← Back to RSKD filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
A. History and Development of the Company
Riskified Ltd. was incorporated on November 26, 2012 and commenced operations in January 2013. In July 2021, we listed our Class A ordinary shares on the NYSE. We are a company limited by shares organized under the laws of the State of Israel. We are registered with the Israeli Registrar of Companies. Our registration number is 51-484411-7.
Our principal executive offices are located at 220 5th Avenue, 2nd Floor, New York, New York 10001.
Our website address is http://www.riskified.com. We use our website as a means of disclosing material non-public information. Such disclosures will be made available on the “Investor Relations” section of our website. Accordingly, investors should monitor such sections of our website, in addition to following our press releases, SEC filings and public conference calls and webcasts. Information contained on, or that can be accessed through our website does not constitute a part of this Annual Report and is not incorporated by reference herein. We have included our website address, and references to various other documents, in this Annual Report solely for informational purposes. The SEC maintains an internet website that contains reports, proxy statements and other information about issuers, like us, that file electronically with the SEC at https://www.sec.gov. Our agent for service of process in the United States is Riskified, Inc., located at 220 5th Avenue, 2nd Floor, New York, New York 10001. For a description of our principal capital expenditures and divestitures for the three years ended December 31, 2025 and for those currently in progress, see Item 5. “Operating and Financial Review and Prospects — Liquidity and Capital Resources.”
B. Business Overview
53
Company Overview
Our mission is to empower businesses to unleash ecommerce growth by outsmarting risk. We have built a next-generation AI-powered ecommerce risk intelligence platform that allows online merchants to create trusted relationships with consumers. Leveraging machine learning that benefits from data from a global merchant network, our platform identifies the individual behind each online interaction, helping merchants—our customers—eliminate risk and uncertainty from their business. Our AI-powered fraud management and risk intelligence platform is designed to help our merchants maximize revenue and profit to allow them to provide superior online shopping experiences for consumers.
We believe legacy ecommerce fraud platforms and rules-based, in-house solutions are frequently slow, inaccurate, expensive and inflexible. They can often produce the wrong decision—by rejecting good transactions or accepting fraudulent ones—which causes merchants to either lose revenue or incur unnecessary expenses in the form of chargebacks and other fees.
Larger, global merchants can also employ hundreds of support personnel to manually review consumer interactions (e.g., orders, returns, refund claims and account recoveries). We believe these slow manual processes produce poor online shopping experiences that lead to abandoned shopping carts. Additionally, this outdated infrastructure may prevent merchants from adapting to fast-changing consumer preferences and fraud techniques, including the nascent adoption of Agentic Commerce.
Our AI-powered ecommerce risk intelligence platform is built to solve these problems with proprietary machine learning models that drive an automated decisioning engine. We have designed our platform to be fast, accurate, scalable, and cost-effective. Our platform supports our core Chargeback Guarantee product—which optimizes merchant approval rates—as well as our other products that mitigate similar and adjacent ecommerce risks for those same merchants, including Policy Protect, Dispute Resolve and Account Secure.
All of our products are designed to enable merchants to generate additional revenue or cost savings, while improving the online shopping experience for consumers. Our core product, the Chargeback Guarantee, automatically approves or declines online orders with guaranteed performance levels that vary in accordance with our merchants’ priorities. Our AI Technologies analyze hundreds of attributes per transaction, generating decisions in real time. We guarantee the outcome of these decisions by assuming the cost of fraud associated with each order that we approve. Simultaneously, we provide contractual minimum approval rates for our Chargeback Guarantee merchants that are typically higher than these merchants can achieve on their own.
We access our merchants’ transaction data through deep integrations into their mission-critical infrastructure, including but not limited to their ecommerce, order management, fulfillment, payments, refunds, returns and customer relationship management systems. Collecting relevant data across our merchant network allows us to identify complex transaction and behavior patterns that are not easily identifiable by merchants on their own. Our ability to help our merchants stems from the fact that we continuously feed this real-time training data into our sophisticated machine learning models.
We service merchants of all sizes, from multi-billion dollar global omnichannel retailers to small pure play merchants, including via partnerships and/or integrations with Shopify and other ecommerce platforms, such as Salesforce Commerce Cloud, AWS Marketplace, Commercetools, Adobe Commerce, IXOPAY and others. However, we focus on supporting enterprise merchants, which we define as merchants generating over $75 million in online sales per year. Our merchants include some of the largest ecommerce brands in the world, including Ring, Lastminute.com, SHEIN, and Macy’s. Our merchants operate in a variety of verticals, including Tickets & Travel, Fashion and Luxury, Money Transfer and Payments, Electronics, Home and General. We categorize general retail merchants and food merchants within our “General” category.
We charge merchants using our Chargeback Guarantee product a percentage of every dollar of GMV that we approve on their behalf, so we are incentivized to approve as many orders as we safely can. We
54
believe that this merchant-centric approach, coupled with our rigorous decisioning process, maximizes our financial results and those of our merchants.
We typically charge merchants a fixed fee per transaction for utilizing Policy Protect. Merchants using our Chargeback Management System, which is a component of our Dispute Resolve product, are typically charged a monthly platform fee and additional fees per transaction in the event we also provide representment services. Other products that do not require us to guarantee our decisions, are typically charged a fixed fee per transaction.
