PwC Australia: The Scandal That Proved the Walls Don't Work
Confidential intelligence. Three signed agreements. Fifty-three partners. One dollar.
In late 2013, PwC partner Peter Collins joined Treasury’s BEPS Tax Advisory Group, one of several private-sector experts consulted on international tax reform. Collins, PwC Australia’s head of international tax, was a credible choice. He signed a confidentiality undertaking on 11 December 2013. The domestic measure that became the Multinational Anti-Avoidance Law came later, with an exposure draft released in May 2015. The MAAL was designed to close the loopholes that let multinationals shift profits out of Australia and into low-tax jurisdictions. Collins signed further confidentiality undertakings in April 2016 and February 2018.
Three separate undertakings, each one making explicit that the information Collins received was confidential, that it was not to be shared outside the consultation process, and that it was certainly not to be used for commercial advantage. Collins agreed to all of this. Then he did the opposite, systematically, for years.
Confidential OECD material had circulated internally during 2014. By mid-2015, the emails show a more explicitly commercial operation forming around the MAAL: confidential policy intelligence was being used to inform client approaches and restructuring work. The firm assembled what the Senate inquiry later described as a “global team” to win new business on the back of confidential government policy. PwC’s first tranche of the effort, dubbed Project North America, contacted at least 14 US multinational companies and advised them on restructuring their tax arrangements to sidestep the very law that Collins was helping to write. In August 2015, a PwC colleague emailed a Google employee to confirm the MAAL’s likely start date, information that came directly from confidential government briefings. The email did not mention that the information was confidential.
The revenue PwC generated from this effort was approximately A$2.5 million. Remember that number, because it will become important later.
The Distribution Network
The detail that matters most in this case is not what Collins did. One partner breaching a confidentiality undertaking is serious but containable. Firms deal with rogue individuals. They investigate, they terminate, they move on. What makes the PwC Australia scandal different is how many people received the information and what they did with it.
When the Senate Economics Legislation Committee tabled 144 pages of internal PwC emails in May 2023, the scale of the distribution became visible. At least 53 redacted PwC email addresses, spanning offices in Australia, the United States, the United Kingdom, and Ireland. PwC’s own internal review subsequently identified a broader set of recipients across the full chain of correspondence. Partners. Directors. Tax practice leads. People in positions of seniority who would have understood immediately what they were looking at and where it came from.
One of those emails, sent by partner Paul McNab to then-head of tax Tom Seymour in January 2016, captured the culture in a single sentence. McNab wrote that PwC had been “aggressive in telling these relationships they needed to act early,” and noted that this was “heavily helped by the accuracy of the intelligence that Peter Collins was able to supply us.” Seymour, who would later become CEO, replied the next day and copied in additional PwC personnel.
“The accuracy of the intelligence.” Not “information.” Not “insight.” Intelligence. The word choice tells you everything about how the participants understood what they were doing. They were running an intelligence operation inside a professional services firm, using confidential government policy as the raw material and multinational tax advisory as the product.
Anyone who has worked in a Big 4 tax practice knows how this would have played out operationally. The partners receiving Collins’s intelligence did not sit on it and agonise over its provenance. They picked up the phone. They called their relationship leads on US multinational accounts. They scheduled meetings. They developed restructuring proposals, complete with the specific detail that no competitor could match, because no competitor had a partner sitting inside the government’s policy development process. The value proposition was speed: act before the legislation takes effect, and we can show you how to avoid it. Speed was the product. The intelligence was the input.
Nothing in the disclosed chain shows anyone stopping the initiative or escalating the confidentiality concern. Not the Office of General Counsel. Not the risk team. Not Tom Seymour, who received the email, replied to it, and widened the distribution. Nobody in the available record read the words “intelligence that Peter Collins was able to supply us” and asked whether that intelligence was supposed to leave Collins’s desk. In a partnership culture where revenue generation is the primary measure of contribution, the partner who shares information that wins business is a hero. The partner who flags a compliance concern that kills a revenue opportunity is a nuisance.
