10 minutes

When Culture Becomes A Legal Obligation: HR and Risk Executives Reimagining People Governance

Here's a tighter version: Boards are now named in Australia's psychosocial safety and positive duty frameworks. Not implied. Named. That changes what HR needs to bring into the boardroom. For years, HR reporting has given boards lag data: complaint volumes, engagement scores, turnover. Numbers describing what already happened. Under a proactive prevention standard, that's not governance, it's a record of outcomes the organisation was supposed to prevent. I spoke with Jeremy Gledhill, a Certified Practising Risk Manager with 20+ years reporting risk to boards, about this. Risk management has long grappled with the invisible value problem: when mitigation works, nothing happens, and the board sees an absence of harm rather than the work that prevented it. HR has been living that same problem without the language to name it. This piece sets out what board-level people risk governance needs to look like now, and what HR and boards need to build together to meet a standard the law already requires.
Written by
Jessie Ivancic
Published on
August 11, 2026

The legal obligations sitting on Australian boards in relation to culture and people risk have changed more substantially in the last three years than in the preceding two decades. Positive duty under anti-discrimination law, psychosocial risk obligations under work health and safety legislation, and the compounding effect of Fair Work Act reform have collectively moved culture and people risk from soft leadership territory into named legal accountability. Most board-level HR governance reporting was not designed for that standard. Something changed in Australian HR governance over the last three years that the profession hasn’t, in my opinion, fully realised.

The positive duty obligations under the Sex Discrimination Act 1984 (Cth), strengthened through the Respect at Work legislation in 2022 and backed by Australian Human Rights Commission enforcement powers from December 2023, require organisations to proactively eliminate unlawful conduct before it occurs. Not respond to it, prevent it.

The psychosocial risk framework under the model work health and safety law has shifted the obligation on organisations to identify, assess, and control psychosocial hazards with the same rigour applied to physical ones.

And then there is the Fair Work Act reform environment. The Closing Loopholes Acts, passed across 2023 and 2024, compressed years of substantial change into a short period, with commencements staggered across the following eighteen months. HR functions are still bedding down one change while the next one arrives.

The cumulative effect is this: HR is now carrying obligations that look and behave like risk management obligations. Preventative, evidence-based, demonstrable over time.

Most HR reporting infrastructure wasn’t built for that standard. It was built for headcount management.

If the board is accountable for culture, strategy, and risk oversight, and these new areas of obligation have emerged, the question for HR is how to inform the board of what it needs to feel confident that leadership is discharging its responsibility to manage these risks, and in turn, facilitating the board’s own oversight obligations.

To answer that, we first need to examine the metrics we consider indicative of cultural, strategic, and legal risk.

For a long time, HR practitioners have read the lead indicators of psychosocial harm through intuition. Moments, conversations, observations. Human experience has afforded us the ability to see patterns, identify concerns, deploy interventions, and monitor the temperature. But risk management is a more formal discipline. It involves matrices, numerical assessments, and documented controls. A structured approach to what HR has always done intuitively.

When you look closely, the process is essentially the same. Like formal risk functions, HR identifies, assesses, controls, and reviews. We just don’t label it that.

But in the era of psychosocial safety and positive duty, where demonstrating action before harm occurs is a legal obligation, our mental notes of those senses and observations are not demonstrable risk control.

So how do we formalise it? What can we learn from our risk executive colleagues? And how do we use appropriate language and frameworks to develop our risk maturity and legal compliance without trying to become a risk function?

Jeremy Gledhill is an enterprise risk and resilience leader with more than 20 years of experience across manufacturing, infrastructure, environmental services, and public sector organisations. A Certified Practising Risk Manager, he translates complex risk into clear, practical insight that supports confident decision-making. His experience spans enterprise risk frameworks, insurance program design and claims management, internal audit and assurance, and governance systems that strengthen organisational accountability. Jeremy is also an independent advisor to Nooma, O-HR’s safe, intelligent HR platform built by HR leaders for HR practitioners, business owners, and consultants, currently in its final stages of development before release.

When Jeremy came on board as an advisor, I was struck by how quickly we found shared language. This article draws on highlights from that conversation, with the aim of developing our collective approach to articulating HR’s value in risk terms.

What boards are actually asking for

Boards are future-focused. The data HR has traditionally provided is almost entirely retrospective. Retention rates, engagement scores, complaint volumes. These tell the board what has already happened.

Jeremy’s observation on this was direct: boards often receive people-related data from multiple sources, formal and informal, and when that data conflicts or uses nebulous terms like “culture problem” or “toxic environment,” the result is decision paralysis. “When the board is told we have a culture problem, what does that mean? And how are they supposed to react?”

