KPMG International Cooperative

Netherlands · kpmg.com · 18 vendors

KPMG International Cooperative is a global organization of independent professional services firms. It provides Audit, Tax, and Advisory services to businesses, governments, and public sector agencies worldwide, helping them address complex challenges and drive sustainable growth.

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 4 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-08-17 · revision 11

18 direct vendors, 248 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

KPMG exhibits medium-high migration readiness, scoring 70. The company's internal tech stack is highly conducive to migration, featuring extensive adoption of major cloud platforms (Microsoft Azure, Google Cloud Platform, Oracle Cloud, IBM Cloud) and modern data and AI technologies. Strategic initiatives like "KPMG Velocity" and the "KPMG Workbench" multi-agent AI platform highlight a proactive approach to digital transformation and the adoption of modern architectures. Financially, KPMG's strong and growing revenue base provides ample resources to fund significant migration projects. However, migration readiness is significantly challenged by the extremely complex regulatory environment and extensive data residency requirements. Operating in 138 countries, KPMG faces intricate GDPR data localization preferences, Netherlands-specific data protection, financial services data residency, and country-specific data sovereignty laws. These requirements necessitate meticulous data mapping, legal review, and architectural design, substantially increasing the complexity, cost, and timeline of any large-scale migration. While the diverse vendor ecosystem (based on the internal tech stack) reduces single-vendor lock-in, managing migrations across numerous critical vendor platforms (e.g., Microsoft, Google, ServiceNow, Salesforce, SAP, Oracle) introduces considerable integration and coordination challenges. The pending assessments for NIS2, HIPAA, SOC2, and ISO 27001 also add layers of compliance validation that must be integrated into migration planning.

Compliance

11 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

KPMG International is headquartered in the Netherlands (EU), making GDPR universally applicable. The organization explicitly references the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as its supervisory authority, processes personal data of EU/EEA residents at scale across 143+ countries, and has published a detailed privacy statement referencing GDPR legal bases (consent, legitimate interest, contract, legal obligation). Risk is rated Medium rather than Low because: (1) KPMG operates a complex multi-entity global network with cross-border data transfers, increasing the surface area for compliance gaps; (2) KPMG handles sensitive client data including financial records and special category data (diversity, health); (3) GDPR enforcement by the Dutch AP and other EU DPAs has intensified; (4) cross-border data transfers outside the EEA (to 143+ countries) require ongoing SCCs/adequacy decisions management. However, risk is not High because KPMG has demonstrated active compliance infrastructure (Global Privacy Office, DPO-equivalent contact, published privacy policy with GDPR-aligned legal bases, cookie consent mechanisms, and data subject rights procedures).

Evidence: https://kpmg.com/xx/en/misc/privacy.html, https://kpmg.com/xx/en/misc/governance.html, https://kpmg.com/xx/en/home/about/offices.html, https://autoriteitpersoonsgegevens.nl/en

NIS2 (source) — Assessment Required

NIS2 risk is rated High for the following reasons: (1) KPMG International is headquartered in the Netherlands (EU) and operates extensively across all EU member states; (2) KPMG's member firms provide services to Essential and Important Entities (banking, financial markets, energy, healthcare, transport, public administration), which may classify KPMG itself as an ICT service management provider or digital provider under NIS2 Annex I/II; (3) KPMG's global IT infrastructure, cloud platforms, and managed services offerings could qualify it as a 'managed service provider' or 'digital service provider' under NIS2 scope; (4) KPMG far exceeds the size thresholds (50+ employees, €10M+ turnover) — it employs ~265,000 people globally with revenues exceeding €35 billion; (5) NIS2 penalties can reach €10M or 2% of global annual turnover for Essential Entities; (6) The Netherlands transposed NIS2 into national law (Cyberbeveiligingswet) effective October 2024; (7) Non-compliance risk is elevated because NIS2 is newly transposed and many organizations are still assessing their classification. Assessment Required because KPMG's precise NIS2 entity classification (Essential vs. Important) depends on how Dutch/EU regulators classify professional services firms providing ICT and advisory services to critical sectors.

