Governance, Risk & Compliance
Building a workplace compliance framework that can be monitored and evidenced
Designing a compliance framework is the easier half. This guide covers operating one: the monitoring chain, evidence architecture, testing, exceptions, verified remediation and governance reporting.

Key points
- An obligation register is not a policy library: it records the source, the provision and the interpretation behind each requirement.
- Control existence, control design and operating effectiveness are three separate questions, and evidence of activity is not evidence of result.
- Testing cadence should be risk- and trigger-based; there is no general Australian legal rule setting an annual, quarterly or monthly review cycle.
- Self-attestation is first-line evidence, not assurance — independence should be proportionate to the risk the control carries.
- A completed action is not a resolved issue: closure should turn on proportionate verification, not task status.
- No dashboard, platform, certification or volume of records proves compliance; the records and reasoning underneath must remain retrievable.
Scope: operating the framework, not merely designing it
Organisations that get into difficulty on workplace compliance are rarely missing a framework. They have an obligations list, a policy set, a control library and a governance forum. What they cannot readily show is whether those controls operated in the period in question, and on what evidence.
This article deals with that operating question. Design — how obligations, controls, owners and evidence should be structured — is addressed in building a defensible workplace compliance framework. What follows assumes a framework exists and asks how it is monitored, tested, corrected and reported.
Two propositions sit underneath what follows. No software, dashboard, policy set, certification or volume of stored records proves legal compliance by itself; compliance is a question about conduct measured against a legal requirement. And the useful unit of analysis is the chain connecting a source obligation to a defensible conclusion about whether it was met. This is general information, not legal advice.
The monitoring chain from obligation to assurance
A monitored framework is a chain: obligation, interpreted requirement, risk and context, control, accountable owner, operating evidence, testing result, exception, verification, and governance reporting.
The first join is between the obligation register and the policy library. A register records the source — statute, regulation, award, agreement, contract or licence condition — the provision relied on, who interpreted it and what it is understood to require. A policy library records what the organisation has told its people to do. A mature register makes the interpretation visible so it can be revisited when the law changes.
The second join separates three questions often merged. Does the control exist? Is it designed so that, operating as intended, it would address the risk? Did it in fact operate effectively across the period? A control can exist, be well designed, and still fail because a role was vacant, a system rule was overridden, or its population was defined too narrowly.
The third join separates evidence that an activity occurred from evidence that the control achieved its result. An attendance record shows training was delivered; it does not show the task can now be performed correctly. Conflating the two produces confident reporting on ineffective controls.
Governance, accountability and the assurance lines
Ownership belongs with the business role that can actually change how the control operates — the payroll manager, the site manager, the people leader — not the function maintaining the register. Allocated for presentational reasons, it produces the record of accountability without the substance.
Four activities are often reported under the single word "monitoring". Management monitoring is a leader's ordinary supervision of their own operation. First-line checks are structured self-checks by the people who run the control. Second-line review by compliance, risk, WHS or human resources assesses and challenges but does not inherit the owner's accountability. Independent assurance comes from someone genuinely outside the chain of management responsible for the control.
Under the model work health and safety laws, officers must take reasonable steps that include ensuring appropriate resources and processes are available and used, and verifying that they are — see Safe Work Australia on officer duties under WHS laws. Verification is active; receiving a dashboard does not discharge it. That material is model law and guidance rather than binding law, jurisdictions implement the model laws with local variation, and Victoria operates its own occupational health and safety scheme.
Evidence architecture and lawful record handling
Evidence is fit for purpose when it is contemporaneous, attributable, complete enough for its use, securely retained, accessible to those who need it, version-controlled where the version matters, and proportionate to the risk.
Retention and access are governed by the law and the record type, not a single organisational rule. Employee records and pay slips carry their own requirements under the Fair Work Act and regulations, described in the Fair Work Ombudsman's guidance on record-keeping and pay slips. Safety, privacy, tax and industrial instrument requirements each run on their own terms. Keeping the required records does not cure an underlying underpayment or misclassification; it makes the error visible and calculable.
Monitoring systems should collect the minimum personal information needed rather than everything the platform can store. Health information, complaint content, investigation material and identifiable survey responses warrant particular care. Access should be role-based and lawful, sensitive material should sit apart from board reporting where identification is unnecessary, and use of survey data should match what people were told at collection.
Designing the monitoring and testing plan
A monitoring plan states, for each in-scope control, who checks it, how, against what criteria, how often, and what happens to the result. Coverage is driven by risk: consequence of failure, likelihood, the volume and variability of the activity, and the reliance other controls place on it.
