The Australian Securities and Investments Commission has warned approximately 2,900 registered company auditors that misconduct will attract increased surveillance and, where evidence permits, stronger enforcement action.
ASIC wrote to auditors on 22 July, reminding them of their legal, ethical and professional obligations at a time of heightened concern about conduct within audit firms and declining confidence in the profession, amplified in recent months by the steady stream of headlines about the KPMG audit leaks scandal.
The regulator said auditor misconduct remains one of its enforcement priorities. Available action includes applying to the Companies Auditors Disciplinary Board to suspend or cancel an auditor’s registration, issuing infringement notices and commencing civil proceedings.
ASIC Commissioner Kate O’Rourke said the regulator was concerned about auditors who had failed to comply with legal requirements and professional standards requiring them to act independently and ethically. ASIC will increase its attention to conflicts of interest and relationships that may compromise, or appear to compromise, an auditor’s objectivity.
The letter followed the escalation of the KPMG Australia confidential-information scandal, which has prompted wider questions about independence, professional conduct and the regulator’s ability to oversee the country’s largest audit firms.
The consequences are already spreading beyond KPMG. The disclosures have prompted closer scrutiny of auditor independence, firms’ handling of confidential information and the limits of ASIC’s powers over partnership-based audit firms
ASIC is already conducting a separate surveillance exercise examining internal complaints received by the Big Four about their audit practices. That review covers complaints and whistleblower allegations involving matters such as the misuse or internal sharing of confidential information.
The regulator is also continuing its established programme of reviewing financial reports and audit files. For the 2026–27 financial year, files will be chosen through a combination of risk-based and random selection, expanding the possibility that weaknesses may be identified outside audits already regarded as high risk.
ASIC’s letter reiterates that registered auditors must avoid prohibited relationships and conflicts that prevent objective and impartial judgement. They must also provide accurate and timely information to ASIC, report relevant contraventions and attempts to interfere with an audit, and comply with the ethical principles of integrity, objectivity, competence, confidentiality and professional behaviour.
The regulator said it would review auditors’ compliance with annual reporting obligations during 2026–27 and introduce twice-yearly meetings for registered company auditors to discuss enforcement priorities, emerging risks and examples of good practice.
ASIC’s authority nevertheless remains structurally constrained. Big Four firms in Australia operate as partnerships, and ASIC does not supervise those partnerships in the same way that it regulates companies. Its direct authority is principally exercised over individual registered auditors, even when concerns may arise from firm-wide governance, culture or internal systems.
From PwC to KPMG: reform returns to the agenda
Treasury’s July 2026 options paper describes that gap directly. Large audit partnerships have no separate legal personality, and current law does not impose comprehensive firm-level obligations equivalent to those applying to authorised audit companies. In practice, the lead auditor may face deregistration or other penalties while senior decision-makers responsible for the firm’s policies and control systems remain outside the immediate enforcement framework.
The government first committed to examining that structure after the PwC tax-leaks scandal. Former PwC tax partner Peter-John Collins obtained confidential information while participating in government consultations on proposed multinational anti-avoidance rules and shared it within PwC, including with personnel outside Australia. The information was used to help the firm and its clients anticipate the new legislation.
Parliamentary inquiries subsequently concluded that the episode exposed serious failures in PwC’s governance, conflict management and handling of confidential government information.
In August 2023, the government said the scandal had demonstrated that parts of Australia’s regulatory framework were not fit for purpose. Alongside reforms to tax-promoter penalties and the powers of the Tax Practitioners Board, Treasury was instructed to examine whether stronger governance, transparency, executive-accountability and conflict-management requirements should apply to large consulting, accounting and auditing firms.
Treasury released an initial consultation paper in May 2024. It examined the regulation of partnerships, auditor independence, conflicts of interest, transparency, enforcement powers, whistleblower protections and concentration in the audit market. But it did not recommend a particular model; it said a later consultation would canvass the possible policy responses. The consultation closed in June 2024, leaving the broader question of firm-level audit regulation unresolved.