How the Wall Was Supposed to Work
Every Big 4 firm will tell you it has controls. Confidentiality walls. Conflict-of-interest registers. Independence protocols. Annual sign-off requirements. Training modules with quizzes at the end. PwC Australia had all of these. The firm’s own later review noted that at no point did anyone identify “the potential conflict of interest that arose from having client-facing partners participating in confidential Government consultations,” nor did anyone alert the Office of General Counsel or the risk team.
PwC’s own subsequent findings make clear that the failure was in design as well as enforcement. The firm acknowledged that the inherent conflict created by having client-facing partners participate in confidential government consultations was never recognised, that no central mechanism recorded the undertakings and notified affected teams, and that commercial incentives operated without an independent counterweight. The wall was a policy document and a set of procedures, the kind that sounds rigorous when described in a pitch and looks thorough when printed in an annual transparency report. In practice, it was a partition in an open-plan office. Everyone walked around it when they had a reason to.
The reason, in this case, was commercial opportunity. Collins had access to information that gave PwC’s tax advisory practice a competitive advantage. Sharing that information meant PwC could approach multinational clients before their competitors did, with specific knowledge of what the legislation would contain and when it would take effect. The commercial incentive to share was direct and measurable. The compliance incentive to stay quiet was diffuse and, as events proved, unenforced.
We have all seen this dynamic. Every former Big 4 partner reading this has sat in a meeting where information that should have stayed behind a wall was shared, casually, because the partner sharing it was trying to win a pitch and the information made the pitch stronger. The difference between PwC Australia and every other instance is not that the wall failed. The wall fails routinely. The difference is that someone, eventually, reported it.
The Decade of Delay
The ATO began scrutinising MAAL-related structures during 2016. By October 2017, it had identified that Collins might have shared information covered by Treasury confidentiality obligations. Suspicion fell on PwC.
What followed was one of the most frustrating institutional failures in Australian regulatory history. The ATO tried to investigate. PwC responded by claiming legal professional privilege over tens of thousands of documents. The ATO’s second commissioner later told Senate estimates that the investigation was “frustrated through false LPP claims.” The ATO shared information with the AFP in 2018. The AFP concluded it did not have enough evidence to pursue a formal investigation, partly because privacy rules prevented the ATO from sharing the material the AFP would have needed.
So the ATO referred Collins to the Tax Practitioners Board in July 2020. The TPB, a small regulator without the resources or the mandate for a case of this complexity, took until the end of 2022 to reach its decision. And that decision, when it came, was modest: Collins was deregistered as a tax agent and barred from reapplying for two years. The TPB chair expressed “concern” about tax practitioners who “abuse their positions of trust.”
Two years. For a systematic breach of three confidentiality undertakings that fed a multinational intelligence-sharing operation across four countries. The TPB did also impose remedial orders on PwC for failing to manage conflicts of interest, requiring improved confidentiality registers, reporting processes, and training. Those measures were real, but they fell well short of accountability across the wider network that had commercialised the information. The system had processed the breach the way a body processes a low-grade infection: just enough immune response to keep functioning, not enough to clear it.
If the story had ended there, it would have disappeared. One paragraph in a regulatory bulletin. A footnote in compliance training. The system would have absorbed the breach the way it absorbs most breaches: quietly, without consequence, without change.
The Senate Blew the Doors Off
The Australian Financial Review broke the story in January 2023, drawing on the TPB’s published findings. That caught the attention of the Senate, which was already running a broader inquiry into consulting services. On 2 May 2023, the Senate Economics Legislation Committee tabled 144 pages of internal PwC emails that the TPB had provided as answers to questions on notice.
Those emails changed everything. They showed the scale of internal distribution, the language partners used when discussing the leaked intelligence, and the degree to which senior leadership was informed. They also showed that PwC had known about the problem for years and had chosen containment over disclosure.
Tom Seymour’s response in March 2023, before the emails were released, was revealing. At the Financial Review’s Business Summit, Seymour described evidence that 20 to 30 partners and staff had received confidential information as a “perception problem.” Six weeks later, when the full email cache made the scope undeniable, he resigned.
