, 2025

or

For the transition period from to

Commission File Number: 001-40206

XBP Global Holdings, Inc.

(Exact Name of Registrant as Specified in its Charter)

​ ​ ​

(Address of Principal Executive Offices) ​ (Zip Code)

Registrant’s Telephone Number, Including Area Code: (844) 935-2832

Securities Registered Pursuant to Section 12(b) of the Act:

​ ​ ​ ​ ​

Common Stock, Par Value $0.0001 per share ​ XBP ​ The Nasdaq Capital Market

Indicate by check mark if the Registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act.☐Yes ☒No

Indicate by check mark if the Registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. ☐Yes ☒No

Indicate by check mark whether the Registrant (1) has filed all reports required by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the Registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. ☒Yes☐No

Indicate by check mark whether the Registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this chapter) during the preceding 12 months (or for such shorter period that the Registrant was required to submit such files). ☒Yes☐No

Indicate by check mark whether the Registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, or a smaller reporting company. See definitions of “large accelerated filer”, “accelerated filer”, “smaller reporting company” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

​ ​

​ Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☐

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the Registrant is a shell company (as defined in Rule 12b-2 of the Act). ☐ Yes ☒No

The aggregate market value of the Registrant’s voting and non-voting shares of common stock held by non-affiliates of the Registrant was approximately $6,220,383 computed by reference to the price at which such common stock was last sold as of June 30, 2025, (based on a closing price of $9.30).

As of March 30, 2026, the Registrant had 11,768,050 shares of common stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

The information required by Part III of this Report, to the extent not set forth herein, is incorporated herein by reference from portions of the registrant’s definitive proxy statement that will be filed for the 2026 Annual Meeting of Shareholders, which the registrant intends to file with the Securities and Exchange Commission no later than 120 days after the close of the fiscal year ended December 31, 2025.

Table of Contents

TABLE OF CONTENTS

Part I 5

​ ​

Item 1. Business 5

​ ​

Item 1A. Risk Factors 21

​ ​

Item 1B. Unresolved Staff Comments 36

​ ​

Item 1C. Cybersecurity 36

​ ​

Item 2. Properties 37

​ ​

Item 3. Legal Proceedings 38

​ ​

Item 4. Mine Safety Disclosures 38

​ ​

​ ​

​ ​

Item 6. [Reserved] 39

​ ​

​ ​

Item 7A. Quantitative and Qualitative Disclosure About Market Risk 64

​ ​

Item 8. Financial Statements and Supplementary Data 65

​ ​

​ ​

Item 9A. Controls and Procedures 143

​ ​

Item 9B. Other Information 146

​ ​

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspection 146

​ ​

​ ​

Item 10. Directors, Executive Officers, and Corporate Governance 147

​ ​

Item 11. Executive Compensation 147

​ ​

​ ​

​ ​

Item 14. Principal Accountant Fees and Services 147

​ ​

​ ​

Item 15. Exhibit and Financial Statement Schedules 148

​ ​

​ ​

2

Table of Contents

SPECIAL NOTE REGARDING FORWARD-LOOKING STATEMENTS

Certain statements included or incorporated by reference in this Annual Report on Form 10-K (“Annual Report”) are not historical facts but are forward-looking statements for purposes of the safe harbor provisions under The Private Securities Litigation Reform Act of 1995. Forward-looking statements generally are accompanied by words such as “may”, “should”, “would”, “plan”, “intend”, “anticipate”, “believe”, “estimate”, “predict”, “potential”, “seem”, “seek”, “continue”, “future”, “will”, “expect”, “outlook” or other similar words, phrases or expressions. These forward-looking statements include statements regarding our industry, future events, strategy, plans, intentions, or expectations or anticipated future results and other statements that are not historical facts. These statements are based on the current beliefs and assumptions of our management and are not predictions of actual performance. These statements are subject to a number of risks and uncertainties regarding our business that may change at any time, and, therefore, our actual results may differ materially from those that we expected. The factors that may affect our results include, among others: the impact of political and economic conditions on the demand for our services; the impact of a data or security breach; the impact of competition or alternatives to our services on our business pricing and other actions by competitors; our ability to address technological development and change in order to keep pace with our industry and the industries of our clients; the impact of terrorism, natural disasters or similar events on our business; the effect of legislative and regulatory actions in the United States and internationally; the impact of operational failure due to the unavailability or failure of third-party services on which we rely; the effect of intellectual property infringement; the Business Combination or Restructuring (as defined below); and other factors discussed in this report under the headings “Risk Factors”, “Legal Proceedings”, “Management’s Discussion and Analysis of Financial Condition and Results of Operations” and otherwise identified or discussed in this Annual Report. You should consider these factors carefully in evaluating forward-looking statements and are cautioned not to place undue reliance on such statements, which speak only as of the date of this report.

The forward-looking statements made by us in this report speak only as of the date of this report. We undertake no obligation to update or revise any forward-looking statements to reflect events or circumstances occurring after the date of this report, except as otherwise required by law. In addition, forward-looking statements provide our expectations, plans or forecasts of future events and views based upon information available to us as of the date of this report and while we believe such information forms a reasonable basis for such statements, such information may be limited or incomplete, and our statements should not be read to indicate that we have conducted an exhaustive inquiry into, or review of, all potentially available relevant information. These statements are inherently uncertain and you are cautioned not to unduly rely upon these statements.

Unless otherwise indicated or the context otherwise requires, references in this section to “we,” “our,” “us,” “XBP Global”, “the Company” and similar terms are to BPA before the Business Combination (as such terms are defined below), and to XBP Global Holdings, Inc. following the Business Combination.

DEFINED TERMS

Following is a glossary of other abbreviations and acronyms that are found in this Annual Report:

“BPA” means Exela Technologies BPA, LLC, (n/k/a XBP Americas, LLC) collectively with its subsidiaries and affiliates.

“Business Combination” means the acquisition of BPA by the Company pursuant to a Membership Interest Purchase Agreement dated July 3, 2025.

“Bylaws” means the bylaws of the Company.

“Charter” means the amended and restated certificate of incorporation of the Company.

“Common Stock” means the common stock of XBP Global Holdings, Inc., par value $0.0001.

3

Table of Contents

“Company” or “XBP Global”means XBP Global Holdings, Inc., a Delaware corporation (f/k/a XBP Europe Holdings, Inc.)

“Consenting ETI Parties” means GP 3XCV LLC and XCV-STS, LLC (two subsidiaries of ETI)

“EIM” means enterprise information management.

“EMEA” means the Europe, Middle East and Africa geographical region.

“ERP” means enterprise resource planning system.

“Exchange Act” means the Securities Exchange Act of 1934, as amended.

“ETI” means Exela Technologies, Inc., a Delaware corporation.

“GAAP” means generally accepted accounting principles in the United States.

“IT” means information technology.

“Nasdaq” means The Nasdaq Stock Market LLC.

“MIPA” means the Membership Interest Purchase Agreement dated July 3, 2025

“Plan” means the plan of reorganization filed on May 7, 2025, by BPA along with certain affiliates reflecting the proposed Restructuring.

“Restructuring” means the restructuring of the indebtedness of BPA and certain affiliates pursuant to the plan support agreement entered into on April 16, 2025, as amended, with an ad hoc group of holders of certain notes of BPA.

“Sarbanes-Oxley Act” means the Sarbanes-Oxley Act of 2002, as amended.

“SEC” means the United States Securities and Exchange Commission.

“Securities Act” means the Securities Act of 1933, as amended.

4

Table of Contents

PART I

ITEM 1. BUSINESS

Overview

XBP Global is a multinational technology and services company powering intelligent workflows for organizations worldwide. Our proprietary platforms and agentic AI-driven automation enable our clients to entrust us with their most impactful digital transformations and mission-critical operations. Our operational foundation is further defined by deep domain expertise across industries and the public and private sectors. We possess decades of experience helping clients navigate shifting global regulatory frameworks and supporting compliance with the rigorous standards required by government entities and highly scrutinized industries, including banking, healthcare and insurance. We pair this expertise with platform-agnostic, end-to-end structured workflows that combine AI-driven automation with dedicated human-in-the-loop exception handling and proprietary orchestration software, enabling our clients to transition from labor-intensive, reactive operations to digitally orchestrated, exception-driven workflows. For the period August 1, 2025 to December 31, 2025 (Successor) and January 1, 2025 to July 31, 2025 (Predecessor), we generated $359.4 million and $431.7 million of revenue, respectively. As of December 31, 2025, we served more than 2,500 clients throughout the world.

Our solutions and services reach multiple elements within a client’s organization. We use a global delivery model and primarily host solutions in our data centers, on the cloud, or directly from our clients’ premises. As of December 31, 2025, we had 10,600 employees in 20 countries operating either remotely from our business facilities or co-located at our clients’ facilities. Our solutions offer geographic flexibility, and we believe the combination of our hybrid hosted solutions and global workforce in the Americas, EMEA and Asia offers a meaningful differentiation to the industries we serve and services we provide.

Our Solutions and Services

We offer flexible commercial models tailored to our clients’ needs. We generate revenue through transaction-based processing fees, fixed-fee managed services, and recurring software licenses and maintenance, along with professional services for system configuration and integration. Our solutions continue to evolve to include more self-

5

Table of Contents

service features that are easy to deploy and designed to integrate with existing systems, including those of small and medium-sized businesses.

In addition to operating our own datacenter, we have extended our existing data investments into AI capabilities and initiatives via the sophisticated proprietary deep-learning models we now deploy. Our investments in agentic AI, which we believe is the operating system of the modern enterprise, are now infused into many of our offerings described below. Our focus on agentic AI starts with investments that materially improve the productivity of our workforce and extends to delivering value to clients in both their on-premise and hybrid cloud environments. Additionally, our extensive experience in large-scale document processing informs the design of our custom AI models targeted at complex workflows. We are also developing specialized, vertical-specific AI solutions tailored for the nuanced regulatory and operational requirements of the highly complex sectors we serve.

Finance and Accounting Solutions

XBP Platform — Exchange for Bills and Payments

The XBP platform provides a secured network, allowing billers, consumers and businesses to communicate and transact utilizing a modern technology stack that can connect to any client system without significant capital investments by new clients. Business-to-business billers are able to communicate with payers electronically, offering transparency and simplified reconciliations. By structuring and linking data across disparate client systems, our XBP platform can be rapidly implemented using each client’s existing infrastructure and in-country settlement processes. This product allows payers to receive their bills in a single place, with analytics, alerts and several payment options. Downstream processes can be integrated with actionable data that is offered as a value-added service.

The XBP platform payment solutions enable consolidation of inbound payment channels and data continuity to enhance treasury management. Among other things, the product offers integrated receivables dashboards, multi-channel bill presentment and payment, reconciliation, exception and dispute management, ageing analytics, collections management and targeted engagements.

Through the introduction of the XBP platform for small and medium sized businesses (“SMBs”), clients are able to access our XBP web portal and leverage rich features to organize their bills, initiate communication and manage their order-to-cash cycle (“O2C”) effectively, including accounts receivable, all designed to improve liquidity by expediting payments. We also use the XBP platform as the tool to support our ERP data consolidation offering. To address the time-consuming and error-prone processes that enterprises can face when consolidating data from multiple ERPs, we use our AI-enabled robotic process automation suite, along with off the shelf ERP connectors, to extract data from multiple ERPs and feed it into the XBP platform for clients to have one consolidated view without data being subject to the risks commonly associated with manual handling.

Our accounts payable and broader procure-to-pay (“P2P”) solution leverages artificial intelligence to simplify the complexities of supplier onboarding, management, and invoice processing. Our P2P platform integrates with our Digital Mailroom (“DMR”) technology, which processes unstructured data utilizing locally hosted large language models (“LLMs”). By deploying these models within our own infrastructure, we help our clients meet their data privacy and compliance obligations— which we believe can be a competitive differentiator in securing major AI-driven mandates. The P2P solution process begins by initiating a requisition, which moves to procurement where bids are solicited from an approved supplier network. Our P2P solution also records receipt of goods and invoices and performs AI-based three-way matching. Exceptions are intelligently routed and, once approved, the purchase is recorded directly into the client’s ERP system for payment. We then generate and deliver a payment file in the format the bank requires,

6

Table of Contents

or, in some cases, process the payment on the client’s behalf. By deploying these solutions, we are able to decipher complex invoices, resolve exceptions, and provide predictive forecasts and insights into legacy accounting platforms.

Plug and play solutions across the P2P and O2C cycle to simplify and personalize user experience, optimize treasury management and facilitate compliance while reducing administrative cost.

Request To Pay

Our consistent focus on innovation in the open banking space allowed us to become one of the first market participants to develop an approved Request to Pay (“RTP”) solution for the UK market. This product was developed in cooperation with a key partner, Mastercard, and was approved in 2020 by Pay.UK, the operator and standards body for the U.K.’s interbank retail payment systems. Meanwhile, the European Union is advancing its own RTP solution to complement the E.U. Instant Payments Regulation adopted in March 2024. Whether in the U.K. or European Union, RTP enables billers to make payment requests and allows payers to act on such requests through a secure, unified messaging service that provides end-to-end audit trails for billers and facilitates two-way communication throughout the payment process. The solution is designed to help reduce the number of late payments by allowing the payer to exercise more options, including opening a line of communication regarding the amount, frequency and time of payment. Driven by recent regulatory frameworks such as the U.K.’s National Payments Vision (2024) and the E.U. Instant Payments Regulation, RTP has evolved into a foundational component of the broader account-to-account ecosystem. Recent industry assessments highlight that its potential uses have expanded beyond e-invoicing and e-commerce to include point-of-sale instant transfers, variable recurring payments and integrated digital wallets. The benefits across these use

7

Table of Contents

cases are many and include improved liquidity management, reduction of payment defaults, avoidance of credit card fees and reduced reliance on cash by enabling a low-cost real-time account to account transfer.