Cadence should be risk- and trigger-based rather than uniform. There is no general Australian legal rule requiring annual, quarterly or monthly review of workplace compliance controls, and inventing one produces wasted effort on stable controls or false comfort on volatile ones.
Triggers should be defined in advance: legislative or regulatory amendment; an award variation or new enterprise agreement; changed regulator guidance; a decision altering the accepted interpretation; a payroll, rostering or HRIS change; acquisition or restructure; a serious incident or complaint pattern; and the departure of a control owner.
Some organisations align this work to ISO 37301:2021, the voluntary international standard for compliance management systems, setting out requirements with guidance for use. It is a structuring reference, not Australian law; conformity is not a safe harbour, and certification does not establish that any legal obligation has been met.
A five-row control-and-evidence matrix
Five materially different controls in one structure. The evidence column shows what the control produces, not proof it worked; testing examines effectiveness.
| Control and context | Intended outcome | Operating evidence | Testing approach | Exception signal |
|---|---|---|---|---|
| Award classification and pay calculation applied through payroll | Employees are correctly classified and receive all applicable minimum entitlements under the relevant law and industrial instrument, including amounts generated by the pay calculation where relevant. | Classification decisions with reasons; pay rules mapped to clauses; time data. | Targeted recalculation for defined cohorts; duties review near classification boundaries. | Unexplained variance; repeated manual overrides; duties change without review. |
| Employee records and pay slips for employers covered by relevant Commonwealth workplace laws | Required records exist, are accurate and retained; pay slips carry required content. | Record set; pay slip templates and issue logs; retention config; amendment logs. | Attribute-level completeness check across a defined population, closed period. | Missing fields; prior-period records unavailable; amendments without an audit trail. |
| Verification that a critical WHS or OHS risk control is in place and used | The control operates in the field as designed; gaps are found before an incident. | Inspection records; maintenance and calibration data; competency and HSR consultation. | Workplace observation, worker interviews, and records compared to what is present. | Verification records without field confirmation; recurring defects; reported workarounds. |
| Complaint and investigation process governance | Matters are triaged, owned without conflict, and closed with reasons. | Triage records; conflict checks; interim measures and review dates; closure records. | File review by someone outside the matters, testing conflict handling and reasoning. | Matters open past review dates; conflict checks absent; recurring themes untreated. |
| Handling of privacy-sensitive monitoring and evidence | Only necessary personal information is collected; access is lawful and role-based. | Access configuration and logs; collection notices; de-identification rules. | Access logs reviewed against role definitions; reports sampled for identification. | Access outside role scope; identifiable material in governance packs; over-collection. |
Testing execution, conclusions and limitations
A test that can be relied on records six things before it starts and two when it ends: population; method (whole-of-population analysis, targeted selection, random sample, observation or walk-through); period; tester and their relationship to the control; pass/fail criteria; evidence to be examined; then the result and the conclusion.
Statistical sampling is not mandatory in every case; for many workplace controls a whole-of-population recalculation or a risk-weighted selection is cheaper and more informative. What matters is that the method is stated, supports the conclusion, and that the conclusion is not expressed more broadly than the method allows.
Limitations belong in the result: a test confined to one site or pay period, incomplete source data, a control that changed mid-period. Stating this prevents the conclusion being reused where it cannot support the point.
Independence should be proportionate to risk. Owner self-checks suit routine, low-consequence controls. Where failure creates safety, remuneration, discrimination or licence exposure, self-attestation alone is not a basis for concluding the control is effective.
Exceptions, incidents and obligation change
Not every exception is a breach, and treating them identically distorts response and reporting. Classify at capture. A control failure did not operate as designed. A process deviation departed from the documented method without defeating the control's purpose. An evidence gap may have operated but cannot be shown to have done so. An isolated error is a one-off with an identifiable cause. A systemic issue is a pattern with a structural cause. An obligation change makes the control inadequate however well it operated.
Whether an exception also amounts to a contravention is a separate legal question, turning on the facts and the applicable instrument, and often one on which advice is appropriate before conclusions are recorded.
Root-cause analysis should reach past the immediate error to the conditions that allowed it: a rule configured from an outdated instrument, a role without capacity to perform the check, a system change deployed without compliance review. Where the cause is an obligation change, the response belongs in the register and the control design, not a performance conversation.