The fee we charge our merchants for Chargeback Guarantee, is a risk-adjusted price, which is expressed as a percentage of the GMV that we approve. This fee, which is established at contract inception, varies by merchant based on a variety of inputs, including the type of merchant, the order population, submission rates, historical fraud levels, the risk level of the end market (including industry and geographic region), and the guaranteed approval rates we agree to provide. When our merchants ask us to review transactions from end markets that carry higher risk, we may charge higher fees to help offset the increased likelihood of receiving a chargeback. In some instances, we may charge a merchant a fixed fee per transaction for fraud and risk intelligence services that do not carry the same liability shift offered with our Chargeback Guarantee product.
If an approved transaction that we have guaranteed results in an eligible chargeback, we will reimburse the merchant for the amount of the lost sale. In this situation, we record a chargeback expense in cost of revenue. Reimbursements are typically provided to the merchant in the form of credits on future invoices.
55
Our AI-powered Ecommerce Risk Intelligence Platform & Product
Our AI-powered ecommerce risk intelligence platform automates the complexities of ecommerce for merchants, and enables them to offer simple, frictionless consumer experiences.
The Riskified AI-powered Ecommerce Risk Intelligence Platform
Data Sources
We deeply integrate into merchants’ systems that house and track transaction data and online interactions. Extrapolating this level of access across our global merchant base provides tremendous data resources that we use to train our machine learning models. We can draw insights from billions of historical transactions executed on our merchant network, each of which contains hundreds of data attributes.
Analytics
Extensive and automated analysis of these attributes, both individually and as part of the aggregated global network, positions us to determine which consumers and transactions are legitimate or fraudulent. Our machine learning algorithms produce real-time insights that are trained for anomaly detection and pattern recognition based on the other transactions and interactions that have occurred, and are occurring, on our network.
Merchant Tools
Our dashboards give merchants visibility into every decision that we make. This visibility empowers merchants to review, understand, and override decisions where we are unwilling to guarantee a transaction. Our dashboards also include up-to-date key performance metrics, including order approval rates, account challenges, order declines and chargebacks.
Risk Management
Risk management is at the very heart of our business. We have established processes that are designed to help us manage our overall chargeback exposure and control realized chargeback expenses within predetermined parameters. In addition, we are able to adjust our merchants’ approval and
56
chargeback rates in real time to rebalance our exposure and our expected expenses during any given period.
•Strong track record driven by real-time training data: Our engagement model has built-in feedback loops that provide us with up-to-date, high quality training data in the form of chargeback transactions from across our merchant network. This data constantly updates our models to improve their accuracy. Additionally, we have observed a large and diverse population of chargeback transactions since our founding. Combined with our real-time feedback loops, the volume of our high-quality, historical chargeback data is critical to the accuracy of our models. Since our founding, we have incurred relatively few chargebacks, measured as a percentage of our total approved transactions. Historically, chargeback expenses have been in line with our annual budgets.
•Active risk monitoring: We supplement our models with a variety of tools that detect anomalies and prevent fraud in real time. We use a layered approach to ensure that there are multiple levels of analyses performed on each transaction we approve. This layered approach optimizes the overall performance of our AI-powered ecommerce risk intelligence platform while also creating fail safe mechanisms. For example, our anomaly detection models are designed to detect blind spots that our supervised models cannot. We also employ real-time alerting systems for early detection any time our exposure exceeds certain thresholds. Lastly, we use a combination of automated and manual reviews from highly skilled risk analysts to review our exposure on a regular basis, no less than daily.
•Real-time adjustments optimize long term outcomes: We adjust our merchants’ approval rates in real time as we detect riskier order populations. This allows us to optimize outcomes for our merchants when we see safer transactions, while also reducing approval rates when we see riskier transactions. This ability to react opportunistically to changing market conditions and fraud trends allows us to optimize our long term approval rate while also managing our overall chargeback exposure.
•Risk diversification: Significant fraud events are typically isolated to a particular merchant or industry. As a result, our chargeback expenses have become less volatile over time as we scale and diversify our merchant base. Furthermore, the average transaction value we approve is less than $200. This means that unexpected chargebacks need to occur in large volumes to meaningfully impact our overall chargeback expenses. As of December 31, 2025, our portfolio of potential chargeback liabilities was diversified across a wide variety of industries, hundreds of merchants and millions of individual transactions. We believe this scale and diversity significantly reduces the likelihood of material unexpected chargeback expenses.
•Short-term durations provide rapid visibility: Our merchant agreements generally allow chargebacks to be submitted up to six months from the order approval date. Merchants are also typically required to notify us of an eligible chargeback within five days of becoming aware of a chargeback that occurred within this six month period. As a result, chargeback liabilities typically have very short durations. More than 90% of chargebacks are incurred within 90 days of the transaction date. This allows us to forecast the expenses associated with a new cohort of approved transactions at the same time. Furthermore, as we receive chargeback notifications from our merchants, we are able to decline similar future orders in real time.
Our Products
Our AI-powered ecommerce risk intelligence platform is comprised of multiple products that are all powered by the same automated decisioning engine. On top of this decisioning engine, we offer an assortment of powerful tools designed to enhance visibility and control for merchants’ fraud teams, powered by our unique network data and advanced machine learning models. Chargeback Guarantee is
57
our core product that is used by substantially all of our customers. Merchants typically use our other products, either individually, or in combination with Chargeback Guarantee to overcome ecommerce pain points that are similar or adjacent to chargeback fraud and abuse.
