Governance, Risk & Compliance

The positive duty in practice: how to audit and evidence sexual harassment prevention

A practical assurance guide for employers, boards and executives: how to scope a review of positive-duty measures, test design, implementation and effectiveness, find evidence gaps, prioritise corrective action and report with honest limits.

By the AWS Editorial Team
Four colleagues discussing printed reports around a meeting table

Key points

  • The s 47C positive duty covers five classes of relevant unlawful conduct: sex discrimination in a work context, sexual harassment and sex-based harassment in connection with work, conduct creating a workplace environment hostile on the ground of sex, and related victimisation.
  • Assurance asks a different question from prevention design: whether the measures are reasonable and proportionate for this organisation, operating as intended and producing evidence that they reduce risk.
  • Test every AHRC standard through three separate lenses — design, implementation and effectiveness — and do not credit a well-drafted policy as an operating control.
  • Low complaint numbers are not a pass mark. Triangulate complaints with confidential workforce feedback, disclosures, exit data and operational indicators before drawing conclusions.
  • Board reporting should combine leading and lagging measures, rated findings with named owners and dates, and a plain statement of the review's scope and limitations.
  • No audit, certification or zero-incident record establishes compliance. The Commission assesses what was reasonable and proportionate in the circumstances.

Why assurance is a different question from prevention design

Most organisations can now produce a sexual harassment policy, a training completion report and a description of their reporting channels. Far fewer can show a board, a regulator or their own workforce that those measures are operating as intended, reaching the people most exposed, and reducing risk. That gap — between having measures and being able to evidence that they work — is where assurance sits.

This guide is written for the people who have to answer that question: directors, executives, general counsel and risk, audit, HR and WHS leaders. It assumes that prevention measures already exist. How to design them — policy content, reporting pathways, manager training and the prevention matrix — is covered in our guide to sexual harassment prevention: policies, reporting pathways and manager training. Here the focus is how to test those measures with appropriate challenge, find the evidence gaps, prioritise corrective action and report assurance honestly.

The duty being tested: scope, standard and regulator

Section 47C of the Sex Discrimination Act 1984 (Cth) requires employers and persons conducting a business or undertaking to take reasonable and proportionate measures to eliminate, as far as possible, five classes of relevant unlawful conduct: discrimination on the ground of sex in a work context; sexual harassment in connection with work; sex-based harassment in connection with work; conduct creating a workplace environment that is hostile on the ground of sex; and related acts of victimisation. An audit scoped only to sexual harassment therefore tests part of the duty, not all of it.

What is reasonable and proportionate depends on the duty holder's size, nature and circumstances, its resources, the practicability and cost of measures, and any other relevant matter. That is a judgement about a particular organisation, which is why a review should record the organisation's risk profile and resources and explain why the measures tested are, or are not, proportionate to them.

The Australian Human Rights Commission's Guidelines for Complying with the Positive Duty set out four guiding principles and seven standards: leadership; culture; knowledge; risk management; support; reporting and response; and monitoring, evaluation and transparency. The guidelines are not legally binding, but the Commission uses them in assessing compliance. They make a practical audit framework, provided the reviewer remembers they are not a checklist and not a safe harbour.

Since 12 December 2023 the Commission has had functions to monitor and assess compliance. Where it reasonably suspects non-compliance it can conduct an inquiry, require information and documents, issue a compliance notice specifying action to be taken or not taken, apply to a federal court for an order directing compliance with a notice, and accept enforceable undertakings. A credible internal assurance record is not a defence in itself, but it is exactly the kind of material an organisation will want to be able to produce if the Commission asks what it has done and how it knows its measures work.

Concurrent WHS and OHS duties are a separate test

Sexual and gender-based harassment is also a work health and safety hazard. In jurisdictions that have adopted the model WHS laws, a person conducting a business or undertaking must eliminate psychosocial risks so far as is reasonably practicable and, if that is not reasonably practicable, minimise them. Safe Work Australia's model Code of Practice: Sexual and gender-based harassment has legal effect only where a jurisdiction has approved it. Victoria operates under its own Occupational Health and Safety Act 2004, and the Occupational Health and Safety (Psychological Health) Regulations 2025 commenced on 1 December 2025, with guidance from WorkSafe Victoria.

