
A KPMG whistleblower who emailed ASIC in September 2025 said the experience showed how hard it is to expose wrongdoing in Australia, after the regulator closed the complaint days later. The whistleblower said they had first tried to blow the whistle internally at KPMG, and that the matters were also taken to KPMG International, but KPMG dismissed the allegations as a private employment matter. That’s the machinery at work: a giant firm, a regulator, and a worker trying to force the truth into a system built to absorb it.
Who Gets Silenced
The whistleblower told ASIC that KPMG Australia "refused to acknowledge my whistleblower status or protections" and that "reviews commissioned and controlled by KPMG — including those conducted under legal privilege — cannot credibly be presented as independent." The email said the whistleblower had approached ASIC "under the continuing threat of retaliatory legal action from KPMG" and wrote, "Despite this, the truth must come out." Those are not the words of someone protected by the apparatus. They’re the words of someone trying to survive it.
The email said the issues were "of public interest" and went to ASIC's statutory mandate to ensure the integrity of financial reporting, uphold auditor independence and safeguard confidence in Australian markets. It also said, "Delay in addressing them risks allowing systemic misconduct to continue unchecked, directly undermining market integrity and investor confidence." The whistleblower warned ASIC that "the matters I raised are urgent and warrant immediate investigation," but the regulator closed the complaint days later. ASIC told ABC News, "ASIC takes all whistleblower reports and allegations of misconduct seriously." The gap between that line and the closed complaint says plenty.
What the Firm Admitted
A KPMG spokeswoman said, "We acknowledge that KPMG Australia failed the whistleblower, and for that we have unreservedly apologised," and added, "Now, more than ever, we are focused on creating an environment where people feel safe to speak up." That apology came after the scandal had already unfolded and after senior executives still at KPMG at the time were copied on the email, many of whom have since left the firm. The firm’s own language about safety sits awkwardly beside the whistleblower’s account of retaliation, dismissal and internal control.
The article said the government is reviewing whistleblower laws, but the current setup leaves disclosures about partnerships and unincorporated associations outside "eligible whistleblower" protections. That means the people most likely to run into corporate power without a shield can still be left exposed when they try to speak.
Reform, With the Same Old Limits
ASIC chair Sarah Court told a June 19 parliamentary hearing that there were "clear gaps in the regulatory settings" and that the Corporations Act should be extended to deal with big partnerships and sanctions should be "significantly increased." Court said, "We also consider the current whistleblower protections to be deficient," and, "They need to be extended so that those that are seeking to make disclosures in relation to the conduct of partnerships such as KPMG are clearly protected." That’s the reform pitch: patch the holes, widen the statute, add more sanctions. It still leaves the same institutions policing themselves until they don’t.
Assistant Treasurer Daniel Mullino is considering changes to the law that could boost access to justice for whistleblowers and address gaps on who is covered. The government is also looking at whether anonymous and confidential disclosure protections are "fit for purpose" and whether a proposed financial rewards scheme for whistleblowers is needed. The article said such a scheme would be akin to a bounty-style reward in the United States for some whistleblower disclosures. Some stakeholders and prior parliamentary inquiries have backed the idea, but Treasury's consultation paper warns it could invite a flood of low-value or speculative reports and make disclosures look profit-motivated rather than public-interest-motivated.
A whistleblower protection authority remains a live issue. The article described it as a one-stop shop responsible for investigating whistleblower complaints, and said it would also be able to investigate consequences suffered by whistleblowers and compensate them for losses. Greens finance and public service spokesperson senator Barbara Pocock backed the idea, saying, "Strong whistleblower protections are vital to a democracy." She said, "In the absence of regulators with teeth — ASIC and the Tax Practitioners Board — there is an urgent need for corporate whistleblower protections to extend to the Big Four and for a new whistleblower authority that actually supports and protects whistleblowers." Pocock added, "This means ensuring all entities are required to meet the whistleblower provisions of the Corporations Act 2001 and establish a whistleblower authority."
The same system keeps producing the same problem. In March, Labor senator Deborah O'Neill shared with parliament a whistleblower's allegations that confidential board papers from Lendlease were used to support bids for major audit tenders for Westpac and Dexus, and earlier this month current and former KPMG partners were hauled before a federal inquiry probing why the firm allegedly shared client information and ignored the whistleblower's allegations when they first surfaced. The names change. The hierarchy doesn’t.