After more than a decade of POSH Law, perhaps the question is no longer whether organizations are compliant, but whether employees actually feel safe.
As an external member, you may spend years helping organizations understand the law. You help draft policies, constitute Internal Committees (ICs), train members, conduct awareness programmes, advise management and support inquiries. Over time, you watch organizations become increasingly sophisticated in their approach to compliance.
And then an incident happens. A woman is assaulted at a place where she should have been safe. The country is outraged. Questions follow about accountability, institutional responsibility, workplace safety and whether the systems we have built are actually working.
For those of us who have spent years in this space, the question becomes deeply uncomfortable. We begin to wonder how much have we actually changed or are we just moving in circles?
From Nirbhaya to POSH: A Decade of Institutional Change
The 2012 Nirbhaya case was undoubtedly a watershed moment in India’s conversation around violence against women. It triggered a significant legal reform, including the Criminal Law (Amendment) Act, 2013. Around the same period, the guidelines laid down in the Vishaka judgement was made a law through the enactment of Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 (POSH Act).
More than a decade later, an entire ecosystem has developed around POSH. There are practitioners helping organizations, large and small, with policies, IC constitution, training, employee awareness programmes, posters, annual reports and compliance audits. There is also now SHe-Box, a centralised government portal intended to provide greater visibility and monitoring of workplace sexual harassment complaints and the institutions responsible for addressing them. These are important developments.
But they also raise a more fundamental question. What happens when compliance exists, but culture does not? Let’s discuss some of the challenges of being compliant on paper but not in practicality.
The Real Test of POSH Is Not the Checklist
As a POSH practitioner, I have seen organizations become remarkably efficient at completing the compliance checklist. The policy is in place. The IC has been constituted. Annual awareness programmes are conducted. IC members undergo training. Posters are displayed. Documentation is meticulously maintained. On the face of it, such an organization may appear exemplary in a compliance audit.
Yet compliance on paper does not necessarily translate into a workplace culture that actively prevents boundary violations or sexual harassment.
One of the clearest examples is the annual “nil” report. Too often, the absence of complaints is treated as evidence that the system is working. An organization files a nil report and moves on without pausing to ask the more difficult question:
Does a nil report genuinely reflect a workplace where employees feel safe and respected? Or does it reflect a workplace where employees are hesitant to come forward?
A nil report is a data point. It is not, by itself, a measure of a healthy workplace culture. The absence of complaints can mean that there was no harassment. But it can also mean that employees do not know where to go, do not trust the process, fear retaliation, do not believe anything will change, or simply do not want to subject themselves to a process they perceive as difficult or exposing. That is why number of complaints, by themselves, tell us very little about organizational culture. The more meaningful question is whether employees have confidence in the system.
When the Respondent Has Power
The distance between compliance and commitment becomes particularly visible when the respondent is senior, influential, commercially important or someone who has been with the organization for a long time. That is often when the real test of an Internal Committee begins.
I have seen pressure being placed on IC members. Sometimes it is subtle.
“Can we look at this differently?”
“Do we really want to take such a strict view?”
“Is there a way we can resolve this without making it bigger than it needs to be?”
Sometimes, the concern is not about the complaint at all. It is about the consequences the decision like –
What will happen to the team?
What will happen to the business?
What will happen to the senior leader?
What message will this send?
And somewhere in that conversation, the IC can begin to look less like an independent committee and more like an inconvenient obstacle.
The POSH framework places considerable responsibility on the IC. It must examine allegations objectively, assess evidence, hear parties and witnesses, follow the principles of natural justice and arrive at a reasoned conclusion. However, the real test of independence arises when the respondent holds power.
An IC cannot exercise independent judgment if its findings are subtly or overtly influenced by organizational convenience, commercial considerations or the potential consequences for a senior employee.
Management has an important role to play. It must provide the IC with time, resources, administrative support and institutional cooperation. It must help ensure that parties and witnesses are protected from retaliation and that the committee can function effectively.
