Industrials
Equifax Inc. (EFX)
Data as of July 13, 2026
Environment story
Equifax discloses greenhouse gas reduction commitments but provides minimal quantitative emissions data in available filings. Scope 1, 2, and 3 emissions figures are not disclosed. The company acknowledges reliance on renewable energy availability and supplier sustainability standards, but lacks concrete baseline metrics, interim targets, or net-zero target year specification. Cloud migration to third-party providers may increase operational carbon footprint through data center energy consumption. No evidence of verified physical decarbonization infrastructure investments. Risk factor language indicates company recognizes ESG disclosure obligations but implementation and credibility remain unverified. Moderate greenwashing risk due to stated commitments without quantifiable progress metrics.
Criticisms on file
-
Undisclosed Emissions Data: Company fails to disclose Scope 1, 2, or 3 greenhouse gas emissions figures in 10-K or proxy filing.Source: EFX 10-K (2025) Item 1A Risk Factors; Item 1B Cybersecurity
-
No Net-Zero Target Year Specified: Company acknowledges GHG reduction commitments but does not specify target net-zero year or interim milestones.Source: EFX 10-K (2025) Risk Factors—'Our reputation and/or business could be negatively impacted by stakeholder responses to our responsible business priorities and commitments'
-
Anti-ESG Sentiment Risk Acknowledgment: Company discloses concern about 'anti-ESG sentiment' in U.S. and potential scrutiny, reputational risk, or market access restrictions from activism related to ESG reporting.Source: EFX 10-K (2025) Risk Factors—'More recently, an anti-ESG sentiment has developed in the U.S. among certain activists, institutions and governments'
Disclosed initiatives
-
Greenhouse Gas Emissions Reduction CommitmentCompany has announced commitments to reduce greenhouse gas emissions, acknowledged in 10-K risk factors as reliant on accuracy of estimates and assumptions around renewable energy availability and supplier sustainability standards.
-
Cloud Technology MigrationMigrating applications and systems infrastructure from on-premises to cloud-based solutions hosted by third parties; expected to improve efficiency and reduce systems infrastructure costs, though may alter operational carbon footprint.
Social story
Equifax discloses approximately 15,000 global employees and acknowledges talent retention challenges in specialized areas (data analytics, AI, IT security, cloud security). No published CEO-to-median-worker pay ratio, workforce diversity percentages, gender/racial pay gap metrics, or union status disclosed in available filings. Company describes global Security team of ~450 cybersecurity professionals and references mandatory annual security training for all employees, with security performance included in bonus-eligible employee evaluations. No documented labor union suppression activities, strikes, or NLRB complaints in provided sources. Supply chain labor practices (human rights audits, conflict minerals, living wage) not disclosed. Diversity and pay equity data unavailable, limiting social pillar assessment.
Criticisms on file
-
Undisclosed Diversity and Pay Equity Metrics: No workforce or leadership diversity percentages, gender pay gap, or racial pay gap disclosed in 10-K or proxy.Source: EFX 10-K (2025); EFX DEF 14A (2025)
-
Undisclosed CEO-to-Median-Worker Pay Ratio: No CEO compensation or pay ratio disclosure in available filings.Source: EFX DEF 14A (2025)
-
Supply Chain Labor Practices Undisclosed: No disclosed supply chain audits, human rights due diligence, conflict minerals policy, or living wage commitments.Source: EFX 10-K (2025); EFX DEF 14A (2025)
Disclosed initiatives
-
Employee Security Training and Performance MetricsAnnual mandatory security training for all employees; customized role-based training; individual security performance tracked; security performance included as metric in annual incentive compensation for bonus-eligible employees.Addresses insider threat mitigation and reinforce company-wide security culture.
-
Global Security Team ExpansionCompany maintains approximately 450 cybersecurity professionals globally under CISO leadership; Chief Information Security Officer role reports directly to Senior Leadership Team and Board.Demonstrates commitment to data security workforce.
-
Talent Retention Initiatives for Specialized RolesCompany acknowledges retention challenges in data analytics, AI, IT security, cloud security, and application development; identifies intense competition for technical specialties.Risk factor disclosure; no specific mitigation programs detailed.
