Summary

  • The corporate US resolution is a DPA, not a guilty plea. McKinsey Africa accepted responsibility for the acts described in the statement of facts and agreed to a three-year term. The information remains a charging instrument. That distinction does not diminish the admissions, but it prevents a conditional corporate resolution from being reported as a conviction.

  • The former partner's plea is separate. Vikas Sagar's individual guilty plea has its own actor, intent and procedural history. It cannot be assigned to every partner, employee, local firm or official mentioned in other records. Conversely, the corporate DPA cannot be treated as a substitute for individual adjudication.

  • South African institutions supply independent evidence. NPA, SIU, Eskom, parliamentary and Judicial Commission records cover procurement, repayments, public-enterprise governance and related cases. Their conclusions and time frames must not be blended into the US statement of facts or into a single monetary total.

  • The operational control failure began before invoicing. Partner selection, beneficial ownership, capability, fee allocation, access to confidential information, sole-source justification and public-client approvals needed one independent gate before an engagement could advance.

  • Professional partnership governance matters. A senior partner can combine commercial influence, client relationships, staffing authority and prestige. A control that depends on another partner challenging that authority without protected escalation is structurally weak.

  • Repayment is remedy evidence, not a full effectiveness certificate. Returning fees can remove benefit and support public recovery. It does not by itself prove that later partner engagements were competitively awarded, independently approved or free of undisclosed influence.

  • Durable repair must be replayable. An independent reviewer should be able to reconstruct public need, procurement route, confidential-information access, partner ownership, scope, contribution, fee, approval, invoice, payment, accounting and post-engagement testing from immutable evidence.

Begin with the US procedural map

The Justice Department's McKinsey Africa case page is the cleanest procedural index. It identifies the Southern District of New York matter, docket 24-cr-00669-CM, and links the information, deferred prosecution agreement and announcement. A case register should preserve that structure. The information states the charge; the DPA states the conditions of deferred prosecution and incorporates admissions; the announcement summarizes the resolution. Calling all three a conviction would be wrong, while calling them merely an allegation would ignore the subsidiary's express acceptance of the statement of facts.

The filed criminal information charged McKinsey Africa with conspiracy to violate the FCPA's anti-bribery provisions. It described the subsidiary, the US parent, a former senior partner, two South African consulting firms, Transnet and Eskom, and public officials whose identities were known to the parties. It alleged that the scheme used sensitive non-public procurement information and local partners in proposals for consulting work. The information is a prosecutor's charging document. Its allegations become corporate admissions only to the extent incorporated into and accepted through the DPA.

The deferred prosecution agreement and statement of facts provide that incorporation. McKinsey Africa agreed that the statement was true and accurate, accepted responsibility for acts of officers, directors, employees and agents described there, and undertook cooperation, compliance and reporting obligations for three years. The statement says the conduct ran from at least 2012 through 2016 and involved consulting opportunities at Transnet and Eskom. It also describes confidential information, proposed fee divisions, sole-source work and the understood use of part of consulting fees for bribes.

Those admissions are the firmest factual foundation for the corporate article.

The Department's resolution announcement reconciles the $122.85 million criminal penalty, potential credit for payments to South African authorities, cooperation and remediation considered by prosecutors. It says the firm enhanced third-party due diligence, instituted controls requiring diligence before work begins, added risk review for public clients and advance approval for sole-source work, and repaid revenue from potentially tainted contracts. Those are material control commitments. They remain descriptions within a resolution, not independent proof that every redesigned control operated effectively afterward.

The Southern District of New York's parallel announcement also records that the former senior partner had pleaded guilty in December 2022 and that the plea was unsealed with the corporate resolution. This separate procedural lane is critical. Individual criminal responsibility depends on that person's admissions and case. The DPA says other personnel participated in legitimate work without being told of the scheme. Governance analysis should examine how the system allowed concealed conduct without converting uninformed participation into guilt by association.

South African records have their own authority

The National Prosecuting Authority's 2024/25 annual report describes a McKinsey settlement in the wider state-capture enforcement portfolio and the coordination with US authorities. An annual report is an institutional account of outcomes and recoveries, not the full terms of each underlying instrument. It is useful for South Africa's remedy and enforcement chronology, but the DPA controls the US corporate admissions and any South African agreement controls local consequences.

