Compliance Framework Paper 02
Auditors · Advisers · Regulatory Capture · AI Liability
The Captured Watchdog
Auditors, Advisers and the
Compromised Inner Circle
How the structural conflicts at the heart of the Big Four audit model, the revolving door advisory market and AI-assisted compliance are converging to eliminate individual accountability — and why plausible deniability can no longer cloak systematic law-breaking.
AML Edtech
kim.amledtech.uk
June 2026
This paper is produced for educational and compliance training purposes. It does not constitute legal advice. All individuals named are identified on the basis of official records, parliamentary proceedings or declared public registers. See full legal notices on the final content page.
Executive Summary

The Model Exposed

The professional services firms at the centre of UK and global business — the Big Four audit and advisory firms, the lobbying consultancies staffed by former ministers, the strategic advisory businesses structured to avoid transparency disclosure — present themselves as independent, expert and neutral. They are none of these things.

In 2001, the collapse of Enron and the destruction of Arthur Andersen exposed the structural conflict at the heart of the audit model: an auditor that makes more money from consulting than from auditing has a financial incentive not to find the problems it is paid to find. The Sarbanes-Oxley Act of 2002 was the legislative response. It did not fix the structural conflict. It imposed process requirements on top of a broken model and declared victory. Today the Big Four make approximately three times their audit revenue from consulting — a ratio three times worse than Andersen's in 2001 — while auditing 97% of US public companies and virtually all systemically important financial institutions globally. Roughly one in four audits at some firms is currently deemed inadequate by the PCAOB. The problem is 100 times larger. The fix never came.

Consulting-to-audit fee ratio at Big Four today — 3x worse than Andersen in 2001
97%
US public companies audited by the Big Four — effective oligopoly, no competitive pressure
27%
EY audit failure rate (PCAOB) — roughly 1 in 4 audits inadequate at some firms
0.001%
1MDB fine as % of Deloitte annual revenue — a parking ticket. No deterrent.

This paper documents a pattern of conduct across multiple named firms and individuals — from the KPMG Australia whistleblower scandal to the Mandelson/Palantir/OpenAI procurement questions to Purnell's appointment at Flint Global — that demonstrates a systematic failure of professional independence that is structural, not incidental. It then examines a new and largely unacknowledged layer of risk: the deployment of AI in audit and AML functions at scale, and the German court rulings of 2026 that have established the deploying organisation owns AI output as its own act.

The compliance function inside any firm whose business model depends on conflicts of interest cannot be genuinely independent. It will be captured, sidelined or complicit. Those are the only three options.

Central argument

For every corporate client that engages these firms — as auditor, as adviser, as regulatory strategist — the question is not whether to trust them. It is whether your governance and compliance framework is asking the right questions about what these firms do with your information, whose interests they are actually serving and what they are not telling you. Plausible deniability has been allowed to cloak systematic law-breaking for too long. This paper names what it sees.

Section 1

The Founding Scandal: Enron and the Original Sin

1.1 What Enron Actually Was

Enron was not a rogue trader. It was a machine for converting future promises into present revenue, using accounting rules as raw material. The core mechanism was mark-to-market accounting: Enron would sign a long-term contract and immediately book the projected future profits as current revenue — regardless of whether any cash had moved or whether the deal would ever pay out. The books looked spectacular. The underlying reality was a debt-laden shell.

At the time of its bankruptcy in December 2001, Enron had moved at least $27 billion — almost 50% of its total assets — off-balance-sheet into related special purpose entities to hide poorly performing assets and inflate income. This was not unknown to the people responsible for oversight. According to the Levin Center, the Board of Directors had been informed by Arthur Andersen that Enron was using high-risk accounting and extensive off-the-books activity — and the Board knowingly permitted both practices, explicitly approving the deceptive transactions. [Sources: Levin Center; Wikipedia.]

$63bn
Total assets in the Enron collapse — the largest US bankruptcy to that date
25,000
Employees who lost their jobs. $2bn in pension savings and $1.2bn in retirement funds wiped out
62%
Of 15,000 savings plan holders had relied on Enron stock at $83/share — subsequently worthless

1.2 The Arthur Andersen Problem

During 2000, Arthur Andersen earned $25 million in audit fees and $27 million in consulting fees from Enron alone. The consulting income exceeded the audit fees. That is the original sin: when your auditor makes more money advising you than checking you, the independence model has already failed — regardless of what the engagement letter says.

The Enron Board knew this. According to the Levin Center, the Board approved Andersen's dual roles as auditor and consultant, despite the obvious conflicts involved in the firm auditing its own advisory work while protecting its substantial consulting income. When the SEC investigation began, Andersen shredded documents. The firm was convicted of obstruction of justice and lost its licence to audit public companies. By the time the Supreme Court reversed the conviction on a technicality in 2005, Arthur Andersen had lost the majority of its clients and ceased operating. The Big Five became the Big Four.