Our Chargeback Guarantee product automatically approves or declines online orders with guaranteed performance levels that vary by merchant. Our machine learning models analyze hundreds of attributes per transaction, generating accurate decisions instantaneously. Through our proprietary smart linking technology, we strive to accurately match transactions that occur on our network with other similar transactions that have occurred on our network across hundreds of variables per transaction. We guarantee the outcome of these decisions by assuming the cost of fraud associated with each transaction we approve. Simultaneously, we provide contractual minimum approval rates for our Chargeback Guarantee merchants that are typically higher than the approval rates that these merchants were able to achieve prior to commencing work with us. Additionally, Auth Rate Enhance, an advanced configuration of Chargeback Guarantee, helps to increase trust with issuing banks and improve authorization rates by sharing enriched order data via direct integrations with partners including Capital One, Discover and Bank of America. Building upon this foundation, Adaptive Checkout further optimizes conversions by dynamically adapting each checkout flow based on real-time assessments, leveraging one time password, CVV check, or smart recommendations for 3D Secure routing to ensure more good customers are approved without taking on additional risk. It also includes PSD2 optimization for certain European orders where Strong Customer Authentication (SCA) is mandated by the European Payment Directives, to help increase total conversion and reduce cart abandonment. In addition, we have built a first-class Chargeback Management System, which is a key component of our Dispute Resolve product. This workflow product is designed to aid our merchants when they dispute chargebacks for which Riskified is not liable, through a process known as “representment”. With Dispute Resolve, we are able to utilize our network data, machine learning technology, and integrations with payment gateways to provide merchants with a single pane of glass to see and manage all of their chargebacks effectively, while automating key elements of the dispute process, such as compiling “compelling evidence” submissions for fraud and non-fraud related chargeback abuse, which can occur when consumers knowingly take advantage of the chargeback process (commonly referred to as “liar buyer” or “friendly fraud”). The visibility, automation and speed that we are able to provide in the chargeback “representment” process augments our Chargeback Guarantee offering, and is an important component of our comprehensive chargeback management solution.
The growth of our merchant network has enabled us to identify many other pain points that our decisioning engine can help solve for our merchants. We are able to help solve these problems using the extensive information we collect from our merchants’ online store fronts and back-end systems including but not limited to, their order management, fulfillment, payments, refunds, returns and other customer support systems.
Our Policy Protect product uses machine learning to detect and prevent refund and returns policy abuse in real-time whenever consumers may be taking advantage of a merchant’s Terms and Conditions. Policy Protect is powered by a proprietary engine that forms identity clusters from billions of historical transactions, hundreds of billions of data attributes, and repeat interaction histories for more than 1 billion consumers, across a global merchant network, broadening the view of customer identity beyond their singular profile with a merchant. Policy Protect helps merchants balance generous policies while protecting their bottom line. With Policy Protect, we enable merchants to offer lenient refund and returns policies, attractive promotions and loyalty programs, and launch limited edition items to their loyal customers while reducing losses associated with return abuse, reseller abuse and other forms of online policy abuse with high levels of accuracy. Our Dynamic Returns feature within Policy Protect also optimizes return flows (including instant refunds) based on customer behavior and abuse risk. This allows merchants to provide unique benefits to good customers, which improves their shopping experience, loyalty and life time value, without risking abuse. Merchants can leverage the power of Policy Protect in Decision Studio, a powerful suite of tools that provides AI-powered self-service capabilities for the creation, simulation, and management of customer-facing policies. Through a seamless blend of enriched
58
data points with dynamic AI-powered logic based on Riskified's identity and risk models, Decision Studio is designed to give merchants the power to achieve a delicate balance between human expertise and AI-based automation. This provides merchants with more control over their refund, return, promo and resale policies.
Our Account Secure product cross-checks every login attempt against the account owner’s behavior across our entire merchant network, and provides precise real-time actions on compromised accounts such as notification to the true account owner or multi-factor authentication (MFA). Account Secure provides good customers with a better experience by reducing friction while preventing fraudsters and other bad actors from compromising the accounts.
We continuously evaluate our product suite to ensure that we are investing in and allocating resources to those products that deliver the highest return on investment for our merchants and our shareholders. From time-to-time, we may elect to deprioritize investment in an existing product or to discontinue a product entirely.
Benefits of Our AI-powered ecommerce Risk Intelligence Platform
We believe we provide superior outcomes for online merchants by eliminating the friction and uncertainty commonly associated with ecommerce. Our AI-powered ecommerce risk intelligence platform is designed to provide the following benefits:
•Increase sales: We allow merchants to generate higher revenues by increasing their approval rates for online transactions.
•Reduce fraud: Our platform automatically identifies and rejects fraudulent online transactions that would result in unnecessary expenses for our merchants. We also assume the cost of fraudulent transactions if they are approved.
•Reduce operating costs: We replace antiquated systems and labor-intensive, costly fraud fighting methodologies with automated algorithms that save our merchants significant time and money. By reducing the operating costs our merchants incur, we free business resources that can be redirected towards growing their businesses.
•Optimize consumer experiences: Higher approval rates mean lower consumer drop-off and fewer false declines of legitimate consumers. Our product gives merchants the ability to take full advantage of omnichannel flows such as buy-online-pickup-in-store and buy-online-pickup-at-curb without increasing the risk of fraudulent sales. In addition, we enable merchants to maintain consumer-friendly policies by preventing policy abuse and malicious account logins. This builds a stronger, long-term relationship between merchants and consumers, driving more sales to merchants over time.
•Leverage the power of the Riskified network: Our AI-powered ecommerce risk intelligence platform gets stronger with each transaction we process and each merchant we add to our network. Our platform evaluates millions of transactions daily using feedback and insights derived from all prior transactions. Each transaction that we review enhances our data sets and improves our ability to identify similar characteristics between transactions on our network. We are able to identify individual consumers within our network and across different merchants to map their behaviors and identify patterns, which, in some instances may result in fraud.
