What boards need to consider about psychosocial risk
I facilitated a panel discussion in Melbourne last week with around 100 senior HR and HSE professionals. The panel, Dr Rod Gutierrez of dss+, Wade Needham of Natural Resources APAC, and Jackie Walsh of Bunnings, covered a lot of ground. But the conversation that stayed with me afterwards was the one about what actually reaches the board. Curiosity is a key requirement for all effective board members and this was driven home in the session.
The risk register isn't the risk
Wade Needham described a familiar scene: management brings a beautifully colour-coded risk register to the board, red, green, yellow. It's when a director asks whether the organisation is in or out of tolerance, or where resources are needed, that the conversation gets harder. A register tells you what's been documented but it doesn't tell you what's been done.
The Star judgment changed what "oversight" means
The Federal Court's decision in ASIC v Bekier, handed down in March this year, found that Star Entertainment's former CEO and Chief Legal and Risk Officer had breached their duty of care under section 180 of the Corporations Act, largely because critical risk information was buried and didn't reach the board in a form directors could act on. The non-executive directors weren't found liable in that instance, but the judgment was clear that directors can't simply rely on management assurances. They're expected to interrogate, probe and challenge what's put in front of them. Wade made the same point from the psychosocial risk angle: boards need to know at point of allegation, not after the fact, and they need enough detail to grade the seriousness without it becoming a reputational exercise in itself.
Training gaps are now a documented liability
Comcare's prosecution of the Department of Defence, which resulted in a conviction and a $188,000 fine after a worker's death, centred on a specific failure: supervisors weren't trained to recognise when a performance management process itself was causing psychological harm, or to know when to pause it. It's a stark example of how a well-intentioned policy, applied by untrained people, becomes the risk itself.
The complainant is not the problem
Wade raised something boards need to sit with directly: when a complaint lands, whether a whistleblower matter or an interpersonal one, the instinct is often to frame it as a threat to the trust in the management team, and by extension to treat the complainant as the problem. That instinct is precisely what the Star judgment penalises. The better question for a board is what the complaint is a symptom of, and whether it points to a structural issue in how work is designed.
Three functions, one system
Dr Rod Gutierrez's framing has stuck with me: operations owns the risk and implements the controls, HR designs many of those controls, and safety holds the assessment and evaluation process. For a board, the job isn't to pick which function owns psychosocial risk. It's to ask whether those three are actually connected, and to expect a straight answer.
If your board is asking what "enough" looks like on psychosocial risk, that's a conversation The Strategic Step Advisory can help you have.