Enterprise Information Management

Our enterprise information management solutions consume and organize large amounts of data across multiple formats and store the information in cloud-enabled proprietary platforms, including DocumentDNA, our secure electronic repository and document management platform. We also gather transaction data from enterprise systems for hosting. The data we collect and extract for our clients is used to complete a client-mandated process and is then made available to our clients and their end-consumers for a period of time in return for an access fee or software license revenue as part of the hosting service. These solutions use state of the art cloud-based relational and non-relational databases to provide scalable, secure and resilient digital archiving. Demonstrating our commitment to security standards, our electronic archiving system, eFirst Archive SAE, holds the French NF 461 certification. This standard establishes guidelines for document creation, storage, use and disposal, and is designed for stringent quality and security levels throughout a document’s lifecycle. We use this suite of solutions extensively in our digital transformation projects.

Agentic AI-Enabled Robotic Process Automation

We have been at the forefront of implementing robotic process automation (“RPA”) in our services. While we started with traditional RPA tools to enable desktop automation, followed by server-level automation, we have since started leveraging agentic AI (“computer use”) tools extensively for simulating human activities at computer terminals. We have built up a large library of automation rules by both industry and client embedded into our solution suite. We view agentic AI-based automation as a step towards the automation of processes in instances where application programming interfaces do not exist. An example of this is old legacy systems, which may only be accessed through UIs that were intended for a human operator to access.

Digital Mailroom Solutions

Our DMR links physical mail delivery and the modern digital workspace. As part of our comprehensive services, we frequently handle the entire mailroom operation for our clients, utilizing either our own processing centers or a client’s existing facilities. At the core of this process, DMR serves as the secure point of entry, receiving and digitizing physical mail. Then, our Smart Sort Transformation solution employs AI-enabled classification and intelligent routing to categorize and deliver documents to the correct employee, department, or system. Our intelligent document processing platform, paired with dedicated “human-in-the-loop” exception handling, can then convert the correspondence into actionable electronic data. These offerings reduce the need for dedicated mailroom personnel who

8

Table of Contents

physically open, review, and sort incoming documents. This transition from manual, location-specific sorting to software-driven routing provides scalable, impactful automation benefits to mailroom operations. For our clients, this can result in accelerated processing cycle times and a significant reduction in per-transaction costs and also serves as a fundamental enabler of a hybrid or remote workplace environment. Our largest DMR deployment is with the German savings bank finance group, to which over 50 million users have access.

Workflow Automation

We have built extensive proprietary workflow automation platforms across industries and regions. Our platforms are designed to have intuitive user interfaces with drag & drop configuration enabling a certain amount of customization. Our platforms use our EIM engines by default, are designed to integrate with popular databases and enterprise systems, and are offered across three user categories:

XBP Global provides agentic AI-enabled observability, reporting, and analytics capabilities embedded within its platforms to deliver actionable intelligence across collaboration, task management, and operational workflows. Through configurable dashboards, users can consolidate and organize disparate data sources into intuitive visual and audio interfaces, build custom dashboards with dynamic drilldowns and alerts, and link insights directly to managers and action items to drive optimization and issue resolution. These analytics provide real-time visibility into revenue, cost, profitability, cash flow, process performance, and KPIs, including AI-driven triggers that notify stakeholders when trends deviate from defined thresholds to support timely capacity and operational adjustments. We believe these analytics modules complement our services and solutions by enhancing the user experience, reducing reliance on third-party tools, and centralizing business management within XBP Global’s platforms, while enabling dashboard sharing across organizations to drive broader adoption and deeper penetration of our front-end applications across the enterprise.

Legal Administration

Through our subsidiary, Rust Consulting, Inc., we provide administration services for complex legal and regulatory matters, including class action settlements, mass torts, product recalls, and data breach responses. Our service delivery encompasses the entire project lifecycle, requiring the management of multi-channel communication networks and high-volume data workflows. As part of this process, we orchestrate large-scale notification campaigns, disseminating millions of outgoing legal notices and settlement payments across both physical mail and electronic communication channels. Additionally, we manage the simultaneous intake of inbound claims and inquiries across these diverse channels, which includes operating dedicated contact centers, where we are deploying automated chatbots to streamline the handling of high-volume inquiries.

Our operational capabilities are built upon decades of experience administering thousands of complex projects, processing millions of claims, and facilitating the distribution of billions of dollars in settlement funds. Due to this sustained scale, we frequently serve as the designated administrator for distributions overseen by federal courts and government agencies, including the Federal Trade Commission, the Department of Justice, and the Consumer Financial

9

Table of Contents

Protection Bureau. To help maintain the strict compliance and accountability standards mandated by these oversight bodies, our processing infrastructure incorporates comprehensive data validation processes, deficient claim review, and professional exception management. These structural controls help provide accuracy, regulatory adherence, and secure fund distribution across large-scale legal administrations.

Integrated Marketing Communications

Our Integrated Marketing Communications business provides technology-enabled services that help organizations design, produce, and deliver communications to clients, members, and business partners. These communications include statements, invoices, checks, regulatory notices, client correspondence, and targeted marketing communications. The industry is experiencing a secular shift as volumes for transactional printing decline due to digital substitution. Conversely, demand for direct mail and commercial graphics is expanding, as clients increasingly rely on high-quality, variable data printing to expand market share. By prioritizing our marketing execution capabilities and aligning our enterprise resources with these expanding direct mail volumes, we are investing to be an integral partner in this market.

Our platform integrates document composition software, automated workflow management, and multi-channel delivery capabilities that support high-volume communications across both digital and physical channels, including print and mail, email, SMS, web portals, and other digital delivery methods. Through these solutions, clients can automate the creation and distribution of communications, maintain regulatory compliance, and optimize delivery channels based on cost, speed, and client preferences. Our technology also enables enhanced client engagement through tools such as dynamic QR codes and personalized digital links embedded within communications, allowing recipients to transition from physical communications to digital experiences. We continue to evaluate additional applications of these capabilities as part of our broader efforts to enhance client communications and engagement.

XBP Brand Central is our cloud-based platform that enables organizations to manage branded materials, marketing assets, and printed communications through a centralized digital storefront. The platform allows clients to order, customize, and distribute printed materials, promotional products, and marketing collateral while maintaining brand standards and controlling costs. XBP Brand Central integrates ordering, composition, production, and fulfillment workflows, supporting print-on-demand and inventory management capabilities. By consolidating procurement and distribution through a single platform, XBP Brand Central helps clients improve operational efficiency, maintain brand consistency, and reduce inventory and logistics costs.

Our production and technology platforms have capacity to support enterprise communications programs across the United States and Europe. We continue to invest in technology, automation, AI-enabled analytics, and data-driven communications capabilities that support the growing demand for digital communications, enhanced client engagement, and automated enterprise communication platforms. Our integrated model combines software-driven workflow management with production and distribution capabilities, enabling clients to manage complex communications programs through a single platform.

Smart Office

Our Smart OfficeSM suite is an enterprise IoT (“internet of things”) solution designed to optimize facility management and workplace experiences. To transition legacy facilities into connected “Smart Campuses,” the suite centers on XBP Concierge—a unified, mobile-first application that consolidates room and desk booking, intelligent indoor wayfinding using beacon technology, and service helpdesks. Our platform integrates with existing enterprise applications and serves as a physical-to-digital bridge connecting software to IoT devices such as occupancy sensors, intelligent digital lockers, and access control systems. By capturing real-time data from the physical office, the suite delivers predictive analytics regarding user behavior and space utilization, enabling clients to optimize their real estate footprint and manage high-density hybrid work environments. Furthermore, to automate physical workflows and support just-in-time near-site logistics, we intend to develop our capabilities to integrate collaborative robots into our orchestration platform. Once deployed, these “cobots” are intended to operate alongside human staff to execute high-volume physical tasks, with “human-in-the-loop” exception handling, which we believe will allow clients to further relocate and digitize legacy front-office operations to centralized off-site hubs. A key component of this logistical

10

Table of Contents

support is the integration of our DMR capabilities, which further de-tethers the workforce from physical office dependencies by securely digitizing and intelligently routing inbound correspondence.

Industry Specific Services and Solutions

While the above-described solutions and services can be leveraged across industries, over the years we have also developed services and solutions for specific industries which help our clients around the world. The most significant are summarized below.

Healthcare Industry Solutions and Services for Insurance Companies and Healthcare Providers

XBP Global’s healthcare industry clients include commercial and government-sponsored healthcare plans, as well as healthcare providers, including hospital networks, university hospital systems, and large medical distribution systems, and accounted for approximately 28% of total revenues in 2025.

We bundle our core solutions and services with a comprehensive suite of healthcare payer- and provider-specific offerings, including end-to-end revenue cycle management (“RCM”). These services encompass clinical documentation, medical coding, claims processing, revenue integrity, enrollment, credentialing, denial and appeals management, and payment operations.

For healthcare payers, XBP Global delivers specialized operational and technology-enabled services designed to improve administrative efficiency, claims accuracy and regulatory compliance. These services include claims intake and adjudication support, eligibility and benefits verification, provider data management, prior authorization processing, care management support, encounter data management, coordination of benefits, payment integrity, fraud, waste and abuse (FWA) detection, and member services operations. We also support value-based care administration, risk adjustment documentation review, quality reporting and regulatory submissions for government programs such as Medicare and Medicaid.

Experienced revenue cycle and payer operations professionals manage complex transactions and exceptions across these services, supported by automation for routine, high-volume tasks such as document digitization, reconciliation and workflow processing. Our approach combines domain expertise with intelligent automation, analytics and exception-based processing to improve claims accuracy, accelerate adjudication cycles and enhance financial outcomes for both payers and providers. These services embed technology directly into provider and payer workflows, including intelligent automation, analytics, and exception-based processing to address accounts receivable, compliance requirements, clinical documentation improvement, underpayments, contractual adjustments and payment integrity.

Our cloud-based PCH Global platform supports these services by streamlining claims submission and payment processing for providers and facilitating real-time connectivity with payer systems. It leverages its distributed architecture to integrate XBP Global’s multiple industry offerings, including edit engines, payment application, healthcare analytics and revenue integrity capabilities. This integrated ecosystem enables cleaner claims at the point of service, reducing the risk of denial, delay and rework, thereby improving liquidity for various industry stakeholders. The PCH Global platform includes a dedicated online portal designed for small and medium-sized healthcare providers. By enabling these practices to submit and track claims directly through an intuitive, self-service interface, the portal provides a speedy, cost-effective alternative to traditional submission methods, significantly reducing administrative overhead and accelerating the overall payment cycle.

The healthcare RCM outsourcing market is experiencing significant growth, driven by demand for scalable solutions amid persistent industry labor shortages, rising regulatory complexity, interoperability mandates, and the continued shift toward value-based care models. To capitalize on these industry trends, XBP Global is engaged in ongoing development of an AI-first revenue cycle and payer operations solution suite, intended to support a transition from labor-intensive, reactive workflows to a digitally orchestrated, exception-driven operating model. This approach emphasizes embedding automation for routine tasks while leveraging experienced professionals for complex exceptions, with technology incorporating configurable thresholds, comprehensive audit trails, and human-in-the-loop controls to support compliance, public-sector accountability, and adaptability to evolving regulatory and technological landscapes.

11

Table of Contents

Banking and Financial Industry Solutions and Services

We provide a broad array of payment solutions to many of the world’s largest financial institutions. These solutions allow our clients to bridge their physical and digital payment channels while maintaining security and auditability levels consistent with global financial regulations. We process more than a billion payments annually. Our banking and financial industry offerings include solutions for payment processing and payment enablement, mortgage enrollment, lending and loan management, confirmation of payee, KYC, anti-money laundering, governance, compliance and information management solutions and accounted for approximately 19% of revenue in 2025.

We handle a variety of payment channels in addition to checks and credit cards, including mobile payments, automated clearing house (ACH), Real Time Payments (called Faster Payments in the UK), Single Euro Payments Area (SEPA), Bank Giro in Nordic countries and other payment networks. Regulators have increasingly mandated security overlay services, such as the RTP standards described above, to mitigate fraud in real-time payments. Additionally, Confirmation of Payee (“CoP”) and Verification of Payee (“VOP”) are U.K. and E.U. standards, respectively, that verify payee information against account details. We were among the first service providers to launch a live client on our CoP service with the Co-operative Bank in 2020 and have been an approved CoP aggregator since 2024. We are also registered with the European Payments Council as a vendor of VOP services. We perform these services on behalf of banks or our other clients. Open banking is changing the regulatory environments in many of the Company’s markets, which permit non-bank payment processors to connect to the payment networks directly. These banks look to us to manage the payment infrastructure (software, hardware and hosting), the process design, the operational aspects of the services, payment scheme compliance (to the in-country interbank clearing schemes) and the application of the appropriate governance processes covering this heavily regulated industry. The bank clients outsource functions from their payments infrastructure and operations to us, and we then manage the end-to-end design and build, test and operate aspects of the payments processes using our in-house resources, software and know-how.

