Summary
The firm disposition is an admitted administrative settlement. In June 2019 KPMG admitted the facts in an SEC order, acknowledged the stated PCAOB-rule violation, accepted a censure and cease-and-desist order, paid a $50 million penalty and undertook an independently reviewed ethics-and-integrity programme. That is not a corporate criminal plea.
Two courses of conduct must be examined together without being collapsed. One concerned confidential PCAOB inspection-planning information and work on already completed audits. The other concerned answer sharing and manipulation of passing scores on internal training examinations. Their methods differed, but both tested whether performance pressure could displace professional integrity.
Individual records changed over time. SEC settled orders have their own findings and sanctions. The criminal case produced pleas, trial verdicts and sentences, but later court orders vacated pleas and judgments and dismissed charges after intervening law concerning intangible regulatory information. Historical verdicts must not be stated as present convictions.
Remediation must be evidenced at the transaction level. Hiring screens, information-access logs, workpaper histories, exam-item controls, preservation holds, investigation protocols, discipline and compensation need independent testing. A report that a policy exists is not proof that it works when inspection or career pressure is high.
Audit committees have a legitimate assurance interest. They should not seek regulator-confidential selection information. They should ask whether the firm can demonstrate clean separation from it, immutable audit completion records, meaningful learning assessments and protected escalation when senior quality leaders are implicated.
The legal map begins with the firm order
The SEC's firm-level announcement says KPMG paid a $50 million penalty to settle charges involving illicit use of PCAOB data and cheating on internal training examinations. It also states an unusual procedural feature: KPMG admitted the facts in the Commission's order and acknowledged that the conduct violated a PCAOB integrity rule and supplied a basis for remedies under Exchange Act Section 4C and Commission Rule 102(e). Those admissions belong to KPMG LLP in that administrative proceeding.
Precision matters in both directions. Calling the disposition merely a no-admit settlement would erase the admissions that the SEC expressly recorded. Calling it a guilty plea would invent a criminal procedure that the firm did not enter. The accurate description identifies the respondent, administrative instrument, admissions, penalty and undertakings. It also distinguishes those firm facts from allegations, settlements or changing outcomes in proceedings against individuals.
The order joined two bodies of conduct because both bore on the integrity expected of public-company auditors. Yet joining them did not make them factually identical. Inspection information passed through people moving between a regulator and the firm and was used in relation to selected audits. Exam misconduct involved internal assessment materials, peer sharing and a weakness in the testing platform. A responsible analysis tracks separate actors, systems, dates and evidence while asking the common governance question: what happened when incentives made an unearned result easier than the underlying work?
That legal map is the first control lesson. Internal reporting should label every fact by its source and procedural status: firm admission, Commission finding, individual allegation, individual settlement, historical verdict, vacated judgment, company representation or independent review. Without those labels, a board can receive a rhetorically forceful but legally unreliable account. Accountability depends on preserving distinctions, not on making the narrative sound more severe.
The order defines two integrity failures, not a general verdict on every audit
The SEC cease-and-desist order is the controlling firm instrument. It describes confidential inspection selections, criteria and focus areas obtained between 2015 and 2017; actions directed at certain audits after reports had been issued; answer sharing on internal courses; and manipulation of an exam server that permitted users to choose a lower passing threshold. Its findings were made pursuant to KPMG's offer and are expressly not binding on any other person or entity.
The same boundary prevents overstatement about audited companies. The order did not declare that every KPMG audit was deficient, that every post-issuance file change was improper, or that every professional cheated. It identified specified conduct and control failures. Engagement-specific audit quality remains a separate evidentiary question. A firm can suffer a system failure without every engagement failing, just as a clean inspection sample cannot certify every engagement.
The order is especially important because the national group responsible for audit quality and professional practice featured in the inspection-information events. A conventional three-lines diagram is weak assurance if senior control personnel can influence the same metrics by which their function is judged. Control ownership therefore needs a fourth element: independent custody of the evidence used to evaluate the control owner. Inspection correspondence, selection data, audit-file access and quality metrics should not be administratively alterable by leaders whose compensation or status depends on the result.
