Two Decades of Scandal: Every Major Big 4 and MBB Failure Since Arthur Andersen
The complete public record of fines, bans and settlements across Deloitte, PwC, EY, KPMG, McKinsey, BCG and Bain, with one insider sentence on each.
Last updated 22 July 2026. We will update this post as new cases emerge. Bookmark it.
In August 2005, KPMG signed what was then the largest criminal tax settlement in American history: $456 million and an admission of criminal wrongdoing, under a deferred prosecution agreement, for designing and selling tax shelters that manufactured at least $11 billion in phony tax losses. The firm promised it had changed. In June 2019 the SEC fined the same firm $50 million for altering completed audit files using confidential inspection plans stolen from inside its own regulator, and for exam cheating among its audit professionals. Same firm, fourteen years apart. In April 2024 the PCAOB handed down the largest fine in its history, $25 million, to KPMG Netherlands, where more than 500 people had shared answers on internal exams and the firm misled investigators about it. And last month, KPMG Australia’s chairman told a parliamentary committee that confidential client data had crossed the firm’s “ethical divider” into a team pitching against that client’s interests.
We open with KPMG only because someone has to go first. Deloitte, PwC and EY each have an equivalent sheet, and so do McKinsey, BCG and Bain. Every incident below was described, at the time, as isolated: a rogue partner, a one-off lapse in a single country. Read one entry and the explanation is plausible. Read forty in a row and “isolated” turns into a description of the pattern itself.
This is the record, firm by firm and in date order: what happened, what it cost, what the regulators did, and one italic sentence under each entry on how it looked from inside a partnership. The facts come from regulator announcements, court records and named investigative reporting, with links; the italics are ours. Some ground rules: we name firms; we mostly do not name individuals unless they led a firm, testified publicly, or were convicted. Where a matter rests on allegations or journalism rather than an adjudicated finding, we say so. Figures and currency conversions are as reported by the primary source, and the list is long without being exhaustive.
The title says “since Arthur Andersen,” so start there. Andersen was convicted in June 2002 of obstruction of justice for shredding Enron audit documents. The Supreme Court overturned that conviction three years later on jury-instruction grounds, and by then it made no difference: clients had fled within weeks and the firm had surrendered its licences. Eighty-nine years of history ended inside twelve months. The verdict arrived too late to matter either way; the indictment alone had been fatal. The surviving firms absorbed that lesson thoroughly, which is one reason nearly every entry below ends in a settlement.
Deloitte
2018. Taylor, Bean & Whitaker. Deloitte audited mortgage lender Taylor, Bean & Whitaker from 2002 to 2008 while TBW ran a fraud with Colonial Bank built on fictitious and double-pledged mortgage loans; both companies failed in August 2009. Deloitte paid $149.5 million in 2018 to resolve potential False Claims Act liability for missing it. (HousingWire)
Nine years from collapse to settlement is long enough for every partner involved to retire on full points.
2019. Serco Geografix. The FRC fined Deloitte £6.5 million, discounted to £4.2 million for settling, over the 2011 and 2012 audits of the Serco subsidiary at the centre of the electronic-tagging overbilling affair, and added £300,000 in costs. The engagement partner was fined personally. (Consultancy.uk)
The settlement discount alone exceeded a partner’s annual profit share. Deterrence was not the design goal.
2020. Autonomy. A then-record £15 million FRC fine and a severe reprimand for “serious and serial failures” in the 2009 and 2010 audits of Autonomy, the software company HP bought for $11.1 billion in 2011 and wrote down by $8.8 billion a year later. Two former audit partners were fined, one of them excluded from the profession for five years. (FRC)
HP’s deal team still gets mocked for this acquisition. They at least had an excuse: they relied on the audits.
2021. 1MDB. Deloitte audited Malaysia’s 1MDB and its SRC International unit from 2011 to 2014, resigned in 2016, was fined 2.2 million ringgit in 2019 for failing to report irregularities in a linked bond issuance, and paid the Malaysian government $80 million in 2021 to settle all claims, the largest 1MDB settlement by any audit firm in Southeast Asia. Billions moved out of the fund through shell structures of exactly the kind audit methodology exists to catch. (Bloomberg)
Deloitte’s defence, that the fraud was deliberately concealed, describes every fraud in history.
