Most investors read an S-1 (the registration form a company files with the SEC before selling shares to the public for the first time) for one number: the valuation. They skim past everything else. Institutional analysts read three sections of that same filing as one connected story:
- The risk factors,
- The MD&A (Management's Discussion and Analysis, where leadership explains the numbers in their own words),
- Footnotes buried in the financial statements.
This framework shows exactly how that's done, using SpaceX's actual 2026 S-1 as the live example throughout.
Why Every S-1 Follows the Same Map
Every S-1 has to lay out its sections in a specific order, because the SEC requires it. Risk factors are governed by Item 105 of Regulation S-K, which the SEC substantively amended in August 2020. That amendment tightened the standard from disclosing a company's "most significant" risks to its "material" ones, and added a requirement that any risk factor section running over 15 pages must open with a concise, bulleted two-page summary. If you're reading a source that still describes the older "most significant" standard, that source is out of date. MD&A, separately, is governed by Item 303.
Because every company has to follow this same structural map, the checklist in this article holds for any S-1 you read, not just SpaceX's.
Why the Risk Factors Section Is the Wrong Place to Skim
Risk factors do two jobs at once, and that dual purpose is exactly what trips readers up. They warn investors about real risks, and they legally protect the company. If a stock drops later, the company can point back to its own risk factors and say it gave fair warning. That's why risk factors tend to sound alarming and generic at the same time, and it's why a risk factor that breaks through the legal boilerplate to name an actual dollar figure deserves far more attention than one that doesn't.
SpaceX's May 2026 S-1 contains 36 pages of risk factors, and one of them puts a real number on the legal exposure tied to absorbing Musk's AI and social media companies: roughly $530 million in potential liability, including an Irish Data Protection Commission inquiry into Grok's handling of children's data. That's a risk factor worth tracking. A generic line about "regulatory uncertainty" with no figure attached isn't.
Reading through that risk factors section directly, the $530 million estimate sits roughly a third of the way down, right after two pages of standard, boilerplate regulatory language, a pattern worth knowing if you're trying to skim past the generic warnings to the numbers that actually matter.
Checklist: Risk Factor Section
- Look for dollar figures, not vague warnings. A risk factor with a real number is useful information. A line like "the market may be volatile" with nothing else attached is legal cover, not a signal.
- Watch for soft, reassuring language sitting right after a stated risk. Phrases like "actively managing this risk" or "well positioned to handle it" are the kind of downplaying language the SEC's 2020 amendments were specifically designed to discourage.
- Connect concentration risk to the actual numbers. SpaceX's Starlink business generated more than half of its 2025 revenue, around $11 billion, while its AI segment absorbed around 60% of 2025 capital spending, roughly $20 billion, while only growing revenue by about 22%. Any risk factor about depending on a single segment needs to be checked against numbers like these, not read in isolation.
- Watch for one person holding outsized control. SpaceX's S-1 shows Musk holding 93.6% of Class B shares, which carry ten votes each, giving him roughly 85.1% of total voting power at the time of listing. Secondary reporting on the post-IPO figure varies; some analyses put it closer to 82.4%, which is a reminder that voting power percentages shift depending on exactly when and how they're measured. What matters for a control risk assessment is that every credible estimate sits well above the 50% threshold, not the exact decimal.
- Notice large incentive packages disclosed near the risk section. SpaceX's filing includes a roughly 1.3 billion restricted share award for Musk, vesting on milestones that include a $7.5 trillion market cap target, alongside non-financial goals like a million-person Mars colony. Compensation tied to targets that extreme is worth flagging as a governance risk in its own right.
MD&A, Reading It the Way the SEC Actually Intended
MD&A exists to do three specific jobs, as laid out in the SEC's own interpretive guidance on the subject: let investors see the business through management's eyes, help investors judge whether past results predict future ones, and signal whether reported numbers are durable or one-time events.
Checklist: MD&A Section
- Find the "key drivers" discussion first, and check whether it lines up with what's disclosed in the risk factors and business strategy sections. A driver mentioned here that never shows up as a risk factor anywhere else is a gap worth noting.
- Check the numbers at both the whole-company and segment level. For SpaceX, that means reading MD&A's framing against the fact thattheAI segment alone posted a $6.35 billion operating loss in 2025, even while Starlink was profitable enough to carry the rest of the business.
- Read the critical accounting estimates section closely. The SEC wants companies to explain why a given estimate is uncertain, how accurate it's been historically, and how likely it is to change. A weak or evasive answer to any of those three questions tells you something on its own.
- Compare the liquidity discussion against the actual cash flow numbers. If MD&A stays silent on debt covenants while the debt footnotes show rising leverage, that silence is itself the signal worth chasing down.
Financial Statement Notes, Where the Real Accounting Choices Live
This is the section most retail readers skip entirely, and it's the section institutional readers read first.
Checklist: Financial Statement Notes
- Check whether the financial numbers are still current under SEC rules. Financial statements in a registration statement go stale after a set number of days following the fiscal year end, and the exact window shifts depending on filer status and fiscal year timing. Treat any specific day count you read as a general guide rather than a fixed universal rule, and confirm the precise window for the filer type in question before modeling it.
- Check segment numbers against the consolidated total. SpaceX's own filing shows the AI segment's capital spending running at roughly three times the rocket segment's,with total company capex climbing from $4.4 billion in 2023 to $20.7 billion in 2025. A single blended number for the whole company would hide that gap between spending and growth completely.
- Use the exhibit list as a map to the real contracts. Material agreements are filed as exhibits precisely because they're too important to summarize in a paragraph of prose. Reading the actual contract terms, not a sentence describing them, is the only reliable way to know what a company is actually bound to.