The NPA's Transnet case announcement concerns charges against former Transnet executives and others connected with a locomotive transaction advisory tender awarded to a McKinsey-led consortium. It is relevant because it shows that public-client procurement and individual cases continued on their own track. It is not proof of guilt: charges and arrests are not convictions, and the article does not attribute one defendant's alleged conduct to McKinsey Africa beyond the corporate admissions in the DPA.

The Special Investigating Unit's Transnet investigation record defines a broad mandate covering appointments of McKinsey, Trillian and Regiments, related payments, irregular or wasteful expenditure, procurement and undisclosed interests. Scope is not outcome. A proclamation or investigation mandate shows what the SIU was authorized to examine; it does not establish every suspected fact. Control owners should nevertheless treat such scope as a risk map, because it joins partner interests, supplier appointment, payment and employee conflicts within one evidence system.

The SIU's 2018 interim report places the McKinsey-related work within wider investigations at Eskom and Transnet. Interim reporting is date-bound. Matters may still be under investigation, litigation or referral, and later records may refine the amount, party or legal theory. An accountable firm therefore maintains a claim register that records each authority, allegation, procedural status and source date instead of building a permanent narrative from the earliest public document.

Eskom's records show procurement and recovery over time

Eskom's 2019 integrated report says McKinsey's services were procured through a sole-source process without competitive bidding and that subcontracting involving Trillian did not follow necessary procurement processes. It also records McKinsey's repayment of R902 million plus R99 million interest and Eskom's pursuit of money paid to Trillian. These are Eskom's corporate disclosures about procurement irregularity and remedy. They should not be silently equated with the later US bribery admissions, which cover a defined statement of facts and named corporate defendant.

Eskom's 2021 annual report updates financial recovery from suppliers and litigation against Trillian. The later report illustrates why recovery totals need identifiers. A repayment by McKinsey, a judgment against another firm and a settlement with a different adviser can all appear in one governance-cleanup section. Adding them without preserving payer, recipient, legal basis, tax or interest treatment and collection status can double count remedy or attribute one entity's unpaid judgment to another.

The utility's 2018 interim financial statements provide an earlier snapshot: a non-competitive sole-source process, subcontracting concerns, management departures, charges lodged against relevant employees, termination of business relationships and repayment. The date matters. A disclosure that a process is open or a hearing is scheduled cannot be quoted years later as though it remains current. The evidence pack should preserve the 2018 status while later sources provide resolution or continuing uncertainty.

The South African Parliament's final report on the Eskom inquiry assembled testimony, documents and committee conclusions about public-enterprise governance. It included McKinsey material among a much larger state-capture record. Parliamentary findings can illuminate board, procurement and executive-accountability failures, but they are not criminal verdicts. Their strength for this article lies in showing how consulting engagements interacted with a weakened public-client control environment.

The archived Judicial Commission's Part IV report on the capture of Eskom supplies a later investigative synthesis. It analyzes governance, procurement, officials and private counterparties across a broad record. The Commission could recommend further investigation and accountability, but its conclusions should retain their institutional character. The article uses them to test public-buyer controls and the environment in which consultants operated, not to manufacture a conviction that a court did not enter.

A separate archived Commission record addressing the McKinsey, Trillian and Regiments contracts illustrates the need to separate procurement illegality, corruption findings, payment approval and recommendations for law-enforcement work. The same engagement can generate administrative, civil, disciplinary and criminal questions. A control inventory should assign each question to an owner and evidence standard rather than assume that one investigation resolves them all.

The company's own account changed as evidence developed

McKinsey's South Africa statements archive gathers its 2017-2024 responses, repayments, Commission submissions and later resolution statement. This is valuable first-party evidence because it shows the firm's public position across time. It is not an independent adjudication. Earlier statements described what internal reviews had or had not found with the information then available; the 2024 DPA later established admissions that must control where the records differ.