2022. Mitie and SIG. Two smaller FRC actions in one year: £1.45 million after reduction over goodwill-impairment testing in Mitie’s FY2016 audit, and £906,250 after reduction over the 2015 and 2016 audits of SIG plc, where the FRC found breaches of requirements it called fundamental to independent audit. (FRC)
The amounts were minor; the findings were the tell. Impairment testing and revenue basics are first-year material, not judgment calls.
2021 to 2025. The exam-cheating and quality-control run. A string of PCAOB actions across the Deloitte network: $350,000 for Deloitte Canada in 2021 after staff altered the clocks on their computers to backdate work-paper sign-offs; $900,000 for Deloitte Colombia over quality-control failures tied to a 2016 Bancolombia audit; $1 million each for Deloitte Indonesia and Deloitte Philippines for widespread answer-sharing on internal training exams, with a Philippines leader barred; and $3 million for Deloitte Netherlands within a combined $8.5 million Dutch action that also caught EY and PwC. (PCAOB)
The geography matters more than the sums. Answer-sharing turned up wherever regulators looked closely, on four continents and at every one of the four firms.
2025. The Canberra report. Deloitte Australia refunded part of a A$440,000 contract after a 237-page assurance review for the Department of Employment and Workplace Relations was found to contain fabricated references, including a quote that appears nowhere in the Federal Court judgment it was attributed to, with the judge’s name misspelled. A University of Sydney researcher caught it. Deloitte then disclosed the report had been produced with help from Azure OpenAI’s GPT-4o and issued a corrected version. (Fortune)
It was, of all things, an assurance review, the one product whose entire value is that somebody checked.
2025. The Newfoundland report. Weeks later in Canada: a 526-page health-workforce plan for Newfoundland and Labrador, priced near C$1.6 million, contained at least four citations to papers that do not exist. Deloitte Canada said AI had not written the report, only “selectively” supported some citations, and stood by its recommendations. (Fortune)
If the recommendations stand regardless of whether the evidence exists, ask what the 526 pages were for.
PwC
2019. Colonial BancGroup. PwC audited Colonial BancGroup while the Taylor Bean fraud ran through it. The FDIC sued; a federal judge found PwC negligent in December 2017 and ordered $625.3 million in damages; the parties settled for $335 million in 2019. (HousingWire)
Two firms audited two ends of the same fraud for six years and neither saw it. It comes back in the pattern section below.
2023. Americanas. Brazil's largest accounting fraud, and a two-firm story. Americanas S.A. disclosed roughly R$20 billion of accounting inconsistencies in January 2023 and entered bankruptcy protection with about R$43 billion of debt. Its independent investigation found ~R$25 billion of inflated results through fictitious cooperative advertising entries and ~R$21 billion of understated financial debt through supplier finance booked as trade payables. KPMG audited from 2016 until an early termination in the third quarter of 2019, six days after its engagement partner escalated a control letter on the accounts the fraud ran through; PwC returned, its three-year cooling-off having just elapsed, and signed unmodified opinions for 2019 to 2021. The CVM opened an administrative accusation against KPMG in November 2024. PwC remains under review. No final sanction against either firm. (Reuters)
Mandatory rotation is the reform the profession points to as proof the independence problem is solved. Here it gave the client a lawful exit from the auditor asking questions and a lawful predecessor to replace it with.
2020. Luanda Leaks. The ICIJ’s investigation into Isabel dos Santos, daughter of Angola’s former president, showed PwC charging rich fees to advise on Angolan tax avoidance and on deals around state oil company Sonangol, including $21.4 million routed to the firm through a Dubai shell company for a 2017 Sonangol “modernization” project. Portuguese police raided PwC’s Lisbon offices in January 2023 at Angola’s request. These are journalistic findings, not adjudicated ones. (ICIJ)
Every firm runs a client-acceptance committee. Files like this one show how often it functions as a filing requirement rather than a brake.
2023. The Australian tax leaks. This is the one that rewired a national government’s relationship with the profession. From 2013, PwC partner Peter Collins advised Treasury on the confidential design of new multinational anti-avoidance laws, signed three confidentiality agreements, and shared the intelligence internally anyway. PwC then marketed structures to sidestep the very laws Collins was helping write, earning about $2.5 million advising 14 US companies. Internal emails released by a Senate inquiry showed dozens of partners in the loop. CEO Tom Seymour resigned in May 2023. PwC sold its entire government-consulting business, rebadged as Scyne Advisory, for one Australian dollar, accepted a $642,000 fine over 170 false claims of legal professional privilege, lost hundreds of partners and staff, and saw FY2023–24 revenue fall by A$820 million, roughly a quarter, to A$2.35 billion. (Overview)
We have both sold and staffed confidential government working groups. The wall between that work and the tax practice was a sentence in an engagement letter, and everyone senior knew a sentence was all it was.
