A tale of two emails: what they reveal about KPMG Australia’s culture
One asked for confidential client information. The other tried to stop it. What happened next reveals KPMG Australia’s culture
Key takeaways
Confidential client information was treated as commercially useful intelligence inside KPMG
Career and financial pressures made speaking up personally costly
KPMG scrutinised the whistleblower more rigorously than the senior partners he accused
Project Magenta failed to find evidence sitting within systems it had the power to search
The firm’s response focused on containment, not the search for the truth
Two emails sit at the centre of the KPMG Australia confidential-information leaks scandal.
The first was sent by an unidentified KPMG colleague to Eileen Hoggett, then the lead partner for the Lendlease audit. The colleague asked to see confidential competitor audit proposals that Hoggett had obtained through her access to Lendlease board documents. Hoggett responded by instructing her executive assistant to retrieve them from her locker and share them.
The second was sent by the whistleblower to Julian McPherson, then KPMG Australia’s head of audit. In it, the whistleblower acknowledged the personal and professional pressures that had previously discouraged him from speaking more forcefully, described conduct he believed fell below KPMG’s ethical standards and explained why he could no longer remain silent.
The two emails tell a clear story about life inside KPMG Australia.
The first shows confidential client information being treated as commercially useful material.
The other shows an employee struggling with the unethical behaviour he was witnessing on a regular basis, believing that speaking more forcefully would place his career and income at risk.
KPMG leadership’s reaction completes the picture.
The email that treated confidential information as a resource
The email that ended Hoggett’s career at KPMG Australia shows that the confidentiality breach was known to others inside the firm.
Hoggett knew. She had accessed confidential Lendlease board material, including rival audit proposals submitted by EY and PwC, and retained printed copies.
Paul Rogers knew. He was involved in using it during KPMG’s pursuit of Westpac’s external audit. KPMG subsequently sanctioned both Rogers and Hoggett in connection with the matter.
The unnamed writer of the email knew.
And the whistleblower knew too.
That is already enough to undermine any suggestion that the episode was an entirely private aberration committed by one partner acting alone.
The email that tried to push for change
Of all the people who were aware of the confidential Lendlease material and the way it had been used, it appears that only one tried to do something about it: the whistleblower.
In an internal email sent to Julian McPherson on 30 May 2024—later provided to and published by the parliamentary committee and discussed during its KPMG hearing—he wrote:
“Whilst I regret the role that I have played in this to date, I have learnt that personal prospects, promotion and income should not warrant turning a blind eye and not speaking up louder, sooner.”
He went on to say:
“I can no longer stand by and watch this happen and absolutely feel that I have done the right thing when raising some of these concerns.”
The whistleblower described the conduct he had observed through his work with partners pursuing new business and managing the commercial operations of KPMG’s audit practice:
“I work with multiple partners identifying and pursuing new business opportunities and I work with multiple partners on the commercial operations of our business, ie setting of fees, negotiations and process improvements. Through this I have seen a number of actions taken by individuals that are quite clearly not up to the ethical standards of KPMG or the expectations of regulators, governments or the public at large.”
He argued that what he had witnessed was not confined to a handful of disconnected events:
“These are not isolated incidents but instead endemic within the organisation whereby profit and revenue growth is placed above everything else including integrity, people, wellbeing and fundamentally doing the right thing.
Some of these incidents involving current KPMG partners and ex-KPMG partners I have personally witnessed, others I have seen evidence of and have led to significant commercial outcomes for KPMG, but raise serious questions about what lengths the business is prepared to go to achieve growth and profit.”
What the two emails reveal about KPMG’s culture
Read together, the two emails show both sides of the same institutional culture.
One person recognised the commercial value of improperly available information and asked to see it.
Another recognised that the behaviour was wrong but acknowledged that career and financial considerations had previously discouraged him from speaking more forcefully.
What we have at play here are two reinforcing cultural mechanisms.
The first is normalisation.
Within at least part of the firm, confidential information appears to have been treated not as material protected by an inviolable ethical boundary, but as commercially useful intelligence.
The most revealing part of the Hoggett exchange is not simply that she retained the documents or agreed to share them. It is that another colleague knew the competitor proposals were available and considered it acceptable to request them.
The second mechanism is silence.
The whistleblower explicitly identified personal prospects, promotion and income as reasons people might turn a blind eye or fail to speak loudly enough. His email described an environment in which challenging conduct by powerful partners could carry greater personal risk than remaining silent.
The two mechanisms sustained one another.
Misconduct could become normalised because people benefited from it. Silence could become rational because those who challenged it placed their careers and incomes at risk.
KPMG investigated the whistleblower
Leadership’s reaction to the whistleblower’s email is as revealing as the email itself.
When the whistleblower took his allegations to McPherson, McPherson authorised a search of the whistleblower’s work computer.
KPMG therefore understood from the beginning that electronic records might be relevant. It possessed the technical ability and organisational authority to obtain and search them.
What it did not do was apply equivalent scrutiny to the senior partners whom the whistleblower had accused of misappropriating and using highly confidential information belonging to a longstanding audit client.
The asymmetry is stark.
KPMG searched the device of the person reporting the suspected misconduct, but not the corresponding emails and devices of the people alleged to have committed it.
There may have been legitimate reasons to inspect the whistleblower’s laptop. The firm could reasonably have wanted to preserve evidence, understand the allegations or establish which records he had accessed.
The indictment lies not in conducting that search. It lies in stopping there.
A genuine truth-seeking process would have followed the evidence in both directions. It would have examined the whistleblower’s records for evidence supporting his account and searched the relevant communications of Hoggett, Rogers and others for evidence capable of confirming or disproving it.