The duties overlap in subject matter but differ in their source, standard, regulator and consequences. "Reasonably practicable" under safety law is not the same test as "reasonable and proportionate" under s 47C, and WHS duties are framed around risks to health and safety rather than the five classes of unlawful conduct. Some State and Territory anti-discrimination laws impose their own prevention duties, such as Victoria's Equal Opportunity Act 2010. A combined review can be efficient — shared risk registers, consultation and evidence — but its report should say which obligation each finding relates to rather than presenting one assurance opinion as satisfying all of them. For the safety side of the work, see psychosocial risk management: what employers should be reviewing now.

Who owns assurance and how to set scope

Ownership of the prevention framework usually sits with an executive, often the chief people officer or chief executive. Ownership of assurance should sit with whoever the board relies on to challenge management: an audit and risk committee, internal audit, a risk function, a suitably separated peer or an external reviewer engaged by one of them. The practical concern is sufficient separation from the controls being assessed to support candid challenge. Formal independence or use of an external reviewer is not a statutory requirement. A people team can self-assess, although higher-risk or contested areas may warrant review by someone who did not design or operate the control.

Write a short terms of reference before testing starts. It should state the question being answered; the legal obligations in scope and those excluded; the business units, sites and workforce groups covered, including contractors, labour-hire workers and volunteers where relevant; the period tested; the methods and evidence sources; who will see identifiable information; how any live risk discovered during the review will be escalated; and the form of the final findings and limitations, unless a formal assurance opinion has genuinely been commissioned. A narrow first review — for example, the three highest-risk sites and the reporting and response standard — is better than a whole-of-organisation review so broad that nothing is tested in depth.

Decide early whether legal professional privilege is being sought. That is a legal question for the organisation's lawyers. It affects who commissions the work and how it is documented, and it cannot be assumed simply because a lawyer is copied into correspondence.

Map exposure before choosing what to test

Testing effort should follow risk. Before reviewing documents, build a simple exposure map using the organisation's own data and consultation with workers and their representatives. Plot where relevant unlawful conduct is more likely to occur, and where it is less likely to be reported.

  • Role and task: customer-facing, care, hospitality, security, sales, field and isolated roles; roles involving travel, overnight stays or work in clients' premises.
  • Worksite and environment: remote or regional sites, fly-in fly-out accommodation, sites where alcohol is present, male-dominated worksites, poorly lit or unsupervised areas.
  • Shift and time: night, weekend and overtime work when fewer managers, HR staff or support options are available.
  • Power imbalance: steep hierarchies, workers on probation, visas, apprenticeships or insecure contracts, reliance on a supervisor for rosters or references, and senior or high-revenue individuals.
  • Third-party contact: customers, patients, clients, contractors and members of the public, including digital contact through messaging and social platforms.
  • Workforce composition: young workers, gender-imbalanced teams, and workers who may face compounded barriers to reporting because of disability, cultural background, sexuality or gender identity.

An evidence map across the seven standards

For each standard, list the evidence that would show the measure is designed, the evidence that it is implemented, and the evidence that it is effective. The map then drives the testing plan and makes gaps visible. Illustrative evidence for each standard is set out below; an organisation should adapt it to its own measures rather than treat it as a compliance list.

  • Leadership: board and executive minutes showing the duty is discussed and resourced; a named accountable executive; leadership targets or performance measures; evidence that leaders acted on previous findings.
  • Culture: current values and conduct standards; confidential survey results on respect, safety and speaking up; evidence that consequences for misconduct apply regardless of seniority; exit-interview themes.
  • Knowledge: training content mapped to all five classes of conduct; completion data by role, site and worker type including contractors; comprehension testing results; manager capability assessments.
  • Risk management: a risk assessment covering the exposure map; controls addressing work design, environment, supervision and third-party contact; control owners and review dates; consultation records.
  • Support: available internal and external support options; evidence workers know how to access them; interim safety measures used in live matters; separation between support roles and decision-makers.
  • Reporting and response: multiple channels including one outside the line hierarchy; triage and escalation procedures; case files showing timeliness, fairness and outcome communication; retaliation monitoring.
  • Monitoring, evaluation and transparency: a defined data set and review cycle; de-identified trend reports to leadership; evaluation of whether measures changed outcomes; communication back to the workforce about what changed.

