The professional services firms at the centre of UK and global business — the Big Four audit and advisory firms, the lobbying consultancies staffed by former ministers, the strategic advisory businesses structured to avoid transparency disclosure — present themselves as independent, expert and neutral. They are none of these things.
In 2001, the collapse of Enron and the destruction of Arthur Andersen exposed the structural conflict at the heart of the audit model: an auditor that makes more money from consulting than from auditing has a financial incentive not to find the problems it is paid to find. The Sarbanes-Oxley Act of 2002 was the legislative response. It did not fix the structural conflict. It imposed process requirements on top of a broken model and declared victory. Today the Big Four make approximately three times their audit revenue from consulting — a ratio three times worse than Andersen's in 2001 — while auditing 97% of US public companies and virtually all systemically important financial institutions globally. Roughly one in four audits at some firms is currently deemed inadequate by the PCAOB. The problem is 100 times larger. The fix never came.
This paper documents a pattern of conduct across multiple named firms and individuals — from the KPMG Australia whistleblower scandal to the Mandelson/Palantir/OpenAI procurement questions to Purnell's appointment at Flint Global — that demonstrates a systematic failure of professional independence that is structural, not incidental. It then examines a new and largely unacknowledged layer of risk: the deployment of AI in audit and AML functions at scale, and the German court rulings of 2026 that have established the deploying organisation owns AI output as its own act.
The compliance function inside any firm whose business model depends on conflicts of interest cannot be genuinely independent. It will be captured, sidelined or complicit. Those are the only three options.
For every corporate client that engages these firms — as auditor, as adviser, as regulatory strategist — the question is not whether to trust them. It is whether your governance and compliance framework is asking the right questions about what these firms do with your information, whose interests they are actually serving and what they are not telling you. Plausible deniability has been allowed to cloak systematic law-breaking for too long. This paper names what it sees.
Enron was not a rogue trader. It was a machine for converting future promises into present revenue, using accounting rules as raw material. The core mechanism was mark-to-market accounting: Enron would sign a long-term contract and immediately book the projected future profits as current revenue — regardless of whether any cash had moved or whether the deal would ever pay out. The books looked spectacular. The underlying reality was a debt-laden shell.
At the time of its bankruptcy in December 2001, Enron had moved at least $27 billion — almost 50% of its total assets — off-balance-sheet into related special purpose entities to hide poorly performing assets and inflate income. This was not unknown to the people responsible for oversight. According to the Levin Center, the Board of Directors had been informed by Arthur Andersen that Enron was using high-risk accounting and extensive off-the-books activity — and the Board knowingly permitted both practices, explicitly approving the deceptive transactions. [Sources: Levin Center; Wikipedia.]
During 2000, Arthur Andersen earned $25 million in audit fees and $27 million in consulting fees from Enron alone. The consulting income exceeded the audit fees. That is the original sin: when your auditor makes more money advising you than checking you, the independence model has already failed — regardless of what the engagement letter says.
The Enron Board knew this. According to the Levin Center, the Board approved Andersen's dual roles as auditor and consultant, despite the obvious conflicts involved in the firm auditing its own advisory work while protecting its substantial consulting income. When the SEC investigation began, Andersen shredded documents. The firm was convicted of obstruction of justice and lost its licence to audit public companies. By the time the Supreme Court reversed the conviction on a technicality in 2005, Arthur Andersen had lost the majority of its clients and ceased operating. The Big Five became the Big Four.
The legislative response was the Sarbanes-Oxley Act 2002: tougher penalties for destroying financial records, mandatory independent audits, CEO and CFO personal certification of accounts, and new oversight via the Public Company Accounting Oversight Board (PCAOB). Everyone declared the lesson learned. It was not learned. It was rebranded.
The Big Four audit 97% of US public companies. With no meaningful competition, there is no market mechanism to reward better auditing. The $536,000 fine Deloitte paid in 2019 for its role in the 1MDB scandal was less than 0.001% of the firm's annual revenue — a parking ticket, proportionally. There is no deterrent. [Source: National Whistleblower Center.]