That unfinished work returned to the political agenda after the KPMG Australia scandal became public in March 2026. The allegations concerned the internal use and sharing of confidential client information in connection with efforts to win audit work.
KPMG later acknowledged that client documents had been inappropriately shared internally and that its treatment of the whistleblower, the rigour of its investigations and the response of its leadership had fallen short. The firm’s chief executive and national head of audit resigned in May.
When Treasury released its detailed options paper on 30 June 2026, Assistant Treasurer Daniel Mulino explicitly connected the proposed changes to the conduct exposed at both PwC and KPMG. Asked why the options paper had taken nearly three years to emerge, he said the government had been progressing other elements of the PwC response but was now accelerating its work, “especially” in light of what had happened at KPMG.
What Treasury is considering
The options would produce a considerably more interventionist system than the one under which ASIC sent its July letter.
One proposal would require audit firms—including partnerships—to obtain a licence from ASIC before auditing reporting entities. Continued licensing could be made conditional on compliance with firm-wide quality-management and ethical obligations, allowing ASIC to supervise and sanction the organisation rather than relying principally on action against an individual lead auditor.
Treasury is also considering several ways of separating audit from consulting. The least radical would prohibit a company from buying non-audit services from its external auditor. Operational separation would retain both businesses inside the same firm but require greater separation of their management, finances and incentives. Structural separation would go further by requiring audits to be conducted by firms that do not offer non-audit services.
Other proposals would impose stronger governance and fit-and-proper requirements on large audit firms, introduce civil penalties for audit partnerships and give ASIC broader surveillance, administrative and remediation powers. Treasury is also considering more frequent inspections and the publication of firm-level findings.
The wider package includes possible restrictions on non-audit services, operational or structural separation of audit from consulting, reductions in the permitted size of accounting partnerships, periodic tendering and mandatory audit-firm rotation after 20 years.
None of these options has yet been approved by the government or enacted. Treasury is consulting until 12 August 2026, and some of the more substantial changes would require cooperation with Australia’s states and territories because partnerships are largely governed under state law.
Enforcement before reform
For the moment, ASIC must work with the powers it already has. Its letter to the country’s registered auditors therefore represents an immediate enforcement response: increased surveillance, closer attention to independence and conflicts, and greater willingness to pursue individual disciplinary or court action where evidence supports it.
The Treasury process addresses the larger question left exposed by successive scandals: whether misconduct that emerges from a firm’s culture, incentives and internal systems can be dealt with adequately by disciplining individual auditors—or whether Australia needs a regime capable of holding the audit firms themselves directly accountable.
Related Coverage
Reuters: Australia increases auditor oversight after KPMG scandal
Reports that the letter was sent to approximately 2,900 auditors and explains ASIC’s increased focus on conflicts and personal relationships.
Reuters: ASIC reviews audit-conduct complaints at Big Four firms
Covers the separate surveillance examining how the largest audit firms handle internal complaints and whistleblower allegations.
Reuters: Australia considers stronger regulation of Big Four firms
Explains the government’s wider reform process, including proposals to expand ASIC’s authority over partnership-based accounting firms.
Want to stay up to date on all things Big Four around the world?
Check out the News section and subscribe to Big4News for weekly deep dives and briefings.
This is part of Big4News’ continuing coverage of the KPMG Australia Audit Leak Scandal.
KPMG Australia Audit Leaks Scandal
The KPMG Australia scandal that erupted publicly in March 2026 represents one of the most significant integrity crises to hit the Big Four in Australia since the PwC tax leaks affair. At its core are allegations—first raised internally by a whistleblower in 2024 and later amplified through parliamentary privilege—that senior partners misused highly conf…
About Claudine Cassar
I’m a corporate anthropologist and former Deloitte equity partner. I sold my technology business to Deloitte in 2016 and led the Malta Consulting team for five years. I am the founder and editor of Big4News, which provides independent, clear analysis of PwC, Deloitte, EY, and KPMG — free from corporate spin.
Find me on LinkedIn, X, Instagram, or my author website.
Feel free to reply to this newsletter — I read every reply.





