top of page
Search

The HR Dilemma: When the Function Meant to Protect People Also Has to Protects the Organization...



There’s a difficult truth many organizations prefer not to confront: the function often presented as protecting and serving people is also part of the system designed to protect and serve the organization.

In an ideal organization, that distinction shouldn’t exist. Protecting the organization and protecting its people should not be competing duties, and serving the organization and serving its people should not require different loyalties. After all, an organization is not merely a legal entity, a governance structure, a reporting chart, or a collection of policies. An organization is a gathering of people, with people, for people. It exists because human beings come together to create value that none of them could create alone.


That is the foundation we too often forget.


The tension appears when the purpose of the organization is distorted. When the organization stops being a vehicle for shared value and becomes a vehicle for preserving position, status, control, or personal power, governance itself begins to drift. Structures that were meant to serve the mission begin to serve the people who have captured authority. Processes that were meant to protect integrity begin to protect the system from accountability. Policies that were meant to create fairness begin to shield unfairness behind procedural language.

This is close to what we might call the Iron Law of Organizations: over time, the people who hold power inside an institution can become more invested in preserving their position within the organization than in serving the purpose for which the organization exists. When that happens, the mission becomes secondary to internal survival, and the machinery of governance can be turned toward protecting the “unleaders” rather than protecting the people, the mission, or the truth.


That is where the HR dilemma begins.


Human Resources performs necessary functions. Payroll, benefits, hiring support, onboarding, employment documentation, compliance processes, policies, employee records, and employment administration all need to be managed properly. These responsibilities matter, and organizations can’t grow responsibly without some form of structure around them.

But administration is not the same as protection, and compliance is not the same as ethical leadership.

The deeper question is not whether organizations need HR-related functions. They do. The real question is whether an internal HR department can credibly be presented as the independent guardian of people when it reports into the same management structure it may one day need to challenge.

That question becomes especially urgent when someone raises a serious concern: misconduct, retaliation, harassment, discrimination, abuse of authority, conflicts of interest, fraud, bullying, psychological abuse, or violations of organizational values. On paper, most organizations have reporting mechanisms for these situations. There’s a policy, a hotline, a form, a process, and usually a statement promising confidentiality and protection from retaliation.

But the ethical question isn’t whether a reporting channel exists. The real question is who controls it.



When governance drifts away from purpose


The problem is not simply that HR may be conflicted. The deeper problem is that any organizational function can become conflicted when governance itself has drifted away from purpose.


Governance should exist to keep the organization aligned with its mission, values, responsibilities, and stakeholders. It should protect the organization by protecting the conditions that make the organization legitimate: trust, fairness, accountability, competence, transparency, and respect for people.

But when governance is captured by self-preservation, its role changes. It no longer asks, “What is right for the people, the mission, and the long-term integrity of the organization?” It asks, “What protects the current leadership, the current narrative, and the current distribution of power?”


That shift is often subtle at first. It may appear as cautious messaging, legal review, reputation management, procedural discipline, or the desire to avoid “creating precedent.” None of these things are necessarily wrong in themselves. Organizations do need care, consistency, and legal awareness. But when those mechanisms become detached from ethics and purpose, they can gradually create a culture where truth is treated as a threat, dissent as disloyalty, complaints as disruption, and harmed people as liabilities.


That is when governance stops serving the organization’s purpose and starts serving the “unleaders” who benefit from avoiding accountability.

HR, in that context, is not always the root problem. It becomes one of the instruments through which the deeper governance failure is expressed.



The structural conflict at the heart of internal reporting




When an employee, volunteer, member, or stakeholder reports harm, misconduct, or abuse of authority, the organization is immediately placed in a defensive position.

If the report is true, the organization may have failed to prevent the harm, detect it earlier, enforce its own policies, or stop a culture, leader, manager, or governance system from operating in contradiction with its stated values. That creates legal exposure, reputational exposure, governance exposure, and leadership exposure.