What Sets Us Apart
We generate substantial return on investment for our merchants
We generate substantial return on investment throughout the lifecycle of our relationships with our merchants by increasing merchants’ online sales, reducing their operating costs and enhancing their
59
consumers’ shopping experiences. We believe that the active performance management we perform is an important driver of our merchants' return on investment. We provide performance management through a combination of real time monitoring, proprietary tools, and surgical optimization of specific subsets of our merchants' order volumes.
Powerful flywheel effect
We are a market leader in ecommerce risk intelligence. We believe that we receive access to significantly more customer data per transaction than banks and other payment companies and that this privileged level of access means that we are able to provide superior ecommerce fraud and risk analytics. We have built our products around this capability and, as of December 31, 2025, review more than $155 billion in GMV annually. Our AI-powered ecommerce risk intelligence platform gets stronger with each transaction we process and each merchant we add to our network. Each transaction that we review enhances our data sets and improves our ability to identify similar characteristics between transactions on our network. Our platform evaluates millions of transactions daily using feedback from past transactions, including whether or not those transactions resulted in eligible chargebacks. This drives our sophisticated transaction matching ability. As we grow our network, by increasing GMV from existing merchants and by onboarding new merchants, this sophisticated transaction matching enables us to deliver a strong return on investment for our merchants and drives robust product innovation that enhances the consumer shopping experience. We then leverage this improved ROI for our merchants and our enhanced product suite to attract more merchants, which drives more transactions to our platform.
Compounding data advantages over a growing merchant network
Since our founding, we have accumulated billions of historical transactions from our merchant network with hundreds of data variables per transaction. As a result we have repeat interaction histories for more than 1 billion consumers. This data was collected across our global merchant base comprising hundreds of leading ecommerce merchants, with whom we have built trusted relationships. As a result, our AI Technologies are able to create powerful, real-time predictive insights that we believe are difficult to replicate.
The scale of our merchant network and processed volume continue to grow. For the year ended December 31, 2025, our total GMV grew 10% year-over-year to $155.1 billion. We serve some of the largest and most recognizable ecommerce brands globally. Based on data available to us, our merchant base includes approximately 50 publicly held companies worldwide. We believe the scale of our AI-powered ecommerce risk intelligence platform is a competitive advantage because it is the foundation of the scope, depth and power of the data we use to train our models.
Strong expertise serving the enterprise market
We service merchants of all sizes, from multi-billion dollar global omnichannel retailers to small pure play merchants, including via partnership and/or integrations with Shopify and other ecommerce platforms, such as Salesforce Commerce Cloud, AWS Marketplace, Commercetools, Adobe Commerce, IXOPAY and others. However, we focus on supporting enterprise merchants, which we define as merchants generating over $75 million in online sales per year. For the year ended December 31, 2025, we estimate that more than 90% of our Billings were derived from enterprise merchants. We are positioned to support enterprise merchants for several reasons. First, our AI-powered ecommerce risk intelligence platform is highly customizable to meet each merchant’s unique requirements. Second, we are able to simplify the vast amounts of complexity that are unique to enterprise operating environments. Third, unlike many ecommerce enablement platforms, we do not compete with our merchants to own the consumer relationship through mobile apps or other touch points. We believe this gives us privileged access to significantly more data than banks or other payment companies receive. In addition, in 2025 we achieved both the Amazon Web Services Retail and Consumer Packaged Goods Competency designations for proven success in helping global merchants stop fraud, prevent abuse, and grow
60
revenue with confidence, while delivering validated solutions that help consumer goods and retail brands overcome operational challenges in digital commerce.
Entrepreneurial culture fostering continuous innovation
Our culture is an essential component of our success that allows us to hire and retain top talent. We strive to nurture a highly collaborative working environment where everyone, no matter what location or role, is empowered to solve challenging problems while also contributing to the communities we live in. Our Operating Principles (Clients Success First, Drive Results, Team Up, and Stay Ahead) lay out how our employees should operate to drive success for our clients. We empower our team members to learn and grow and make a conscious effort to promote people from within, offer varied development opportunities, and create space for people to try new things and utilize their unique skill sets. We also host a Fraud Academy for our analytics employees, which includes approximately 60 hours of formal training, to help our team members further develop their skills.
Our Merchants
Our AI-powered ecommerce risk intelligence platform is explicitly designed and engineered to integrate with a wide range of merchants. We can accommodate and grow with the world’s largest merchants:
•Scale: We serve merchants with multiple regional store fronts and large global presences. Our largest merchants generate tens of billions of dollars in online sales each year.
•Industry: Our merchants represent diversified online sellers in various industries such as Tickets & Travel, Fashion and Luxury, Money Transfer and Payments, Electronics and Home. We categorize general retail merchants and food merchants within our “General” category.
•Merchant Profile: Our merchants range from direct-to-consumer brands, online-only retailers, omnichannel retailers, online marketplaces, and ecommerce service providers that bear the liability for disputed transactions.
•Geography: Our merchants are located in approximately 36 countries based on the location of the merchant’s headquarters. Approximately 54% of our Billings for the year ended December 31, 2025 were derived from US-based accounts. Our Billings in Asia-Pacific increased by 53% year-over-year in 2025.
