Auditen
sector watch

The high cost of control theatre

If you think a signed certification saves you from an SEC amendment, you haven't been paying attention since 2002. I spent the early years of SOX watching firms treat internal controls like a painting they could hang on the wall to impress the auditors. It looked great from a distance, but it didn't actually stop anything from leaking.

We are seeing a return to that same brand of theatre, and the SEC is currently tearing the curtains down.

Look at PLDT. This isn't just a minor correction; it's one of the most serious actions we've seen this week. Amending a 20-F because of material control weaknesses and having audit opinions pulled is a catastrophic failure of design. When you get to that point, you aren't talking about "process improvements." You're talking about a total collapse of trust in the numbers.

Then you have Tricolor. Former executives charging into fraud by falsifying loan documents isn't a "control gap." It's a deliberate bypass of every check and balance that should have been in place.

The common thread here is the gap between what's on the PDF and what's happening in the ledger.

This extends beyond financial reporting into the SOC 2 world, where the theatre has become truly absurd. Take tl;dv. They had a SOC 2 certification, yet they still leaked over 180,000 meeting records because of a vendor failure. A certificate is not a control. It's a snapshot of a moment in time, often curated to look as clean as possible for the auditor. If your "effective" controls allow nearly 200,000 records to walk out the door, your controls weren't effective. They were decorative.

Some will argue that these are isolated incidents—one is fraud, one is a technical leak, and one is a reporting failure in a different jurisdiction. They'll say the frameworks are sound and the failures are human.

That's the wrong answer. The framework isn't the control; the framework is just the map. If you use a perfect map but still drive the car into a lake, the map didn't fail you—your driving did. The problem is that too many firms have stopped trying to drive and are instead spending all their time polishing the map.

The second-order effect here hits the auditors first. We're already seeing the friction. EHang swapping out PwC for 2026 suggests a relationship soured, likely over exactly these kinds of tensions between reporting expectations and reality. But the real heat will move to the insurers next. When Medusa ransomware hits north of 500 critical infrastructure organizations, the underwriters stop caring about your ISO or SOC certifications. They start asking for raw evidence of how you actually block an unauthorized lateral move in your network.

What does this cost you at year-end? For PLDT, it costs them their credibility and a messy filing process. For others, it's the €225 million in GDPR fines we saw in the second quarter alone.

The regulators are stopped being impressed by the paperwork. They're looking for the actual lever that stops the bad thing from happening. If you can't point to that lever—not a policy document, but the actual mechanism—you don't have a control. You have a brochure.

Watch the SEC's next move on crypto issuers and their capital raising rules. If they demand hard evidence of custody controls rather than just "attestations," the entire sector is going to realize how thin their ice really is.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed