Accounting firms exist to hold others to account. Their foundational promise to every client is confidentiality. That promise, and the vast commercial architecture built upon it, is now in serious question at KPMG Australia, following a whistleblower scandal that has consumed the firm’s leadership, triggered a formal government investigation, and set lawmakers talking about dismantling the model entirely.
A whistleblower raised concerns internally as far back as 2024, alleging that confidential board papers belonging to Lendlease, one of Australia’s largest property and infrastructure companies, had been accessed and used by KPMG staff to support audit bids for Westpac, a major bank, and Dexus, a property group.
These were not internal memos or general industry research. They were Lendlease’s private board documents, shared with KPMG’s audit team in confidence, and explicitly marked off-limits to anyone outside that engagement.
KPMG ran three internal investigations. All three cleared the firm. The whistleblower’s account was formally classified as unsubstantiated. And for the better part of a year, Lendlease, the company at the centre of the allegations, was told nothing. Lendlease was only informed about the allegations in May 2025, a full year after the accusations were first raised internally.
From the Senate to the Boardroom
The story became public in March 2026, when Senator Deborah O’Neill read the whistleblower’s account into the parliamentary record under privilege, forcing it into the open. What followed was a rapid chain of institutional consequences.
The Australian Securities and Investments Commission (ASIC), the country’s corporate regulator, commenced a formal investigation, with ASIC chair Sarah Court confirming in June 2026 that the regulator had begun looking into KPMG and a number of its registered company auditors.
CEO Andrew Yates stepped down in May 2026. An investigation by law firm Allens had turned up evidence that KPMG said it had not found during its earlier internal review, and it was this finding that ultimately prompted Yates to resign.
Audit boss Julian McPherson also departed. Chief Operating Officer (COO) Eileen Hoggett stepped down from her role in June, though she remained an audit partner while investigations continued. ASIC is actively investigating both Hoggett and audit partner Paul Rogers over their alleged roles in the Lendlease leak.
The leadership cull did not stop there.
A Second Breach Surfaces
Just as KPMG’s damage-control effort was taking shape, the scandal widened. At a parliamentary hearing on June 19, 2026, Chairperson Sheppard confirmed that KPMG staff had shared sensitive information about telecom company Optus with a separate internal team bidding for an audit contract at its rival, Telstra. Sheppard acknowledged that unredacted Optus information had moved ‘through an ethical divider’ between the two teams when it should not have.
The Telstra contract ultimately went to Deloitte, meaning the information leak did not translate into a contract win. But the principle at stake is stark. Segregation between client-facing teams either holds or it does not, and in this case it did not.
The significance of the Optus admission is hard to overstate. It confirmed what KPMG had dismissed for nearly two years. The firm’s internal information barriers were porous, and that client confidentiality had been compromised not once, but at least twice, across two entirely separate engagements.
The Cost of Lost Trust
Chairperson Martin Sheppard, along with senior partners Paul Rogers and Eileen Hoggett, resigned as KPMG attempted to contain the damage. Interim chief executive Stan Stavros described the departures as ‘necessary and immediate’, and acknowledged that the firm had not met the standards expected of it.
“The parliamentary committee’s enquiries highlighted issues, including unethical behaviour by senior personnel, and the human impact of KPMG’s handling of the whistleblower. KPMG Australia is focused on ensuring those failings are understood, addressed and not repeated,” Stavros said.
For Lendlease, the consequences were decisive. The company dropped KPMG as its auditor, ending a relationship that stretched for nearly seven decades.
Lendlease chairperson John Gillam described KPMG’s conduct as a ‘fundamental breach of trust’. The firm is also seeking reimbursement for the cost of switching auditors.
The commercial fallout reaches further than one client. The Australian federal government placed more than $270 million in KPMG contracts under intense scrutiny, and the Department of Finance formally declared the situation a ‘significant event’.
Under rules introduced after the PwC tax leaks scandal of 2023, public sector clients can now require KPMG to guarantee that no personnel working on government projects are linked to the misconduct.
The firm’s Canberra operations face particular pressure, with a large tranche of government contracts up for renewal.
The broader sector trend is telling. New federal contracts awarded to the Big Four collectively fell to $348 million in 2025, down from $637 million in 2024, as the Anthony Albanese government grew increasingly cautious about governance, transparency, and confidentiality across major consulting firms.
A Structural Problem, Not Just a Personnel One
The regulatory and political response to KPMG’s crisis goes beyond demanding resignations. Lawmakers are now questioning whether the structural design of the ‘Big Four’ firms is itself the problem.
Unlike public companies, accounting partnerships are not directly supervised by ASIC. They are regulated instead under state-based partnership law, meaning they are not subject to the strict reporting requirements that ASIC imposes on corporations.
This exemption has long been a source of tension. After the PwC scandal in 2023, parliamentary inquiries recommended a range of reforms. These included limiting partner numbers to improve accountability, and separating audit and consulting services to reduce conflict of interest. None of the major reforms were ultimately implemented.
With KPMG now following PwC into scandal, patience is running short. Assistant Treasurer Daniel Mulino confirmed that the severity of the KPMG allegations had prompted him to revisit those stalled recommendations, including proposals to cap partner numbers at 400 and to bring major firms under the Corporations Act so that ASIC gains enforcement powers over entire entities.
Greens Senator Barbara Pocock has been the most direct voice in parliament. She pointedly asked at the hearing whether the partnership structure was ‘now non-functioning’, noting that Australia had arrived at the same point, with a second major firm, in only three years. Senator Deborah O’Neill asked whether KPMG was dealing with a few bad actors, or something more systemic.
The Deeper Question
KPMG Australia’s response has followed a familiar crisis script. Executives have resigned, an ethics consultant is being brought in, an independent chair will replace Sheppard, and outside directors will join the board. The firm says it has reported the Optus matter to all affected clients and regulators.
But the credibility problem runs deeper than any governance reshuffle can quickly resolve. Three internal investigations failed to find what an outside law firm later uncovered. The whistleblower was dismissed.
A client whose confidential documents were allegedly misused spent a year in the dark. And the public admission that a second client’s information crossed an internal firewall came only because a senior executive was under oath in parliament.
PwC’s path after 2023 offers a cautionary parallel. The firm stepped back from new government work for more than a year and sold its government advisory division, which had generated roughly a fifth of its revenue, for just one dollar. Its revenue fell by 26% in the following financial year. KPMG now risks a version of the same trajectory.
At stake is not simply one firm’s market share. The entire premise of the audit industry rests on the idea that an auditor serves the public interest by rendering an independent, untainted judgement on a company’s financial health.
When the information gathered in that role is allegedly recycled to win new business, that premise collapses. Investors, boards, and regulators depend on auditors to be above the commercial fray. A firm that uses confidential client data as a sales tool is not auditing, but is exploiting.
Australia is now confronting an inconvenient question that has been deferred for too long. Is the self-governing, partnership-based model of the ‘Big Four’ compatible with the public interest obligations those firms carry? Two scandals in three years suggest the answer may be no.
