Auditen
practitioner note

Why Amend Your Form 20-F?

There is a particular kind of dread reserved for the compliance officer who has to tell the board that the annual report—already filed with the SEC—needs amending. It’s the regulatory equivalent of walking back into a room you've already left to admit you lied about where the money went.

PLDT Inc. is currently in this position. The firm is amending its 2025 Form 20-F following material control weaknesses and the withdrawal of audit opinions. For those who don't spend their weekends reading SEC filings, a "material weakness" isn't just a typo in a spreadsheet. It's a formal admission that the internal controls over financial reporting are so broken they could reasonably allow a significant misstatement to slip through.

The paperwork tells us exactly where the failure happened: the gap between what was asserted and what could be proven.

When a firm files its 20-F, it isn't just providing data; it's certifying that the controls producing that data actually work. The problem is that many organisations treat control frameworks as a filming exercise—they record a version of reality that looks good for the auditor and then stop recording. When an audit opinion is pulled, it means the auditor has looked at the evidence and decided it doesn't support the claim.

This isn't limited to financial reporting. Look at tl;dv. They held a SOC 2 certification, yet just under 182,000 meeting records were leaked due to a vendor-related failure.

The SOC 2 badge is often treated as a shield. It isn't. A SOC 2 report is a snapshot of a moment in time, usually focused on the design of controls rather than their constant operational effectiveness. If your "Vendor Management" control simply requires you to collect a PDF of your vendor's own certificate once a year, you haven't implemented a control; you've implemented a filing cabinet.

The evidence required to prevent this isn't more certificates. It is proof of active monitoring.

For the practitioner tasked with fixing this, the focus must shift from *design* (what we say we do) to *effectiveness* (what we can prove we did). If you are managing third-party risk, a vendor’s SOC 2 report is not evidence that your data is safe; it is merely evidence that someone else's auditor was satisfied with their process. Real evidence looks like quarterly access reviews, documented penetration tests of the vendor's specific API, and an actual kill-switch for data flows when a vendor fails a check.

Some will argue that it’s impossible to monitor every single sub-processor in a modern cloud stack. They're right. You can't.

But the alternative isn't blind trust—it's risk tiering. If you treat a critical data processor with the same level of scrutiny as your office stationery supplier, you deserve the resulting breach. The regulator doesn't expect perfection, but they do expect a rational link between the risk and the control. When that link breaks, you end up in the "material weakness" category.

The second-order effect here is a tightening noose for the auditors themselves. We see it with EHang replacing PwC as its 2026 auditor. When firms start pulling opinions or being replaced shortly after material weaknesses come to light, the PCAOB starts looking at whether the auditors were too cozy with the clients they were supposed to be policing.

The insurers will follow. If a firm has to amend a 20-F due to control failures, their D&O insurance premiums will likely spike the moment the renewal notice hits the desk.

You should ask your internal audit lead for the last three "failed" controls that were identified and corrected before the external auditors arrived. If they can't find any, it means either your system is perfect or your internal audit isn't actually looking.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed