A KPMG Partner Used AI to Pass the Firm's AI Training Exam, and Got Caught
What happened
The test was designed to certify that KPMG Australia's staff understood how to use artificial intelligence responsibly. The irony is that one of the firm's own partners passed it by doing exactly what it warned against: feeding restricted course materials into an AI tool and submitting the output as his own work.
The partner, who holds registration as a company auditor in Australia, uploaded a reference document from an internal AI training course into an AI tool to answer an exam question. The document was drawn from the course itself, making the submission a violation on two counts: using unauthorized AI assistance during a credentialing exercise, and misusing materials the firm had designated for classroom instruction only. KPMG reportedly detected the activity in August 2025 through internal monitoring, not through any voluntary disclosure. The discovery triggered a formal internal investigation.
The firm imposed a financial penalty exceeding A$10,000, deducted from the partner's future income. Given the partner's seniority and registered auditor status, the incident carried professional weight beyond the firm's internal rules. A partner whose role includes signing off on corporate audits is held to a standard that treats procedural compliance as foundational, not optional. Passing a compliance certification through deception cuts at that standard regardless of how the deception was carried out.
Following the internal investigation, the partner self-reported the matter to Chartered Accountants ANZ, the professional body that governs registered auditors in Australia. Chartered Accountants ANZ confirmed it was investigating. Self-reporting in that context reflects the disclosure obligations that come with professional registration rather than a voluntary act of contrition. But the disclosure does not change what the underlying incident revealed: a person in a position of professional trust chose a shortcut through a program that was specifically designed to test judgment about that kind of shortcut.
The episode surfaces a problem that affects any organization running competency assessments in environments where AI tools are readily accessible. There is no reliable way, after the fact, to determine whether a submitted answer represents a person's own understanding or the output of a tool they were not supposed to use. A provable record of what a system did during an assessment window, and what materials were accessed while completing it, would make that determination possible without depending on monitoring luck or after-the-fact self-disclosure. Without it, certification programs measure access to AI tools as much as they measure the knowledge they were designed to verify.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.