Also, there is a clear distinction between supporting the process and influencing its outcome. Management may legitimately ask whether an inquiry is progressing and whether the IC has what it needs. However, it should not seek to determine where the inquiry should lead. Management must support the IC, but it must not steer it.
Fair Process Also Means Acknowledging Misuse
There is another reality that we must be willing to acknowledge.
I have encountered situations where a POSH mechanism appeared to be used to settle scores arising from an existing interpersonal or workplace dispute. I have also seen situations where an organization appeared more interested in finding a technical reason not to conduct an inquiry, or in finding a way to establish guilt than in understanding what had actually happened.
Acknowledging the possibility of misuse, however, must not become an argument against POSH Law. Instead, it makes a fair and robust process even more important. A complainant deserves to be heard. A respondent deserves a fair opportunity to respond. An organization needs a process capable of distinguishing between an allegation that is substantiated, one that is not proved, one that is inconclusive and one that is demonstrably malicious.
That requires an IC that is not merely constituted, but genuinely competent to conduct an inquiry and make those distinctions. An IC that exists on paper but cannot effectively discharge its responsibilities is not meaningful implementation of POSH.
When Managers are not fully aware of their responsibilities
One of the more striking things I have encountered in practice is that employees can sometimes be better informed about POSH than the people managing them.
An employee may know that a complaint can be made, understand who the IC members are and be aware of their rights. But what happens when that employee approaches their manager with a concern?Does the manager know how to respond? Does the manager know what should be escalated to the IC?Does HR understand the boundaries of what it can share? Does leadership understand when its involvement becomes interference?
These questions matter because confidentiality can be compromised without anyone consciously deciding to compromise it.
A complaint may be discussed with colleagues because someone believes they are “helping.” A complainant’s or respondent’s identity may be casually disclosed without an appreciation of the consequences. A manager may ask questions that should properly be left to the IC.These are not always deliberate acts of interference. Sometimes, they are simply the result of people not understanding their roles.
This is why POSH training cannot stop with employees and IC members. Managers, HR and leadership also need to understand both their responsibilities and the limits of their involvement. An effective POSH framework depends not only on knowing what to do, but also on knowing what not to do.
The Workplace Has Changed. Has Our Understanding of POSH Kept Pace?
The workplace of 2013 is not the workplace of 2026. Today’s workplace is hybrid, digital, mobile and increasingly dispersed. Employees communicate through WhatsApp and other messaging platforms. Meetings take place over video. Teams work remotely. Employees travel together, work from client locations and interact with contractors, vendors and other third-party service providers. Work relationships extend well beyond traditional office premises and conventional working hours. Our understanding of the workplace must evolve accordingly.
The same is true of sexual harassment. Inappropriate conduct can no longer be understood only through the lens of physical and verbal interactions within an office. Digital harassment, inappropriate messages, unwanted sexual content, online conduct and misuse of workplace communication channels require organizations to think more carefully about both the scope of their policies and the standards of conduct expected from employees digitally.
A POSH policy should therefore do more than reproduce statutory language. It should translate the law into the realities of how people actually work and communicate within that organization. A hospital, factory, technology company, law firm, logistics company and hospitality business will face different workplace risks. Their policies, training and preventive strategies should reflect those realities.
A Poster Is Not Communication If People Cannot Understand It
This may sound like a small point, but in practice, it is not. I have seen organizations display beautifully designed POSH posters that appear to satisfy every compliance requirement, yet communicate very little to a significant section of their workforce.
Where an organization employs blue-collar workers, contract workers, housekeeping staff, security personnel or employees who are more comfortable communicating in a regional language, an English-only poster may technically satisfy a requirement while failing its purpose.
The real question should not be if the poster been displayed? It should be if the person who needs this information actually understands it and knows what to do with it? Meaningful communication may require local-language posters, simpler language, visual communication or verbal reinforcement, depending on the workforce.
Compliance has little meaning if the information does not reach, and cannot be understood by every person it is intended to protect.
