You take on a second hire and someone raises a bullying complaint. You onboard a contractor and a data breach follows. You dismiss a poor performer and end up in the Fair Work Commission because the process was never written down. None of these outcomes are inevitable — but they become far more likely when your business is operating on unwritten rules and good intentions. Company policies are how you convert legal obligations into everyday operating instructions, and they are how you demonstrate to a regulator, a court, or a tribunal that you took reasonable steps before something went wrong.
What a company policy actually does
A company policy is a written statement of how your business expects people to behave or act in a defined situation. It is not a contract. Unless your employment contracts say otherwise — and they should not — a policy generally does not create a contractual entitlement that an employee can enforce as a term of their engagement. What it does create is a documented standard against which conduct and management decisions can be measured.
That distinction matters for two reasons. First, it means you can update a policy when the law or your business changes without needing individual consent from each employee — provided your contracts include a clause preserving that flexibility. Second, it means the evidentiary value of a policy depends on whether people actually knew about it and received training on it. A policy that exists only on a shared drive and has never been acknowledged or trained on offers much weaker protection than one that is embedded in induction, signed off on joining, and refreshed annually.
Which laws drive your policy obligations
Policies are not written in isolation. Each one typically sits under one or more pieces of legislation that create the underlying duty. Understanding which law is engaged helps you draft the right policy and pitch its contents correctly.
Fair Work Act 2009 and modern awards
The Fair Work Act 2009 (Cth) sets the National Employment Standards in Part 2-2 — ten minimum entitlements that apply to all national system employees regardless of what a contract or policy says. Hours of work, annual leave, personal and carer's leave, parental leave, flexible work requests, notice of termination and redundancy pay all flow from the NES. Your policies on leave, hours, overtime, and disciplinary procedures must not undercut those minimums, and they must not undercut the terms of any applicable modern award.
For small businesses — those with fewer than 15 employees — the Small Business Fair Dismissal Code sets the minimum procedural steps required before terminating an employee. A documented performance or disciplinary policy that mirrors the Code's process is your clearest defence against an unfair dismissal claim in the Fair Work Commission.
Work Health and Safety Act 2011 and officers' due diligence
Every employer in a jurisdiction that has adopted the Work Health and Safety Act 2011 (Cth) has a primary duty to ensure, so far as is reasonably practicable, the health and safety of workers. Officers — including directors and senior managers — carry a separate and personal duty under s 27 of the Act to exercise due diligence to ensure the business meets its WHS obligations. Due diligence under s 27 includes taking reasonable steps to acquire and keep up to date knowledge of WHS matters, understand the hazards associated with your operations, and ensure your business has appropriate resources and processes to eliminate or minimise risks.
A WHS policy, a hazard identification procedure, and an incident reporting process are the minimum documentary evidence that you have discharged that due diligence obligation. If a worker is injured and there is no evidence of a safety system, the officer's personal liability exposure is real.
Sex Discrimination Act 1984 — the positive duty
This is the legal development most likely to be underestimated by small businesses. Section 47C of the Sex Discrimination Act 1984 (Cth) imposes a positive duty on every employer and person conducting a business or undertaking to take reasonable and proportionate measures to eliminate, as far as possible:
- sexual harassment in connection with work
- sex-based harassment in connection with work
- discrimination on the ground of sex in a work context
- conduct creating a workplace environment that is hostile on the ground of sex
- related acts of victimisation
The Australian Human Rights Commission has held compliance and enforcement powers under this duty since 12 December 2023. The duty is proactive — it is not satisfied by waiting for a complaint and then responding to it. Businesses of all sizes must take positive steps to prevent this conduct before it occurs. A sexual harassment and sex-based harassment policy, reporting channels, regular training, and a documented investigation process are the foundational measures required. Without them, the business is exposed to both individual complaints and regulatory inquiry.
Privacy Act 1988
The Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to businesses with an annual turnover of more than $3 million, and to certain smaller businesses regardless of turnover — including private health service providers and businesses that trade in personal information. If your business is covered, you need both an external-facing privacy policy explaining how you collect, use and disclose personal information, and internal procedures governing how staff handle that information. An employee record exemption exists for handling of information directly related to the employment relationship, but this does not eliminate the need for internal data handling procedures — particularly where customer data is involved.
Corporations Act 2001 — whistleblower protections
If your business is incorporated, Part 9.4AAA of the Corporations Act 2001 (Cth) contains the whistleblower protection regime. Eligible whistleblowers who disclose information about misconduct by the company are protected from civil, criminal and administrative liability and from victimisation. Larger proprietary companies and public companies are required to have a whistleblower policy in place. Even if you are not required to have a formal policy, documenting your process for receiving, investigating and protecting disclosures signals to staff that concerns can be raised safely.
The core policies every business needs
You do not need to write everything at once. A risk-proportionate approach starts with the policies that address the highest-likelihood legal exposure, then expands over time.
People and conduct
A code of conduct sets professional standards, conflict of interest rules and the general expectations that underpin every other policy. A bullying, harassment and sexual harassment policy defines the prohibited conduct, provides multiple reporting channels, explains the investigation process, and reinforces confidentiality and anti-victimisation protections — this is the document most directly engaged by the s 47C positive duty. A performance and discipline policy documents the feedback, warning and termination pathway aligned to the Fair Work framework and, for small businesses, to the Small Business Fair Dismissal Code.
Work health and safety
A WHS policy confirms your duty to provide a safe workplace and your consultation and reporting arrangements. An incident reporting procedure sets out the step-by-step process for reporting injuries, near misses and notifiable incidents to the relevant WHS regulator. These two documents are the minimum evidence of an officer's due diligence under s 27 of the WHS Act.