1.3 The Fix That Fixed Nothing — The 100× Problem

The legislative response was the Sarbanes-Oxley Act 2002: tougher penalties for destroying financial records, mandatory independent audits, CEO and CFO personal certification of accounts, and new oversight via the Public Company Accounting Oversight Board (PCAOB). Everyone declared the lesson learned. It was not learned. It was rebranded.

The Structural Conflict — Never Fixed

Consulting revenues at 3× audit, across 4 firms that audit virtually everything

The Big Four today make as much as three times their audit fees from consulting — the same structural conflict that destroyed Andersen, at 3× the ratio, across four firms that now audit virtually everything. The disincentive to anger a client by reporting internal control failures is three times stronger than it was at Andersen in 2001. [Source: National Whistleblower Center.]
The oligopoly problem

The Big Four audit 97% of US public companies. With no meaningful competition, there is no market mechanism to reward better auditing. The $536,000 fine Deloitte paid in 2019 for its role in the 1MDB scandal was less than 0.001% of the firm's annual revenue — a parking ticket, proportionally. There is no deterrent. [Source: National Whistleblower Center.]

They are also paid to design the rules they will then fail to enforce. The Big Four are routinely engaged by governments to advise on post-crisis financial regulation — including the reforms that follow the failures their audits missed. According to the National Whistleblower Center, the fees they earned advising on financial reforms after 2008 far exceeded their losses from the crisis itself. The firms that failed to catch the crisis were paid to design its regulatory response.

1.4 The Post-Enron Failures That Slipped Through

Sarbanes-Oxley did not prevent: Wirecard (EY signed off on the accounts); 1MDB (Deloitte and others); Carillion (KPMG); NMC Health (EY); Patisserie Valerie; Thomas Cook — all passed by their Big Four auditors. More recently, EY Kenya in 2024 confessed to fraudulent and corrupt practices in a World Bank project in Somalia. PwC arms in Kenya, Rwanda and Mauritius admitted to fraudulent and collusive practices to secure a consultancy deal in Ethiopia. [Source: Daily Nation.] The system that failed at Enron in 2001 is structurally identical today. It is simply bigger, more global, more complex and more deeply woven into the machinery of the state. The problem is 100 times larger. The fix never came.

Section 2

The Auditor Betrayal: The Model Exposed in the Present Tense

2.1 KPMG Australia: Your Confidential Information as a Sales Tool

In a speech to the Australian Senate on 24 March 2026, Labor Senator Deborah O'Neill shared the testimony of a KPMG whistleblower under parliamentary privilege. [Source: Australian Senate Hansard, 24 March 2026; reported by The Guardian, 9 June 2026.] The allegation, as stated by Senator O'Neill in parliament: senior KPMG partners had repeatedly shared clients' confidential information internally to help other parts of the firm win audit mandates. The watchdog was using its clients' secrets as a competitive weapon.

Senator O'Neill named, under parliamentary privilege, partners Eileen Hoggett and Paul Rogers as having allegedly shared confidential information from audit client Lendlease with other KPMG staff to help win further contracts. These are allegations made under parliamentary privilege; ASIC's investigation is ongoing and no findings of fact have been published at the time of writing. The alleged victims included Lendlease — audited by KPMG for decades and paying approximately $10 million a year in fees — alongside Macquarie Group, Westpac, Dexus and Telstra. [Source: Australian Senate Hansard, 24 March 2026.]

KPMG's response to the whistleblower is itself instructive. KPMG confirmed it was aware of the allegations since early 2024. Its own statement acknowledged its initial investigation "was not rigorous enough." A second review was commissioned, then a third by law firm Allens, then a fourth — because Allens is now challenging its own previous findings. This is not, in this paper's analytical opinion, investigation. It is delay architecture: each successive review buying time and diluting accountability.

ASIC has confirmed it is formally investigating Hoggett and Rogers. [Source: ASIC Senate estimates testimony, reported by The Guardian, 9 June 2026.] KPMG's Australian chief executive Andrew Yates and national managing partner of audit Julian McPherson have resigned. KPMG faces scrutiny of over $650 million in active Australian government contracts.

Laws and standards engaged
The MLRO question

KPMG's compliance and MLRO function knew, or had reasonable grounds to know, about the whistleblower's allegations from early 2024 — over two years before parliamentary disclosure. The obligation under POCA 2002 s.330 is not triggered by proof. It is triggered by reasonable grounds for suspicion. Conduct that generates commercial advantage through the misuse of confidential client information is capable of constituting a money laundering predicate under the Fraud Act 2006. The MLRO's position requires examination.

