Richard James is Director and Principal Investigator at RIVICA Investigations & Covert Solutions. He has more than 34 years of investigative experience spanning policing, anti-corruption, government investigations and covert operations in Australia and the UK. Full bio at the end of the article.
Key Takeaways
The investigations behind this interview
The questions in this interview arise from a succession of processes used by KPMG Australia to examine allegations raised by a former Audit Director — beginning with an internal investigation, followed by external legal reviews and then an investigation conducted by Allens under the oversight of a KPMG board subcommittee.
KPMG’s initial internal investigation did not substantiate the whistleblower’s allegations. The firm subsequently engaged Ashurst to review aspects of its response. Documents later published by the parliamentary committee show that, in one of those reviews, Ashurst was asked to assess KPMG’s own “Investigated Response” and advise whether there appeared to be a reasonable basis for the conclusions it had reached. Ashurst expressly recorded that its work was limited to the material provided to it and that, apart from checking the conclusions against that material, it had not independently verified the information.
The distinction became important when Ashurst appeared before the Parliamentary Joint Committee on Corporations and Financial Services on 19 June 2026. Ashurst partner Jane Harvey told the committee that the firm “were never engaged to conduct an investigation” into the whistleblower’s allegations. The parliamentary committee has since said that the Ashurst and Allens processes had been central to KPMG’s assurances that it had undertaken comprehensive internal and external investigations and to its position that most of the allegations had been found to be unsubstantiated.
By September 2025, a KPMG board subcommittee had appointed Allens to conduct a further investigation, known as Project Magenta. Allens reported in December 2025 that none of the allegations within its investigation had been substantiated, although it identified conduct in examining one allegation that it considered likely to have breached KPMG’s terms with its client and its confidentiality policy.
That was not the end of the process. As further evidence emerged, Allens continued its work with an expanded scope. On 29 May 2026, KPMG acknowledged that its original internal investigation had not been conducted with the necessary rigour and said that, with new evidence, the continuing Allens investigation was challenging conclusions reached in the earlier investigations.
The consequences of that expanded work became clearer in July. Allens uncovered new evidence concerning one of the whistleblower’s central allegations: that confidential Lendlease information had been retained by former KPMG chief operating officer Eileen Hoggett in a locker at the firm’s Sydney office. The allegation had previously been denied. On 24 July, KPMG told the parliamentary committee that the new evidence meant it now accepted that the allegation had been substantiated.
At a further parliamentary hearing on 14 August, Hoggett acknowledged that the documents had been printed and placed in her locker, but said she did not recall printing or storing them herself and was not aware that they had been used to win new work.
Since then, KPMG has published a further independent lessons-learned review by the Andrews Group. The review found that the firm had taken an overly legalistic approach to the whistleblower, initially placed too much emphasis on workplace grievances rather than the ethical issues being raised, failed to manage conflicts appropriately and did not provide adequate safeguards or support. KPMG says it has accepted all six recommendations.
It is against that chronology that James considers a broader question: what makes an investigation genuinely independent — and what happens when the organisation being investigated retains influence over its scope, evidence and assumptions?
Editor’s note: Richard James’s comments in this interview are based on material in the public domain, including parliamentary hearings, media reporting and the publicly documented chronology of events. He has not reviewed KPMG’s internal documents, unredacted investigation reports or private communications, and his observations should therefore be read in that context.
His comments assess the investigative processes described in the public record from the perspective of a practitioner with more than 34 years’ experience in law enforcement and investigations. They are not intended as legal findings about any individual, but as an assessment of how a properly independent investigation should operate and where, in his view, the publicly described processes appear to have fallen short.
The Interview
Was the fundamental failure poor execution, or were the processes simply not designed to find the truth?
Honestly, both. But they are not the same problem and they do not carry the same weight.
Poor execution is fixable. You can retrain people, tighten methodology, improve documentation. But a process that is not designed to find the truth will not find it no matter how well it is run.