Nine partners were stood down. Four were named publicly: Collins, McNab, Bersten, and Fuller. The acting CEO, Kristin Stubbins, issued an open letter apologising on behalf of the firm, while simultaneously resisting calls to release the names of all individuals involved. The Treasury referred the matter to the AFP for criminal investigation. Federal agencies reviewed and in many cases paused PwC engagements; by April 2024, PwC and the Department of Finance had agreed that PwC would temporarily refrain from bidding for new Commonwealth work.
The Price of A$2.5 Million
The commercial consequences landed fast and hard. PwC entered an exclusivity agreement to sell its government consulting practice to private equity firm Allegro Funds for A$1. The business, rebranded as Scyne Advisory, had been valued at over A$100 million. PwC sold it for a single dollar because no other outcome was politically survivable. As long as PwC retained its government consulting arm, every government contract the firm held or bid for would carry the taint of the tax leak. The only way to cauterise the wound was amputation.
More than 1,400 partners and staff transferred into Scyne. Others departed through attrition, retirement, or redundancy. PwC was also embroiled in a separate but related dispute over expansive legal professional privilege claims. The ATO initially assessed penalties over 170 claims and settled for approximately A$642,000. Senate committees argued that PwC’s approach to privilege had frustrated regulatory scrutiny more broadly, though the ATO said the settlement was separate from the Collins confidentiality breach itself.
In its FY2023-24 transparency report, PwC Australia disclosed a 24 per cent decline in profit and an A$820 million drop in revenue, bringing total revenues down to approximately A$2.5 billion. Not all of that contraction was caused directly by the scandal; the Scyne divestment removed a large business from PwC’s reported revenue base. But the asymmetry between cause and consequence is unmistakable.
The first tranche of Project North America produced at least A$2.5 million in fees. The consequences cannot be reduced to an equally precise counter-number, but they include a government consulting business transferred at a nominal A$1 sale price, years of regulatory and parliamentary scrutiny, and a collapse of trust that no financial statement can fully isolate. Kevin Burrowes, installed as the new CEO, disclosed an Australian salary of A$2.8 million but later revealed a further annual payment of approximately A$1.2 million from PwC International that had not been communicated to the wider Australian partnership. That tells you something about the culture of disclosure even after the crisis that was supposed to have reformed it.
What the Firm Actually Did Wrong
The popular narrative is that Peter Collins went rogue. That is the narrative PwC preferred, and for a while, the regulatory system accommodated it. The ATO’s initial referral to the TPB named Collins alone. When the TPB expanded its inquiry to examine PwC’s institutional role, the ATO, citing secrecy provisions, refused to provide further documents, frustrating the TPB’s broader investigation. Later proceedings extended to other senior figures: in September 2025, the TPB terminated former CEO Tom Seymour’s tax-agent registration and imposed a four-year bar.
The one-bad-apple framing is comforting. It implies the system works and this was an aberration. But look at what actually happened after Collins shared the intelligence. He did not have to persuade reluctant colleagues to use the information. He did not face internal resistance or whistleblower reports from partners who received the emails and recognised the breach. The information flowed through the firm’s global tax network the way all useful commercial information flows through a Big 4 partnership: quickly, widely, and with enthusiasm. Partners did not push back. They asked how to monetise it.
The firm’s response, once the ATO started asking questions, was not transparency. It was legal professional privilege claims, 170 of which were later found to be false. PwC used the legal architecture designed to protect legitimate client communications to obstruct a regulator investigating the firm’s own misconduct. That is not one bad apple. That is institutional behaviour.
And that institutional behaviour has a logic to it that anyone who has been a partner at one of these firms will recognise. The first priority in a crisis is containment. Limit the exposure. Identify the smallest possible number of individuals who can take the blame. Invoke every procedural shield available. Wait for the news cycle to move on. The calculus is simple: the cost of transparency (partner departures, client losses, regulatory escalation) is immediate and quantifiable. The cost of concealment is uncertain and may never arrive. Partners optimise for the certain cost, every time.