They are also paid to design the rules they will then fail to enforce. The Big Four are routinely engaged by governments to advise on post-crisis financial regulation — including the reforms that follow the failures their audits missed. According to the National Whistleblower Center, the fees they earned advising on financial reforms after 2008 far exceeded their losses from the crisis itself. The firms that failed to catch the crisis were paid to design its regulatory response.
Sarbanes-Oxley did not prevent: Wirecard (EY signed off on the accounts); 1MDB (Deloitte and others); Carillion (KPMG); NMC Health (EY); Patisserie Valerie; Thomas Cook — all passed by their Big Four auditors. More recently, EY Kenya in 2024 confessed to fraudulent and corrupt practices in a World Bank project in Somalia. PwC arms in Kenya, Rwanda and Mauritius admitted to fraudulent and collusive practices to secure a consultancy deal in Ethiopia. [Source: Daily Nation.] The system that failed at Enron in 2001 is structurally identical today. It is simply bigger, more global, more complex and more deeply woven into the machinery of the state. The problem is 100 times larger. The fix never came.
In a speech to the Australian Senate on 24 March 2026, Labor Senator Deborah O'Neill shared the testimony of a KPMG whistleblower under parliamentary privilege. [Source: Australian Senate Hansard, 24 March 2026; reported by The Guardian, 9 June 2026.] The allegation, as stated by Senator O'Neill in parliament: senior KPMG partners had repeatedly shared clients' confidential information internally to help other parts of the firm win audit mandates. The watchdog was using its clients' secrets as a competitive weapon.
Senator O'Neill named, under parliamentary privilege, partners Eileen Hoggett and Paul Rogers as having allegedly shared confidential information from audit client Lendlease with other KPMG staff to help win further contracts. These are allegations made under parliamentary privilege; ASIC's investigation is ongoing and no findings of fact have been published at the time of writing. The alleged victims included Lendlease — audited by KPMG for decades and paying approximately $10 million a year in fees — alongside Macquarie Group, Westpac, Dexus and Telstra. [Source: Australian Senate Hansard, 24 March 2026.]
KPMG's response to the whistleblower is itself instructive. KPMG confirmed it was aware of the allegations since early 2024. Its own statement acknowledged its initial investigation "was not rigorous enough." A second review was commissioned, then a third by law firm Allens, then a fourth — because Allens is now challenging its own previous findings. This is not, in this paper's analytical opinion, investigation. It is delay architecture: each successive review buying time and diluting accountability.
ASIC has confirmed it is formally investigating Hoggett and Rogers. [Source: ASIC Senate estimates testimony, reported by The Guardian, 9 June 2026.] KPMG's Australian chief executive Andrew Yates and national managing partner of audit Julian McPherson have resigned. KPMG faces scrutiny of over $650 million in active Australian government contracts.
KPMG's compliance and MLRO function knew, or had reasonable grounds to know, about the whistleblower's allegations from early 2024 — over two years before parliamentary disclosure. The obligation under POCA 2002 s.330 is not triggered by proof. It is triggered by reasonable grounds for suspicion. Conduct that generates commercial advantage through the misuse of confidential client information is capable of constituting a money laundering predicate under the Fraud Act 2006. The MLRO's position requires examination.
The KPMG scandal broke against the backdrop of a structurally identical case at PwC. According to The Guardian's reporting, a PwC partner was found to have leaked confidential Australian government tax policy to clients in Australia and the United States to help them structure their affairs to avoid the incoming legislation. The clients were paying for intelligence the government had shared with PwC in confidence, as a trusted professional adviser on the very policy being exploited.
According to The Guardian, the Australian government banned PwC from competing for new government work for two years. The value of government contracts signed with the Big Four fell from $218 million in 2021–22 to $114 million in 2024–25. Australian Federal Police investigations were opened. A Senate inquiry heard evidence. Senator O'Neill's assessment, stated on the public record to the ABC: "If a company like KPMG can do that to Lendlease, they can do it to anyone." [Source: Senator Deborah O'Neill, ABC interview, June 2026, reported by The Guardian.] The same analytical observation applies to PwC.
