Article · POSH & Workplace Compliance

Why POSH Compliance Belongs in Every M&A and Governance Diligence Checklist

A target's POSH compliance history is a legitimate, checkable governance signal - not a peripheral HR matter to be waved through.

When a due-diligence team walks into an acquisition, POSH compliance is rarely the first thing on the checklist. Given how directly the courts are now supervising implementation, and how squarely a governance failure here can sit with a company's leadership, that's an oversight worth correcting.

The obligation sits with the "employer," and that's broader than it sounds

The POSH Act's core duties - constituting an Internal Committee, framing and displaying a policy, assisting in inquiries, filing annual reports - are placed on the "employer" as defined under Section 2(g). For a company, that generally captures the persons responsible for managing, supervising and controlling the workplace, which in practice draws in the entity itself and can implicate the officers actually responsible for HR and compliance decisions. This isn't a free-floating obligation that HR quietly owns in isolation - it's an obligation with the entity's governance structure sitting directly behind it.

The Act doesn't create a standalone personal-liability clause for directors the way some other statutes do, and - to be precise about where the law actually stands - no court has yet held a director or KMP personally liable specifically for failing to act on a POSH complaint escalated to them. What follows is our own analytical reasoning about how such a failure could surface, not a description of an established legal rule: a governance lapse of that kind would most plausibly be pursued through existing, separately-established doctrines - fiduciary-duty claims, oppression-and-mismanagement proceedings, or, for a listed company, disclosure obligations that exist entirely independent of POSH itself - rather than through any liability mechanism POSH itself creates. Treat this as a risk worth pricing into diligence, not as settled case law.

Where this becomes concretely relevant in a transaction

A target company with no properly constituted Internal Committee, no evidence of annual reporting, or an unresolved complaint sitting past its statutory deadlines isn't just an HR loose end - it's an active compliance liability that transfers, in substance if not always in strict legal form, to whoever ends up controlling that entity. A pending inquiry that's been handled poorly (say, in the manner the Supreme Court found objectionable in Aureliano Fernandes) carries litigation risk that doesn't disappear because ownership changed hands.

For a listed target specifically, a material POSH-related event - a high-profile complaint against senior management, or an adverse Internal Committee finding - can independently trigger disclosure obligations under securities regulations, and increasingly features in the governance-pillar disclosures institutional investors expect to see addressed in ESG-linked reporting. A diligence process that skips this doesn't just miss a compliance gap; it misses a genuine valuation and reputational variable.

What a real diligence module actually checks

A proper POSH diligence exercise goes beyond asking whether a policy document exists. It should confirm: whether an Internal Committee is currently and correctly constituted at every qualifying location (not just head office); whether the target has actually filed its required annual reports, and what those reports show about complaint volumes and outcomes; whether any complaint has been pending inquiry beyond the statutory 90-day window, or awaiting employer action beyond the 60-day window, since either is a live procedural defect rather than a resolved matter; and whether SHe-Box registration - increasingly expected across a growing list of states - has actually been completed.

Where a gap surfaces, it doesn't automatically kill a deal, but it does belong in the same conversation as any other identified liability - factored into representations and warranties, escrow structuring, or a specific pre-closing remediation condition, rather than left as an unaddressed assumption that the acquirer will "sort it out later."

Why this is a genuinely underserved diligence area

Financial, tax and IP diligence are mature disciplines with well-established checklists. POSH diligence, by contrast, is still frequently treated as a box-ticking HR question rather than a governance-risk assessment - even though the current judicial environment makes clear that regulators and courts are taking implementation failures seriously, not treating them as a formality. That gap is exactly where a diligence practice that actually builds out a substantive POSH module differentiates itself from one that doesn't.

The takeaway

A target's POSH compliance history is a legitimate, checkable governance signal - not a peripheral HR matter to be waved through. Building a genuine POSH module into your standard diligence checklist, rather than a single "do you have a policy" question, catches exactly the kind of liability that a court's current enforcement posture is designed to expose.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Boards should consult qualified legal counsel for company-specific guidance.