The Pattern Repeats
Eighteen months after the PwC Australia tax leak became front-page news, PwC faced a second crisis on a different continent. In September 2024, Chinese regulators imposed a six-month business suspension on PwC’s mainland auditing arm, PwC Zhong Tian, plus fines totalling 441 million yuan (approximately US$62 million) over its audits of collapsed property developer Evergrande. The China Securities Regulatory Commission said PwC had “turned a blind eye” to and “even condoned” Evergrande’s fraud, finding that 88 per cent of PwC’s real-estate site-observation records were inauthentic and that Evergrande had inflated revenues by approximately US$78 billion across 2018 to 2020. PwC had audited Evergrande for nearly 14 years. In April 2026, Hong Kong’s Accounting and Financial Reporting Council imposed a further HK$300 million fine over the same audits.
More than 50 Chinese companies dropped PwC or cancelled plans to appoint it, including Bank of China, which switched to EY. The client exodus triggered layoffs across PwC’s China practice before the mainland ban even formally began.
Then, in February 2025, Saudi Arabia’s Public Investment Fund restricted PwC from competing for certain new advisory assignments across PIF and its subsidiaries, cutting the firm out of Vision 2030 mega-projects that had been a growth engine for its Middle East practice. The Financial Times linked the dispute to PwC’s attempt to recruit NEOM’s chief internal audit officer, though neither the precise rationale nor the full scope of the restriction was publicly established. PwC cut approximately 1,500 staff and 60 partners across the region. The restriction was lifted in January 2026.
Three crises in three jurisdictions in less than two years. Australia, China, Saudi Arabia. Different circumstances, different regulators, different triggers. But the same firm, exhibiting the same institutional reflexes: protect the revenue, contain the damage, minimise the number of people held accountable, invoke procedural defences, and hope the next quarter’s numbers are strong enough to make everyone forget.
The connecting thread is not recklessness or corruption in the way those words are normally understood. Nobody at PwC woke up and decided to enable fraud or betray government confidences for the thrill of it. The connecting thread is a governance model in which the financial incentives to cut corners consistently overwhelm the compliance incentives to maintain standards, and in which the partnership structure means that the people who would need to enforce those standards are the same people whose income depends on the revenue those corners generate.
The Question Nobody Wants to Answer
PwC’s response to the Australian scandal was to sell the government consulting business. The logic was that removing the government advisory practice would remove the conflict of interest that enabled the breach. But the MAAL leak did not happen because PwC had a government consulting arm. It happened because a partner with access to confidential information had colleagues with a commercial incentive to use it, and no control in the firm was strong enough to prevent the transfer.
Selling the government practice addressed the symptom. The information flowed because the incentive to share exceeded the consequence of sharing. That incentive calculus has not changed. It cannot change within the current model, because the current model depends on partners cross-selling across practice lines, sharing client intelligence to win adjacent engagements, and treating the firm’s collective knowledge base as a competitive asset. Confidentiality walls ask partners to do the opposite of what the business model rewards them for doing. Every time.
KPMG Australia demonstrated this in 2026, when confidential audit-client data crossed the firm’s “ethical divider” into teams pitching for rival clients’ audit work. Different firm, different data, different regulatory obligations, but an analogous mechanism: confidential information crossed an internal boundary at the point where doing so could support a commercially important pitch. The whistleblower who reported it was treated the way PwC’s regulatory interlocutors had been treated: as the problem, not the solution.
Two analogous failures at two different firms in three years, in the same country. If a control fails twice in comparable circumstances, the issue is probably not that both firms implemented the control badly. The more plausible conclusion is that policy-only walls cannot hold where both sides share a P&L and the commercial information can move without technical friction.
A$2.5 million in advisory fees. An A$820 million revenue decline in a single year. A government consulting business transferred for a dollar. At least 53 recipients of confidential intelligence and, in the disclosed record, not one flag raised. Those numbers tell you everything about where the incentives actually point, and how far the compliance architecture is from being able to redirect them.
Is there a design for internal confidentiality walls that actually works at scale? Not in theory. Not as described in a transparency report. In practice, inside a Big 4 partnership, where the people behind the wall and the people in front of it share a compensation pool and a single P&L. Has anyone seen it work?


