Boards and executive leaders routinely oversee a broad spectrum of organisational risks, from financial performance and cybersecurity to environmental, legal and reputational exposures. Often however, Work Health and Safety (WHS) risks are managed through separate compliance systems rather than as an integral component of enterprise risk management. Given that a serious injury (or worse) to a worker can have a significant impact to an organisation in addition to the individual worker’s health, this distinction is increasingly difficult to justify, both from a governance perspective and under Australia’s Model WHS Act.

The Model WHS Act places a primary duty of care on persons conducting a business or undertaking (PCBUs) to ensure, so far as is reasonably practicable, the health and safety of workers and others. It also imposes a personal duty on officers to exercise Due Diligence to ensure that the PCBU complies with its legislative obligations. These duties elevate WHS from an operational issue to a matter of strategic governance.

Unlike many enterprise risks, WHS risks cannot simply be accepted because they fall within an organisation’s stated risk appetite. The Act requires organisations to eliminate risks where reasonably practicable or, when this is not possible, to minimise risks through appropriate control measures. This creates a fundamentally different decision-making framework. The question is not whether a risk is acceptable to the organisation, but whether the organisation has done everything that is reasonably practicable to manage it.

Despite this distinction, the principles of effective risk management remain remarkably consistent. Leading organisations identify hazards, assess the likelihood and consequences of adverse events, implement controls based on the hierarchy of control, monitor the effectiveness of those controls and continually review their risk profile. These are the same principles that underpin sound enterprise risk management and informed governance for all types of risks.

Integrating WHS into enterprise risk management enables boards to consider critical safety risks alongside strategic, operational and financial risks, providing greater visibility of the interdependencies between them. A serious workplace incident can disrupt operations, damage organisational reputation, reduce shareholder confidence, attract regulatory scrutiny, and expose officers to personal liability. These outcomes are no less significant than those arising from cybersecurity breaches or financial misconduct.

The most mature organisations recognise that effective WHS governance is not achieved through compliance alone. It requires safety risks to be evaluated, monitored and reported using the same rigour applied to every other material business risk. By embedding WHS within enterprise risk management, organisations strengthen governance, support officer Due Diligence and improve organisational resilience. More importantly, they fulfil the fundamental purpose of the Model WHS Act: to protect the health and safety of workers and others while enabling organisations to operate responsibly and sustainably.

Please contact us for more information.