
Whistleblowing legislation is increasingly placing personal accountability on boards and directors. Here is what governance leaders must understand to avoid serious legal exposure.
The era of institutional anonymity for governance failures is closing. Across Australia and comparable jurisdictions, whistleblowing legislation has evolved from a framework that merely protected disclosers to one that actively pursues those at the top who fail to uphold those protections. Boards and individual directors are now squarely in the crosshairs of regulators, and the personal consequences of non-compliance have never been more serious.
How Personal Accountability Has Shifted
Historically, penalties for mishandling whistleblower disclosures were levied against organisations as corporate entities. That calculus has changed materially. Under Australia's Corporations Act 2001 and the Treasury Laws Amendment (Enhancing Whistleblower Protections) Act 2019, individuals — including officers and directors — can be held personally liable for engaging in, authorising, or failing to prevent detrimental conduct against a whistleblower.
The concept of detrimental conduct is broad. It encompasses dismissal, demotion, harassment, discrimination, harm to a person's reputation or finances, and any action that disadvantages a discloser because of a protected disclosure. Critically, a director does not need to have personally ordered the retaliation. Where a board member knew of retaliatory behaviour and took no meaningful steps to stop it, regulators and courts can treat that inaction as its own form of liability.
Similar personal accountability provisions exist in whistleblowing frameworks across the United Kingdom, the European Union, and the United States. The direction of travel internationally is consistent: those who govern organisations bear a duty of care that extends to the protection of people who speak up.
What Boards Are Now Expected to Do
Regulators have made their expectations explicit. Boards are not merely expected to ratify a whistleblower policy and move on. They are expected to actively oversee the whistleblowing framework as an ongoing governance obligation. This includes several concrete responsibilities:
- Policy ownership: The board must ensure a compliant, up-to-date whistleblower policy exists and is accessible to all eligible disclosers, including employees, contractors, and in some cases suppliers.
- Confidentiality obligations: Directors must ensure the organisation's systems protect the identity of disclosers. Unauthorised disclosure of a whistleblower's identity is itself a criminal offence under the Corporations Act, and officers who permit such breaches may face personal criminal penalties.
- Adequate resourcing: Boards bear responsibility for ensuring the whistleblowing function — whether internal or through a third-party channel — is properly resourced, independent, and capable of handling disclosures confidentially and promptly.
- Culture and tone from the top: Regulators increasingly assess whether board conduct creates or tolerates a culture of silence. Evidence that leaders discouraged disclosures, ridiculed concerns, or failed to act on reports can be used to demonstrate systemic failures that attract personal scrutiny.
- Investigation oversight: Where a disclosure triggers an investigation, the board must ensure the process is fair, protected, and free from undue influence by those implicated.
The Consequences of Getting It Wrong
The consequences for directors who fall short of these obligations are significant and have both civil and criminal dimensions. Under Australian law, individuals found to have engaged in detrimental conduct against a whistleblower can face substantial civil penalties. Where the conduct involves deliberate identification of a whistleblower, criminal sanctions including fines and imprisonment are available to prosecutors.
Beyond statutory penalties, directors face serious reputational damage, potential disqualification from managing corporations, and exposure to civil claims brought directly by affected disclosers. Courts have also shown a willingness to scrutinise the actions — and inactions — of boards during whistleblowing incidents as part of broader assessments of whether directors have met their duties of care and diligence under the Corporations Act.
Regulatory bodies including the Australian Securities and Investments Commission have signalled that whistleblower-related enforcement is a sustained priority. The message to boards is unambiguous: this is not a compliance formality. It is a governance imperative with personal stakes.
A Note on Policy Alone Not Being Sufficient
One of the most common and costly misconceptions among boards is that having a written whistleblower policy satisfies their obligations. It does not. A policy that exists on paper but is unsupported by a secure, confidential, and independently operated reporting channel leaves the organisation — and its directors — exposed. Disclosers must have a practical, trustworthy mechanism through which to come forward without fear of identification or reprisal. Where that mechanism is absent or ineffective, the policy itself becomes evidence of a governance failure rather than a defence against one.
Regulators and courts will assess whether disclosers had a genuine, functioning pathway available to them. A secure whistleblowing channel that meets legislative requirements is not optional infrastructure — it is a legal obligation.
If your organisation has not yet established a compliant, confidential whistleblowing service, now is the moment to act. Directors who delay do so at their own personal risk. Specialist whistleblowing platform providers such as Whistleblowing.services exist precisely to help organisations of all sizes meet their legal obligations, protect disclosers, and give boards the oversight capability they need to demonstrate genuine compliance.
