Meeting the Positive Duty — A Practical Guide to Respect@Work
Since December 2022, Australian organisations must actively eliminate sexual harassment, not just respond to it.
Gentia · 11 November 2025

Most organisations think they've got sexual harassment prevention covered. They have a policy. They run training. They have a process for handling complaints.
Since December 2022, that's no longer enough.
The positive duty changed the obligation. Australian organisations now have a legal duty to eliminate sexual harassment, sex discrimination, and victimisation — not just respond to it when it happens.
The Australian Human Rights Commission has enforcement powers. It can investigate your organisation, issue compliance notices, and take enforcement action, even without a complaint being made.
The question is no longer "do you have a policy?" It is "what reasonable and proportionate measures did you take to eliminate this risk?"
That is a fundamentally different question. And most organisations aren't ready to answer it.
Culture eats compliance for breakfast
Here's what we've learned after years of working in this space: the positive duty is really a culture question, not a compliance question.
You can have the world's best sexual harassment policy. You can train every employee. You can establish robust complaint processes. But if your organisational culture doesn't support respect and dignity, harassment will persist.
Culture is not your values poster on the wall. It's not the code of conduct sitting on your intranet.
Culture is what happens when no one's watching. It's the emotional blueprint that tells people how to act and what to expect from others. It's created by a trillion tiny acts — how people greet each other, who gets invited to meetings, what jokes land, how managers respond when someone raises a concern.
And here's the uncomfortable truth: culture is defined by what you tolerate, not what you say.
If a high performer makes inappropriate comments and nothing happens, that's your culture.
If someone reports harassment and their colleagues start treating them differently, that's your culture.
If leaders talk about respect but lose their temper in meetings, that's your culture.
Strategy is a plan. Culture is the engine that drives it. If culture is dysfunctional, nothing you implement will stick.
The seven pillars of Respect@Work compliance
The AHRC framework identifies seven pillars organisations need to have in place. Here is each one: what good looks like, what evidence you need, and where most organisations fall short.
Pillar 1: Leadership and governance
If your board and executive team aren't engaged, everything else is window dressing.
The AHRC expects:
- Board understanding. Does your board actually understand the positive duty — not vaguely, but what it specifically requires?
- Regular reporting. Do they receive reports on harassment prevention, not just incident numbers after something goes wrong?
- Accountability. Are senior leaders held accountable for culture? Is it built into their KPIs and performance reviews?
- A standing agenda item. This should be discussed at least quarterly — not annually, not when something happens.
- Resources. Budget, staff time, technology, expertise. This can't be a side-of-desk activity for someone in HR who's already stretched.
- Leadership modelling. Are leaders actually demonstrating respectful behaviour and speaking up when they witness something inappropriate?
Evidence needed: board meeting minutes, executive KPIs including culture metrics, budget allocations, governance charters.
If you can't produce that evidence, you have a gap. And that's exactly what the AHRC will look for.
Pillar 2: Policies and procedures
Most organisations have a policy. The question is whether it's comprehensive, accessible, and actually used.
Comprehensive means it:
- Clearly defines sexual harassment, aligned to Section 28A of the Sex Discrimination Act
- Covers sex-based harassment — harassment based on gender that isn't sexual in nature
- Defines victimisation, meaning retaliation when someone makes a complaint
- Covers all contexts: online harassment, third-party harassment from clients and customers, and work events
- Provides multiple reporting pathways, not just "tell your manager" — what if the manager is the problem?
- Includes documented, trauma-informed investigation procedures
- Is reviewed annually and updated when legislation changes
- Is communicated to everyone: permanent staff, contractors, casuals, labour hire
A policy that sits in a drawer doesn't protect anyone. It just gives you something to point to when things go wrong.
Pillar 3: Risk assessment
This is where we see the biggest gaps.
You can't determine what's reasonable and proportionate without first understanding your risks. Risk assessment isn't optional. It's the evidence base that demonstrates you're taking proactive steps.
There are eight major risk factors to consider:
- Power imbalances — steep hierarchies, casual workers fearing for their jobs, visa-dependent workers, young or inexperienced workers
- Gender imbalance — male-dominated teams, token representation, absence of women in leadership
- Customer and client interaction — public-facing roles, service industry, "customer is always right" culture
- Isolated or remote work — working alone, home visits, FIFO arrangements, overnight travel
- Alcohol availability — licensed venues, work social events, client entertainment, drinking culture
- High-pressure environments — competitive workplaces, long hours, "work hard play hard" culture
- Lack of diversity — homogeneous workforce, exclusionary in-groups
- Poor workplace culture — sexualised banter normalised, aggressive behaviour tolerated, complaints dismissed
Several of those are recognised psychosocial risk factors in their own right, which is why this work sits alongside your broader work health and safety obligations rather than separately from them.
Your assessment needs to be based on actual data — employee surveys, focus groups, turnover data, exit interviews — not assumptions. You need a documented risk register that gets reviewed regularly, at least annually or when significant changes occur.
A risk assessment conducted once and filed away is worthless. It has to be a living document.
Pillar 4: Training and education
Poor quality training can do more harm than good.
Checkbox compliance training — boring, disconnected from reality, treating harassment as a simple "don't do this" list — creates cynicism, wastes resources, and provides no real protection.
What good training looks like:
- For managers. Enhanced training on recognising warning signs, responding to disclosures in a trauma-informed way, when to escalate versus handle informally, and how to create a respectful team culture. Two to three hours, scenario-based with role plays.