2024. Evergrande, Beijing’s verdict. China’s Ministry of Finance and the CSRC suspended PwC Zhong Tian, the firm’s mainland audit arm, for six months and took 441 million yuan (about $62 million) in fines and confiscations, the harshest penalty a Big 4 firm has ever received in China. Regulators said PwC issued “false audit reports” on Evergrande, found 88 percent of sampled project records inconsistent with reality, and concluded the developer had inflated mainland revenue by roughly $80 billion across 2019 and 2020. More than 50 major clients left, Bank of China, Alibaba and Tencent among them, and PwC fired six partners. (Consultancy.asia)
The ban hurt more than any fine could. Fines get absorbed; fifty lost audit clients are a franchise event, and regulators everywhere took notes.
2025. Riyadh. Saudi Arabia’s Public Investment Fund barred PwC from new advisory work across the fund and its subsidiaries for a year, cutting the firm out of Vision 2030 work. No official reason was ever given; Bloomberg’s reporting tied the fallout to PwC’s attempt to hire away NEOM’s chief internal audit officer. PwC cut about 1,500 staff and 60 partners across the Middle East before the ban was lifted in late January 2026. (Bloomberg)
When a sovereign client can vaporise a regional practice with one unexplained letter, the trusted-advisor language in the pitch deck reads differently.
2024 to 2026. The fine ledger. The PCAOB fined the US firm $2.75 million and PwC Australia $600,000 in March 2024 over quality-control and reporting failures. The Dutch firm was caught in the 2025 exam-cheating action. PwC Singapore was fined $1.5 million in 2025. In the UK, fines came over Wyelands Bank and, this month, £3.2 million over the 2019 and 2020 Babcock audits, PwC’s second penalty over that client after a combined action of almost £8 million in 2023, alongside London Capital & Finance actions that included the FCA’s first-ever fine of an auditor, £15 million, for failing to report suspected fraud. (City A.M.)
Five jurisdictions in twenty-four months is the point at which “local issue” requires a new map.
2026. Evergrande, Hong Kong’s turn. Hong Kong’s AFRC fined PwC HK$300 million and imposed a six-month ban on new public-interest-entity clients, the first restriction of its kind on a PIE auditor; combined with a HK$1 billion SFC compensation fund for shareholders, the total reached HK$1.3 billion, about US$166 million, over audits that had blessed the same overstated revenue Beijing acted on, roughly 564 billion yuan. (Yahoo Finance)
The same audit failure, priced twice by two regulators, and the combined bill still rounds to two weeks of PwC’s global revenue.
EY
2020. Three clients, one year. EY affiliates were the auditors of NMC Health, which failed after revealing more than $4 billion in hidden debt; Luckin Coffee, which admitted about $314 million in fabricated sales; and Wirecard. All three imploded within months of each other. (Forbes)
Auditing is a portfolio business, and 2020 was the year EY’s tail risk correlated.
2022. The ethics exam. The SEC fined EY $100 million, at the time the largest penalty ever imposed on an audit firm, after finding that audit professionals had cheated on the ethics component of the CPA exam and on continuing-education courses, and that the firm misled the SEC’s enforcement staff during the investigation, denying any current cheating problem one day after learning of one. EY admitted the facts. (SEC)
The exam in question was the ethics exam. We would not dare invent that detail.
2023. Wirecard. EY signed unqualified opinions on Wirecard for close to a decade before the German payments company went into insolvency in June 2020, once the company itself conceded that €1.9 billion in cash, about a quarter of its balance sheet, probably never existed. Germany’s audit watchdog APAS banned EY from taking new listed-company audit clients in Germany for two years, fined the firm €500,000 plus smaller sums against five individual auditors, and investigators described audit work that was at minimum negligent and in places grossly so. EY dropped its appeal in 2024. (CNN)
Confirming cash is week-one work for a first-year. Whatever else went wrong across a decade of clean opinions, it began with the simplest test on the audit plan.