2.2 PwC Australia: Selling Government Policy to the Private Sector

The KPMG scandal broke against the backdrop of a structurally identical case at PwC. According to The Guardian's reporting, a PwC partner was found to have leaked confidential Australian government tax policy to clients in Australia and the United States to help them structure their affairs to avoid the incoming legislation. The clients were paying for intelligence the government had shared with PwC in confidence, as a trusted professional adviser on the very policy being exploited.

According to The Guardian, the Australian government banned PwC from competing for new government work for two years. The value of government contracts signed with the Big Four fell from $218 million in 2021–22 to $114 million in 2024–25. Australian Federal Police investigations were opened. A Senate inquiry heard evidence. Senator O'Neill's assessment, stated on the public record to the ABC: "If a company like KPMG can do that to Lendlease, they can do it to anyone." [Source: Senator Deborah O'Neill, ABC interview, June 2026, reported by The Guardian.] The same analytical observation applies to PwC.

Laws and standards engaged
Section 3

The Revolving Door as Procurement Mechanism

3.1 Mandelson, Global Counsel and the Untendered Contract

Peter Mandelson co-founded and part-owned Global Counsel, a London-based advisory firm. According to The Guardian, in 2024 Global Counsel's clients included OpenAI — the maker of ChatGPT, valued at $500 billion — and Palantir, the US defence and data analytics company. Both engagements were declared on the official lobbying register. [Source: The Guardian, 2026.] In 2024, Keir Starmer appointed Mandelson as UK Ambassador to Washington.

According to The Guardian, in the summer of 2024 OpenAI signed a memorandum of understanding with the UK government to develop AI partnerships across justice, security and education. In September 2024, it signed a deal to provide 2,500 ChatGPT licences to UK civil servants, starting in the Ministry of Justice. According to The Guardian, Palantir has secured more than £500 million in contracts with the NHS and the Ministry of Defence. The MoD awarded Palantir a £241 million military contract without an open competitive tender.

According to The Guardian, a meeting took place between Prime Minister Starmer, Mandelson and Palantir's chief executive at Palantir's Washington DC showroom before the contract was awarded, and that meeting was not minuted. When asked whether Starmer and Mandelson knew at the time of the Washington meeting that Palantir was a client of Mandelson's firm, ministers declined to answer directly. The shadow defence secretary asked why the meeting was not minuted. The minister said the government intended to "publish as much material as we can as soon as reasonably possible." [Source: The Guardian, 2026.]

According to The Guardian, George Osborne, former UK Chancellor of the Exchequer, has since been appointed as OpenAI's "Head of OpenAI for Countries." His knowledge of how UK government procurement decisions are structured and delivered is not incidental to that role.

Laws and standards engaged

3.2 Purnell, Flint Global and the Architecture of Opacity

James Purnell served in the Blair Cabinet and resigned from Parliament in 2009. According to The Guardian and reporting by Open Democracy and City AM, he became CEO of Flint Global in 2024. Flint is a high-end strategic advisory and lobbying firm whose clients, according to its EU transparency register filings and open-source reporting, have included Uber, Amazon, BP, Airbnb, Apple (its European arm was paid over €1 million to lobby on Apple's behalf), Google, Microsoft and Glencore.

According to The Guardian, Flint does not publish its UK client list and does not subscribe to voluntary transparency codes. It exploits the narrow scope of the Transparency of Lobbying Act 2014 to avoid its limited disclosure requirements. Its UK activities are structurally invisible to public scrutiny. According to The Guardian, Flint is majority-owned by private equity firm Cinven, with its ownership held through a Jersey-based holding company. The beneficial ownership chain is deliberately opaque.

According to The Guardian and City AM, Purnell was appointed as chief of staff to Prime Minister Andy Burnham. At the time of appointment, Flint was providing strategic advice to Thames Water's junior bondholders — who were engaged in a financial battle for control of the company as the government was considering public ownership. Burnham has publicly stated that Thames Water should be nationalised. According to The Guardian, Purnell's incoming employer was advising the parties fighting precisely that outcome. According to City AM, Flint was also working with hotel magnate Surinder Arora on his Heathrow Reimagined campaign — a live rival bid to shape the operation of the third runway expansion. According to Open Democracy, Purnell has since resigned from Flint and given up his shares. He deleted or privatised his LinkedIn profile.

Laws and standards engaged
The Cinven dimension

Flint Global is not a professional partnership. It is a commercial asset owned by a private equity firm. When Flint advises clients on government relations, regulatory strategy or contested corporate transactions, the ultimate beneficiary of that advice includes Cinven's return on investment. That conflict is invisible in every transparency framework that currently exists. The clients who believed they were receiving independent strategic counsel were receiving advice filtered through the commercial interests of a leveraged PE vehicle.