We have internal policies and procedures that conform to the standards required by banks and regulators for such sensitive and crucial activities and help us comply with local laws and regulations. Our processing facilities are Payment Card Industry (“PCI”) certified. Additionally, our platforms are equipped to process complex regulatory and financial transactions on behalf of our clients, such as helping our clients maintain compliance with Regulation Z (which governs consumer credit disclosures and costs under the Truth in Lending Act) and helping manage annuity payments. These policies and procedures are intended to position us well to accommodate evolving data privacy laws and regulations related to LLMs and AI.

Liquidity and Disbursement Solutions

We provide liquidity and disbursement solutions designed to facilitate capital flow. Utilizing proprietary, AI-enabled automation, our platform connects small-to-medium businesses (SMBs) and lending institutions. A primary application of this service is expediting the processing and routing of government disbursements, such as federal tax refunds, which allows commercial clients to receive their funds faster.

Cross Border Payments

We operate foreign currency services for banks in the U.K. and Ireland. These services are more complex than domestic payments as they require us to comply with international sanctions regimes (e.g., OFAC) and involve many more regulations, rules and downstream processes including exchange rate charging tariffs.

Digitization of Checks

We provide mobile and remote deposit technologies to our banking and financial services clients. For example, when the U.K. transitioned from traditional check processing to an image clearing system (“ICS”) in 2017, to speed up the settlement of checks, XBP Global and Vocalink (part of Mastercard) were selected to jointly build the infrastructure of this new inter-bank clearing system. Today, ICS has standardized digital check processing across the U.K. Within this ecosystem, we have delivered ICS-compliant services to participant banks in the U.K. and have worked to upgrade their mobile and remote deposit capabilities.

12

Table of Contents

Mortgage and Loan Management

To improve the speed and provide cost efficiencies within a compliant mortgage and lending completion process, our proprietary mortgage and loan management solutions enable lenders to originate and service loans with greater efficiency by automating the entire mortgage lifecycle, from origination to submission and post-completion disbursements.

Public Sector

We provide technology and services to public sector clients, including central, federal, state, and local government agencies, as well as national tax authorities, which accounted for approximately 11% of total revenues in 2025. Once integrated, our solutions become deeply embedded in these highly scrutinized public workflows, because our processing environments and data custody protocols are built from the ground up to satisfy rigorous regulatory standards, we provide a secure, compliant physical and cloud-based infrastructure that we believe represents a significant barrier to entry for new market participants.

XBP Global solutions are primarily deployed across pension benefits and administration, tax return processing, payment operations, inter-agency information management and communications with citizens and government employees. These solutions have evolved over time to include digital capabilities designed to reduce taxpayer refund waiting time, decrease the potential for tax fraud, and provide auditable reports to relevant stakeholders. Furthermore, we have the secure infrastructure and AI-enabled technology platforms in place to process payments, perform collection services, handle overflow taxpayer calls, provide e-filing for individual income tax, generate outbound taxpayer notifications across traditional and electronic channels, and host other specialized solutions built specifically to meet the exacting standards of public sector oversight.

Insurance Industry Solutions and Services

XBP Global offers a suite of insurance industry solutions aimed at providing digital engagements and rapid integration of disparate systems and silos. Our insurance industry solutions accounted for approximately 7% of total revenues in 2025. We provide applications and services to facilitate automation and digital transformation for underwriting and enrollments, premium payments, claims submission, first notification of loss, fraud, waste & abuse monitoring, and integrated communications. Our solutions are aimed at improving the client experience by providing digital pathways and transparency with web portals and integrated communications, while helping to improve quality and risk management.

Other Industries

For the commercial, technology, manufacturing, telecommunication, utilities, pharma, life sciences and legal industries, we primarily provide the multi-industry solutions described earlier. For 2025, our commercial industry revenue accounted for approximately 6% of total revenues, our service industry revenue accounted for approximately 11% of total revenues, our revenues from the technology and manufacturing industry accounted for approximately 8%, our telecommunication and utilities industry revenue accounted for approximately 3% of total revenues, our pharma and life sciences industry revenue accounted for approximately 2% of total revenues, while our revenue from the legal industry accounted for approximately 5%.

Historically, the majority of revenue for the above-mentioned industries was generated in the Americas, though we believe there is significant expansion opportunity throughout EMEA and the Asian markets. As we have made investments in our global scale, technology platforms and business strategy, some of our multinational clients have expanded our services to other geographies to leverage our international footprint. We believe our value proposition as a single source provider, with global platforms and location agnostic operations, positions us as a differentiated partner to our multi-national clients.

13

Table of Contents

Overview of Revenues

We provide services to our clients on a global basis. During the periods August 1, 2025 to December 31, 2025 (Successor) and January 1, 2025 to July 31, 2025 (Predecessor), our revenues by geography were as follows: $291.7 million and $421.0 million, respectively in the United States (90.1% of combined annual revenues), $60.9 million and $0, respectively in EMEA (7.7% of combined annual revenues) and $6.8 million and $10.6 million, respectively from the rest of the world (2.2% of combined annual revenues). We present additional geographical financial information in Note 21, Segment Information within our consolidated financial statements.

As described further in our consolidated financial statements, revenues reported for EMEA do not include amounts attributable to the period prior to the Business Combination. Our business consists of two reportable segments:

Additional financial information for our business segments and regarding our Successor/Predecessor period and our Company’s fresh start accounting is included in Note 21, Segment Information and Note 4, Fresh Start Accounting, respectively, within our audited consolidated and combined financial statements.

Our revenues can be affected by various factors such as our clients’ demand pattern for our services. These factors have historically resulted in lower revenues in the third quarter and higher revenues in the fourth quarter. Backlog is not a metric that we use to measure our business.

History and Development of Our Company

XBP Global Holdings, Inc. was originally incorporated as CF Acquisition Corp. VIII, a blank check company formed under the laws of the State of Delaware on July 8, 2020. On March 16, 2021, the Company consummated its initial public offering. The Company’s initial purpose was to effect a business combination with one or more businesses. On October 9, 2022, CF Acquisition Corp. VIII entered into a merger agreement with XBP Europe, Inc., at the time a subsidiary of ETI. This initial business combination was completed on November 30, 2023, at which time the Company was renamed XBP Europe Holdings, Inc., reflecting the acquisition of ETI’s historical European operations, and the Company’s shares and public warrants started trading on The Nasdaq Stock Market LLC under the ticker symbols “XBP” and “XBPEW,” respectively.

On July 29, 2025, XBP Europe Holdings, Inc. finalized its acquisition of BPA, ETI’s historical operations in the Americas and Asia, pursuant to the MIPA. The consideration for the sale was $1.00, reflecting the encumbered nature of BPA, which at the time of entry into the MIPA was involved in voluntary bankruptcy proceedings under the caption In re DocuData Solutions, L.C., Case No. 25-90023 (CML) (the “Chapter 11 Cases”). The Business Combination was subject to certain conditions subsequent including the emergence of BPA and certain of its affiliates from the Chapter 11 Cases, which occurred on July 29, 2025. Prior to the Business Combination, the Company and BPA had both been indirect subsidiaries of ETI. In connection with the Business Combination, the Company changed its

14

Table of Contents

name from “XBP Europe Holdings, Inc.” to “XBP Global Holdings, Inc.” and ceased being a subsidiary of ETI. Together with the European operations acquired in 2023, the Company’s current global platform is built upon a portfolio of acquired and predecessor entities with more than 50 years of commercial and operational history.

BPA Chapter 11 Reorganization

On March 3, 2025, BPA along with certain affiliates (the “BPA Debtors”) commenced the Chapter 11 Cases in the United States Bankruptcy Court for the Southern District of Texas (the “Bankruptcy Court”). On April 16, 2025, the BPA Debtors entered into a Plan Support Agreement (as amended, the “Plan Support Agreement”) with an ad hoc group of holders of certain notes, ETI, certain non-BPA Debtor subsidiaries of ETI (together with ETI, the “Consenting ETI Entities”), and certain other parties thereto. In the Plan Support Agreement such parties agreed, subject to certain conditions, to support the BPA Debtors’ reorganization plan in the Chapter 11 Cases and to take all commercially reasonable actions necessary and appropriate to facilitate the Restructuring. On May 7, 2025, the BPA Debtors filed the Plan reflecting the proposed Restructuring, which was confirmed by the Bankruptcy Court on June 23, 2025. On July 29, 2025 (the “Emergence Date”), BPA consummated the Restructuring and emerged from bankruptcy having satisfied or waived all the conditions set forth in the Plan.

See Note 1, Description of the Business of the notes to the consolidated financial statements for additional information about the Restructuring.

Key Business Strategies

Our business strategy centers on securely managing complex workflows for our clients. We accomplish this by deploying proprietary software and automated workflows that unify physical logistics and modern digital infrastructure. By combining decades of experience managing sensitive operations with adherence to mandated compliance standards, we provide a structurally durable operating model that securely processes complex data that off-the-shelf software tools cannot easily manage. The key elements of our growth strategy are described below:

15

Table of Contents

Clients

As of December 31, 2025, we served over 2,500 clients across a variety of industries, many of which are recurring clients that have maintained long-term relationships with us and our predecessor companies. We have successfully leveraged these relationships to offer extended value chain services, driving long-term retention and increasing overall margins. Clients turn to us due to a demonstrated ability to work on large-scale projects, past performance and record of delivery, and deep domain expertise accumulated from years of experience in key verticals.

Our solutions reach a wide range of industries and transactions

We maintain a strong mix of diverse clients with low client concentration. While our top 5 clients accounted for 27% of 2025 revenue, and our top 10 clients accounted for 39% of 2025 revenue, no single client accounts for more than 10% of 2025 revenue. By operating across a diverse set of end markets, we seek to balance our client mix and mitigate our dependency on any single client or specific industry vertical.

Research and Development

Our ability to compete successfully depends upon our development of advanced technologies that modernize complex enterprise workflows. Through investment, intellectual property development, and targeted acquisitions, our research and development efforts are primarily focused on deploying artificial intelligence and embedded processing solutions. Because we serve as the secure point of entry for vast quantities of proprietary corporate data—capturing unstructured inputs directly through our physical and DMR operations—we regularly handle complex, highly regulated

16

Table of Contents

workflows. This experience guides our engineering efforts as we bridge the gap between AI and real-world enterprise implementation.

We are enhancing our end-to-end processing environments by pairing intelligent document processing and our orchestration software with dedicated, human-in-the-loop exception handling. This structured, platform-agnostic workflow provides that as we develop hyper-automation and custom machine learning models to classify and action data instantly, we help our clients maintain the requisite security protocols and auditable chains of custody. As part of our broader innovation pipeline, we are also actively developing specialized, vertical-specific AI solutions tailored to the operational and regulatory requirements of the sectors we serve. Additional financial information regarding our R&D expense is included in Note 2, Basis of Presentation and Summary of Significant Accounting Policies within our consolidated financial statements.

Intellectual Property

We deploy a combination of internally developed proprietary knowledge platforms and agentic AI-driven automation. Our decisioning engines incorporate hundreds of thousands of client- and industry-specific rules that enable high-accuracy preparation and decisioning of complex, regulated transactions where generalized software often fails to meet the precision, auditability and compliance requirements of our clients. We believe this accumulated body of domain expertise is a meaningful differentiator in serving our target markets.

Our business processes and implementation methodologies are confidential and proprietary and include trade secrets that are important to our business. We own a variety of trademarks and patents, which are registered or pending.We regularly enter into nondisclosure agreements with clients, business partners, employees and contractors that require confidential treatment of our information to establish, maintain and enforce our intellectual property rights. Our licensed intellectual properties are generally governed by written agreements of varying durations, including some with fixed terms that are subject to renewal based on mutual agreement. Generally, each agreement may be further extended, and we have historically been able to renew most existing agreements before they expire.

Competition

We believe that the principal competitive factors in providing our solutions include proprietary platforms, industry specific knowledge, quality, reliability and security of service, and price. We are differentiated competitively given our scale of operations, reputation as a trusted partner with deep domain expertise, innovative solutions, and highly integrated technology platforms that provide clients with end-to-end services addressing many aspects of their mission-critical operational processes. We continue to integrate best practice delivery processes into our service delivery capabilities to improve quality and service levels and to increase operational efficiencies. The markets in which we serve are competitive with both large and small businesses, as well as global companies:

● Bills and payments aggregators and processors;

17

Table of Contents

● Niche service providers in specific verticals and/or geographies.

Regulation and Compliance

We handle, directly or indirectly through client contracts and business associate agreements, a significant amount of sensitive information, including personal, financial and health related information. As a result, we are subject to federal, state and local privacy and information security laws and regulations, including the Gramm Leach Bliley Act (“GLBA”), the Health Insurance Portability and Accountability Act (“HIPAA”) and the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). We are also subject to sector specific confidentiality, data use, and security requirements imposed by certain of our clients, including regulated financial institutions and healthcare entities. Further, we are subject to country specific rules governing data protection, records retention, and information handling in the jurisdictions in which we operate outside the United States.

Our commitment to global compliance is underscored by our adherence to a rigorous framework of international certifications and independent third-party assessments. These certifications include ISO 9001 (Quality Management Systems), ISO/IEC 27001 (Information Security Management), ISO 22301 (Business Continuity Management), and ISO/IEC 28000 (Supply Chain Security Management). Furthermore, our operations are supported by a broad suite of System and Organization Controls (“SOC”) 1 Type II and SOC 2 Type II reports. These independent assessments are intended to provide a foundation for the deployment of advanced automation and digital transformation initiatives for our clients. By maintaining this consistent third-party validation, we seek to maintain internal controls that remain robust and scalable as we evolve our service offerings.

