<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>1.1 Case study: lessons from PwC Australia&#39;s tax scandal by Gia Instructor</title>
      <link>https://padlet.com/governanceinstitute/k9ykihohw6okljke</link>
      <description>Strategy &amp; Culture</description>
      <language>en-us</language>
      <pubDate>2025-03-06 00:15:27 UTC</pubDate>
      <lastBuildDate>2026-05-19 05:32:29 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Question 1 reply </title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537719627</link>
         <description><![CDATA[<p>From my perspective - I see that the question perhaps reads more so what role could PwC Australia's Board have played to intervene when <strong>they were aware of the <em>1st incident, </em></strong>and <strong><em>then in the 10-years </em></strong>since the breach?</p><p> </p><p>By focusing on the very first breach would help to immediately provide insights and opportunities that a retrospective, decade-long view simply can’t match. In terms of an analogy - it’s like treating an infection at its outset rather than waiting until it spreads system-wide or worse in this case (a decade later) having metastases. </p><p><br/></p><p>I’ve identified eight immediate board interventions at the first incident. While more could be added, these actions across people, process, and systems lay the foundation for a strategic incident-management plan and a robust target operating model, based on these identified improvement areas from the incident breach. </p><p>As soon as the Board became aware of the first breach in 2013, it could—and should—have taken decisive, visible action to stop the misconduct from (further) metastasising and affecting the business and its clients:</p><ol><li><p>Critical Management Team / Incident Response Team Mobilised: Mandate an immediate, independent forensic review; much like a cyber breach a CMT / IRT must be mobilised to undertake immediate actions &nbsp;directly from the Chairman and Board, CEO to the business; &nbsp;</p><ul><li><p>Suspend any individuals implicated in the breach</p></li><li><p>Secure all draft materials and communications for audit from the incident</p></li><li><p>Report preliminary findings to regulators within 30 days (of the breach incident)</p></li></ul></li><li><p>Ethics &amp; Integrity Committee: Convene a Board-level Ethics &amp; Risk Taskforce</p></li><li><p>Conflict of Interest, Compliance &amp; Security: Firewall advisory and commercial teams (isolate and create “Chinese walls” remove conflicts of interest)</p></li><li><p>Oversight and Protection Channels: Strengthen whistleblower channels and protections</p></li><li><p>Exec / SLT/ Management Integrity and Ethical Metrics: Tie (in) any and all leadership incentives to ethical metrics</p></li><li><p>Transparent Reporting: Where possible Implement 'real-time' governance dashboards, or at very least dashboards that provides reporting transparency on like activity. </p></li><li><p>Responsive Engagement: &nbsp;Proactively engage regulators and major clients. Be responsive rather than reactive. Voluntarily brief the ATO and Tax Practitioners, and Board on proposed recommendations and corrective steps</p></li><li><p>Continuous (Review and) Improvement: Institutionalise continuous improvement cycles</p></li></ol><p><br/></p><p>Now if we were to 'fast-forward' to address the main question as to what could the PwC board have done to intervene in the 10years . As a governance practitioner with 15+ years of end-to-end (business project) delivery and board reporting, I understand (and appreciate) how a board’s strategic oversight can make or break an organisation’s ethical and risk profile. </p><p><br/></p><p>Post incident some 10 years on, my observations based on (the case study) information provided and other references (specifically - <em>Ainsworth, Kate. “What is the PwC tax scandal? Who is Peter-John Collins? Who knew about it? Why does it matter?” ABC News, June 5 2023</em>), and recently published <em>Department of Finance. “Examination of the ethical soundness of PricewaterhouseCoopers Australia.” Australian Government — Department of Finance, August 2025. </em><a rel="noopener noreferrer nofollow" href="https://www.finance.gov.au/sites/default/files/2025-08/examination-of-pwc-australias-ethical-soundness.pdf"><em>https://www.finance.gov.au/sites/default/files/2025-08/examination-of-pwc-australias-ethical-soundness.pdf)</em></a></p><p><br/></p><p>As to how PwC Australia’s Board could (and in my opinion should) have stepped in over the decade following the initial 2013 breach are as follows and these specifically dovetail into the initial (2013) breach and incident ‘management response’ I have outlined earlier (if they had have done so).</p><p><br/></p><p>1<strong>. Reinforce 'Tone' at the Top and Ethical Culture</strong></p><ul><li><p>Establish a clear “<strong>values before profit</strong>” mandate embedded in the Board Charter, making ethical conduct a top priority in every Board, and leadership discussion and to be demonstratable throughout the organisation.</p><p><br/></p></li></ul><p><strong>2. Strengthen Risk Management and Internal Controls</strong></p><ul><li><p>Mandate an immediate root-cause analysis (RCA) after the 2013 incident, followed by Board-approved remediation plans with clear milestones and accountabilities. Strategic plans, objectives and goals need to align with (recommendation) remediation plans and therefore the new operational baselines established.</p></li></ul><ul><li><p>Require rotating, surprise internal audits of any workgroup with access to privileged information, reporting findings directly to the Board.