{
  "ticker": "JKHY",
  "company": "JKHY",
  "filing_type": "10-K",
  "year_current": "2026",
  "year_prior": "2025",
  "summary": {
    "added": 0,
    "removed": 0,
    "modified": 3,
    "unchanged": 3,
    "total_current": 6,
    "total_prior": 6
  },
  "source": "SEC EDGAR",
  "url": "https://riskdiff.com/jkhy/2026-vs-2025/",
  "markdown_url": "https://riskdiff.com/jkhy/2026-vs-2025/index.md",
  "json_url": "https://riskdiff.com/jkhy/2026-vs-2025/index.json",
  "access": "public_preview",
  "source_filings": [
    {
      "label": "2026 10-K filing on SEC EDGAR",
      "url": "https://www.sec.gov/Archives/edgar/data/779152/000077915226000067/0000779152-26-000067-index.htm"
    },
    {
      "label": "2025 10-K filing on SEC EDGAR",
      "url": "https://www.sec.gov/Archives/edgar/data/779152/000077915225000055/0000779152-25-000055-index.htm"
    }
  ],
  "generated": "2026-09-28",
  "ai_summary": "Three existing risk areas—regulatory compliance, acquisitions, and intellectual property—were substantively revised, while no risks were added or removed.",
  "ai_brief": {
    "executive_summary": "Three existing risk areas—regulatory compliance, acquisitions, and intellectual property—were substantively revised, while no risks were added or removed.",
    "direction": "mixed",
    "top_themes": [
      "Regulatory & Legal",
      "Acquisition Risks",
      "Intellectual Property Risks"
    ]
  },
  "risks": [
    {
      "status": "MODIFIED",
      "current_title": "Regulatory and Compliance Risks",
      "prior_title": "Regulatory and Compliance Risks",
      "severity": {
        "deterministic": 6,
        "ai_bump": 0,
        "total": 6,
        "tier": "medium",
        "signal_hits": [
          "china",
          "cyber",
          "regulation",
          "supplychain",
          "rates",
          "privacy"
        ]
      },
      "similarity_score": 0.907,
      "confidence": "high",
      "key_changes": [
        "Reworded sentence: \"As a supplier of software and services to financial institutions, portions of our operations are subject to ongoing supervision and examination by the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Consumer Financial Protection Bureau.\"",
        "Reworded sentence: \"If regulators identify significant issues, or if we fail to meet supervisory remediation expectations, we could be subject to regulatory actions that could harm our client relationships and reputation.\"",
        "Reworded sentence: \"Moreover, the legislative and regulatory landscape continues to evolve to include alternative payment types, including digital and cryptocurrencies.\"",
        "Reworded sentence: \"This environment imposes comprehensive data privacy compliance obligations in relation to our collection and use of personal information, including a principle of accountability and the obligation to demonstrate compliance through policies, procedures, training, and audits.\"",
        "Reworded sentence: \"Further, the Federal Trade Commission (“FTC\") and state attorneys general may interpret federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of data.\""
      ],
      "current_body": "The software and services we provide to our clients are subject to government regulation that could hinder the development of our business, increase costs, or impose constraints on the way we conduct our operations. The financial services industry is subject to extensive and complex federal and state regulation. As a supplier of software and services to financial institutions, portions of our operations are subject to ongoing supervision and examination by the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Consumer Financial Protection Bureau. Credit Unions are subject to supervision by the National Credit Union Administration. These federal agencies, and comparable state agencies, regulate services we provide and the way we operate, and we are required to comply with a broad range of applicable federal and state laws and regulations. We are routinely subject to the examination process with such regulators, which includes the identification of areas where we can improve our practices to better comply with the applicable regulations and guidelines. If regulators identify significant issues, or if we fail to meet supervisory remediation expectations, we could be subject to regulatory actions that could harm our client relationships and reputation. Failure by third parties, with whom we contract or partner, to comply with regulations or guidelines could also harm our relationships and reputation. Such failures could require significant expenditures to correct and could negatively affect our ability to retain clients and obtain new clients. In addition, existing laws, regulations, and policies could be amended or interpreted differently by regulators in a manner that imposes additional costs and has a negative impact on our existing operations or that limits our future growth or expansion. New regulations could require additional programming or other costly changes in our processes or personnel. Our clients are also regulated entities, and actions by regulatory authorities could influence both the decisions they make concerning the purchase of data processing and other services and the timing and implementation of these decisions. We will be required to apply