One of the most common conversations we have with legal, risk, compliance and HR professionals is not about regulatory change. It is about the budget.
Increasingly, these leaders understand the risks facing their organisations. They understand the growing expectations of regulators. They recognise that privacy breaches, cyber incidents, workplace misconduct, financial crime, psychosocial risks, Artificial Intelligence (AI) governance can create significant legal, financial and reputational consequences. Yet many tell us they struggle to secure funding for initiatives aimed at addressing those risks.
Curiously, the same organisations rarely question expenditure on workplace health and safety. Safety training is funded. Safety systems are funded. Safety reporting is funded. Boards understand why these investments matter.
The question is why other areas of compliance are treated differently.
Australian boards have accepted that workplace health and safety deserves strategic attention and investment. Many have not yet reached the same conclusion about broader compliance risk. As regulatory expectations continue to evolve, that distinction is becoming increasingly difficult to justify.
The issue is not that directors do not care about compliance. Rather, many boards still see compliance as something owned by legal, HR or risk, rather than something that requires active board attention and investment. This often results in compliance initiatives competing for funding against revenue-generating projects, technology investments, or operational priorities, even though the consequences of compliance failures can be every bit as significant.
A major privacy breach can expose customer information, trigger regulatory investigations, result in compensation claims and damage customer trust. A cyber incident can shut down systems, disrupt services and create significant recovery costs. Failures relating to workplace conduct, anti-money laundering obligations, responsible lending or anti-bribery controls can lead to investigations, remediation programs, litigation and substantial financial penalties.
As former ASIC Chairman Greg Medcraft observed, boards and senior management are responsible for creating cultures where people take ownership of “doing the right thing”. Importantly, he argued that effective governance structures, systems and controls must support values and culture. In other words, compliance is not simply about having policies; it is about creating an environment in which compliant behaviour becomes part of how the organisation operates.
This theme is echoed by regulators today. APRA has repeatedly emphasised that boards have a profound influence on organisational culture, risk management and governance outcomes. Risk governance is no longer viewed as a technical exercise delegated to management. It is increasingly regarded as a core board responsibility.
Over the past two decades, Australian regulators have steadily increased their focus on director accountability and governance oversight. While the legal concept of limited liability remains fundamental to corporate law, there has been a clear shift towards holding directors and officers personally accountable where governance failures contribute to organisational misconduct. This trend is evident across workplace health and safety legislation, financial services regulation, anti-money laundering obligations, privacy and cyber governance expectations, psychosocial risk management, workplace conduct reforms and emerging AI governance frameworks.
As a result, boards can no longer assume that compliance failures will be viewed solely as operational matters to be addressed by management after the fact. Increasingly, regulators are asking what the board knew, what oversight it exercised and how it satisfied itself that appropriate controls were operating effectively before an incident occurred.
The Expanding Scope of Director Accountability
The following table highlights the breadth of areas where directors are now expected to provide active oversight.
| Area | Key Regulators | Board and Director Responsibilities | Potential Consequences |
| Workplace Health & Safety | SafeWork regulators, WorkSafe authorities | Exercise due diligence by understanding WHS risks, ensuring appropriate resources and processes are available, and verifying that systems for managing WHS obligations are operating effectively. | Personal fines, criminal prosecution, enforceable undertakings, and in the most serious cases, imprisonment. |
| Corporations Act Governance | ASIC | Act with care and diligence, act in good faith and in the best interests of the company, and take reasonable steps to oversee risk management and governance arrangements. | Civil penalties, compensation orders, director disqualification, pecuniary penalty orders and reputational damage |
| Financial Services | ASIC, APRA | Oversee conduct risk, operational resilience, breach reporting, compliance frameworks and culture. For APRA-regulated entities, CPS 230 now expressly requires management of operational risks including legal, regulatory, compliance, conduct, technology and data risk. | Regulatory action, licence impacts, banning orders, civil penalties |
| AML/CTF | AUSTRAC | Oversee AML/CTF governance, ensure appropriate senior management accountability, risk assessment, program approval, monitoring, escalation and reporting controls. | Significant penalties, enforceable undertakings, and regulatory investigations |
| NCCP and Consumer Credit | ASIC | Oversee responsible lending obligations and consumer protection frameworks. | Civil penalties, remediation programs, licence conditions and reputational damage |
| Privacy & Cyber Security | OAIC, ASIC, APRA | Oversee cyber resilience, privacy governance and data protection frameworks. | Civil penalties, OAIC investigations, ASIC scrutiny, class actions, compensation claims and reputational harm |
| Respect@Work & Psychosocial Risks | Australian Human Rights Commission, Fair Work Ombudsman, WHS regulators | Ensure the organisation takes proactive and proportionate measures to eliminate, as far as possible, relevant unlawful conduct, and manages psychosocial hazards under WHS duties. | Litigation, compensation claims, regulatory intervention and workplace disruption |
| Anti-Bribery & Corruption | ASIC, AFP and international regulators | Oversee anti-corruption frameworks, reporting systems and risk controls | Criminal investigations, penalties and exclusion from contracts or tenders |
| Modern Slavery | Australian Border Force | Oversee supply chain risk management, approve modern slavery statements and oversee supply chain risk identification, action and reporting. | Regulatory scrutiny, investor pressure and reputational consequences, although reforms to strengthen the Act have been under consultation. |
| AI Governance | OAIC, ASIC, APRA and emerging regulatory frameworks | Oversee responsible AI use, privacy impacts, bias controls, transparency and human oversight | Privacy breaches, discrimination claims, governance failures and regulatory scrutiny |
| Competition and Consumer Law | ACCC, ASIC where financial products/services are involved | Oversee consumer protection, misleading or deceptive conduct risk, unfair contract terms, pricing claims, greenwashing and complaint/remediation frameworks. | Civil penalties, corrective advertising, enforceable undertakings, remediation, litigation and reputational damage. |
| Employment Compliance & Wage Underpayments | Fair Work Ombudsman, Fair Work Commission, state/territory regulators | Oversee payroll governance, award classification, record keeping, contractor arrangements and escalation of underpayment risks. | Penalties, back-pay liabilities, enforceable undertakings, litigation, accessorial liability exposure and reputational harm. |
What is striking about this list is that many of these obligations barely featured in board discussions twenty years ago. Today, they are increasingly central to directors’ governance responsibilities.