Instead, the whistleblower’s claims, conduct and credibility were subjected to forensic scrutiny. The senior partners’ accounts were treated as representations that could largely be accepted.
KPMG knew how to look.
It chose to look at the whistleblower.
Ashurst found warning signs without conducting an investigation
The failure became more serious when Ashurst encountered evidence suggesting that improper conduct had occurred.
Ashurst was not retained to conduct a comprehensive investigation into the substance of the whistleblower’s allegations. The law firm subsequently told Parliament that its work principally concerned employment-related matters, contradicting the impression KPMG had created when referring to an external legal review that supported its internal conclusions.
Yet despite this narrower mandate, Ashurst reportedly identified “some risk” that KPMG had breached contractual or confidentiality obligations to Lendlease through the use of confidential board material during the pursuit of Westpac’s audit.
That was not a final legal finding that a breach had occurred. But it was a serious warning.
KPMG’s own processes also uncovered sufficient misconduct to impose sanctions on Hoggett and Rogers.
By that point, the firm was no longer dealing with an entirely uncorroborated allegation made by a former employee. It knew that confidential Lendlease information had been used inappropriately. It had sanctioned senior partners. It had a specific allegation that Hoggett had retained printed material. And it controlled the internal systems capable of testing her denial.
Ashurst had not been asked to investigate the full matter, yet it had still found evidence pointing towards unethical behaviour.
How, even then, were Hoggett’s emails not searched?
The Ashurst findings should have transformed the investigative posture. Hoggett’s denials could no longer reasonably be treated as authoritative statements requiring no corroboration. They were claims made by a person already implicated in established misconduct and needed to be tested against the documentary record.
Instead, KPMG continued to place greater weight on seniority than on evidence.
The board was forced to reopen the matter
KPMG did not commission Project Magenta simply because leadership recognised that its earlier work had been inadequate.
According to reports, KPMG had resisted reopening the matter until three independent directors—Mike Baird, Jane Hemstritch and Patty Akopiantz—pressed the board to act after receiving further information from the whistleblower.
Their intervention forced the firm to establish a special board subcommittee and commission what was presented as a proper external investigation: Project Magenta, conducted by Allens.
The committee’s draft charter demonstrates that this was not intended to be a passive monitoring body. Its stated purpose was to provide direct oversight of the investigation.
It was authorised to appoint an external investigator, determine and direct the scope of the investigation, receive interim reports and oversee remedial action.
Most importantly, it had “full and unrestricted access to all Firm records, property and personnel” and could make that access available to its chosen investigator.
The charter itself noted that direct board involvement in an investigation was unusual and normally reserved for serious, complex matters or situations involving conflicts of interest.
The committee therefore had the authority and access needed to ensure a rigorous investigation. It failed to do so.
Project Magenta
Project Magenta interviewed only 14 senior KPMG partners and directors. Many of the interviews reportedly lasted around half an hour.
Hoggett denied retaining printed documents. She reportedly claimed that she did not know material could be printed from the Diligent platform used by Lendlease to distribute confidential board papers.
According to AFR reporting, an email search was considered unnecessary because of Hoggett’s “position of authority and accountability as the lead partner for the Lendlease audit”.
Hoggett had already been sanctioned for unethical behaviour. Treating her denials as reliable because of her “position of authority” was a serious error of judgment.
A later search demonstrated just how serious. It uncovered the internal email contradicting Hoggett’s denial and showing that another colleague knew the competitor proposals were available and had requested access.
Project Magenta did not fail because the truth was concealed so skilfully that no reasonable investigation could have found it.
It failed because the relevant search was not performed.
A culture of containment
The sequence of decisions speaks for itself.
KPMG searched the whistleblower’s computer. It subjected his employment position and credibility to extensive scrutiny.
Ashurst, despite its limited mandate, found evidence of a possible confidentiality breach.
KPMG sanctioned Hoggett and Rogers.
A board committee with unrestricted access to the firm’s records then approved an investigation that still did not search Hoggett’s communications.
KPMG subsequently used Project Magenta to support its public contention that the whistleblower’s central allegations had not been substantiated.
Whether or not every participant consciously intended to suppress the truth, the process operated as a mechanism of containment.
John Sams’s decision to expel Hoggett, rather than allowing her to retire early and save face, marks a clear break with the firm’s earlier instinct to contain the consequences for senior insiders. Whether KPMG’s new leadership has learned the wider lessons of the scandal will depend on whether it applies the same resolve to the culture and investigative failures that protected her denials for so long.
What the two emails tell us
The two emails, and the firm’s response to them, reveal more about KPMG Australia’s culture than any formal statement about integrity or values.
One showed confidential client information being treated as commercially useful. The other showed why speaking up had become so difficult.
KPMG’s reaction tied the two together. It treated the misconduct as a problem to be managed and contained — and the person who challenged it as the greater institutional risk.
Subsequent events have shown how misplaced those priorities were.
This is part of Big4News’ continuing coverage of the KPMG Australia Audit Leak Scandal.
KPMG Australia Audit Leaks Scandal
The KPMG Australia scandal that erupted publicly in March 2026 represents one of the most significant integrity crises to hit the Big Four in Australia since the PwC tax leaks affair. At its core are allegations—first raised internally by a whistleblower in 2024 and later amplified through parliamentary privilege—that senior partners misused highly conf…
About Claudine Cassar
I’m a corporate anthropologist and former Deloitte equity partner. I sold my technology business to Deloitte in 2016 and led the Malta Consulting team for five years. I am the founder and editor of Big4News, which provides independent, clear analysis of PwC, Deloitte, EY, and KPMG — free from corporate spin.
Find me on LinkedIn, X, Instagram, or my author website.
Feel free to reply to this newsletter — I read every reply.