</p></li></ul><p><strong>3.Activate Specialised Board Committees </strong>such as:  Audit and Risk – to oversee data-leak controls, review forensic-audit results, Governance and Remuneration - Tie partner bonuses to ethical KPIs and breach-free performance, Compliance and Ethics - Validate conflict-of-interest disclosures, champion whistle-blower cases; Strategy - Assess reputational risk in government engagements.</p><p><strong>4. Insist on Continuous Monitoring and Assurance</strong></p><ul><li><p>Require 'Plan-Do-Check-Act' (PDCA) cycles for all new confidentiality controls, reporting progress at each Board meeting.</p></li><li><p>Commission an external “health check” of governance processes every two years, with results tabled in full to the Board, and shared with leadership and cascaded as needed to uplift the controls and capability to support a continuously improved culture. </p></li></ul><p>5. E<strong>ngage Regulators and External Stakeholders</strong></p><ul><li><p>After initial ATO suspicions (raised from 2016), the Board could have proactively briefed the Tax Practitioners Board and AFP on its remediation steps—demonstrating transparency and commitment.</p></li><li><p>Invite an independent ethics ombudsman (or representative) to attend select Board sessions and provide unfiltered feedback.</p></li></ul><p><strong>6. Scenario-Test and Stress-Test Board Resilience</strong></p><ul><li><p>Run annual “tabletop exercises” simulating a confidentiality breach, customer lawsuits, or regulatory clampdown to test Board and Leadership decision-making speed and adequacy.</p><p><br/></p></li></ul><p>By embedding these interventions into Board practices, PwC Australia (board) could have:</p><ol><li><p>Detected and contained misuse of privileged information &gt; far earlier.</p></li><li><p>Demonstrated to regulators and the public that it took (and takes all) breaches seriously.</p></li><li><p>Aligned partner and staff incentives with ethical performance, not just revenue. (*may require an ESG lens and approach)</p></li><li><p>Maintained—or even strengthened—its market position by showcasing ;best-in-class' (or simply best-practice) governance by being responsive and proactive rather than reactive and in ‘damage control’.</p></li></ol><p>(Drawing on my product project delivery practice) If we were to apply a ‘Lessons Learnt &amp; Retrospective lens’ we could reflect and ask these questions (of PwC and to be put to their board) -</p><ul><li><p>How might a stronger 'Whistleblower Protection Policy' (training and comms) have accelerated internal reporting and subsequent incident management?</p></li><li><p>What (digital) assurance tools could provide the Board ‘real-time’ visibility into data flows and or red flag incidents? And;</p></li><li><p>Should Board self-assessments include a dedicated governance-maturity track? (governance maturity matrix ‘GMM’); and lastly; </p></li></ul><p><br/></p><p>By embedding these proactive, measurable interventions—rather than adopting a “watch and see” ('the fire burn') stance—the Board and C-level could have detected misuse faster, stopped ethical drift, and closed governance gaps long before a decade of misconduct took root.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-08-07 10:14:15 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537719627</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537839725</link>
         <description><![CDATA[<p>From my experience leading post-incident compliance programs—from Senate, Audit Office and Treasury enquiries to regulators such as the ACCC and SIRA,  recommendations and enforceable undertakings—when an organisation’s mission, values, vision and objectives are compromised, operational failure follows. Re-establishing and transforming those four pillars is essential to realign the business, restore trust and repair reputational damage. PwC is no exception. </p><p><br></p><p>PwC’s decade-long misuse of confidential tax-law drafts reveals a fundamental misalignment across its mission, values, vision, and objectives, where short-term revenue repeatedly trumped long-term trust.</p><p>Here we can see a clear departure and direct conflict of these 4 key areas (Mission, Values, Visions and Objectives);</p><p>·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Clear Mission Drift</p><p>·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Values compromised</p><p>·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vision vs. Execution – a clear gap of aspirational visions and operational realty</p><p>·&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Objectives Over Ethics</p><p><br></p><p>The misuse over (the documented) a ten-year span illustrates a stark departure from its stated mission to build trust and solve important problems. By treating government deliberations and respective briefings as purely ‘commercial assets’ to be ‘traded’, the firm prioritised client fees over public interest (revenue over ethics and integrity) —a certain lapse that a timely, ‘mission-aligned’ intervention might have prevented.</p><p>(PwC’s) Core values of integrity, teamwork, and excellence similarly unravelled as privileged information was circulated internally for profit, collaboration became inward facing (i.e. doing business with themselves) to drive revenue rather than (a higher) societal benefit, and excellence came to mean ‘crafting’ aggressive (and ‘dodgy’) tax schemes instead of upholding ethical standards.</p><p><br></p><p>Although PwC aspires (*aspired) to lead the professional services industry with thought leadership and ethical stewardship, it took a decade before fire-walled advisory teams, robust incident-management protocols, and clear accountability measures were put in place. This delay exposed a significant gap between the firm’s aspirational vision and its operational reality. Visions vs. Execution (were and) are direct odds with one another.