Investigation

Who Audits the Auditors?

Four firms audit 99% of the S&P 500. They can't be fired. They've never permanently lost a licence. And they're the ones certifying that your VPN keeps no logs, your cloud storage is encrypted, and your browser respects your privacy.
Published June 2026 26 sources cited 4 firms investigated
97%of US market cap
audited by Big Four
$180Bcombined annual
revenue
£100M+UK fines in
5 years
0licences permanently
revoked

KPMG stole the test answers from the regulator

Between 2015 and 2017, KPMG executives recruited former employees of the PCAOB — the body that inspects auditors — to steal confidential data revealing which audits would be inspected next. They used this to prepare in advance and "game the system." Five people were charged with conspiracy and wire fraud. KPMG's former head of National Office was sentenced to prison. $50 million penalty.[17]

The auditor cheated the audit of the auditor.

EY verified €1.9 billion using screenshots

For nearly a decade, EY gave Wirecard clean audit opinions. To verify the existence of €1.9 billion supposedly held at a Singapore bank, EY relied on screenshots and documents provided by Wirecard itself. They never called the bank. The bank later said the account never existed. The German watchdog found EY's work "grossly negligent." Wirecard collapsed. €24 billion in value erased.[7]

KPMG forged documents when the regulator came looking

During spot checks on KPMG's audit of Carillion, staff manufactured fake evidence and presented it as documents that had been "through oversight not included on the audit file." The FRC Tribunal was unequivocal: "No accountant should require any education or training to realise that deliberately misleading anyone, but especially a regulator, is at least incompatible with integrity."[18]

Months later, Carillion collapsed with £7 billion in liabilities. KPMG's CEO called the audit work "very bad" and said he "simply cannot defend" it.[9]

EY knew Lehman Brothers was hiding debt. They said nothing.

EY audited Lehman Brothers for years. They were aware of Repo 105 — a scheme to disguise repurchase agreements as sales to hide billions in debt. A Lehman VP warned EY directly. EY failed to alert the board. The bankruptcy examiner concluded EY's failure "amounted to negligence and malpractice." Then the global financial system collapsed. $99 million settlement.[13]

All four firms cheated on their own ethics exams

This is not a metaphor. EY was fined $100 million by the SEC — the largest fine ever imposed on an audit firm — after at least 49 auditors shared answer keys to CPA ethics exams. Hundreds more cheated on continuing education. EY then withheld evidence of the cheating from SEC investigators, which doubled the penalty.[15]

The PCAOB separately fined Deloitte, PwC, and EY a combined $8.5 million for widespread exam cheating in the Netherlands alone. Hundreds of professionals including senior leaders cheated over five years.[16]

The firms that can't pass their own integrity tests are the ones certifying your VPN, your password manager, your cloud storage, and your browser.

In South Africa, KPMG's auditor was "complicit in the cover-up"

KPMG gave VBS Mutual Bank a clean bill of health in 2017. Months later, it collapsed with R2 billion looted. The independent investigator concluded the looting "would not have been possible had KPMG not signed off on the bank's financial results" and that the KPMG auditor was "complicit in the cover-up." The audit partner was debarred for life.[14]

The chain of custody

Every "independently audited" claim follows the same chain. At every link, the conflict of interest is structural:

You
Trust the product because it says "independently audited"
The tech company
Chose the auditor. Paid the auditor. Negotiated the scope.
$$
The Big Four auditor
Checked for 8 days. Said "nothing came to our attention."
The regulator (PCAOB / FRC / SEC)
Has fined them repeatedly. Has never permanently revoked a licence.
↑ The Big Four advise the regulator on the rules that govern auditing ↑

The Big Four audit 97% of US market capitalisation and 99% of the S&P 500.[5] There is no alternative market. The regulator cannot revoke their licences because the economy depends on them. They know this. The fines are a cost of business — a fraction of their $180 billion in combined annual revenue.

The Project On Government Oversight calls this "Accounting's Big Lie": "The audit firms are not independent — they are dependent."[4]

How "independent" audits actually work

The privacy audit standard (ISAE 3000) has no prescriptive methodology. Scope is negotiated with the client. Many reports provide only "limited assurance" — the negative statement "nothing came to our attention." Companies rarely disclose which level of assurance they obtained. The same standard is used across VPNs, cloud storage, and financial services.[1][2]

Deloitte's 2023 NordVPN audit ran 30 November to 7 December — eight days to verify year-round no-logs claims. Fewer than 40% of VPN vendors undergo genuine third-party audits, yet almost all claim privacy protections.[3]

Consumer Reports tested 16 VPNs and found 12 either inaccurately represented their products or made hyperbolic claims. Six were vulnerable to brute force attacks.[6]

The pattern repeats across categories. EY audits Google Chrome, Gmail, Google Drive, and Microsoft 365. Deloitte audits Facebook. The same firms whose financial audits missed billions in fraud are now certifying privacy and security controls across the products people use every day.