We also maintain region specific certifications and align our services with recognized national and international standards, including the NF 461 electronic archiving certification in France; the German Federal Office for Information Security’s TR 03138 (RESISCAN) technical guideline for legally compliant replacement scanning in Germany; the Cyber Essentials Plus assurance scheme in the United Kingdom; and BS 10008, the British Standard governing the legal admissibility and evidential weight of electronically stored information. In addition, our information management and secure destruction practices are aligned with internationally recognized standards, including ISO 15489 for records management and BS EN 15713 for the secure destruction of confidential and sensitive material.

In addition, while many of our services to our clients are not directly regulated, those services must be delivered in a manner consistent with legal and procedural frameworks applicable to our clients. For example, our bankruptcy claims administration services must comply with requirements and deadlines established under the United States Bankruptcy Code and the Federal Rules of Civil Procedure. We also support clients that are subject to regulatory oversight, which may result in our operations being reviewed by those oversight bodies from time to time. Further, as a government contractor, we are subject to associated regulations, compliance obligations and performance requirements. Certain of our contracts also require us to meet specific information security standards or undergo periodic third party assessments or certifications.

Changes to existing laws, adoption of new laws or regulations, or failure to comply with applicable requirements may result in additional operational costs, required changes to our business practices, liability for monetary damages or penalties, governmental inquiries or investigations, criminal or civil enforcement actions, restrictions on our ability to collect, use or process information, and/or allegations of contractual nonperformance. Any of these outcomes could materially adversely affect our business, financial condition, results of operations, profitability or cash flows.

Privacy and Information Security Regulations

Data privacy and information security laws in the United States and internationally apply to the access, collection, processing, transfer, use, storage, retention, and destruction of personal information in connection with our services. In the United States, our financial institution clients are subject to GLBA, and we are contractually bound to maintain controls consistent with that framework. We also perform services for healthcare companies and are therefore subject to HIPAA, HITECH, and related regulations. We additionally perform credit related services that require us to comply with payment card standards, including the PCI Data Security Standard. Federal and state privacy and information security laws, including consumer protection statutes, may also apply directly to our operations.

18

Table of Contents

Privacy laws often require notification to affected individuals, state and federal regulators, and consumer reporting agencies in the event of certain security incidents resulting in unauthorized access to or disclosure of personal information. State data breach notification laws in the United States continue to expand in scope and complexity, and several states have enacted comprehensive privacy laws imposing additional compliance obligations, such as consumer rights management, data minimization requirements, and restrictions on certain automated processing activities.

Privacy laws outside the United States may impose additional or more restrictive obligations. For example, in the European Union, the General Data Protection Regulation (“GDPR”) imposes significant requirements relating to data protection, cross border data transfers, data subject rights, breach response and notification, and security safeguards, and provides for substantial penalties for non-compliance. Many other jurisdictions in which we operate have adopted, or continue to adopt, GDPR inspired privacy regimes, each with its own regulatory, notice, and data transfer requirements.

Public attention to data protection, cybersecurity incidents, and the use of personal information continues to increase, accompanied by evolving legislation, regulations and case law aimed at strengthening consumer privacy, information security, and governance of data use. Emerging regulatory frameworks relating to artificial intelligence and automated decision making may also impose additional compliance considerations for companies that process large volumes of data, including service providers such as us. While we believe we are compliant with our regulatory obligations, information security threats continue to evolve, resulting in increased risk and exposure. Legislation, regulation, litigation, court rulings, enforcement activities or other events could expose us to increased costs, liability or reputational harm.

Human Capital

We consider our employees to be the foundation for our growth and success.

As of December 31, 2025, we had approximately 10,600 employees. We have a global workforce with approximately half of our employees located in Americas and EMEA, and the remainder located in India and the Philippines. Our employee count fluctuates from time to time based upon the timing and duration of our engagements. Our senior leadership team has extensive experience with workflow automation, and while we have grown through a number of acquisitions, we have retained an experienced and cohesive leadership team.

We are fully committed to developing and fostering a culture of diversity and inclusion and understand that our ability to identify and hire talented individuals from all backgrounds and perspectives is key to our continued success.

19

Table of Contents

We locate our operation centers in areas where the value proposition it offers is attractive relative to other local opportunities, resulting in an engaged and educated multi-lingual workforce that is able to make a meaningful global contribution from their local marketplace. We offer our employees a focused set of training programs to increase their skills and leadership capabilities with the goal of creating a long-term funnel of talent to support the Company’s continued growth. Additionally, our proprietary platforms enable rapid learning and facilitate knowledge transfer among employees, reducing training time.

Reverse Stock Split

On December 12, 2025, the Company filed a Certificate of Amendment to its Third Amended and Restated Certificate of Incorporation with the Secretary of State of Delaware, to effect a one (1) share for ten (10) shares reverse stock split of the Company’s Common Stock (the “Reverse Stock Split”). The Reverse Stock Split had no effect on the par value of the Common Stock. Fractional shares were not issued as a result of the Reverse Stock Split. Stockholders who would otherwise have been entitled to a fractional share of Common Stock instead received cash in lieu of fractional shares based on the closing sales price of the Company’s Common Stock as quoted on the Nasdaq on December 12, 2025.

The Reverse Stock Split resulted in a proportionate adjustment to the per share exercise price and the number of shares of Common Stock issuable upon the exercise of our outstanding stock options and warrants. As a result of the Reverse Stock Split, the number of shares of Common Stock issuable on exercise of each of our warrants has decreased in proportion to such decrease in outstanding shares of Common Stock. As a result, each private and public warrant previously exercisable for one share at $11.50 per one share, is now exercisable for one-tenth of a share at $11.50 per one-tenth of a share ($115.00 per share). Each ETI warrant previously exercisable for one share at $4.98 per one share, is now exercisable for one-tenth of a share at $4.98 per one-tenth of a share ($49.80 per share)

Except as otherwise indicated, all share and per share information herein gives pro forma effect to the Reverse Stock Split.

Status as a Smaller Reporting Company

We are a “smaller reporting company” as defined in Rule 12b-2 of the Exchange Act and have elected to take advantage of certain of the scaled disclosures available for smaller reporting companies.

Available Information

Our website address is www.xbpglobal.com. We are not including the information provided on our website as a part of, or incorporating it by reference into, this Annual Report. We make available free of charge through our website our annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K, and amendments to these reports, as soon as reasonably practicable after we electronically file such material with, or furnish such material to, the SEC. In addition, we make available our code of ethics entitled “Code of Ethics and Business Conduct” free of charge through our website. We intend to post on our website all disclosures that are required by law or Nasdaq listing standards concerning any amendments to, or waivers from, any provision of our code of ethics.

The SEC maintains an internet site that contains reports, proxy and information statements and other information regarding issuers that file electronically with the SEC at www.sec.gov. The information contained on the websites referenced in this Annual Report is not incorporated by reference into this filing.

20

Table of Contents

ITEM 1A. RISK FACTORS

In the course of conducting our business operations, we are exposed to a variety of risks, some of which are inherent in our industry and others of which are more specific to our own business. In addition to the other information set forth in this Annual Report on Form 10-K, and other filings we have made and will make in the future with the SEC, you should carefully consider the following risk factors and uncertainties, which could materially affect the Company’s business, financial condition and operating results. Additional risks and uncertainties not currently known to management or that management currently deems immaterial also may materially, adversely affect the Company’s business, financial condition or operating results.

Risks Relating to our Business

Our strategic focus on automating and modernizing the workplace through artificial intelligence involves significant execution risks, and failure to successfully develop or monetize these solutions could materially harm our business.

A key element of our corporate strategy is the deployment of artificial intelligence, including agentic AI, machine learning, and intelligent workflow automation, into our core platforms to automate enterprise workflows. Executing this strategy requires substantial upfront and ongoing investments in technology infrastructure, proprietary data modeling, and specialized engineering talent. The market for AI solutions is rapidly evolving, highly competitive, and subject to shifting client preferences. If our AI-enabled platforms fail to deliver anticipated efficiencies, if clients resist adopting these automated workflows, or if we are unable to keep pace with the technological advancements of larger, better-funded competitors, our strategy may not succeed. Furthermore, the increasing integration of AI into mission-critical and highly regulated workflows exposes us to complex regulatory, execution and implementation risks. As the Company deploys AI to automate workflows previously performed by its own workforce, it faces the risk that this automation displaces higher-margin managed service revenues faster than new AI-enabled revenue streams can replace them, compressing margins during the transition period. If we are unable to successfully develop, deploy, and monetize our AI-driven solutions, our competitive position, revenue growth, and financial condition could be materially and adversely affected.

Many of the Company’s client contracts may be terminated without cause and with limited notice, and government contracts subject it to audits, investigations and potential penalties that could result in contract termination, financial liability and reputational damage.

Many of the Company’s client contracts may be terminated by its clients without cause and without any fee or penalty, with only limited notice. The Company may not be able to replace a client that elects to terminate or fails to renew its contract with it. In addition, a portion of the Company’s revenues is derived from contracts with the U.S. federal and state governments and their agencies and from contracts with foreign governments and their agencies. Government entities typically finance projects through appropriated funds. The public procurement environment is unpredictable and this could adversely affect the Company’s ability to perform work under new and existing contracts. Any such reductions in revenue could materially adversely affect the Company’s business, results of operations and financial condition.

Moreover, government contracts are generally subject to a right to conduct audits and investigations by government agencies. If a government entity determines that there were contractual breaches or improper or illegal activities related to any government contracts, the Company may be subject to various civil and criminal penalties and administrative sanctions, which may include termination of contracts, forfeiture of profits, suspension of payments, fines and suspensions or debarment from doing business with the government. Further, the negative publicity that could arise from any such penalties, sanctions or findings in such audits or investigations could have an adverse effect on the Company’s reputation in the industry and reduce its ability to compete for new contracts and could materially adversely affect the Company’s results of operations and financial condition.

The Company’s long-term contracts are based on cost estimates that may prove inaccurate, and its inability to offset increased operational costs with corresponding fee increases could materially impact its financial performance.

The pricing and other terms of the Company’s client contracts are based on estimates and assumptions the Company makes at the time it enters into those contracts. These estimates reflect the Company’s best judgments

21

Table of Contents

regarding the nature of the engagement and its expected costs to provide the contracted services and could differ from actual results. Not all of the Company’s larger long-term contracts allow for escalation of fees as the Company’s costs of operation increase and those that allow for such escalations do not always allow fee increases at rates comparable to cost increases that the Company experiences. Where the Company cannot negotiate long-term contract terms that provide for fee adjustments to reflect increases in its cost of service delivery, the Company’s business, results of operations and financial condition could be materially impacted. The Company has entered into, and expects to continue to enter into, contracts in which fees are contingent in whole or in part on achieving specified performance metrics or client outcomes. These arrangements introduce revenue variability and the risk that the Company bears costs without commensurate compensation if target outcomes are not met or are disputed.

The Company’s workflow automation solutions require extended selling cycles and implementation periods, which can strain finances through upfront expenses without immediate revenue and create risks of contract loss after significant investment.

The Company often faces long selling cycles to secure new contracts for its workflow automation solutions. If the Company is successful in obtaining an engagement, the selling cycle can be followed by a long implementation period. Delays in internal approvals, technology implementations or client decisions can prolong these cycles. Even if the Company succeeds in developing a relationship with a potential client and begins to discuss the services in detail, the potential client may choose a competitor or decide to retain the work in-house prior to the time a contract is signed. Additionally, the Company may not begin receiving revenue until after the implementation period and its solution is fully operational, leading to upfront expenses without immediate profits. These extended cycles can strain finances, especially when hiring new staff before revenue collection. The Company’s inability to obtain contractual commitments after a selling cycle, maintain contractual commitments after the implementation period or limit expenses prior to the receipt of corresponding revenue may have a material adverse effect on its business, results of operations and financial condition.

The Company operates in a highly competitive industry and faces significant competition from companies with stronger financial resources, better brand recognition and lower-cost operations, as well as from clients who may choose to perform services in-house.

The Company’s industry is highly competitive, fragmented and subject to rapid change. The Company competes primarily against local, national, regional and large multi-national information and payment technology companies, including focused workflow automation companies based in offshore locations, workflow automation divisions of information technology companies, other workflow automation and consulting services and digital transformation solution providers and the in-house capabilities of the Company’s clients and potential clients. These competitors may include entrants from adjacent industries or entrants in geographic locations with lower costs than those in which the Company operates.

As agentic AI, LLMs, and intelligent document processing tools become increasingly accessible, we expect competition to intensify. We may face new competitive pressures from AI-native software startups and major global technology companies entering the workflow automation space. Furthermore, the proliferation of highly capable, off-the-shelf AI tools may increasingly empower our clients and potential clients to seamlessly perform complex digital transformations and workflow automations in-house, significantly reducing their reliance on our services and managed platforms. Increased competition, the Company’s inability to compete successfully against competitors, pricing pressures or loss of market share could result in reduced operating margins, which could materially adversely affect the Company’s business, results of operations and financial condition.

The Company operates in an industry characterized by rapid technological change, and failure to develop competitive technology solutions, adapt to digital transformation trends or respond to evolving client needs could result in loss of market share and revenue.