Peter Mandelson co-founded and part-owned Global Counsel, a London-based advisory firm. According to The Guardian, in 2024 Global Counsel's clients included OpenAI — the maker of ChatGPT, valued at $500 billion — and Palantir, the US defence and data analytics company. Both engagements were declared on the official lobbying register. [Source: The Guardian, 2026.] In 2024, Keir Starmer appointed Mandelson as UK Ambassador to Washington.
According to The Guardian, in the summer of 2024 OpenAI signed a memorandum of understanding with the UK government to develop AI partnerships across justice, security and education. In September 2024, it signed a deal to provide 2,500 ChatGPT licences to UK civil servants, starting in the Ministry of Justice. According to The Guardian, Palantir has secured more than £500 million in contracts with the NHS and the Ministry of Defence. The MoD awarded Palantir a £241 million military contract without an open competitive tender.
According to The Guardian, a meeting took place between Prime Minister Starmer, Mandelson and Palantir's chief executive at Palantir's Washington DC showroom before the contract was awarded, and that meeting was not minuted. When asked whether Starmer and Mandelson knew at the time of the Washington meeting that Palantir was a client of Mandelson's firm, ministers declined to answer directly. The shadow defence secretary asked why the meeting was not minuted. The minister said the government intended to "publish as much material as we can as soon as reasonably possible." [Source: The Guardian, 2026.]
According to The Guardian, George Osborne, former UK Chancellor of the Exchequer, has since been appointed as OpenAI's "Head of OpenAI for Countries." His knowledge of how UK government procurement decisions are structured and delivered is not incidental to that role.
James Purnell served in the Blair Cabinet and resigned from Parliament in 2009. According to The Guardian and reporting by Open Democracy and City AM, he became CEO of Flint Global in 2024. Flint is a high-end strategic advisory and lobbying firm whose clients, according to its EU transparency register filings and open-source reporting, have included Uber, Amazon, BP, Airbnb, Apple (its European arm was paid over €1 million to lobby on Apple's behalf), Google, Microsoft and Glencore.
According to The Guardian, Flint does not publish its UK client list and does not subscribe to voluntary transparency codes. It exploits the narrow scope of the Transparency of Lobbying Act 2014 to avoid its limited disclosure requirements. Its UK activities are structurally invisible to public scrutiny. According to The Guardian, Flint is majority-owned by private equity firm Cinven, with its ownership held through a Jersey-based holding company. The beneficial ownership chain is deliberately opaque.
According to The Guardian and City AM, Purnell was appointed as chief of staff to Prime Minister Andy Burnham. At the time of appointment, Flint was providing strategic advice to Thames Water's junior bondholders — who were engaged in a financial battle for control of the company as the government was considering public ownership. Burnham has publicly stated that Thames Water should be nationalised. According to The Guardian, Purnell's incoming employer was advising the parties fighting precisely that outcome. According to City AM, Flint was also working with hotel magnate Surinder Arora on his Heathrow Reimagined campaign — a live rival bid to shape the operation of the third runway expansion. According to Open Democracy, Purnell has since resigned from Flint and given up his shares. He deleted or privatised his LinkedIn profile.
Flint Global is not a professional partnership. It is a commercial asset owned by a private equity firm. When Flint advises clients on government relations, regulatory strategy or contested corporate transactions, the ultimate beneficiary of that advice includes Cinven's return on investment. That conflict is invisible in every transparency framework that currently exists. The clients who believed they were receiving independent strategic counsel were receiving advice filtered through the commercial interests of a leveraged PE vehicle.
The structural problems documented in Sections 1 to 3 are not new. What is new — and what the accounting and audit profession has not yet seriously confronted — is the addition of artificial intelligence to the audit process at scale, at the precise moment that courts are beginning to establish who owns AI output when it is wrong.