The exam record makes the same point in a different system. Training completion had consequences, including restrictions on audit work and potential compensation effects. A platform allowed passing thresholds to be manipulated through a hyperlink parameter, while answers circulated through email, printouts and colleagues. The lesson is not that automated testing is inherently weak. It is that a control becomes performative when identity, item secrecy, scoring logic, attempt history and exception approval are not protected as evidence.
Inspection confidentiality protects the measurement itself
The SEC's 2018 announcement of charges against six accountants explains why advance selection information was valuable. The PCAOB uses inspections to assess whether registered firms complied with relevant laws, rules and standards in selected audits. If a firm knows which completed files will be inspected and can focus undisclosed re-review on them, the sample no longer measures ordinary performance under the same conditions.
Confidentiality is therefore not a ceremonial restriction protecting a regulator's preference for secrecy. It preserves the validity of an oversight method. The control objective is comparable to protecting test items before an examination or preserving randomization in a clinical trial. Once the measured party learns the sample in advance, a better score may reflect preparation for the measurement rather than improvement in the underlying population.
That insight changes hiring governance. Recruiting experienced regulators can improve a firm's knowledge of standards, inspection methods and public expectations. The risk is not the hire itself. It arises when the firm fails to identify nonpublic information the recruit may possess, limit access while obligations are assessed, prohibit solicitation, monitor unusual disclosures and give the recruit a safe route to reject requests from powerful new colleagues. A generic confidentiality clause is too remote from the actual pressure points.
A defensible hiring record would show the candidate's former responsibilities; cooling-off and conflict analysis; written instructions concerning former-employer information; restricted systems or assignments; training for the hiring manager and receiving team; certifications at defined intervals; and investigation triggers if inspection-specific material appears. It would also show that commercial or quality leaders cannot waive those safeguards alone. The objective is to gain legitimate expertise without importing another institution's protected information.
The original individual orders began as allegations, except where settled
The January 2018 order concerning Cynthia Holder and other respondents instituted contested proceedings and alleged a chain through former PCAOB personnel and KPMG national-office leaders. At that stage, allegations against nonsettling respondents were not findings. Brian Sweet, by contrast, resolved his own administrative matter in a separate instrument.
That distinction is central to evidence hygiene. An order instituting proceedings can describe the Commission staff's case in detail, but it does not transform every allegation into an adjudicated fact. Later settlements may establish findings for a consenting respondent within that proceeding. Criminal pleas or verdicts may supply different admissions or determinations. Each update must be attached to the correct person; it cannot be back-propagated to everyone named in the original narrative.
For an audit firm, the governance implication is that an internal investigation should maintain a respondent-and-issue matrix. Rows identify people and legal entities; columns identify alleged acts, source material, interview status, employment action, regulator referral, litigation status and final disposition. This avoids the two common errors of treating preliminary suspicion as settled fact and, conversely, treating the later failure of a criminal theory as proof that workplace or professional standards were never breached.
Employment decisions also need their own documented standard. A firm may act on policy violations or loss of trust using an employment-law process different from the government's criminal burden. But it should record what evidence it relied upon, allow fair response, ensure comparable discipline and revisit public descriptions if later proceedings materially change. Fairness is not leniency. It is control over the accuracy, scope and continued currency of consequential judgments.
Sweet's settlement shows why former-regulator information needs active controls
The SEC's settled order for Brian Sweet contains findings specific to him, including that before leaving the PCAOB he copied confidential information and, after joining KPMG, disclosed inspection-related information. He consented without admitting or denying the findings, except as to jurisdiction, to a cease-and-desist order and denial of the privilege of appearing or practicing before the Commission as an accountant.
Sweet's procedural posture differs from KPMG's later admission of the firm-order facts. It also illustrates why a policy that relies solely on the departing regulator's self-restraint is incomplete. The receiving firm controls recruitment, onboarding, device use, team placement, requests from supervisors and access to engagement files. A control system should treat an unexplained piece of selection-specific knowledge as an exception requiring immediate containment, not as useful insight to be circulated until someone proves its origin.
Practical safeguards can be tested. Investigators can sample hires from regulatory and standard-setting bodies, review onboarding attestations, compare prior responsibilities with assigned clients, inspect access logs around inspection planning, and search communications for selection lists or nonpublic focus areas. Testing should be conducted by people independent of the practice leaders who sponsored the hires. Exceptions should go directly to legal, ethics and the board or an appropriately independent committee.