That is the more fundamental problem at KPMG. The moment someone decided to treat the original disclosure as a personnel matter rather than a governance and audit integrity concern, the process that followed was pointed in the wrong direction. It was not investigating whether confidential client information had been misused. It was managing an employment dispute. Those are different exercises and they produce different results.
Project Magenta was a more serious attempt, but it had its own structural problem. The scope was set by a KPMG board subcommittee. The interviews were short, focused on senior figures, and accepted credibility based partly on seniority. Nobody spoke to the whistleblower, external witnesses, affected clients, or rival firms. The digital records that would have tested what witnesses said were not examined.
You can have very competent people executing that process and still not get to the truth. The architecture was wrong. That is not an execution problem. That is a design problem.
What should an investigator do if the remit is too narrow? Insist on wider scope or decline to sign off?
Push back first. And if the pushback fails, walk away.
I know that sounds straightforward but in practice there is real commercial pressure in the other direction. Nobody wants to lose an engagement by being difficult about scope. But here is the thing. If you sign a report knowing your remit was too narrow to properly test the central allegations, you risk creating a misleading impression that your conclusions are supported by the evidence. It does not matter how carefully worded the report is if the scope does not support the conclusion being drawn from it.
The Ashurst situation illustrates this perfectly, though from a slightly different angle. Ashurst was not asked to investigate the substance of the allegations. It was asked something much narrower. Whether KPMG had reasonable grounds for describing the allegations as false and misleading. That is a completely different question. But KPMG subsequently relied on the Ashurst process as part of its assurances that it had undertaken comprehensive internal and external investigations and that the bulk of the whistleblower’s allegations were unsubstantiated.
Ashurst told Parliament that it had not conducted an investigation into the whistleblower’s allegations and had not been asked to do so.
Now I am not suggesting Ashurst did anything wrong. Their mandate was what it was. But that gap between what KPMG said the investigation found and what the investigator said it was actually asked to do is a cautionary tale for anyone accepting a narrow brief and then watching it get characterised as something broader.
If your terms of reference will not let you reach a sound conclusion, say so before you sign anything.
Should seniority or assessed credibility ever be a reason not to collect documentary evidence that could test what a witness has said?
No. And I will be blunt about this because it matters.
Credibility assessment is a tool for weighing evidence when the evidence itself is unclear or conflicting. It is not a reason to skip collecting the evidence in the first place. If documentary evidence exists that could test what someone has told you, you collect it. That is not optional. That is the job.
Seniority is actually one of the more dangerous credibility proxies I have come across in investigative work. In my experience, the people most capable of maintaining a denial under sustained pressure are often those who have spent careers building their authority and their networks. Seniority gives you confidence. It gives you institutional support. It gives you the ability to shape the environment in which you are being questioned. None of that makes you more honest.
Eileen Hoggett denied keeping or sharing the Lendlease documents. Her denial was accepted, in part because of her position of authority and accountability as lead partner. The truth came out when a later investigation found a single email showing she had instructed her executive assistant to retrieve and share printed copies she had kept in her locker.
That email existed throughout the earlier investigation. It was not found because the investigation did not search the relevant internal communications after assessing the relevant witnesses as credible, taking account in part of their positions of responsibility and authority.
Documents do not adjust their account under questioning. That is why you examine them regardless of how credible the witness appears. If you skip the document review because you find the witness convincing, you are trusting a person over the evidence. In investigative work that is the wrong order of operations every time.
Why does the distinction between reviewing an earlier investigation and conducting a fresh one matter?
Because they are asking fundamentally different questions.
A review of an earlier investigation asks: was the process sound and do the conclusions follow from what was done? It works within the frame of the original inquiry. It can assess whether the methodology was appropriate. What it cannot easily do is surface what the original investigation did not look for, because the reviewer is working from a picture of the evidentiary landscape that the original investigation created.
A fresh investigation asks: what actually happened? It starts from the allegations themselves, not from someone else’s account of them. It is not bound by the earlier scope, the earlier assumptions, or the earlier conclusions.