Billings by Industry
61
62
Billings by Geography
For the year ended December 31, 2025, merchants integrated on our AI-powered ecommerce risk intelligence platform generated total GMV of $155.1 billion, up from $141.2 billion GMV for the year ended December 31, 2024. Our network is made up of hundreds of retailers including some of the largest ecommerce brands in the world, such as Ring, Lastminute.com, SHEIN, and Macy’s.
For information regarding segmental revenue and revenue by geographic region, see Note 4 - Revenue Recognition in our audited consolidated financial statements included elsewhere in this Annual Report.
Go-to-Market Strategy
We market our AI-powered ecommerce risk intelligence platform directly to online merchants primarily through our enterprise sales team, with a strong focus on long-term customer value. Our seasoned direct sales team is highly skilled in identifying online merchant pain points, demonstrating our value-add and providing dedicated support to address the online merchants’ needs.
Some merchants prefer the flexibility to start their relationship with us by submitting only a portion of their order volumes to us. We welcome this approach and have successfully implemented a “Land and Expand” strategy, where we create long-term partnerships that result in strong retention and revenue that is likely to recur. As we gain our merchant’s trust, we are generally able to increase the order volume they submit to us and the value we provide. In addition, our multi-product platform, comprising Chargeback Guarantee, Policy Protect, Dispute Resolve and Account Secure, provides our sales teams with multiple
63
entry-points into the ecommerce market, which is designed to create a continuous sales motion and increased merchant coverage.
Seasonality
We experience seasonal fluctuations in our revenue as a result of consumer spending patterns. Historically, our revenue has been strongest during the fourth quarter of our fiscal year due to increases in retail commerce during the holiday season. See Item 5.D. “Trend Information” for a description of the seasonality of our business.
Intellectual Property
Intellectual property rights are important to the success of our business. We rely on a combination of copyright, trademark and trade secret laws in the United States and in other jurisdictions, as well as confidentiality procedures and contractual obligations in contracts with employees, contractors and third parties, to establish and protect our intellectual property, including our proprietary technology, know-how and brand. We have chosen not to register any copyrights and we do not currently have any patents or pending patent applications, and instead rely primarily on trade secret protection to protect our proprietary software. Further, while we believe intellectual property is important, we believe that factors such as the technological and creative skills of our personnel, creation of new features and functionality, and frequent enhancements to our models, features and proprietary technology are more essential to establishing and maintaining our technology leadership position.
The Riskified brand is central to our business strategy, and we believe that maintaining, protecting and enhancing the Riskified brand is important to expanding our business. As of December 31, 2025, we held four registered trademarks in the United States and thirty-two registered trademarks in foreign jurisdictions, including registrations of RISKIFIED, eConfidence and the Riskified logos. As of December 31, 2025, we had applied for one additional trademark registration in foreign jurisdictions.
Despite our efforts to protect our proprietary rights, competitors or other unauthorized parties may attempt to misappropriate our technology or may independently develop similar technologies, and we may not be able to prevent competitors from selling products incorporating those technologies. For more information regarding the risks relating to intellectual property, see Item 3.D. “Risk Factors — Risks Relating to Our Business and Industry — Any failure to protect our intellectual property rights could impair our ability to protect our proprietary technology and our brand.”
Government Regulation
As with any company operating in our field, we grapple with a growing number of local, national and international laws and regulations. These laws are often complex, sometimes contradict other laws, and are frequently evolving. Laws may be interpreted and enforced in different ways in various locations around the world, posing a significant challenge to our global business. This ambiguity includes laws and regulations possibly affecting our business, such as those related to data privacy and security, artificial intelligence and machine learning, pricing, taxation, intellectual property ownership and infringement, anti-money laundering, anti-corruption, product liability, consumer protection, financing, payment authentication, economic and financial sanctions, trade embargoes, and export control. Changes to such laws and regulations could cause us or third-party partners on which we rely to incur additional costs and change our or their respective business practices in order to comply. See “— Data Protection and Privacy”, “—Anti-Corruption and Sanctions” and “—Artificial Intelligence” for further discussion related to the impact of government regulation on our business.
Data Protection and Privacy
We are subject to laws across several jurisdictions regarding privacy and protection of data. Laws and regulations related to data protection, privacy, cybersecurity, consumer protection, financing, payment authentication, point-of-sale lending, and other laws and regulations can be very stringent and
64
vary from jurisdiction to jurisdiction. These laws govern how companies collect, process, and share data, grant rights to data subjects, and require that companies implement specific information security controls to protect certain types of information.
For example, we are subject to the PPL and its regulations (including the Data Security Regulations) (collectively, “Privacy Laws”), which impose obligations regarding how personal data is processed, maintained, transferred, disclosed, accessed and secured. In addition, the Privacy Protection Regulations (Transfer of Data to Databases Outside the State Borders), restrict and impose conditions on cross-border transfers of Personal Information from Israel. The Privacy Laws may require us to adjust our data protection and data security practices, information security measures, certain organizational procedures, applicable positions (such as an information security manager) and other technical and organizational security measures. To the extent that any administrative supervision procedure is initiated by the PPA that reveals irregularities with respect to our compliance with the Privacy Protection Act, in addition to our exposure to administrative fines, civil claims (including class actions) and in certain cases criminal liability, we may also need to take remedial actions to rectify such irregularities, which may increase our costs.
In the EEA and UK, we are also subject to the EU GDPR and the UK GDPR, as well as national legislation supplementing the GDPR and the UK GDPR. The GDPR and UK GDPR implement stringent operational requirements regarding, among others, data use, sharing and processing, data breach notifications, data subject rights and cross- border data transfers. In relation to data transfers to the US, the EU-US Data Privacy Framework, the successor of the EU-US Privacy Shield entered into effect in July 2023, and the UK has enacted the UK extension to the EU-US Data Privacy Framework to facilitate EU-US and UK-US data transfers, respectively.