Once that happens, the person raising the concern can quickly become perceived not as someone to protect, but as a liability to manage. This is where internal reporting mechanisms often fail. The person who comes forward may believe they’re entering a process designed to establish truth and protect integrity, while in reality, they may be entering a process designed to protect the organization from the consequences of that truth.


That distinction matters deeply.


A truly ethical reporting mechanism isn’t designed to protect the organization from embarrassment. It’s designed to protect the integrity of the organization, which sometimes means confronting embarrassing, uncomfortable, or damaging truths.



A company is not the police, the judge, or the jury

Organizations aren’t courts. They aren’t law enforcement agencies. They aren’t independent public authorities. They shouldn’t behave as if they can privately prosecute, privately adjudicate, and privately close matters that may involve illegality, abuse, or serious ethical violations.


If something potentially illegal has happened, the role of the reporting mechanism shouldn’t be to contain the matter internally for the convenience of the organization. Its role should be to preserve the facts, protect the person reporting, prevent retaliation, and ensure the case is oriented toward the appropriate formal authority.


If the matter isn’t illegal but still violates decency, trust, professional ethics, or the stated values of the organization, then it shouldn’t simply disappear into an HR file. It becomes a governance issue, because the absence of illegality does not mean the absence of harm. It belongs within the fiduciary responsibilities of those who administer and oversee the organization.


In both cases, independence is essential.


An organization can’t credibly claim ethical leadership while reserving for itself the exclusive right to determine whether it has behaved ethically.



When abuse is unethical but not illegal




There is another layer to this issue, and it is one I had to understand as an immigrant in the United States.


In several countries, especially in parts of Europe, workplace psychological harassment, moral harassment, bullying, or abusive conduct may be addressed more directly through legal frameworks, labor protections, health and safety duties, or employer obligations. Those frameworks are not perfect, and they do not prevent every abuse, but they at least recognize that mistreatment at work can be a systemic harm and not merely an interpersonal disagreement.


The U.S. context can be different. Some forms of harassment, discrimination, retaliation, or hostile work environment conduct may be illegal when they relate to protected characteristics, protected activity, or specific statutory rights. But many forms of workplace bullying, gaslighting, humiliation, intimidation, manipulation, and psychological abuse can remain outside meaningful legal protection when they don’t fit into one of those recognized categories.


That realization was disturbing to me.


It means that a person can be mistreated in ways that are clearly harmful, clearly unethical, and clearly destructive to dignity and health, while still discovering that the law may offer little or no direct protection. It also means that “legal” and “ethical” are not the same thing. Something can be lawful and still be profoundly wrong.


That gap creates space for “unleaders” to operate. It allows people in positions of power to bully, isolate, undermine, gaslight, and retaliate while staying just inside the boundary of what the law will recognize or what the organization can conveniently deny. It allows governance systems to say, “No policy was violated,” while people are being harmed in plain sight.

This is precisely why ethical leadership cannot be reduced to compliance. Compliance asks whether the organization can defend what happened. Ethical leadership asks whether it should have happened at all, what harm it created, what responsibility the organization has, and what must change to prevent it from happening again.


It is also one of the reasons I decided to found the Ethics and Leadership Association.


Not to create another mechanism for judging who is a “good leader” and who is an “unleader,” not to turn ethics into a label people use against one another, and not to personalize every failure as a matter of individual virtue or moral deficiency. That approach rarely helps organizations improve, and it often makes people defensive before the real work can even begin.


The purpose is different.


ELA exists to help people and organizations do this right. It is about giving leaders, managers, boards, and teams the tools, frameworks, language, and shared reference points they need to depersonalize ethical issues and handle them with structure. When organizations lack those tools, everything becomes personal: personalities, loyalties, power dynamics, reputations, and informal influence. When the right frameworks exist, difficult situations can be addressed with more clarity, consistency, fairness, and accountability.


That matters because taking proper care of people is not a soft issue. It is an organizational performance issue. Organizations that protect dignity, reduce fear, handle conflict fairly, and prevent abuse of power become more resilient, retain trust more easily, learn faster, reduce destructive conflict, and improve organizational agility because people are less afraid to speak, challenge, report risks, and contribute honestly. Managers also become more effective in their roles when they are not left alone to improvise ethical decisions under pressure, without a framework, without language, and without a clear process.


