Why sexual harassment data belongs in the boardroom, and why it almost never gets there

Ask a board what the organisation’s cyber risk position is, and someone has a dashboard. Incidents open. Incidents past service level. Mean time to close. A trend line, reported quarterly, with a named owner sitting somewhere in the room. Ask the same board what its harassment risk position is, and what usually comes back is…

Legal Updates β€’ July 20, 2026 β€’ 33 views β€’ By Ungender Team

Ask a board what the organisation’s cyber risk position is, and someone has a dashboard. Incidents open. Incidents past service level. Mean time to close. A trend line, reported quarterly, with a named owner sitting somewhere in the room.

Ask the same board what its harassment risk position is, and what usually comes back is a policy document and a training completion rate. Sometimes an assurance that there have been no complaints this year, offered in the tone of good news.

It is rarely good news.

A workplace with no complaints is either exceptional or it is silent. From a boardroom, the two are indistinguishable. And the organisations that discover which one they were tend to discover it in the worst possible way: through a resignation, a headline, a writ petition, or a labour officer’s inspection.

We sit in these rooms often. What we have come to believe is that this is not a story about negligent boards. It is a story about under-served ones.


The asymmetry nobody has justified

Every serious risk in a large organisation has a reporting line. Financial exposure has one. Cybersecurity has one. Regulatory compliance has one. Operational risk, credit risk, supply chain risk, data privacy: each has an owner, a cadence, a set of numbers, and a route by which those numbers reach the people who are accountable for them.

Harassment is expected to travel from an Internal Committee, through an HR function, to a board, on goodwill.

No dashboard. No cadence. No agreed metrics. Frequently no route at all, unless something has already gone badly enough wrong that it arrives as a crisis rather than as information.

Ask yourself what other risk of this consequence β€” legal, financial, reputational, human β€” an organisation would knowingly run that way.

The board is already accountable. It simply cannot see.

This is the part that surprises people, and it is worth stating plainly.

The board is already required to speak to this. Under the Companies Act Rules, a company’s Board Report must carry a statement that the company has complied with the provisions relating to the constitution of an Internal Committee under the POSH Act. That statement is signed. It is filed. It is a representation by the directors.

For listed entities, SEBI’s Reporting framework goes further, requiring disclosure of complaints of sexual harassment: numbers filed, numbers resolved, and what remains pending.

So consider the position most boards are actually in. They are certifying POSH compliance, and disclosing complaint numbers to the market, on the basis of an assurance passed up a chain β€” from a committee, to an HR lead, to the board β€” with no system underneath it that anyone could interrogate.

The directors are not being reckless. They are signing something they have been given no instrument to verify.

And the surrounding environment is hardening, not softening. State governments are activating inspection powers that had lain dormant for years, with detailed compliance checklists. The National Commission for Women has pushed for those powers to be operationalised more widely. The mandated POSH audit is no longer a theoretical exposure. What was once assessed by whether a policy existed is increasingly assessed by whether the process can be evidenced.

An assurance is not evidence. It is a hope, passed upward.


“We have had no complaints”

We want to spend a moment on this sentence, because it is the single most misread data point in the whole field.

A low complaint count can mean the workplace is genuinely safe. It can also mean that people have concluded, correctly or otherwise, that reporting is more dangerous than staying silent. It can mean the reporting channel is not known, not trusted, or not reachable by the people most exposed to harm β€” the frontline, the contractual, the night shift, those who do not work in English.

Those two situations produce an identical number. And a board that treats a falling complaint count as a success metric has, without meaning to, created a powerful incentive for the organisation beneath it to keep that number low.

This is why complaint volume alone is close to useless as a governance signal. What matters is complaint volume read alongside everything else: how quickly matters are acknowledged, how many cross their statutory timeline, whether reporting rises after an awareness cycle (which is usually a sign the channel is working, not failing), and whether some functions or locations produce complaints at rates that differ sharply from the rest of the organisation.

None of that is visible without a system. All of it is invisible in a training completion rate.

What leadership actually needs, and what it must not have

Here is where boards, reasonably, get nervous. The instinct is that harassment data is too sensitive to move, and that giving leadership visibility means giving leadership access to complaint files.

It does not. It must not. And confusing those two things is what has kept many organisations stuck.