Further, following Brexit, the UK government has indicated its intention to diverge from the EU’s privacy framework. These prospective changes may require us to make changes to our data privacy compliance operations and/ or to our business practices and may result in substantial costs, which in turn may compromise our growth strategy and otherwise adversely affect our business.
The EU GDPR and UK GDPR impose significant penalties for non-compliance (up to EUR 20 million for breaches of the EU GDPR, or GBP 17.5 million in the case of the UK GDPR or up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher).
We are also subject to evolving EU and UK privacy laws on cookies, tracking technologies and e-marketing. In the EU and UK, consent may be required for the placement of certain cookies or similar tracking technologies on an individual’s device and for direct electronic marketing. Such consent is tightly defined and includes a prohibition on pre-checked consents and a requirement to obtain separate consents for each type of cookie or similar technology. Recent European court and regulator decisions are driving increased attention to cookies and similar tracking technologies.
On December 16, 2020, the European Union published a new cybersecurity strategy which aims at adapting online and offline security requirements in response to growing interconnectedness and digitization. In December 2022, the Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148, or the NIS 2 Directive, was published in the official journal of the European Union. As EU Member States were required to adopt the NIS 2 Directive into national law by October 17, 2024, however, not all of them have done this yet, so it is difficult to assess the impact on our business or operations, but it may require us to modify our cybersecurity practices and policies and we could incur substantial costs as a result.
On November 1, 2022, the Digital Markets Act, or the DMA, entered into force and on November 16, 2022, the Digital Services Act, or the DSA, followed. As further guidance is issued and interpretation of both the DSA and the DMA evolves, it is difficult to assess the impact of the DSA and DMA on our
65
business or operations, but, to the extent applicable, it may require us to modify our practices and policies and we could incur substantial costs as a result.
We are also subject to Lei Geral de Proteção de Dados, which imposes similar requirements to the GDPR on the collection and processing of data of Brazilian residents.
We are also subject to the CCPA, which, among other things, gives California residents rights regarding their Personal Information, including rights to opt out of certain Personal Information sharing/selling and requires in-scope business to provide California residents detailed information about how their Personal Information is used and disclosed. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches. Similar laws coming into effect in numerous other U.S. states, the potential for adoption of a comprehensive U.S. federal data privacy law, and new legislation in international jurisdictions may continue to change the data protection landscape globally and could result in us expending considerable resources to meet these requirements.
Additionally, in China, we are subject to the CSL, DSL, PIPL and other data-related regulations, such as the Cybersecurity Review Measures. The CSL requires certain network operators and service providers to, among other things, take necessary measures to safeguard the operation of networks and imposes certain additional requirements on CIIOs. The DSL provides for data security and privacy obligations on entities and individuals carrying out data processing activities, including but not limited to the collection, storage, use, processing, transmission, provision, and public disclosure of data. The DSL also requires data processors to establish and improve a whole-process data security management system, organize data security education and training, and take corresponding technical measures and other necessary measures to safeguard data security. The DSL requires a national security review procedure for those data activities which may affect national security and imposes export restrictions on certain data and information. Under the Cybersecurity Review Measures, a network platform operator who possesses personal data of more than one million users is required to apply for a cybersecurity review before listing in a foreign country, and the competent governmental authorities may initiate a cybersecurity review if they deem certain network products or services or data processing activities to affect national security. Network platform operators are not defined but are understood to be broadly interpreted to include all network platform operators or service providers, thus providing for a broad application. A mandatory cybersecurity review is likely to prolong the timeline of any contemplated listing abroad and increase the regulatory burden on entities that are subject to this requirement. The PIPL became effective on November 1, 2021. Notably, the PIPL, similar to the GDPR, applies extra-territorially and reiterates the circumstances under which a personal information processor may process personal information, such as when (i) the individual’s consent has been obtained; (ii) the processing is necessary for the performance of a contract to which the individual is a party; (iii) the processing is necessary to fulfil statutory duties and statutory obligations; (iv) the processing is necessary to respond to public health emergencies or protect the life, health and property safety of natural persons under emergency circumstances; (v) the personal information that has been made public is processed within a reasonable scope in accordance with the PIPL; (vi) personal information is processed within a reasonable scope to conduct news reporting, public opinion-based supervision, and other activities in the public interest; or (vii) under any other circumstance as provided by any law or regulation. Failure to comply with PIPL can result in fines of up to RMB 50 million or 5% of the prior year’s total annual revenue for the personal information processor and/or a suspension of services or data processing activities. Other potential penalties include a fine of up to RMB 1 million on the person in charge or directly-responsible personnel and, in serious cases, individuals and entities may be exposed to criminal liabilities under other local Chinese law, such as the Criminal Law of the People’s Republic of China. The PIPL also prohibits personnel responsible for violations of the PIPL from holding high level management or data protection officer positions in relevant enterprises. The CSL, DSL and PIPL also impose certain data localization requirements on CIIOs, important data processors and organizations that process personal information above a certain threshold, unless an exemption applies. Furthermore, the national regulators, namely the Cybersecurity Administration of China and the State Administration of Market Regulation, have continued to issue new guidance and requirements for the processing of personal data. As the introduction of new compliance
66
requirements that occur on an ongoing basis typically apply with immediate effect, they may lead to additional costs and may require further changes to our compliance operations. See Item 3.D. “Risk Factors —Risks Related to our Business and Industry—Compliance with continuously evolving privacy laws and regulations, including laws and regulations governing processing of personal information, including payment card data, and our actual or perceived failure to comply with such laws and regulations may result in significant liability, negative publicity, and/or erosion of trust and could have an adverse effect on our revenues, our results of operations and financial condition.”