The firm's 2020 commitment to repay Transnet and SAA fees says new material presented by the Judicial Commission created further doubt about partner conduct and led to a decision to return fees from projects involving Regiments. It also framed repayment as voluntary and stated that the Commission had not implicated current personnel in corruption at that time. Both parts belong in the record. Repayment acknowledges unacceptable risk or benefit; it does not itself determine the criminal intent of every person.

McKinsey's chief risk officer provided a detailed written submission to the Judicial Commission about engagements, reviews, partner arrangements and proposed repayments. The submission is a party's evidence, subject to testing against Commission, client and enforcement records. Its governance value is in exposing the firm's claimed control design: who reviewed partners, what information was available, how fees were structured and where later evidence changed the firm's assessment.

The root problem preceded any invoice

It is tempting to frame a corruption case as a payment-control failure. That is too late. By the time an invoice reaches accounts payable, the public-client opportunity, procurement route, partner and economic split may already be locked. Finance can verify arithmetic and coding while missing that the commercial design itself is compromised. The first control point must be the decision to pursue the engagement and the conditions under which the firm will accept it.

Every state-enterprise opportunity should begin with a public-need record. It should identify the buyer, statutory role, approved budget, procurement method, tender or sole-source authority, responsible officials, intended outcome, timetable and conflict register. The consulting firm should record how it learned of the opportunity and whether any information was confidential or available only through a person connected to the decision. If the source cannot be documented, the opportunity should not progress.

The public-need record also protects legitimate consulting. State enterprises sometimes require specialized support under urgent operational conditions. A lawful exception to competition may exist. Accountability does not presume that every sole-source engagement is corrupt. It requires contemporaneous evidence of the exception's legal basis, why alternatives were unavailable, how price and scope were benchmarked, who approved it and when competitive procurement will resume. A vague urgency claim is not evidence.

Consulting firms often sell through relationships rather than products. A senior partner may understand the client's operational problem long before a formal request. That knowledge can improve a tender, but it also creates asymmetric access. The control must distinguish ordinary market development from confidential procurement intelligence. Staff should classify documents by origin and restriction, and proposal teams should prove that criteria, competitor information and award expectations came from authorized sources.

Third-party partner diligence must test function, not form

A local partner cannot be approved merely because incorporation, tax and empowerment documents exist. The firm must know beneficial owners, controllers, politically exposed connections, public-client relationships, litigation and sanctions history, personnel, location, financial capacity and the expertise needed for the proposed scope. Each claim should have a source and reviewer. Self-certification is an input, not the decision.

Capability testing should be engagement-specific. A firm qualified for community engagement may not be qualified for railway procurement analytics, generation turnaround or financial modeling. The diligence record should map named people, hours, deliverables and tools to the statement of work. If the partner receives a large fee share while its expected contribution declines, the exception should reopen automatically and payments should stop until independently justified.

Ownership checks must extend beyond the registered shareholder. The reviewer should identify trusts, nominees, financing, related entities and anyone entitled to a success payment. Relationships with public officials or intermediaries should be documented and evaluated under a consistent conflict standard. A public official's recommendation is not by itself proof of misconduct, but it is a reason to remove selection from the commercial partner and require enhanced independent review.

The diligence function needs its own access to external data and enough time to challenge. If the commercial team can describe a partner as mandatory and set a deadline that forces approval, the gate is nominal. Procurement calendars should reserve review time, and late partner additions should trigger delay or a documented decision by an authority outside the revenue chain.

Diligence expires when facts change. New owners, changed fee splits, public-client personnel moves, adverse media, an investigation or unusual payment request should reopen approval. The partner master should block new engagements and invoices until the refresh is complete. A yearly checkbox cannot govern a relationship whose risk changed last week.

Fee sharing needs a contribution ledger

A fee percentage should be explainable in units of work and risk. The engagement record should identify who originated the work, who will deliver each module, what seniority and hours are expected, what intellectual property is used, what costs are borne and what acceptance evidence will exist. A percentage unsupported by contribution is an exception even if it is customary in a market.

