
Australia’s corporate regulator is examining 551 complaints concerning alleged audit misconduct disclosed by KPMG, PwC, EY and Deloitte, bringing the internal handling of complaints at the Big Four accounting firms under regulatory scrutiny.
The Australian Securities and Investments Commission (ASIC) told a federal parliamentary hearing that the complaints cover the period since 1 July 2023. The regulator has used compulsory information-gathering powers to obtain material and is now determining whether individual matters require further investigation, enforcement action or other regulatory activity.
The number needs careful qualification. ASIC chair Sarah Court specifically cautioned against interpreting it as 551 serious whistleblower matters. ASIC has not established that 551 breaches occurred.
The more important legal question is therefore what happens when information originally held within an organisation's internal complaints system becomes evidence examined by a regulator. The regulatory pressure is arriving as the Big Four also reshape their operating models, with PwC’s 2026 accounts showing an 11.9% fall in average employee numbers while revenue declined just 3.1%.
ASIC's work follows whistleblower revelations involving allegations that confidential Lendlease board papers were used to support bids for major audit tenders involving Westpac and Dexus.
At the parliamentary hearing, ASIC executive director of enforcement and compliance Chris Savundra said the Big Four had so far disclosed 551 complaints.
Court clarified the scope of ASIC's request. It included complaints relating to alleged misconduct by registered company auditors, including the misuse or sharing of confidential information.
ASIC has used its compulsory information-gathering powers to obtain the material and is examining the complaints to determine whether there is further work for the regulator to undertake in relation to particular issues.
That distinction is important. A complaint records an allegation; it is not evidence that ASIC has established misconduct. Nor does the aggregate figure reveal how serious the individual allegations are or how they are distributed among KPMG, PwC, EY and Deloitte.
Risk starts with scrutiny
An internal complaint does not establish misconduct. Its regulatory significance can change, however, when allegations concern matters within a regulator's remit and the regulator obtains the underlying records to determine whether investigation or enforcement activity is warranted.
Court was explicit about the limits of what can currently be inferred.
ASIC does not yet know how many of the complaints represent serious whistleblower issues, and further work is required to understand the material.
That matters both legally and reputationally. Internal reporting systems can contain allegations of very different character and seriousness. A large aggregate number cannot establish that the complaints have a common cause or that misconduct occurred.
The public evidence reported from the hearing also does not establish how the 551 complaints are divided among the four firms. PwC, one of the four firms named, has separately reported its 2026 UK group results, with revenue down 3.1% and average employee numbers down almost 12%.
Senator Barbara Pocock asked whether they were spread relatively evenly between KPMG, PwC, EY and Deloitte. Court suggested that further information on that question be provided to the committee off-camera.
For now, the 551 figure is evidence of the scale of material ASIC is examining — not the scale of proven wrongdoing.
The current inquiry illustrates the transition particularly clearly.
The complaints existed within the firms. ASIC requested information concerning them and then used compulsory powers to obtain material.
It is now assessing that information to determine whether particular complaints warrant further regulatory activity.
For legal and compliance teams, that procedural shift matters because the regulator is no longer looking only at an allegation presented in isolation. It can examine records created inside the organisation concerning the complaint and its handling.
What those records establish will depend on the individual case. The material currently available does not establish that any particular Big Four firm mishandled any of the 551 complaints.
Scrutiny widens the exposure
Once a regulator obtains internal complaint records, its assessment can extend beyond the existence of the original allegation to the documentary record surrounding it. Whether that leads to investigation or enforcement depends on what the evidence establishes; regulatory scrutiny should not be confused with a finding of liability.
ASIC also disclosed a distinct investigation concerning KPMG's 2025 Transparency Report.
In its submission to the parliamentary hearing, ASIC said it was investigating alleged false or misleading statements in the report, which was lodged with ASIC under the Corporations Act.
Its initial inquiries include examining the basis for a statement that there were no whistleblower complaints related to audit quality.
That investigation has not produced a finding, on the information presently available, that the statement was false or misleading.
The distinction is significant. ASIC is examining both underlying complaint material across the Big Four and, separately, whether a formal statement made by KPMG accurately reflected the position relevant to its Transparency Report.
ASIC is also assessing corporate entities within the KPMG group to identify any director conduct that might require further regulatory consideration. Court explained that the regulator was examining KPMG-related corporate entities because Corporations Act obligations could apply to those corporations.
Again, that is an assessment rather than a finding of misconduct.
There is no single threshold in the material supplied establishing when every internal complaint must become a board matter.
The current ASIC scrutiny nevertheless demonstrates when the nature of the risk can change.
Once a regulator uses compulsory powers to obtain internal material, the issue has plainly moved beyond an exclusively internal process. The organisation may then face questions concerning what its records show, whether related complaints exist and whether statements previously made externally are consistent with the information held internally.
That is particularly significant where the same issue may extend across more than one complaint or business entity.
For senior legal, compliance and governance functions, the practical question is therefore not simply whether an individual allegation has been substantiated. It is whether the information being examined could have consequences beyond the individual complaint.
