Quick Answer:
To mitigate the risk of non-compliance, work through seven steps: recognise where your real exposure sits, accept that the law applies regardless of your size or location, build training and policies as your reasonable steps defence, apply the ‘your honour’ test to decisions, make sure people can identify, report and resolve incidents, hold your management team to the standard, and send a consistent message from the top. The order matters. Six of the seven fail if the first one is skipped, because a business that has not recognised its exposure cannot resource the response.
In this guide
- What non-compliance costs now
- Step 1: Recognise the risk
- Step 2: The law does not discriminate
- Step 3: Training and policies as a reasonable steps defence
- Step 4: Respect the ‘your honour’ test
- Step 5: Identify, report and resolve incidents
- Step 6: A management team that carries the standard
- Step 7: A clear message from the top down
- The 7 steps to mitigate the risk of non-compliance at a glance
- How to tell whether the steps are working
- What good looks like on paper
- Bringing it together
- Frequently asked questions
It is everyone’s responsibility to do the right thing when it comes to fair work, privacy, and health and safety at work.
Not only because the law requires it, but because people have the right to be safe and to be treated fairly and with respect.
The most highly engaged businesses have leaders who set and maintain those standards, supported by a workplace compliance system that makes the standard visible.
What has changed since that idea was uncontroversial is the consequence of getting it wrong.
The steps below are the seven that good businesses take to mitigate the risk of non-compliance across those three areas, and they are the same seven whether you employ eight people or eight hundred.
This guide covers Australian federal workplace, privacy and work health and safety obligations. Work health and safety duties vary between states and territories, and Victoria operates under separate legislation.
What Non-Compliance Costs Now
Before the steps, the reason for them. Businesses that mitigate the risk of non-compliance well tend to have done this part first.
Three things changed in the last few years that make the old ‘risk versus cost’ calculation out of date.
| Area | What changed | Why it changes the calculation |
|---|---|---|
| Wages and conditions | From 1 January 2025, intentional underpayment of wages is a criminal offence. The Fair Work Ombudsman states prosecution can result in monetary fines, prison time, or both | Underpayment moved from a civil debt to be repaid into a matter with personal criminal exposure |
| Wages and conditions | Maximum civil penalties for serious contraventions were increased from 27 February 2024. For a non-small business employer, an underpayment penalty can be the greater of three times the value of the underpayment or the relevant penalty unit amount | The penalty now scales with the size of the underpayment rather than sitting at a fixed ceiling |
| Privacy | In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over the Medlab Pathology data breach, the first civil penalty of its kind under the Privacy Act | The maximum stopped being theoretical. There is now a decided case |
| Privacy | For serious or repeated interference, penalties can reach the greater of a penalty unit amount, three times the benefit obtained, or 30% of adjusted turnover during the breach period | A turnover-linked penalty means the exposure grows with the business rather than being absorbed by it |
| Workplace behaviour | The positive duty under the Sex Discrimination Act requires employers to take reasonable and proportionate measures to eliminate sexual harassment, sex discrimination and hostile workplace environments, and the Australian Human Rights Commission has power to enforce it | The obligation is preventative. Waiting for a complaint is no longer a compliant position |
| Health and safety | Psychosocial hazards are managed under the same framework as physical ones, and officers carry a personal due diligence duty | Workload, bullying and poor support became risk register items rather than culture issues |
The point of the table
None of these are edge cases or future proposals. Each is in force, and the privacy row now has a decided Federal Court penalty attached to it. A business still weighing compliance as a cost against an unlikely risk is using a model that the last three years has quietly retired.
Step 1: Recognise The Risk
Legacy compliance thinking treated risk as a physical matter. Time and money went to work health and safety understood as slips, plant and heights, which was sensible and remains necessary.
The gap is that the same rigour was rarely applied to conduct, privacy and pay.
Recognising the risk means naming your exposure across all three, in writing, with an owner.
Most businesses can describe their physical hazards and cannot describe their behavioural or privacy ones.