2023. Project Everest. EY spent more than a year and roughly $600 million designing a split of its audit and consulting arms, then abandoned the plan in April 2023 when the US executive committee refused to proceed, with the fight centring on who would keep the lucrative tax practice. The firm walked away carrying over $700 million in debt and no split. (AccountancyAge)
The only Big 4 firm to seriously attempt the reform regulators keep hinting at could not get it past its own partners. File that away for every future debate about voluntary separation.
2025 to 2026. NMC Health. Administrators of the failed hospital group sued EY for about £2 billion over 2012–2018 audits that missed more than $4 billion of hidden debt. The High Court trial opened in May 2025 and ran through the summer; in February 2026, with judgment still pending, EY settled on confidential terms with no admission of liability, and the administrators’ report filed in May put the payment at £105.5 million. An FRC probe that has reportedly identified serious failings continues, and EY’s UK firm set aside a record £188 million for fines and legal claims. (Bloomberg; Irish Times)
A nine-figure provision is a forecast. EY’s own finance function is telling you what it expects the next few years to look like.
2025. The Dutch exams. EY Netherlands was one of the three firms in the PCAOB’s combined $8.5 million Dutch exam-cheating action. (CFO Dive)
See Deloitte, above. Same offence, same years, different logo.
2025 to 2026. The UK fine ledger. The FRC fined EY £4.9 million over Thomas Cook and £325,000 over Stirling Water Seafield, and has open probes into unauthorised audit reports and an independence question involving Shell. (AccountancyAge)
None of these made the front page, which is a data point in itself. The market has repriced what counts as news from a Big 4 audit practice.
2026. The loyalty-fraud report. EY Canada published a cybersecurity marketing report in which the AI-detection firm GPTZero found 16 of 27 citations fabricated, misattributed or dead, including a confident reference to a McKinsey study that has never existed, itself traced back to someone else’s blog post. EY pulled the report the same day. (GPTZero)
A fake McKinsey citation inside an EY report is the industry’s supply chain in miniature.
2026. The Prime Minister’s bank account. EY dismissed two graduate employees it had seconded to Commonwealth Bank; one of them, along with a second man, was then criminally charged over allegedly accessing Prime Minister Anthony Albanese’s personal banking data. The case is before a Sydney court and no findings have been made. (The Register)
Secondment bills like consulting and behaves like employment: the firm takes the fee, the client holds the access controls, and neither side monitors conduct. This entry is what that gap looks like.
KPMG
2005. The shelters. The opening story, in full, ran to $456 million, an admission of criminal wrongdoing, and a deferred prosecution agreement over shelters with names like FLIP, OPIS, BLIPS and SOS, which produced at least $11 billion in fictitious losses and cost the US Treasury at least $2.5 billion. Nine individuals were charged, among them a former deputy chairman. (DOJ)
Remember the deferred prosecution structure. It recurs on this page like a chorus.
2017. Gupta state capture. KPMG South Africa audited Gupta family companies for about 15 years, work that included Linkway Trading, through which R30 million of public money meant for poor dairy farmers in the Free State moved via Dubai to pay for a lavish 2013 family wedding. The firm also produced the discredited rogue-unit report for the revenue service, used to force out finance minister Pravin Gordhan, and later withdrew it. In September 2017 the local CEO, chairman, COO and five senior partners resigned, and KPMG conceded its work “fell considerably short” of its standards. The audit regulator struck the lead partner off the register in 2019. (Daily Maverick)
The resignations followed the newspapers rather than any internal review, which tells you which alarm system a partnership actually wires up.
2019. The stolen inspection list. The SEC fined KPMG $50 million after the firm obtained confidential information from a PCAOB insider identifying which of its audits would be inspected, then altered completed work papers to improve its results, and after finding widespread answer-sharing on internal training exams. KPMG admitted wrongdoing. (SEC)
The remedy for a high deficiency rate was, in practice, advance knowledge of the sample. Cheaper than quality, until the SEC priced it.
2023. Carillion. KPMG signed unqualified opinions on the UK construction group for 2014 through 2016; Carillion went into liquidation in January 2018 after announcing £1.045 billion in contract provisions. The FRC fined KPMG a record £21 million, reduced from £30 million for cooperation, with its chief executive calling the work “a textbook case study in failure,” and sanctioned two former partners, one excluded from the profession for ten years. A separate 2022 tribunal had already fined the firm £14.4 million after staff forged documents to mislead FRC inspectors. (FRC)
The second fine deserves its own line: staff forged documents aimed at the inspectors who inspect the auditors. At that point the org chart of trust has run out of levels.
