Culture+
← Back to blog
Psychosocial SafetyBoard & GovernanceInclusive Leadership

Psychosocial Safety Governance Lessons from the Department of Defence Conviction

By Felicity Menzies2026-08-117 min read
Psychosocial Safety Governance Lessons from the Department of Defence Conviction

This is the fifth article in a weekly series on psychosocial hazard management in Australia. The series builds week on week, from the commercial stakes through recent prosecutions to The Psychosocial Safety Blueprint™, a proprietary executive operating model developed by Culture Plus for governing the systems that determine psychosocial safety. Subscribe on cultureplusconsulting.com.

Download the full Psychosocial Safety Blueprint™ →

In December 2025, the NSW Local Court convicted the Department of Defence and fined it $188,000 after Defence pleaded guilty to a Category 3 offence under section 33 of the Work Health and Safety Act 2011 (Cth). Defence admitted it had failed to take reasonably practicable measures to eliminate or minimise risks to the health and safety of a Royal Australian Air Force technician, breaching its primary duty under section 19(1). The Court also made an adverse publicity order.

It was the first conviction of a Commonwealth employer for failing to manage psychosocial risks under federal work health and safety laws.

The fine is the least interesting part of this case. What deserves employer attention is the gap the prosecution exposed between documented controls and the capability required to operate them. Defence had policies and guidance. What it lacked was supervisors trained to apply the available controls when psychosocial risk emerged during performance management.

Any organisation relying on policy as evidence that psychosocial risk is controlled should be aware of that distinction.

Policies existed. Capability did not.

Defence had existing policies and guidance addressing psychological health and safety.

This case involved the use of a draft Work Plan procedure as a performance management tool. Comcare identified controls that were available to Defence, including training supervisors to recognise when the process could become a psychosocial hazard, to identify risks affecting an employee undergoing performance management, and to understand when further intervention was required. That intervention could include referring an employee for medical assessment or suspending the performance management process altogether.

The issue at the heart of the prosecution was not whether Defence had documented its expectations. It was whether supervisors — the people required to give effect to those expectations — had the capability to do so. They did not.

This matters for every executive team.

A policy describes what the organisation intends to happen. An effective control changes what actually happens when risk arises. A policy is not a control when it cannot be enacted because staff have not received relevant training.

Policy coverage is not risk coverage

I've seen this too often. Unfortunately, many organisations treat the existence of a policy as evidence that a risk is controlled. The process is:

  • the hazard is identified
  • a policy or procedure is mapped against it
  • this appears on the risk register as a control

But control design and control effectiveness are different questions. A control can be well designed on paper and still fail in practice, because the people responsible for applying it do not recognise when it is required, do not understand how to use it, or lack the authority or support to act.

The psychosocial risk framework requires controls to be implemented and maintained so they remain effective. Documentation alone does not satisfy that standard.

For executive teams, this reshapes the assurance conversation. "Do we have a policy?" gives way to a harder question: what evidence demonstrates that the control works in practice? That is the evidence-of-effectiveness standard now shaping officer due diligence.

Performance management is a foreseeable source of psychosocial risk

The context of this prosecution is also relevant.

Performance management can generate or intensify multiple psychosocial hazards, including:

  • job insecurity
  • low job control
  • poor support
  • poor organisational justice
  • conflict and deteriorating workplace relationships
  • unclear expectations or role requirements

These are foreseeable risks that must be identified and controlled as part of the process itself.

The duty does not wait for an employee to become distressed or for psychological harm to occur. By that point, most of the decisions affecting risk have already been made: how the process will be conducted, who will manage it, how concerns will be communicated, what support will be available, and what will happen if risk escalates.

This is why psychosocial controls cannot sit in a separate policy document, at arm's length from the process itself. They need to be built into how performance management is designed and run — much as they belong before the announcement in organisational change.

What executives should examine

The Defence conviction raises several clear questions for organisations managing performance concerns or other high-risk people processes:

  • Have the psychosocial hazards associated with performance management been identified?
  • Are managers trained to recognise when the process is creating or intensifying psychosocial risk?
  • Do they know what controls are available and when to apply them?
  • Are there defined escalation points where HR, WHS or medical advice should be sought?
  • Can the process be modified, slowed or suspended where risk is no longer adequately controlled?
  • Is there evidence these controls are actually being used?
  • Does the organisation test whether managers have the capability to operate them?

These questions do not belong to HR or WHS alone. The effectiveness of the control environment turns on decisions about manager capability, accountability, escalation, resources and assurance. Those are governance decisions, and they sit with the executive and the board.

Training completion is not evidence of capability

The case also exposes a broader weakness in how organisations measure control effectiveness.

Training completion is commonly offered as evidence that a capability control is operating, but this is weak evidence. Completion shows that someone attended a program or clicked through a module. It says nothing about whether they can recognise a psychosocial hazard, make the required judgement, and apply the appropriate control in the middle of a difficult workplace situation.

For material psychosocial risks, organisations need stronger forms of assurance. That may include observation, scenario-based assessment, case review, manager supervision, employee experience data, incident trends, and testing of whether escalation mechanisms are understood and used.

The objective is evidence that the people responsible for operating the control can actually do so. More training, on its own, won't get you there — capability development has to be designed for transfer into practice.

The governance test

The governance test is straightforward. For every material psychosocial control the organisation relies on, can the executive demonstrate who is responsible for operating it, that they have the capability to do so, and that there is evidence the control works in practice?

The control should be clearly defined. The person responsible for operating it should understand what is required of them. And assurance should test effectiveness rather than simply confirm that a policy exists or training has been completed.

That is the distinction the Defence conviction brings into focus. A policy and guidance can demonstrate intent. It cannot demonstrate control effectiveness.

This article provides general executive commentary and does not constitute legal advice. Organisations should obtain advice from qualified legal practitioners about their particular obligations and circumstances.

Download the free white paper → The Psychosocial Safety Blueprint™ — the full executive operating model.

Discuss Your Needs → A confidential discovery conversation.

Solutions

Sources

  • Comcare, "Defence convicted after RAAF worker's death", 19 December 2025. Defence pleaded guilty to a single charge under section 33 of the Work Health and Safety Act 2011 (Cth); Comcare states that Defence breached its primary duty under section 19(1), was convicted and fined $188,000, and that Magistrate Brett Thomas made an adverse publicity order.
  • Comcare, Regulatory Guide – Managing Psychosocial Hazards, including requirements concerning the identification, assessment, control and maintenance of psychosocial risk controls.
  • Comcare, Work Health and Safety (Managing Psychosocial Hazards at Work) Code of Practice 2024.
  • The Psychosocial Safety Blueprint™, Culture Plus Executive Papers No. 01, Chapter 4, "Recent Regulatory Signals".

Felicity Menzies is the CEO and Principal Consultant of Culture Plus Consulting, a specialist practice focused on building respectful, safe, and inclusive workplace cultures across corporate and government organisations in Australia. Culture Plus Consulting provides workplace culture diagnostics and tailored interventions, including trauma-informed leadership development programs, to help organisations build the capability to lead safely and effectively.

Keep reading

More insights like this in your inbox.

Weekly insights on fostering respectful, safe and inclusive workplaces — direct to your inbox.

No spam. Unsubscribe anytime.

Work with us

Ready to translate insight into action?

Book a confidential call →