Data protection regulators may seek jurisdiction over our activities in locations in which we process data or have users but do not have an operating entity. Where the local data protection and privacy laws of a jurisdiction apply, we may be required to register our operations in that jurisdiction or make changes to our business so that user data is only collected and processed in accordance with applicable local law. In addition, because our products are accessible from various jurisdictions, certain foreign jurisdictions may claim that we are required to comply with their privacy and data protection laws, including in jurisdictions where we have no local entity, employees or infrastructure. In such cases, we may require additional legal review and resources to ensure compliance with any applicable privacy or data protection laws and regulations. In addition, in many jurisdictions there may in the future be new legislation that may affect our business and require additional legal review.
Anti-Corruption and Sanctions
We are subject to laws and regulations of the jurisdictions in which we operate, including the United States, United Kingdom, European Union and Israel, that govern or restrict our business and activities in certain countries and with certain persons, including the economic and financial sanctions and trade embargo regulations administered by the U.S. Treasury Department’s Office of Foreign Assets Control, the U.S. Department of State, and the export control laws administered by the U.S. Commerce Department’s Bureau of Industry and Security as well as by authorities of the United Kingdom, the European Union, the State of Israel, the United Nations Security Council, and other relevant sanctions and export control authorities.
Additionally, we are subject to anti-corruption, anti-bribery, anti-money laundering, terror finance and similar laws imposed by governments around the world with jurisdiction over our operations, which may include, among others, the FCPA, the U.S. domestic bribery statute contained in 18 U.S.C. 201, the U.S. Travel Act, the USA PATRIOT Act, the U.K. Bribery Act 2010, Chapter 9 (sub-chapter 5) of the Israeli Penal Law, 5737-1977, the Israeli Prohibition on Money Laundering Law, 5760-2000 and other applicable laws in the jurisdictions in which we operate. Historically, technology companies have been the target of FCPA and other anti-corruption investigations and penalties. See Item 3.D. “Risk Factors—Risks Related to our Business and Industry—Our failure to comply with the anti-corruption, trade compliance, anti-money laundering and terror finance and economic sanctions laws and regulations of the United States and applicable international jurisdictions could materially adversely affect our reputation and results of operations.”
67
Artificial Intelligence
Our business heavily relies on AI Technologies, and the regulatory framework for this technology is rapidly evolving. Already, certain existing legal regimes (e.g. relating to data privacy) regulate certain aspects of AI Technologies, and many federal, state and foreign government bodies and agencies have enacted or are currently considering additional laws and regulations governing AI Technologies. Additionally, existing laws and regulations may be enjoined in judicial proceedings, or may be interpreted or enforced in ways that would affect the operation or use of our AI Technologies, or could be rescinded or amended as new administrations take differing approaches to evolving AI Technologies. In the United States the regulatory framework for AI Technologies faces significant uncertainty. At the federal level, Congress has yet to enact meaningful AI legislation. Instead, federal policy on AI has been shaped by a series of executive orders that have shifted priorities and requirements substantially depending on the administration in power. In the absence of federal AI legislation, states have filled the void by enacting laws regulating different aspects of AI Technologies. For example, California has enacted laws and regulations related to AI safety protocols, reporting and transparency, among other AI-related topics. In addition, Colorado’s Artificial Intelligence Act will require developers and deployers of “high-risk” AI systems to implement certain safeguards against algorithmic discrimination (among other requirements), Utah’s Artificial Intelligence Policy Act establishes disclosure requirements and accountability measures for the use of generative AI in certain consumer interaction, and the Texas Responsible Artificial Intelligence Governance Act prohibits the development and deployment of AI systems for certain purposes while establishing a regulatory sandbox. Moreover, state AI laws such as Colorado’s Artificial Intelligence Act and various comprehensive state privacy laws, including the CCPA, regulate the use of automated decision-making technology that results in legal or similarly significant effects on individuals, and provide rights to individuals with respect to that automated decision making. Many states have also enacted sector-specific AI laws, including related to the use of AI for health-related purposes and financial services. Additionally, new laws regulating artificial intelligence – in particular generative artificial intelligence, algorithmic recommendation and deep synthesis technologies - have been enacted in China, and in August 2024, the European Union’s EU AI Act entered into force, establishing a comprehensive, legal framework for the regulation of artificial intelligence systems across the EU. The majority of obligations under the EU AI Act will apply from August 2026, and once fully applicable, the EU AI Act will have a material impact on the way artificial intelligence is regulated in the EU, including requirements around transparency, conformity assessments and monitoring, risk assessments, human oversight, security, accuracy, training, data transparency, copyright compliance and technical documentation. There is also an increase in litigation in a number of jurisdictions, including the United States, relating to the development, security and use of artificial intelligence. See Item 3.D. “Risk Factors—Risks Related to our Business and Industry—As the regulatory framework for machine learning technology and artificial intelligence evolves, including with respect to unintentional bias and discrimination, our business, financial condition, and results of operations may be adversely affected.”
Environmental, Social and Governance
As we continue to establish ourselves as a global company, with employees, customers, suppliers and shareholders all over the world, the way that we think about ourselves, our communities and our governance practices has also evolved, including through the lens of ESG best practices.
