The high price of a pulled opinion
The most serious action this week belongs to PLDT Inc. The SEC is forcing them to amend their 2025 Form 20-F after material control weaknesses surfaced and their auditors pulled their opinions.
When an auditor withdraws an opinion, you've moved past a "finding" and into a crisis. For those who weren't around for the early days of SOX, this is the nuclear option. It means the people paid to verify your numbers decided they could no longer put their name on the work.
What does this cost you at year-end? Everything. You lose market confidence, your borrowing costs spike, and you spend the next eighteen months paying a Big Four firm an arm and a leg to reconstruct a control environment that should have been designed correctly in the first place.
Then we have Tricolor. The SEC charged former executives with fraud for falsifying loan documents. This isn't a failure of control design; it's a failure of integrity. But from a controls perspective, it reveals a gaping hole in how they verified loan data. If your "verification" process can be bypassed by an executive with a pen, you don't have a control. You have a suggestion.
It’s the same theme we see with tl;dv. They leaked over 180k meeting records because of a vendor failure. The kicker? They had a SOC 2 certification.
I've spent two decades watching firms treat SOC reports like insurance policies. They aren't. A SOC 2 tells you the vendor *said* they have a process and someone else *saw* that process. It doesn't guarantee that the process actually works in real-time or that your specific integration with that vendor is secure.
Some will argue that relying on third-party certifications is the only scalable way to manage risk. They’re wrong. Scalability is a poor excuse for blindness. If you don't test the hand-off between your system and the vendor, the certificate is just expensive wallpaper.
The second-order effect here hits the insurers. As these "certified" vendors fail, cyber insurance providers will stop taking SOC reports at face value. They’ll start demanding evidence of actual third-party testing or they'll simply hike premiums for any firm with a heavy vendor footprint.
We also saw the Medusa ransomware group hit over 500 critical infrastructure organizations. While the headlines focus on the hackers, the real story is the systemic failure of patch management across those sectors. If you can't keep your perimeter closed, the rest of your internal controls are irrelevant.
Finally, GDPR fines hit just under a quarter billion euros in the second quarter. The number is high, but it’s predictable. Regulators have stopped looking for "intent" and started penalizing the lack of documented proof.
The question now is whether you're spending your budget on people who actually know how to build a control or on consultants who just know how to describe one in a report. I suspect most of you are doing the latter.
Watch PLDT’s amended filing. The level of remediation they're forced into will set the benchmark for "material weakness" fixes for the rest of the year.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)