This step is covered in more depth in recognise the risk of compliance, which is the first post in this series.
| Exposure | The question that surfaces it | Where it usually hides |
|---|---|---|
| Pay and entitlements | Could we evidence correct rates and hours for every worker for the last seven years? | Award interpretation, casual loading, and unpaid time before and after shifts |
| Workplace behaviour | What would we produce if asked to show the reasonable and proportionate measures we take to prevent sexual harassment? | Policies that exist but were never trained, acknowledged or enforced |
| Privacy | Do we know what personal information we hold, where it is, and who can reach it? | Old systems, spreadsheets, and data kept long past its purpose |
| Health and safety | Is our risk register current, and does it include psychosocial hazards? | Registers that list physical hazards only |
| Contractors and labour hire | Do our duties extend to people who are not our employees? | The assumption that a contract transfers the duty, which it does not |
If any row cannot be answered in a sentence, that is your first exposure, not your worst one.
The worst one is usually whichever row nobody has been made responsible for.
Step 2: The Law Does Not Discriminate By Size, Type Or Location
There is a persistent belief that obligations scale with headcount, and it is the assumption that most often stops a smaller business from doing anything to mitigate the risk of non-compliance.
Some administrative requirements do scale. The underlying duties largely do not.
| The belief | The position |
|---|---|
| We are too small for this to apply | The primary work health and safety duty applies to a person conducting a business or undertaking of any size. The positive duty under the Sex Discrimination Act applies to all employers |
| We are a not-for-profit, so it is different | A business or undertaking includes not-for-profits. Volunteers are workers for work health and safety purposes |
| We are regional, so nobody is looking | Regulator jurisdiction is not geographic within a state, and complaints travel |
| Our people are contractors | Work health and safety duties are owed to workers, which includes contractors, subcontractors and labour hire staff. A contract does not move the duty |
| We use a labour hire provider, so they carry it | Both the provider and the host hold duties. They overlap rather than transfer |
Where size does change things
Small business employers are treated differently in some specific places, such as the threshold for certain Fair Work penalties and some record-keeping and reporting requirements. That is a difference in administration and penalty scale, not a difference in whether the duty exists. Confirm your specific position rather than assuming either way.
Step 3: Training And Policies Are Your Reasonable Steps Defence
This step is often stated too strongly, and the accurate version is more useful. Training and policies are not a guarantee against liability, and no measure is.
What they do is form the foundation of a reasonable steps position, which is the framework that actually gets applied when a claim is tested.
Say it accurately
The question a court or regulator asks is not whether a policy existed. It is whether the employer took reasonable steps in the circumstances. A policy nobody was trained on, could not locate, and had never seen enforced is evidence that the steps were not taken, not evidence that they were.
| Element | What makes it count | What makes it worthless |
|---|---|---|
| The policy | Current, specific to your operations, and written so a new starter understands it | Downloaded from a template, never localised, and dated four years ago |
| The training | Delivered, completed, and recorded against named individuals with dates | An email attaching the policy, with no record of who read it |
| Acknowledgement | Signed or system-recorded, and refreshed when the policy changes | Collected once at induction and never again |
| Enforcement | Applied consistently, including to senior and high-performing people | Applied to some people and not others, which is worse than not having the policy |
| Review | On a cycle and after every incident that tests it | Never revisited, so the policy describes a business that no longer exists |
The fourth row does the most damage. Inconsistent enforcement is not a neutral failure.
It is affirmative evidence that the standard was not real, and it is usually the fact that decides these matters. The systems view of the same problem is set out in audit-ready risk management.
Step 4: Respect The ‘Your Honour’ Test
This is the most practical test in the list and it costs nothing to apply.
