Stage 1

The risk factor that wasn't there last year

A new risk factor in a 10-K is leadership admitting a problem in writing. Compare it to last year's filing and you'll know where the budget is going.

Kevin French
· 4 min read

Every 10-K has a long list of risk factors. Almost all of it is boilerplate the lawyers carry forward year after year.

The paragraph that wasn't there last year is different. Someone decided that risk was real enough to put in front of investors. That's a buying signal.

Why new language means new money

Item 1A is where a public company tells investors what could hurt the business. Legal and finance write it carefully. Nobody adds a paragraph for fun. Every new line gets argued over, and every new line creates disclosure obligations later.

So when a risk factor appears for the first time, it means the problem got big enough that leaving it out felt more dangerous than putting it in.

And the problems that make it into Item 1A are often problems a services firm can fix. A system implementation that's running late. A dependency on a single vendor or platform. A shortage of people with the skills to run something critical. A cyber exposure tied to old infrastructure.

Once leadership has named a risk in public, they have to show progress against it. That's a program. Programs need people. The team they have is already stretched, or the risk wouldn't exist.

How to find it

Pull the current 10-K and last year's from SEC EDGAR. Open both to Item 1A. Read them side by side.

That's tedious the first few times. It gets fast. Most risk factor sections keep the same order and the same headers year over year, so the new paragraph stands out once you know the shape of the old one. Paste both into a compare tool if you want to see every changed word.

I covered the broader reading method in How to read a 10-K like a seller. This is one narrow use of it, and it's the one with the best return on time.

What's strong and what's noise

Strong language names something specific. "We are implementing a new enterprise resource planning system, and delays or failures in that implementation could disrupt our operations." That's a company telling you a program is live and leadership is nervous about it.

Strong language names a dependency. "We rely on a limited number of third-party providers for critical technology services." If that's new, something happened. A vendor got acquired, raised prices, or failed them.

Strong language names a capability gap. "We may be unable to attract and retain personnel with expertise in data, analytics and artificial intelligence." That's leadership admitting the team they need isn't the team they have.

Noise is anything generic. A new paragraph about macroeconomic conditions or general cybersecurity threats usually came from outside counsel updating the template for every client. It tells you nothing about this account.

Watch for paragraphs that got longer too. A legacy systems risk that was two sentences last year and six this year is a risk that grew. I wrote about that case in Legacy systems in a 10-K are an invitation.

Whose name is on it

A risk factor lands on whoever owns the fix. An implementation risk is the CIO's, and often a business leader who sponsored the program. A dependency risk is the CIO's and the CFO's, since a single-vendor exposure is a cost and continuity problem at once. A talent risk is shared between the CHRO and whichever technology leader can't hire.

The CFO signed off on the language. The general counsel reviewed it. Neither of them is usually your buyer, but both of them now care about the outcome.

Say a regional distributor adds a risk factor this year about its ERP implementation, warning that delays could affect order fulfillment. Here's an opener to the CIO.

This year's 10-K added a risk factor on the ERP implementation that wasn't in last year's. Once that's in front of investors, the program has a public clock on it and you're the one holding it. My guess is the core build is fine and the trouble is data migration and testing capacity, with the same people pulled between cutover and keeping the old system alive. Is that close, or is the risk somewhere else?

The hook is the new paragraph. The trigger is that the CIO now owns a public risk. The hypothesis is a specific guess about where the implementation is hurting. The exit lets them correct you in one line.

When to move

10-Ks drop once a year, mostly in the first quarter for calendar-year companies. That makes this a seasonal signal. The weeks after filing season are when you have the freshest comparisons across your whole list.

But don't treat it as stale by summer. A risk factor stays in the filing until it's resolved, and the 10-Qs will tell you if it's getting worse. Look for updated risk language there and in the earnings call.

The real power is in stacking. A new implementation risk plus job posts for a program manager plus a new CIO in the last year is a company that knows it's in trouble and is trying to staff its way out. One signal is a reason to look. Three is a reason to write. More on that distinction in What a buying signal is and isn't.

Old risk factors are wallpaper. New ones are leadership telling you, in a legal document, what keeps them up at night. Read the difference and write to the person who owns it.

See which of your accounts are moving.

Stage 1 reads your site, finds accounts that fit and checks their filings and news. Your first Board in about two minutes. Free for 14 days, no credit card.