The case has been granted leave to appeal to the German Federal Court of Justice, which will set binding national precedent. UK courts will watch it closely.
The principle these courts have established — the organisation deploying the AI owns the output as its own act — maps directly onto the audit context in the most uncomfortable direction possible for the Big Four. Audit firms are racing to deploy AI to reduce the cost of audit work. Junior associate hours, historically the engine of due diligence volume, are being replaced by models. Audit fees remain high. Liability disclaimers remain buried in engagement letters. The German courts are now saying: "The AI got it wrong" is not a defence. "We did not know the AI would do that" is not a defence.
If a Big Four firm deploys an AI system to conduct audit procedures, flag risks or produce findings — and that system misses a fraud, produces a materially false risk assessment, or issues a clean bill of health on a balance sheet that conceals liabilities — the firm owns that output as its own professional act. The partner who reviewed a dashboard summary of the AI's work, rather than the underlying transactions, has not discharged the firm's liability. They have accepted it.
In 2001, Arthur Andersen could at least argue that human professionals made the relevant calls — however corruptly, however negligently. The accountability chain ran through identifiable individuals who took identifiable decisions. Sarbanes-Oxley was built on that premise: certify the accounts personally, name the responsible senior manager, impose individual liability.
In an AI-assisted audit environment, if a model signs off on a Wirecard-scale fraud and the engagement partner reviews only a summary dashboard, the accountability chain does not merely weaken — it dissolves in a way the current regulatory framework was not designed to address. The German courts are beginning to reconstruct it. The EU AI Act tightens the liability architecture further from August 2026, requiring transparent disclosure when users are communicating with AI (Article 50) and establishing operator liability for high-risk AI system outputs. The accounting profession is sleepwalking into this.
For MLROs and compliance professionals, the AI liability question generates a specific obligation that most financial crime frameworks have not yet addressed: when your institution relies on AI-generated outputs to make AML decisions — transaction monitoring alerts, risk scoring, SAR triage — and that system produces a false negative that masks a predicate offence, who is responsible?
The Money Laundering Regulations 2017 impose obligations on the regulated firm, not on the AI provider. The POCA 2002 s.330 failure-to-disclose obligation runs to the compliance professional, not to the model. The German framework confirms what the statutory position already implies: the organisation deploying the AI owns its output. An MLRO who relies on an AI triage system that suppresses a SAR filing cannot point to the system as the reason the SAR was not filed. They filed nothing. The obligation is theirs.
AI deployment in AML functions requires the same governance as any other material control: documented validation, ongoing monitoring, clear escalation paths when the model's output is uncertain, and named human accountability for the decisions that flow from it.
The MLRO who has spent years defending the indefensible — managing upwards, absorbing institutional pressure not to file, rationalising non-disclosure as "insufficient grounds for suspicion" — has historically operated in an environment where the key protection was information asymmetry. Investigators could not easily reconstruct what the compliance function knew, when it knew it, and what it chose not to do. The volume of communications, the informality of senior management conversations, the absence of written records of decisions not taken — these created the fog inside which plausible deniability lived.
AI forensics eliminates that fog.
When regulators, prosecutors or civil litigants deploy AI investigative tools against a firm — and this is already happening in major enforcement cases — they are not reading documents sequentially. They are querying. "At what date did this individual's email traffic indicate awareness of this transaction pattern?" "Which compliance system access logs show this MLRO queried this account?" "What is the probability, based on the information available to this person on this date, that they had reasonable grounds for suspicion under POCA 2002 s.330?" These are not questions a human investigator could answer efficiently across a million documents. They are precisely the questions AI answers well.
The audit trail that AI creates when embedded in compliance systems works in both directions. AI-assisted transaction monitoring logs every alert generated, every alert suppressed, every threshold applied and every decision made — or not made. That log is discoverable. An MLRO who relied on an AI system to triage alerts, and who cannot demonstrate that the system's suppression logic was validated, monitored and periodically reviewed, has not created a shield. They have created a forensic record of systemic non-compliance.