- For all workers. Foundation training covering the legal definition, workplace-specific examples, rights and responsibilities, reporting pathways, and bystander intervention. Sixty to ninety minutes, interactive, delivered at onboarding and refreshed annually.
- For HR and investigators. Specialist training in trauma-informed investigation methodology, advanced interview techniques, evidence collection, and procedural fairness. This is professional development, not awareness training.
- For board and executives. Strategic training on governance responsibilities and what the positive duty actually requires of them.
The critical question most organisations miss: are you measuring effectiveness? Not completion rates. Effectiveness. Pre and post assessments for knowledge gain. Tracking behaviour change over time.
If you're just counting who clicked through the e-learning module, you're measuring the wrong thing.
Training is not a box to tick. It's a capability to build.
Pillar 5: Reporting and response
This is where the rubber meets the road when something goes wrong.
Multiple reporting pathways. Manager, HR, external hotline, online portal, anonymous channel. You need at least three options, clearly documented and accessible. The most common reason people don't report is that they don't trust the process, don't believe anything will happen, fear retaliation, or the person they should report to is the problem.
If someone's only option is their direct manager, and their manager is the harasser, you don't have a reporting system. You have a closed door.
Response requirements. The AHRC expects response within 48 hours with initial contact and support — not "we'll get back to you when we can." Investigations must be trauma-informed, providing safety, transparency, choice, and empowerment. Procedural fairness for both complainant and respondent.
When harassment is substantiated. Consequences for the perpetrator, support for the person harmed, and systemic improvements to prevent it happening again.
Retaliation monitoring. Actively monitor for retaliation. It's the most common reason people regret reporting. If colleagues treat them differently, if they're passed over for opportunities, if their work life becomes harder — that's victimisation, and it's unlawful.
A complaint process that looks good on paper but fails in practice is worse than no process at all. It creates the illusion of safety while delivering none.
Pillar 6: Culture and prevention
This is where the real work happens.
Culture determines:
- Whether people feel safe reporting
- Whether bystanders intervene
- Whether complaints are taken seriously or quietly buried
- Whether harassers face consequences or get promoted anyway
You need to measure culture regularly through validated surveys — psychological safety, inclusion, respect, harassment prevalence. Not a one-off survey, but ongoing measurement tracking trends over time.
Look at whether bystander intervention is actually occurring. Are managers addressing concerning behaviour before it escalates, or waiting until a formal complaint when significant harm has already occurred? How are you managing high-risk contexts like work social events?
Where psychological safety is low, harassment thrives in silence. If you're not measuring culture, you're guessing. And guessing isn't a compliance strategy.
Pillar 7: Monitoring and continuous improvement
Compliance isn't a destination. It's a continuous loop.
The AHRC expects:
- Comprehensive data collection across all domains: prevalence, reporting, risk factors, culture, training completion, prevention activities
- Regular analysis, at least quarterly, to identify trends, patterns and emerging issues
- Leadership receiving regular reports, with harassment metrics going to the board quarterly
The critical question: are you using data insights to drive improvement actions, or just collecting data for reporting?
Data without action is just paperwork. The point of measurement is to learn.
When something goes wrong, conduct a post-incident review to identify systemic issues. Implement improvements. Don't just close the file and move on.
If you're not learning, you're not improving. If you're not improving, you're falling behind.
Why this is hard
Everything described above is a lot. Seven pillars, dozens of requirements, evidence across every one.
If you're thinking "we're nowhere near this," you're not alone.
The gaps usually aren't in the obvious places. Most organisations have a policy. Most do some training.
The gaps are in the harder questions:
- Is your board receiving regular reports on prevention, not just incidents?
- Is your risk assessment based on actual data, or assumptions?
- Are you measuring training effectiveness, or just completion rates?
- Are you learning from incidents to fix systemic issues?
These are the questions the AHRC will ask. Most organisations can't answer them confidently.
And this isn't static. Risks change. Your workforce changes. Legislation evolves. A restructure creates new power dynamics. A shift to remote work changes how people interact. A new client contract introduces third-party risks.
Compliance isn't something you achieve once and file away. It's something you maintain continuously.
The goal is continuous compliance
The organisations that get this right don't run annual audits that are outdated within months. They have continuous visibility into where they stand. They know where the gaps are before the AHRC asks. They can produce a compliance report with supporting evidence at short notice.
This isn't about avoiding liability, although it does that too. It's about actually preventing harm. Building workplaces where people feel safe, respected, and able to do their best work.
That's the prize. Not a clean audit. A healthy culture.
Find out where you stand
The hardest part is knowing where you actually are.
Most organisations have a general sense — probably okay in some areas, probably gaps in others — but not a clear, honest picture. And the seven pillars above are demanding precisely because they ask for documented evidence rather than good intentions.
That's the position a Gentia Roadmap is designed to resolve. It works from the material your organisation already holds — policies, position descriptions, structure, incident and claims data, workforce reporting — and produces a documented assessment of where risk actually sits, mapped against your obligations, with a prioritised plan for closing the gaps.
It covers psychosocial risk broadly rather than Respect@Work alone, which matters here, because several of the eight risk factors in Pillar 3 are psychosocial hazards in their own right. Power imbalance, high-pressure environments and poor workplace culture do not sit in a separate compliance box from job demands, role clarity and support. They are the same conditions, viewed through a different obligation.
Whichever way you approach it, the principle holds.
The organisations that get this right are not the ones with the best intentions. They're the ones with the best systems.