The firm should also separate legitimate public knowledge from protected detail. Public inspection procedures, published reports and professional experience can inform quality programmes. Specific future selections, nonpublic focus areas and confidential regulator deliberations cannot. Training should use examples that require employees to classify information and choose escalation routes. A broad instruction to “respect confidentiality” does not show whether people recognize the boundary when a disclosure arrives as career advice or an informal warning.
Post-issuance work should be visible, attributable and reviewable
The confidential-selection record matters because personnel used advance knowledge in relation to already completed audits. Audit documentation rules can permit certain additions or changes after the report date under defined circumstances, but the history must make clear what changed, when, why and by whom. Post-issuance work cannot silently become part of the contemporaneous basis for an opinion that was already released.
An effective repository therefore needs immutable event logging rather than only a final PDF. It should record original completion, subsequent access, changed entities, reason codes, preparer, reviewer, supporting evidence and whether an inspection or inquiry was known. Privileged investigations can have controlled visibility without erasing the audit trail. Administrative access should be divided so that a quality leader cannot both authorize and obscure an exceptional change.
Sampling should begin with pressure, not random convenience. Reviewers should select engagements accessed after report issuance, especially around inspection notifications, regulator requests, litigation holds or senior-quality interventions. They should reproduce every change and determine whether contemporaneous documentation supported it. They should also examine whether work was newly performed, merely clarified or inappropriately presented as if it had existed earlier.
Audit committees have a narrow but important role. They should not demand confidential regulator information or interfere with an inspection. They can ask the external auditor how post-issuance changes are governed, what exceptions are reported internally, whether logs are independently tested and whether any matter relevant to their engagement required disclosure. The answer should describe operating evidence, not expose another issuer's confidential file.
Exam security is an audit-quality control, not an HR convenience
The SEC's 2020 release on three former audit partners shows that answer sharing continued to produce individual actions after the 2019 firm settlement. The release describes settled findings involving Timothy Daly, Michael Bellach and John Donovan and also discusses deletion of messages or inaccurate responses during KPMG's investigation. All three settled without admitting or denying the findings, except jurisdiction, and received different suspension periods.
Mandatory learning is often treated as evidence that a control environment has been communicated. That inference is valid only if completion demonstrates individual engagement with the material. When answers are shared or passing scores can be manipulated, a learning dashboard measures access to the workaround as much as knowledge. The risk is acute where the same completion record determines eligibility to perform audit work.
The design response includes an item bank with controlled access; randomized questions; server-side scoring that cannot be changed through user parameters; cryptographically logged attempts; limits on screenshots and printing where lawful; anomaly detection for identical answer patterns and implausible completion times; independent exception approval; and a route for challenging a flawed question without sharing it. Remote proctoring can create privacy and bias risks, so it should not be treated as the only answer.
Most importantly, the firm should separate learning from punishment sufficiently to encourage truthful signals. If a failed attempt instantly threatens compensation or status, employees have a stronger incentive to conceal weakness. A mature programme provides remediation and retesting while reserving discipline for dishonesty. The measure of quality is not a perfect first-attempt pass rate. It is whether professionals acquire and apply the required knowledge and whether the system detects manipulation.
Daly's order connects exam misconduct with preservation and candour
The Daly order describes a request for photographs of exam questions and answers, deletion after a firm preservation notice, and an inaccurate questionnaire response that he later corrected. It states that he settled without admitting or denying the findings except jurisdiction and permitted an application for reinstatement after three years subject to specified conditions.
This record contains three control stages: prevention, preservation and investigation response. Weakness at the first stage allowed material to be shared. Once the investigation began, the preservation notice created a clear duty. The questionnaire then sought a truthful account. Testing only whether the exam platform was redesigned would miss the later conduct that determines whether an organisation can reconstruct what happened.
Preservation should therefore be engineered, not merely announced. Legal and information-security teams need authority to suspend routine deletion, collect relevant business messages and retain system logs promptly. The hold population should reflect roles, teams and communication patterns rather than only names known on day one. Custodians should acknowledge the hold, disclose relevant channels and receive a simple route to ask questions without editing or deleting material.