2024. The record fine. The PCAOB’s largest penalty ever, $25 million, went to KPMG Netherlands, where more than 500 professionals shared exam answers over five years, the practice reached the firm’s former head of assurance, who was barred for life, and the firm repeatedly misrepresented what it knew to investigators. (PCAOB)
Five hundred participants over five years leaves no room for the word “isolated.” At that scale the behaviour has a training programme.
2025. Form AP. The PCAOB censured and fined nine KPMG network firms a combined $3.375 million for failing to disclose, on the Form AP filing that names every firm participating in an audit, which other firms worked on theirs; smaller UK fines over Carr’s Group and N Brown, and an earlier $500,000 PCAOB fine for KPMG Japan, sit alongside it. (PCAOB)
Who actually did the work is the entire premise of an audit signature. The sums are small; the subject is not.
2026. The AI-ethics exam. KPMG Australia confirmed in February that 28 staff had used AI tools to cheat on the firm’s mandatory AI-ethics training since mid-2025, among them a partner-level registered auditor fined more than A$10,000. This is the same national firm the PCAOB sanctioned $450,000 in 2021 over cheating that implicated as many as 1,100 partners and staff, and the same global network that announced itself, in 2024, as the first organisation in the world to earn ISO 42001 certification for AI governance, a service it also sells. (Report)
We read this entry aloud to three former colleagues. All three laughed before they winced.
2026. The audit-data leak. The fire is still burning on this one. KPMG staff moved confidential information from audit clients Lendlease and Optus to colleagues pitching for the audits of Westpac, Dexus and Telstra. Chairman Martin Sheppard told Parliament on 19 June that unredacted Optus data crossed what the firm called its ethical divider and reached the team pursuing rival Telstra. A whistleblower had first raised concerns on 30 May 2024; the firm’s documented response was to search his laptop, deny him a pay rise, pull his client work and threaten dismissal. Since March: CEO Andrew Yates resigned (an A$1.7 million notice payment plus A$2.4 million in retirement entitlements), the head of audit left, the COO stepped aside, the firm appointed its first independent chair, Lendlease ended an audit relationship of roughly 68 years, ASIC opened a formal investigation, the Department of Finance froze KPMG out of new federal contracts until the end of September, the Greens referred the firm to the National Anti-Corruption Commission, and the AFR reports preparations to cut as many as a thousand jobs and up to a fifth of partner pay. A second parliamentary hearing is set for 14 August. (Bloomberg; Canberra Times)
Every firm’s first crisis instinct is containment; we have sat in the rooms where that instinct wins. What distinguishes this case is that the containment file became evidence.
2026. The Total Experience report. KPMG International published an AI thought-leadership report in October 2025; by the time GPTZero finished with it in June, 40 of 45 citations proved fabricated, mangled or misattributed, and UBS, the NHS, Swiss Federal Railways and Transport for London told the Financial Times that its claims about their AI usage were untrue or misleading. KPMG removed the report. (GPTZero; The Register)
Four institutions had to publicly correct a Big 4 firm’s account of their own operations. The report was marketing, which is the problem: the product being marketed is accuracy.
McKinsey
2018. The Saudi influencer report. A 2016 McKinsey document analysed Twitter sentiment after Saudi austerity measures and identified three people driving negative online conversation about the government. All three were subsequently targeted: writer Khalid al-Alkami was arrested, a second account-holder disappeared, and Omar Abdulaziz, a close associate of Jamal Khashoggi, had his phone hacked and relatives detained, with torture reported. McKinsey said the report was for internal use. During the crown prince’s rise the firm was embedded enough in Riyadh that the Planning Ministry earned the nickname “Ministry of McKinsey.” (Courthouse News)
An internal-use defence concedes the report existed and named the names. Everything after that concession is a dispute about distribution.
2018. Eskom and Trillian. McKinsey took roughly R1 billion from South Africa’s state power utility on a turnaround contract, run alongside a Gupta-linked partner firm, that was later found unlawfully procured. The firm repaid the R1 billion (about $74 million) with interest in 2018 and a further $39 million in 2020 over other state-owned-enterprise work. (SA Government News)
Repayment with interest is the professional-services equivalent of a guilty plea entered in a whisper.