- Watch the $120,000 related-party threshold. Under Item 404 of Regulation S-K, a company must disclose any transaction over $120,000 involving an officer, director, or anyone owning 5% or more of the company. A transaction sitting right around that line deserves a closer look, since it's a hard threshold rather than a fuzzy judgment call. SpaceX's filing itself discloses several related-party transactions tied to the Tesla and xAI relationships, which is exactly the kind of disclosure this rule is designed to surface.
- Treat the use-of-proceeds section as a test, not a checklist item. As a general pattern, vague use-of-proceeds language tends to correlate with higher pricing uncertainty, while specific, itemized language tends to hold up better under scrutiny. SpaceX's own use-of-proceeds list opens specifically with "expansion of AI compute infrastructure," which is about as unambiguous as this kind of disclosure gets.
- Remember that not every dollar raised reaches the company's balance sheet. A meaningful slice, commonly in the 3% to 7% range for a standard-size deal, goes to the underwriting banks as a gross spread.
Connecting the Signals to an Actual Valuation Model
Spotting these signals only matters if you know how each one actually moves a valuation model. Here's the direct mapping:
- A quantified litigation risk, like SpaceX's $530 million legal cost estimate, lowers equity value directly or adds a discrete liability scenario to a sum-of-the-parts model.
- Segment concentration means applying different multiples to different segments rather than one blended multiple across the whole company, since a capex-heavy AI segment and a profitable satellite business don't deserve the same valuation lens.
- A capex-heavy, unprofitable segment lowers near-term free cash flow assumptions until spending efficiency actually shows up in the growth numbers.
- Dual-class control structures justify a governance discount, reflecting the reduced influence outside shareholders have over major decisions.
- Related-party transactions sitting near the $120,000 threshold trigger a quality-of-revenue adjustment, since insider-linked revenue isn't the same quality as arm's-length revenue.
- A vague use-of-proceeds section raises the uncertainty discount applied to the deal overall.
- Stale financials require an updated run-rate estimate before they can be modeled with any confidence.
SpaceX's own filing gives a clean illustration of why reading these signals together matters more than reading any one in isolation. The company describes a $28.5 trillion total addressable market, with the large majority of that figure, $26.5 trillion, attributed to AI, and a further $22.7 trillion of that specifically tied to enterprise AI applications. Whether a market opportunity that large actually supports the deal's valuation depends entirely on whether spending efficiency in the financial notes ever catches up to it, not on the size of the market figure by itself.
Quick Reference Table
Section | What to Extract | Risk If Ignored |
Risk factor specificity | Quantified, dollar-denominated risk vs. generic boilerplate | Overweighting risks with no real probability behind them |
Mitigating language | Reassurance language softening a stated risk | Underweighting a risk the company itself downplayed |
Concentration and segment risk | Revenue and capex broken out by segment | Valuing the whole company on one blended multiple |
Control and governance risk | Voting power, dual-class structure, incentive design | Missing a structural risk with no clean market comparable |
MD&A key drivers | Consistency with risk factors and business strategy | A growth story with no matching disclosed risk |
Critical accounting estimates | How uncertain, how accurate historically, how likely to shift | Treating a soft estimate as more solid than management claims |
Staleness clock | Days from fiscal year end, filer-status dependent | Modeling off financials the SEC no longer treats as current |
Related-party threshold | Transactions at or near $120,000 | Missing insider-linked revenue or expense |
Use of proceeds specificity | Stated vs. vague intended use | Mispricing and underestimating post-IPO capital discipline |
Run this checklist on any S-1 on EDGAR. Every claim in the filing exists to be checked against the real numbers sitting a few pages away, and the biggest signals tend to hide exactly where two separate sections quietly disagree.
Frequently Asked Questions
If two companies disclose similar dollar-figure risks, does that mean their actual risk exposure is the same?
Not necessarily. A quantified risk tells you the company's own estimate of potential exposure, but it doesn't tell you the probability of that exposure materializing. A $500 million litigation estimate tied to an active regulatory inquiry carries different weight than the same dollar figure tied to a hypothetical future scenario the company is required to disclose but considers unlikely.
Can a company legally avoid disclosing a risk it considers immaterial
Yes, and that's precisely why the 2020 amendments to Item 105 shifted the standard from "most significant" risks to "material" ones. Materiality is a legal judgment the company and its counsel make, which means a risk one analyst considers important might not clear the bar a company sets for itself. That's part of why cross-checking risk factors against MD&A and the segment financials matters, since a real risk sometimes only surfaces in the numbers rather than in the risk factor language itself.
Does a longer risk factors section signal a riskier company?
Not on its own. Under the SEC's 2020 rule, any section running past 15 pages simply triggers a two-page summary requirement; it isn't a penalty for having more disclosed risks. A company in a genuinely complex, multi-segment business, like one combining space launch, satellite internet, and AI infrastructure under one filing, will naturally generate more risk factors than a single-product company, independent of how risky either business actually is.
How do you tell the difference between a related-party transaction that's a real concern and one that's routine?
Scale and independence matter more than the existence of the relationship itself. A related-party transaction priced at fair market value with clear commercial logic behind it is common and usually low-risk. One sitting suspiciously close to the $120,000 disclosure threshold, or one where the pricing logic isn't independently verifiable, deserves the closer look this framework recommends.
Why do analysts treat the use-of-proceeds section as a valuation signal rather than just a formality?
Because it's a forward-looking commitment that can be checked against reality later. A specific use-of-proceeds statement, like directing capital explicitly toward AI infrastructure expansion, gives analysts something concrete to measure actual spending against in the quarters after listing. A vague statement gives them nothing to hold the company to, which is exactly why vague language tends to correlate with higher pricing uncertainty at the deal stage.