Section 4

The AI Dimension: A New Layer of Unaccountability

The structural problems documented in Sections 1 to 3 are not new. What is new — and what the accounting and audit profession has not yet seriously confronted — is the addition of artificial intelligence to the audit process at scale, at the precise moment that courts are beginning to establish who owns AI output when it is wrong.

4.1 What the German Courts Have Now Said

Higher Regional Court of Hamm — 12 May 2026 (I-4 UKl 3/25)

"Whoever uses the bot is responsible for its output"

A cosmetic surgery clinic used an AI chatbot to schedule appointments and answer patient questions. When asked, the bot described the managing directors as holding specialist titles they did not hold. The clinic was ordered to cease and desist. The court held that the chatbot's incorrect responses constituted misleading commercial acts by the company. The AI provider was not liable. The deploying organisation was liable — for hallucinations it could not have predicted and did not generate. [Source: Lexology / MME Legal.]
Precedent status

The case has been granted leave to appeal to the German Federal Court of Justice, which will set binding national precedent. UK courts will watch it closely.

Regional Court of Munich I — 28 May 2026 (26 O 869/26)

AI-generated content is the operator's own content

The Munich court held that a search engine operator was responsible for false statements in an AI-generated search overview. The AI selected, combined and structured information from multiple sources and presented it as a coherent self-contained response. The court treated that output as the operator's own content. Google argued that users could check linked sources. The court rejected that defence. [Source: Grunecker / Leaders League; ERP Today.] The court's prescribed remedy: topic filters, guardrails, escalation to human review, ongoing monitoring and spot checks.

4.2 Why This Is Explosive for the Audit Profession

The principle these courts have established — the organisation deploying the AI owns the output as its own act — maps directly onto the audit context in the most uncomfortable direction possible for the Big Four. Audit firms are racing to deploy AI to reduce the cost of audit work. Junior associate hours, historically the engine of due diligence volume, are being replaced by models. Audit fees remain high. Liability disclaimers remain buried in engagement letters. The German courts are now saying: "The AI got it wrong" is not a defence. "We did not know the AI would do that" is not a defence.

If a Big Four firm deploys an AI system to conduct audit procedures, flag risks or produce findings — and that system misses a fraud, produces a materially false risk assessment, or issues a clean bill of health on a balance sheet that conceals liabilities — the firm owns that output as its own professional act. The partner who reviewed a dashboard summary of the AI's work, rather than the underlying transactions, has not discharged the firm's liability. They have accepted it.

4.3 The Enron Parallel

In 2001, Arthur Andersen could at least argue that human professionals made the relevant calls — however corruptly, however negligently. The accountability chain ran through identifiable individuals who took identifiable decisions. Sarbanes-Oxley was built on that premise: certify the accounts personally, name the responsible senior manager, impose individual liability.

In an AI-assisted audit environment, if a model signs off on a Wirecard-scale fraud and the engagement partner reviews only a summary dashboard, the accountability chain does not merely weaken — it dissolves in a way the current regulatory framework was not designed to address. The German courts are beginning to reconstruct it. The EU AI Act tightens the liability architecture further from August 2026, requiring transparent disclosure when users are communicating with AI (Article 50) and establishing operator liability for high-risk AI system outputs. The accounting profession is sleepwalking into this.

4.4 The MLRO Implication

For MLROs and compliance professionals, the AI liability question generates a specific obligation that most financial crime frameworks have not yet addressed: when your institution relies on AI-generated outputs to make AML decisions — transaction monitoring alerts, risk scoring, SAR triage — and that system produces a false negative that masks a predicate offence, who is responsible?

The Money Laundering Regulations 2017 impose obligations on the regulated firm, not on the AI provider. The POCA 2002 s.330 failure-to-disclose obligation runs to the compliance professional, not to the model. The German framework confirms what the statutory position already implies: the organisation deploying the AI owns its output. An MLRO who relies on an AI triage system that suppresses a SAR filing cannot point to the system as the reason the SAR was not filed. They filed nothing. The obligation is theirs.

AI deployment in AML functions requires the same governance as any other material control: documented validation, ongoing monitoring, clear escalation paths when the model's output is uncertain, and named human accountability for the decisions that flow from it.

4.5 The Investigative Mirror: When AI Turns on the Compliance Function

The MLRO who has spent years defending the indefensible — managing upwards, absorbing institutional pressure not to file, rationalising non-disclosure as "insufficient grounds for suspicion" — has historically operated in an environment where the key protection was information asymmetry. Investigators could not easily reconstruct what the compliance function knew, when it knew it, and what it chose not to do. The volume of communications, the informality of senior management conversations, the absence of written records of decisions not taken — these created the fog inside which plausible deniability lived.

AI forensics eliminates that fog.

