KPMG LLP (KPMG), the United States member firm of KPMG International Ltd., is committed to protecting client confidential information, including only using it for permissible purposes
Systems: The KPMG information security framework consists of comprehensive policies, procedures, and standards used to help secure information resources and protect confidential information entrusted to us by our clients. Our system of internal controls is consistent with applicable authoritative sources and industry standards, as well as professional standards promulgated by the American Institute of Certified Public Accountants (AICPA) for public accounting firms. KPMG also complies with all applicable data protection and privacy laws and regulations.
Our Code of Conduct: The KPMG Code of Conduct applies to all KPMG personnel. Among other things, it sets forth our values, responsibilities, and commitments and emphasizes the importance of our confidentiality obligations as a licensed accounting firm. Partners, employees and contractors sign confidentiality agreements upon hiring. Every year, they are required to provide an Annual Compliance Confirmation (ACC), which, among other things, is a re-affirmation of the employee's understanding of, and commitment to comply with, the following: the Code of Conduct, firm privacy, information security and confidentiality policies, and the terms of any applicable engagement agreements.
Related concepts in our Code of Conduct include:
- Encouraging all partners and employees to speak up if a situation makes them uncomfortable – no matter how large or small the matter or who is involved.
- How to report a situation anonymously using The Ethics & Compliance Hotline.
- Protections for whistleblowers, including KPMG’s strict policy against retaliation.
Review our Code of Conduct here.
Confidential Information: KPMG personnel are required to execute their work and handle data in accordance with the confidentiality requirements set forth in applicable contracts, laws and regulations, and professional standards, including the AICPA Code of Professional Conduct.
Training: KPMG personnel must complete Security Awareness and Privacy training when they join the firm and annually thereafter. These courses teach compliance and adherence to firm information security policies while working in the office, at home, at client sites, and when traveling. All training is tracked and reported for compliance through our internal Ethics and Compliance Reporting System.
Ongoing communications: Communications are a core aspect of the KPMG US Security Awareness Program, including to educate KPMG personnel on emerging security threats, relevant policies, and leading practices both internal and external to KPMG. Through firmwide collaboration, we utilize multiple communication vehicles and methods to deliver ongoing, meaningful, and consistent messaging. Communications are published both firmwide and, when needed, in a targeted fashion to focus messaging or guidance on specific groups. This approach helps drive behavioral change and ensures security awareness is an integral part of who we are as a firm.