If the Company fails to accurately anticipate and meet its clients’ needs through the development of new technologies and service offerings or if its new services are not widely accepted, the Company could lose market share and clients to its competitors, which could materially adversely affect its results of operations and financial condition. More specifically, the workflow automation industry is characterized by rapid technological change, evolving industry standards and changing client preferences, especially with regards to AI and intelligent workflow automation. While we

22

Table of Contents

have made investments in AI-related technologies, the rapid development of artificial general intelligence by third parties may render our proprietary decisioning engines less competitive. The success of the Company’s business depends, in part, upon its ability to develop technology and solutions that keep pace with changes in its industry and the industries of its clients. Although the Company has made, and will continue to make, investments in the research, design and development of new technology and platform-driven solutions, it may not be successful in addressing these changes on a timely basis or in marketing the changes it implements. In addition, products or technologies developed by others may render the Company’s services uncompetitive or obsolete. Failure to address these developments could have a material adverse effect on the Company’s business, results of operations and financial condition.

In addition, existing and potential clients are actively shifting their businesses away from paper-based environments to electronic environments with reduced needs for physical document management and processing. This shift may result in decreased demand for the physical document management services the Company provides such that its business and revenues may become more reliant on technology-based services in electronic environments, which are typically provided at lower prices compared to physical document management services. Although the Company has solutions for clients seeking to make these types of transitions, a significant shift by its clients away from physical documents to non-paper-based technologies, whether now existing or developed in the future, could adversely affect its business, results of operations and financial condition.

The Company’s reliance on third-party hardware and software creates risks of service disruptions, increased costs and operational delays if vendors discontinue products or raise prices, or if it encounters defects in third-party components.

Although the Company has developed its platform-driven solutions internally, it relies, in some cases, on third-party hardware and software in connection with its service offerings, which it purchases, leases or licenses from third-party vendors. Detecting design defects or software errors in third-party hardware or software is challenging due to their complexity and unique specifications. Any errors or defects in third-party hardware or software incorporated into the Company’s service offerings may result in a delay or loss of revenue, diversion of resources, damage to its reputation or potential claims against the Company.

Further, such third-party hardware and software may not continue to be available on commercially reasonable terms or at all. Any loss of the right to use any of this hardware or software, or any increases in the price charged by third-party vendors, could negatively affect the Company’s business until equivalent technology is either developed by the Company or, if available from other third-party vendors, is identified, obtained and integrated on commercially reasonable terms. Further, changing hardware vendors or software licensors could detract from management’s ability to focus on the ongoing operations of the Company’s business or could cause delays in the operations of its business.

Certain higher-risk engagements involving significant financial sums, sensitive data or complex legal matters could expose the Company to increased liability, reputational damage and operational disruption despite its risk mitigation efforts.

The Company provides certain workflow automation solutions for clients that, for financial, legal or other reasons, may present higher risks compared to other types of claims processing or document management engagements. Examples of higher risk engagements include class action and other legal distributions involving significant sums of money and engagements where the Company receives or processes sensitive data, including personal consumer or private health information.

As the Company’s clients use its services for important aspects of their businesses, any errors, defects, disruptions in service or other performance problems could hurt the Company’s reputation and may damage its clients’ businesses. As a result, clients could elect not to renew the Company’s services or delay or withhold payment. The Company could also lose future sales or clients may make warranty or other claims against it. These consequences have resulted, and may in the future result, in increased allowances for expected credit losses, lengthened collection cycles for accounts receivable, and increased expense and risk of litigation.

We rely on dedicated human-in-the-loop exception handling to oversee our agentic AI automation, and this control framework is subject to human error. Because our clients use our services for mission-critical aspects of their businesses—such as healthcare claims adjudication and large-scale legal settlement distributions—any failure by our

23

Table of Contents

human operators to identify sophisticated AI errors, hallucinations, or processing defects could hurt our reputation, severely damage our clients’ businesses, and expose us to substantial financial and legal liabilities

Any actual or alleged error or omission by the Company, its clients or other third parties or possible fraudulent activity in one or more of these higher-risk engagements could result in the diversion of management resources, damage to the Company’s reputation, increased service costs or impaired market acceptance of the Company’s services, any of which could materially adversely affect the Company’s business and financial condition.

The Company’s business depends on protecting its intellectual property and avoiding infringement claims from others, and failure in either area could result in loss of competitive advantage, substantial damages or operational restrictions.

The Company’s success depends in part on certain methodologies and practices it utilizes in developing and implementing applications and other proprietary intellectual property rights. In order to protect such rights, the Company relies upon a combination of nondisclosure and other contractual arrangements, as well as trade secret, copyright, trademark and patent laws. The Company also generally enters into confidentiality agreements with its employees, clients and potential clients and limits access to and distribution of its proprietary information. There can be no assurance that the laws, rules, regulations and treaties in effect in the United States, Europe, India and the other jurisdictions in which the Company operates and the contractual and other protective measures it takes are adequate to protect the Company from misappropriation or unauthorized use of its intellectual property, or that such laws will not change. There can be no assurance that the resources invested by the Company to protect its intellectual property will be sufficient or that its intellectual property portfolio will adequately deter misappropriation or improper use of its technology, and its intellectual property rights may not prevent competitors from independently developing or selling similar products and services. The Company may not be able to detect unauthorized use and take appropriate steps to enforce its rights, and any such steps may be costly and unsuccessful. Infringement by others of the Company’s intellectual property, including the costs of enforcing its intellectual property rights, may have a material adverse effect on its business, results of operations and financial condition. The Company could also face competition in some countries where it has not invested in an intellectual property portfolio.

If the Company is not able to protect its intellectual property, the value of its brand and other intangible assets may be diminished, and its business may be adversely affected. The value of, or the Company’s ability to use, its intellectual property may also be negatively impacted by dependencies on third parties, such as its ability to obtain or renew on commercially reasonable terms licenses that it needs in the future, or its ability to secure or retain ownership or rights to use data in certain software analytics or services offerings. In addition, if the Company is found to infringe any third-party rights, it could be required to pay substantial damages or it could be enjoined from offering some of its products and services. Any such circumstances may have a material adverse effect on the Company’s business, results of operations and financial condition.

The Company’s revenues are concentrated, making it vulnerable to downturns, consolidation or regulatory changes in specific sectors.

A substantial portion of the Company’s revenues are derived from specific industries. The Company’s success largely depends on continued demand for its services from clients in these industries, and a downturn or reversal of the demand for workflow automation, or the introduction of regulations that restrict or discourage companies from engaging the Company’s services, could materially adversely affect its business, financial condition and results of operations. Further, consolidation in any of these industries or combinations or mergers, particularly involving the Company’s clients, may decrease the number of potential clients for its services. For example, the Company has been affected by the worsening of economic conditions and significant consolidation in the financial services industry and continuation of this trend may negatively affect its revenues and profitability.

The Company’s competitive bidding process for commercial and government contracts requires substantial upfront investment with uncertain returns and exposes it to protest risks, cost estimation challenges and opportunity costs.

Many of the contracts awarded to the Company through competitive bidding procedures are extremely complex and require the investment of significant resources in order to prepare accurate bids and proposals. Competitive bidding imposes substantial costs and presents a number of risks that may adversely affect the Company’s financial position,

24

Table of Contents

including: (i) the substantial cost and managerial time and effort that the Company spends to prepare bids and proposals for contracts that it may or may not be awarded; (ii) the need to estimate accurately the resources and costs that will be required to implement and service any contracts the Company is awarded, sometimes in advance of the final determination of its full scope and design; (iii) the expense and delay that may arise if the Company’s competitors protest or challenge awards made to it pursuant to competitive bidding and the risk that such protests or challenges could result in the requirement to resubmit bids and in the termination, reduction or modification of the awarded contracts, or may eventually lead to litigation; and (iv) the opportunity cost of not bidding on and winning other contracts the Company might otherwise pursue.

The Company’s profitability depends on its ability to obtain adequate pricing for its services in competitive markets and maintain cost efficiency through restructuring actions, technology initiatives and global delivery centers, and its failure to achieve productivity improvements or absorb pricing pressures could materially adversely affect its results of operations, particularly given operational risks in developing countries and increasingly stringent service requirements.

The Company’s success depends on its ability to obtain adequate pricing for its services. Depending on competitive market factors, prices the Company obtains for its services may decline from previous levels. If the Company is unable to obtain adequate pricing for its services, its results of operations and financial condition could be materially and adversely affected. In addition, the Company’s contracts are increasingly requiring tighter timelines for implementation as well as more stringent service level metrics. These requirements make the bidding process for new contracts more difficult and require the Company to adequately consider these requirements in the pricing of its services.

The Company, from time to time, engages in restructuring actions to reduce its cost structure. If the Company is unable to maintain its cost base at or below current levels or sustain process and systems changes resulting from prior restructuring actions, such failures could materially adversely affect its results of operations and financial condition. The Company’s ability to sustain and improve profit margins depends on a number of factors, including its ability to continue improving the cost efficiency of its operations through programs such as process automation, its capacity to absorb pricing pressures on its services through cost improvements and the successful completion of information technology initiatives. If any of these factors adversely materialize or if the Company is unable to achieve and maintain productivity improvements through restructuring actions or information technology initiatives, its ability to offset labor cost inflation and competitive price pressures would be impaired, each of which could materially adversely affect its results of operations and financial condition.

Failure to comply with data privacy and data protection laws in processing and transferring personal data across jurisdictions may subject the Company to penalties and other adverse consequences, and the enactment of more stringent data privacy and data protection laws may increase its compliance costs.

Privacy and data security regulations continue to become more complex and have greater consequences. For example, Europe’s GDPR imposes several stringent requirements for controllers and processors of personal data, including higher standards for obtaining consent from individuals to process their personal data, more robust disclosures to individuals and a strengthened individual data rights regime, and shortened timelines for data breach notifications. Failure to comply with the requirements of the GDPR and the applicable national data protection laws of the European Union member states may result in fines of up to €20,000,000 or up to 4% of the total worldwide annual turnover of the preceding financial year.

In addition, data privacy laws in the United States, similarly impose or may impose obligations on the Company and many of its clients, potentially as both businesses and service providers. These laws continue to evolve, and as various states introduce similar proposals, the Company and its clients could be exposed to additional regulatory burdens. In addition, India’s Digital Personal Data Protection Act and its implementing rules impose consent, processing and breach notification obligations that may apply to the Company’s Indian operations and increase its compliance obligations and costs.

Evolving data privacy and data protection laws may require the Company to make changes to its practices and services and may also increase its potential liability exposure through new or higher potential penalties for noncompliance. Furthermore, privacy laws and regulations are subject to differing interpretations and may be inconsistent among jurisdictions. The Company’s clients expect it to meet voluntary certification and other standards

25

Table of Contents

established by third parties, such as PCI Data Security Standard. If the Company is unable to maintain these certifications or meet these standards, it could adversely affect the Company’s ability to provide its solutions to certain clients and could harm its business.

The costs of compliance with, and other burdens imposed by, privacy laws, regulations and standards may limit the use and adoption of the Company’s services, reduce overall demand for its services, make it more difficult to meet expectations from its commitments to clients and its clients’ customers, lead to significant fines, penalties or liabilities for noncompliance, impact its reputation or slow the pace at which it closes sales transactions, in particular where clients request specific warranties and indemnity for noncompliance with privacy laws, any of which could harm the Company’s business.

Furthermore, the uncertain and shifting regulatory environment may cause the Company’s clients or its clients’ customers to resist providing the data necessary to allow the Company’s clients to use its services effectively. In addition, new services developed or acquired in connection with changing events may expose the Company to liability or regulatory risk. Even the perception that the privacy and security of personal information are not satisfactorily protected or do not meet regulatory requirements could inhibit sales of the Company’s products or services and could limit adoption of its cloud-based solutions.

The Company must maintain strict physical and information security standards subject to regular client and third-party audits, and failure to meet these requirements or negative audit findings could result in contract termination and reputational damage.

Many of the Company’s client contracts require that it maintain certain physical and/or information security standards, and, in certain cases, the Company permits a client to audit its compliance with these standards. Any failure to meet such standards or pass such audits may have a material adverse impact on the Company’s business. Further, clients from time to time may require stricter physical and/or information security than they negotiated in their contracts and may condition continued volumes and business on the satisfaction of such additional requirements. Some of these requirements may be expensive to implement or maintain and may not be factored into the Company’s contract pricing. Further, on an annual basis, the Company obtains third-party audits of certain of its locations in accordance with third-party attestation standards. Many of the Company’s clients expect that it will engage in such procedures and report to them the results. Negative findings in such an audit and/or the failure to adequately remediate in a timely fashion such negative findings may cause clients to terminate their contracts or otherwise have a material adverse effect on the Company’s reputation, results of operations and financial condition.

The Company faces significant cybersecurity risks and vulnerability to data breaches from sophisticated cyber threats, employee errors and third-party compromises, which could result in loss of client confidence, business disruption, legal liability and substantial financial costs.

The Company collects and retains large volumes of internal and client data, including personally identifiable information and other sensitive data, both physically and electronically, and its various information technology systems enter, process, summarize and report such data. The Company also maintains personally identifiable information about its employees. Safeguarding client, employee and its own data is a key priority for the Company, and its clients and employees have come to rely on the Company for the protection of its information.