The plausible deniability era is ending. The compliance professional who sat in Position 2 (Sidelined) and claimed not to know — AI reconstruction of their email access, system queries, meeting calendars and internal communication patterns will rapidly establish the boundary between what they could not have known and what they chose not to pursue. The Big Four partners who approved Enron's off-balance-sheet vehicles relied on the complexity of the structure and the volume of the paperwork as protection. Those protections erode dramatically when an AI system can ingest the entire transaction history of a firm, identify the anomalies, trace the approval chains and surface the communications in which those anomalies were discussed — in hours rather than years.
The MLRO who currently believes they are navigating institutional pressure successfully by not asking the questions whose answers would require them to act should understand that their institution's AI systems are generating the answers anyway. The question is simply who gets to ask them first — the compliance function, or the investigators.
AI has a way of biting you in the arse. The profession has not yet reckoned with how comprehensively.
If you are an MLRO or compliance director at a Big Four firm, a lobbying advisory firm or any professional services organisation operating in the space described above, your function is in one of three positions. There is no fourth option.
You are aware of the conflicts. You have been briefed — formally or informally — on client relationships that create material tensions with your firm's independence obligations. You have assessed those conflicts. You have concluded, under commercial pressure, under seniority pressure, under the implicit or explicit understanding that revenue-generating partners are not to be challenged, that the conflicts are manageable. You have documented the assessment. The documentation is the shield, not the conclusion.
You are not aware. Senior partners do not route their decisions through compliance when those decisions involve the firm's most profitable relationships. Your mandate formally extends to the whole firm. In practice, it extends to the activities of junior and mid-level staff. The partners who sit on audit committees, who managed the Lendlease relationship, who attended meetings that are now the subject of parliamentary inquiry — they did not consult you, and no one expected them to.
You are aware. You have concluded, for whatever mix of career, commercial and institutional reasons, that raising the issue is more professionally dangerous than not raising it. You have not filed. You have not escalated. You have not documented your concern in a form that creates a paper trail you cannot later deny.
The law does not permit any of these three positions without consequence.
POCA 2002 s.330 (failure to disclose in the regulated sector) applies to any individual in the regulated sector who knows or suspects that another person is engaged in money laundering and fails to make an authorised disclosure as soon as practicable. The Money Laundering Regulations 2017 designate accountancy firms as regulated entities. The duty is not contingent on certainty. It is triggered by reasonable grounds for suspicion.
The KPMG whistleblower went to KPMG Australia's executives, board members and KPMG International. They were not given a hearing. They then went to Parliament. The compliance function's role is to be the route between the first two steps and the third. That it apparently was not is the sharpest indictment of the "Position 2: Sidelined" scenario in recent corporate history.
SM&CR — the Senior Managers and Certification Regime — applies to FCA-regulated firms. Under SM&CR, the MLRO is a named Senior Management Function (SMF17). Personal liability for failures within their function is not theoretical. The Woodford case demonstrated that SM&CR can produce zero individual accountability when regulators choose not to use it. That is a regulatory failure, not a legal one. The legal exposure remains.
The following questions are not currently asked of Big Four firms or advisory businesses as a matter of standard due diligence. They are not asked because the firms concerned have spent considerable effort shaping the frameworks that govern what questions are expected.
Who are their other clients in our sector, our regulatory space and our competitive market? What conflicts exist between our engagement and those other mandates? The answer "we have a conflicts policy" is not an answer. A conflicts policy that operates on self-assessment, without external verification or disclosure to the affected client, is a mechanism for managing the appearance of independence, not its substance.
The KPMG Australia case is not an aberration. It is the auditor's model exposed. Every partner with access to your books has relationships, incentives and commercial pressures that extend beyond your engagement. Your financial position, your strategic plans, your operational vulnerabilities, your regulatory exposures — all of this enters the firm's information environment. Where does it go when it leaves your building in their heads?