2019. ICE. ProPublica and the New York Times revealed that McKinsey’s engagement with ICE, begun under one administration as organisational work, was redirected under the next toward executing the immigration crackdown, with the firm proposing cuts to spending on detainee food, medical care and supervision. Total billings passed $20 million, and the team ghostwrote the contracting document that justified its own $2.2 million extension. (ProPublica)
Every consultant has drafted the client memo that requests more consulting. Few have done it for a detention system’s food budget.
2020. Luanda Leaks. McKinsey’s slice of the dos Santos-era Sonangol work was $15.4 million, routed through the same Dubai shell company as PwC’s and BCG’s fees. As with PwC’s entry above, these findings come from journalism, and no court has ruled on them. (ICIJ)
Three rival firms shared one Dubai invoicing address, which says more about client selection than any values page.
2021 and 2024. Purdue. McKinsey advised Purdue Pharma for over a decade on how to “turbocharge” OxyContin sales, work that included targeting the highest-volume prescribers and a 2017 proposal to pay distributors rebates tied to overdoses linked to pills they moved. When states began suing Purdue, senior McKinsey people emailed about deleting documents. The firm paid $573 million to 47 states, DC and five territories in 2021 without admitting wrongdoing, then $650 million in December 2024 to resolve a Department of Justice criminal investigation, entering a five-year deferred prosecution agreement while a former senior partner pleaded guilty to obstruction of justice for destroying records. In April 2026 the firm agreed to contribute a further $125 million to Purdue’s bankruptcy estate, again without admitting wrongdoing, taking its opioid-related settlements past $1.7 billion in total. (FiercePharma; Reuters)
Strip the industry framing away and describe the engagement plainly: paid experts optimised sales of a product at the centre of a mass-casualty epidemic, and the firm’s recorded reflex when accountability approached was the delete key. No partnership-governance reform addresses this. It is a question of what work you will take.
2022. Paris. A French Senate report alleged that a McKinsey executive gave false sworn testimony about the firm’s tax payments in France, prompting a fiscal investigation that remains in the allegation column. (The Hill)
Tax advice is the product; the firm’s own tax posture is the free sample everyone inspects.
Ongoing. Bankruptcy disclosures. McKinsey’s restructuring arm has faced repeated allegations that it failed to disclose connections to interested parties in US corporate bankruptcy cases, where disclosure by advisers is a legal requirement; in 2019 the firm paid $15 million to the US Trustee to resolve disclosure questions across three cases.
Disclosure rules exist because the court cannot see the conflicts on its own. A firm that treats them as negotiable has told you its theory of the referee.
2024. The China file. The House Select Committee on the Chinese Communist Party alleged that McKinsey concealed extensive work for Chinese government bodies, including on five-year plans and Made in China 2025, while holding more than $480 million in US Department of Defense contracts, and that the firm’s global managing partner misrepresented that work under oath in February 2024. These are the committee’s allegations. (House Select Committee)
A client-acceptance policy meets exactly one test that matters at this scale, and simultaneous service to both sides of a strategic rivalry is that test.
2024. The South Africa DPA. Closing the Eskom-era loop, and separate from the 2018 repayments: McKinsey Africa agreed to a $122.85 million criminal penalty under a three-year deferred prosecution agreement over bribery of Transnet and Eskom officials between 2012 and 2016, conduct that had earned the firm about $85 million. A former partner had pleaded guilty in 2022, and a parallel South African resolution added roughly $50 million. (DOJ)
Count the deferred prosecution agreements on this page. For firms whose product is judgment, the DPA has become a recurring line item, and line items get budgeted.
BCG
2020. Luanda Leaks. BCG’s slice of the dos Santos-era work was the largest of the three consulting firms: $31.2 million through the Dubai shell company for the 2017 Sonangol project, plus a stint helping run the jewellery house De Grisogono, acquired with Angolan state loans. Portuguese police raided the Lisbon office in January 2023 as part of the dos Santos investigation. As with the PwC and McKinsey entries, these are journalistic findings. (Consultancy.com.au)
De Grisogono deserves its own business-school case: a strategy firm helping operate a jewellery house bought with public money.