Despite the Company’s efforts to protect sensitive, confidential or personal data or information, the Company can provide no assurances that its security measures designed to protect the data of its clients and its clients’ customers will always be effective. The Company’s services and underlying infrastructure may in the future be materially breached or compromised as a result of the following:

26

Table of Contents

● vulnerabilities existing within new technologies and infrastructures;

The Company has experienced, and expects to continue to experience, attempted intrusions and security incidents of varying severity. A security breach or incident could result in unauthorized parties obtaining access to, or the denial of authorized access to, the Company’s IT systems or data, or its clients’ systems or data, including intellectual property and proprietary, sensitive or other confidential information. A security breach could also result in a loss of confidence in the security of the Company’s services, damage its reputation, negatively impact its future sales, disrupt its business and lead to increases in insurance premiums and legal, regulatory and financial exposure and liability. Any resulting interruptions in the Company’s services or the ability of its clients to access its services could result in a loss of potential or existing clients and harm its business.

The Company’s increasing integration of AI into its offerings presents risks of reputational harm, legal liability, increased costs, and competitive disadvantage if AI applications generate controversy, perform inadequately or require substantial investment in development and testing.

The Company is increasingly building Artificial Intelligence (“AI”) into many of its offerings. As with many innovations, AI presents additional risks and challenges that could affect the Company’s business. If the Company enables or offers AI-enabled solutions that draw controversy due to their perceived or actual impact on human rights, privacy, employment or in other social contexts, it may experience reputational harm, competitive harm or legal liability. Data practices by the Company or others that result in controversy could also impair the acceptance of AI solutions. This in turn could undermine the decisions, predictions or analysis that AI applications produce, subjecting the Company to competitive harm, legal liability or reputational harm. The rapid evolution of AI will require the application of resources to develop, test and maintain the Company’s products and services to help ensure that AI is implemented ethically in order to minimize unintended, harmful impact.

Geopolitical tensions and global macroeconomic uncertainty could adversely affect our business, financial condition, and results of operations.

Our operations and the businesses of our clients are subject to risks associated with international geopolitical tensions and broader macroeconomic instability. Recent and ongoing global conflicts, such as those in Eastern Europe and the Middle East, as well as evolving trade policies and diplomatic tensions between the U.S. and other nations, have contributed to significant global economic uncertainty. These events have led to, and may continue to result in, increased inflationary pressures, currency exchange rate volatility, supply chain disruptions, and a heightened risk of state-sponsored cyberattacks. Changes in trade policy, including the imposition of new or increased tariffs on technology hardware, equipment, and components used in the Company’s operations, could increase operating costs and, to the extent such policies affect the cost structures of the Company’s clients, may reduce demand for the Company’s services. Furthermore, prolonged macroeconomic uncertainty could cause our current and prospective clients to delay, reduce, or cancel their spending on workflow automation and technology services, which would result in lower transaction volumes. If global economic conditions deteriorate or current geopolitical conflicts escalate, our business, financial condition, and results of operations could be materially and adversely affected.

27

Table of Contents

Currency fluctuations between the U.S. Dollar and foreign currencies in the Company’s international operations could materially affect its recorded assets, liabilities, revenues, and operating margins.

The functional currencies of many of the Company’s businesses outside of the United States are the local currencies. Changes in exchange rates between these foreign currencies and the U.S. Dollar will affect the recorded levels of the Company’s assets, liabilities, net sales, cost of goods sold and operating margins and could result in exchange gains or losses. The primary foreign currencies to which the Company has exposure are the European Union Euro, Swedish Krona, British Pound Sterling, Canadian Dollar and Indian Rupee. Exchange rates between these currencies and the U.S. Dollar in recent years have fluctuated significantly and may do so in the future. The Company’s operating results and profitability may be affected by any volatility in currency exchange rates and its ability to effectively manage currency transaction and translation risks. To the extent the U.S. Dollar strengthens against foreign currencies, the Company’s foreign revenues and profits will be reduced when converted into and reported in U.S. Dollars.

Fluctuations in raw material costs, particularly paper, ink and energy, may increase the Company’s operational expenses and reduce demand for its printing services, and it may be unable to pass these costs on to clients or benefit from by-product sales.

Purchases of paper, ink, energy and other raw materials represent a large portion of the Company’s costs. Increases in the costs of these inputs may increase the Company’s costs and it may not be able to pass these costs on to clients through higher prices. In addition, the Company may not be able to resell wastepaper and other print-related by-products or may be adversely impacted by decreases in the prices for these by-products. Increases in the cost of materials may adversely impact clients’ demand for the Company’s printing and printing-related services.

The Company’s ability to attract and retain qualified personnel and to manage increasing labor costs and evolving employment law obligations across its global operations could materially affect its business and results of operations.

The Company’s operations depend significantly on attracting and retaining personnel with specialized expertise in workflow automation, AI, and technology integration. Competition for such talent is intense, particularly from larger technology companies with greater compensation resources, and the Company’s ability to attract and retain key technical and managerial personnel may be further affected by uncertainty associated with the Restructuring. The failure to attract or retain such personnel could impair the Company’s ability to execute its strategy and adversely affect its operations. Competition for skilled labor is intense and the costs associated with recruiting and training employees can be significant. Increased labor costs due to competition, increased minimum wage or employee benefits costs (including various federal, state and local actions to increase minimum wages), unionization activity or other factors would adversely impact our cost of sales and operating expenses.

The Company is also subject to applicable rules and regulations relating to its relationship with its employees, including minimum wage and break requirements, health benefits, unemployment and sales taxes, overtime, working conditions and immigration status. Legislated increases in the minimum wage and increases in additional labor cost components, such as employee benefit costs, workers’ compensation insurance rates, compliance costs and fines, as well as the cost of litigation in connection with these regulations, would increase our labor costs. In addition, many employers, including the Company, have been subject to actions brought by governmental agencies and private individuals under wage-hour laws on a variety of claims, such as improper classification of workers as exempt from overtime pay requirements and failure to pay overtime wages or record breaks properly, with such actions sometimes brought as class actions or under “private attorney general” statutes. Employment litigation risks, including wage-hour disputes, could result in substantial liabilities and expenses, diverting management attention and elevating labor costs.

The Company has significant operations in India, where India’s evolving Labour Codes may alter the Company’s obligations with respect to wages, employee benefits, provident fund contributions, gratuity accruals, and social security. The extent and timing of adoption at the state level introduce compliance uncertainty and could adversely impact the Company’s cost of sales and operating expenses.

28

Table of Contents

The Company has identified material weaknesses in its internal control over financial reporting, and a failure to remediate such material weaknesses in a timely manner could impair its ability to produce accurate financial statements, result in restatements, damage investor confidence and potentially lead to delisting from Nasdaq.

As a public company, the Company is subject to the reporting requirements of the Exchange Act, the Sarbanes-Oxley Act, and the listing standards of Nasdaq. The Sarbanes-Oxley Act requires, among other things, that the Company maintain effective disclosure controls and procedures and internal control over financial reporting. In order to maintain and improve the effectiveness of its disclosure controls and procedures and internal control over financial reporting, the Company has expended, and anticipates that it will continue to expend, significant resources, including accounting-related costs and significant management oversight.

As disclosed in our Quarterly Report on Form 10-Q for the quarter ended September 30, 2025, the Company has previously identified material weaknesses in the areas of goodwill impairment and financial reporting processes, risk assessment, information and communication, and monitoring activities and the control environment. These material weaknesses were the result of the Company’s acquisition of BPA. Material weakness in BPAs internal control over financial reporting were previously reported in the risk factors section of the Company’s Proxy Statement Pursuant to Section 14(a) of the Securities Exchange Act of 1934 filed with the SEC on July 15, 2025. BPA had concluded its internal control over financial reporting was not effective as of December 31, 2024 due to pervasive material weaknesses in its internal control over financial reporting. The Company reassessed the controls of the combined entity (XBP Global Holdings, Inc.) after the Business Combination and determined that the material weakness discussed above persisted.

A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of our annual or interim financial statements will not be prevented or detected on a timely basis. Based on the results of its evaluation, management concluded that as of December 31, 2025, the Company’s disclosure controls and procedures were not effective due to the material weaknesses in financial reporting, ineffective control environment, and ineffective information and communication, as described above.

In order to remediate these material weaknesses, the Company is taking remediation measures with appropriate executive sponsorship and with the assistance of third-party specialists. These remediation measures may be time-consuming and costly and there is no assurance that these measures will ultimately have the intended effects. Additionally, the measures taken to date, and actions that may be taken in the future, may not be sufficient to (a) remediate in a timely manner or at all the control deficiencies that led to the material weaknesses or (b) prevent or avoid potential future material weaknesses due to a failure to implement and maintain adequate internal control over financial reporting or circumvention of these controls. In addition, even if the Company is successful in strengthening its controls and procedures, in the future these controls and procedures may not be adequate to prevent or identify irregularities or errors or to facilitate the fair presentation of its financial statements.

If the Company is unable to remediate the material weaknesses, or if any new material weaknesses are discovered in the future, then it may be unable to maintain compliance with the requirements of securities laws, stock exchange listing rules or debt instrument covenants regarding timely filing of information; it could lose access to sources of capital or liquidity; and investors may lose confidence in its financial reporting and its stock price may decline as a result. Remediation measures that have been taken to date, or any future remediation measures, may be insufficient to remediate the material weaknesses or avoid potential future material weaknesses or the perception thereof.

As a result of the material weaknesses described above and other related matters raised or that may in the future be identified, the Company faces potential for adverse regulatory consequences, including investigations, penalties or suspensions by the SEC or Nasdaq, litigation or other disputes which may include, among others, claims invoking the federal and state securities laws, contractual claims or other claims arising from the material weaknesses in its internal control over financial reporting and the preparation of its consolidated financial statements. Any such regulatory consequences, litigation, claim or dispute, whether successful or not, could subject the Company to additional costs, divert the attention of its management, or impair its reputation. Each of these consequences could have a material adverse effect on the Company’s business, reputation, results of operations and financial condition.

The Company may identify future material weaknesses in its internal controls over financial reporting or fail to meet the demands that will be placed upon it as a public company, including the requirements of the Sarbanes-Oxley

29

Table of Contents

Act, and it may be unable to accurately report its financial results, or report them within the timeframes required by law or stock exchange regulations. We can provide no assurance that the Company’s existing material weaknesses will be remediated or that additional material weaknesses will not exist or otherwise be discovered, any of which could adversely affect its reputation, results of operations and financial condition.

For a discussion of management’s evaluation of the Company’s disclosure controls and procedures and the material weaknesses identified, see Part II, Item 9A, “Controls and Procedures.”

Risks Relating to our Indebtedness

The Company’s substantial level of indebtedness could place it at a competitive disadvantage and limit its operational flexibility compared to less leveraged competitors.

As of December 31, 2025, the Company had total indebtedness of approximately $387.6 million, which could place the Company at a competitive disadvantage to less leveraged competitors because, among other things: it could affect the Company’s ability to satisfy its obligations under its indebtedness; a portion of its cash flow from operations will be used for debt service and therefore will be unavailable to support operations or for working capital, capital expenditures, expansion, acquisitions or general corporate or other purposes; the Company’s ability to refinance its then-existing debt, obtain additional debt financing or equity financing or pursue mergers, acquisitions and asset sales, on terms acceptable to them or at all, may be limited and its costs of borrowing may be increased; as a result of its significant indebtedness, the Company may be more vulnerable to economic downturns and its ability to withstand competitive pressures may be limited; and the Company’s operational flexibility in planning for, or reacting to, changes, opportunities and challenges in its businesses, including changes in the market sector in which it competes, changes in its business and strategic opportunities and adverse developments in its operations, may be severely limited.

The Company faces significant interest expense and principal repayment obligations, and its ability to service this debt depends on future performance and cash generation that is subject to factors beyond its control.

The Company’s ability to make payments on and to refinance its debt will depend on its future financial and operating performance and its ability to generate cash in the future. This, to a certain extent, is subject to general economic, business, financial, competitive, legislative, regulatory and other factors that are beyond the Company’s control.

There can be no assurance that the Company will be able to generate sufficient cash flow from operations or that sufficient future borrowings will be available to pay off the Company’s debt obligations. The Company may need to refinance all or a portion of its debt on or before maturity; however, there can be no assurance that it will be able to refinance any of its debt on commercially reasonable terms or at all. If the Company’s cash flows and capital resources are insufficient to fund its debt service obligations and other cash requirements, the Company could face substantial liquidity problems and could be forced to reduce or delay investments and capital expenditures, or to sell assets or operations, seek additional capital or restructure or refinance its indebtedness and settlement obligations. The Company may not be able to effect any such alternative measures, if necessary, on commercially reasonable terms or at all and, even if successful, such alternative actions may not allow the Company to meet its scheduled debt service obligations and settlement obligations. The agreements governing the Company’s indebtedness (a) have terms and conditions that restrict its ability to dispose of assets and the use of proceeds from any such disposition and (b) restrict its ability to raise debt capital.

The Company’s inability to generate sufficient cash flows to satisfy its debt obligations, or to refinance its indebtedness on commercially reasonable terms or at all, would materially and adversely affect its financial position and results of operations. If the Company cannot make scheduled payments on its debt, an event of default may result. An event of default may allow the creditors to accelerate the related debt as well as any other debt to which a cross-acceleration or cross-default provision applies. Significant fluctuations in prevailing interest rates, whether driven by inflationary pressures, central bank policy or broader macroeconomic conditions, could affect the Company's ability to refinance or service its substantial indebtedness on acceptable terms or at all. If the Company is unable to repay amounts outstanding under its financing agreements when due, the lenders thereunder could, subject to the terms of the financing agreements, seek to foreclose on the collateral that is pledged to secure the indebtedness outstanding under such facility.