Designing the tests: design, implementation and effectiveness

The most common assurance failure is crediting design as if it were operation. Treat the three lenses separately. Design asks whether the measure, if it operated as written, would address the identified risk proportionately. Implementation asks whether it actually operates, consistently and for the people it is meant to protect. Effectiveness asks whether there is evidence it is reducing risk or improving reporting, support and response.

Use a mix of methods matched to the question. Document review establishes design. Walk-throughs and control-operation testing — for example, confirming that a late-shift supervisor rota, a customer-conduct escalation process or a venue alcohol control actually happened on sampled dates — establish implementation. Confidential channels, focus groups and interviews with workers, managers, contact officers and those who have used the reporting system test whether the system is known, trusted and usable. Training comprehension can be tested with short scenario questions rather than completion records alone.

Where complaint-file review is necessary and proportionate, document the sampling rationale and restrict access to identifiable material to the reviewers who need it. Use a random sample where consistency across matters is being tested and a purposive sample where higher-risk matters — such as those involving senior respondents, third parties or withdrawn complaints — require attention. Test the process against the organisation's own procedure — triage, interim measures, communication with the parties, timeliness, reasons for outcomes and systemic follow-up — without reopening the merits of concluded matters. Where a sampled file raises concerns about the reliability of a specific investigation, the separate questions discussed in how to review a workplace investigation before relying on its findings apply.

Keep a working-paper trail that records what was tested, the sample, the evidence seen, the result and any limitation. An opinion that cannot be traced to evidence will not withstand challenge from a board, a regulator or the workforce.

Triangulating complaints with other signals

Complaint numbers are a lagging indicator, and on their own they are ambiguous. A low count can mean low incidence, but it can equally mean that workers do not know how to report, do not trust the process, fear retaliation or see no point. A rising count after a prevention campaign may reflect greater confidence rather than more conduct. The reviewer's job is to test which explanation the evidence supports.

Triangulate at least three sources. Formal complaints and informal disclosures, including those that went to contact officers or external channels. Anonymous, confidential workforce feedback with targeted questions on witnessing or experiencing conduct, awareness of reporting routes, confidence in them and fear of consequences. And operational data such as turnover and absence in exposed cohorts, exit themes, incident reports involving customers or contractors, and the timeliness of responses. If a survey indicates that a meaningful proportion of people at a site have experienced or witnessed relevant conduct while that site has recorded no complaints, the divergence is a warning requiring investigation. Test the survey's reliability, awareness of and trust in reporting routes, use of alternative disclosure channels and fear of retaliation; the divergence does not by itself establish that the reporting system has failed.

Balance lagging measures with leading indicators that show the system is active: risk assessments completed and reviewed, controls tested and operating, consultation held, training comprehension scores, time from report to first contact, and completion of agreed corrective actions.

Confidentiality, privacy and procedural fairness during a review

An assurance exercise can itself cause harm if it is careless with information. Limit access to identifiable complaint material to the reviewers who need it, keep working papers secure, report only de-identified results, and apply minimum group sizes to survey data so that small teams cannot be identified. Privacy obligations and the organisation's own policies apply to the handling of personal and sensitive information.

Participants should be told the purpose of the review, what it will and will not do, how their information will be used and the limits of confidentiality. Do not promise absolute confidentiality. If an interview reveals a current risk to someone's safety, or a matter that requires a response, it should be escalated through the proper channel with appropriate support rather than handled inside the review.

An assurance review is not a disciplinary process and should not make findings about individual conduct. Where review evidence may later be relied on to take action against a person, procedural fairness in that separate process will require the person to have an opportunity to respond. Keeping the two processes distinct protects both the people involved and the integrity of the review.

Rating findings and assigning corrective action

Rate each standard, and each material control within it, on a small maturity scale such as: not in place; documented only; partly implemented or inconsistent; operating without evidence of effectiveness; embedded and evidenced. Rate design, implementation and effectiveness separately so that the board can see where the weakness lies.