</p><p>Commercial objectives— (such as the highlighted growth and market-share targets) consistently overshadowed clear essential confidentiality and conflict-management guardrails. Lacking enforceable KPIs (and remuneration incentives) tied to ethical conduct, the firm only realigned its priorities after suffering severe financial losses, mass partner and employee exits (or forced exits), and intense public backlash (and scrutiny).</p><p><br></p><p>Such systemic misalignment will naturally underscore the absolute necessity of embedding proactive governance measures such as - firewalls, continuous monitoring, ethical KPIs, and rapid critical incident response—into every level of strategy and execution from the outset.</p><p><br></p><p>The So what? The PwC saga proves that without embedding proactive, mission-aligned governance—complete with firewalls, continuous monitoring, ethical KPIs, transparent reporting, spot independent auditing, and rapid incident response—into the very fabric of operations, even the most prestigious firms (can and will) risk catastrophic reputational, financial, and operational collapse. Thus putting all - Mission, Values, Visions and Objectives - in serious jeopardy.</p>]]></description>
         <enclosure url="" />
         <pubDate>2025-08-07 13:59:35 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537839725</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537889569</link>
         <description><![CDATA[<p>Question 3 –</p><p>When a (professional services) firm entrusted with shaping public policy (such as in the case study tax breach) fails to safeguard government (briefings / outcomes) deliberations, the fallout is - and should be - swift and severe. Similarly that Boards (from any organisation different and same) must absorb the hard-won insights from the PwC breach and build ironclad governance that not only protects sensitive information but also preserves public trust.</p><p><br/></p><p>Referencing my reply for question 1 applying the lessons learnt lens, and combining the 4 key pillars (mission, values, visions and objectives) reply in question 2 - in short - these 6 high level key lessons from PwC's clear failures as follows for similar and or any other business where these pillars are compromised;</p><ol><li><p>Embed Mission and Values into Governance -Every board agenda, policy approval, and strategic discussion should be mapped directly to your organisation’s mission, vision, values, and objectives.</p></li></ol><p>2.  Approve Comprehensive Confidentiality and Conflict Protocols - Executives need a board mandate to implement ironclad confidentiality controls that mirror program-level firewalls on a corporate scale.</p><p>3. Align Executive Incentives with Integrity Metrics - Performance frameworks must reward ethical behaviour just as they do financial and operational targets.</p><p>4. Establish and Embed a Rapid Incident Response (Team ‘IRT) pr Crisis Management Team (CMT) - A mature crisis-management capability must be sponsored and monitored at the board level; this will also tether into a disaster recovery unit (and should be stood up if not already) that will include establishing and reviewing applicable controls, policy and process should any said crisis or incident become identified.</p><p>5. Champion Transparency and Accountability - Board leadership sets the tone for openness and responsibility across the organisation. This includes transparent reporting top down.</p><p>6. Oversight and Continuous Improvement - Maintaining robust governance demands ongoing attention and refinement from the board.</p><p><br/></p><p>By internalising these lessons, boards can transform reactive remediation into proactive, responsive resilience—ensuring that when they advise on government’s (being the public's) most sensitive matters, they do so with unwavering integrity and the full weight of a mission-aligned governance framework.</p><p><br/></p><p>A final lesson that needs to hold gravity – and one from professional personal experience – if a similar organisation within the same or similar industry experiences the same or similar breach as PwC did - the applicable regulatory body and relevant government bodies will ensure that they make an example of that organisation. &nbsp;The rationale - the organisation at the centre of the ‘new’ breach failed to proactively safeguard their business, internal and external stakeholders and therefore did not apply responsive lessons learnt - to ‘check their own backyard’ - in ensuring robust guardrails and at a minimum tactical stop gaps and controls are in play. (<em>See also Telco / ACCC – Telstra and now Optus – mis selling, rewarding / unconscionable behaviour and fraud).</em></p><p><br/></p><p>The so what - Boards and executives <strong>must </strong>anchor every decision in a unified mission and values, enforce robust confidentiality and conflict-management protocols, tie executive incentives to integrity KPIs, institutionalise rapid incident response, champion transparency and accountability, and sustain continuous oversight and improvement to protect confidential government engagements and preserve public trust.</p><p><br/></p><p>Lastly, the board and organisation may also consider exploring the following to build evidentiary, robustness, collective ownership and standards:</p><ul><li><p>Benchmarking the firm’s confidentiality controls against cross-industry standards (financial services, defence).</p></li><li><p>Integrating scenario-based ethics training into new employee, partner and vendor onboarding.</p></li><li><p>Establishing an annual “Ethics Hackathon” to crowdsource new safeguards from employees at every level.</p></li></ul><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2025-08-07 15:05:56 UTC</pubDate>
         <guid>https://padlet.com/governanceinstitute/k9ykihohw6okljke/wish/3537889569</guid>
      </item>
   </channel>
</rss>
