As Australia considers breaking up its Big Four firms because of renewed scrutiny, policymakers should recognize that separating audit from consulting is only part of the answer. They must also address misconduct within auditing and ensure the actors responsible bear financial consequences. Australia’s scandal may also prove a useful warning for US policymakers — and its response may offer a useful test bed.
Policymakers should focus closely on how audit firms win business. Regulators should require stronger controls on who can access confidential client information, independent review of all major sales pitches, and compensation arrangements that ensure improper gains are recoverable after the responsible partners leave the firm. Such measures would target a problem that structural separation alone can’t solve.
The allegations in Australia make the gaps clear. For example, KPMG Australia is accused of using confidential information obtained from one client to pursue audit work from others. An audit-only firm could do that — it would no longer have consulting work to cross-sell, but it still would have information that competitors don’t, while competing for audit clients.
When the same firm is tasked with both independently scrutinizing a company’s financial statements and selling that company advisory services, the incentives can compete. Entity-level separation can reduce those conflicts by making the auditor less financially reliant on the client for work unrelated to the audit in front of them.
That solution, however, doesn’t reach every source of potential misconduct inside the audit business. Indeed, US regulators have already seen a variant of this broad problem.
In 2019, the Securities and Exchange Commission reached a settlement with KPMG’s US firm over misconduct involving confidential information regarding inspections by the Public Company Accounting Oversight Board. According to the agency, a former KPMG partner had attempted to use improperly obtained information about the regulatory inspection of another accounting firm to help KPMG win audit business.
The US episode is instructive because spinning off a consulting firm wouldn’t have prevented it. The misconduct arose from competition within the audit sector itself. Structural separation can reduce conflicts between divisions, but it can’t eliminate the natural temptation to turn confidential information into an advantage over rivals.
Australia has already moved in this general direction for tax advisers. New legislation increases penalties against individual agents for unethical conduct and can impose liability on partners as well. That is a strong policy recognition that deterrence works best when consequences reach the people making the offending decisions, rather than falling purely at the firm level.
But penalties against individuals aren’t the same as recovery of the economic spoils of misconduct. A partner who wins business improperly may receive compensation stemming from those actions years before the conduct is uncovered. Regulators should therefore pair individual sanctions with required compensation arrangements that consider how bonuses or profit distribution can remain attributable to specific transactions — and thus recoverable when misconduct is found, even after a partner leaves the firm.
Imagine a partner who helps win business through improper use of confidential information, receives compensation reflecting that success, then leaves the firm long before regulators can act. Years later, a firm-level penalty may be paid by current partners, including people who had nothing to do with the misconduct and never shared in the rewards. The former partner, meanwhile, may have already collected the relevant bonus or profit distribution.
Firms should remain responsible for supervision and their culture and practices, but institutional liability and individual financial accountability are different things. And each places different pressures on the relevant actors in the decision-making process. Regulators should be attentive to both.
There needs to be a more targeted response. Australia’s proposals already contemplate stronger safeguards for confidentiality. That leaves a question over whether those obligations will translate into something regulators can test.
Regulators should scrutinize whether audit firms are independent from their clients, and also how they compete for new business. Firms auditing public companies should be required to prove that access to confidential client and regulatory information is limited to legitimate professional needs, that exposure within the firm is tracked, and that sensitive information can’t migrate from an audit team to a sales pitch — even informally.
Major proposals for new audit work should at minimum receive independent review by someone whose compensation and performance metrics aren’t tied to winning the contract. That review should ask basic questions such as where the information supporting the pitch came from and what information is being leveraged. Regulators could then test controls through direct inspections of a random sampling of bids and related records.
Properly calibrated, none of this would require preventing auditors from using their experience or sector knowledge when pursuing new clients. The relevant line should be drawn between expertise gained through experience and confidential information entrusted to the firm for a specific and limited purpose. Separating audit and consulting should be seen more as a tool to prevent privileged access from becoming a competitive advantage rather than a cure-all.