Prioritise corrective action by risk rather than by ease. A useful approach is to act immediately on anything indicating a live risk to people or unsafe reporting; within about 30 days on missing foundational controls in risk management, reporting and response, and support; within about 90 days on controls that exist on paper but are inconsistent or unevidenced; and within the annual cycle for maturing controls that already work. These horizons are illustrative, not legal deadlines.

Every action needs a named owner with authority to deliver it, a completion date, a description of the evidence that will show it is done, and a re-test date. Track actions in the organisation's risk or GRC system so that completion is visible and overdue items are escalated. Closure should require evidence, not a status update.

Reporting assurance to the board

Boards need a report they can act on, not a compliance declaration. A useful format has four parts: the scope and method, including what was not tested; an overall view by standard across the three lenses; key findings ranked by risk with owners and dates; and a short set of trend measures that will be repeated at each report so that movement can be seen.

Measures might include, suitably de-identified: the proportion of higher-risk sites with a current risk assessment and tested controls; training comprehension by role; confidential survey results on awareness of reporting routes, confidence in the process and fear of retaliation, compared by cohort; disclosures and complaints by channel and class of conduct; median time from report to first contact and to outcome; retaliation concerns raised; and corrective actions open, closed and overdue.

Be explicit about limitations. State the sample sizes, the sites not visited, the survey response rate and any data quality problems. Conclusions are limited to the review's scope, methods, sample and the quality of the evidence tested; they do not certify compliance or guarantee the absence of relevant conduct. Avoid phrases such as "compliant" or "fully meets the positive duty". An honest statement that the organisation has tested its measures, what it found and what it is doing about it is far more credible than an unqualified pass.

Re-testing and triggers

Assurance is a cycle. Set a routine governance review, commonly annual, and schedule targeted re-testing of high-risk controls and closed corrective actions between cycles. Re-test earlier when something changes the risk: a serious incident or pattern of reports; a restructure, acquisition or new site; a new client, customer cohort or third-party arrangement; a change in shift patterns or staffing; a regulator inquiry or notice; adverse survey or exit results; or evidence that a control is not operating. Record the trigger and the result so that the board can see the framework responds to change.

Scaling the review for small and medium businesses

The duty applies to organisations of all sizes, but what is proportionate differs. A small business does not need a formal internal audit. It can still do the essentials: list where the risks are, check that its measures actually happen, ask workers confidentially whether they know how to raise a concern and would feel safe doing so, provide at least one reporting option outside the owner or direct manager, and write down what it found and changed. An owner can ask a trusted adviser, an industry association resource or a peer business to act as a second pair of eyes.

Medium-sized organisations often benefit from a rotating approach — testing two or three standards in depth each year so that all seven are covered over a cycle, with reporting and response and risk management tested every year. Organisations with multiple sites, significant third-party exposure or a history of issues may benefit from greater separation between reviewers and control owners, a formal sampling method and committee-level reporting. That separation can be achieved internally or externally depending on risk, capability and resources; an external reviewer is not automatically required.

An illustrative assurance workflow

The following hypothetical example shows how the pieces fit together. A distribution business with a head office and four warehouses, several operating around the clock with labour-hire workers, asks its audit and risk committee to commission a positive-duty review. The terms of reference cover all five classes of conduct, the two highest-risk warehouses and the reporting and response, risk management and knowledge standards, with the other standards reviewed at design level only.

The reviewer builds an exposure map showing that night shifts have one supervisor per site and that labour-hire workers receive a shorter induction. Document review finds a sound policy and procedure. Implementation testing finds that labour-hire workers at one site were not told about the external reporting line, and that the night-shift supervisor is also the first contact point for complaints about the supervisor's own team. The confidential survey shows night-shift workers report witnessing inappropriate comments at materially higher rates than day-shift workers, but that site has recorded no complaints in two years. A sample of eight case files shows timely triage but no systemic follow-up.

The report rates reporting and response as documented but not effectively implemented for night shift and labour-hire workers, assigns the operations director to add a second reporting route and review night supervision within 30 days, assigns HR to align labour-hire induction with the host agreement within 90 days, and schedules a pulse survey and re-test at the affected site in six months. The limitations section notes the two sites not visited and the survey response rate.