The decision point
The clearest action threshold arises when an issue can no longer be contained within ordinary internal complaint handling because a regulator has formally sought the underlying material or begun examining related conduct. At that stage, the potential significance extends beyond resolution of the individual allegation and into wider legal, regulatory and governance risk.
The hearing also exposed a wider debate about how whistleblower information reaches regulators.
ASIC is looking at complaints dating from 1 July 2023. Senator Pocock questioned whether examining only that period would fail to capture relevant historical complaints and argued for a broader review.
The hearing also addressed the protection available to people making disclosures directly to ASIC. Court said there needed to be urgent clarity about whether disclosures made to ASIC by whistleblowers are protected.
That issue is separate from whether any particular allegation against one of the Big Four is substantiated.
It matters because regulators investigating organisational misconduct can depend partly on information supplied by people inside the organisations concerned. Uncertainty about how disclosures are protected can therefore affect the reporting environment in which regulatory intelligence is generated.
The KPMG Transparency Report investigation demonstrates another distinction that can matter to regulated organisations.
Regulatory scrutiny may concern the alleged original conduct, but it can separately concern what an organisation subsequently said about its position.
ASIC is examining the basis for statements in KPMG's report, including the statement concerning whistleblower complaints related to audit quality.
No conclusion should be drawn about the accuracy of that statement while the investigation remains unresolved.
The broader compliance issue is nevertheless clear: formal statements about complaints, controls or governance can themselves become the subject of regulatory examination.
That makes the relationship between internal records and external disclosures particularly important. Where an organisation makes formal representations concerning complaints or governance arrangements, inconsistencies between those representations and its underlying records may attract regulatory attention.
For the Big Four, the immediate development is regulatory scrutiny, not established liability.
ASIC has obtained complaint material using compulsory powers and is reviewing it to determine whether further action is justified.
This creates a different evidential position from individual complaints remaining exclusively within separate firms. The regulator can consider multiple records and decide whether any particular issues merit investigation.
It does not follow that a high number of complaints establishes a systemic problem. Equally, apparently separate allegations may warrant closer examination if the underlying evidence reveals connections.
That determination is precisely the work ASIC says it is now undertaking.
The wider pattern
Internal complaints can acquire wider regulatory significance when authorities are able to examine records across cases rather than treating each allegation in isolation. The decisive issue is not complaint volume itself, but what the evidence reveals about the alleged conduct, the organisation's records and any formal representations subsequently made about those matters.
The regulatory pattern is relevant beyond accounting firms.
Large organisations commonly operate multiple channels through which employees can report concerns. Individual complaints may initially be investigated separately because they involve different people, incidents or business units.
External scrutiny can change the frame of reference.
A regulator examining records across cases may be able to ask whether allegations that appeared unrelated internally have common features. It may equally conclude that they do not.
That is why the distinction between allegation, internal finding, regulatory investigation and regulatory outcome matters.
Conflating those stages can exaggerate liability before evidence has been tested. Ignoring the transition between them can create the opposite problem by treating an issue as purely internal after it has acquired external regulatory significance.
ASIC's examination of the 551 complaints is continuing.
The regulator is assessing whether particular matters require further investigation, enforcement action or other activity. The information presently available does not establish how many complaints, if any, will progress to enforcement.
ASIC's separate investigation into alleged false or misleading statements in KPMG's 2025 Transparency Report also remains unresolved, as does its assessment of KPMG-related corporate entities for possible director conduct requiring further regulatory consideration.
The immediate position for KPMG, PwC, EY and Deloitte is therefore one of heightened regulatory scrutiny rather than established wrongdoing.
The more lasting lesson for other organisations is procedural. Internal complaints do not necessarily remain internal. Once regulators obtain the underlying records, both the alleged conduct and the documentary history surrounding it can become part of the regulatory examination.
ASIC is examining 551 complaints disclosed by KPMG, PwC, EY and Deloitte concerning alleged audit misconduct, but has explicitly cautioned against treating all 551 as serious whistleblower matters.
The regulator has used compulsory information-gathering powers and is determining whether individual complaints warrant investigation, enforcement or other regulatory activity.
ASIC is separately investigating alleged false or misleading statements in KPMG's 2025 Transparency Report. No finding of wrongdoing has been established in the information currently available.
For organisations more broadly, the important transition occurs when an issue moves from internal complaint handling into formal regulatory scrutiny. At that point, underlying records and formal external statements can become relevant alongside the original allegation.
This analysis is based on evidence from ASIC chair Sarah Court and executive director of enforcement and compliance Chris Savundra given to a federal parliamentary inquiry in Sydney, as reported by ABC News.
ASIC's statements concerning the 551 complaints, its use of compulsory information-gathering powers, its separate KPMG Transparency Report investigation and its assessment of KPMG-related corporate entities should be linked directly to the relevant ASIC submission or parliamentary record where available before publication.
The article deliberately distinguishes allegations, complaints, investigations and regulatory findings. It does not infer wrongdoing from the existence of a complaint or regulatory inquiry.
