KPMG Australia has spent the better part of two years losing a CEO, a chairman, a COO, government contracts worth hundreds of millions of dollars, and, by its own admission, the trust of clients it had audited for decades. All of it traces back to a whistleblower email sent in May 2024, warning that senior partners were misusing confidential client data to chase new business. What happened after that email is a case study in how quickly a firm can unravel when an investigation fails and a culture protects the wrong people.
The Whistleblowing Scandal, in Brief
The allegations centered on Lendlease, the property giant that had been a KPMG audit client for nearly seven decades. According to a former KPMG Australia audit director, senior partners accessed and copied restricted Lendlease board papers, including rival pitch strategies from EY and PwC, to help the firm win competing audit work from Westpac, Dexus, and Macquarie.
The director had already flagged a toxic environment inside the firm, citing bullying by senior partners, and had been working from an overseas office rather than return to what they described as a hostile Sydney workplace. In May 2024, they sent a detailed account of the misconduct to KPMG Australia’s leadership, including its Head of Audit. Shortly after, they left the firm under a separation agreement.
What followed was, by KPMG’s own later admission, an investigation that never should have passed for one. Leadership told the whistleblower an external law firm had been brought in to review the leak. That firm’s review effectively cleared the partnership, and internal leaders described the matter to their own independent board members as a minor human resources issue. A second review, commissioned later by a board subcommittee and run by law firm Allens, accepted senior partners’ denials at face value and initially found the allegations unsubstantiated.
Scandal Timeline
Here’s the condensed version of how it played out. (For a more in-depth treatment, click here.)
- May 2024: A whistleblower sends a detailed report on the data misuse to KPMG Australia leadership, then exits the firm.
- 2024–2025: KPMG treats the complaint as a workplace grievance. An external review effectively clears the firm. A subsequent review by Allens accepts partner denials and initially calls the allegations unsubstantiated.
- March 2026: Senator Deborah O’Neill uses parliamentary privilege to expose the allegations, triggering a federal inquiry.
- April 2026: The Australian Securities and Investments Commission (ASIC) opens a formal investigation. KPMG admits its internal reviews “fell short.”
- May 2026: CEO Andrew Yates and Head of Audit Julian McPherson resign.
- June 2026: Under parliamentary questioning, KPMG admits to a second, previously unreported breach: staff shared confidential Optus data with a team bidding for Optus’s rival, Telstra. The federal government and several states halt new contracts with the firm. Chairman Martin Sheppard, chief operating officer Eileen Hoggett, and audit partner Paul Rogers resign.
- July 2026: KPMG appoints John Sams as CEO. Investigators recover physical copies of the stolen Lendlease documents from Hoggett’s office locker, and the firm expels her from the partnership, forfeiting a retirement payout reportedly worth more than a million dollars.
Two years, two reviews that came back clean, and a parliamentary inquiry later, KPMG was still finding evidence that its own investigators had missed, or had chosen not to find.
The Cost of Getting It Wrong
The executives at the center of this made the decisions. The people paying for those decisions, in large part, did not.
By July 2026, the toll at the top of the firm included a CEO, a chairman, and a chief operating officer, plus additional senior partners fined or pushed out of the partnership. The federal government barred KPMG from bidding on new Commonwealth contracts through September 30, 2026, freezing an estimated $270 million in work, and the Australian Capital Territory, Western Australia, New South Wales, Queensland, and Victoria followed with bans of their own. Lendlease, the client at the center of the original complaint, ended its audit relationship with the firm outright. The Telstra audit work at the heart of the Optus breach went to Deloitte instead.
The financial damage compounds from there. KPMG Australia’s 2025 revenue had already fallen 3 percent to roughly A$2.3 billion, and reporting since indicates the firm is planning to cut close to 1,000 jobs while reducing partner pay by as much as 20 to 30 percent. None of the employees losing their jobs leaked a single document. Most of them likely learned the details of this scandal from the same news coverage everyone else did.
Who Bears the Brunt of Misconduct?
Misconduct at the top of an organization rarely stays contained to the people who committed it. The auditors, consultants, and support staff now facing layoffs didn’t access anyone’s confidential board papers. The graduates who joined the firm hoping to build a career didn’t know their employer would spend two years denying a complaint that turned out to be true. They’re absorbing the cost of decisions made several pay grades above them, which is exactly how misconduct usually works. The damage radiates out much further than the people who caused it, and it lands hardest on people who had no say in any of it.
The fallout has reached beyond KPMG itself, too. Coming on the heels of the earlier PwC tax-leak scandal, this case has pushed Australian Treasury to publish a policy options paper examining whether the Big Four firms should be legally required to separate their audit divisions from their consulting arms. Regulators are also confronting a structural gap the scandal exposed directly: ASIC can investigate individual auditors, but it has no power to penalize the partnership as a single entity, because Australia’s Big Four operate under state-based partnership law rather than corporate law. A crisis caused by one firm’s decisions is now reshaping how an entire industry gets regulated.
What Ethics and Compliance Leaders Should Take From This
It’s tempting to read the KPMG Australia story as a case of good values undone by weak middle management: a values-were-fine-but-execution-failed narrative, the kind that shows up in a lot of post-scandal commentary. That’s not what happened here, and it’s worth being precise about why, because the real lesson is more uncomfortable than that.
Look at who actually failed here. A chairman testified to Parliament that confidential client data crossed an “ethical wall” it never should have. A chief operating officer, according to investigators, kept physical copies of stolen board documents in her own locker while repeatedly denying under oath that any leak had occurred. Two separate reviews, one commissioned internally and one from an outside law firm, took senior partners’ denials at face value instead of testing them. None of that describes a manager interpreting ambiguous policy badly. It describes the people responsible for setting the policy in the first place, and in at least one case, actively concealing the evidence against themselves.
That distinction changes what compliance leaders should actually check. Most engagement surveys and speak-up dashboards are built to measure how well managers handle complaints, on the assumption that the risk lives in the middle of the org chart. KPMG shows what happens when the subject of a complaint has enough authority to shape how, or whether, the complaint gets investigated at all, and no manager-behavior survey would have caught that. The harder question is this: if someone reported concerns about a member of your executive team or board, who would run that investigation, and could that person say no to the executive if the findings pointed the wrong way?
The Question Worth Asking
Independence isn’t a checkbox exercise, either. KPMG brought in an outside law firm to review the allegations, and that review still cleared the partnership, because the scope, the access, and the standard of proof were all set by the people being investigated. An investigation is only as independent as the terms it’s allowed to operate under. Compliance leaders should be able to answer, specifically, who controls the scope of an investigation into a senior leader, and whether that scope can be quietly narrowed after the fact.
Culture, meanwhile, shows up in what gets tolerated, not what gets published. The whistleblower here described bullying from a named board member years before the data misuse came to light. A firm with a genuinely healthy speak-up culture doesn’t let a pattern like that persist for years next to a stated commitment to the opposite. When KPMG’s chairman later said the firm was “inviting scrutiny and challenge” on its remediation, that was the right instinct. It just arrived several years and one parliamentary inquiry too late.
The question worth asking inside your own organization isn’t whether your Code of Conduct says the right things. Most do. It’s whether the people with the most power to bury a finding are also the people subject to the least oversight when they try.