2024. The DOJ declination. A separate Angola matter with a cleaner paper trail: between 2011 and 2017, BCG’s Lisbon office paid about $4.3 million in commissions to an agent connected to Angolan officials, who helped the firm win eleven contracts with the economy ministry and one with the central bank, worth about $22.5 million in revenue. BCG self-disclosed after finding a 2014 email, fired those involved, and in August 2024 the US Department of Justice declined prosecution in exchange for $14.4 million in disgorged profits. (DOJ letter)
A declination is the best available outcome in a foreign-bribery case, and BCG earned it by the book: disclose, cooperate, fire, disgorge. Eleven ministry contracts through one connected agent still describes a business-development channel, whatever the engagement letters called it.
2024 to 2025. Gaza. Between October 2024 and May 2025, BCG helped establish and run the US and Israeli-backed Gaza Humanitarian Foundation and, under a workstream reported as Project Aurora, built financial models that included costing the “voluntary relocation” of Palestinians out of Gaza, a concept a senior UN official condemned as ethnic cleansing. BCG described the work as pro bono; the Financial Times, which led the reporting, put the contracted value above US$4 million and billings above $1 million a month. The CEO apologised, two partners were fired for what the firm called unauthorised work, the chief risk officer and the head of social impact stepped down, and Save the Children and the World Food Programme reviewed or paused their ties to the firm. (Middle East Eye)
Two fired partners is the rogue-actor defence at a firm whose entire method is that nothing reaches a client unreviewed. Pick which claim to believe about BCG; both cannot be true.
Bain
2022. SARS. Bain’s 2015–2017 restructuring of the South African Revenue Service under commissioner Tom Moyane gutted the agency’s enforcement capacity. Two judicial commissions found that Bain’s local managing partner had met President Jacob Zuma repeatedly and that the firm’s work facilitated state capture. South Africa’s National Treasury banned Bain from public contracts for ten years, until 2032, citing “corrupt and fraudulent practices”; the UK Cabinet Office had imposed a three-year ban of its own in 2022, then lifted it for the global firm in March 2023 while keeping the South African arm excluded. Bain repaid its fees with interest, apologised, wound down its client-facing South African business, and continues to deny wilfully enabling state capture. Whistleblower Athol Williams left the country after testifying. (TimesLIVE)
A ten-year sovereign ban is the closest thing consulting has to a licence revocation, and the industry’s response was to keep pitching as if it had happened to someone else’s profession.
The AI report problem
Three of the four Big 4 firms have now been caught publishing reports with fabricated, AI-hallucinated citations: Deloitte twice, in Australia and Canada, then EY Canada, then KPMG International, with fabrication running from a handful of fake references to 40 out of 45. PwC is, so far, the only Big 4 firm with a clean sheet on this, and no MBB firm has yet been caught. Most of the forensic work has come from GPTZero, which coined the term “vibe citing” for hallucinated references and traced fake citations laundering from one document into another. Each firm caught reached for the same defence, that the substance and recommendations were unaffected. That defence deserves the scrutiny the citations never got: if the conclusions hold regardless of whether their evidence exists, the evidence was decoration, and the client paid for decoration.
The regulators kept score
Behind the case-by-case entries sits a quieter dataset. The PCAOB’s Part I.A deficiency rate measures the share of inspected audits where the file did not contain sufficient evidence to support the opinion issued. For the US Big 4, that rate ran 12 percent in 2020, 16 in 2021, 26 across 2022 and 2023, and back to 20 in 2024. Across all inspected firms it hit 40 percent in 2022, peaked at 46 percent in 2023, and eased to 39 in 2024; BDO USA touched 86 percent. Enforcement moved in parallel: PCAOB civil penalties went from about $1.1 million in 2021 to a record $11 million in 2022 and $11.9 million by November 2023, and since 2021 the board has sanctioned at least nine firms for exam cheating. One number puts the escalation in scale: the single fine against KPMG Netherlands in April 2024 was more than double the board’s entire record 2022 total. (Accounting Today; Floyd Advisory)
Australia has gone furthest. After two identical wall failures at two firms in three years, new Big 4 federal contracts fell from A$637 million to A$348 million between 2024 and 2025, and this month Canberra moved to expand ASIC’s powers, publishing a Treasury options paper that describes conduct from the large firms “that is not fair and honest.” ASIC has widened its audit-conduct scrutiny to all four.
The 2024 improvement in the PCAOB numbers is real, and the firms will cite it. Weigh it honestly: the improvement arrived under the most intense regulatory attention the profession has faced since 2002, and it still leaves a fifth of inspected Big 4 audits without sufficient evidence for the opinions they carried. In what other product category would a 20 percent verified defect rate be presented as recovery?
