HR Governance & Compliance in Kenya

HR Governance & Compliance in Kenya

Employee Protection in Kenya: Why Governance and Compliance Matter

When an employee experiences delayed wages, an unsafe workplace, discrimination, harassment or an unfair disciplinary process, the problem is often described as an “HR issue.”

But that description is incomplete.

Employee protection is also a governance issue.

Decisions about staffing, remuneration, performance targets, workplace safety, technology, outsourcing and complaint handling are not made by HR alone. They are shaped by boards, senior management, procurement teams, finance departments, legal advisers, compliance officers and operational managers.

This means that an organisation cannot protect its employees through an HR policy alone. It needs an integrated governance and compliance framework that connects legal obligations, leadership accountability, operational controls, employee voice and effective remedies.

Employee protection begins with governance

Good corporate governance is fundamentally concerned with how decisions are made, who is responsible for them, what information reaches leadership and how an organisation is held accountable.

These questions directly affect employees.

For example:

  • Who approves performance targets that may encourage employees to work excessive hours?
  • Who ensures that outsourced workers receive appropriate safety equipment?
  • Who investigates a complaint involving the chief executive or head of HR?
  • What information does the board receive about harassment, payroll errors, workplace injuries and employee grievances?
  • Who verifies that corrective actions have actually been implemented?

If the organisation cannot answer these questions clearly, its employee-protection framework is likely to contain serious gaps.

A strong governance framework should connect four essential elements:

  1. Rules: What does the law or organisational policy require?
  2. Controls: What procedures make the requirement part of everyday work?
  3. Evidence: How does the organisation demonstrate that the control is operating?
  4. Remedy: What happens when an employee is harmed or a control fails?

A policy without operational controls is largely aspirational. A control without evidence is difficult to verify. A finding without an effective remedy leaves the employee exposed.

Kenya has a strong legal foundation for employee protection

Article 41 of the Constitution of Kenya guarantees every person the right to fair labour practices. It also recognises workers’ rights to fair remuneration, reasonable working conditions, union participation and collective bargaining.

Employee protection is further supported by legislation that includes:

  • The Employment Act, 2007;
  • The Occupational Safety and Health Act, 2007;
  • The Labour Relations Act, 2007;
  • The Work Injury Benefits Act, 2007;
  • The Data Protection Act, 2019; and
  • The Employment and Labour Relations Court Act, 2011.

Together, these laws address matters such as employment contracts, remuneration, leave, equality, sexual harassment, workplace safety, collective relations, occupational injuries, employee data and termination.

The challenge is that these obligations are often managed separately.

HR may handle employment contracts and discipline. The safety department manages workplace hazards. Procurement appoints contractors. IT manages monitoring systems. Finance processes payroll. Legal becomes involved when a dispute arises.

When these functions do not communicate, important employee risks can fall between departments.

Organisations should therefore maintain a legal and regulatory obligations register showing:

  • The applicable legal requirement;
  • The employees or workers affected;
  • The department responsible;
  • The required procedure or control;
  • The evidence that must be retained;
  • The escalation process; and
  • The date on which the obligation will be reviewed.

This register should cover legislation, regulations, collective bargaining agreements, contractual promises, internal policies and relevant sector requirements.

Employee protection should cover the entire employment lifecycle

Workplace risk does not begin when an employee raises a grievance. It begins with the first decision to recruit.

Recruitment

Recruitment advertisements and selection criteria can unintentionally exclude qualified applicants. Unstructured interviews may allow personal preferences or unconscious bias to influence decisions.

A defensible recruitment process should use:

  • Role-related selection criteria;
  • Consistent interview questions;
  • Properly constituted interview panels;
  • Conflict-of-interest declarations;
  • Documented reasons for selection;
  • Proportionate background checks; and
  • Reasonable accommodation where required.

Onboarding

Employees should receive more than a contract to sign.

They need a clear explanation of their remuneration, deductions, working hours, leave entitlements, reporting lines, safety procedures, data-processing practices and complaint channels.

An employee’s signature on a policy acknowledgement may prove receipt. It does not necessarily prove that the employee understood the policy or can use it in practice.