The full record

FirmCaseWhat they missedConsequence
EYWirecard (2020)€1.9B that didn't exist. Decade of clean opinions.[7]EY banned 2 years in Germany.
PwCEvergrande (2024)"Turned a blind eye." 14 years of auditing.[8]$62.2M fine + 6-month China ban.
KPMGCarillion (2018)£7B in liabilities. Clean opinion months before collapse.[9]£21.4M fine.
EYNMC Health (2020)$4B hidden debt. Management picked its own audit samples.[10]£105.5M settlement.
DeloitteAutonomy/HP (2011)£118M hidden losses. "Serious and serial failures."[11]$8.8B HP writedown.
PwCSatyam (2009)Fictitious assets. SEC: "much larger quality control failure."[12]2-year India audit ban.
EYLehman (2008)Knew about Repo 105 debt-hiding. Said nothing.[13]$109M in settlements.
KPMGVBS Bank SA (2018)R2B looted. Auditor "complicit in cover-up."[14]Partner debarred for life.

In Australia, it's worse

In Australia, the Big Four don't just miss fraud. They leak government secrets, suppress reports on illegal welfare schemes, and fabricate academic citations — all while collecting $3.2 billion in federal contracts over five years.[26]

PwC: "Project North America"

PwC's head of international tax signed three confidentiality agreements with Treasury, then leaked confidential briefings on new anti-avoidance tax laws to 143 PwC partners. They used the leaks to contact 23 US tech companies — including Google, Uber, and Facebook — on how to dodge the laws before they were even publicly announced.[19][20]

CEO resigned. 12 partners forced out. AFP criminal investigation. PwC sold its government arm for $1. Revenue fell 26%. The Senate titled its report "A calculated breach of trust." Despite the purported ban, PwC and its successor held $138 million in federal contracts.[21][22]

PwC: The Robodebt report that was never delivered

PwC was paid ~$1 million to review the Robodebt scheme. The DHS Secretary told PwC partner Terry Weber the report "was not to be finalised." PwC delivered an 8-page PowerPoint instead of the contracted 70-page report, billed the full amount, and the illegal scheme continued for two more years. Hundreds of thousands of people received unlawful debts. $1.8 billion class action settlement.[23]

KPMG: Leaked client papers to win tenders (2025)

KPMG allegedly shared confidential Lendlease board papers to win Westpac and Dexus audit tenders. Same pattern as PwC — using confidential information for commercial advantage. CEO and top auditor resigned. ASIC investigating. $650 million in federal contracts at risk.[24]

Deloitte: Fabricated citations in a $440K government report (2024)

Deloitte used GPT-4o to write a 237-page "independent assurance review" of an automated welfare penalty system. The report contained fabricated academic citations and invented court references. Caught not by Deloitte's quality controls, but by a University of Sydney researcher. Deloitte refunded $97K of $440K. Did not disclose AI use.[25]

A $100 million KPMG Defence contract revealed governance failures so casual that officials congratulated themselves for not recording minutes of a meeting. The "only negative" noted was that "the donuts arrived too early."[26]

What this means when any product says "independently audited"

We track Big Four audit involvement across 14 product categories. The same firms appear everywhere:

CategoryProductAuditorStandardAssurance
VPNExpressVPNKPMGISAE 3000Limited
NordVPNDeloitteISAE 3000Limited
PIADeloitteISAE 3000Limited
SurfsharkDeloitteISAE 3000Limited
Cloud StorageTresoritEYISAE 3000Reasonable
Google DriveEYSOC 2 / ISO 27001
DropboxEYSOC 2 Type II
BrowserGoogle ChromeEYSOC 2 Type II
EmailGmailEYSOC 2 / ISO 27001
ProductivityMicrosoft 365EYSOC 2 / ISO 27001
Social MediaFacebookDeloitteSOC 2 Type II
FinanceWiseDeloitteSOC 2 Type II

Every VPN audit above used limited assurance — the lowest level. Tresorit is the only product with reasonable assurance. EY alone audits Google Chrome, Gmail, Google Drive, Dropbox, and Microsoft 365 — a single firm certifying the security of products used by billions. Products not listed (Mullvad, Proton VPN, Bitwarden, Signal, Firefox) use specialist auditors or open-source code instead. See individual category pages for full audit comparisons: VPN, password manager, cloud storage, browser, email, finance.

