The price of falsified paperwork
The SEC recently went after former executives at Tricolor, a subprime auto lender, for fraud and falsifying loan documents. This isn't some complex accounting alchemy involving offshore shells. It was basic forgery—altering documents to make things look better than they were.
When the people signing off on the numbers are the same ones benefiting from those numbers, you don't have a process; you have a liability.
The organization got this wrong by treating "trust" as a primary control. In many small firms, the founder or a senior partner handles the most sensitive documents because they're the only ones who "know how it works." This creates a vacuum where no one is actually checking the source data against the final filing. The executives at Tricolor operated in that vacuum.
The fix for this doesn't require an enterprise resource planning system that costs more than your annual rent. It requires a boring, manual segregation of duties.
Specifically: the person who prepares the document cannot be the same person who authorizes it. If you're too small to have two different people, you hire a third-party contractor for four hours a month to perform "blind spot checks." This means they pick five random files and trace them from the original customer application straight through to the ledger.
It costs almost nothing. A few hundred dollars a month for a freelance bookkeeper or an external consultant is a rounding error compared to an SEC enforcement action.
Some will argue that this slows things down. They'll say that in a fast-moving business, adding a second layer of approval creates friction that kills growth.
That friction is the point.
Compliance isn't about speed; it's about evidence. If you can't prove who verified a document and when, the regulator assumes the document is a fiction. Trusting your staff—or yourself—is not a control. It's a gamble.
The fallout here extends beyond the executives and the firm. The second-order effect hits the auditors and the insurers. When an SEC charge reveals systemic forgery, every audit opinion signed off on that company for the last few years becomes a red flag. The auditors who missed these discrepancies are now exposed to professional negligence claims or regulatory scrutiny of their own. If you're using a small audit firm, make sure they aren't just "rubber-stamping" your files because you've been a loyal client for five years. A lazy auditor is just as dangerous as a fraudulent executive.
You might think this only happens at the scale of a "giant" lender like Tricolor. It doesn't. The SEC and other regulators are increasingly focused on document integrity across the board. They don't care about your intent; they care about the gap between the record and the reality.
Stop looking for software that promises to "automate" your integrity. You can't automate honesty, but you can make it harder to lie by ensuring someone else is always looking at the receipts.
Check your document permissions this week. Ensure that the person who enters your financial data cannot unilaterally edit the final PDF before it's sent out.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)