A firm that simultaneously advises your regulator, your government department and your competitors is not providing you with independent advice. It is providing advice filtered through its other relationships. A firm advising both the government on procurement policy and a corporation bidding under that policy has an interest in the outcome that is not yours. What has it chosen not to tell you because telling you would disadvantage another client?
The Big Four advise governments on regulatory reform. They also advise the private sector on how to respond to it. The firms that consulted on the Money Laundering Regulations 2017 also advise on compliance with them. The firms that provided input on the Procurement Act 2023 also advise on securing government contracts under it. If your adviser helped write the regulation — and also advises your competitor on the same question — the information asymmetry is structural, not incidental.
Which clients receive the most current intelligence, the most senior attention, the most forthcoming advice? Is your organisation in the inner circle, or is your information feeding someone else's competitive position within it? Flint Global's refusal to publish its client list makes this question unanswerable for its clients. An unanswerable question about your adviser's other mandates is itself a material risk.
The answer, based on the cases in this paper, is no. They are commercial actors with multiple conflicting mandates, opaque ownership structures, government relationships that generate private benefit and a demonstrated willingness to exploit client information for competitive advantage. Proceeding on the assumption that they are neutral is not a due diligence failure. It is a governance failure.
The due diligence you apply to a new corporate client — mapping beneficial ownership, identifying conflicts of interest, assessing the independence of key individuals — should apply in full to any professional services firm you engage. Run the same KYC on KPMG that you would run on a high-risk client. Who are their significant shareholders? What is their regulatory history? Who are their other clients in your space?
A standard conflicts letter says "we have checked our records and identified no conflict." That is not sufficient. You need a written representation that names the firm's other clients in your sector, your regulatory space and your competitive market, and confirms that none of those relationships will affect the quality or independence of advice provided to you. If they refuse, that refusal is a risk indicator requiring escalation.
Compartmentalise what you share. Apply need-to-know principles. Do not share strategic information about M&A activity, regulatory submissions or competitive positioning with a firm that also serves your counterparties. The KPMG Australia case proves that internal information barriers between audit teams at the same firm are not reliably enforced. Do not assume your information is contained within the team you engaged.
Track the employment movements of senior individuals at your advisers and your regulators. When a senior partner at your audit firm joins your regulator — or vice versa — that relationship carries information. When a former minister joins the firm advising you on regulatory strategy, the question of what they know that you don't is live and material. Review this annually. Document the review.
If your analysis gives you reasonable grounds to suspect that your adviser's conduct in relation to your engagement — or another client's engagement — constitutes a money laundering predicate, your obligation under POCA 2002 s.330 is to file. The prestige of the firm does not alter the statutory threshold. The test is reasonable grounds for suspicion. Not proof. Not certainty. Suspicion.
Your firm has retained a Big Four firm for statutory audit for six years. You discover that the same firm's advisory division has been retained by your largest competitor for regulatory strategy advice for the past three years. The audit partner advises you this is managed through an internal firewall.
What documentation do you require? What is your assessment under FRC Ethical Standards for auditors? What are your obligations under POCA 2002 if you subsequently discover the firewall has been breached and the firm's advisory team has used knowledge of your financial position in its work for your competitor?
Your institution engages a strategic consultancy whose senior partner is a former Cabinet minister. The government is preparing to announce a regulatory change that will materially affect your sector. The partner appears to know the direction of the announcement before it is made.
How do you assess whether this constitutes inside information under MAR Article 7? What is your obligation under FSMA 2000 s.131A? Does it matter that the information reached you indirectly, through the adviser's commentary, rather than in explicit terms?
You are compliance director at a public sector contractor. A key government contract is awarded to a competitor without open tender. The competitor is a client of the lobbying firm that employs a former minister who attended pre-procurement meetings with the relevant department. The meetings were not fully minuted.
What financial crime indicators does this pattern raise? What is the threshold for a SAR under POCA 2002 in the absence of a proven predicate offence? Who in your organisation do you escalate to?
