Back
Business

KPMG Australia Scandal: Client Data Misuse, Whistleblower Treatment, and Government Response

View source

A Culture of Confidentiality Breaches: The KPMG Australia Scandal

A series of revelations beginning in 2024 have led to the resignation of KPMG Australia's CEO, audit head, and chairman, as well as a formal investigation by the Australian Securities and Investments Commission (ASIC) and a temporary ban on the firm bidding for new federal government contracts.

The core allegations involve KPMG staff sharing confidential client information to win new business and the firm's treatment of the whistleblower who raised these concerns.

Key Events and Allegations

Whistleblower Complaint

In May 2024, a KPMG employee made allegations to the firm that confidential client documents were being inappropriately shared internally. The whistleblower claimed that senior staff accessed board papers from client Lendlease and used that information to pitch for and win audit contracts with other firms, including Westpac and Dexus. The whistleblower's identity was later revealed to a former KPMG partner.

Initial Internal Investigations

KPMG conducted an internal investigation that did not substantiate the claims. The firm then engaged the law firm Ashurst for an external review, which also did not support the allegations. KPMG later acknowledged that these initial investigations were not conducted with the "necessary rigour required."

Escalation and Public Disclosure

The matter was raised under parliamentary privilege in March 2026 by Senator Deborah O'Neill. Following this, KPMG appointed law firm Allens to conduct a third investigation. This investigation found evidence that confidential client information, including data from Lendlease and Optus, had been shared with teams bidding for work with Westpac, Dexus, and Telstra. The Allens investigation also found instances of inappropriate document sharing.

Senior Resignations and Demotions

  • Andrew Yates, Chief Executive Officer of KPMG Australia, resigned in late May 2026.
  • Julian McPherson, National Managing Partner of Audit and Assurance, stepped down in late May 2026.
  • Eileen Hoggett, Chief Operating Officer, was demoted and resigned from her executive role in early June 2026.
  • Martin Sheppard, Chairman of KPMG Australia, resigned in late June 2026.
  • Paul Rogers, an audit partner, was identified as being under formal investigation by ASIC and left the firm in late June 2026.

Treatment of the Whistleblower

Multiple reports indicate that the whistleblower faced retaliation. According to testimony and documents presented to a parliamentary committee, the whistleblower was denied a pay raise, had client work withdrawn, and was threatened with termination. KPMG performed searches of the whistleblower's computer in 2024. The whistleblower signed a deed of release and is no longer employed by the firm.

In a statement to the committee, the whistleblower said the decision to speak out had "devastating consequences" and that, had they known the extent of the retaliation, they would not have done so.

Confidential Data Leaks

The Allens investigation confirmed that confidential information from KPMG's audit client, Lendlease, was shared within the firm. In a separate incident, KPMG admitted that staff auditing the telecommunications company Optus shared unredacted confidential information with colleagues bidding for an audit contract with Telstra.

Regulatory and Government Response

Australian Securities and Investments Commission (ASIC)

ASIC commenced a formal investigation into KPMG and several of its registered company auditors. ASIC Chair Sarah Court confirmed that the regulator is formally investigating partners Eileen Hoggett and Paul Rogers. ASIC Chair Sarah Court noted that the process has highlighted shortcomings in the regulator's powers to directly investigate partnerships.

Federal Government

In June 2026, the Department of Finance requested that KPMG voluntarily refrain from bidding for new Commonwealth government contracts until September 30, 2026. KPMG agreed to this temporary ban. The Department of Finance also commissioned an independent review of KPMG's governance, culture, ethics, and integrity frameworks.

At the time of the ban, KPMG held 297 active contracts with the Australian federal government, valued at a total of $653 million. The ban does not apply to these existing contracts.

The Australian Greens referred KPMG to the National Anti-Corruption Commission.

Proposed Regulatory Reforms

Assistant Treasurer Daniel Mulino released a Treasury options paper proposing structural reforms for the accounting, audit, and consulting industry. Proposals included:

  • Forcing firms to separate audit and consulting functions.
  • Introducing a licensing regime for audit firms overseen by ASIC.
  • Mandating public tendering for audit services every 10 years.
  • Enhancing ASIC's powers to investigate and sanction partnerships.

State Government Responses

Multiple state governments reviewed their contracts with KPMG following the news of the data breaches. The Victorian government stated it would review all contracts with the firm. The New South Wales government requested that KPMG disclose its plan to address ethical lapses and confirm that no personnel under investigation were working on NSW government contracts.

Client Responses

Lendlease announced it would put its external audit contract out to tender, ending a 68-year relationship with KPMG. Lendlease Chairman John Gillam described the misuse of the company's data as a "fundamental breach of trust." The Reserve Bank of Australia (RBA) announced it would re-tender its whistleblower hotline service, which was provided by KPMG.

Parliamentary Inquiry

The Parliamentary Joint Committee on Corporations and Financial Services held a hearing in June 2026 to investigate the allegations. Witnesses included former KPMG CEO Andrew Yates, former chairman Martin Sheppard, former audit head Julian McPherson, Lendlease CEO Tony Lombardo, and independent board member Mike Baird.

During the hearing, former CEO Yates confirmed the Optus data leak and stated that the confirmation of this leak motivated his resignation. KPMG used legal professional privilege to decline to provide some documents to the committee.