When regulators, prosecutors or civil litigants deploy AI investigative tools against a firm — and this is already happening in major enforcement cases — they are not reading documents sequentially. They are querying. "At what date did this individual's email traffic indicate awareness of this transaction pattern?" "Which compliance system access logs show this MLRO queried this account?" "What is the probability, based on the information available to this person on this date, that they had reasonable grounds for suspicion under POCA 2002 s.330?" These are not questions a human investigator could answer efficiently across a million documents. They are precisely the questions AI answers well.

The audit trail that AI creates when embedded in compliance systems works in both directions. AI-assisted transaction monitoring logs every alert generated, every alert suppressed, every threshold applied and every decision made — or not made. That log is discoverable. An MLRO who relied on an AI system to triage alerts, and who cannot demonstrate that the system's suppression logic was validated, monitored and periodically reviewed, has not created a shield. They have created a forensic record of systemic non-compliance.

The plausible deniability era is ending. The compliance professional who sat in Position 2 (Sidelined) and claimed not to know — AI reconstruction of their email access, system queries, meeting calendars and internal communication patterns will rapidly establish the boundary between what they could not have known and what they chose not to pursue. The Big Four partners who approved Enron's off-balance-sheet vehicles relied on the complexity of the structure and the volume of the paperwork as protection. Those protections erode dramatically when an AI system can ingest the entire transaction history of a firm, identify the anomalies, trace the approval chains and surface the communications in which those anomalies were discussed — in hours rather than years.

The MLRO who currently believes they are navigating institutional pressure successfully by not asking the questions whose answers would require them to act should understand that their institution's AI systems are generating the answers anyway. The question is simply who gets to ask them first — the compliance function, or the investigators.

AI has a way of biting you in the arse. The profession has not yet reckoned with how comprehensively.

Section 5

The Three Positions of the Compliance Function

If you are an MLRO or compliance director at a Big Four firm, a lobbying advisory firm or any professional services organisation operating in the space described above, your function is in one of three positions. There is no fourth option.

Position 1

Captured

You are aware of the conflicts. You have been briefed — formally or informally — on client relationships that create material tensions with your firm's independence obligations. You have assessed those conflicts. You have concluded, under commercial pressure, under seniority pressure, under the implicit or explicit understanding that revenue-generating partners are not to be challenged, that the conflicts are manageable. You have documented the assessment. The documentation is the shield, not the conclusion.

Position 2

Sidelined

You are not aware. Senior partners do not route their decisions through compliance when those decisions involve the firm's most profitable relationships. Your mandate formally extends to the whole firm. In practice, it extends to the activities of junior and mid-level staff. The partners who sit on audit committees, who managed the Lendlease relationship, who attended meetings that are now the subject of parliamentary inquiry — they did not consult you, and no one expected them to.

Position 3

Complicit

You are aware. You have concluded, for whatever mix of career, commercial and institutional reasons, that raising the issue is more professionally dangerous than not raising it. You have not filed. You have not escalated. You have not documented your concern in a form that creates a paper trail you cannot later deny.

The law does not permit any of these three positions without consequence.

POCA 2002 s.330 (failure to disclose in the regulated sector) applies to any individual in the regulated sector who knows or suspects that another person is engaged in money laundering and fails to make an authorised disclosure as soon as practicable. The Money Laundering Regulations 2017 designate accountancy firms as regulated entities. The duty is not contingent on certainty. It is triggered by reasonable grounds for suspicion.

The KPMG whistleblower went to KPMG Australia's executives, board members and KPMG International. They were not given a hearing. They then went to Parliament. The compliance function's role is to be the route between the first two steps and the third. That it apparently was not is the sharpest indictment of the "Position 2: Sidelined" scenario in recent corporate history.

SM&CR — the Senior Managers and Certification Regime — applies to FCA-regulated firms. Under SM&CR, the MLRO is a named Senior Management Function (SMF17). Personal liability for failures within their function is not theoretical. The Woodford case demonstrated that SM&CR can produce zero individual accountability when regulators choose not to use it. That is a regulatory failure, not a legal one. The legal exposure remains.

Section 6

The Questions Every Boardroom Must Ask

The following questions are not currently asked of Big Four firms or advisory businesses as a matter of standard due diligence. They are not asked because the firms concerned have spent considerable effort shaping the frameworks that govern what questions are expected.

1

How compromised is this firm?

Who are their other clients in our sector, our regulatory space and our competitive market? What conflicts exist between our engagement and those other mandates? The answer "we have a conflicts policy" is not an answer. A conflicts policy that operates on self-assessment, without external verification or disclosure to the affected client, is a mechanism for managing the appearance of independence, not its substance.

2

What will they do with our internal information?

The KPMG Australia case is not an aberration. It is the auditor's model exposed. Every partner with access to your books has relationships, incentives and commercial pressures that extend beyond your engagement. Your financial position, your strategic plans, your operational vulnerabilities, your regulatory exposures — all of this enters the firm's information environment. Where does it go when it leaves your building in their heads?