A junior member of your compliance team reports that a senior partner at your firm's external audit provider shared information about your company's forward financial guidance with a contact at a hedge fund. The information was not public at the time. You have no direct evidence — only the allegation.
What is your assessment process? What are your obligations under FSMA 2000 Part VIII regarding market abuse? At what point do you notify the FCA? What are the employment law protections for your team member under the Employment Rights Act 1996 s.47B (whistleblowing)?
Your organisation's audit firm also holds a substantial consulting mandate — advisory fees from your firm exceed its audit fees. During a routine review you discover that the audit team has not escalated a significant internal control weakness identified eighteen months ago. The consulting team, working on a separate transformation project, recommended a solution to that same control weakness — a solution your firm then contracted them to implement. The audit team signed off on the accounts in the interim without qualifying them.
What conflict of interest framework applies? At what point does this pattern constitute a breach of auditor independence under FRC Ethical Standards? What are your obligations as MLRO if you conclude the audit sign-off was compromised by commercial considerations?
Your institution's external auditor has deployed an AI system to conduct preliminary risk assessment across the transaction population. The engagement partner reviews a dashboard summary produced by the model and signs the audit opinion. Six months later, a fraud is discovered that was present in the transaction data the AI reviewed. The AI system produced no alert. The partner reviewed no underlying transactions.
Under the German courts' "deployer owns the output" principle, what is the audit firm's liability position? What questions should your institution's MLRO have asked about the auditor's AI methodology before accepting the audit opinion? Does the firm's standard engagement letter exclusion of liability for AI-assisted procedures hold?
Your institution's AML transaction monitoring system is AI-assisted. The model assigns risk scores to alerts and automatically suppresses those below a threshold before they reach human review. A SAR is later filed by a correspondent bank on a customer your system had scored as low-risk for eighteen consecutive months. The underlying pattern — structuring across multiple accounts with consistent just-below-threshold amounts — was present throughout. The MLRO was not aware: the AI suppressed the alerts.
Under POCA 2002 s.330, assess your personal liability position. What governance framework should have been in place? What does the EU AI Act Article 50 require by August 2026 in relation to AI systems making decisions that affect individuals?
You are appointed MLRO at a large advisory firm. In your first month you identify three client relationships creating material conflicts with the firm's independence obligations. You escalate to the managing partner. You are told the conflicts are managed through approved procedures. You are not satisfied with the quality of those procedures. Senior management make clear that further escalation would be unwelcome.
What are your options under the FCA's prescribed person whistleblowing route? What is your personal liability under POCA 2002 s.330 if you do not file and misconduct is subsequently established? What does SM&CR SMF17 require of you in this position?
Flint Global's Jersey holding company and Cinven ownership are invisible under current UK disclosure requirements. The PSC register requirements should be extended to cover advisory firms, lobbying consultancies and any entity that seeks to influence government decision-making or regulatory outcomes, regardless of incorporation jurisdiction.
Audit firms should be required to disclose in writing to their audit clients any material new client relationship capable of affecting the independence of the audit engagement. The current regime requires periodic self-assessment. It does not require disclosure to the audited entity. This gap is where KPMG Australia operated for years.
ACOBA must be given statutory enforcement authority. Its recommendations must be binding. Breaches must carry published sanctions. Every case in this paper involves individuals whose conduct was within the letter — if not the spirit — of ACOBA guidance. The guidance is the problem.
The Economic Crime and Corporate Transparency Act 2023 applies to large organisations. The Big Four are large organisations. If a partner commits fraud — by misusing client information, by deploying government intelligence commercially, or by structuring advice to benefit one client at another's expense — the firm should face corporate criminal liability. The adequate procedures defence should require demonstrated effectiveness, not merely the existence of a policy.
The FRC and FCA must require audit firms and regulated entities deploying AI in audit, risk assessment or AML functions to maintain documented validation records, human review escalation protocols and named accountability for AI-assisted conclusions. Engagement letter exclusions of liability for AI-assisted procedures must not be permitted to circumvent the fundamental duty of care. The German courts have established the principle: deployer owns the output. UK regulators must embed it in sector-specific rules before the next Wirecard-scale failure demonstrates that they did not.