Remediation, interim controls and verified closure
Each remediation item needs a named owner, a due date, an agreed scope, an escalation path if it slips, and a defined closure test. Where exposure is live while the permanent fix is built, the interim control should be documented the same way — that it is temporary, what it does not cover, and when it will be withdrawn.
Completion and resolution differ. A completed task means someone did what they said; a resolved issue means the condition that produced the exception no longer does. Closure should require evidence of the second: a re-test over a later period, a recalculation showing the corrected result, a field verification, or review by someone other than the person who did the work.
Where remediation affects employees — a pay correction, a records reconstruction — scope, communication and record-keeping should be handled deliberately, as set out in wage compliance reviews and documentation. Remediation that is well documented does not remove liability for the underlying error.
Governance dashboards and board reporting
A dashboard is a navigation aid over the records. It is not the evidence, and a board pack is not the evidentiary source; the records and the reasoning behind each conclusion sit underneath and must remain retrievable.
Useful reporting covers trend rather than a single period, the exposures that matter and how they are changing, material exceptions with their classification, overdue and re-opened actions, repeat failures in the same control or cause category, the basis and confidence attaching to each assurance conclusion, and the decisions required. Red, amber and green colouring compresses that into one dimension and hides what governance most needs: whether a conclusion rests on assurance or self-assessment, and whether the position is improving.
Reporting should also be honest about coverage: which controls were not tested this period, and why.
Two worked examples
Example A — a classification interpretation issue found in payroll testing. A national services employer scheduled targeted testing after an award variation altered a classification definition relevant to part of its workforce. The test covered all employees in three affected classifications over the preceding twelve months, recalculated entitlements against the instrument, and was run by a reviewer outside payroll operations. Duties for one cohort had expanded over two years without a classification review, producing a shortfall. The employer preserved the time and payroll records, assessed the affected cohort and the completeness of records, and required second-person approval of classification changes while the pay rules were rebuilt. Closure was conditional on an independent recalculation for a later period. The documentation supported the response; it did not remove the underlying liability, which was assessed with advice.
Example B — testing a psychosocial risk control where complaints are low. A manufacturer with sites in two states tested its controls for high job demands in a shift-based function. Low complaint volume alone did not establish low risk and was tested against other indicators. The review drew on rostering and overtime data, leave and turnover patterns, exit information, de-identified survey results, hazard reports, and consultation with workers and health and safety representatives. The control owner was the operations manager, with the WHS lead performing second-line review. Because one site is in Victoria, the review applied the Victorian occupational health and safety scheme there and the applicable model-based WHS regime at the other. It found the rostering control was well designed but routinely overridden during peak demand. Board reporting described the finding, exposure and remediation without identifying individuals. Related considerations appear in psychosocial risk management.
Where Strobe fits, and a twelve-step operating cycle
Strobe is the AWS governance, risk and compliance platform. It holds obligations, controls, owners, evidence, testing results, exceptions and actions as linked records, so a conclusion in a report traces back to the test, the evidence and the owner that produced it, and the audit trail survives changes of people and period. It supports scheduling, trigger-based tasking, escalation and closure verification.
What it does not do should be equally clear. It does not interpret the law, decide what an award or agreement requires, or replace the accountable owner or the organisation's advisers. Storing evidence is not assurance. It improves the consistency and auditability of an operating model the organisation defines and runs, with support available through GRC and advisory work.
The cycle below moves a designed framework to a monitored one. A small set of well-tested controls produces more useful assurance than a register too large to operate.
- Define scope: the entities, sites, workforce populations and obligation domains covered this cycle, and what is deliberately out of scope.
- Build or refresh the obligation register from source instruments, recording the provision, the interpretation and who made it.
- Map each material obligation to the controls intended to address it, and identify obligations with no control and controls with no obligation.
- Assess control design against the risk before testing operation, so weak design is not mistaken for poor execution.
- Assign each control to a business owner with authority and capacity to change how it operates.
- Define the operating evidence each control produces, generated as a by-product of the work rather than assembled later.
- Set cadence by risk and define the events that force an out-of-cycle review.
- Write the testing plan: population, method, period, tester, independence, criteria and evidence for each control in scope.
- Execute testing and record conclusions and limitations, distinguishing what the method proves from what it suggests.
- Classify every exception at capture, run root-cause analysis on patterns, and route obligation changes to the register.
- Track remediation with owners, dates, documented interim controls where exposure is live, and closure on proportionate verification.
- Report trend, exposure, material exceptions, overdue actions, repeat failures, assurance basis and decisions required, and record the decisions taken.
What employers should be able to demonstrate
- An obligation register distinct from the policy library, recording each interpretation.
