🙏 This reporting is free because readers fund it.

More →
August 28, 2026

Stealing the Exam: KPMG, the Regulator’s List, and the Fraud That Wasn’t Property

Stealing the Exam: KPMG, the Regulator’s List, and the Fraud That Wasn’t Property

The Public Company Accounting Oversight Board exists because auditors once graded their own homework, and the homework was Enron’s. Congress created the board in the Sarbanes-Oxley Act of 2002, in the rubble of Arthur Andersen, to do one essential thing: inspect the auditors. Each year the PCAOB selects, in strict confidence, a sample of a firm’s public-company audits and re-examines them — the profession’s pop quiz, its power derived entirely from surprise. An auditor who knows which engagements will be inspected can quietly re-polish those files and present the regulator with a curated version of its work. Which is why the scandal that broke over KPMG in January 2018 struck the profession with such force. The national leadership of the audit-quality function at one of the Big Four — the executives whose job title was, in effect, integrity — had spent nearly three years acquiring the PCAOB’s confidential inspection selections through a pipeline of recruited insiders. Federal prosecutors in Manhattan reached for the obvious metaphor and did not let go of it: KPMG’s executives, they said, had been stealing the exam.

The case would produce guilty pleas, federal convictions, a fifty-million-dollar SEC penalty resting on admitted facts, and then — in a coda almost no one anticipated — the unraveling of the convictions themselves, after the Justice Department conceded that the conduct it had proved to a jury did not fit the statute it had charged. The KPMG inspection scandal is therefore two stories braided together: one about how a compliance culture rots from the top, and one about the difference — unsettling to contemplate — between conduct that is wrong and conduct that is criminal.

An Audit Firm in Trouble

The scheme had a business rationale, which is the detail that separates it from mere rogue behavior. KPMG’s PCAOB inspection results in the mid-2010s were dismal: the board’s inspectors were finding deficiencies in roughly half of the KPMG audits they examined, year after year — the worst showing among the Big Four. Bad inspection results carried real costs: embarrassment before audit committees, leverage lost in client pitches, and pressure from a regulator with the power to make life difficult. The firm responded in the ordinary corporate way — task forces, monitoring programs, new leadership for the Department of Professional Practice — and in one extraordinary way: it began hiring the examiners.

In the spring of 2015, KPMG recruited Brian Sweet, a PCAOB employee who had helped plan inspections of KPMG itself. Federal prosecutors would later describe what happened around his departure with clinical precision: on his way out of the regulator, Sweet took confidential materials with him, including the board’s inspection plans. On his first day at KPMG, according to the government’s case, he was asked by Thomas Whittle, the firm’s national partner-in-charge of inspections, for the current inspection selections — and was told, in substance, that his loyalty was now to KPMG. Sweet delivered. The information flowed up: to Whittle, to David Middendorf, the national managing partner for audit quality and professional practice, and to David Britt, co-head of the banking and capital markets audit group — men who sat, between them, atop the very functions that existed to keep the firm honest with its regulator, and who treated the contraband not as a crisis to be reported but as an asset to be managed, guarded on a need-to-know basis like any other piece of competitive intelligence. Armed with the list of which audits the PCAOB would re-examine, KPMG personnel conducted stealth re-reviews of the selected engagements — shoring up workpapers before the inspectors arrived, in some cases adding documentation after the fact — so that the regulator would inspect not the audit as it had been performed but the audit as it had been dressed for inspection.

The pipeline renewed itself the way such pipelines do. Sweet kept in touch with former PCAOB colleagues, among them Cynthia Holder, who passed him confidential inspection information while still employed at the board — and while seeking a job at KPMG, which she got in August 2015. Holder in turn cultivated Jeffrey Wada, a PCAOB inspections leader who, passed over for promotion and angling for a position at the firm, tipped the 2016 selections and then, in early 2017, the full preliminary 2017 inspection list — announcing one delivery, in a phone call the government would quote at trial, with the words “I have the grocery list.” He sent his résumé to Holder days later, the quid trailing the quo by less than a week.

It is worth dwelling on what the stealth re-reviews actually were, because the mechanics carried the scheme’s full corruption in miniature. An audit exists as a file of workpapers — the documented evidence that required procedures were performed before the firm signed its opinion. PCAOB rules sharply restrict altering workpapers after an audit is complete, precisely so that the file the inspector examines is the audit that happened. The re-review teams, dispatched to engagements the leaked lists had flagged, combed those files for weaknesses the inspectors might find and buttressed them — in the government’s account, sometimes adding documentation months after the opinions had been issued. The exercise did nothing for the investors relying on the audits; the work underneath was whatever it had been. Its sole function was to defeat the measurement. The audit-quality department had become, in the most literal sense available, a department for the appearance of audit quality.

The Partner Who Said No

The scheme died the way it had lived: through a personnel decision. In February 2017, seeking to warn an engagement team, a KPMG partner was told that her banking audit was on the leaked 2017 list. She did not treat the information as a gift. She reported it — up the chain and, crucially, onward until it reached the firm’s Office of General Counsel. KPMG retained outside counsel, investigated, and did what firms in such moments often only claim to do afterward: it went to the regulators itself, disclosed the breach to the SEC and the PCAOB, and in April 2017 fired six people, including Middendorf, Whittle, Britt, Sweet, and Holder, along with Scott Marcello, the vice chair of audit, for failing to escalate what he had learned. When the criminal charges arrived in January 2018 — the U.S. Attorney for the Southern District of New York and the SEC filing in parallel — the defendants were the individuals, not the firm; KPMG’s self-report and cooperation had kept the entity out of the dock.

The entity did not escape unmarked. In June 2019 the SEC imposed a $50 million civil penalty on KPMG in a settled order whose facts the firm admitted — a rarity in SEC practice — covering the inspection-data scheme and a second scandal the investigation had turned up along the way, one that required no recruited regulators at all: KPMG audit professionals, including partners, had been cheating on the firm’s own internal training exams, sharing answer keys for tests on auditing standards and professional ethics, and in some cases manually editing the hyperlinks on exam results to lower the passing threshold — occasionally to scores the order described as low as 25 percent. The regulator’s enforcement director called the totality of the conduct astonishing. It was the detail the profession found hardest to metabolize: the exam-stealing had been wholesale, from the PCAOB’s list down to the ethics quiz.

Trials and Sentences

The trial, when it came, staged the scheme’s two possible descriptions against each other. The government presented recorded calls, e-mails, and Sweet’s inside narration of a conspiracy running from the regulator’s inspection rooms to the summit of KPMG’s quality apparatus. The defense offered the counterintuitive argument that the conduct, whatever its propriety, had defrauded no one of anything: re-reviewing audits made the audits better, the PCAOB lost no money, and confidential regulatory information was not property in the statute’s sense — an argument the jury rejected and an appellate epoch would later vindicate. In the meantime, the profession absorbed the spectacle of a national managing partner for audit quality standing trial in Manhattan federal court on the same species of charge the Justice Department deploys against boiler rooms.

The individual cases resolved in the usual cascade. Sweet pleaded guilty immediately and became the government’s central cooperator. Holder and Whittle pleaded guilty in October 2018; Britt later entered a plea as well. Middendorf and Wada went to trial in Manhattan in early 2019, and in March a jury convicted both of wire fraud and conspiracy — the theory being that they had schemed to defraud the PCAOB of its confidential property, namely the inspection selections — while acquitting on a separate conspiracy count. That fall, Judge J. Paul Oetken sentenced Middendorf to a year and a day, and Wada to nine months; Holder received eight months. The sentences were modest, but the professional consequences were total: the SEC barred the participants from appearing or practicing before it as accountants, and careers built over decades in the profession’s upper altitude were over.

Then the law moved. In 2020, in the Bridgegate case, Kelly v. United States, a unanimous Supreme Court reiterated that the federal fraud statutes protect property, not regulatory power — a government’s allocation of lanes on a bridge, or its regulatory decision-making, is not “property” in the statute’s sense. In late 2022 the Second Circuit, applying Kelly on remand in United States v. Blaszczak, vacated convictions built on the theft of confidential government agency information, holding that such information, valuable only as an instrument of regulation, was not the agency’s property. The implication for the KPMG defendants was direct, and in 2023 the government conceded it: the PCAOB’s inspection selections — the grocery list itself — had value only in the exercise of regulatory oversight, and the trial evidence was therefore insufficient to establish the “property” element of wire fraud. The Second Circuit remanded the Middendorf and Wada cases with instructions to dismiss, and the convictions of the trial’s two defendants — served sentences and all — were wiped away. Guilty pleas resting on the same theory followed the same road out.

The wreckage extended past the defendants. Scott Marcello, the vice chair who led the entire U.S. audit practice, was fired not for joining the scheme but for failing to escalate it when told — a career ended by an omission, and a signal to every executive in the profession about what “tone at the top” means when regulators audit it afterward. The PCAOB itself absorbed a share of the disgrace: the scheme had run on its own alumni and a serving employee, and within a year the SEC had replaced the board’s entire five-member leadership, while the new chairman tightened controls on inspection data and the ethics walls around departing staff. And the training-exam cheating that KPMG’s case exposed proved to be no anomaly of one firm: in 2022 the SEC fined Ernst & Young $100 million — the largest penalty ever imposed on an audit firm — after finding that its professionals, too, had cheated on ethics exams, including the very CPA ethics exam, and that the firm had withheld evidence of it from the regulator during the investigation. Whatever the profession had learned from KPMG’s example, it had not learned it everywhere.

Wrong Versus Criminal

The KPMG dismissals were not an anomaly of one case but part of a broader contraction. In the same seasons, the Supreme Court unanimously erased the fraud convictions in Ciminelli, rejecting the Second Circuit’s “right to control” theory that had made deprivation of economically valuable information a stand-in for property loss, and pared back honest-services doctrine in Percoco. The federal courts were redrawing, case by unanimous case, the boundary between conduct that offends and conduct that Congress has actually criminalized — and prosecutors’ most flexible instrument, the wire-fraud statute, kept being handed back to them shorter.

It is worth being precise about what the reversal did and did not say, because the distinction is the case’s deepest lesson. No court found that the conduct had not occurred, or that it was acceptable; the government’s concession was that Congress’s fraud statutes, as the Supreme Court now read them, did not reach it. The SEC’s administrative findings, the admitted facts in the firm’s $50 million order, the PCAOB rule violations, the terminations, the bars — all of that stood. The criminal law had been, in the appellate courts’ judgment, the wrong tool, stretched by prosecutors around conduct that was plainly corrupt but not plainly a theft of property. Accounting’s trade press, which had covered the trial as a morality play, covered the dismissals with something like vertigo: the executives who stole the exam had, as a matter of federal criminal law, stolen nothing.

For the profession, the episode’s meaning never depended on the criminal ledger. Sarbanes-Oxley’s central bet was that an independent inspector, armed with surprise, could do what markets and malpractice suits had failed to do after Enron: force audit quality upward. The KPMG scheme was a direct assault on that architecture by the people highest in the firm charged with honoring it — a compliance department turned counterintelligence operation against its own regulator. The PCAOB tightened its internal controls on inspection data and its ethics walls around departing staff; the revolving door between the board and the firms it inspects, the scheme’s load-bearing mechanism, drew scrutiny it has never fully shed. And audit committees learned to read inspection reports with a new question in mind: not only how many deficiencies the regulator found, but whether the firm had known where the regulator would look.

The cleanest summary of the affair belongs to the numbers that started it. The purpose of stealing the inspection list was to make KPMG’s audits look better than they were — to manage the metric rather than the work. In this it succeeded briefly and then failed catastrophically, converting a bad deficiency rate into a historic scandal, a $50 million admitted-facts penalty, and a permanent case study taught to every auditing student in the country. The metric, it turned out, was never the asset. The asset was the thing the founder of a rival firm had named a century earlier as the auditor’s entire inventory — the credibility of the signature — and no version of the exam, stolen or passed, was ever going to protect it.

Sources: SEC Press Release 2019-95 and accompanying settled order, In re KPMG LLP (June 17, 2019, admitted facts, $50 million penalty); U.S. Attorney’s Office, S.D.N.Y., charging announcements (Jan. 2018), conviction release, United States v. Middendorf and Wada (Mar. 2019), and sentencing releases (2019); SEC charges against six individuals (Jan. 2018); Kelly v. United States, 590 U.S. 391 (2020); United States v. Blaszczak, 56 F.4th 230 (2d Cir. 2022); Second Circuit orders remanding the Middendorf and Wada appeals for dismissal on the government’s concession (2023); PCAOB inspection reports for KPMG LLP (2014-2017); contemporaneous coverage by the Wall Street Journal, Reuters, Bloomberg, Financial Times, Law360, and Going Concern.

Reader-Supported Journalism

We don't have corporate backers. We have you.

No ads. No paywalls. No sponsor influence — ever. If this reporting matters to you, please help us keep going.

KPMGPCAOBaudit inspectionswire fraudDavid MiddendorfSEC enforcementaccounting ethicsKelly v. United States

Independent Journalism Needs You

You just read something most publications won't touch. We investigate judges who shouldn't be on the bench, attorneys who prey on clients, and a legal system that too often protects itself instead of the public. We do it openly, aggressively, and without apology.

We don't have a paywall. We don't take money from law firms, bar associations, or corporate advertisers who might prefer we stay quiet. Every piece of reporting on this site — every judge exposed, every disbarment documented, every reversal analyzed — was made possible entirely by readers like you.

If you read us regularly — if this work has ever made you angry, informed you, or helped you — we humbly ask you to support us today. It takes less than a minute. Even $1 goes directly toward keeping this reporting alive. Without it, we cannot continue.

Reader Supported

This journalism is free because readers like you make it possible.

We don't have corporate advertisers. We don't take money from law firms. Every investigation you read here is funded entirely by readers. Even $1 keeps us going.

Join 80 readers who donated this month

80% toward our monthly goal of 100 supporters

Secure checkout via Stripe. Cancel your monthly gift anytime.

The Ethics Reporter is independent and reader-funded. We have no corporate backers. Your support is everything.