substantial research and development and other corporate resources to adapt our products to this evolving, complex, and often unpredictable regulatory environment. Our failure to provide compliant solutions could result in significant fines or consumer liability on our clients, for which we may bear ultimate liability. Moreover, the legislative and regulatory landscape continues to evolve to include alternative payment types, including digital and cryptocurrencies. The regulatory environment for crypto assets, stablecoins, and digital currencies is rapidly evolving, with increased oversight from federal and state regulatory agencies. Recent developments, including the GENIUS Act, and other legislative initiatives, bring increased oversight and more robust compliance obligations including consumer protection, anti-money laundering, sanctions compliance, operational resilience and recordkeeping requirements. We closely monitor legislative and regulatory changes to ensure any existing or new business models, product offerings, and risk and compliance programs adapt to new requirements. Any failure to comply with such laws and regulations could expose us to liability, regulatory scrutiny and/or reputational damage. Rapid changes to cryptocurrency laws and regulations could increase the costs and complexity of compliance, including associated recordkeeping costs, or could require us to change our business practices in a timeframe or manner adverse to our business. As we make significant investments in research, development, and marketing for new products in emerging technologies in an uncertain and rapidly changing regulatory landscape, we may not achieve immediate or expected returns. 19 19 19 Compliance with data privacy and cybersecurity laws, regulations, and rules may adversely impact our expenses, development, and strategy. We are subject to complex laws, rules, and regulations related to data privacy and cybersecurity, and each year, this regulatory landscape is rapidly changing. If we fail to comply with such requirements, we could be subject to reputational harm, regulatory enforcement, and litigation. The use, confidentiality, and security of private client information is under increased scrutiny. Regulatory agencies, Congress, state legislatures, and foreign regulatory and governmental bodies are considering numerous regulatory and statutory proposals to protect the interests of consumers and to require compliance with standards and policies that have not been defined. The number of state privacy and cybersecurity laws and regulations has grown tremendously over the past several years, resulting in an increasingly complex and fragmented regulatory landscape. This environment imposes comprehensive data privacy compliance obligations in relation to our collection and use of personal information, including a principle of accountability and the obligation to demonstrate compliance through policies, procedures, training, and audits. These laws often include industry-specific requirements and broad consumer data protection obligations. While many of these frameworks share common principles, each jurisdiction imposes unique compliance standards, definitions, and obligations that may not align with one another. This lack of uniformity, combined with frequent legislative updates and regulatory amendments, creates ongoing challenges for organizations seeking to maintain consistent and compliant data governance practices across multiple jurisdictions. Further, the Federal Trade Commission (“FTC\") and state attorneys general may interpret federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of data. In addition, compliance with these laws and regulations may require changes to our technology and our internal processes and procedures, including the way that we handle, process, and store data, which could divert company resources and negatively impact growth opportunities. We will also be affected by these regulations as a third-party provider to clients who are subject to such regulations and will seek our assistance in their compliance efforts. Failure to comply or readily address compliance and regulatory rule changes made by payment card networks could adversely affect our business. We are subject to card association and network compliance rules governing the payment networks we serve, including Visa, MasterCard, Zelle, FedNow, and The Clearing House’s RTP network, and all rules governing the Payment Card Industry Data Security Standards. This environment imposes comprehensive data privacy and cybersecurity obligations in relation to our collection and use of personal information, including meeting specific cybersecurity standards and the obligation to demonstrate compliance through policies, procedures, training, and audits. Lack of compliance with these rules and standards, may have a severe impact on our ability to do business, including fines and penalties, loss of revenue, negative reputational impact, increased costs of operations, and disruption of services, including the inability to provide card processing services to our clients. Changes made by the payment networks may result in reduction in revenue, increased costs of operations, and negative impact on growth opportunities if company resources need to be diverted to address such changes.",