- Named business owners for every material control, with assurance lines separated.
- A testing plan with cadence justified by risk and defined event triggers.
- Test records stating population, method, period, tester, criteria and limitations.
- Exceptions classified and remediation closed on verification, not task completion.
- Governance reporting showing trend, coverage and assurance basis.
Frequently asked questions
- What is the difference between a policy library and a monitored compliance framework?
- A policy library is a set of documents telling people what to do. A monitored framework links each source obligation to the interpretation applied, the control intended to address it, the accountable owner, the evidence the control produces, the testing that examines whether it worked, and the exceptions and actions that follow. The same documents can sit in either model; what changes is whether the operating model around them is defined, owned, tested and reported.
- What is the difference between monitoring and assurance?
- Monitoring is ongoing management oversight and first-line checking by the people who run the control. Assurance is an independent examination of whether the control operated effectively, performed by someone outside the chain of management responsible for it. Second-line functions such as compliance, risk, WHS or human resources sit between the two: they assess and challenge, but they do not inherit the owner's accountability. Reporting a monitoring result as assurance overstates what the organisation actually knows.
- How often should workplace compliance controls be tested?
- There is no general Australian legal rule requiring workplace compliance controls to be tested annually, quarterly or monthly, and adopting a uniform cycle usually means wasted effort on stable controls and false comfort on volatile ones. Cadence should be set by risk — consequence of failure, likelihood, volume and variability of the activity, reliance placed on the control — and supported by defined event triggers such as legislative amendment, an award variation or new agreement, changed regulator guidance, a system change, restructure, a serious incident, or the departure of a control owner. Specific instruments or contracts may set their own timing requirements.
- What evidence shows that a control is operating?
- Evidence that the activity occurred — approvals, logs, checklists, inspection records, training completions — is the starting point, but it is not the same as evidence that the control achieved its intended result. Effectiveness is examined through testing: a defined population, a stated method, a period, a tester, criteria that distinguish pass from fail, and a conclusion that does not extend beyond what the method supports. Useful evidence is contemporaneous, attributable, complete enough for its purpose, securely retained, accessible and proportionate; retention and access requirements depend on the governing law and the record type.
- Can a dashboard prove that an organisation is compliant?
- No. A dashboard is a navigation aid over the underlying records, and a board pack is not the evidentiary source. Compliance is a question about conduct measured against a legal requirement, and it is answered by the records and the reasoning behind each conclusion, which must remain retrievable in their own right. No platform, policy set, certification or volume of stored data establishes compliance by itself.
- Who should own workplace compliance controls?
- The accountable business role with the authority and capacity to change how the control operates — the payroll manager, the site manager, the people leader — rather than the function that maintains the register. Second-line reviewers and independent assurance providers assess and challenge that ownership; they do not take it over. Where ownership is allocated for presentational reasons, the organisation holds a record of accountability without the substance of it.
- When can a remediation action be closed?
- When the condition that produced the exception no longer produces it, and there is proportionate evidence of that. A completed task is not necessarily an effective fix. Depending on the risk, closure evidence might be a re-test over a later period, a recalculation showing the corrected result, a field verification, or review by someone other than the person who performed the work. Where an interim control was used while the permanent fix was built, its withdrawal should be a deliberate, recorded step.
- Where does Strobe fit?
- Strobe is the AWS governance, risk and compliance platform. It holds obligations, controls, owners, evidence, testing results, exceptions and actions as linked records, so a reported conclusion can be traced to the test, the evidence and the owner that produced it, and supports scheduling, trigger-based tasking, escalation and closure verification. It does not interpret the law, decide what an award or agreement requires, replace the accountable owner or the organisation's advisers, or guarantee compliance. Storing evidence is not assurance.
Discuss this matter with AWS
Briefings can be scoped on a confidential basis. We respond within two business days.
Contact AWSRelated briefings
Governance, Risk & Compliance
Building a well-documented workplace compliance framework
A workplace compliance framework should be coherent across HR, safety and operations. We outline the building blocks employers should put in place.
Read briefing →Governance, Risk & Compliance
How GRC technology supports workplace risk and assurance
Spreadsheets and inboxes do not scale for modern workplace risk and assurance. We outline what GRC technology should do for a workplace-risk-focused organisation.
Read briefing →Governance, Risk & Compliance
Business continuity planning for workforce disruption
Workforce disruption is one of the most common and least planned-for continuity risks. This briefing outlines how business impact analysis, scenario planning and tested response plans strengthen resilience.
Read briefing →