Evidence: https://kpmg.com/xx/en/misc/governance.html, https://kpmg.com/xx/en/our-insights/risk-and-regulation.html, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.ncsc.nl/onderwerpen/nis2, https://www.rijksoverheid.nl/onderwerpen/cybersecurity/cyberbeveiligingswet

ISAE 3000 (source) — Compliant

Risk is rated Low because: (1) KPMG is one of the world's leading providers of ISAE 3000 assurance services — it is the auditor, not the auditee, in most ISAE 3000 contexts; (2) KPMG member firms are licensed and regulated by national audit oversight bodies (e.g., AFM in the Netherlands, FRC in the UK, PCAOB in the US) to perform assurance engagements; (3) KPMG's audit and assurance practice is its core business, and ISAE 3000 compliance is fundamental to its professional license to operate; (4) Non-compliance with ISAE 3000 standards would result in loss of audit licenses — an existential risk that KPMG actively manages. Risk is Low because KPMG's entire business model depends on maintaining ISAE 3000 compliance, and it is subject to continuous regulatory oversight by audit supervisory bodies.

Evidence: https://kpmg.com/xx/en/what-we-do/services/audit.html, https://kpmg.com/xx/en/what-we-do/services/ESG.html, https://kpmg.com/xx/en/misc/transparency-reporting.html, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits, https://www.afm.nl/en/professionals/onderwerpen/accountantsorganisaties

Financials

Three-year financials

Financial Resilience Score: 7/10

KPMG demonstrates strong financial resilience underpinned by its scale (US$39.8bn in FY25 aggregated revenues), global diversification across ~138 countries, and three well-balanced service lines (Audit, Tax & Legal, Advisory). Revenue has grown every year from FY21 (US$32.1bn) to FY25 (US$39.8bn), a ~5.1% CAGR, showing durability through pandemic aftermath, high interest rates, and geopolitical volatility. Regulatory tailwinds from BEPS/Pillar Two tax reform, CSRD/ESG disclosure requirements, and AI assurance demand support continued growth in higher-margin advisory and tax services. However, KPMG remains the smallest of the Big Four (behind Deloitte ~US$70bn, PwC ~US$56bn, EY ~US$52bn) and operates a federated partnership structure where KPMG International Limited does not consolidate member firm financials. No global EBIT or equity is publicly disclosed, limiting transparency into profitability and balance-sheet strength. The network faces reputational contagion risk from member-firm scandals (e.g., South Africa Gupta, UK Carillion), ongoing regulator scrutiny on audit quality (PCAOB, FRC, AFM), advisory cyclicality (only 2-2.9% growth in FY24-25), and Asia-Pacific weakness tied to China's slowdown. A US$4.2bn 3-year investment programme in technology, AI, talent, and ESG (with US$1.7bn+ deployed in FY24) and strategic alliances with Microsoft, Google, ServiceNow, SAP, Oracle, Salesforce, Workday, and Anthropic support competitive positioning. The Big Four oligopoly provides structural protection via regulatory licenses, scale, brand, and talent barriers to entry.

Key strengths: Scale with US$39.8bn aggregated FY25 revenues across ~138 countries, Consistent multi-year revenue growth (FY21-FY25 CAGR ~5.1%), Diversified across Audit (35%), Tax & Legal (23%), Advisory (42%), Regulatory tailwinds from Pillar Two, CSRD/ESG, and AI assurance demand, US$4.2bn 3-year investment plan in technology, AI, talent, and ESG, Big Four oligopoly with high barriers to entry, Strategic alliances with Microsoft, Google, ServiceNow, SAP, Oracle, Salesforce, Workday, Anthropic, Audit business grew 6% in FY25 reflecting strong core franchise

Risk factors: Federated partnership structure with no consolidated balance sheet, No public disclosure of global EBIT or equity, Reputational contagion from member-firm scandals (South Africa Gupta, UK Carillion), Regulator scrutiny of audit quality (PCAOB, FRC, AFM) with material fines, Advisory cyclicality: only 2% growth FY24 and 2.9% FY25, Asia-Pacific weakness: -1.6% in US$ in FY24, tied to China slowdown, AI disruption to traditional labour-based service pricing, Talent inflation and partner compensation pressure, Multi-disciplinary model conflicts with regulators (potential audit/consulting split), Smallest of the Big Four by revenue

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report