Boards and executive leaders routinely oversee a broad spectrum of organisational risks, from financial performance and cybersecurity to environmental, legal and reputational exposures. Too often, however, Work Health and Safety (WHS) risks are managed through separate compliance systems rather than as an integral component of enterprise risk management. Given that a serious injury, illness or fatality can have significant consequences for an organisation, as well as for the affected worker and their family, this distinction is increasingly difficult to justify from both a governance perspective and under Australia’s Model Work Health and Safety (WHS) laws.
The Model WHS Act places a primary duty of care on a person conducting a business or undertaking (PCBU) to ensure, so far as is reasonably practicable, that the health and safety of workers and that other persons is not put at risk from work carried out as part of the business or undertaking. It also imposes a personal duty on officers to exercise due diligence to ensure that the PCBU complies with its WHS duties and obligations. These duties elevate WHS from an operational compliance issue to a matter of strategic governance and risk management.
Unlike many enterprise risks, WHS risks cannot simply be accepted because they fall within an organisation’s stated risk appetite. The legislation requires duty holders to eliminate risks to health and safety so far as is reasonably practicable, and, if elimination is not reasonably practicable, to minimise those risks so far as is reasonably practicable. This creates a different decision-making framework. The question is not whether a risk is acceptable to the organisation, but whether the organisation has taken the steps that are reasonably able to be taken to manage it.
Despite this distinction, the principles of effective risk management remain consistent. Leading organisations identify hazards, assess the consequences and likelihoods of adverse events, implement controls in accordance with the hierarchy of control, monitor the effectiveness of those controls and continually review their risk profile. These are the principles that underpin sound enterprise risk management and informed governance for WHS risk as well as all other material business risks.
Integrating WHS into enterprise risk management enables boards and executives to consider critical safety risks alongside strategic, operational and financial risks, providing greater visibility of the interdependencies between them. A serious workplace incident can disrupt operations, damage organisational reputation, reduce stakeholder confidence, attract regulatory scrutiny and expose officers to personal liability. These outcomes are no less significant than those arising from cybersecurity breaches, financial misconduct or other enterprise-level events.
The most mature organisations recognise that effective WHS governance is not achieved through compliance activity alone. It requires safety risks to be evaluated, monitored and reported with the same discipline that’s applied to every other material business risk. By embedding WHS within enterprise risk management, organisations strengthen governance, support officer due diligence and improve organisational resilience. More importantly, they help fulfil the fundamental purpose of the WHS framework: to protect the health and safety of workers and others while enabling organisations to operate responsibly and sustainably.
Please contact us for more information.