3

What hidden agenda does this firm have?

A firm that simultaneously advises your regulator, your government department and your competitors is not providing you with independent advice. It is providing advice filtered through its other relationships. A firm advising both the government on procurement policy and a corporation bidding under that policy has an interest in the outcome that is not yours. What has it chosen not to tell you because telling you would disadvantage another client?

4

How will you be disadvantaged by legislation this firm helped shape?

The Big Four advise governments on regulatory reform. They also advise the private sector on how to respond to it. The firms that consulted on the Money Laundering Regulations 2017 also advise on compliance with them. The firms that provided input on the Procurement Act 2023 also advise on securing government contracts under it. If your adviser helped write the regulation — and also advises your competitor on the same question — the information asymmetry is structural, not incidental.

5

Are they picking winners and losers?

Which clients receive the most current intelligence, the most senior attention, the most forthcoming advice? Is your organisation in the inner circle, or is your information feeding someone else's competitive position within it? Flint Global's refusal to publish its client list makes this question unanswerable for its clients. An unanswerable question about your adviser's other mandates is itself a material risk.

6

Is this firm a neutral actor?

The answer, based on the cases in this paper, is no. They are commercial actors with multiple conflicting mandates, opaque ownership structures, government relationships that generate private benefit and a demonstrated willingness to exploit client information for competitive advantage. Proceeding on the assumption that they are neutral is not a due diligence failure. It is a governance failure.

Section 7

A Practical Framework for MLROs

1

Treat your external adviser as a counterparty, not a partner

The due diligence you apply to a new corporate client — mapping beneficial ownership, identifying conflicts of interest, assessing the independence of key individuals — should apply in full to any professional services firm you engage. Run the same KYC on KPMG that you would run on a high-risk client. Who are their significant shareholders? What is their regulatory history? Who are their other clients in your space?

2

Require written conflict confirmation with scope

A standard conflicts letter says "we have checked our records and identified no conflict." That is not sufficient. You need a written representation that names the firm's other clients in your sector, your regulatory space and your competitive market, and confirms that none of those relationships will affect the quality or independence of advice provided to you. If they refuse, that refusal is a risk indicator requiring escalation.

3

Control your information as you would a data breach risk

Compartmentalise what you share. Apply need-to-know principles. Do not share strategic information about M&A activity, regulatory submissions or competitive positioning with a firm that also serves your counterparties. The KPMG Australia case proves that internal information barriers between audit teams at the same firm are not reliably enforced. Do not assume your information is contained within the team you engaged.

4

Monitor the revolving door actively

Track the employment movements of senior individuals at your advisers and your regulators. When a senior partner at your audit firm joins your regulator — or vice versa — that relationship carries information. When a former minister joins the firm advising you on regulatory strategy, the question of what they know that you don't is live and material. Review this annually. Document the review.

5

Know your SAR obligation precisely

If your analysis gives you reasonable grounds to suspect that your adviser's conduct in relation to your engagement — or another client's engagement — constitutes a money laundering predicate, your obligation under POCA 2002 s.330 is to file. The prestige of the firm does not alter the statutory threshold. The test is reasonable grounds for suspicion. Not proof. Not certainty. Suspicion.

Section 8

Training Scenarios

Scenario 1

The Conflicted Auditor

Your firm has retained a Big Four firm for statutory audit for six years. You discover that the same firm's advisory division has been retained by your largest competitor for regulatory strategy advice for the past three years. The audit partner advises you this is managed through an internal firewall.

Key questions

What documentation do you require? What is your assessment under FRC Ethical Standards for auditors? What are your obligations under POCA 2002 if you subsequently discover the firewall has been breached and the firm's advisory team has used knowledge of your financial position in its work for your competitor?

Scenario 2

The Former Official

Your institution engages a strategic consultancy whose senior partner is a former Cabinet minister. The government is preparing to announce a regulatory change that will materially affect your sector. The partner appears to know the direction of the announcement before it is made.

Key questions

How do you assess whether this constitutes inside information under MAR Article 7? What is your obligation under FSMA 2000 s.131A? Does it matter that the information reached you indirectly, through the adviser's commentary, rather than in explicit terms?

Scenario 3

The Untendered Contract

You are compliance director at a public sector contractor. A key government contract is awarded to a competitor without open tender. The competitor is a client of the lobbying firm that employs a former minister who attended pre-procurement meetings with the relevant department. The meetings were not fully minuted.

Key questions

What financial crime indicators does this pattern raise? What is the threshold for a SAR under POCA 2002 in the absence of a proven predicate offence? Who in your organisation do you escalate to?