Before you finalise a decision, ask how it would sound if you had to explain it, out loud, to somebody whose job is to decide whether it was reasonable.
| The decision | How it sounds in the room | What the test suggests instead |
|---|---|---|
| We knew about it but it was not a priority this quarter | An admission that the risk was identified and accepted without a decision-maker | Record the decision, who made it, and the reason. An accepted risk with an owner is defensible |
| The policy covers it | Invites the next question, which is who was trained and when | Be able to produce the training record before you rely on the policy |
| We dealt with it informally to protect everyone | Reads as no investigation and no record | Keep a proportionate record even for informal resolutions |
| That is how it has always been done here | Describes a practice, not a control | If the practice is right, write it down. If it cannot be written down, it is not right |
| Nobody complained | Directly contrary to a preventative duty | Show what you did to find the problem before anyone complained |
The test works because it converts a private judgement into a public one. Most decisions that later look indefensible were not made recklessly.
They were made quietly, by somebody who never had to say them out loud.
Step 5: Make Sure People Can Identify, Report And Resolve Incidents
A business only manages the incidents it hears about. Every organisation has a reporting rate well below its incident rate, and the gap is where the risk accumulates.
| Stage | What has to be true | The usual failure |
|---|---|---|
| Identify | People can name what counts, including behaviour and near misses | Workers think reporting is for injuries, so conduct and near misses are never raised |
| Report | There is one obvious route, and using it is low friction | Multiple channels, none of them clearly owned, so people ask a colleague instead |
| Acknowledge | The person knows it was received and what happens next | Silence, which is the single fastest way to stop future reports |
| Investigate | Proportionate, timely, and focused on cause before fault | Starting with who is to blame, which ends the flow of information permanently |
| Resolve | An action with an owner and a date, not a conclusion | The matter closes with a finding and nothing changes |
| Review the control | Controls are revisited after the incident, which regulation 38 requires | The incident closes without anyone asking whether the control failed |
The acknowledgement stage is the cheapest fix and the one most often missing.
Telling somebody what happened to their report, including when the answer is that nothing will change, keeps the information coming.
The mechanics of running this well are covered in psychosocial hazards at work, where the reporting gap is widest.
Step 6: A Management Team That Carries The Standard
Efforts to mitigate the risk of non-compliance fail at the middle far more often than at the top or the bottom.
Executives set the policy, workers are trained on it, and supervisors decide every day whether it is real.
- Give them the authority to stop work and make it explicit. A supervisor who has to seek permission to stop something unsafe does not have a control
- Train them as supervisors, not only in the task. Most are promoted for technical skill and never trained in the responsibility that comes with directing others, as set out in what supervisors and managers must consider when managing work health and safety risks
- Hold them to the same standard as everyone else. One exception for a high performer undoes the whole framework
- Measure what they escalate, not only what they resolve. A manager who never escalates is either in an unusually safe operation or absorbing risk quietly
- Make culture part of their role description so it is assessed rather than assumed
The signal to watch
If escalations from a team drop to zero, that is rarely good news. It usually means the team has learned that raising something creates work for them and changes nothing. Rising escalations in a new system are a sign it is working, not a sign the business got worse.
Step 7: Send A Clear Message From The Top Down
The final step is the one that makes the other six durable. Workers calibrate to what leadership does under pressure, not to what it says in a policy.
| What leadership does | What people conclude |
|---|---|
| Raises safety and conduct first at every all-hands, including good quarters | This is a standing commitment, not a reaction to something that went wrong |
| Applies the standard to a senior person publicly | The rules are real. This is the single most persuasive act available to a leadership team |
| Funds the control that was requested and explains the ones it declines | Requests are considered, so it is worth making them |
| Reports compliance outcomes to the board alongside financial ones | It is governed, and the officer due diligence duty is being met in a way that can be evidenced |
| Goes quiet on it when a deadline is tight | The standard is conditional, which is what people will remember |
The last row is the whole step in one line. Every organisation is compliant when it is not costing anything.
What people actually learn from is the one occasion it did, and the risk-aware culture that results is built or lost in those moments.