      "prior_body": "The software and services we provide to our clients are subject to government regulation that could hinder the development of our business, increase costs, or impose constraints on the way we conduct our operations. The financial services industry is subject to extensive and complex federal and state regulation. As a supplier of software and services to financial institutions, portions of our operations are subject to ongoing supervision and examination by the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation, the Consumer Financial Protection Bureau, and the National Credit Union Association, among other regulatory agencies. These agencies regulate services we provide and the way we operate, and we are required to comply with a broad range of applicable federal and state laws and regulations. We are routinely subject to the examination process with such regulators, which includes the identification of areas where we can improve our practices to better comply with the applicable regulations and guidelines. If regulators 17 17 17 identify significant issues, or if we fail to meet supervisory remediation expectations, we could be subject to regulatory actions that could harm our client relationships and reputation. Failure by third parties, with whom we contract or partner, to comply with regulations or guidelines could also harm our relationships and reputation. Such failures could require significant expenditures to correct and could negatively affect our ability to retain clients and obtain new clients. In addition, existing laws, regulations, and policies could be amended or interpreted differently by regulators in a manner that imposes additional costs and has a negative impact on our existing operations or that limits our future growth or expansion. New regulations could require additional programming or other costly changes in our processes or personnel. Our clients are also regulated entities, and actions by regulatory authorities could influence both the decisions they make concerning the purchase of data processing and other services and the timing and implementation of these decisions. We will be required to apply substantial research and development and other corporate resources to adapt our products to this evolving, complex, and often unpredictable regulatory environment. Our failure to provide compliant solutions could result in significant fines or consumer liability on our clients, for which we may bear ultimate liability. Compliance with new and existing data privacy and cybersecurity laws, regulations, and rules may adversely impact our expenses, development, and strategy. We are subject to complex laws, rules, and regulations related to data privacy and cybersecurity. If we fail to comply with such requirements, we could be subject to reputational harm, regulatory enforcement, and litigation. The use, confidentiality, and security of private client information is under increased scrutiny. Regulatory agencies, Congress, state legislatures, and foreign regulatory and governmental bodies are considering numerous regulatory and statutory proposals to protect the interests of consumers and to require compliance with standards and policies that have not been defined. The number of state privacy and cybersecurity laws and regulations has grown tremendously over the past several years, resulting in an increasingly complex and fragmented regulatory landscape. These laws often include industry-specific requirements and board consumer data protection obligations. While many of these frameworks share common principles each jurisdiction imposes unique compliance standards, definitions, and obligations that may not align with one another. This lack of uniformity, combined with frequent legislative updates and regulatory amendments, creates ongoing challenges for organizations seeking to maintain consistent and compliant data governance practices across multiple jurisdictions. Further, the FTC and state attorneys general may interpret federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of data. In addition, compliance with these laws and regulations may require changes to our technology and our internal processes and procedures, including the way that we handle, process, and store data, which could divert company resources and negatively impact growth opportunities. We will also be affected by these regulations as a third-party provider to clients who are subject to such regulations and will seek our assistance in their compliance efforts. Failure to comply or readily address compliance and regulatory rule changes made by payment card networks could adversely affect our business. We are subject to card association and network compliance rules governing the payment networks we serve, including Visa, MasterCard, Zelle, FedNow, and The Clearing House’s RTP network, and all rules governing the Payment Card Data Security Standards. If we fail to comply with these rules and standards, we could be fined or our certifications could be suspended or terminated, which could limit our ability to service our clients and result in reductions in revenues and increased costs of operations. Changes made by the networks, even when complied with, may result in reduction in revenues and increased costs of operations."
    }
  ],
  "full_url": "https://riskdiff.com/jkhy/2026-vs-2025/full/"
}