The contribution ledger should be updated as work changes. If a partner's personnel do not attend, deliverables migrate to the main firm or scope shrinks, the fee must be recalculated before billing. That creates a direct control over the risk described in the US statement of facts, where a partner's share could increase while its contribution diminished. The system should not allow an engagement partner to approve both the revised share and the payment.

Public-client invoices add another layer. The consulting firm should reconcile its invoice to accepted deliverables and then reconcile any partner payment to the partner's verified contribution. The public customer should not pay for undisclosed subcontracting or a fee split that its procurement decision did not authorize. Contract changes need the same competition, conflict and approval checks as the original award.

Payment data should identify the legal beneficiary, bank country, account owner, invoice, tax treatment and service period. No employee should be able to substitute a beneficiary after approval. Split invoices, round-dollar amounts, accelerated payments and requests routed through a third party should create alerts reviewed by compliance, not only finance.

Senior-partner authority needs structural challenge

Professional firms often depend on partner judgment. Partners own relationships, assemble teams, price work, evaluate peers and influence promotion. That design can make a high-producing partner unusually difficult to challenge. The answer is not generic training; it is separation of authority around high-risk public work.

The client-service partner should not select the local partner, approve diligence, clear conflicts, validate confidential-information provenance and authorize payment. Those decisions should be divided among professionals who do not share the engagement's revenue credit. High-risk approvals should be visible to a regional or global committee with access to the underlying documents, not a presentation prepared by the deal team.

Revenue credit is itself a control input. The firm should disclose how an engagement affects partner evaluation and compensation to the independent reviewer. A reviewer who does not know that a deadline or fee affects promotion cannot calibrate pressure. Compensation systems should reduce or hold back credit where third-party evidence remains incomplete, even if the client has paid.

Challenge must be documented. The file should show questions asked, evidence requested, exceptions, resolution and dissent. An approval memo that contains only a conclusion cannot prove review. If a senior partner overrides an objection, the system should identify the authority, rationale and subsequent monitoring; some categories, such as undisclosed beneficial ownership or unexplained public-official influence, should be non-overridable.

Confidential information requires provenance controls

Consulting teams receive sensitive client data legitimately. The problem is not confidentiality alone but information that shapes a public award and arrives outside an authorized channel. Each procurement-sensitive document should carry an origin, owner, access basis, restriction and approved uses. Teams should not be able to move material from personal email or messaging into a proposal without review.

Proposal workspaces can enforce that control. Drafts should link claims about competitors, budgets, scoring criteria and decision timing to approved sources. Unsupported fields should remain blocked or visibly flagged. The point is not to eliminate professional judgment; it is to make the provenance of decision-changing information reviewable.

Communications monitoring must be risk-based and lawful. High-risk public-sector engagements may justify preservation of approved business channels, alerts for transfer to personal accounts and targeted review when an investigation or credible concern arises. Monitoring should respect employment and privacy law, with published rules, limited access and audit logs. Secret surveillance is not a substitute for a clear records policy.

When a partner or employee deletes relevant material after learning of an inquiry, the response should be automatic: preserve devices and accounts, suspend alteration privileges, notify independent counsel and the appropriate governance body, document the incident and assess disclosure duties. The DOJ credited McKinsey for reporting deletion efforts and providing evidence. A durable system should not depend on improvisation after deletion is discovered.

Public-client controls remain part of the system

Supplier accountability does not erase buyer responsibility. State enterprises control procurement rules, access to confidential information, evaluation panels, contract authority, acceptance and payment. A public buyer should maintain an immutable tender file, segregate specification drafting from award, record contacts with bidders and disclose conflicts. Consultants can strengthen those safeguards by refusing work when the buyer cannot demonstrate them.

Jointly drafted scopes create special risk. Technical dialogue may be legitimate before procurement, but a potential bidder should not write criteria that unfairly exclude competitors or predetermine its own selection. Any market engagement should be open, recorded and governed by the buyer. If a consultant helped define the need, the conflict should be evaluated before it later bids for delivery.

Public buyers also need visibility into subcontractors and fee sharing. Approval of a prime contractor does not authorize undisclosed partners. The contract should require beneficial ownership, work allocation, price and changes to be disclosed, and should permit audit of service evidence and payments. Confidential commercial information can be protected while still allowing the state to test value and integrity.