Performance, promotion and remuneration

During employment, organisations should periodically review decisions relating to:

  • Performance ratings;
  • Salary adjustments;
  • Promotion;
  • Training opportunities;
  • Leave;
  • Working hours;
  • Reasonable accommodation; and
  • Disciplinary action.

Leaders should look for unexplained patterns without assuming that every difference proves discrimination. The purpose of analysing workforce data is to identify areas that require further investigation.

Discipline and termination

Discipline and termination are among the clearest tests of an organisation’s commitment to fairness.

A fair process should ordinarily include:

  • A clear explanation of the allegation or concern;
  • Preservation of relevant records;
  • A reasonable investigation;
  • An opportunity for the employee to respond;
  • An impartial decision-maker;
  • A proportionate outcome; and
  • An effective appeal process.

A valid concern does not justify denying an employee a fair hearing. Equally, a procedurally correct hearing cannot cure an invented or unsupported reason for termination.

Good records should reflect genuine consideration. A polished file assembled after the decision has already been made cannot turn a predetermined outcome into a fair process.

Workplace safety is a leadership responsibility

Occupational safety and health should not be treated as an annual compliance exercise.

Risk assessments must reflect the organisation’s actual activities. The risks faced by a construction company will differ from those faced by a hospital, financial institution, school or professional-services firm.

Boards and senior management should understand how decisions concerning staffing, maintenance, equipment and procurement affect safety.

An organisation may report 100 per cent completion of safety training while employees continue working without appropriate protective equipment. In that situation, training statistics create an appearance of compliance without reducing the underlying risk.

Effective assurance should therefore include:

  • Workplace inspections;
  • Employee interviews;
  • Review of incident records;
  • Testing of emergency procedures;
  • Verification of corrective actions; and
  • Examination of recurring hazards across sites.

The objective is not simply to document that an incident was reported. It is to establish whether the injured person received assistance, the relevant notification was made, evidence was preserved, the cause was investigated, and the hazard was corrected.

Employees must be able to speak without fear

An organisation cannot rely entirely on information supplied through management reporting lines.

Employees are often the first people to identify unsafe conditions, discriminatory practices, payroll errors, unethical conduct or harmful management behaviour.

A credible grievance and whistleblowing mechanism should be:

  • Easy to find;
  • Free to use;
  • Accessible to different categories of workers;
  • Available through more than one reporting channel;
  • Capable of independent escalation;
  • Supported by clear response timelines; and
  • Protected against retaliation.

A low number of complaints does not automatically indicate a healthy workplace. It may also mean that employees do not trust the reporting process.

Organisations should therefore ask more meaningful questions:

  • Do employees know where to report concerns?
  • Do they believe they will be taken seriously?
  • Can agency and temporary workers use the same channels?
  • What happens when the complaint involves a senior executive?
  • Are complainants protected from subtle retaliation after a case is closed?
  • Do employees receive feedback on the outcome?

Retaliation is not always an explicit threat. It may appear through undesirable shifts, isolation, delayed promotion, sudden negative appraisals or exclusion from important assignments.

Outsourcing does not eliminate responsibility

Many organisations depend on cleaners, security guards, drivers, temporary workers and other personnel supplied by contractors.

The lead organisation may control the workplace and daily activities, while another company formally employs and pays the workers. This arrangement can create uncertainty about who is responsible for wages, protective equipment, supervision and grievance handling.

Governance should begin by mapping who:

  • Recruits the workers;
  • Pays them;
  • Supervises their work;
  • Provides equipment;
  • Controls the workplace;
  • Investigates incidents; and
  • Takes disciplinary action.

Procurement teams should also assess whether a proposed contract price realistically allows the supplier to pay lawful wages, provide adequate staffing and meet safety obligations.

An unrealistically low contract price can manufacture non-compliance.

Contractual clauses on labour practices are helpful, but they are not enough. Organisations should verify working conditions, investigate incidents and ensure that outsourced workers can report hazards directly to the person controlling the site.

Employee monitoring and artificial intelligence require stronger oversight

Modern workplaces collect extensive employee information, including biometric records, location data, recruitment profiles, communications, medical information and performance scores.