One Annual Awareness Session Cannot Change Organizational Culture
This remains one of the most persistent misconceptions about POSH. Every year, an organization conducts its POSH session. Employees attend and feedback is collected. Then, the organization considers the requirement addressed. But culture does not change in two hours.
A senior manager, factory worker, HR professional, field employee and IC members do not face the same workplace realities. They therefore should not necessarily be having the same POSH conversation. Training needs to reflect their respective circumstances, responsibilities and risks.
Also, POSH awareness session cannot be the only occasion on which an organization talks about these issues. There needs to be an ongoing dialogue around boundaries, consent, gender, power, respectful communication and what it means to intervene when behaviour crosses a line.
Culture is built through repetition and everyday conversations and not through annual awareness sessions.
Perhaps We Need to Rethink How IC Members Are Selected
The constitution of an IC is often treated as a compliance exercise. Identify eligible employees, appoint them and arrange training. But being an IC member is not simply an additional designation.
It requires time, judgment, emotional resilience, an ability to listen without prejudgment, an understanding of natural justice and the confidence to arrive at a finding that may sometimes be uncomfortable for the organization.
Perhaps organizations should consider creating a larger pool of potential IC members, training them, assessing their understanding through hypothetical situations, understanding their interest in the role and considering whether they have the bandwidth to undertake it before constituting the committee.
The question must shift from just who can we appoint to who is capable and willing to carry this responsibility? The distinction matters. Once an inquiry begins, IC members must be WILLING to take up the opportunity and must be given adequate time, resources and institutional support. It is difficult to expect people to conduct serious inquiries alongside their regular responsibilities without recognizing the demands that the role places upon them.
IC Learning Should Not End With a Training Certificate
POSH is not static. Judicial decisions continue to shape its interpretation. Technology creates new forms of conduct. Workplaces evolve. New questions emerge. An IC member who attended training several years ago cannot reasonably be expected to remain current simply because they once received a certificate. IC members should therefore engage in periodic learning through discussions on recent judgments, legal developments, emerging issues and difficult hypothetical situations.
These discussions must not be limited to periods when a complaint is pending. In fact, they may be even more valuable when there is no active complaint, because members can learn without the pressure of an ongoing proceeding.
IC members should document appropriate learnings from their tenure so that newly appointed members do not have to begin from scratch every time the committee changes. Continuous learning is therefore not an additional feature of a well-functioning IC. It should be part of maintaining competence.
So, What Must Change?
Despite these challenges, I have seen leaders who have moved beyond asking “are we compliant?” to asking “What are we missing? What more can we do to make our employees safer and build a culture of mutual respect?” That shift is significant. It reframes POSH from a legal obligation to an organizational responsibility.
Yes, we need policies, properly constituted ICs, training, reporting mechanisms, statutory compliance but all of this should be bare minimum now.
The real questions are harder:
- Are IC members competent and current?
- Do managers understand their responsibilities?
- Is confidentiality genuinely respected?
- Can the IC function independently when the respondent is powerful?
- Do policies reflect the realities of the workplace?
- Are blue-collar and contract workers meaningfully included?
- Are emerging digital risks being addressed?
- Are leaders actively examining culture rather than simply waiting for complaints?
These are the questions that can tell us whether POSH is functioning as intended.
The motto should be continuous capability, culture and prevention.
After more than a decade of POSH, perhaps we need to move beyond asking whether organizations have complied with the law and ask whether the law is changing the way organizations function.
A policy, a training session, IC appointment, a poster, a nil report are all measurable. But trust, psychological safety, an employee’s willingness to speak up, the confidence of an IC to withstand organizational pressure is harder to measure. However, these may be far more meaningful indicators of whether the system is actually working.
Perhaps the next stage of POSH should focus more on continuous capability, culture and prevention. The goal cannot simply be to create workplaces that know what to do after sexual harassment occurs. The goal must be to create workplaces where people understand boundaries, respect one another, feel safe speaking up and recognize that dignity is not a compliance requirement. It is a basic condition of work that requires repeated and continuous conversation. Perhaps that is how we finally stop moving in circles.