Acceptance should be independent of the sponsor who selected the adviser. Deliverables need defined outcomes, evidence and responsible users. A slide deck delivered is not the same as operational benefit. Payment should follow documented acceptance, and success fees should use metrics the adviser cannot control or retrospectively redefine.

Escalation must protect the person who stops revenue

Employees may see irregular partner behavior, unusual information or unsupported fee splits before control functions do. The firm needs confidential reporting channels, anti-retaliation protection and escalation outside the local partnership. Reports involving a senior partner or public official should bypass anyone whose compensation or relationship creates a conflict.

Case triage should preserve both urgency and fairness. A credible concern can justify pausing an opportunity without declaring anyone guilty. The firm should record what was alleged, which records were secured, who is recused, what interim restrictions apply and when the matter will be reviewed. A pause is a control, not a verdict.

Patterns matter. Separate complaints about one partner, public customer or local intermediary may appear minor. A global case system should connect them through entity, beneficial owner, bank account, device, official and engagement. Access should be tightly controlled, but fragmentation across offices should not prevent a pattern from reaching independent investigators.

Boards need information about suppressed as well as substantiated concerns. Metrics should include high-risk opportunities stopped, partners rejected, late diligence, unexplained fee changes, confidential-information exceptions, personal-channel use, overdue investigations, retaliation allegations and repeat control failures. A low case count can mean effective prevention or weak detection; the board needs enough context to tell the difference.

Remediation must be tested as an operating system

The DPA describes enhancements to diligence, public-sector review, sole-source approval, training, discipline and reporting. Each commitment can be converted into a test population. For example, reviewers can sample every public-sector engagement using a local partner, not just files selected by management, and verify that diligence predated work, beneficial owners were independently checked, contributions matched fees and sole-source authority was documented.

Testing should follow exceptions. If diligence was completed late, the reviewer should determine whether work or information access began before approval and whether payment was blocked. If the answer is no, the control may exist on paper without constraining behavior. Repeated late completion should affect partner compensation and authority.

The firm should test for hidden populations: engagements coded as private even though a state-owned enterprise is the ultimate beneficiary, local firms treated as ordinary vendors rather than business-development partners, or fee shares embedded in prime pricing. Data analytics can identify government domains, public ownership, round percentages, high margins, repeated co-bidders and payments in jurisdictions unrelated to service.

Independent assurance should have access to original records and the ability to interview staff without management selection. Reports should describe population, sample, exceptions, root causes, owners and closure evidence. A statement that controls were enhanced does not reveal whether they operated when revenue pressure was highest.

Probation and reporting obligations have an end date; governance should not. Before obligations expire, the board should commission a lookback across the full term and disclose internally whether exceptions fell, repeat entities disappeared, investigations were timely and public-sector work complied with the new gate. Any unresolved high-risk exception should remain visible after formal resolution ends.

Measure remedy without merging unlike amounts

Corporate penalties, credited foreign payments, fee repayments, interest, civil recovery and amounts sought from other entities are not interchangeable. A remedy ledger should record payer, recipient, currency, gross amount, credit, interest, legal basis, covered conduct, payment date and collection status. It should also flag when one payment satisfies or offsets another obligation.

Repayment has at least three accountability functions. It can remove benefit, restore a public institution and signal that the firm will not retain revenue from tainted work. It cannot establish every disputed fact or compensate every downstream effect. Public-enterprise losses may include procurement distortion, delayed projects, staff time and weakened competition that exceed a consulting fee.

Discipline is also bounded evidence. Removing a partner or reducing compensation can show enforcement of professional standards. Privacy and employment law may limit disclosure, but the board should still receive anonymized information about level, rationale, consistency and whether supervisors were assessed. Discipline focused only on the most visible actor may leave incentive and review failures intact.

Public remediation should avoid triumphal closure. A company can acknowledge reforms and continued investment while stating which controls remain under testing. That is more credible than treating a settlement as proof that no similar risk remains. The firm should publish enough about the control architecture and independent assurance to let clients ask informed questions without revealing personal or investigative data.