The 7 Steps To Mitigate The Risk Of Non-Compliance At A Glance
| Step | What it means | The one thing to produce |
|---|---|---|
| 1. Recognise the risk | Name your exposure across pay, conduct, privacy and safety | A written exposure list with an owner for each line |
| 2. The law does not discriminate | Duties apply regardless of size, structure or location | Confirmation of which obligations apply to you, in writing |
| 3. Training and policies | The foundation of a reasonable steps position | Completion records against named people with dates |
| 4. The ‘your honour’ test | Decisions you could explain out loud to a decision-maker | A recorded decision with the reason, for anything accepted |
| 5. Identify, report, resolve | People can raise things and see what happened | An acknowledged report with an action, an owner and a date |
| 6. Management carries the standard | Supervisors have authority, training and accountability | Supervisor training records and an escalation log |
| 7. Message from the top | Leadership applies the standard when it is costly | Compliance reported to the board alongside financial results |
If you can only start one, start with step 1. The other six are all responses to an exposure, and a business that has not named its exposures will resource the response to the wrong one.
How To Tell Whether The Steps Are Working
Every organisation believes its programme to mitigate the risk of non-compliance is functioning until something tests it.
These are the indicators that tell you earlier, and none of them requires an audit. The full method for assessing an individual hazard sits in how to run a workplace risk assessment.
| Indicator | What it means if it is healthy | What it means if it is not |
|---|---|---|
| Reports per month, by type | People trust the process enough to use it for conduct as well as injury | A flat or falling rate, with conduct reports near zero, means people are going around the system |
| Time from report to acknowledgement | Measured in hours, so people see the system respond | Measured in weeks, which teaches everyone that reporting is pointless |
| Proportion of actions closed on time | Actions have owners and dates that hold | A large overdue backlog, which is the clearest predictor of a repeat incident |
| Escalations from supervisors | A steady flow, including requests that get declined | Zero, which almost always means risk is being absorbed at the middle |
| Training completion, including managers | High and current, with managers completing before their teams | High for workers and low for managers, which is the most common pattern and the most damaging |
| Repeat findings | Rare, because reviews change the control | The same finding recurring, which means investigations end at conclusions rather than actions |
Tracking these continuously rather than annually is what separates a live programme from a folder, and it is the argument for continuous risk monitoring.
What Good Looks Like On Paper
If a regulator, an insurer or a court asks how you mitigate the risk of non-compliance, these are the six records that answer it.
| What you will be asked | The record that answers it |
|---|---|
| What are your compliance obligations? | A written list, confirmed rather than assumed |
| What did you train, and who completed it? | Completion records against named individuals with dates |
| What have people reported, and what happened? | A report register with actions, owners and dates |
| What risks have you accepted, and who accepted them? | Decision records with the reason and the decision-maker |
| How do your managers know the standard? | Supervisor training records and an escalation log |
| What changed after the last incident? | The investigation and the control review it triggered |
The fourth row is the one most businesses cannot produce, and it is the one that most often decides the outcome.
An accepted risk with a named decision-maker and a recorded reason is a governance position. The same risk with nobody’s name on it is an oversight, and the two look very different afterwards.
Bringing It Together
The seven steps have not changed much in a decade. What has changed is the consequence of skipping them.
Intentional wage underpayment is now criminal, the first civil penalty under the Privacy Act has been handed down, and the obligation to prevent sexual harassment is preventative and enforceable rather than reactive.
None of that makes compliance a cost to be minimised. It makes the old risk-versus-cost framing unusable, because the risk side of that equation is no longer speculative.
If you take one thing from this, take step 1 and step 4. Name your exposures in writing with an owner for each, and apply the ‘your honour’ test before you finalise anything.
Those two habits will surface most of what the other five steps exist to address, and neither requires a budget.
When you are ready to structure the rest, the common governance, risk and compliance challenges covers what usually gets in the way.
Make the seven steps something you can evidence
Sentrient keeps policies, training completions, incident reports, actions and decision records in one place, so the evidence a regulator asks for already exists rather than being assembled after the fact.