Investigators also need a correction protocol. A person who realizes an answer was incomplete should be able to correct it promptly, with the timing and reason recorded. That does not erase the initial response, but it produces a more accurate record and may be relevant to assessing intent and cooperation. The system's objective is reliable fact finding, not trapping people into defending a first error.
Bellach's order shows how hierarchy can distort mutual accountability
The Bellach order addresses his sending exam images to a lead engagement partner and later deleting messages after a preservation notice. It describes the professional relationship and the prospect of succession to a lead role, facts relevant to understanding pressure, while making findings pursuant to Bellach's own offer and not binding other persons.
Integrity controls often assume that partners will model behaviour and that junior staff will resist misconduct. The harder scenario is a request embedded in mentorship, engagement succession or performance evaluation. A recipient may understand both that the request is wrong and that refusal could affect a career. Training that says “speak up” without changing the power structure leaves that conflict unresolved.
Controls should make certain requests reportable by design. An ethics channel should allow immediate confidential consultation; retaliation monitoring should compare staffing, ratings and promotion outcomes after reports; and a senior request for exam content should trigger review without requiring the recipient to prove a broader scheme. Supervisors should be evaluated on whether their teams raise concerns, not rewarded for an absence of reports.
The same logic applies to audit judgments. A staff member who disputes an aggressive conclusion needs an escalation path outside the engagement hierarchy, a preserved record of the issue and protection from subtle career consequences. Quality culture is measurable in whether dissent survives. Anonymous surveys are useful, but case-level evidence—response time, disposition, staffing changes and retaliation tests—shows whether the mechanism operates when power is unequal.
Donovan's order demonstrates that sharing can become a team norm
The Donovan order concerns receiving answers from subordinates, distributing materials within a team and an inaccurate response to investigators. The conduct described is not merely a bilateral exchange. It illustrates how a workaround can be normalized through a workgroup until individual completion statistics appear legitimate.
Team-level normalization is difficult to detect if monitoring looks only for one prolific sender. Analytics should examine clusters: unusually similar response sequences, concentrated completion windows, repeated score patterns across reporting lines and transmissions close to exam deadlines. Those indicators are not proof of misconduct. They are risk signals for fair investigation, with controls against false positives and inappropriate surveillance.
Management information should not encourage gaming. A dashboard that ranks leaders by timely completion and pass rate without showing retests, anomaly flags, question quality or remediation creates a narrow target. Balanced measures might include substantive assessment results, observed application in audit work, identified learning gaps, timely correction and the quality of supervisory response. A lower pass rate can be a healthier signal if the exam is meaningful and the programme repairs gaps.
Discipline should be consistent across rank. A firm should map conduct factors—soliciting, sending, receiving, system manipulation, preservation breach, false statement, self-report, cooperation and prior history—to a documented framework. Individual circumstances still matter, but unexplained differences between partners and staff undermine the integrity message. The board should receive anonymized consistency analysis and review outliers.
Later SEC orders preserve professional findings even as criminal law changed
The SEC order concerning Thomas Whittle and the separate order concerning David Britt resolved administrative proceedings with findings and professional sanctions specific to those respondents. Their consent orders stand on the Commission's professional-practice authority and the records described in each instrument.
Those administrative dispositions should not be merged with the criminal case. Different proceedings can examine overlapping conduct under different legal elements, burdens and remedies. Later change in a wire-fraud property theory does not automatically rewrite a professional-integrity order. Conversely, an SEC order cannot be cited as though it were a criminal conviction.
This is why an accountability register needs more than a single “case status” field. It should track forum, respondent, allegation or finding, consent language, sanction, review rights, reinstatement possibility and subsequent change. The same person may have a vacated criminal judgment and a separate administrative order. A current report should display both accurately rather than choose the one that supports a preferred story.
Boards should insist on that discipline in internal legal reporting. Status updates need date stamps, source documents and change logs. Public statements should be reviewed when a material disposition changes. Fairness to individuals and credibility with regulators both depend on not preserving an obsolete label after the legal record moves.
PCAOB's supervisory action widens the lens to incentives and oversight
The PCAOB's 2022 settled order concerning Scott Marcello found that he failed reasonably to supervise with a view to preventing violations by associated persons. The order discusses inspection-result pressure, information that reached him and the steps the Board concluded he failed to take. Marcello consented without admitting or denying the findings, except as to the Board's jurisdiction.
