Your Vendor Might Be a Company of One: SEC MC No. 10-2026 and the OPC Vendor Risk Gap
Key takeaways: SEC Memorandum Circular No. 10, Series of 2026, effective 16 February 2026, sets out how One Person Corporations (OPCs) report to the SEC — and it treats them differently from a normal corporation in ways that matter to anyone accrediting one as a vendor. An OPC below ₱3 million in assets or liabilities can file an Unaudited Financial Statement instead of an AFS, has no board to check the single stockholder's decisions, and must disclose self-dealing between the company and that same stockholder. If your vendor list is quietly filling up with OPCs — a common structure for single-contract contractors and small trading suppliers — your accreditation process may be treating them the same as a normal corporation when the risk profile is not the same at all.
Procurement teams have spent the last few years learning to read SEC filings, AFS thresholds, and beneficial-ownership chains. One Person Corporations sit slightly outside that pattern, and most vendor accreditation checklists were never built with them in mind.
What exactly does SEC MC No. 10-2026 change?
The circular consolidates reportorial requirements, monitoring procedures, and penalties specifically for OPCs. Two provisions matter most for anyone assessing one as a counterparty.
First, the financial-statement rule mirrors the general ₱3 million AFS threshold, but with a twist: an OPC under that threshold can submit an Unaudited Financial Statement together with a Statement of Management's Responsibility, signed under oath by the president and treasurer — who, in an OPC, may well be the same person as the sole stockholder. There is no external audit and no independent officer verifying the numbers.
Second, the circular formalizes disclosure of self-dealing and related-party transactions between the OPC and its single stockholder. Any such transaction must be disclosed in, or alongside, the financial statement. The SEC is effectively acknowledging what an OPC structurally is: one person acting as owner, and often as officer, with no board to check a decision before it's made.
Why does an OPC on your vendor list carry different risk than a regular corporation?
Because the usual governance assumptions procurement teams lean on don't apply. A regular corporation has a board, at least some separation between ownership and management, and — above the AFS threshold — an external auditor's signature on the numbers. An OPC below ₱3 million has none of that. The person who owns the company, runs the company, and signs off on its own unaudited numbers is the same individual.
That is not automatically a red flag — plenty of legitimate small suppliers, consultants-turned-contractors, and single-project vendors incorporate this way for tax and liability reasons, not to hide anything. But it does mean the financial statement you receive from an OPC vendor carries a different evidentiary weight than one from a corporation with a board and an auditor behind it. Concentration risk is also structural rather than incidental: if the single stockholder is unavailable, ill, or simply walks away, there is no management layer left to keep the business running or the contract fulfilled.
Isn't this just the same AFS threshold story from last month?
Partly — MC No. 10-2026 applies the same ₱3 million line as the general AFS threshold change. But the OPC angle adds two things a generic small-supplier read misses. One is the missing board: a normal small corporation under the threshold still, in principle, has directors who can be asked what they knew. An OPC does not. The other is the self-dealing disclosure requirement itself — the SEC is signaling that related-party risk inside a single-stockholder entity is real enough to require its own disclosure line, which is a useful admission that procurement teams should take seriously rather than treat as boilerplate.
What should a procurement or risk team actually do differently for an OPC vendor?
A few adjustments, not a wholesale rebuild:
- Flag OPC status at accreditation, not after. A vendor's Articles of Incorporation or SEC registration will show if it is organized as an OPC. Tag it in your vendor record so the difference isn't lost in a generic "corporation" bucket.
- Weight an Unaudited Financial Statement accordingly. Treat a self-certified UFS from an OPC as a starting point, not a verified fact — and lean more heavily on external data: CIC credit history, payment behavior with other counterparties, and business registration standing.
- Ask about the self-dealing disclosure directly. If the OPC discloses related-party transactions with its single stockholder, read what's there. A pattern of self-dealing in a company with no board to question it is a different risk than the same pattern in a normal corporation.
- Treat single-person key-man risk as real, not theoretical. For any OPC vendor handling work you can't easily re-source, ask what happens to delivery if the sole stockholder is unavailable for an extended period.
The bottom line
SEC MC No. 10-2026 is not a dramatic rule change — it is a housekeeping circular that consolidates how One Person Corporations report. But it makes explicit something procurement and credit teams should already be building into their process: an OPC is not a smaller version of a normal corporation, it is a structurally different one, with a different evidentiary standard for its financials and a formalized acknowledgment of self-dealing risk. Vendor accreditation processes that don't distinguish between the two are measuring different risks with the same yardstick.
Last updated: July 2026. Sources: SEC Memorandum Circular No. 10, Series of 2026 (Guidelines on the Compliances of One Person Corporations); SEC Memorandum Circular No. 9, Series of 2026 (AFS filing threshold); Securities and Exchange Commission.

