JKHY: 10-K Risk Factor Changes

2026 vs 2025  ·  SEC EDGAR  ·  2026-09-28
⚠ AI Risk Brief Interpretation layer — deterministic data below

Three existing risk areas—regulatory compliance, acquisitions, and intellectual property—were substantively revised, while no risks were added or removed.

Direction ↔ Mixed
ThemesRegulatory & LegalAcquisition RisksIntellectual Property Risks
✓ Deterministic extraction — no AI-generated data

Classification is based on semantic text similarity scoring and may include approximations. “No match” means no high-confidence textual match was found — not necessarily that a section was removed.

0
New Risks
0
Removed
3
Modified
3
Unchanged
🟡 Modified Disclosure change6/10

Regulatory and Compliance Risks

high match confidence

Sentence-level differences:

  • Reworded sentence: "As a supplier of software and services to financial institutions, portions of our operations are subject to ongoing supervision and examination by the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Consumer Financial Protection Bureau."
  • Reworded sentence: "Moreover, the legislative and regulatory landscape continues to evolve to include alternative payment types, including digital and cryptocurrencies."
  • Reworded sentence: "This environment imposes comprehensive data privacy compliance obligations in relation to our collection and use of personal information, including a principle of accountability and the obligation to demonstrate compliance through policies, procedures, training, and audits."
  • Reworded sentence: "Further, the Federal Trade Commission (“FTC") and state attorneys general may interpret federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of data."
  • Reworded sentence: "We are subject to card association and network compliance rules governing the payment networks we serve, including Visa, MasterCard, Zelle, FedNow, and The Clearing House’s RTP network, and all rules governing the Payment Card Industry Data Security Standards."

Current (2026):

View prior text (2025)

The software and services we provide to our clients are subject to government regulation that could hinder the development of our business, increase costs, or impose constraints on the way we conduct our operations. The financial services industry is subject to extensive and complex federal and state regulation. As a supplier of software and services to financial institutions, portions of our operations are subject to ongoing supervision and examination by the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, the Consumer Financial Protection Bureau, and the National Credit Union Association, among other regulatory agencies. These agencies regulate services we provide and the way we operate, and we are required to comply with a broad range of applicable federal and state laws and regulations. We are routinely subject to the examination process with such regulators, which includes the identification of areas where we can improve our practices to better comply with the applicable regulations and guidelines. If regulators identify significant issues, or if we fail to meet supervisory remediation expectations, we could be subject to regulatory actions that could harm our client relationships and reputation. Failure by third parties, with whom we contract or partner, to comply with regulations or guidelines could also harm our relationships and reputation. Such failures could require significant expenditures to correct and could negatively affect our ability to retain clients and obtain new clients.

In addition, existing laws, regulations, and policies could be amended or interpreted differently by regulators in a manner that imposes additional costs and has a negative impact on our existing operations or that limits our future growth or expansion. New regulations could require additional programming or other costly changes in our processes or personnel. Our clients are also regulated entities, and actions by regulatory authorities could influence both the decisions they make concerning the purchase of data processing and other services and the timing and implementation of these decisions. We will be required to apply substantial research and development and other corporate resources to adapt our products to this evolving, complex, and often unpredictable regulatory environment. Our failure to provide compliant solutions could result in significant fines or consumer liability on our clients, for which we may bear ultimate liability.

Compliance with new and existing data privacy and cybersecurity laws, regulations, and rules may adversely impact our expenses, development, and strategy. We are subject to complex laws, rules, and regulations related to data privacy and cybersecurity. If we fail to comply with such requirements, we could be subject to reputational harm, regulatory enforcement, and litigation. The use, confidentiality, and security of private client information is under increased scrutiny. Regulatory agencies, Congress, state legislatures, and foreign regulatory and governmental bodies are considering numerous regulatory and statutory proposals to protect the interests of consumers and to require compliance with standards and policies that have not been defined. The number of state privacy and cybersecurity laws and regulations has grown tremendously over the past several years, resulting in an increasingly complex and fragmented regulatory landscape. These laws often include industry-specific requirements and board consumer data protection obligations. While many of these frameworks share common principles each jurisdiction imposes unique compliance standards, definitions, and obligations that may not align with one another. This lack of uniformity, combined with frequent legislative updates and regulatory amendments, creates ongoing challenges for organizations seeking to maintain consistent and compliant data governance practices across multiple jurisdictions. Further, the FTC and state attorneys general may interpret federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of data. In addition, compliance with these laws and regulations may require changes to our technology and our internal processes and procedures, including the way that we handle, process, and store data, which could divert company resources and negatively impact growth opportunities. We will also be affected by these regulations as a third-party provider to clients who are subject to such regulations and will seek our assistance in their compliance efforts.

Failure to comply or readily address compliance and regulatory rule changes made by payment card networks could adversely affect our business. We are subject to card association and network compliance rules governing the payment networks we serve, including Visa, MasterCard, Zelle, FedNow, and The Clearing House’s RTP network, and all rules governing the Payment Card Data Security Standards. If we fail to comply with these rules and standards, we could be fined or our certifications could be suspended or terminated, which could limit our ability to service our clients and result in reductions in revenues and increased costs of operations. Changes made by the networks, even when complied with, may result in reduction in revenues and increased costs of operations.

🟡 Modified Acquisition Risks 🔒
🟡 Modified Intellectual Property Risks 🔒
2 more changes in this filing

Full diff access, historical comparisons, and cross-company signal tracking.

Get Pro access Already a Pro subscriber? View full diff →