Anyone who has read my articles or had the misfortune of sitting next to me at an industry event when this topic has come up knows my thoughts on the limitations of modern HR reporting, so I’ll be concise: The HRIS was never designed to capture the practice layer of HR work. It captures workforce transactions: headcount in and out, leave accrued and deducted. But the judgement, the early intervention, the risk actively managed before it became a complaint or a cost, none of that is visible in the system. And it was never designed to be.

What Jeremy and I agree on is that the gap is not one of awareness. HR practitioners understand the new obligations. The gap is methodological. The observations exist, but the systems to capture and communicate them in terms boards can act on have not, not so much.

The invisible value problem

This is where the two disciplines converge in a way I find genuinely clarifying.

Risk management has exactly the same structural problem. When mitigation works, nothing happens. No incident, cost, or claim. The value of the work is invisible by design. The board sees an absence of harm, not the activity that prevented it.

“The real skill is putting out the small fire before it turns into a bushfire,” Jeremy said. “The issue is it’s often seen as ‘it must not have been a big issue’ because it was resolved so easily.”

Short of the absence of lag indicators, there’s no real measure of the value created.  The investigation that never became a claim. The performance issue that was addressed early and didn’t escalate. The restructure designed so carefully that it didn’t generate a single grievance. None of that appears in a dashboard.

So how should we be reporting it? Jeremy suggests shifting board papers away from metrics-focused slides that look the same every month toward structured discussion prompts. Surface the activity, name what was observed, what was done, where the gaps remain. Make the judgement visible rather than collapsing it into a number.

Jeremy is right about the endpoint, but the reason HR reporting looks the way it does is that practitioners haven’t had the governance infrastructure to surface anything richer. When the register only exists as a spreadsheet someone updates quarterly, there’s nothing to discuss except the number. When the register captures condition, trend, controls, and rationale as a live record, the board conversation becomes genuinely possible.

Reporting people risk: from scorecard to governance record

A properly maintained people risk register gives you six things to report on: the condition that was observed and why it was registered; the inherent risk before controls were applied; the controls in place and whether they are holding; the residual risk after controls; the trend direction since last review; and the rationale for every governance decision made along the way. That is not a scorecard. It is a governance record. Used well, it gives HR the material to answer the questions executives and boards actually need answered: what are we watching, what are we doing about it, is it working, and what needs a decision from this group.

How many times have you seen a board member interrogate the risk numbers? It is understandable. A score quantifies their prioritisation of concern, and disagreement over scoring is common. Risk scoring involves professional judgement, and professional judgement varies. Two practitioners assessing the same condition may land on different scores. That is not a flaw to engineer out, it is an honest reflection of how people risk works. It is a subjective exercise. Where that becomes a problem is when the numbers consume the airtime that should be spent discussing the condition they were designed to surface.

A score without context is just a data point. The condition behind it is what requires governance. A useful checklist for HR leaders reporting people risk:

  • Report the condition, not just the level
  • Make judgment visible
  • Surface trend, not just status
  • Report what did not escalate and why
  • Name the controls that held, the conditions that were caught before they compounded, and where future work is needed.

That is evidence of a functioning system.

On psychosocial risk governance specifically

Jeremy’s concern about how organisations approach psychosocial risk is that when it is treated as a compliance exercise, copied and pasted or outsourced to someone who doesn’t know the organisation, the result is documentation without understanding. And without understanding the actual context and consequences, the controls cannot be fit for purpose.

“Get the risk team involved,” Jeremy said. “They love this work and can add real value.”

From an HR perspective, the positive duty obligations make this non-negotiable. Passive documentation is not a defence under a proactive prevention standard. The evidence needs to show consistent, reasonable action over time, not a single risk register filed and forgotten.

Jeremy’s recommendation for board reporting in this space was practical: don’t present the risk assessment to the board as reporting. Focus the board on accountability rather than overwhelming them with the details they cannot act on, including:

  • gaps identified against the organisation’s risk appetite
  • controls being implemented, by whom, and by when.

He also raised position description reviews as an underused governance mechanism. Organisations are consistently good at adding tasks and controls to roles and rarely good at removing them. Role creep in a changing world is a highly plausible, if not likely, concern.