Explore the workplace compliance system | Book a free demonstration
Frequently Asked Questions
1. How do you mitigate the risk of non-compliance in a workplace?
Work through seven steps in order: recognise where your exposure sits across pay, conduct, privacy and safety, accept that the duties apply regardless of your size or location, build training and policies as the foundation of a reasonable steps position, apply the ‘your honour’ test to decisions, make sure people can identify, report and resolve incidents, hold your management team to the standard, and send a consistent message from leadership. Step one comes first because the other six are responses to an exposure you have to name before you can resource.
2. What is the risk of non-compliance for a small business?
The same duties apply. The primary work health and safety duty applies to a business or undertaking of any size, and the positive duty under the Sex Discrimination Act applies to all employers. Some penalty thresholds and administrative requirements differ for small business employers, so the scale of consequence can differ, but the existence of the obligation does not. Confirm your specific position rather than assuming size gives you an exemption.
3. Is underpaying wages a criminal offence in Australia?
Intentional underpayment of wages became a criminal offence from 1 January 2025. The Fair Work Ombudsman states that prosecution can result in monetary fines, prison time, or both. Separately, maximum civil penalties increased from 27 February 2024, and for a non-small business employer an underpayment penalty can be the greater of three times the value of the underpayment or the relevant penalty unit amount. Honest mistakes are treated differently from intentional conduct, and specific matters need legal advice.
4. Do training and policies protect a business from liability?
They do not guarantee protection, and no measure does. What they do is form the foundation of a reasonable steps position, which is the framework applied when a claim is tested. The distinction matters, because a policy that was never trained, never acknowledged and never enforced tends to be treated as evidence that reasonable steps were not taken. Inconsistent enforcement is more damaging than having no policy at all.
5. What are the penalties for a privacy breach in Australia?
For serious or repeated interference with privacy, penalties can reach the greater of a penalty unit amount, three times the benefit obtained from the conduct, or 30% of the organisation’s adjusted turnover during the breach period. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over the Medlab Pathology data breach, which was the first civil penalty of its kind under the Privacy Act.
6. What is the positive duty and who does it apply to?
The positive duty under the Sex Discrimination Act requires employers and persons conducting a business or undertaking to take reasonable and proportionate measures to eliminate sexual harassment, sex discrimination and hostile workplace environments so far as possible. It applies to all employers, and the Australian Human Rights Commission has power to enforce compliance with it. Because the duty is preventative, waiting for a complaint before acting is not a compliant position.
7. Who is responsible for compliance in an organisation?
Everyone holds part of it, and the parts differ. The organisation holds the primary duties. Officers hold a personal due diligence duty focused on governance, resources and assurance. Workers, including supervisors, must take reasonable care that their acts and omissions do not affect others, follow reasonable instructions and cooperate with notified policies. Compliance most often fails at the supervisory layer, where policy meets daily decisions.
8. How do you know whether a compliance programme is actually working?
Watch six indicators rather than waiting for an audit: reports per month broken down by type, time from report to acknowledgement, the proportion of actions closed on time, escalations coming from supervisors, training completion including managers, and whether findings repeat. Zero escalations and a large overdue action backlog are the two clearest early warnings, and both usually appear well before an incident does.
Disclaimer: This article is general information, not legal advice. Workplace, privacy and work health and safety obligations change, vary between states and territories, and depend on your circumstances. Confirm your obligations with the relevant regulator or a qualified adviser before acting.
Sources
- Fair Work Ombudsman, Criminalising wage underpayments and other issues
- Fair Work Ombudsman, Litigation, compliance and enforcement
- OAIC, Australian Clinical Labs ordered to pay penalties in first for the Privacy Act
- OAIC, Civil penalties: serious or repeated interference with privacy
- Australian Human Rights Commission, The positive duty in the Sex Discrimination Act
- Australian Human Rights Commission, Positive duty: compliance and enforcement
- Safe Work Australia, Duties under WHS laws
- Safe Work Australia, Officer duties
- Safe Work Australia, Identify, assess and control hazards
- Safe Work Australia, Psychosocial hazards
- SafeWork NSW, Due diligence
- Work Health and Safety Regulations 2011 (Cth), regulation 38, Review of control measures