The impact reaches beyond one consultancy

State enterprises manage electricity, ports, rail and other essential infrastructure. Procurement failures divert scarce funds, weaken competition and occupy managers who should be improving service. Even when consulting work has operational value, a tainted award can make legitimate recommendations harder to trust and can delay implementation while contracts, payments and decisions are reviewed.

Legitimate local consulting firms also bear harm. Empowerment and supplier-development policies are intended to widen participation and capability. When a partner arrangement is used as a channel for improper influence, it casts suspicion on qualified firms and can provoke overcorrection that excludes smaller suppliers. The answer is not to abandon local partnership but to verify ownership, contribution and price consistently.

Employees face moral and professional consequences. Many consultants may have performed real work without knowledge of misconduct. A careful account protects them from collective accusation while asking whether systems gave them the information and channels needed to recognize risk. Individual fairness and institutional accountability are compatible when records remain actor-specific.

The consulting profession depends on access to confidential information and trust in advice. Firms help governments design procurement, strategy and controls; they may later seek implementation work. That position creates structural conflicts that no client-service promise can resolve alone. Transparent engagement rules and independent review protect both the public and the legitimacy of consulting.

Consulting evidence is unusually difficult to test

Physical procurement offers visible units: a specified component is delivered, inspected and counted. Consulting value is more difficult to isolate. A team may diagnose a problem, design a process, train staff and support implementation while the client's own employees make the final decision. That does not make advisory work intangible or valueless, but it increases the importance of a contemporaneous work record. Without it, a later reviewer can see a fee and a presentation but cannot reliably determine who contributed, what changed or whether the scope justified the price.

Each engagement should therefore have a service-evidence matrix. The matrix links contractual objectives to named deliverables, responsible teams, underlying analyses, client reviewers, acceptance dates and expected operational outcomes. Drafts and working papers can remain confidential, but their existence, ownership and review history should be provable. The matrix should also distinguish advice from authority: the consultant may recommend a procurement or operating choice, while the public entity remains responsible for approving it.

Outcome measurement needs the same discipline. Savings, productivity or performance claims can be distorted by baseline choice, external events or changes the client made independently. The engagement should freeze the baseline, calculation method, data owner and counterfactual before a success fee or public benefit is asserted. An independent client function should validate the result, and the adviser should disclose uncertainty rather than present a precise number unsupported by the evidence.

That discipline is particularly important when a local partner's fee is justified by access, relationships or market knowledge. Relationship-building may be legitimate work, but it must be described in activities that a reviewer can test: stakeholder mapping, lawful consultations, technical adaptation, language work, local staffing or implementation support. A statement that the partner “opened doors” is a warning, not a deliverable. It may conceal improper influence, or it may simply be an imprecise description of legitimate market expertise; either way it requires clarification before approval.

The firm should also distinguish a subcontractor from a business-development intermediary. A subcontractor performs part of the client work and should be paid against accepted delivery. An intermediary helps obtain business and creates a different anti-corruption risk. An entity performing both roles should not be classified according to the lower-risk label. Its fee should be divided into documented components, with any contingent business-development element either prohibited for high-risk public work or subjected to enhanced review.

Client confidentiality cannot prevent oversight. Contracts can authorize independent auditors to inspect records under protective terms, limit use and redact personal information. The firm should be able to show its board and monitor that work occurred without exposing sensitive client strategy publicly. If confidentiality is invoked to withhold all contribution evidence from compliance, the engagement is not governable.

Data retention should reflect the long life of public accountability. Investigations may begin years after an engagement, while ordinary collaboration platforms delete messages quickly. The retention schedule should preserve approvals, partner diligence, procurement-sensitive communications, working papers supporting material claims, acceptance and payment for the period required by law and risk. Legal holds must suspend deletion across email, messaging, devices and cloud workspaces. Personal channels should be prohibited for engagement decisions because the firm cannot reliably preserve or audit them.

Quality review and integrity review should remain separate. A technically strong analysis does not cure a compromised award, and a procedurally clean engagement can still deliver poor advice. Quality teams should test method, data and conclusions. Compliance teams should test procurement, conflicts, partners, information provenance and payments. The board needs both results and should not allow delivery quality to offset an integrity exception in a composite score.