30

Table of Contents

Substantially all of the Company’s assets are subject to liens that secure its indebtedness, giving secured lenders superior claims and foreclosure rights in the event of insolvency, liquidation or default.

Substantially all of the Company’s assets are subject to liens that secure its indebtedness. If the Company becomes insolvent or is liquidated, or if there is a default under certain financing agreements, and payment on any obligation thereunder is accelerated, its lenders would be entitled, subject to the applicable credit documents, to exercise the remedies available to a secured lender under applicable law, including foreclosure on the collateral that is pledged to secure the indebtedness thereunder, and they would have a claim on the assets securing the obligations under the applicable facility that would be superior to any claim of the holders of unsecured debt.

Restrictive covenants in the Company’s financing agreements, including financial, affirmative and negative covenants, limit management’s discretion and the Company’s operational and financial flexibility, and failure to comply could result in defaults, waivers, increased costs or acceleration of indebtedness.

The financing agreements governing the Company’s indebtedness contain customary financial covenants, affirmative covenants and negative covenants that restrict the Company’s ability to operate its business and pursue strategic objectives. These covenants, among other things, require the Company to satisfy specified financial ratios and performance metrics, comply with reporting and operational requirements, and limit its ability to incur additional indebtedness or liens, make restricted payments, dispose of certain assets, make certain investments, enter into transactions with affiliates, or engage in mergers, consolidations or other fundamental transactions.

Compliance with the Company’s restrictive financial covenants is tested as of specified measurement dates and may, from time to time, depend on the Company’s operating performance and the successful execution of planned transactions, including asset dispositions or other balance-sheet actions. Our ability to meet those financial covenants can be affected by events beyond our control, and we may not be able to meet those covenants. There can be no assurance that any planned transactions will be completed on a timely basis, on acceptable terms, or at all. Even if the Company is in compliance with its debt covenants as of the date of filing of this Annual Report, subsequent developments, or our inability to successfully execute planned transactions, could result in non-compliance in future periods.

As a result of these covenant restrictions, the Company may be limited in its ability to respond to changing market conditions, pursue business opportunities, fund operations or execute its growth strategy, any of which could materially and adversely affect its business, financial condition and results of operations. Any failure to comply with the restrictive covenants in the Company’s financing agreements could result in an event of default. In such circumstances, the Company may be required to seek waivers or amendments from its lenders, which may not be granted, and, if granted, could impose additional costs, more restrictive terms or other adverse conditions. The need to obtain waivers or amendments, or the occurrence of a default, may also require public disclosure and could adversely affect the Company’s liquidity, access to capital, reputation and business prospects. An event of default could permit lenders to accelerate the Company’s indebtedness and exercise remedies against collateral securing such indebtedness. A significant portion of our indebtedness could become immediately due and payable. We cannot be certain whether we would have, or would be able to obtain, sufficient funds to make these accelerated payments. If any such indebtedness is accelerated, our assets may not be sufficient to repay in full such indebtedness and our other indebtedness. If the Company is unable to repay amounts outstanding under its financing agreements when due, the lenders thereunder could, subject to the terms of the financing agreements, seek to foreclose on the collateral that is pledged to secure the indebtedness outstanding under such facility.

Despite restrictions in the Company’s debt agreements, it may be able to incur substantial additional indebtedness in the future, which could intensify current financial risks and strain its ability to obtain necessary financing for corporate purposes on acceptable terms.

The Company may be able to incur substantial additional indebtedness in the future, which could intensify the related risks that it currently faces. Although agreements governing the Company’s indebtedness restrict the incurrence of additional indebtedness, these restrictions are subject to a number of qualifications and exceptions and the additional indebtedness incurred in compliance with these restrictions could be substantial.

Moreover, the Company may need to seek additional financing for general corporate purposes. For example, it may need funds to make acquisitions or for capital expenditures needed to remain competitive in its market sector. The

31

Table of Contents

Company may be unable to obtain any desired additional financing on terms that are favorable or acceptable, including as a result of its debt levels or if there is a decline in the demand for its services or in the solvency of its clients, vendors or suppliers or other significantly unfavorable changes in economic conditions occur. Depending on market conditions, adequate funds may not be available to the Company on acceptable terms or at all, and it may be unable to fund expansion, successfully develop or enhance products or respond to competitive pressures, any of which could have a material adverse effect on the Company’s competitive position, business, financial condition, results of operations and cash flows.

Risks Resulting from the Restructuring

BPA recently emerged from bankruptcy, which may adversely affect the Company’s business and relationships.

BPA emerged from bankruptcy on July 29, 2025. It is possible that BPA’s bankruptcy filing, and its subsequent emergence from bankruptcy, may adversely affect the Company’s business and relationships with clients, vendors, contractors or employees. Due to uncertainties, many risks exist, including the following:

The occurrence of one or more of these events could have a material and adverse effect on the Company’s reputation, results of operations and financial condition.

The Company’s historical financial statements are not comparable to the information contained in the Company’s financial statements after the application of fresh-start accounting following the Restructuring.

Following the Restructuring, the Predecessor (as defined below) met the criteria and was required to adopt fresh start accounting in accordance with ASC 852, Reorganizations, which on the Emergence Date resulted in a new entity, the Successor, for financial reporting purposes, with no beginning retained earnings or deficit as of the fresh start reporting date. Financial information prior to the Emergence Date is referred to as “Predecessor” company information, which reflects the combined historical financial statements of BPA prepared using BPA’s previous combined basis of accounting. The financial information beginning August 1, 2025 is referred to as “Successor” company information and reflects the consolidated financial statements of XBP Global, including the financial statement effects of recording fair value adjustments and the capital structure resulting from the Business Combination and fresh start accounting of BPA.

Fresh start accounting requires that new fair values be established for BPA’s assets, liabilities and equity as of the Convenience Date (July 31, 2025), and therefore certain values and operational results of the consolidated financial statements subsequent to July 31, 2025 are not comparable to those in the Company’s consolidated financial statements prior to and including July 31, 2025. The Convenience Date fair values of the Successor’s assets and liabilities differ materially from their recorded values as reflected on the historical balance sheet of the Predecessor. As a result, it may be difficult for stockholders to assess the Company’s performance in relation to prior periods.

The allocation of fair value is dependent upon a number of estimates and assumptions. Whether actual future results and developments will be consistent with the Company’s estimates and assumptions depends on a number of factors, including but not limited to: (i) prices received for its services; (ii) its ability to maintain customers’ confidence in its viability as a continuing entity and to attract and retain sufficient business from them; and (iii) the overall strength and stability of general economic conditions of its industry. To the extent that the Company’s estimates, assumptions, valuations, appraisals and the financial projections used to develop the allocation of fair value are not realized, it has recorded, and in the future may be required to record, impairment charges.

During the period August 1, 2025 to September 30, 2025, the Company experienced a sustained and significant decline in its market capitalization causing the market capitalization to fall below the Company’s book value after the

32

Table of Contents

application of fresh start accounting at Emergence Date. Management concluded that this sustained decline, combined with revised long-term projections compared to those used to compute enterprise value of the reconstituted Successor as set forth in the Disclosure Statement for Joint Plan of Reorganization approved by the Bankruptcy Court, represented a triggering event under ASC 350. In connection with the completion of the interim impairment test, the Company recorded an impairment charge of $215.8 million and $80.0 million to goodwill relating to the reporting units reported under the Applied Workflow Automation segment and Technology segment, respectively, during the period August 1, 2025 to September 30, 2025. Additionally, later during the fourth quarter of 2025, the Company conducted its annual budgeting process along with an update to its long-range plan. Following the completion of that process, the Company made an evaluation based on changes in the Company’s long-term projections, concluding that a triggering event for an impairment analysis had occurred for certain reporting units reported under the Applied Workflow Automation segment. Revised long-term projections resulted in lower than previously projected long-term future cash flows for certain reporting units which reduced the estimated fair values to below their carrying values. Accordingly, the Company performed quantitative impairment test as of December 31, 2025, resulting in an impairment charge of $24.5 million to goodwill relating to the reporting units reported under the Applied Workflow Automation segment. Therefore, as a result of these two interim impairment assessments performed on September 30, 2025 and December 31, 2025, impairment charges totaling $320.3 million, were recorded to goodwill for the period August 1, 2025 to December 31, 2025.

It is also possible that additional restructuring and related charges may be identified and recorded in future periods. Such sales, disposals, liquidations, settlements, or charges could be material to the Company’s results of operations and financial condition in any given period.

Uncertainty regarding the tax treatment of the Business Combination and Restructuring could have a material adverse effect on the Company.

The tax treatment of the Business Combination and related Restructuring is complex and involves uncertainty under applicable U.S. federal, state and international tax laws. While steps have been taken in an effort to mitigate these risks in accordance with applicable laws, there can be no assurance that taxing authorities in any relevant jurisdiction will agree with the intended treatment. Any adverse determination could negatively impact the Company’s financial condition, results of operations or cash flows. In addition, although certain tax indemnity arrangements have been established with ETI in connection with the Business Combination, there is no guarantee that they will fully protect the Company from adverse tax exposures. This risk is heightened if ETI, as the indemnifying party, experiences financial or liquidity constraints that impair its ability to satisfy its obligations.

Risks Related to Our Common Stock

The Company has a limited public float, which adversely affects trading volume and liquidity, and may adversely affect the price of the Common Stock and access to additional capital.

As of December 31, 2025, ETI, Gates Capital Management and Avenue Capital held approximately 25.7%, 24.4% and 9.3% of the Company’s outstanding shares of Common Stock, respectively, in each case assuming the exercise of all warrants held by the Consenting ETI Parties. Due to the limited public float, the trading price of our Common Stock may fluctuate widely due to various factors, including the volume of purchases or sales of Common Stock relative to the public float. The limited public float could adversely affect the Company’s business and financing opportunities and negatively impact the price of our Common Stock.

The Company is a “smaller reporting company,” and its reliance on associated disclosure exemptions could make its securities less attractive to investors.

The Company is a “smaller reporting company” within the meaning of the Securities Act, and intends to elect to take advantage of certain exemptions from various reporting requirements that are applicable to other public companies that are not smaller reporting companies including, but not limited to, not being required to comply with the auditor internal controls attestation requirements of Section 404 of the Sarbanes-Oxley Act. As a result, holders of our securities and potential investors may not have access to certain information they may deem important. There can be no assurances whether investors will find the Company’s securities less attractive because of such exemptions. If some investors find the securities less attractive as a result of reliance on these exemptions, the trading prices of the Company’s securities

33

Table of Contents

may be lower than they otherwise would be, there may be a less active trading market for the Company’s securities and the trading prices of the securities may be more volatile.

Substantial future sales of shares of Common Stock could cause the market price of the Company’s Common Stock to decline.

As of December 31, 2025, ETI, Gates Capital Management and Avenue Capital held approximately 25.7%, 24.4% and 9.3% of the outstanding shares of Common Stock, respectively, in each case assuming the exercise of all warrants held by the Consenting ETI Parties. ETI, Gates Capital Management and Avenue Capital are each permitted to resell all of their shares pursuant to resale registration statements previously filed with the SEC. In addition, our board of directors could designate and sell a class of preferred stock with preferential rights over the Common Stock with respect to dividends or other distributions. We also filed a universal shelf registration statement on Form S-3 with the SEC that registers the sale of up to $250.0 million of any combination of our common stock, preferred stock, debt securities, warrants, rights or units from time to time and at prices and on terms that we may determine. The sale or resale of a substantial number of shares of Common Stock in the public market (or the market perception that such sales or resales could occur) could adversely affect the market price for shares of Common Stock. Furthermore, the selling security holders under the resale registration statements may continue to offer the securities for a significant period of time, the precise duration of which cannot be predicted. Accordingly, the adverse market and price pressures resulting from an offering may continue for an extended period of time.

The Company has entered into a Shareholder Rights Agreement that may delay, defer or prevent a tender offer or takeover attempt that public stockholders might consider in their best interest.

On July 29, 2025, the Company entered into a Shareholder Rights Agreement (the “Shareholder Rights Agreement”), which provides for the issuance of one right per share of Common Stock, exercisable if any person or entity acquires 30% or more of the Common Stock (subject to certain exceptions). Each Right entitles the registered holder to purchase from the Company one one-thousandth of a share of Series A Preferred Stock. The Shareholder Rights Agreement is intended to protect against unsolicited takeovers and expires on January 29, 2027, unless redeemed or exchanged earlier.

The provision of the Company’s Charter that authorizes the Board to issue preferred stock from time to time based on terms approved by the Board, such as pursuant to the Shareholder Rights Agreement, may delay, defer or prevent a tender offer or takeover attempt. Authorized but unissued preferred stock may enable the Board to render it more difficult or to discourage an attempt to obtain control of the Company and thereby protect continuity of or entrench its management, which may negatively impact the market price of the Common Stock. If, in the due exercise of its fiduciary obligations, for example, the Board was to determine that a takeover proposal was not in the best interests of the Company, such preferred stock could be issued by the Board without stockholder approval in one or more private placements or other transactions that might prevent or render more difficult or make more costly the completion of any attempted takeover transaction by diluting voting or other rights of the proposed acquirer or an insurgent stockholder group, by creating a substantial voting bloc in institutional or other hands that might support the position of the incumbent board of directors, by effecting an acquisition that might complicate or preclude the takeover, or otherwise.

