
Whistleblowing legislation across major jurisdictions is placing direct personal liability on boards and directors. Here is what governance leaders must now understand about their individual obligations.
The era of delegating whistleblower obligations entirely to compliance teams is over. Across Australia, the European Union, the United Kingdom, and beyond, legislative frameworks are increasingly naming boards and individual directors as personally accountable for how their organisations receive, handle, and respond to whistleblower disclosures. For directors who assumed that a generic policy buried in an employee handbook was sufficient, the regulatory environment has shifted decisively — and the personal consequences of getting it wrong are serious.
What the Legislation Actually Requires of Directors
In Australia, the Corporations Act 2001 and the Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019 together impose obligations that extend well beyond the organisation as a legal entity. Eligible recipients — including certain officers and senior managers — carry individual responsibilities to maintain the confidentiality of a discloser's identity and to ensure that no detrimental action is taken against a person who has made a protected disclosure. A director who becomes aware of victimisation and fails to act can face personal exposure, not merely corporate liability.
In the European Union, the Whistleblower Protection Directive, transposed into national law across member states, obliges organisations above a certain size to establish formal internal reporting channels and to acknowledge, follow up, and provide feedback on reports within defined timeframes. Competent authorities in multiple member states have made clear that board-level sign-off on these systems is an expected governance standard — meaning directors cannot credibly claim ignorance of whether a compliant channel exists.
In the United Kingdom, while the Public Interest Disclosure Act 1998 remains the foundational framework, regulatory bodies including the Financial Conduct Authority have signalled through their individual accountability regimes — particularly the Senior Managers and Certification Regime — that senior individuals bear direct responsibility for cultures and systems that either protect or suppress legitimate disclosures.
The Personal Risks Directors Cannot Afford to Ignore
The shift toward individual accountability means that directors now face a range of potential consequences that were historically reserved for the corporate entity:
- Civil liability: Directors may be held personally liable for losses suffered by a whistleblower who experienced detrimental treatment where that director was involved in, or failed to prevent, the conduct.
- Regulatory sanction: Regulators in financial services, health, and public sector contexts can impose sanctions directly on responsible individuals, including disqualification from holding office.
- Reputational damage: Enforcement actions naming individual directors are increasingly made public, with lasting consequences for professional standing and future board appointments.
- Criminal exposure: In certain jurisdictions and sectors, deliberate suppression of a protected disclosure or active retaliation can give rise to criminal liability for individuals who orchestrate or facilitate such conduct.
It is also worth noting that courts and tribunals have shown a growing willingness to look behind the corporate veil where evidence suggests that senior individuals were directly involved in decisions to marginalise, dismiss, or otherwise harm a person who raised concerns. Directors who argue they were not aware of a disclosure will find that argument harder to sustain where no adequate reporting channel existed in the first place — because the absence of a channel can itself be characterised as a governance failure attributable to the board.
Governance Steps Boards Must Now Take
Leading governance bodies, including the Australian Institute of Company Directors and equivalent organisations in other jurisdictions, have consistently advised that whistleblower governance should sit firmly on the board agenda rather than being treated as a purely operational matter. At a minimum, directors should be satisfied that their organisation has addressed the following:
- A secure, confidential reporting channel that allows disclosers to report concerns — including concerns about senior management — without fear that their identity will be exposed to the very people they are reporting on.
- Clear policies that have been reviewed by qualified legal counsel, approved at board level, and communicated meaningfully to all staff rather than simply published on an intranet.
- Defined accountability for the handling of disclosures, with escalation pathways that allow reports about executives or directors to be received and assessed independently.
- Regular board reporting on the volume, nature, and resolution of disclosures, so that directors maintain genuine oversight rather than nominal governance.
- Anti-retaliation safeguards that are actively monitored, with board-level review of any employment or contractual action taken against a person who has recently made a disclosure.
Directors who cannot answer basic questions about how their organisation's whistleblowing system operates — who receives reports, how confidentiality is protected, and what happens after a report is lodged — are carrying governance risk that is no longer theoretical.
Organisations that have not yet implemented a compliant, secure, and independently managed whistleblowing channel should treat this as a board-priority matter, not a future agenda item. Engaging a specialist whistleblowing service provider gives boards the documented evidence of due diligence they need, and gives employees the confidence to raise concerns through a channel they trust. The time to act is before a regulator or court begins asking why no such channel existed.