What actually works

If Big Four stamps don't verify privacy claims, what does?

MechanismTypeWhy it's strongerExamples
Open-source codeVerifiableAnyone can inspect. Backdoors visible.Mullvad, Bitwarden, Signal, Firefox
Court-tested claimsAdversarialSubpoena or seizure returned zero data.PIA (FBI subpoena), ExpressVPN (Turkey seizure)
Specialist security auditTechnicalPen testing + source code review. Finds real bugs.Cure53 (Mullvad, 1Password), NCC Group (Signal)
Bug bountyContinuousCrowdsourced. Ongoing. Pays for results.ExpressVPN ($100K), 1Password (Bugcrowd)
RAM-only serversHardwareLogging physically impossible.ExpressVPN, Mullvad, PIA
Zero-knowledge architectureStructuralProvider mathematically cannot access data.Tresorit, Bitwarden, Proton Mail
Big Four compliance auditCooperative8-day snapshot. Scope controlled by client.KPMG/Deloitte ISAE 3000, EY SOC 2

The gold standard

Open-source code + specialist security audit + bug bounty + structural privacy guarantees. Verifiable trust, adversarial testing, continuous monitoring, and architecture that makes privacy violations impossible. No Big Four stamp needed.

Products like Mullvad VPN, Bitwarden, and Signal achieve this across different categories. None has ever cited a Big Four audit.

Our position

DeviceGuardian treats Big Four audits as one data point, not as proof. We weight observed behaviour over stated claims, court tests over paid audits, open-source code over compliance stamps, and who owns the company over who audited it.

A Deloitte stamp does not prevent a low grade — in any category. A product without a Big Four audit can earn a strong grade through open-source transparency, adversarial testing, and architecture that makes privacy violations physically impossible.

The firms investigated here — Deloitte, KPMG, PwC, and EY — have full entity pages documenting their inherited risks. When their names appear in product findings across our database, they link directly to these pages.

Sources

  1. 1ISAE 3000 — Wikipedia
  2. 2ISAE 3000 Explained — DISA
  3. 3VPN No-Logs Policies: How to Verify Claims in 2026
  4. 4Accounting's Big Lie and How to Fix It — POGO
  5. 5SEC Probing Big Four Over Conflict of Interest — The Hill
  6. 6VPN Testing: Poor Privacy, Hyperbolic Claims — Consumer Reports
  7. 7German Watchdog Finds EY's Wirecard Audits Grossly Negligent — Irish Times
  8. 8China Slaps PwC with Record $62.2M Fine — SCMP
  9. 9FRC Fines KPMG for Damning Carillion Audit Failings — Compliance Week
  10. 10EY Faces £2bn Lawsuit Over NMC Health Audit Failings — Accountancy Age
  11. 11Deloitte Record Fine for Autonomy Audit — Consultancy.uk
  12. 12PwC's 2-Year Audit Ban in India — Accountancy Age
  13. 13EY Settles Lehman Brothers Audit Suit — CFO.com
  14. 14KPMG Involvement in VBS Corruption Scandal — Consultancy.co.za
  15. 15Texas Hits EY with $3M Ethics Penalty — Accounting Today
  16. 16PCAOB Fines Netherlands Big Four Affiliates $8.5M for Exam Cheating — PCAOB
  17. 17KPMG $50M Settlement for Stolen PCAOB Data — Debevoise
  18. 18FRC Sanctions Against KPMG — Financial Reporting Council
  19. 19Timeline: PwC Australia Tax Leaks Scandal — International Tax Review
  20. 20Damning Emails Reveal PwC's Multiple Breaches — The Mandarin
  21. 21PwC Takes 26% Revenue Hit from Tax Leaks Scandal — Accounting Times
  22. 22PwC and Scyne in $138M Federal Bonanza — Crikey
  23. 23PwC and the Robodebt Royal Commission — Michael West Media
  24. 24KPMG Australia Audit Leak Scandal — Investing.com/Reuters
  25. 25Deloitte's AI Governance Failure — Computerworld
  26. 26KPMG: The Big Four Darling of Defence — Michael West Media

© 2026 DeviceGuardian — arewescrewed.org

Disclaimer · Methodology