Environmental
As a business that is conducted predominantly online, our direct carbon footprint is likely to be smaller than those of manufacturing or other resource-intensive businesses. We do, however, also have indirect emissions and other environmental impacts; while we believe these are also smaller than companies in other sectors, we still strive to make sustainable choices and to limit our impact on the environment and climate in various ways.
68
We have identified two primary sources of environmental impact related to our business operations: (1) our reliance on data centers; and (2) energy consumption and waste derived from our primary office locations in Tel Aviv and New York.
•Data Centers: We do not own or operate our data centers. Instead, we outsource substantially all of the infrastructure relating to our cloud offerings to major vendors such as Amazon Web Services, many of whom have publicly committed to ambitious sustainability targets.
•Office Initiatives: We track our monthly energy usage in our Tel Aviv and New York offices. In addition, to aid in the promotion of environmental conservation, we have implemented a number of waste and energy management initiatives. Our Tel Aviv office, which is our largest site, has received Leadership in Energy and Environmental Design (“LEED”) Operations & Maintenance V4.1 certification with a “Gold” rating.
Social
“Riskified Cares” is our in-house program encompassing social responsibility programs including, community outreach, sustainability and inclusion and belonging:
•Inclusion & Belonging: Our mission is to empower businesses to unleash ecommerce growth by outsmarting risk. We focus on maximizing our merchants’ success, because when they succeed, we succeed. In order to deliver on this mission, we believe it is important to employ a workforce that embodies a range of backgrounds, thoughts, experiences, skills, qualifications and perspectives to expertly assist our broad merchant base.
We are committed to building an inclusive talent base, while attracting and retaining the brightest and most talented individuals from a range of backgrounds. One of the ways we do this is by supporting certain employee community groups, which are open to all employees.
In addition, we believe personal and professional growth are imperative to the well-being of our employees. We have a Learning & Development team that develops and facilitates initiatives that provide our employees with opportunities to acquire new skills through exploration, experience, and peer learning. For example, we offer trainings designed to teach our employees how to leverage AI tools to enhance efficiency and productivity while ensuring that they use those tools in a safe and ethical manner. Finally, we support career pathing through role-specific development plans, 1:1 coaching through external experts, and internal mentoring initiatives that are available to all employees across the organization. For those in or aspiring to leadership roles, we offer a dedicated suite of programs designed to develop management skills and promote engagement, including our Manager Orientation Program, Manager Acceleration Program, and targeted managerial skills workshops.
In addition, we have an Employee Experience team that is dedicated to supporting our employees’ physical and mental health. We offer well-being benefits that vary by location, including extended health insurance and free group fitness classes.
•Compensation Framework: we have implemented a comprehensive framework which guides our pay decisions. We use an objective job evaluation methodology to reduce subjectivity and bias in pay decisions, leading to greater equity in employee compensation.
•Community Outreach: We focus on social matters that impact our people and the communities in which they live. We recognize and respect our employees’ passion for engaging with their local communities, and actively encourage and facilitate this engagement. For example, we have established a robust community volunteering program that enables employees to give back to the communities in which they live and work by volunteering on company time. For the year ended December 31, 2025, our employees volunteered approximately 1,250 hours across 30 different not-for-profit organizations. In addition, in 2025 we received TrustRadius’ “Tech Cares” award for
69
a fourth consecutive year. The TrustRadius “Tech Cares” awards recognize companies that go beyond business as usual, by implementing impactful programs for staff, local communities and others in need.
Governance
We seek to uphold corporate governance practices that align with our core values and protect the interests of our stakeholders, including our shareholders, merchants, employees and communities.
Our Board of Directors has appointed audit, compensation and nominating and governance committees, all guided by committee charters delegating key responsibilities. The roles of each committee are set forth elsewhere in this Annual Report. We have adopted Corporate Governance Guidelines and other key policies, including a Code of Business Conduct and Ethics, an Anti-Corruption Compliance Policy, and a Whistleblower Policy. See Item 6.C. “Board Practices—Corporate Governance Practices.”
C. Organizational Structure
The legal name of our company is Riskified Ltd. and we are organized under the laws of the State of Israel.
Our subsidiaries as of December 31, 2025, are set forth in the table below. Each subsidiary is 100% owned directly by Riskified Ltd.
Name of Subsidiary Place of Incorporation
Riskified, Inc. Delaware, USA
Riskified (Shanghai) Information Technology Co., Ltd Shanghai, People’s Republic of China
Riskified (Japan) K.K. Japan
D. Property, Plants, and Equipment
Our principal facilities are located in Tel Aviv in Israel and in New York City in the United States and consist of an aggregate of approximately 9,510 square meters (approximately 102,350 square feet) of leased office space, which includes approximately 2,490 square meters (approximately 26,830 square feet) of space that we sublease to other tenants. See Item 5. “Operating and Financial Review and Prospects—Liquidity and Capital Resources” for a discussion of costs incurred during the periods presented relating to the expansion and improvement of our facilities.
These facilities accommodate our principal executive offices, research and development, sales and marketing, design, business development, finance, information technology, and other administrative activities. The leases for these facilities in Tel Aviv and New York City expire in 2031 and 2029, respectively and we have options to renew the leases through 2036 and 2034, respectively.
We also lease space in Shanghai, China and Lisbon, Portugal. We believe that our facilities are adequate to meet our needs for the immediate future, and that, should it be needed, suitable additional space will be available to accommodate any such expansion of our operations.