The KPMG matter shows how this plays out in practice. Ashurst reviewed KPMG’s handling of the whistleblower and examined a narrowly framed question about the firm’s grounds for its position. Project Magenta examined the allegations within a scope approved by a KPMG board subcommittee. Both processes were shaped, to varying degrees, by the institutional framing of the original response. Ashurst was not asked to conduct a substantive investigation of the allegations, while Project Magenta concluded that the allegations it examined were unsubstantiated. Later evidence undermined important parts of that earlier position.
A genuinely fresh investigation conducted by someone with no prior involvement, no relationship with the institution, and no inherited assumptions would not have carried that framing forward. It would have started with the allegations and followed the evidence. That is a different exercise and it produces different results.
The practical lesson is simple. If the first investigation failed, commissioning a review of that investigation will not fix the problem. You need someone to start again from the beginning.
Is there an investigative danger when the complainant is scrutinised more aggressively than the people they have accused?
Yes. It is one of the most recognisable patterns in failed institutional investigations and it effectively inverts the burden.
In any serious investigation the central question is whether the conduct alleged actually occurred. The complainant’s credibility matters, but it is not the primary focus. What matters is whether the evidence supports the allegation.
The asymmetry in the KPMG matter is striking. The whistleblower’s laptop was searched on the same day he made his formal disclosure and again on two further occasions months later. His employment history, performance record and proposed relocation featured prominently in KPMG’s April 2026 parliamentary submission, which presented his allegations as unsubstantiated while focusing substantial attention on his circumstances as an employee.
Meanwhile during Project Magenta the communications of the senior partners he had accused were not subjected to equivalent scrutiny. Hoggett’s denial was accepted. The email that disproved it was not found because the search that would have found it was considered unnecessary given her credibility.
A genuinely neutral investigation applies the same standard of scrutiny to the evidence about the accused as it does to the evidence about the complainant. The moment more energy goes into testing the complainant’s credibility than into testing the evidence against the people they have accused, the investigation has stopped being neutral.
In my experience that asymmetry is rarely a deliberate decision. It tends to emerge from the institutional context. The accused are known, senior, and present. The complainant is often isolated and, by the time the investigation is underway, frequently already in a difficult employment position. The investigator who is not actively alert to that dynamic will drift toward it without realising.
Can an investigation be genuinely independent if the client controls what the investigator is allowed to know?
No. That is not independence. That is a managed review.
Independence means freedom from the interests, relationships and institutional pressures of the organisation being examined. That freedom has to extend to the information the investigator receives. An investigator who relies entirely on the organisation to tell them what evidence exists, who the relevant witnesses are, and what documents are available has handed their independence back to the institution before the investigation has started.
The specific problem revealed about Ashurst is a precise illustration. KPMG told Ashurst the whistleblower had provided only high-level information. Ashurst was not told that KPMG had earlier accessed his computer and downloaded documents detailing more than fifteen complaints. Ashurst’s reviews were therefore based on an incomplete picture shaped by what the institution chose to disclose.
The practical answer to this is that a serious investigator does not wait to be told what evidence exists. You identify what categories of evidence should exist in a matter like this and you take steps to obtain them directly. You ask for direct access to relevant email systems and document repositories. You seek out witnesses the organisation has not nominated. You ask specifically what the organisation knew, when they knew it, and what documents record that knowledge.
An investigator who works only with what they are given is reviewing the organisation’s account of itself. That is a legitimate exercise but it is not an independent investigation. The organisation commissioning the work knows the difference even when everyone else does not.
Where does accountability sit when an investigation fails: with the investigator, those who designed and supervised it, or both? Can directors rely on conclusions produced by a process they helped design?
Both. And no.
The investigator whose name is on the report bears professional responsibility for what it says. They accepted the scope. They chose the methodology. They reached the conclusions. Where the constraints were incompatible with a sound finding, the investigator should have said so before signing, not after.
But that does not let the people who designed and supervised the process off the hook. Their accountability operates independently.