Serious compliance failures increasingly invite scrutiny of board process. Regulators, courts, investors and counterparties may ask whether the board treated the risk as foreseeable, whether it received adequate information, whether it challenged management, and whether it ensured appropriate resourcing and controls. In that sense, compliance investment is not simply a legal spend. It helps demonstrate that the organisation took reasonable steps to identify and manage foreseeable risks.
What High-Performing Organisations Understand
Leading organisations understand that compliance is helps build resilience, strengthen trust and support long-term value creation.
For example, Goodman Group publicly identifies board oversight of financial and non-financial risk, compliance frameworks, sustainability, culture and governance as core board responsibilities. This reflects a broader understanding that compliance cannot be separated from organisational performance.
Similarly, APRA-regulated institutions are increasingly expected to demonstrate that risk management, governance and culture are embedded throughout the organisation rather than treated as separate functions.
The lesson is simple. High-performing organisations do not treat compliance as a collection of disconnected obligations owned by legal, HR or risk teams. They view compliance as part of the business’s operating system.
Deborah Coram, CEO of Safetrac, one of Australia’s leading compliance training providers, believes many organisations are still approaching compliance through an outdated lens.
“Most boards now understand why workplace health and safety deserves investment. What we’re seeing, however, is that privacy, cyber security, psychosocial risk, workplace conduct, financial crime and AI governance are often still competing for budget despite carrying potentially significant legal, regulatory and reputational consequences.”
Coram believes the issue stems from how compliance is often positioned within organisations.
“Too often, compliance is treated as a cost centre rather than a strategic control. The organisations that are performing best are not necessarily the ones spending the most money. They’re the ones embedding compliance into the way the organisation operates rather than treating it as an annual training exercise.”
The Compliance Control Pyramid
One reason compliance investment is often misunderstood is that organisations focus on individual activities rather than overall control effectiveness.
Policies establish expectations. Training builds awareness. Monitoring tests whether controls are operating effectively. Reporting provides visibility of emerging risks. Board oversight ensures accountability. Together, these elements form a system.
At the top of that system sits what matters most: capability.
Can employees recognise risks?
Can they make compliant decisions?
Can leaders identify issues before they become incidents?
Can the organisation demonstrate that it took reasonable steps to prevent misconduct?
As Coram explains:
“One of the biggest misconceptions we see is organisations treating compliance as a training problem rather than a governance problem. Policies don’t change behaviour. Training alone doesn’t change behaviour. Completion records don’t prove compliance. What matters is whether people understand their obligations and can apply them when it counts.”
This distinction is becoming increasingly important because regulators are no longer satisfied with asking whether training occurred. They are increasingly interested in whether controls were effective.
Compliance Is Becoming a Growth Issue
Perhaps the most significant misconception in Australian business is the belief that compliance and growth are competing priorities.
In reality, strong compliance frameworks often enable growth.
They help organisations enter new markets, satisfy customer expectations, strengthen culture, improve governance and respond more effectively to regulatory change. They provide confidence that risks are being managed appropriately and that the organisation is capable of scaling sustainably.
The organisations best positioned for long-term success are not those with the most policies or the highest training completion rates. They are the organisations that recognise compliance as a strategic business capability.
As regulatory expectations continue to expand, there is little evidence that scrutiny of board oversight will diminish. If anything, the trend points in the opposite direction. Directors are increasingly expected to oversee culture, cybersecurity, privacy, financial crime, workplace conduct, AI governance, consumer protection, and organisational resilience alongside traditional financial and safety responsibilities.
Workplace health and safety will rightly remain a critical priority for Australian boards. The real question is why other forms of compliance risk are not receiving the same level of attention.
Because compliance is not tested when things are predictable, it is tested when they are not.
And increasingly, regulators are asking boards to demonstrate that compliance was prioritised before the incident occurred, not afterwards.