Leadership does not need to read complaint files. It should not read complaint files. An Internal Committee inquires into the matter before it, independently, on its own merits. Its proceedings are confidential under Section 16. If leadership can open individual matters, the committee’s independence is compromised and the inquiry is contaminated.

What leadership needs is the aggregate. Not the story. The shape.

  • How many matters are open across the organisation, right now
  • How many have crossed, or are approaching, their statutory timeline
  • Time to acknowledgement, and time to closure, as trends
  • Distribution: which functions, locations, and levels, expressed as rates rather than raw counts
  • Whether reporting is rising or falling, and in which parts of the business
  • What is stuck, and where it is stuck

Every one of those can be produced without any individual file becoming readable by anyone outside the committee handling it.

That is not a compromise between confidentiality and oversight. It is what a properly built system does by design: role-based access, so a matter opens only for the committee inquiring into it; an audit trail, so every access has a name and a timestamp; and an aggregate layer, so the employer sees the picture it is accountable for without seeing the contents it has no business seeing.

Confidentiality is not a behaviour. It is an architecture. Done properly, it produces more board visibility, not less β€” because the alternative, the complaint that lives in a trusted inbox and gets forwarded three times, is neither confidential nor visible. It is simply untracked.


The pattern the board is responsible for

There is one more thing only the organisation can see, and it is the most important.

An Internal Committee decides the complaint in front of it. It is not meant to go looking through a respondent’s history, and if it did, it would be prejudicing the very inquiry it is conducting. So when a matter is closed for want of evidence, and a similar matter arises eighteen months later in a different office before a different committee, neither committee is at fault for failing to connect them. Each was doing exactly what the law asks.

Seeing the pattern was never the committee’s job.

It is the employer’s. It is a Section 19 duty β€” to provide a safe working environment β€” and it cannot be discharged by an organisation that is unable to read its own record.

This is the argument for a case management system stated at its most serious. Not efficiency. Not tidiness. The employer has an obligation that no individual committee is positioned to fulfil, and most employers have built nothing that would let them fulfil it either.

Why goodwill stops working at scale

For an organisation of two hundred people, one committed HR lead can hold the whole thing in her head. She knows every matter, every date, every commitment made to every person. We have met her many times. She is usually excellent, and for a while she is enough.

At twenty thousand, she does not exist. She cannot.

What exists instead is several Internal Committees who have never spoken to one another, complaints arriving through four different channels, matters running in a dozen cities, committee members rotating on and off mid-inquiry, statements in languages nobody has translated, and a leadership team that will one day be asked, publicly, what it knew and when.

And the failure at that scale is never one bad decision by one bad actor. It is a hundred small gaps, each individually forgivable. A complaint that sat eleven days before anyone acknowledged it. A witness statement nobody saved. A timeline nobody was counting. A pattern nobody could see.

These are not careless organisations. The failure is not a shortage of care. It is the absence of anywhere for the care to be held.


What we would ask your board to do

Not to buy anything. To find out where it stands.

One. Ask, at the next meeting, how many POSH matters are currently open and how many have crossed their statutory timeline. Note not just the answer, but how long it takes to produce one, and how many people had to be asked. That latency is the finding.

Two. Ask who is able to open a complaint file today, and whether the organisation can produce a list of everyone who has read the most recent one. If it cannot, the confidentiality obligation is being met by hope.

Three. Ask what would be produced, and how quickly, if a matter closed two years ago were challenged tomorrow. A case file should not be something you assemble. It should be something you already have.

Four. Establish a cadence. Harassment risk should reach the board on a schedule, in aggregate, the way every other material risk already does β€” not when it becomes a crisis, and not for the first time in a courtroom.

The claim, stated plainly

Harassment data is governance data.

It carries legal exposure, financial exposure, reputational exposure, and a duty of care to the people who work for you. It is disclosed to regulators and, for listed entities, to the market. The board already certifies it.

Everything about it says it belongs where the board can see it. Almost nothing in how most organisations are built allows it to get there.

If your board asked today how many POSH matters were past their statutory timeline, who would have to go and find out?


Ungender has spent more than a decade in POSH advisory, inquiry, and Internal Committee work, across organisations of every size. Conduct is our case management and compliance platform: a single, defensible record for every matter, role-based access that keeps each Internal Committee sealed inside its own inquiry, and an aggregate view built for the people who are accountable for the whole.

Read more about Conduct β†’