Three patterns
Sort the forty-odd entries above and they resolve into three piles.
The first pile holds audit failures on companies that then failed: Wirecard and EY, Carillion and KPMG, Evergrande and PwC, NMC and EY, Americanas and PwC and KPMG, 1MDB and Deloitte, Autonomy and Deloitte, and Colonial BancGroup, where PwC and Deloitte audited two ends of the same fraud. The economics of this pile are stable and comfortable. The fine lands years later, sized in the single or low double-digit millions, against client losses in the billions; the partners involved have usually retired. What changes firm behaviour is a different instrument, and the record shows it plainly: Germany’s two-year ban moved EY more than any fine, China’s six-month suspension cost PwC over fifty clients, and Hong Kong followed with a PIE restriction. Exclusion has changed behaviour where money never has.
Pile two collects the conflicts between advisory work and a public-interest role: Canberra’s tax intelligence inside PwC, audit-client data inside KPMG Australia’s pursuit teams, the three-firm Dubai invoicing address in Luanda, McKinsey advising the FDA while advising Purdue, the Saudi and SARS engagements. The walls that were supposed to prevent all of this were real in exactly one sense: they existed as sentences in policy documents, acknowledged during onboarding. Between us, the contributors to this publication sat through decades of those acknowledgements, and we watched information cross the walls whenever it made a pitch stronger. Two identical wall failures in one country within three years should end the argument about whether this is a people problem or an incentive problem.
The third pile deserves the most attention, because it involves no client, no fraudulent counterparty and no tempting pile of money: exam cheating at every Big 4 firm across the US, the Netherlands, Australia, Indonesia and the Philippines; stolen regulator inspection plans; documents forged for FRC inspectors; investigators misled at the SEC and the PCAOB; AI-fabricated evidence in published reports; and an AI-ethics exam cheated on with AI. The first two piles have external villains available. The third is the firms alone with their own integrity infrastructure, and the infrastructure lost. We have sat through the all-hands calls that follow each of these announcements, and a couple of us have helped draft the talking points that client-facing teams receive the same afternoon. The training module that follows is always about forty minutes. The quiz at the end can be passed on a skim. That is the soil the third pile grows in.
The strongest defence, taken seriously
The defence of the firms goes like this, and it deserves its best version. These are organisations with revenue between $53 billion and $70 billion each, operating in well over a hundred countries, across a window of more than twenty years; at that scale some misconduct is a statistical certainty, and a list like this one is survivorship bias in reverse. Most of the work, most of the time, is competent; clients keep buying it, and the US Big 4 still audit about 80 percent of the market capitalisation of US-listed companies because no credible alternative exists at that scale. The PCAOB’s own 2024 numbers show correction. Some entries above are journalism or committee allegations rather than verdicts. And Andersen’s fate proves the ultimate sanction is available when conduct warrants it.
Much of that is true, and we say so as people who spent careers inside these buildings delivering work we remain proud of. The defence explains the frequency of failure. It cannot explain the kind. A base-rate argument works for a retailer or a manufacturer, businesses that sell products and sometimes ship bad ones. These firms sell trust: the audit franchise exists because the state grants a handful of private partnerships the role of certifying everyone else’s honesty. For that business, three features of the record above are disqualifying. Repeat offences follow settlements as if the settlements were subscriptions; KPMG’s arc from 2005 to 2026 is the clearest run, and network-wide exam cheating continued for years after EY’s $100 million made the stakes unmistakable. Penalties price in as a cost of doing business; against Deloitte’s $70.5 billion in annual revenue, an eight-figure fine is a rounding decision. And a striking share of the misconduct targets the oversight system itself: stolen inspection selections, forged documents for inspectors, misled enforcement staff, allegedly false testimony before two legislatures. Ordinary corporate scandal cheats customers or markets. Several entries on this page cheat the referee, and a profession that cheats its referee forfeits the case for self-regulation, which is the case the entire model rests on.
Now tell us what’s missing
This page will grow. We will add entries as regulators, courts and journalists produce them, and we will correct anything a reader shows us we got wrong; the caveats above about allegations and currency conversions stand.
What’s missing from this list? If you’ve seen something from the inside that hasn’t been reported, this is the place. Two requests before you type: stay within whatever confidentiality obligations bind you, and bring specifics that can be checked. Patterns and public documents beat client names. The comments are open.