The Company’s Charter contains forum limitations for certain disputes between the Company and its stockholders that could limit the ability of stockholders to bring claims against the Company or its directors, officers and employees in jurisdictions preferred by stockholders.

The Company’s Charter provides that, unless the Company consents in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware is the sole and exclusive forum for (i) any derivative lawsuit brought on the Company’s behalf, (ii) any lawsuit against the Company’s current or former directors, officers or employees or asserting a breach of a fiduciary duty owed by any such person to the Company or its stockholders, (iii) any lawsuit asserting a claim arising under any provision of the Delaware General Corporation Law, the Company’s Charter or Bylaws (each, as in effect from time to time) or (iv) any lawsuit governed by the internal affairs doctrine of the State of Delaware. The foregoing forum provisions do not apply to claims arising under the Securities Act, the Exchange Act or other federal securities laws for which there is exclusive federal or concurrent federal and state jurisdiction. The Company’s Charter also provides that, unless the Company consents in writing to the selection of an alternative forum, the federal district courts of the United States of America are the sole and exclusive forum for the resolution of any complaint asserting a cause of action arising under the Securities Act, the Exchange Act and the rules

34

Table of Contents

and regulations thereunder. The foregoing forum provisions may prevent or limit a stockholder’s ability to file a lawsuit in a judicial forum that it prefers for disputes with the Company or its directors, officers, employees or stockholders, which may discourage such lawsuits, make them more difficult or expensive to pursue, and result in outcomes that are less favorable to such stockholders than outcomes that may have been attainable in other jurisdictions, although stockholders will not be deemed to have waived the Company’s compliance with federal securities laws and the rules and regulations thereunder.

There is uncertainty as to whether a court would enforce such a forum selection provision as written in connection with claims arising under the Securities Act because Section 22 of the Securities Act creates concurrent jurisdiction for federal and state courts over all such Securities Act claims.

In addition, notwithstanding the inclusion of the foregoing forum provisions in the Company’s Charter, courts may find the foregoing forum provisions to be inapplicable or unenforceable in certain cases that the foregoing forum provisions purport to address, including claims brought under the Securities Act. If this were to occur in any particular lawsuit, the Company may incur additional costs associated with resolving such lawsuit in other jurisdictions or resolving lawsuits involving similar claims in multiple jurisdictions, all of which could harm the Company’s business, results of operations and financial condition.

The Company’s Common Stock may be delisted from the Nasdaq Capital Market if it is unable to maintain compliance with Nasdaq's continued listing standards.

As previously disclosed, on September 16, 2025, the Company received a letter from Nasdaq notifying the Company that it was not in compliance with Nasdaq’s minimum bid price requirements. On December 12, 2025, the Company effected a 1-for-10 reverse stock split of the Company’s Common Stock. On December 31, 2025, Nasdaq indicated that the Company had regained compliance with Nasdaq’s minimum bid price requirements. However, there can be no assurance that the Company will be able to maintain compliance with Nasdaq’s continued listing standards. If the Company does not maintain compliance with these standards, its Common Stock may be delisted from Nasdaq. Any delisting of the Company’s Common Stock would have significant adverse effects, including but not limited to a substantial reduction in the liquidity and market price of its Common Stock and impairment of its ability to raise additional capital on acceptable terms, or at all.

If the Company’s Common Stock is delisted, there can be no assurance that it will be listed or quoted on another national securities exchange or quotation service. Consequently, it may be more difficult for investors to buy or sell the Company’s Common Stock and warrants, at prices equal to or greater than the price paid or at all.

35

Table of Contents

ITEM 1B. UNRESOLVED STAFF COMMENTS

None.

ITEM 1C. CYBERSECURITY

Risk Management and Strategy

The Company has developed and maintained a comprehensive cybersecurity program which is integrated within the Company’s enterprise risk management program and encompasses the corporate and operational technology environments, as well as client-facing products and services. Our cybersecurity program has implemented a governance structure and process to identify, assess, manage, mitigate, respond to and report on cybersecurity incidents and risks within an ever-changing threat landscape.

We utilize cybersecurity policies and frameworks based on industry and government standards, including the National Institute of Standards and Technology Cyber Security Framework (“NIST CSF”). This does not imply that we meet any particular technical standards, specifications, or requirements, but rather that we use NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.

To validate the effectiveness of our security posture, we engage third-party security experts to conduct annual deep-dive penetration tests. We maintain transparency regarding our security posture by making attestations and compliance summaries available to relevant stakeholders. Furthermore, our infrastructure is subject to regular external audits against rigorous industry standards, including SOC 2, PCI, and HITRUST. These audits validate that our internal controls are designed appropriately and are functioning effectively in practice.

Our cybersecurity program includes an incident response plan, which establishes (1) a framework for classifying security incidents according to their severity level, considering the nature and scope of the incident; and (2) protocols for the escalation of incidents.

To support this, the Company operates a 24 x 7 security operations center (“SOC”) which monitors our global cybersecurity solutions and production environments to detect and respond to potential anomalies. The SOC serves as a central location for the reporting of cybersecurity matters. The roles and responsibilities of the SOC and our cybersecurity team in the incident response context are established by the incident response plan, as well as in associated playbooks and other procedural documentation. Beyond annual testing, we utilize automated scanning and continuous internal assessments designed to identify and remediate vulnerabilities in our applications, software, and networks to mitigate risks proactively.

We partner with third parties to support and evaluate our cybersecurity program. The services provided by third parties span areas including cybersecurity maturity assessments, incident response, penetration testing, and consulting on best practices.

Our processes also address cybersecurity threat risks associated with our use of third-party service providers, including those who have access to our data or our systems. Third-party risks are included within our risk assessment of vendors, as well as our cybersecurity-specific risk identification program. Cybersecurity considerations affect the selection and oversight of third-party service providers. We perform diligence on third parties—particularly those that have access to our systems, data, or facilities that house such systems or data—and continually monitor cybersecurity threat risks identified through such diligence.

We view security as a shared responsibility across the organization. We maintain a cybersecurity awareness program designed to foster a vigilant security culture, covering topics such as phishing, social networking safety, password security, and mobile device usage. This includes regular phishing simulations to test and reinforce employee awareness. We communicate these and other pertinent security issues or compliance changes through our regular internal communications cadence. Additionally, the Company has mandatory security awareness training addressing cybersecurity, privacy, and confidential information.

36

Table of Contents

In 2024 and 2025, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. Please refer to “Item 1A. Risk Factors” for further information about the material risks associated with various cybersecurity threats.

Governance

Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to its Audit Committee oversight of cybersecurity and other information technology risks. Our Audit Committee oversees management’s ongoing activities related to our cybersecurity risk management and compliance programs.

Our cybersecurity program is led by our Chief Technology Officer (“CTO”), who has two decades of experience in various cybersecurity, software development, product management, and other technology-related roles. Our CTO oversees teams across the company supporting our security functions to “identify, prevent, detect, respond, and recover”. These teams are comprised of personnel with a broad range of experience across the private and public sectors, the technology industry, and different geographic regions.

Our Audit Committee receives periodic reports from our CTO and management on our cybersecurity risks and the current threat landscape trends. In addition, management will update the Board directly, as necessary, regarding cybersecurity incidents. The full Board also receives presentations on cybersecurity topics from our CTO and other security management staff as part of the Board’s continuing education on topics that impact the Company.

ITEM 2. PROPERTIES

We lease and own numerous facilities worldwide with larger concentrations of space in California, Connecticut, Illinois, Iowa, Michigan, Texas, and Washington in the United States and in Canada, France, Germany, India, and the Philippines. The size of our active property portfolio as of December 31, 2025 was approximately 1.8 million square feet comprised of 83 leased properties and 5 owned properties including offices, sales offices, service locations, and production facilities.

Many of our operating facilities are equipped with fiber connectivity and have access to other power sources. Substantially all of our operations facilities are leased under long term leases with varying expiration dates, except for the following owned locations: (i) two operations facilities in India with a combined building area of approximately 78,000 sq. ft., (ii) an operations facility in Troy, Michigan that serves as the Company’s primary data center with an approximate building area of 66,000 sq. ft. (iii) an operations facility in Egham, England with an approximate building area of 11,000 sq. ft. and (iv) an operations facility in Dublin, Ireland with an approximate building area of 25,000 sq. ft. We also maintain an operating presence at more than 200 client sites.

Our properties are suitable to deliver services to our clients for each of our business segments. Our management believes that all of our properties and facilities are well maintained.

37

Table of Contents

ITEM 3. LEGAL PROCEEDINGS

Business Interruption Insurance Claim

During the second half of 2022, certain subsidiaries of the Company experienced a network security incident (the “2022 Network Outage”) impacting certain of such subsidiaries operational and information technology systems. As a result of the 2022 Network Outage, such subsidiaries of the Company experienced lost revenue and incurred certain incremental costs. The Company had reduced its revenue for 2022 by the estimated settlement amount of the incident-related customer claims and recorded an accrued liability for the claims payable to customers. A total of $0 and $1.9 million that may be payable to customers to settle customer claims are recorded as customer payables in accrued liabilities on its combined and consolidated balance sheets as of December 31, 2025 and December 31, 2024, respectively.

On August 29, 2023, the Company submitted a claim to its insurers for $44.6 million in covered losses related to the 2022 Network Outage (the “August 2023 Claim”). During the year 2023, the Company received insurance proceeds of $10.8 million in respect of business interruption claims from its underlying and first excess carriers. On April 17, 2024, the Company commenced an action (the “Insurance Lawsuit”) against two excess-layer insurers (collectively, the “Second Excess Insurers”) seeking a declaratory judgment and alleging breach of contract and bad faith for failing to pay out their share of losses connected to the August 2023 Claim. On August 9, 2024, the Company settled its claim against one of the Second Excess Insurers for $3.6 million, and on October 15, 2024, the Company settled its claim against the other Second Excess Insurers for $3.6 million (less amounts already paid). On October 8, 2024, the Company moved to amend the complaint (the “Amended Complaint”) to add two additional excess-layer insurers to the Insurance Lawsuit. The Amended Complaint was filed on October 24, 2024. On December 2, 2025, the Company settled its claim against the two remaining excess-layer insurers for $5.3 million thereby concluding all insurance-related claims brought by the Company arising from the 2022 Network Outage. The Company does not believe that any additional losses related to the 2022 Network Outage are probable, nor does the Company expect further material costs, customer claims, or insurance recoveries.

Company Subsidiary Litigation

In June 2022, a group of 71 former employees filed claims in the French Labor Court against a subsidiary of the Company arising from their dismissal following the closure of two production sites in France in 2020. Certain claims were resolved prior to litigation, and in March 2023 a French labor court granted summary judgment in favor of 67 claimants, resulting in payments of $1.1 million. During 2024 and 2025, the subsidiary entered into settlement agreements with the remaining claimants, and on November 7, 2025, final settlement agreements were executed, fully resolving the matter. All settlement amounts under these settlement agreements have been paid as of December 31, 2025.

Other

We are, from time to time, involved in other legal proceedings, inquiries, claims and disputes, which arise in the ordinary course of business. Although our management cannot predict the outcomes of these matters, our management believes these actions will not have a material, adverse effect on our financial position, results of operations or cash flows.

ITEM 4. MINE SAFETY DISCLOSURES

Not applicable

38

Table of Contents

PART II

ITEM 5. MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES

Market Information

Our Common Stock is traded on the Nasdaq Capital Market under the symbol “XBP”. Our Public Warrants are listed on the Nasdaq Capital Market under the symbol “XBPEW”.

Stockholders

As of March 30, 2026 there were approximately 252 registered holders of record of our Common Stock. The number of holders of record does not include a substantially greater number of “street name” holders or beneficial holders, whose shares of record are held by banks, brokers and other financial institutions.

Dividends

We have not paid any cash dividends on shares of our Common Stock. The payment of cash dividends in the future will be dependent upon our revenues and earnings, capital requirements, general financial condition, and is within the discretion of our board of directors.

Equity Compensation Plan Information

The following table provides information as of December 31, 2025, with respect to the shares of our Common Stock that may be issued under our existing equity compensation plans.

​ ​ ​ ​ ​ ​ ​

​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​

​ ​ ​ ​ ​ ​ ​

​ ​ Number of Securities to ​ ​ ​ Number of Securities

​ ​ be Issued Upon ​ ​ ​ Remaining Available

​ ​ Exercise of Outstanding ​ Weighted Average ​ for Future Issuance

​ ​ Options and ​ Exercise Price of ​ Under Equity

Equity compensation plans approved by stockholders 278,212 $ — 1,027,619

Equity compensation plans not approved by stockholders — — —

Issuer Purchases of Equity Securities During the Year Ended December 31, 2025

None.

ITEM 6. [Reserved]

39

Table of Contents

ITEM 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS

Forward-Looking Statements

The following Management’s Discussion and Analysis of Financial Condition and Results of Operations should be read in conjunction with a review of the other Items included in this Annual Report and our December 31, 2025 Consolidated Financial Statements included elsewhere in this report. Certain statements contained in this “Management’s Discussion and Analysis of Financial Condition and Results of Operations” may be deemed to be forward-looking statements. See “Special Note Regarding Forward Looking-Statements.”

Source: SEC EDGAR (public domain) · 10-K for the period ended 2025-12-31, filed 2026-03-31 · accession 0001104659-26-037421

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.