Supervision is not satisfied by assigning operational ownership to subordinates. When a leader learns that a team may possess confidential selection information, the supervisory evidence should show immediate containment, legal escalation, protection of the regulator, suspension of affected file access and a documented investigation. Waiting for certainty can allow the suspected advantage to be used and the measurement to be compromised.
Incentives require equivalent scrutiny. Inspection results are useful indicators, but they are samples shaped by selection and inspection method. If promotion, prestige or compensation depends heavily on reducing comments, the metric can displace the objective of sound audits across the portfolio. Leaders need balanced measures that include root-cause repair, recurring-deficiency reduction, consultation quality, staff capacity, speaking-up evidence and results from independently selected internal reviews.
The board should also ask who supervises the national quality function. Independence may require a committee with members outside the audit practice, direct access to internal audit and ethics, and authority over the quality leader's evaluation. The key test is whether a credible allegation against senior quality personnel can be handled without seeking permission from the implicated chain of command.
The PCAOB also had to protect its own side of the boundary
The PCAOB chairman's statement on the 2018 DOJ and SEC actions says the Board reviewed and reinforced information-technology and security controls and compliance and ethics protocols after learning of the alleged misconduct. That is an important institutional boundary: responsibility for protecting confidential inspection information did not rest only with the receiving firm.
Oversight data can cross systems, devices and employment relationships. A regulator needs least-privilege access, download controls, monitoring for unusual queries, restrictions around departures, prompt revocation and post-employment confidentiality enforcement. It also needs cultural controls so that employees can report improper requests from prospective employers or former colleagues without jeopardizing their careers.
The firm and regulator should not respond by preventing all movement between them. Expertise transfer can improve both regulation and practice. The objective is governed mobility: disclosed negotiations, recusal where necessary, review of accessible information, exit certification, receiving-employer instruction and auditable restrictions. Any communication about nonpublic selections should have a mandatory escalation path on both sides.
Independent assurance can test the interface without sharing protected content. Reviewers can examine whether leaver accounts were disabled, whether bulk downloads were flagged, whether receiving teams completed attestations and whether exceptions were investigated. The evidence should demonstrate that controls detect behaviour, not merely that policies prohibit it.
The criminal history must now be stated as history, not current conviction
The DOJ's 2018 charging announcement reported an indictment of former KPMG and PCAOB personnel and a separate guilty plea by Brian Sweet. At filing, the indictment was an allegation and the charged defendants retained the presumption of innocence. Sweet's plea was his own admission and did not prove every allegation against others.
A jury later returned verdicts against David Middendorf and Jeffrey Wada, described in the DOJ's March 2019 trial announcement, and Middendorf was sentenced in September 2019, as recorded in a separate sentencing release. Those sources are valid evidence of what happened at those procedural stages. They are not the end of the chronology.
After the Second Circuit's decision in United States v. Blaszczak changed the treatment of intangible regulatory information under the wire-fraud property element, the government sought dismissal in the Middendorf and Wada appeals. A later district-court coram nobis order in the same case records that their indictments had been dismissed with the court's approval and vacated Thomas Whittle's plea and judgment; related orders also granted relief to other former defendants. Accordingly, this article does not describe those historical wire-fraud results as current convictions.
That later relief does not erase the SEC firm admission or convert the underlying information use into acceptable audit practice. It changes the criminal status because the charged property theory no longer supported the judgments. The distinction is a model for accountable writing: conduct, professional rules and criminal elements are different questions. A firm can learn from the conduct while accurately acknowledging that the criminal convictions were vacated or charges dismissed.
Independent-consultant undertakings need verifiable closure criteria
The 2019 order required KPMG to retain an independent consultant to assess ethics and integrity controls, evaluate the firm's investigation of exam misconduct and review compliance with specified undertakings. It required cooperation, access, recommendations, implementation and certifications on a defined timetable. Those requirements are stronger than a promise to improve, but their durability depends on what was tested and what evidence survives after the engagement ends.
A consultant's work plan should cover governance, hiring, confidential information, audit-file changes, exam architecture, anomaly detection, preservation, investigation quality, discipline, incentives and retaliation. Sample selection should be independent and weighted toward pressure: senior personnel, difficult exams, inspection periods, late file access and high-consequence engagements. Management should not be able to exclude inconvenient populations without a recorded rationale.