I’d add a practical extension to that observation: consider building cyclical sampling of positions into your governance calendar for proactive assessment. Research into the SMART work design model identifies role overload, role conflict, and work-home conflict as primary design pathways to strain, burnout, and psychological injury, operating through accumulated demands rather than individual resilience. Organisations that conduct regular sampling of positions against these dimensions convert what is typically a one-time position description creation step into an ongoing governance control, generating the kind of consistent, documented action that a proactive prevention standard prescribes.

Lead indicators and the safety parallel

The DuPont Bradley Curve describes the maturity stages of a safety culture. Jeremy drew a direct parallel to where HR is now.

“If we start tracking HR practices, not just HR outcomes, we begin to build lead indicators.”

The consistency of how issues are raised and handled. The quality of early interventions. The patterns in how risk is managed before it surfaces as a formal matter. That is how safety culture is measured and defined. The lag indicators follow from the practice.

“This gives us a method of measuring culture much the same way as safety culture is measured,” Jeremy said.

Culture has two dimensions that organisations have largely treated as one. The first is sentiment: how people feel about their work, their team, their leadership. The second is behaviour: how issues are actually raised, how early signals are responded to, whether the norms that are supposed to exist are being practised or just assumed.

Engagement surveys measure the first. Case counts, complaints, and formal matters measure the second. Both are lag indicators. By the time the number appears, the harm has already occurred. That was once sufficient. It isn’t anymore.

What boards are not seeing is the layer before the case: the quality of early intervention, the consistency of how workplace norms are upheld, and the risk being actively managed before it becomes visible. That is the lead indicator layer. And it is almost entirely absent from how organisations report on people risk today.

That absence of visibility is itself a legal and compliance risk. Under Australia’s psychosocial safety framework and the positive duty introduced by Respect@Work, boards have named obligations: specific indicators they are expected to oversee, not just acknowledge. Job demands. Role clarity. The consistency of early intervention. The day-to-day practice of workplace behaviour norms.

What is missing is a way to see both sentiment and behaviour together, in real time, mapped against the exact indicators the law already requires boards to govern. Not a survey. Not a periodic review. A read of the organisation’s culture as it is actually operating, across the indicators that define psychosocial risk. That is the instrument boards do not yet have.

New obligations require new thinking and new alliances

HR is being asked to step into a role the profession hasn’t fully occupied before. That doesn’t happen by working harder inside the same frameworks. It requires honest evaluation of where our thinking, our language, and our reporting have not kept pace with what we are now accountable for.

As our job grows wider, curiosity and conversation with those sitting next to us at the table can deepen that reflection and clarify the path forward. The expertise HR needs to make this shift doesn’t have to be built from scratch. It already exists in the disciplines we share boardrooms with. Risk management has spent decades solving structurally similar problems. The frameworks are there. The language is there. And as this conversation reminded me, so is the willingness to engage.

The boardroom presence HR is working toward is more likely to be built through honest conversation than through better slide design.

A special thanks to Jeremy Gledhill

Jeremy Gledhill is Group Commercial and Risk Manager at Citywide Service Solutions, Certified Practising Risk Manager, RMIA Student of the Year Award finalist, and an independent advisor to Nooma. This piece was developed from a conversation between us on board expectations, people risk governance, and what HR reporting needs to become.

About Nooma

Nooma is O-HR’s AI-enabled Australian HR platform, currently in its final stages of development before release. It is designed to make the practice of HR visible, not just the workforce data it generates, giving HR leaders the governance infrastructure to evidence early intervention, demonstrate preventative action, and report with confidence. If the challenges discussed in this article resonate, join the waitlist to hear more about how we are building the technology to support them.

Join the Nooma waitlist

Follow for more on human-led HR leadership in the AI era.

O-HR

#HRLeadership #HRGovernance #CHRO #PositiveDuty #PsychosocialSafety #WorkplaceRisk #HumanLedHR #RiskManagement

References and further reading

Sex Discrimination Act 1984 (Cth), s 47C (positive duty provision)

Australian Human Rights Commission, Positive Duty under the Sex Discrimination Act 1984 (Cth)

Australian Human Rights Commission, Compliance and Enforcement of the Positive Duty (enforcement powers from 12 December 2023)

Safe Work Australia, Model Code of Practice: Managing Psychosocial Hazards at Work (2022)

Parker, S.K. & Knight, C. (2024), ‘The SMART model of work design: A higher order structure to help see the wood from the trees’, Human Resource Management, 63, 265–291

Centre for Transformative Work Design, SMART Work Design Model

DuPont Bradley Curve (developed 1995, DuPont Safety Resources)

Intelligent HR Newsletter
Jessie Ivancic, GAICD, is exploring frontier technology to advance Australian HR.
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.