Governance story
Equifax has implemented a governance framework including Board-level Audit and Technology Committees with joint quarterly meetings on cybersecurity and risk management oversight. Board monitors enterprise risk assessment annually with nine primary risk categories including cybersecurity. No single share class structure disclosed; company does not appear to operate a dual-class voting regime. Board independence percentage not disclosed in available filings. Company faces significant regulatory scrutiny: 2019 Consumer Settlement with FTC, CFPB, 48 state AGs, NYDFS, and NYDFS related to 2017 data breach; settlement includes extensive business practice commitments and third-party security assessments; non-compliance risks material fines and enforcement actions. CFPB has supervisory authority and can impose penalties up to $1.0 million per day for violations. No disclosed lobbying expenditures or anti-climate/consumer-protection regulatory positions identified in provided documents. Active involvement in multiple consumer protection lawsuits; FCRA attorney fee-shifting provision creates litigation incentive. Company acknowledges AI discrimination risks in credit decisioning products subject to regulatory scrutiny. Governance structure demonstrates Board oversight maturity; regulatory compliance burden is substantial and material.
Criticisms on file
-
2017 Material Cybersecurity Incident: Criminal attack resulting in theft of personal information of U.S., Canadian, and U.K. consumers; resulted in loss of key certifications, customer relationship damage, negative revenue impact.Source: EFX 10-K (2025) Item 1C Cybersecurity; Item 1A Risk Factors
-
2019 Consumer Settlement with FTC, CFPB, 48 State AGs, DC, Puerto Rico, NYDFS: Settled consolidated class action MDL No. 2800 and government investigations related to 2017 breach; settlement effective January 11, 2022; extensive business practice commitments and third-party security assessment requirements; non-compliance risk material penalties and enforcement actions.Source: EFX 10-K (2025) Item 1A Risk Factors—'As part of a global settlement, we entered into agreements with various parties to settle the U.S. Consumer MDL Litigation'
-
CFPB Supervisory Authority and Enforcement Risk: CFPB has broad authority including issuance of regulations, supervisory examinations, enforcement actions; authority to seek rescission, restitution, disgorgement, damages, activity limits, and penalties up to $1.0 million per day for known violations; company has faced past enforcement actions.Source: EFX 10-K (2025) Item 1A Risk Factors—'The CFPB has supervisory authority over our U.S. business and supporting operations'
-
Increased FCRA Consumer Litigation: FCRA attorney fee-shifting provision creates incentive for individual and class action lawsuits against consumer reporting agencies; company discloses number of consumer lawsuits (individual and class action) alleging FCRA violations and resulting costs have increased substantially in recent years.Source: EFX 10-K (2025) Item 1A Risk Factors—'The FCRA contains an attorney fee shifting provision that provides an incentive for consumers to bring individual and class action lawsuits'
-
AI Discrimination Risk in Credit Decisioning: Company acknowledges use of AI and machine learning in credit decisioning products subject to enhanced regulatory scrutiny regarding algorithm bias, data bias, and discriminatory impact; regulatory and litigation risk.Source: EFX 10-K (2025) Item 1A Risk Factors—'Our use of artificial intelligence could lead to enhanced scrutiny. In particular, our use of artificial intelligence in credit decisioning could lead to enhanced scrutiny.'
-
Data Privacy and Regulatory Compliance Burden: Company subject to complex, frequently changing U.S. federal, state, local, and foreign laws (FCRA, GDPR, CCPA, state privacy laws, AI regulations); GDPR fines up to 4% of annual worldwide revenue; increasing legislative focus on algorithms, AI, and machine learning; company devotes substantial compliance resources; regulatory interpretation changes and new laws create material compliance cost risk.Source: EFX 10-K (2025) Item 1A Risk Factors—'We and our customers are subject to various current laws and governmental regulations, and could be affected by new and evolving laws and regulations'
Disclosed initiatives
-
Board Cybersecurity Oversight StructureAudit and Technology Committees coordinate on risk management with quarterly joint meetings; quarterly CISO and CTO reports; annual enterprise risk assessment includes cybersecurity as primary risk category; annual third-party maturity assessment of security program; internal audit red team testing.Demonstrates Board-level governance and accountability for cybersecurity risk.
-
Enterprise Risk Management ProgramChief Risk, Privacy and Compliance Officer leads ERM program; annual enterprise risk assessment producing enterprise risk scorecard; cybersecurity is one of nine primary risk categories; board reviews and sets risk appetite levels.Institutionalized risk governance framework.
-
Consumer Settlement Compliance Program (2019)Implementation of FTC/CFPB/State AGs settlement terms including business practice commitments related to consumer assistance, information security program, and third-party security assessments.Court-mandated compliance framework; ongoing regulatory obligation; failure to comply risks material penalties and enforcement actions.
-
Third-Party Risk Management ProcessGovernance process for oversight of third-party vendors with network access or personal information custody; contracts require suppliers maintain information security standards meeting Equifax requirements; periodic compliance assessments.Extends governance to supply chain and vendor relationships.
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of Equifax Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open Equifax Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics