The hotline report landed on a Tuesday. The compliance analyst logged it, marked it “significant,” and routed it to legal. Legal opened a file and copied HR. HR waited on legal. The general counsel raised it — briefly — at the quarterly risk committee, where it was noted, minuted, and referred for further review. An outside firm was engaged. The outside firm reported back through the same people the report was about.
Eighteen months later, a board director asked the only question that mattered: “Who owns this?” Six executives looked at each other. Every one of them had touched the file. Every one of them had assumed someone else was driving it. The warning had been seen by dozens of people — and owned by none of them.
That boardroom is fictional. What happened at KPMG Australia is not.
A Warning Ages Into a Crisis
On May 30, 2024, a whistleblower inside KPMG Australia made a protected disclosure alleging audit-independence failures and misuse of confidential client information (Parliament of Australia, 2026). The warning entered the system. And then, for nearly two years, the system absorbed it.
It took Senator Deborah O’Neill raising the allegations in the Australian Senate in March 2026 to make the matter unavoidable. What followed was a rapid leadership unraveling: CEO Andrew Yates resigned on May 29, 2026, the same day the firm’s national audit chief stepped down. The COO stepped aside days later. The chairman left in June. By late July, the firm had fined seven staff, appointed a new CEO, and drawn intensified oversight from Australia’s corporate regulator (KPMG Australia, 2026a; Reuters, 2026).
The most instructive detail is KPMG’s own diagnosis. The firm admitted that its treatment of the whistleblower, the rigor of its investigations, and leadership’s action on the allegations all fell short — and its remediation plan focused on governance architecture: an independent chair, independent directors, stronger whistleblower oversight, tighter controls (KPMG Australia, 2026a, 2026b). It’s a sophisticated firm acknowledging that the core failure wasn’t only misconduct. It was that a serious warning sat inside a large organization long enough for everyone to conclude that someone else must be handling it.
The Science: Responsibility Divides by Headcount
Behavioral science has a name for this: diffusion of responsibility. In the foundational experiment, Darley and Latané (1968) found that 85% of people who believed they were the only witness to an emergency reported it. Add one other bystander, and the rate fell to 62%. With four others present, it collapsed to 31%. Nothing about the emergency changed — only the perceived math of who else could act.
Modern reviews identify three mechanisms that suppress action in groups: diffusion of responsibility, fear of being judged for intervening, and the inference that everyone else’s calm means no alarm is warranted (Hortensius & de Gelder, 2018). Layer on “moral muteness” — fewer than half of employees who witness organizational wrongdoing report it (Ethics Unwrapped, n.d.) — and the corporate version of the bystander effect writes itself.
Recent research sharpens the point for executives. Oc and Kouchaki (2024) found that larger work groups reduce individuals’ psychological standing — their felt legitimacy to raise moral concerns — making silence more likely. More uncomfortable still: formal policies and procedures can actually strengthen the bystander effect, because employees infer that “the system” is already responsible. Your hotline, your committee, your outside counsel — each can become one more reason for every individual to do nothing.
This isn’t unique to auditing. The independent investigation into General Motors’ ignition-switch failure described the “GM nod”: a room full of executives nodding agreement on a proposed plan, then leaving with no intention of personally acting (Valukas, 2014). A defect suspected internally for years cycled through committees until it became a recall crisis linked to 124 deaths and a $900 million deferred prosecution agreement (U.S. Department of Justice, 2015). Different industry, same architecture: visible problem, ownerless response.
Why This Is a Growth Problem, Not a Compliance Problem
It’s tempting to file this under governance. Don’t. Warning-handling architecture is revenue architecture.
Enterprise buyers now run vendor-stability diligence before signing multi-year contracts, and a governance scandal reprices every renewal conversation for years. Meanwhile, the same diffusion that buries whistleblower reports buries customer complaints. Federal Reserve guidance notes that repeated complaints often reveal systemic process failures — the “canary in the coal mine” — and that formal complaint programs reduce reputational risk and regulatory escalation (Federal Reserve, 2024). The complaint your team dismisses as frontline noise is often your earliest, cheapest signal of building churn, discounting pressure, or regulatory exposure. Companies that route those signals to a named owner fix the process while it’s still a retention play — not a headline.
The Fix: One Red Flag, One Owner
The remedy is not more policy. The DOJ’s (2024) compliance guidance asks whether companies route complaints to the right personnel, complete investigations on a clock, track cases end to end, and hold managers accountable for supervision failures — not just misconduct. The U.S. Sentencing Commission (2018) goes further: specific, named individuals must own the program.
Translate that into a five-part operating rule: one red flag, one accountable owner, one response clock, one escalation path, one closure memo. Not “legal and HR.” Not “the committee.” One name. Work can be delegated. Accountability cannot.
The Bottom Line
Any internal warning with no single owner is already escalating — whether your calendar reflects it yet or not. The test is one sentence long. For every live warning in your company — whistleblower, customer, product, regulator — can you answer: Who owns this, by when, and what happens if nothing changes?
References
Darley, J. M., & Latané, B. (1968). Bystander intervention in emergencies: Diffusion of responsibility. Journal of Personality and Social Psychology, 8(4), 377–383. https://doi.org/10.1037/h0025589
Ethics Unwrapped. (n.d.). Moral muteness. McCombs School of Business, The University of Texas at Austin. https://ethicsunwrapped.utexas.edu/glossary/moral-muteness
Federal Reserve. (2024). The benefits of a formal complaint management program. Consumer Compliance Outlook, 2024(2). https://www.consumercomplianceoutlook.org/2024/second-issue/benefits-of-formal-complaint-management
Hortensius, R., & de Gelder, B. (2018). From empathy to apathy: The bystander effect revisited. Current Directions in Psychological Science, 27(4), 249–256. https://pmc.ncbi.nlm.nih.gov/articles/PMC6099971/
KPMG Australia. (2026a, May 29). Investigation into whistleblower allegations [Media release]. https://kpmg.com/au/en/media/media-releases/2026/05/investigation-into-whistleblower-allegations-29-may-2026.html
KPMG Australia. (2026b). KPMG Australia action plan. https://kpmg.com/au/en/about/governance-leadership/action-plan.html
Oc, B., & Kouchaki, M. (2024). The more the merrier: How psychological standing and work group size explain managers’ willingness to communicate about unethical conduct in their work group. Journal of Business Ethics, 190(4), 775–786. https://doi.org/10.1007/s10551-023-05431-y
Parliament of Australia. (2026, March 24). Senate official Hansard. https://www.aph.gov.au/Parliamentary_Business/Hansard/Hansard_Display?bid=chamber%2Fhansards%2F29212%2F&sid=0349
Reuters. (2026, July 20). KPMG Australia fines staff up to $126,000 for ‘unacceptable’ misconduct in audit scandal. https://www.reuters.com/legal/government/kmpg-australia-fines-staff-up-126000-unacceptable-misconduct-audit-scandal-2026-07-20/
U.S. Department of Justice. (2015, September 17). Manhattan U.S. attorney announces criminal charges against General Motors and deferred prosecution agreement with $900 million forfeiture [Press release]. https://www.justice.gov/usao-sdny/pr/manhattan-us-attorney-announces-criminal-charges-against-general-motors-and-deferred
U.S. Department of Justice. (2024). Evaluation of corporate compliance programs. https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl
U.S. Sentencing Commission. (2018). Guidelines manual, chapter 8. https://www.ussc.gov/guidelines/2018-guidelines-manual/2018-chapter-8
Valukas, A. R. (2014). Report to Board of Directors of General Motors Company regarding ignition switch recalls. Jenner & Block.