Finally, professional firms should examine their role after advice is delivered. A recommendation can shape a public tender that the same firm or partner later bids to implement. A post-engagement conflict check should identify follow-on opportunities, cooling-off needs and whether earlier confidential access creates an unfair advantage. Where the conflict cannot be managed, the firm should decline the later work. Forgone revenue is evidence that the gate has authority.

A durable control chain

The complete control chain begins with public need and ends with verified closure. The firm records the state entity, need, procurement route and information source. Independent compliance classifies risk and checks conflicts. A separate team verifies every partner's owners, capability, public connections and expected contribution. A public-sector committee approves the opportunity, sole-source basis and fee allocation before work or information access.

During delivery, approved channels preserve communications and proposal provenance. The work plan assigns deliverables, hours and acceptance to each firm. Changes to scope, partner, fee or public officials reopen review. Client acceptance and internal quality review precede invoices. Partner payments follow verified contributions and immutable beneficiary data.

After payment, analytics compare planned and actual work, margins, fee splits, public-client relationships and control exceptions. Complaints and adverse information can pause future work. Investigations preserve evidence, protect reporters and separate corporate, individual and client findings. Remediation owners close actions only with test results, not promises.

The board receives both outcome and friction metrics: opportunities declined, partners rejected, late diligence, fee changes, confidential-information exceptions, personal-channel alerts, investigations, discipline, repayments and repeat entities. Independent assurance samples high-pressure and high-value engagements and reports unresolved exceptions through the end of any DPA and beyond.

Questions that should remain open

The public record does not reveal every internal decision, every person's knowledge or the operating effectiveness of every later McKinsey control. It cannot prove that all consulting work at the two enterprises lacked value, nor that every local partner or official participated in misconduct. It also cannot convert unresolved South African cases into convictions. Those are uncertainty boundaries, not excuses to ignore the admissions and institutional findings that do exist.

Clients and regulators should ask for evidence rather than assurances. How many public-sector opportunities began before diligence? How many local partners changed ownership or fee share? Which sole-source decisions were rejected? Did anyone access procurement-sensitive information from a personal account? How quickly were complaints involving senior partners escalated? Were payments blocked when contribution evidence was missing? What independent testing found repeat exceptions?

They should also ask whether the same controls cover adjacent risk. A private client controlled by a state, a joint venture funded by a public institution or an adviser working through a prime contractor can evade a narrow government-client flag. Risk classification should follow beneficial ownership and decision authority, not the label selected in a sales system.

Finally, they should ask who can stop the work. A committee that advises but cannot delay an engagement is not a gate. A compliance officer whose budget and promotion depend on the local partnership is not independent. A board that learns only after revenue is recognized cannot provide preventive oversight. Stop authority must be explicit, protected and observable in the record.

The same questions should be asked after a control appears to pass. Did the reviewer inspect original ownership evidence or rely on a summary? Did client acceptance identify the people who used the work? Did payment data match the approved legal entity and country? Were exceptions closed by someone outside the engagement? A green status without those answers may describe administrative completion rather than effective prevention. Accountability requires enough retained evidence for another qualified reviewer to reach the same conclusion without depending on the original sponsor's memory or reputation.

Conclusion

McKinsey South Africa became an accountability test because the admitted scheme joined professional authority, public procurement, confidential information and third-party fee sharing before ordinary billing controls could intervene. The 2024 DPA gives the corporate US record its clearest legal boundary; the former partner's plea, South African investigations and proceedings, public-enterprise disclosures, parliamentary and Commission findings, repayments and company statements add distinct layers. None should be inflated or erased.

The durable lesson is not that public consulting or local partnership is inherently suspect. It is that high-risk engagements need an evidence chain independent of the people rewarded for winning them. Public need, procurement route, information provenance, partner ownership, contribution, fee, approval, invoice, payment, escalation and remedy must be replayable. When that chain is complete, legitimate advisers and local firms can compete without relying on influence. When it is not, a prestigious name, valuable deliverable or later repayment cannot substitute for accountable control.