Closure should be issue-specific. For each recommendation, the firm should record root cause, accountable owner, design decision, implementation evidence, operating test, exception rate, remediation of exceptions and residual risk acceptance. The consultant should be able to disagree, and the board should see unresolved items. A completion certificate without that trace cannot show whether a recommendation operated beyond a demonstration environment.
After the mandated period, internal audit or another independent function should repeat key tests. The board should establish leading indicators—unusual access, late workpaper events, exam anomalies, preservation exceptions and hotline retaliation—and outcome indicators such as recurring inspection findings. Improvement is credible when evidence persists without the consultant's immediate presence.
Company transparency is useful but remains self-description
KPMG's 2018 US Transparency Report described its structure, governance, quality-control approach and investments and said the firm was taking decisive actions to strengthen audit quality. It is relevant as the firm's contemporaneous account of design and intent. It is not an independent verdict on effectiveness.
That boundary is important because polished governance descriptions can coexist with control failure. A report may list values, training, inspections and accountability mechanisms without showing how often controls failed, who could override them or whether senior people received different treatment. Stakeholders should use company reports to identify commitments that can be tested, not as substitutes for the test.
Future transparency would be stronger with stable, comparable measures: post-issuance audit-file exception rates; substantiated ethics matters by rank; investigation completion time; retaliation findings; exam anomaly rates; remediation retest results; quality-leader compensation measures; and independent assurance scope. Privacy and fairness require aggregation, but aggregation should not remove all decision-useful information.
The firm should also explain material changes in methodology. A falling anomaly rate can reflect better conduct, weaker detection or a redesigned test population. A rising hotline rate can reflect worsening culture or greater trust. Narrative should reconcile those possibilities and disclose who assured the data. Transparency is accountable when an outsider can understand both the measure and its limitations.
Audit committees should ask for proof without seeking protected information
Audit committees appoint and oversee external auditors, but they do not need—and should never solicit—PCAOB selection data. Their assurance questions should focus on the firm's controls. Has anyone assigned to the engagement recently worked for an audit regulator? What conflict and confidentiality steps applied? Were there exceptional post-report file changes? How does the firm prevent and detect exam manipulation? What independent function tested these controls?
Responses should preserve other clients' and regulators' confidentiality. The firm can describe control design, anonymized testing, exception governance and whether a matter relevant to the issuer exists. It can allow inspection of assurance reports under controlled conditions. It should not reveal selection lists, other engagements or privileged investigative material merely to satisfy curiosity.
Committees should also assess whether the engagement team experiences unhealthy metric pressure. Relevant questions include staffing stability, inspection-linked compensation, consultation usage, unresolved accounting or auditing disputes, late hours and turnover in critical roles. These are risk indicators, not proof of poor audit quality. Their value lies in prompting challenge before pressure produces shortcuts.
Finally, the committee should document the basis for auditor reappointment. Brand, fee and management preference are not enough. The record should show quality indicators, engagement-specific performance, independence, succession, inspection context and remediation evidence. A documented decision supports institutional memory when members rotate.
A durable control architecture makes integrity observable
The integrated model begins with data classification. Regulator-confidential material receives a named owner, access restrictions, retention rules and mandatory incident escalation. Former-regulator hires receive tailored controls. Audit repositories preserve immutable history. Training platforms secure item content and server-side scoring. Legal holds suspend deletion across relevant channels. Investigations have independent governance and fair correction procedures.
The next layer is incentive control. Quality leaders should not be evaluated mainly on an inspection statistic they can influence through file selection or preparation. Partners and staff should not be pushed toward answer sharing by punitive first-attempt metrics. Compensation committees should test whether measures reward truthful identification of weakness, timely repair and robust consultation. Any override should be attributable and independently reviewed.
The third layer is challenge. Ethics, legal, internal audit and a board committee need direct access and authority when senior audit leaders are involved. Analytics can identify unusual patterns, but humans must assess them fairly and protect privacy. Retaliation monitoring must continue after a case closes because career consequences can appear through later staffing and promotion decisions.
The final layer is replay. For a sampled hire, audit file, exam attempt or investigation, an independent reviewer should be able to reconstruct the decision from source evidence. If reconstruction depends on memories, informal messages or a senior person's assurance, the control is not yet durable. Replay is what converts policy into accountability.
