The high cost of pulling an audit opinion
PLDT Inc. is amending its 2025 Form 20-F. For those who don't spend their lives in SEC filings, that’s a disaster. When you have to amend your annual report because of material control weaknesses and the withdrawal of audit opinions, you aren't just fixing a typo. You're admitting that the steering wheel was disconnected from the wheels for an entire reporting cycle.
I’ve seen this movie before. Back in 2004, during the early SOX rush, every C-suite executive thought they could solve control gaps by hiring a big firm to write them a manual and then checking boxes until the auditor went away. They called it "implementation." I called it theatre.
What does this cost you at year-end? Everything. It costs you your credibility with the market and likely triggers a cascade of shareholder lawsuits. The objection here is usually that these are "complex accounting treatments" or "technical glitches." That's nonsense. If the control design doesn't prevent the error, the design is broken. Period.
The second-order effect here isn't just on PLDT; it’s on every other firm in the Philippines and beyond using similar reporting frameworks. The SEC doesn't just look at one failure in a vacuum. They use these as templates for where to look next. If your internal controls over financial reporting are a facade, you're now on a shortlist.
Then we have Tricolor. The SEC charged former executives with fraud and falsifying loan documents. This is the ultimate failure of "Management Review" controls. Whenever I see a control described as "Manager reviews the report for accuracy," my stomach turns. If the manager is the one directing the fraud, that control has a value of zero. It's just a rubber stamp on a lie.
On the security side, tl;dv leaked just over 180,000 meeting records. The punchline? They had a SOC 2 certification.
This is why I hate the "badge" culture. A SOC 2 report is a snapshot of a moment in time, not a guarantee of future performance. In this case, a vendor-related failure bypassed the guards. The implication here hits the customers who relied on that certification to satisfy their own third-party risk assessments. Those customers are now exposed because they trusted a piece of paper over an actual deep dive into how the vendor managed its sub-processors.
The auditors who signed off on those SOC 2s should be sweating. If the vendor management controls were documented as "functioning" while 181,000 records walked out the door, the testing was superficial.
We also have the Medusa ransomware group hitting north of 500 critical infrastructure organizations. When you see a number that high, it's not an isolated incident. It's a systemic failure of patch management and perimeter controls across an entire sector. We talk about "resilience," but resilience is just what you call it when your preventative controls failed and you're hoping the backups actually work.
The money tells the story too. GDPR fines hit roughly €225 million in the second quarter. That’s a lot of capital leaving the balance sheet because firms think they can "manage" privacy via a policy document instead of actual data minimization.
If you want to know if your controls are real, ask yourself one question: If the person responsible for the control disappeared tomorrow, would the error still be caught?
If the answer is no, you don't have a control. You have a person who is good at hiding mistakes.
Watch the SEC's new proposal for crypto issuers raising capital. They're trying to create flexibility, but "flexibility" in regulatory speak usually means "we're going to give you a rope and see if you hang yourself with it." I’ll believe the controls are effective when I see an auditor actually risk their license on the valuation of those assets.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)