What happened
It was reported in February 2026 that a KPMG Australia partner was fined 10,000 Australian dollars and required to repeat mandatory internal AI training after using AI to answer a question in the assessment.
The partner had completed the training in July 2025. It was reported that the course involved a reference manual, which the partner uploaded to an AI tool to help generate an answer, contrary to KPMG’s policy. The firm’s monitoring detected the incident in August.
KPMG said it had identified 28 instances of staff using AI contrary to policy in internal examinations since July 2025. The firm said it introduced monitoring in 2024, followed by a firm wide education campaign, and was continuing to introduce technology intended to block access to AI during testing.
What an auditable version would have shown
This one is different from many of the incidents in this library. KPMG’s own monitoring found the conduct. It did not first come to light through a customer complaint or a regulator.
What the public sources do not show is how many assessments were monitored or what proportion of unauthorised AI use the controls detected.
A record for each assessment could show whether an integrity check ran, what it found and what happened to the result afterwards.
Where the gap was
KPMG said AI use in these assessments was already against its policy. It also said monitoring introduced in 2024 found people using AI outside that policy.
A ConstraintGate is designed to check the rule when the assessment is submitted. A ConductRecord keeps the submission and the result of the integrity check. A MetricRecord is designed to count assessments checked, instances flagged and breaches confirmed.
That would make it possible to distinguish the number of breaches found from the reach of the system looking for them.
What governance should have looked like
KPMG said it introduced monitoring in 2024, followed it with a firm wide education campaign and continued introducing technology intended to block AI access during testing. It also said it would disclose AI related cheating cases in its annual results.
Where an organisation uses an assessment to show that required training has been completed, best practice would be to keep evidence showing how the assessment was completed alongside the result itself. The organisation could then report how many assessments were checked, how many were flagged and how many breaches were confirmed.
Failure Pattern: it was reported that a partner used AI contrary to firm policy while completing mandatory internal AI training. KPMG’s own monitoring detected the conduct.
Governance Principle: where an organisation uses an assessment to demonstrate that required training has been completed, it should be able to show what integrity checks were applied and what those checks found.
The reference implementation of ConstraintGate, ConductRecord and MetricRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- KPMG partner uses AI to cheat on AI test, faces fine, carrying the ASIC and professional body detail (Accounting Times, 17 February 2026)
- KPMG partner in Australia fined over using AI to pass AI test (The Irish Times, 16 February 2026)
- KPMG partner uses AI to cheat on AI test, faces fine (Cyber Daily, February 2026)
- KPMG partner fined for using AI tools to cheat in a test about AI (Business Standard, 16 February 2026)
- KPMG Australia penalises partner, report (International Accounting Bulletin, February 2026)