Basic Materials
RPM International Inc. (RPM)
Data as of July 16, 2026
Environment story
RPM International operates in paint, coating, adhesive, and sealant manufacturing with significant material use, including petroleum-based derivatives and hazardous chemicals. The company discloses limited Scope 1, 2, and 3 emissions data and has not publicly announced a quantified net-zero target date. Environmental controversies include ongoing remediation at multiple sites under CERCLA, an active EPA civil penalty matter ($6.2 million proposed fine for alleged TSCA violation in consumer products), and exposure to hazardous waste handling risks. The 10-K identifies environmental compliance as a material cost driver but provides no verified decarbonization capex, renewable energy transition metrics, or supply-chain emissions reduction initiatives. Greenwashing risk is elevated: the company acknowledges failure to meet sustainability goals as a reputational risk but discloses no baseline emissions, reduction targets, or third-party verification.
Criticisms on file
-
EPA Civil Penalty Proceeding: On December 19, 2024, RPM Consumer segment subsidiary received informal EPA notification of intent to issue civil penalty for alleged Toxic Substances Control Act Section 6 violation related to 2021 consumer product sales. EPA proposed penalty calculation issued January 14, 2025 totaling approximately $6.2 million. Company disputes the penalty and claims it is unwarranted.Source: RPM 10-K FY 2025, Item 3 Legal Proceedings, Environmental Matters section
-
Undisclosed Environmental Liabilities: Company acknowledges 'future liability as yet unknown, but that could be material' at remediation sites still under investigation. Accruals have not been estimated for certain sites and costs may exceed existing accruals for other sites.Source: RPM 10-K FY 2025, Risk Factors section; Item 1A 'Compliance with environmental, sustainability, health and safety and other laws and regulations'
-
Hazardous Material Risk: Use of reactive chemistry and hazardous/flammable materials in manufacturing creates risk of property and personal damage. No quantified loss prevention metrics disclosed.Source: RPM 10-K FY 2025, Item 1A Risk Factors 'The industries in which we operate expose us to inherent risks of legal and warranty claims'
Disclosed initiatives
-
Environmental Compliance ProgramsCompany discloses maintenance of compliance frameworks for Clean Air Act, Clean Water Act, RCRA, CERCLA, TSCA and international standards (Canada Chemical Management Program, EU REACH).
-
Remediation ActivitiesUndertaking remedial activities at multiple properties; company is identified as 'potentially responsible party' under CERCLA at certain sites.Ongoing liabilities at unknown sites; cost exposure exceeds $1 million quantitative threshold.
Social story
RPM International is a large manufacturing and distribution conglomerate with 20 million square feet of operations across four reportable segments and numerous product lines. The 10-K discloses limited workforce diversity metrics, union relations data, or supply-chain labor audits. No CEO-to-median-worker pay ratio, gender/racial pay-gap, or EEO-1 disclosure is evident in the filing. The company acknowledges 'difficulty in retaining key associates' and relies on acquisition-driven talent absorption. Labor relations risks are noted: MAP 2025 restructuring plan (concluded May 31, 2025) generated severance charges ($17.7M in FY2025, $24M in FY2024) with additional $20.1M expected in FY2026, suggesting ongoing workforce instability. No verified union neutrality agreements, living-wage commitments, or conflict-minerals audits are disclosed. Supply-chain ethics oversight relies on vetting and monitoring procedures, but concrete audit results or remediation of identified hazards are not reported. Diversity in technical and executive leadership is not quantified.
Criticisms on file
-
Workforce Instability: Restructuring program (MAP 2025) has generated cumulative severance charges exceeding $72M with an additional $20.1M expected, indicating elevated turnover and workforce reduction across multiple periods.Source: RPM 10-K FY 2025, Item 7 MD&A, 'Restructuring Expense' section and Note B 'Restructuring'
-
Customer Concentration and Supply-Chain Risk: Consumer segment faces substantial customer concentration; sales to key customers (Ace Hardware, Amazon, Home Depot, Lowe's, Walmart, etc.) accounted for 65% of Consumer segment sales in FY2025. Loss of a major customer could materially reduce revenues and impact employee stability.Source: RPM 10-K FY 2025, Item 1A Risk Factors 'We depend on a few key customers for a significant portion of our net sales'
-
No Disclosed Labor Union Relations or Neutrality Agreements: Filing contains no mention of union status, collective bargaining agreements, NLRB proceedings, or labor harmony initiatives.Source: RPM 10-K FY 2025 (absence of disclosure in labor relations section)
Disclosed initiatives
-
Talent Attraction and Retention ProgramsCompany states it maintains 'disciplined, ongoing succession planning process' for senior management and key associates; compensation and benefits programs designed to attract and retain qualified workforce.No disclosed metrics on program effectiveness, turnover reduction, or diversity outcomes.
-
Third-Party Vetting and MonitoringCompany discloses vetting and monitoring of customers, suppliers, service providers, product applicators, sales agents, distributors and other third parties to ensure compliance with laws, regulations, data security, human rights and prevention of illegal trade and corruption.No audit findings, remediation results, or supply-chain human-rights assessments publicly reported.
-
MAP 2025 RestructuringMulti-year restructuring plan (concluded May 31, 2025) designed to streamline business processes, reduce working capital, improve margin, and enhance operating efficiency. Generated severance and facility closure costs totaling $25M in FY2025 and $30M in FY2024; additional $20.1M expected in FY2026.Negative: Ongoing workforce disruption, uncertainty around job security, and redeployment costs.
