Key Takeaways
Formal authority is more likely to be exercised effectively when partner and executive compensation rewards risk stewardship and ethical boundaries, not revenue alone.
Corporate scandals can be outputs of operating systems, not only rogue operators. Accountability must examine incentives as well as individual conduct.
Modern corporations live in a state of institutional cognitive dissonance. On one side of the organisational chart lie sprawling networks of purpose statements, risk policies, ethics boards, and compliance officers. On the other sit the hard-driving engines of commercial power: deal makers, revenue heads, and executives measured by growth and margin.
When these two forces collide, the outcome is rarely a dramatic, cinematic battle of good versus evil. Rather, it is a quiet, systemic rout. Time and again, organisations build sophisticated challenge and assurance mechanisms, mandate them on paper, feed them data, and then watch helplessly — or wilfully — as they fail to act as brakes against corporate disaster.
This brings us to the notion of purpose, the firm’s reason for existing. Audit and consulting have different professional purposes. Audit is grounded in independent assurance: the PCAOB states that auditors have a fundamental obligation to protect investors through informative, accurate and independent opinions. Consulting is centred on solving client problems. Both, however, are vulnerable when commercial incentives begin to override the professional purpose of the work.
Understanding why challenge and assurance functions fail requires confronting the structural mechanics of power.
1. The Paradox of Internal Checks and Balances
Organisations create purpose, risk, and ethics functions for two distinct audiences: regulators who demand accountability through oversight, and markets that reward perceived governance health.
These functions suffer from a structural vulnerability. They are paid, staffed, and housed within the very entities they are meant to challenge. Their career trajectories are influenced by internal political capital.
Formal authority without structural leverage can be illusory. A Chief Risk Officer may have a dotted line to the board, but if commercial leaders control access to the CEO and directors, the risk function can be effectively declawed.
In such situations, the challenge function might provide early warnings when concerns arise, without having sufficient authority to halt, condition or escalate the decisions that could allow those concerns to develop into full-blown scandals.
2. The Anatomy of Business Failure
The following three case studies illustrate what happens when commercial power overrides warnings and professional challenge, leading to a failure of governance, challenge or assurance mechanisms.
Case 1: Enron and Arthur Andersen
In August 2001, Sherron Watkins, a senior Enron accountant, raised concerns about the company’s accounting practices with Kenneth Lay, Enron’s newly reappointed CEO. She also conveyed her warnings to Arthur Andersen, Enron’s auditor, where they were discussed by engagement partner David Duncan, in-house counsel and senior management.
The fraud was massive. The SEC later alleged that Enron used disguised loans structured as asset sales to increase reported earnings by more than $1 billion, increase reported operating cash flows by almost $2 billion, and avoid disclosing more than $2.6 billion in debt.
Andersen’s Enron engagement team included more than 100 accountants and billed the company approximately $58 million in 2000. The firm had classified Enron as a “high-risk” client, but when an internal technical expert did not approve an aggressive accounting approach, he was removed from the team.
The client’s interests and Andersen’s fees had created an obvious tension with an auditor’s professional duty.
The SEC opened an informal investigation into Enron on 28 August 2001. By late September, senior Andersen personnel were anticipating SEC scrutiny and litigation, but instead of retaining evidence, they set up a purpose shred room and destroyed hundreds of thousands of documents relating to their client, while tens of thousands of emails and other electronic documents were deleted.
The consequences were catastrophic. Andersen was convicted in 2002 for corruptly persuading its employees to withhold or alter documents for use in an official proceeding. It subsequently surrendered its US accounting licences and its global network effectively disintegrated.
In May 2005, the US Supreme Court reversed the conviction because the jury had not been properly informed regarding the elements required for a conviction for corrupt persuasion. By then, however, Andersen’s audit practice had already collapsed.
Case 2: McKinsey and Purdue Pharma
In 2013, Purdue Pharma retained McKinsey to identify opportunities to increase OxyContin sales. The resulting “Evolve to Excellence” engagement included advice on how to “turbocharge” the sales pipeline by intensifying marketing to “High Value Prescribers”.
The Department of Justice later alleged that, from 2013 to 2014, this advice caused false and fraudulent claims for medically unnecessary OxyContin prescriptions to be submitted to federal healthcare programmes.
As legal scrutiny of Purdue intensified in 2018, Martin Elling, a senior partner, deleted Purdue-related materials from his McKinsey laptop and Outlook account. Elling subsequently pleaded guilty to obstruction of justice.
McKinsey agreed in December 2024 to pay $650 million to resolve criminal and civil investigations relating to its Purdue work. It also entered a five-year Corporate Integrity Agreement requiring, among other measures, a Compliance Committee to establish a risk-evaluation process and quality oversight for certain client engagements.
Case 3: PwC Australia
From 2013 to 2016, PwC Australia tax partner Peter Collins received confidential information through Treasury consultations and his involvement with the Board of Taxation concerning forthcoming Australian anti-avoidance laws. Despite signing multiple confidentiality agreements, he intentionally shared confidential information with PwC personnel in Australia and overseas.
The information was used to set up a marketing drive dubbed Project North America, generating millions of dollars of revenue for the firm.
There had been several internal warnings — but the firm’s leadership ignored them.
In 2017, PwC Australia’s Office of General Counsel and Risk teams questioned Collins about a September 2015 email relating to a Board of Taxation consultation. PwC later said that no action was taken because there was no formal confidentiality agreement covering that particular meeting, although the Board of Taxation had asked Collins to keep his participation confidential.