Privacy and technology
A privacy policy — both public-facing and internal — addresses how personal information is collected, stored, accessed and disclosed. An acceptable use and IT policy defines how staff may use business devices, networks, cloud services and any AI tools, and sets access control expectations. A social media policy addresses employee conduct on personal accounts where their posts could be attributed to or affect the business.
Employment conditions
A leave policy explains how annual leave, personal and carer's leave, parental leave and other NES entitlements work in practice at your business — notice requirements, approval processes, and any above-award conditions you offer. A flexible and remote work policy sets out how requests are assessed and what obligations employees have when working offsite, including home office safety.
How to create and implement policies that hold up
The drafting process matters as much as the content. A poorly implemented policy can be worse than no policy at all if it creates expectations you do not follow.
Align content with your contracts and awards
Before drafting, identify the modern award that applies to your employees, check your employment contracts for any terms the policy must be consistent with, and note where your contracts cross-reference the policy suite. Your contracts should confirm that policies do not form part of the contract but that employees are expected to comply with them and that policies may be updated from time to time on reasonable notice. That language protects your flexibility to update without triggering a variation-of-contract dispute.
Draft in plain English, not policy template language
Policies that read like they were written for a regulator will not be followed by frontline staff. Use short sentences and active voice. Define terms where genuinely necessary — what counts as a "notifiable incident" under WHS legislation, for example — but avoid jargon hedging. Include examples of what conduct does and does not comply where the line is fact-specific.
Train, acknowledge, and record
For high-risk policies — sexual harassment, WHS, privacy and data handling — provide induction training and at least annual refreshers. Collect written or electronic acknowledgement that staff have received and understood the policy. Keep a log. This record is the primary evidence you produce when a regulator or tribunal asks whether your staff were aware of the policy.
Enforce consistently
If you apply a policy selectively — acting on one complaint and ignoring a similar one — the policy works against you. Inconsistent enforcement is evidence of a discriminatory or arbitrary process. Document every decision, follow your investigation steps, and apply the same standard across the team regardless of seniority or relationships.
Review on a schedule and when the law changes
Set a review cycle of at least 12 months for employment-related policies and whenever a relevant legislative amendment is announced. The s 47C positive duty under the Sex Discrimination Act was enforceable from December 2023 — businesses that had not updated their harassment and sexual harassment policies by that date were already behind. Assign a named owner to each policy so the review does not fall between the cracks.
Where the gap between policies and legal compliance actually sits
The most common failure is not that businesses lack policies — it is that the policies exist but do not accurately reflect the law, have not been updated after amendments, or have never been practically embedded. Three specific gaps appear regularly.
Policies that undercut award or NES entitlements. A leave policy that imposes conditions stricter than the NES — requiring longer notice than the Act permits, or restricting access to leave entitlements in ways the award does not allow — creates a compliance risk every time that policy is applied.
Sexual harassment policies that treat the duty as reactive. Many older policies are framed entirely around complaint handling: what to do after harassment occurs. A policy that only describes what to do after the fact does not discharge the proactive positive duty under s 47C. It needs to address prevention, training obligations, and the employer's own steps to assess and manage risk of this conduct.
Privacy policies that do not reflect how data is actually collected. A public-facing privacy policy that describes data collection practices different from what your business actually does creates exposure under the Privacy Act and, practically, erodes customer trust if a data event occurs.
How Artificer Legal can help
A policy is only as useful as the legal framework it accurately reflects. Artificer Legal assists businesses with:
- Auditing an existing policy suite against current legislative requirements — including the s 47C positive duty and any applicable modern award
- Drafting new or revised policies that work with your employment contracts and industrial instruments
- Reviewing employment contracts to ensure the cross-referencing and flexibility clauses are correctly structured
- Advising on the investigation and disciplinary process when a complaint has been made and the policy is untested
- Assisting when the Fair Work Commission or the Australian Human Rights Commission initiates a process
If you are building a policy suite from scratch or updating after a period of rapid growth, the starting point is usually a short consultation to map your exposure areas against your current documentation. From there, the priority policies can be drafted and implemented in a sequence that addresses the highest legal risk first.
Putting it together
The single thing most likely to determine whether your policy suite actually protects the business is whether it accurately describes what you legally must do — not just what you aspire to do. Policies copied from templates or drafted without checking the current Act text can paper over a compliance gap rather than close it. The laws governing employment, safety, anti-discrimination and privacy have all seen material amendments in recent years, and the s 47C positive duty in particular represents a shift in expectation that predates the formal enforcement power. Build from the legislation outward, not from the template inward.
Key points from this article:
- Company policies translate legal obligations into operating rules and create the documented standard against which management decisions and workplace conduct are measured
- The Fair Work Act 2009 (Cth) NES, modern awards and the Small Business Fair Dismissal Code set the floor for employment condition and disciplinary policies
- Officers carry a personal duty under s 27 of the Work Health and Safety Act 2011 (Cth) to exercise due diligence; a WHS policy and incident reporting procedure are the minimum documentary evidence of compliance
- Section 47C of the Sex Discrimination Act 1984 (Cth) requires proactive measures to prevent sexual harassment, sex-based harassment and related conduct — not merely a process for responding after the fact; enforcement powers have applied since 12 December 2023
- The Privacy Act 1988 (Cth) covers businesses above $3 million turnover and certain smaller businesses; both public-facing and internal privacy and data handling policies are required
- Effective policies must be aligned with contracts and awards, trained on, acknowledged in writing, enforced consistently, and reviewed at least annually and when the law changes