Scenario 4

The Whistleblower

A junior member of your compliance team reports that a senior partner at your firm's external audit provider shared information about your company's forward financial guidance with a contact at a hedge fund. The information was not public at the time. You have no direct evidence — only the allegation.

Key questions

What is your assessment process? What are your obligations under FSMA 2000 Part VIII regarding market abuse? At what point do you notify the FCA? What are the employment law protections for your team member under the Employment Rights Act 1996 s.47B (whistleblowing)?

Scenario 5

The Andersen Pattern

Your organisation's audit firm also holds a substantial consulting mandate — advisory fees from your firm exceed its audit fees. During a routine review you discover that the audit team has not escalated a significant internal control weakness identified eighteen months ago. The consulting team, working on a separate transformation project, recommended a solution to that same control weakness — a solution your firm then contracted them to implement. The audit team signed off on the accounts in the interim without qualifying them.

Key questions

What conflict of interest framework applies? At what point does this pattern constitute a breach of auditor independence under FRC Ethical Standards? What are your obligations as MLRO if you conclude the audit sign-off was compromised by commercial considerations?

Scenario 6

The AI Audit Sign-Off

Your institution's external auditor has deployed an AI system to conduct preliminary risk assessment across the transaction population. The engagement partner reviews a dashboard summary produced by the model and signs the audit opinion. Six months later, a fraud is discovered that was present in the transaction data the AI reviewed. The AI system produced no alert. The partner reviewed no underlying transactions.

Key questions

Under the German courts' "deployer owns the output" principle, what is the audit firm's liability position? What questions should your institution's MLRO have asked about the auditor's AI methodology before accepting the audit opinion? Does the firm's standard engagement letter exclusion of liability for AI-assisted procedures hold?

Scenario 7

The AI SAR Suppression

Your institution's AML transaction monitoring system is AI-assisted. The model assigns risk scores to alerts and automatically suppresses those below a threshold before they reach human review. A SAR is later filed by a correspondent bank on a customer your system had scored as low-risk for eighteen consecutive months. The underlying pattern — structuring across multiple accounts with consistent just-below-threshold amounts — was present throughout. The MLRO was not aware: the AI suppressed the alerts.

Key questions

Under POCA 2002 s.330, assess your personal liability position. What governance framework should have been in place? What does the EU AI Act Article 50 require by August 2026 in relation to AI systems making decisions that affect individuals?

Scenario 8

The Captured MLRO

You are appointed MLRO at a large advisory firm. In your first month you identify three client relationships creating material conflicts with the firm's independence obligations. You escalate to the managing partner. You are told the conflicts are managed through approved procedures. You are not satisfied with the quality of those procedures. Senior management make clear that further escalation would be unwelcome.

Key questions

What are your options under the FCA's prescribed person whistleblowing route? What is your personal liability under POCA 2002 s.330 if you do not file and misconduct is subsequently established? What does SM&CR SMF17 require of you in this position?

Section 9

Recommendations

Mandatory beneficial ownership disclosure for advisory and lobbying firms

Flint Global's Jersey holding company and Cinven ownership are invisible under current UK disclosure requirements. The PSC register requirements should be extended to cover advisory firms, lobbying consultancies and any entity that seeks to influence government decision-making or regulatory outcomes, regardless of incorporation jurisdiction.

Real-time conflict disclosure for audit firms to audit clients

Audit firms should be required to disclose in writing to their audit clients any material new client relationship capable of affecting the independence of the audit engagement. The current regime requires periodic self-assessment. It does not require disclosure to the audited entity. This gap is where KPMG Australia operated for years.

ACOBA reform: statutory powers, mandatory publication and sanctions

ACOBA must be given statutory enforcement authority. Its recommendations must be binding. Breaches must carry published sanctions. Every case in this paper involves individuals whose conduct was within the letter — if not the spirit — of ACOBA guidance. The guidance is the problem.

Extension of the Failure to Prevent Fraud offence to professional services firms with full force

The Economic Crime and Corporate Transparency Act 2023 applies to large organisations. The Big Four are large organisations. If a partner commits fraud — by misusing client information, by deploying government intelligence commercially, or by structuring advice to benefit one client at another's expense — the firm should face corporate criminal liability. The adequate procedures defence should require demonstrated effectiveness, not merely the existence of a policy.

AI governance standards for audit firms with statutory force

The FRC and FCA must require audit firms and regulated entities deploying AI in audit, risk assessment or AML functions to maintain documented validation records, human review escalation protocols and named accountability for AI-assisted conclusions. Engagement letter exclusions of liability for AI-assisted procedures must not be permitted to circumvent the fundamental duty of care. The German courts have established the principle: deployer owns the output. UK regulators must embed it in sector-specific rules before the next Wirecard-scale failure demonstrates that they did not.