Sources, limits and how AWS can help

This guide draws on the Sex Discrimination Act 1984 (Cth), including s 47C, as published on the Federal Register of Legislation; the Australian Human Rights Commission's Guidelines for Complying with the Positive Duty and associated positive-duty resources; Safe Work Australia's model Code of Practice on sexual and gender-based harassment; and WorkSafe Victoria's material on the Occupational Health and Safety (Psychological Health) Regulations 2025. Check the current versions before relying on them, and check the WHS or OHS law and any anti-discrimination law that applies in each jurisdiction where you operate.

AWS is a workplace consultancy, not a law firm, and does not provide legal advice or legal representation. We support employers with independent reviews of prevention frameworks through our workplace advisory and compliance service, psychosocial risk work through psychosocial safety and WHS, investigations and complaint-process reviews through workplace investigations, and evidence and action tracking through GRC technology. For related guidance see managing discrimination and harassment complaints, workplace contact officers and building a compliance framework that can be monitored and evidenced. This article is general information only.

Sample evidence matrix — one row per control

  • Standard and class of conduct: which of the seven standards and which of the five classes of relevant unlawful conduct the control addresses.
  • Risk addressed: the role, site, shift, power imbalance or third-party exposure from the exposure map.
  • Control and owner: what the control is and who is accountable for it operating.
  • Design evidence: the document, procedure or decision that establishes the control, and why it is proportionate.
  • Implementation test and sample: what was tested, how many items, over what period, and the result.
  • Effectiveness evidence: survey, disclosure, operational or outcome data showing whether risk or reporting has changed.
  • Rating: separate maturity ratings for design, implementation and effectiveness.
  • Gap and action: the finding, the corrective action, its owner, due date and the evidence required to close it.
  • Re-test: the scheduled re-test date and any trigger that would bring it forward.
  • Obligation reference: whether the finding relates to the positive duty, WHS or OHS duties, another law or internal policy.
  • Limitations: anything that could not be tested and why.

Frequently asked questions

Is a positive-duty audit legally required?
The Sex Discrimination Act does not prescribe an audit. It requires reasonable and proportionate measures to eliminate relevant unlawful conduct as far as possible. The Commission's monitoring, evaluation and transparency standard expects organisations to check whether their measures work, and a structured review is one proportionate way to do that and to show it has been done.
Who should conduct the review?
Someone with enough separation from the controls being tested to provide candid challenge, enough capability to test them properly and access to the evidence. That may be internal audit, a risk function, a peer from another business unit or an external reviewer. Formal independence and an external appointment are not statutory requirements; the appropriate arrangement depends on the organisation's risks, capability and resources.
Can a review rely on the existing staff engagement survey?
Only partly. General engagement questions rarely measure awareness of reporting routes, confidence in them, bystander experience or fear of retaliation. Add a small number of targeted, confidential questions and set minimum reporting-group sizes so that results cannot identify individuals.
Should reviewers read individual complaint files?
Identifiable complaint files are not necessary for every review. Where file sampling is necessary and proportionate to test whether the documented process operates in practice, use a limited sample and strict access controls: restrict access to what the review requires, use reviewers bound by confidentiality, and record and report findings only in de-identified form. The review should assess process quality, not reopen the merits of concluded matters.
What if the review uncovers a current allegation or risk?
Pause and escalate it through the established response pathway rather than investigating it within the audit. The reviewer's role is to identify that a matter needs attention and to protect the people involved; the response, any investigation and any decision belong to the appropriate channel.
Does certification to a management-system standard show compliance?
No. Certification can show that a management system exists and is maintained against that standard. It does not decide whether measures are reasonable and proportionate for the positive duty, and the Commission's guidelines are not a certification scheme.
How often should prevention measures be re-tested?
Set a routine cycle proportionate to risk, commonly annual for governance review with targeted re-testing of high-risk controls in between, and re-test earlier on triggers such as a serious incident, a restructure, a new site or client contract, a regulator contact or survey results showing a deterioration.

Discuss this matter with AWS

Briefings can be scoped on a confidential basis. We respond within two business days.

Contact AWS