The Transparency of Lobbying Act 2014 captures a fraction of actual influence activity. A statutory register with real scope must capture all paid attempts to influence government decision-making, regardless of the vehicle — advisory firms, think tanks, former officials operating as individual consultants, or firms structured to avoid the current register's definitions. Voluntary codes have failed. The architecture of evasion is more sophisticated than the architecture of disclosure.
The cases documented in this paper share a structural feature that goes beyond individual misconduct. In each instance, the firm or individual at the centre of the controversy was operating precisely as their business model intended. KPMG's auditors were maximising revenue from existing client relationships. Global Counsel was deploying its principal's political network to commercial advantage. Flint Global was providing high-value advisory services to clients with competing interests in live government decisions. The misconduct is not a deviation from the model. In several cases, it is the model.
For compliance professionals, this is the most important conclusion. Due diligence frameworks, conflicts of interest policies and independence standards were designed on the assumption that professional services firms are, at minimum, attempting to operate neutrally. That assumption requires examination.
The auditor is not neutral. The lobbying adviser is not neutral. The former official who joins a consultancy and deploys their government relationships for commercial clients is not neutral. The firm structured through a Jersey holding company owned by private equity, that refuses to publish its client list, that has lobbied against the transparency rules that would reveal its conflicts, is not neutral.
The question for every MLRO, compliance director and board that engages these firms is not "do we trust them?" It is the more precise and answerable question: "What can we verify?" If the answer is less than everything that matters, you are carrying a risk your compliance framework has not priced.
The paragraphs naming Hoggett and Rogers specifically should be reviewed by a UK defamation specialist before the paper goes live. This is a one-hour exercise. The cost is modest. The benefit is documented evidence of reasonable care under s.4, which strengthens the public interest defence if challenged. Do not rely solely on this checklist — it is not a substitute for qualified legal advice on the specific paragraphs.
This white paper has been produced for educational purposes and as fair comment on matters of public record, in the public interest.
Factual statements in this paper are drawn exclusively from the following categories of publicly available source: proceedings of the Australian Senate under parliamentary privilege (Senator Deborah O'Neill, 24 March 2026); official findings and testimony of the Australian Securities and Investments Commission; declared entries on the UK statutory lobbying register; published proceedings of UK parliamentary inquiries; investigative reporting by The Guardian (published 9 June 2026); and supplementary open-source reporting by Open Democracy, City AM and Labour Hub. All factual statements are attributed to their source inline. Where The Guardian is cited as the source, the underlying facts were reported by its journalists and this paper relies on that published reporting.
Analytical statements and conclusions — including characterisations of conduct patterns, assessments of regulatory adequacy and inferences drawn from documented facts — constitute the honest opinion of the author, formed on the basis of the facts cited. They are clearly distinguishable from factual statements and are expressed as opinion throughout.
Named individuals: All individuals named in this paper are named on the basis of official records, parliamentary proceedings or declared public registers. Where allegations are subject to ongoing investigation, this is stated explicitly. Nothing in this paper constitutes an allegation of criminality beyond what has been established in official proceedings or formally investigated by competent authorities.
This paper does not constitute legal advice. Philip Faulkner trading as Netizen 9 is not a law firm and does not provide legal services. Readers requiring legal advice on specific matters should seek qualified legal counsel.
Levin Center (Carl Levin Center for Oversight and Democracy) · Australian Senate Hansard, 24 March 2026 · ASIC Senate estimates testimony · The Guardian, 9 June 2026 · Open Democracy · City AM · Labour Hub · National Whistleblower Center · Best Practice Group / World Finance · Daily Nation · Project on Government Oversight · Lexology / MME Legal · Grunecker / Leaders League · ERP Today
Kim — AML & Compliance Intelligence | kim.amledtech.uk