Control testing should follow scenarios rather than organisational charts
A credible testing programme should combine the two historical pathways with plausible variants. One scenario starts when a regulator employee enters recruitment discussions and tests whether recusals, access restrictions and hiring-manager instructions activate before any protected information can move. A second plants an apparent inspection-selection clue in a controlled exercise and tests whether a recipient contains and reports it rather than forwarding it. A third selects a completed audit and attempts an exceptional post-report change, verifying that the repository records the attempt and requires proper approval.
Training integrity needs equivalent exercises. Testers can create accounts with different roles, attempt to alter score parameters, reuse links, retrieve cached answers, exceed permitted attempts and exploit administrative privileges. They should confirm that the server—not the user's browser—determines the score and that alerts reach a team independent of the people measured by completion statistics. A controlled message containing purported answers can test whether personnel report it, while protecting employees from entrapment and ensuring the exercise itself does not expose genuine exam content.
Investigation readiness can be tested without waiting for misconduct. A tabletop exercise should identify custodians, place holds across approved communication channels, collect audit and exam logs, manage privilege, handle a correction to an interview answer and brief an independent committee. Observers should record delays, unclear authority and evidence that would have expired. Remediation should be assigned and retested, not left as lessons in meeting minutes.
Scenario design should rotate because a rehearsed test can become another performance metric. Internal audit, ethics and technology-risk teams can own different components, with periodic external challenge. The board should see both pass results and failed controls, including whether seniority changed the response. A finding in a simulation is valuable if it prevents a real failure; suppressing it to protect a dashboard repeats the incentive problem the programme is meant to repair.
Quality metrics must distinguish audit improvement from inspection preparation
The firm needs measures that are difficult to improve without improving the underlying work. Examples include recurring root causes across independently selected audits, consultation timeliness, staffing against risk, completion of corrective actions, workpaper quality at the original archive date and the rate at which internal reviews identify issues before external inspection. These measures should be analysed across the portfolio, not only engagements likely to receive attention.
Inspection results remain important. They are external evidence about selected work and can identify serious deficiencies. But they should be displayed with sample size, selection characteristics, inspection year, report timing and limitations. Management should not infer a population-wide success from a better sample or treat a worse sample as proof that every audit failed. Balanced interpretation reduces pressure to manage the selection instead of the system.
Compensation design should use multi-year evidence and independent moderation. A quality leader should not benefit from a late improvement that depends on extraordinary attention to known files. Nor should employees be punished for surfacing difficult issues that initially worsen a metric. Review committees should examine overrides and compare narratives with underlying data. Any change to a quality score after the evaluation period should retain the original value, reason, evidence and approver.
Audit quality also has capacity constraints. Excessive workload, rapid promotion, skill gaps and compressed review can increase shortcut risk even when formal policies are strong. Staffing data, turnover, consultation queues and late workpaper events should be considered together. The purpose is not surveillance for its own sake; it is to identify where the organisation's promises exceed the resources available to perform them honestly.
What evidence would demonstrate repair
Evidence of repair would include zero unexplained access to confidential selection information; complete former-regulator onboarding files; independently sampled post-issuance audit events; exam scoring code under change control; anomaly cases resolved with documented reasoning; preservation holds reconciled to data sources; consistent discipline analysis; and board minutes showing challenge of quality incentives.
It would also include negative evidence handled honestly. A mature firm will still find exceptions. A perfect dashboard can indicate weak detection. The useful questions are whether exceptions are found by the system rather than outsiders, whether seniority changes the response, whether root causes are repaired across the population, and whether repeated issues affect leadership and compensation.
No single inspection result, consultant report or training completion rate can prove integrity. Inspection samples are bounded; consultant mandates end; tests measure a subset of knowledge. Assurance becomes credible through converging evidence from access logs, file histories, exam data, investigations, personnel outcomes, internal audit and engagement performance.
The KPMG record ultimately concerns institutional legitimacy. Auditors ask markets to trust opinions produced from evidence they cannot all inspect themselves. That privilege depends on a firm showing that it will protect the regulator's measurement, preserve the historical audit record, test competence honestly and investigate its own leaders without fear or favour. The accountability test is passed only when those commitments are independently observable under pressure.

