Why KPMG’s whistleblower failure should concern every aged care provider

Published on 20 July 2026

Image source: AI assisted.

KPMG admitted its whistleblower investigation lacked the necessary rigour. For aged care boards, the implications are even greater. Under the Aged Care Act 2024, directors can now face personal penalties of up to $165,000 for governance failures, even where the provider itself avoids regulatory action.

KPMG has run FairCall, a whistleblower hotline it sells to other companies, since 1998. It’s used in more than 80 countries. In May 2026, KPMG admitted that when someone used a whistleblower channel on KPMG itself, the firm got it wrong. Its own statement said the investigation into the discloser’s claims “was not conducted with the necessary rigour required.” 

CEO Andrew Yates resigned days later. “I have been committed to a speak-up culture in our firm,” he said. “It is clear that in this case we have let ourselves down and I take accountability.” The firm’s National Managing Partner for Audit and Assurance resigned alongside him. ASIC is now separately investigating several of KPMG’s registered auditors, and a Senate committee is still working through documents the firm initially withheld.

If the company that sells whistleblower hotlines for a living can fail this badly at running its own, “we have a policy” was never going to be the bar aged care boards get judged against. And in aged care specifically, that judgment is now personal.

What changed on 1 November 2025?

Since that date, the Aged Care Act 2024 and Aged Care Rules 2025 have been fully in force. Directors and officers named as “Responsible Persons” can be held personally liable for whistleblowing governance failures, independent of any finding against the organisation itself. 

Penalties reach $165,000 where conduct results in death or serious injury, $82,500 for Code of Conduct breaches, and $49,500 for failures in due diligence. The liability attaches to the governance gap itself, not the outcome. A responsible person can be exposed even where the provider avoids direct regulatory action, for example by remediating quickly after an incident surfaces.

Image source: AI assisted.

The law is specific about what a compliant system looks like: 

  • a formal policy open to everyone who might raise a concern, not just staff, residents, families and contractors included
  • a secure channel with a genuine anonymous option 
  • documented training 
  • disclosures that feed into complaints and incident management, instead of sitting in their own silo, and 
  • stronger legal protection against victimisation than existed before.

Why this sector, right now?

Aged care isn’t just facing new whistleblowing law in isolation – it’s mid-transition on almost every front at once. 

KPMG’s own 2026 Aged Care Market Analysis, published the same year as its whistleblower failure, shows a sector under real structural pressure: 96,709 people still waiting for a home care package at their approved level, government investment up 9.6% to $39.2 billion in FY25, and the Support at Home reform reshaping how the sector’s 873 home care providers operate since November 2025. KPMG expects some smaller providers to exit the market this year as the new funding model beds in.

Reporting systems don’t break in stable organisations, they break during exactly this kind of change when policies get rewritten site by site faster than anyone can track who owns what. And it’s happening in a workforce that’s already stretched. 

National modelling points to an annual shortfall of around 35,000 direct care workers and a shortage of more than 17,500 nurses in aged care. A provider that loses staff trust in its reporting channel isn’t just carrying compliance risk in a sector that’s already short-staffed. It’s giving people one more reason to leave.

What does that breakdown actually look like?

David Morgan, Managing Director of Whistleblower Technologies at Veremark, has seen the pattern up close.

“I worked with an aged care provider where HR tracked complaints in one spreadsheet, quality and compliance tracked similar issues in another, and each site had introduced its own policies at different times. None of them connected,” Morgan says.

“The board appointed a CEO who dismissed concerns from residents and families as unreasonable. Staff followed her lead or disengaged. The spreadsheets stopped being updated, reporting died, and the organisation lost its ability to see itself clearly.”

“When staff stop raising small concerns, leadership loses the signals that would have helped them improve care before it was too late.”

What will the Commission actually test?

Investigators assessing a responsible person’s due diligence aren’t reading policy documents in isolation, they test: 

  • whether staff know how to raise a concern anonymously and believe they’d be safe doing so
  • whether disclosures were documented and acted on
  • whether the board received intelligence from the speak-up system, and 
  • whether anyone who raised a concern faced detrimental treatment afterward.

A policy answers the first of those. Nothing else on that list is answered by a document sitting in a shared folder, which is exactly what KPMG’s own admission illustrates. The firm had a whistleblower process, and sold one to other people. Having one wasn’t the problem: running it properly was.

Where should providers start?

Morgan points to the same three priorities regardless of provider size:

  1. Independent reporting: A reporting channel should sit independently of the hierarchy it’s designed to monitor. People don’t use channels they don’t trust, particularly when concerns involve managers or executives.
  2. Integrated reporting: One system for whistleblowing, complaints and incidents, with clear ownership and a visible audit trail. Not separate spreadsheets or disconnected processes that leave boards with an incomplete picture.
  3. Capability building: Ongoing training so staff and managers know how to respond when a disclosure is made, not a once-off policy rollout that’s forgotten six months later
Image source: AI assisted.

The question aged care boards needs to answer

The Aged Care Quality and Safety Commission issued 34 banning orders in a single quarter last year. KPMG has run other companies’ whistleblower hotlines since 1998 and still couldn’t get its own right. The question for your board isn’t whether you have a policy, it’s what happens in the 48 hours after someone actually uses it.

For a full breakdown of what “responsible persons” liability means in practice, what a compliant reporting system needs to include under the Aged Care Rules 2025, and where the Commission is most often finding the gap, read Veremark’s report, Whistleblowing in the New Aged Care Framework.

Tags:
aged care
aged care workforce
aged care providers
compliance
technology
aged care reform