PwC later also acknowledged that even after the Tax Practitioners Board began its investigation in 2021 and evidence of confidentiality breaches emerged, there was no internal investigation. Instead, the firm engaged in what was later described by a senate committee as a cover-up.
It took another two years for the firm to officially look into the matter.
The fallout once the facts of the case emerged was severe. CEO Tom Seymour stepped down in May 2023 and subsequently left the partnership, while other senior leaders and partners also departed. PwC then sold its Australian government consulting business to private-equity firm Allegro Funds for A$1; the business, which became Scyne Advisory, took with it around 1,500 PwC partners and employees and had accounted for roughly 20% of the firm’s FY2023 revenue.
The scandal also triggered parliamentary inquiries, regulatory and police investigations, extensive restructuring and hundreds of job cuts as PwC sought to rebuild trust.
3. The Limits of the Three Lines Model
The Institute of Internal Auditors has developed a model for allocating responsibility for risk management, oversight and assurance: the Three Lines Model, which was refreshed in July 2026.
Management forms the first line; specialist risk, compliance and similar roles form the second; and internal audit provides independent third-line assurance.
Second-line functions are expected to support, monitor and challenge first-line management. But they remain part of management, and their authority is determined by the board or applicable law. The model does not itself give them veto authority over commercial decisions.
That is the structural weakness illustrated by the cases above. Serious warning signs had already surfaced inside Andersen, McKinsey and PwC. The problem is what happened once those concerns encountered commercial power.
Challenge functions need to have sufficient access, independence, escalation rights and authority to make resistance meaningful when commercial and ethical objectives conflict.
4. The Rogue Operator Narrative vs. Institutional Complicity
After each scandal, the deflection script is often similar: fire the individual and declare the problem solved. The problem with this approach, of course, is that the unethical behaviour is often just a symptom of the real problem, and if that problem is not diagnosed accurately and resolved, the cycle is likely to repeat itself.
Problematic behaviour is often the result of a system designed to prioritise revenue, measure performance by utilisation and client retention, neutralise internal warnings before they threaten profitability, and insulate decision-makers from accountability.
The “rogue operator” narrative is convenient for an institution because it narrows accountability to a single individual even where the surrounding system rewarded or tolerated the behaviour that occurred.
This does not remove individual responsibility, but it does mean that individual misconduct and the system in which it occurred both require examination.
5. Transparency
Legal risk management can become procedural shelter from accountability. Settlements can avoid full adjudication and leave important questions untested, even where they are accompanied by extensive statements of facts or compliance obligations.
Legal privilege, when improperly asserted to shield decision-making trails from legitimate examination, can frustrate oversight. PwC’s use of legal professional privilege claims in its dispute with the ATO demonstrates the problem: the ATO told Parliament that its investigation had been frustrated by privilege claims, while subsequent Federal Court proceedings found that a substantial proportion of the sample examined was not privileged.
Firms must choose whether to prioritise transparency, accepting the legal risk that comes with it, or instead resort to operational blindness, which often means that lessons are not learned from organisational failures.
Cultivating Internal Alignment
Culture and ethics are critical elements of the scaffolding of success, but they cannot flourish without structural teeth. To make challenge functions effective:
Surface diverging views between risk, legal and compliance. Document them, escalate them, and allow leadership to make explicit, informed decisions about the risks they are taking.
Realign incentives so that challenge functions have real commercial friction — the authority to halt, condition, escalate or expose bad practices alongside fee generation.
Tie partner and executive compensation to risk stewardship and client selectivity, not just revenue and utilisation targets.
External Regulatory Authorities
When everything else has failed and internal mechanisms are bypassed, regulators need effective enforcement tools.
SEC investigations can involve subpoenas for testimony and documentary evidence, while the PCAOB’s disciplinary powers include suspension or revocation of an audit firm’s registration and temporary or permanent bars on individuals associating with registered public accounting firms.
These are qualitatively different from a monetary fine alone because they can affect whether a firm or individual is permitted to continue performing regulated audit work.
Closing Argument: Realigning Purpose and Power
Corporate purpose statements are cheap to write and easy to market. Ethics cannot be outsourced to a compliance committee, and risk-assessment processes cannot substitute for moral judgement.
Until organisations accept that purpose, risk and ethics functions require real operating leverage, they risk remaining performative.
The ultimate question is plain: Are you willing to build a commercially viable ethical model where ethics and revenue are structurally aligned — not in perpetual conflict?
If the answer is yes, that decision must be embedded in partner and executive compensation, client selection and engagement approval. If the answer is no, the risk of another cycle of scandal, settlement and silence remains.
Who is Astrid Yee-Sobraques?
Astrid Yee-Sobraques is a senior risk executive specialising in Enterprise Risk Management, operational resilience and cybersecurity.
She has more than 25 years’ experience across GE Capital, AIG, Citibank and PwC, with expertise spanning Enterprise Risk Management, strategic advisory, regulatory compliance, digital transformation and cybersecurity across banking, asset management and P&C insurance.
Astrid is also a contributor to GARP Risk Intelligence, where her work has addressed AI risk, data governance, cyber risk, operational resilience and interconnected enterprise risk.
This article is part of the Big4News Investigations & Analysis series, which examines the structural forces shaping Deloitte, PwC, EY and KPMG.




