By Peter Wilkinson | 3 July 2026
Andrew Yates resigned as KPMG Australia’s chief executive within days of a whistleblower scandal reaching Senate estimates. Soon after, his audit chief followed him out the door. The firm’s chief operating officer then stood aside from her role, though she remained an audit partner, a distinction most of the public never noticed because the story had already moved past nuance.
KPMG’s whistleblower concerns were raised in an email dated 30 May 2024, and parliamentary/inquiry evidence later showed that board members were not informed of specific allegations until 5 April 2025; ASIC then confirmed on 5 June 2026 that it had commenced formal investigations after an earlier April engagement with KPMG.
That sequence is not chaos. It is what happens when an organisation skips straight to damage control – in this case, a cover-up – without walking the five steps that actually contain a crisis: detection, assessment, response, communication and recovery. Most firms treat these as a checklist. They work better as a discipline built around constantly improving trust, one rehearsed before the whistleblower calls, not improvised after.

The author – Peter Wilkinson
Step One: Detect the Issue Before It Detects You
Every crisis communications consultant in Australia will tell you the same uncomfortable truth. By the time a story breaks publicly, the organisation has usually known about the underlying issue for weeks, sometimes months.
Because of that gap, journalists asked why nobody spoke up sooner. Regulators asked the same question, with more consequence attached.
A newsroom producer chasing this story would have asked one question first: who knew what, and when. That is also the first question a board should be asking itself, long before a journalist does.
Awareness and being alert, is therefore not a single event. It is continuous monitoring across regulatory signals, internal reporting channels, media coverage and stakeholder sentiment, run as a standing function rather than a reaction to one tip.
This is the discipline behind issues management, and it separates an organisation that sees a problem coming from one that reads about it in the paper.
Step Two: Assess Severity With Senior Judgment
Once an issue surfaces, the instinct in most large organisations is to convene a committee. Legal, communications, HR and often external advisers all weigh in before a decision gets made. That process suits consensus, not speed, and a crisis punishes slowness.
KPMG’s chairman, Martin Sheppard, and two senior partners all stepped down. But the assessment behind it needed to happen fast enough to get ahead of an already scheduled parliamentary hearing.
Assessing severity under pressure means weighing legal exposure, regulatory posture and public narrative at the same time. It shouldn’t need eight people to sign off.
For this reason, senior judgment matters more than headcount. A single adviser who has sat through cyber breaches, judicial inquiries and executive misconduct cases before can size up severity in an afternoon. A committee often cannot do it in a week. Wilkinson Group’s Peter Wilkinson built the firm’s model around exactly this principle: no account managers, no junior escalation chain, just the person who takes the call.
Step Three: Respond Within Hours, Not News Cycles
The response step is where most organisations lose control of the narrative. Silence in the first hours does not buy thinking time. Instead, it creates a second story, the one about why leadership went quiet, and that story, as in this case, is often more damaging than the original issue.
Finance officials told parliament they had to chase KPMG multiple times for information the firm should have volunteered. As a result, a technical scandal was reframed as a story about evasiveness, which is far harder to recover from. A crisis communications consultant in Sydney working this file would have pushed for an honest public position well before the department had to write directly to KPMG’s leadership demanding answers.
Build the Protocol Before the Event
Response speed does not mean rushing out an unprepared statement. Rather, it means having a tested protocol ready before the event, so the first public words come from control and reputation management, rather than catch-up and cover-up. This is the entire logic behind a retained model such as Wilkinson Confidante, where the response framework already exists before the phone rings.
If a spokesperson still needs to fumble over the right words under questioning in the moment, that readiness gap shows on camera. It is also why interview preparation and media training sit alongside the protocol itself, not after it.
Step Four: Communicate on Three Messages at Once
Effective crisis communication is never one statement. It is three distinct messages, delivered together, each doing separate work: the incident message, the company message and the personal message.
The incident message states the facts and the timeline plainly, without spin. The company message sets out values and the commitment to fix what went wrong. The personal message, delivered by the leader directly, carries the human acknowledgment that facts and policy statements cannot substitute for.
Directors and executive often skip the personal step because it feels exposing, yet it is also the step audiences remember.
Consistency across all three messages matters as much as the content of each. A reputation management consultant in Australia worth retaining will insist all three are aligned before anything goes out, since a mismatch between the corporate statement and leaders’ own tones erode whatever credibility remains.
Step Five: Recover Trust Through Verified Change
Recovery is the step organisations most often shortcut. Typically, they issue an apology, announce a review, and expect the story to move on. It rarely does, at least not quickly, and never without visible proof that something has actually changed.
Trust = Truth + Transparency + Traceability. That third element is what the KPMG situation will ultimately be judged on. Every commitment the firm makes now, about governance, about partnership structure, about how whistleblowers are protected, will sit online, timestamped and easily retrievable with AI, ready to be checked against whatever happens next.
Recovery after a scandal of this scale typically takes years rather than months. It requires an honest account of what went wrong, changes that are genuinely verifiable rather than promised, and consistent communication sustained well past the point the media moves on. Consequently, CEO reputation management in Australia increasingly means managing this long tail, not just the first fortnight of headlines.
Why the Sequence Matters More Than Any Single Step
None of these five steps works in isolation. Skip detection and the response looks reactive. Skip proper assessment and the response is either too slow or too aggressive, and skipping the personal message leaves the recovery phase starting from a trust deficit that facts alone cannot close.
What separates a genuine crisis PR agency in Australia, one that has actually sat inside inquiries, product recalls and executive misconduct cases, from one that has only studied them in theory is precisely this sequencing instinct. It comes from pattern recognition, not a template. Twenty four years of advising boards through comparable situations teaches you which step is being skipped before the damage becomes visible externally.
KPMG’s scandal is not finished. ASIC’s investigation continues, a parliamentary hearing is underway, and the firm’s federal contract book faces a genuine revenue cliff at the end of the financial year.
Whether the organisation recovers will depend less on any single statement and more on whether it has, belatedly, started walking the five steps in the right order.
Organisations that build this discipline before a crisis arrives spend far less time playing catch-up during and after one.
Get in touch…
Call us directly
Contact email
Address