The KPMG board subcommittee approved Project Magenta’s scope and methodology. The AFR later reported that the board subcommittee, which included a majority of independent directors, had been given full and unrestricted access to the firm’s records, property and personnel and failed to use those powers adequately. That is significant because it removes the argument that the oversight was constrained by the partnership structure. The powers to investigate properly existed. They were not exercised.
A board member who helps design the scope of an investigation and then relies on the conclusions produced within that scope as though they were produced independently should not assume that appointing an external investigator, by itself, discharges their oversight responsibility. The risk is that they have created the appearance of external scrutiny while keeping control of the conditions that determined what that scrutiny could find.
The question any director should be asking is not “have we appointed an external investigator?” It is “has the process we have designed given this investigator a genuine and unencumbered ability to find out what happened?” If you cannot answer yes to the second question, the first question does not give you the protection you think it does.
What minimum investigative steps would you have insisted upon before concluding whether the allegations were substantiated or unsubstantiated, and before putting your name to the report?
A few things I would not have moved on.
Complete access to relevant electronic communications, subject to legitimate privilege, privacy and confidentiality constraints. Not a selection provided by the organisation. Direct access to the systems, or access supervised by someone technically competent acting for me. The Hoggett email existed throughout the earlier investigation. It was not found because the earlier investigation did not search the relevant internal communications. That is not a recoverable situation once a finding has been made and relied upon by regulators and a parliamentary committee.
Interviews with all relevant witnesses. That means the complainant. Junior staff. Affected clients. Competitors who submitted bids that may have been exposed. The people who would most directly know whether the conduct occurred. Project Magenta conducted fourteen interviews, twelve of which lasted approximately thirty minutes, with senior KPMG figures only. If you only speak to the people being accused and their colleagues, you are not investigating the allegations. You are testing their accounts against each other, which is a different exercise entirely.
Independent control over investigative scope. The terms of reference need to give the investigator sufficient freedom to follow the evidence, rather than allowing the institution being investigated to prevent relevant lines of inquiry. I would not accept an engagement where the institution could narrow what I was permitted to examine once the evidence pointed somewhere relevant. If that condition is not met, I am not independent regardless of what the engagement letter says.
No prior relationship with anyone whose conduct is under examination. And that needs to be verified at the outset, not assumed.
A credibility assessment methodology grounded in documents, not seniority. Where someone denies conduct, I test that denial against every available documentary and physical record. I have seen too many senior people maintain a position under questioning that the documents then disprove. The document does not adjust its account. The interview does.
And finally, I would not have concluded the allegations were unsubstantiated unless I could point specifically to what evidence I had examined that tested each allegation directly. “Insufficient evidence” should not be the end of the analysis if obvious evidentiary avenues have not been pursued. In that situation, it may describe what the investigation failed to gather rather than what actually happened. One of the whistleblower’s most serious allegations — that confidential Lendlease information had been retained in Hoggett’s locker — was eventually substantiated. The difference between the investigation that did not confirm it and the one that did was not the quality of the people involved. It was the willingness to look properly.
Who is Richard James?
Richard James is Director and Principal Investigator at RIVICA Investigations & Covert Solutions, a Melbourne-based private investigations firm established in 2014. He has more than 34 years of investigative experience across law enforcement, government investigations, anti-corruption, covert operations and private practice in Australia and the UK.
At RIVICA, James oversees major investigations across corporate, legal, government and private matters. He is a licensed senior investigator in Victoria and has experience in expert-witness and court testimony work. His background also includes providing specialised training and operational support to police and military teams in the Middle East and Southeast Asia.
His work focuses on investigative strategy, evidence gathering and covert operations, combining traditional investigative methods with modern investigative technology.
This article is part of the Big4News Expert Voices Series
Expert Voices
Expert Voices features interviews and guest contributions from former insiders, whistleblowers, academics, regulators and experienced practitioners. The series examines the structures, incentives and professional cultures behind events at Deloitte, PwC, EY and KPMG.