Governance story
RPM International has a substantial debt burden ($2.6 billion at May 31, 2025 vs. $2.9 billion stockholders' equity), which constrains operational flexibility and capital allocation. The company discloses cybersecurity risk governance through an Audit Committee-supervised program based on NIST framework, with a Senior Director of Information Security (15+ years experience) coordinating initiatives. No material cybersecurity incidents are reported to date. Board independence percentage is not disclosed; dual-class share structure is not mentioned, suggesting a single-class voting arrangement. Lobbying spend and political PAC contributions are not disclosed in the 10-K; no party-lean inference is possible. Material regulatory proceedings include the pending EPA TSCA violation penalty ($6.2M proposed) and potential antitrust/consumer-protection exposure from product liability, warranty claims, and data-privacy evolving standards. The company acknowledges vulnerability to cybersecurity breaches, AI-bias risks, and compliance gaps across multiple jurisdictions. Executive compensation philosophy and board composition metrics are not detailed in this filing.
Criticisms on file
-
High Leverage and Debt Covenant Restrictions: Total debt of $2.6 billion (May 31, 2025) vs. stockholders' equity of $2.9 billion creates material financial constraints. Company acknowledges debt covenants 'restrict our operational flexibility' and that default could trigger 'material adverse effect.' Company states 'we cannot guarantee that we will always be able to make timely or sufficient payments of our debt.'Source: RPM 10-K FY 2025, Item 1A Risk Factors 'Our significant amount of indebtedness could have a material adverse impact on our business'
-
Cybersecurity and Data-Privacy Compliance Uncertainty: Company acknowledges evolving, uncertain interpretation of Data Protection Laws (GDPR, CCPA, AI regulations, biometric rules) and states 'It is possible that the Data Protection Laws may be interpreted and applied in a manner that is inconsistent with our data practices.' Risk of breach or non-compliance includes 'substantial costs, reputational damage' and business-practice changes.Source: RPM 10-K FY 2025, Item 1A Risk Factors 'Cybersecurity threats, data privacy compliance, and use of artificial intelligence could have a negative impact on our business'
-
EPA Civil Penalty – Alleged TSCA Violation: Pending unresolved enforcement action for alleged Toxic Substances Control Act Section 6 violation. EPA proposed $6.2 million penalty (January 2025); company disputes and claims penalty is unwarranted. Outcome and range of loss not estimable.Source: RPM 10-K FY 2025, Item 3 Legal Proceedings 'On December 19, 2024, a subsidiary in our Consumer segment received informal notification from the U.S. Environmental Protection Agency...'
-
Intellectual Property Theft and Generative AI Risks: Company acknowledges advances in AI and widespread use of generative AI tools 'may increase the risk of unauthorized access to our intellectual property or otherwise expose our confidential information or trade secrets which could adversely affect the value of our intellectual property, investment in research and development and our business.'Source: RPM 10-K FY 2025, Item 1A Risk Factors 'Our business and financial condition could be adversely affected if we are unable to protect our intellectual property and other proprietary information'
-
Third-Party Risk and Reputational Exposure: Company relies on vetting and monitoring of third parties (customers, suppliers, service providers, social-media influencers, product applicators, sales agents, distributors) but acknowledges that 'In the event one of our third parties experiences a data breach, is found to have violated applicable laws or regulations, loses favor in the market, or the business practices of the third party come under scrutiny...we could be subject to legal claims, fines and reputational damage.'Source: RPM 10-K FY 2025, Item 1A Risk Factors 'We could be adversely affected by or incur liability for the actions or inaction of our third parties'
Disclosed initiatives
-
Cybersecurity Governance and Risk ManagementCybersecurity strategy includes policies, procedures for assessing and managing material threats; program based on NIST cybersecurity framework and other industry frameworks. Third-party vendors conduct ongoing security monitoring, reporting, and forensic analysis including annual external penetration testing. Employee awareness training, phishing testing, and cyber insurance maintained. Annual internal audits test compliance with technology policies and security procedures. Cybersecurity overseen by Audit Committee; Senior Director of Information Security (15+ years IT/cybersecurity experience, CISO Academy training, IS Auditor certification) coordinates initiatives.Company reports no material cybersecurity incidents to date; however, acknowledges that 'threat actors and cybersecurity incidents continue to pose a risk' and that AI/generative AI increases IP theft and confidential information exposure risk.
-
Data Protection and Privacy Compliance ProgramCompany maintains policies, standards, and practices for data security, privacy-by-design, and data-breach reporting integrated into enterprise risk management. Third-party IT providers and consultants vetted for cybersecurity risk and mitigation. Cybersecurity incidents investigated and remediated per incident response procedures.Acknowledges uncertainty in interpretation of evolving Data Protection Laws (GDPR, CCPA, AI/biometric regulations) and risk of non-compliance resulting in 'substantial costs, reputational damage, or business-practice changes adverse to business.'
-
Risk Management Policies and ProceduresCompany maintains internal controls and procedures designed to manage compliance with anti-corruption (FCPA), trade-sanctions (OFAC), data-security, cybersecurity, environmental, health-and-safety, and anti-bribery laws; policies mandate compliance with antitrust, labor, wage-hour, and privacy regulations.Company acknowledges 'not always been, and may not always be, in full compliance with all laws and regulations' and may face 'enforcement actions, fines and private litigation claims and damages, which could be material.'
These are Missionomics' own editorial scores — directional signals built from disclosed facts under a published method, not certifications or definitive ratings of RPM International Inc.. Coverage and confidence vary by data point, and figures can lag real-world changes. Read the full Methodology for sourcing, scoring, and correction details — or open RPM International Inc. in the app for interactive charts and portfolio building.
Browse Companies · Methodology · Terms of Service · Privacy Policy · Back to Missionomics