Under Kenya’s data-protection framework, employers must process personal data lawfully, fairly and transparently. They should also observe principles such as purpose limitation, data minimisation, security and appropriate retention.

Employee consent should be approached carefully because an employee may not feel free to refuse.

Before introducing an employee-monitoring or automated decision-making system, the organisation should ask:

  • What legitimate purpose does the system serve?
  • Is there a less intrusive alternative?
  • What information will be collected?
  • Who will have access to it?
  • How long will it be retained?
  • Could the system disadvantage particular employees?
  • Can an employee challenge inaccurate information?
  • Does human review have the authority to change the outcome?

The employer remains responsible for its employment decisions even when an external technology provider supplies the system or recommendation.

What should boards be asking?

Boards do not need to manage every employee complaint. Their responsibility is to ensure that management has established reliable systems and that serious or conflicted matters receive independent attention.

A useful board workforce report should cover more than headcount, payroll costs and employee turnover.

It should include:

  • Material workplace risks;
  • Serious injuries and safety incidents;
  • Significant payroll errors;
  • Harassment and discrimination trends;
  • Regulatory findings;
  • The age of unresolved corrective actions;
  • Contractor and outsourced-worker risks;
  • Employee confidence in reporting channels; and
  • Areas in which management lacks reliable data.

Boards should also establish escalation thresholds. Matters involving fatalities, serious violence, systemic wage errors, significant data breaches or credible retaliation by senior management may require immediate notification.

Independent directors are particularly important where allegations involve the chief executive, senior management or the head of a control function.

Moving from policy compliance to genuine protection

Organisations can begin strengthening employee protection through a phased approach.

During the first 90 days

They can:

  • Appoint a senior executive responsible for the framework;
  • Map applicable legal and regulatory obligations;
  • Identify severe workplace hazards;
  • Review outstanding wages and statutory contributions;
  • Confirm that complaint channels are accessible;
  • Clarify how allegations involving senior leaders will be handled; and
  • Give the board an honest baseline assessment.

Over the next six to twelve months

Management can:

  • Revise policies and procedures;
  • Train managers using realistic workplace scenarios;
  • Review contractors and labour suppliers;
  • Test payroll and safety controls;
  • Involve employee representatives in proposed changes;
  • Establish a quarterly reporting rhythm; and
  • Conduct independent reviews of high-risk areas.

Over the longer term

Employee protection should be integrated into major organisational decisions involving restructuring, outsourcing, technology, acquisitions, performance targets and budget allocation.

Internal audit should revisit previous failures. Board evaluations should examine whether directors receive meaningful workforce information and whether they challenge incomplete or overly reassuring reports.

The true test of employee protection

The strength of an employee-protection framework is not measured by the number of policies an organisation has adopted.

The real test is whether an employee can:

  1. Understand their rights;
  2. Exercise those rights without fear of retaliation;
  3. Receive a fair and timely response;
  4. Obtain an effective remedy; and
  5. See the organisation address the underlying cause of the problem.

Governance and compliance become meaningful when they make this sequence routine rather than exceptional.

Employee protection is therefore not simply about avoiding litigation. It is about building a lawful, fair and sustainable organisation in which leadership decisions respect human dignity and workplace risks are identified before they become crises.

Organisations that connect board oversight, legal compliance, HR controls, worker voice and independent assurance are better placed to protect their employees, maintain trust and demonstrate responsible governance.

Does your organisation’s employee-protection framework work in practice or does it exist mainly on paper?

Capita Registrars Limited supports boards and senior management teams with governance assessments, legal and compliance audits, policy reviews, board training and the design of practical accountability frameworks.

For support in strengthening your organisation’s HR governance and employee-protection systems, contact Capita Registrars Limited through www.capitaregistrars.co.ke.

Would you like us to help you with anything about:

HR Governance & Compliance in Kenya

Get in Touch with our Team Today

Share Article On:

Facebook
X
LinkedIn
WhatsApp

If you’d like us to help you with anything about:

HR Governance & Compliance in Kenya

Please fill out the form below and we’ll contact you as soon as we receive it. Or click the WhatsApp Button to start a conversation.