Part of making sure the economic incidence of misconduct falls on the right parties would entail requiring firms to structure partner compensation so that portions tied to misconduct remain recoverable. The goal isn’t to punish every partner for every firm failure, but to key recovery to proven wrongdoing or serious supervisory failings, with an opportunity to contest responsibility.
Forward-looking compensation agreements could keep relevant payouts recoverable for a set period even after a partner leaves the firm. Said agreements should supplement penalties at the firm level rather than replace them.
Policymakers facing similar auditor confidentiality issues in other countries, including the US, should pair structural changes with rules aimed directly at the gaps misconduct has evinced. That requires placing controls over how confidential information is used when firms compete for business and modifying compensation arrangements to keep improper gains recoverable.
Breaking up the Big Four may change what firms sell. But policies also need to change how they win business — and who pays when lines are crossed.
Andrew Leahey is an assistant professor of law at Drexel Kline School of Law, where he teaches classes on tax, technology, and regulation. Follow him on Mastodon at @andrew@esq.social.
Inside the scandal that destroyed KPMG’s reputation
A whistleblower, a secret document and a self-inflicted scandal that’s cost hundreds of jobs and shattered reputations. Today, how KPMG blew itself up, with the journo who’s been breaking all the scoops, our own Tansy Harcourt.
Ex-KPMG chief collects $4m payout amid firm’s devastating audit scandal
Former KPMG exec Eileen Hoggett sues firm seeking documents
KPMG begins brutal 500 jobs cull amid audit scandal fallout
Labor government extends ban on KPMG work for public service
KPMG partners lied to deputy general counsel, parliamentary inquiry hears
This episode of The Front is presented by Claire Harvey, produced by Kristen Amiet and edited by Tiffany Dimmack. Our team includes Lia Tsamoglou, Joshua Burton and Jasper Leak, who also composed our music.
A whistleblower, a secret document and a self-inflicted scandal that’s cost hundreds of jobs and shattered reputations. Today, how KPMG blew itself up, with the journo who’s been breaking all the scoops, our own Tansy Harcourt.
Ex-KPMG chief collects $4m payout amid firm’s devastating audit scandal
Former KPMG exec Eileen Hoggett sues firm seeking documents
KPMG begins brutal 500 jobs cull amid audit scandal fallout
Labor government extends ban on KPMG work for public service
KPMG partners lied to deputy general counsel, parliamentary inquiry hears
This episode of The Front is presented by Claire Harvey, produced by Kristen Amiet and edited by Tiffany Dimmack. Our team includes Lia Tsamoglou, Joshua Burton and Jasper Leak, who also composed our music.
Leaky ship KPMG retains $126m in contracts for top-secret AUKUS work
KPMG has kept its keys to Australia’s most classified nuclear secrets – worth $126m to the firm – even after admitting it repeatedly stole and shared confidential client information.
The UK’s accountancy regulator has opened an investigation into KPMG over the audits and financing arrangements of State Oil Limited, part of collapsed oil company Prax Group.
Privately held Prax was founded in 1999 by chief executive and chair Sanjeev Kumar Soosaipillai and his wife Arani Soosaipillai with a single petrol station near St Albans. It expanded into a sprawling conglomerate spanning refineries in the UK and South Africa, petrol stations and a trading business.
Separately from the FRC investigation, Sanjeev Kumar Soosaipillai is being sued by administrators who allege that he told employees to fake £334mn worth of invoices as part of what they called a “web of deceit” that enabled Prax to borrow from Wall Street lenders.
Soosaipillai has denied knowing about the fictitious invoices until being told about them in May or June 2025, and denies giving instructions that they should be created, according to documents filed with the court by his legal team. He told the FT in June that he had “always acted in good faith” to protect the refinery.




Mark Twain knew all about forbidden fruits and freedom:
“Adam was but human—this explains it all. He did not want the apple for the apple's sake, he wanted it only because it was forbidden. The mistake was in not forbidding the serpent; then he would have eaten the serpent”


















