FOI emails reveal DISR raised concerns with KPMG about sensitive government information and conflicts months before internal disclosures emerged.
KPMG Australia was questioned by the Department of Industry, Science and Resources (DISR) about confidential information and conflicts of interest months before a whistleblower formally raised concerns about alleged misuse of client data. FOI emails revealed that the department had already been trying to get assurances from the firm since as early as September 2023.
Correspondence provided to Capital Brief includes correspondence from September 2023 through June 2026 between DISR and KPMG. The documents provide an earlier timeline for concerns about how the accounting firm handled sensitive information.
DISR Raised Questions before Disclosure
DISR made contact on 12 September 2023 with the former KPMG Australia CEO Andrew Yates, regarding the handling of Commonwealth confidential material by the company. The CEO responded to their inquiry approximately two weeks thereafter.
The queries were raised some eight months prior to when a whistleblower from KPMG made an internal report on the abuse of the client's confidential information in May 2024. It has been established that KPMG has admitted to mishandling its whistleblower and its investigation process.
Key points from the disclosed correspondence:
-
DISR questioned KPMG about confidential information handling.
-
The department also raised concerns about conflicts of interest.
-
KPMG responded to the initial information request.
-
A later meeting involved senior DISR officials.
-
KPMG presented its commercial conflict management framework.
KPMG Explained Its Conflict Management Process
On June 28, 2024, about a month after the internal whistleblower disclosure, DISR again contacted Yates to request a meeting focused on confidential information and conflicts of interest.
That meeting was held on September 17, 2024, with DISR's chief financial officer and general manager for integrity attending alongside KPMG representatives. A presentation prepared by KPMG described several categories of potential conflicts, including external audit independence, adversarial, competing-party and commercial conflicts.
KPMG also said it operated a Commercial Conflicts Resolution Committee to oversee and decide commercial conflicts. This disclosure is yet another addition to the larger scandal involving KPMG Australia, which ultimately saw the firm facing parliamentary questions over its misuse of confidential client data. KPMG has admitted that its client files have been improperly shared within the firm.
The controversy has involved allegations concerning information from clients including Lendlease and Optus. The following was made clear by KPMG in June 2026, when it stated that there was inappropriate sharing of information about Optus within its organization during the ongoing parliamentary inquiries.
With regard to DISR, this newly available correspondence indicates that confidentiality and conflicts were already being addressed between DISR and KPMG prior to the whistleblowing claims.
Thus, Business Fortune believes that the disclosures highlight why stronger safeguards are essential when firms handle sensitive government and client information.















Comments