Boards that ignored speak-up systems are now the regulator’s next target
Last updated on 30 July 2026

For years, a whistleblower policy sitting in a folder was enough to satisfy an audit. Under the Aged Care Act, that’s no longer true. Providers must maintain dedicated systems, training and secure anonymous channels (not just a document) spanning residential care, home care and community services, with complaints and incident-management systems required to integrate rather than sit in silos.
At a recent Inside Ageing webinar, whistleblower systems specialist David Morgan set out why the regulator is treating this as a governance mechanism, not an HR task – and walked through an anonymised case study of what happens when a board doesn’t see it that way.
A regulator building capacity, not just watching
The Aged Care Quality and Safety Commission’s enforcement team has grown past 100 people, funded off the back of an earlier independent capability review. Commission research surveying more than 2,500 people across the sector this year found three things:
- Older people and families largely expect what the new rights-based laws already require.
- Raising concerns still isn’t normalised, because people wait until an issue feels “serious enough”.
- Whether someone speaks up at all depends as much on fear of consequences and system barriers as on the seriousness of the issue itself.
Where it went wrong
The case study Morgan walked through involved a growing aged care provider operating residential and home care services across multiple sites in one state. As the organisation expanded, its governance didn’t keep pace.
HR tracked complaints in its own spreadsheet. Quality and compliance kept a separate one. Different sites ran inconsistent versions of the same policies. Complaints, incidents and whistleblower reports had no connection to one another, and the formal reporting system was, in the words of staff interviewed, “clunky”. So clunky that people simply stopped using it, leaving the organisation with an incomplete picture of its own risk.
What followed was a familiar cultural pattern: high staff turnover, blame shifting between departing and remaining staff, entrenched silos at executive level, and what Morgan called “secret squirrel” behaviour (staff deliberately withholding information to protect their position).
The catalyst, in Morgan’s account, was leadership.
A chief executive whose values didn’t align with the organisation’s purpose set the tone from the top. Concerns raised by residents, families and staff were dismissed as unreasonable rather than assessed on their merits. Staff took their cue from that, disengaged, and stopped reporting internally.
The information didn’t disappear: it went elsewhere.
Anonymous reports went to the regulator while complaints reached local MPs and the media. By the time the regulator arrived, the organisation had lost the ability to demonstrate it was managing its own risk. The chairman departed, other board members left, and an enforceable undertaking followed, along with a heavy remediation workload.
The governance lesson
Morgan’s recommendations centre on boards getting an integrated, trend-level view – not just historical incident logs, but reporting that lets directors ask what might be coming next.
He offered a hypothetical illustration of what that could look like: say a board sees 47 reports in a quarter, with 23 still open and 42% resulting in no further action. The real value isn’t the raw numbers, it’s the questions they should prompt about complaint quality, investigation capacity and consistency across sites.
For boards, the practical shift is treating speak-up data the way they’d treat financial or clinical risk reporting: consolidated, trend-based, and reviewed at board level before a regulator asks to see it – not after.