{"url_path":"/sec/airi/10-k/2026/item-9a","section_key":"item-9a","section_title":"Item 9A CONTROLS AND PROCEDURES**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-03-27","source_url":"https://www.sec.gov/Archives/edgar/data/1009891/0001213900-26-035731-index.html","accession_number":"0001213900-26-035731","cik":"0001009891","ticker":"AIRI","issuer_name":"AIR INDUSTRIES GROUP","edgar_url":"https://www.sec.gov/Archives/edgar/data/1009891/0001213900-26-035731-index.html","primary_entity_key":"0001009891","primary_entity_name":"AIR INDUSTRIES GROUP"},"word_count":898,"has_tables":true,"body_markdown":"**ITEM 9A. CONTROLS AND PROCEDURES**\n\n \n\n*Evaluation of Disclosure Controls and Procedures*\n\n \n\nAn evaluation was conducted under the supervision and with the participation\nof our management, including the Chief Executive Officer (“CEO”), our principal executive officer, and Chief Financial Officer\n(“CFO”), our principal financial officer (“PFO”), of the effectiveness of the design and operation of our disclosure\ncontrols and procedures, as defined in Rule 13a-15(e) and Rule 15d-15(e) of the Exchange Act, as of December 31, 2025. Based on that evaluation,\nthe CEO and CFO concluded for the reasons discussed below that our disclosure controls and procedures were not effective as of December\n31, 2025 to ensure that the information required to be disclosed by us in the reports that we file or submit under the Exchange Act, is\nrecorded, processed, summarized and reported within the required time periods, and that such information is accumulated and communicated\nto our management to allow timely decisions when required.\n\n \n\n*Management’s Report on Internal Control\nover Financial Reporting*\n\n \n\nSection 404 of the Sarbanes-Oxley Act of 2002\nrequires that management document and test the Company’s internal control over financial reporting and include in this Form 10-K\na report on management’s assessment of the effectiveness of our internal control over financial reporting.\n\n \n\nManagement is responsible for establishing and\nmaintaining adequate internal control over financial reporting. Internal control over financial reporting refers to those policies, procedures\nand processes that pertain to the maintenance of records that accurately and fairly reflect transactions with respect to our assets; provide\nreasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally\naccepted accounting principles and that receipts and expenditures are made only in accordance with authorizations of our management; and\nprovide reasonable assurance regarding the prevention and timely detection of unauthorized transactions with respect to our assets that\ncould have a material effect on our financial statements.\n\n \n\nBecause of inherent limitations, internal control\nover financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods\nare subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the\npolicies or procedures may deteriorate.\n\n  \n\nManagement assessed the effectiveness of our internal\ncontrol over financial reporting as of December 31, 2025. In making this assessment, management used criteria set forth by the Committee\nof Sponsoring Organizations of the Treadway Commission in Internal Control – Integrated Framework (2013).\n\n \n\nIn connection with their review of our internal control over financial\nreporting as of December 31, 2025, our Chief Executive Officer and Chief Financial Officer have concluded that our internal controls over\nfinancial reporting were not effective as of December 31, 2025 as a result of a material weakness identified in 2022 that were not yet\nremediated.\n\n \n\nHistorically, we outsourced certain information technology (“IT”)\nrelated functions to a third-party vendor. In 2022, we identified a material weakness with respect to our IT systems in that we did not\ndesign and/or implement primary user access controls and program change management systems over key IT systems to validate that data produced\nby the relevant IT systems were complete and accurate and to ensure appropriate segregation of duties to adequately restrict user and\nprivileged access to the financially relevant systems and data to the our personnel. Further, we identified a material weakness with respect\nto the activities of our vendor in connection with the design and operation of our IT systems in that because this vendor is unable to\nprovide a SOC 1 (Standard Operating Control) Report, we were unable to verify and validate the effectiveness of the vendor’s control\nprocedures when implementing changes to our IT systems, including systems affecting our financial IT applications and underlying data\naccount records.\n\n \n\n34\n\n \n\n \n\nIn fiscal 2024 and continuing in fiscal 2025,\nwe implemented new IT controls that required our third-party vendor to make only changes to our IT systems with specific authorization\nand a requirement that such change be monitored, in real-time by an employee of our company that is familiar with the changes that are\nbeing made by our third-party vendor. Although we implemented a process to monitor users being granted privileged access and that such\naccess is being monitored by a periodic user review process, additional enhancements and more formalized documentation is still required.\nAs such, we consider this material weakness not to be remediated as of December 31, 2025.\n\n \n\nThis annual report does not include an attestation\nreport of our registered public accounting firm regarding internal control over financial reporting. The rules of the Securities and Exchange\nCommission do not require an attestation of the Management’s report by our registered public accounting firm in this annual report.\n\n \n\n**Change in Internal Control over Financial Reporting**\n\n \n\nDuring the fourth quarter of 2025, we implemented and enhanced our\ninternal control over financial reporting to include additional processes to monitor users being granted privileged access and enhanced\nour periodic user reviews to ensure such privileged access continues to be appropriate. Except for these items, there have not been any\nchanges in our internal control over financial reporting, as such term is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange\nAct, during our most recently completed fiscal quarter ended December 31, 2025, which is the subject of this report, that have materially\naffected, or are reasonably likely to materially affect, our internal control over financial reporting."}