A lobbying register with genuine scope

The Transparency of Lobbying Act 2014 captures a fraction of actual influence activity. A statutory register with real scope must capture all paid attempts to influence government decision-making, regardless of the vehicle — advisory firms, think tanks, former officials operating as individual consultants, or firms structured to avoid the current register's definitions. Voluntary codes have failed. The architecture of evasion is more sophisticated than the architecture of disclosure.

Conclusion

These Are Not Neutral Actors

The cases documented in this paper share a structural feature that goes beyond individual misconduct. In each instance, the firm or individual at the centre of the controversy was operating precisely as their business model intended. KPMG's auditors were maximising revenue from existing client relationships. Global Counsel was deploying its principal's political network to commercial advantage. Flint Global was providing high-value advisory services to clients with competing interests in live government decisions. The misconduct is not a deviation from the model. In several cases, it is the model.

For compliance professionals, this is the most important conclusion. Due diligence frameworks, conflicts of interest policies and independence standards were designed on the assumption that professional services firms are, at minimum, attempting to operate neutrally. That assumption requires examination.

The auditor is not neutral. The lobbying adviser is not neutral. The former official who joins a consultancy and deploys their government relationships for commercial clients is not neutral. The firm structured through a Jersey holding company owned by private equity, that refuses to publish its client list, that has lobbied against the transparency rules that would reveal its conflicts, is not neutral.

The question for every MLRO, compliance director and board that engages these firms is not "do we trust them?" It is the more precise and answerable question: "What can we verify?" If the answer is less than everything that matters, you are carrying a risk your compliance framework has not priced.

Pre-Publication Legal Screening Checklist

Reproduced in the interests of transparency and as a model for compliance publishers

Copyright and fair dealing (CDPA 1988)

Defamation — factual statements (Defamation Act 2013 s.2)

Defamation — opinion and public interest (s.3 and s.4)

Recommended specialist review before publication

The paragraphs naming Hoggett and Rogers specifically should be reviewed by a UK defamation specialist before the paper goes live. This is a one-hour exercise. The cost is modest. The benefit is documented evidence of reasonable care under s.4, which strengthens the public interest defence if challenged. Do not rely solely on this checklist — it is not a substitute for qualified legal advice on the specific paragraphs.

Legal Notices and Disclaimer

Sources, Defences and Limitations

This white paper has been produced for educational purposes and as fair comment on matters of public record, in the public interest.

Factual statements in this paper are drawn exclusively from the following categories of publicly available source: proceedings of the Australian Senate under parliamentary privilege (Senator Deborah O'Neill, 24 March 2026); official findings and testimony of the Australian Securities and Investments Commission; declared entries on the UK statutory lobbying register; published proceedings of UK parliamentary inquiries; investigative reporting by The Guardian (published 9 June 2026); and supplementary open-source reporting by Open Democracy, City AM and Labour Hub. All factual statements are attributed to their source inline. Where The Guardian is cited as the source, the underlying facts were reported by its journalists and this paper relies on that published reporting.

Analytical statements and conclusions — including characterisations of conduct patterns, assessments of regulatory adequacy and inferences drawn from documented facts — constitute the honest opinion of the author, formed on the basis of the facts cited. They are clearly distinguishable from factual statements and are expressed as opinion throughout.

Named individuals: All individuals named in this paper are named on the basis of official records, parliamentary proceedings or declared public registers. Where allegations are subject to ongoing investigation, this is stated explicitly. Nothing in this paper constitutes an allegation of criminality beyond what has been established in official proceedings or formally investigated by competent authorities.

Defences relied upon

This paper does not constitute legal advice. Philip Faulkner trading as Netizen 9 is not a law firm and does not provide legal services. Readers requiring legal advice on specific matters should seek qualified legal counsel.

Sources

Levin Center (Carl Levin Center for Oversight and Democracy) · Australian Senate Hansard, 24 March 2026 · ASIC Senate estimates testimony · The Guardian, 9 June 2026 · Open Democracy · City AM · Labour Hub · National Whistleblower Center · Best Practice Group / World Finance · Daily Nation · Project on Government Oversight · Lexology / MME Legal · Grunecker / Leaders League · ERP Today

Kim — AML & Compliance Intelligence | kim.amledtech.uk

AML Edtech — Compliance Intelligence
Train your team to
ask the right questions
Kim is an AI-powered AML compliance coach that turns papers like this into live training conversations — scenario-based, interactive and aligned to regulatory standards.
kim.amledtech.uk
Try Kim free — no sign-up required
Framework Paper 02 of the AML Edtech Compliance Framework Series · Philip Faulkner trading as Netizen 9 · June 2026
This paper is published under the Defamation Act 2013 s.2, s.3 and s.4 defences and Defamation Act 1996 Schedule 1 qualified privilege.