Ethical leadership is not about being morally perfect. It is about being equipped to make better decisions, especially when the situation is ambiguous, emotional, political, or risky.


That is also why the work of organizations such as End Workplace Abuse matters so much. Where the law is incomplete, advocacy becomes necessary. Where organizational systems normalize mistreatment, education becomes necessary. Where people are harmed by conduct that remains too often invisible or unprotected, ethical leadership must help name the harm, challenge the structures that allow it, and support the movement toward stronger protections.


This is why End Workplace Abuse becoming a Value Partner with the Ethics and Leadership Association matters. The connection is not incidental. It reflects a shared belief that dignity at work is not a luxury, that abuse of power is not a management style, and that organizations have a responsibility to protect people not only from what is illegal, but also from what is unethical, corrosive, and dehumanizing.



When the process is turned against the person who speaks



There’s another way internal reporting mechanisms can become dangerous: they can be turned against the very person who raised the concern.

The pattern is painfully familiar. Someone reports misconduct, abuse, retaliation, harassment, or an ethical breach. Instead of protecting the person who came forward and investigating the substance of the concern, the organization reframes the situation. The person who reported becomes the person under investigation.

The original complaint disappears into procedural fog. The focus shifts from the alleged wrongdoing to the conduct, tone, motives, attitude, loyalty, or “professionalism” of the person who raised it. The organization may imply that the complaint itself was disruptive, harmful, exaggerated, malicious, or evidence of poor judgment.


In practice, the message becomes clear: “You raised a concern, but now the concern is you.”


What makes this even more damaging is the absence of meaningful due process. In many internally controlled processes, the person being targeted may not be told clearly what they’re accused of, who made the accusations, what evidence exists, what standard is being applied, or how they can respond. They may be expected to defend themselves against vague allegations, anonymous claims, or shifting narratives.


That isn’t a fair process; it’s a controlled one.


When the organization controls the complaint, the counter-complaint, the investigation, the evidence, the interpretation, and the outcome, the imbalance of power becomes overwhelming. The process may look formal from the outside, but for the individual inside it, it can feel like being trapped in a system where the rules are hidden, the accusations are unclear, and the conclusion has already been written.


This is why independence matters not only for the person reporting harm, but also for anyone accused through the process. A credible mechanism must protect both truth and fairness. It must prevent retaliation against the original complainant, but it must also prevent the organization from manufacturing, amplifying, or selectively using counter-allegations to silence, discredit, or remove that person.

Ethical leadership requires due process. That means clear allegations, access to the substance of the claims, a fair opportunity to respond, impartial review, documented reasoning, and protection from retaliatory misuse of the process.

Without those safeguards, the reporting mechanism doesn’t protect integrity. It protects power.



The impossible promise of HR



This raises a difficult question about the role of Human Resources.

HR departments perform necessary administrative and organizational functions. Payroll, benefits, hiring processes, compliance requirements, employment documentation, onboarding, policies, employee relations records, and workforce administration all need to be managed properly. Those functions matter.

But there’s a difference between HR administration and ethical protection.

The problem is that organizations often present HR as the place employees can go when they’ve been harmed by the organization, by a manager, or by a leadership culture. That promise is structurally difficult to keep.


When an employee reports wrongdoing, HR is rarely independent from the organization’s interests. HR is usually part of the management system. It reports into the same executive structure that may have created, tolerated, minimized, or ignored the harm. It’s also often expected to reduce legal risk for the organization.

That creates a fundamental tension.


To fully stand with the person reporting harm, HR may need to acknowledge that the harm occurred. But acknowledging that harm occurred may also mean acknowledging that the organization allowed it to occur. That acknowledgement can create legal, reputational, and financial consequences.


So the person reporting the issue may gradually be reframed, not as the person harmed, not as the person trying to protect the organization’s integrity, but as the source of risk.


This is why many employees learn, often painfully, that internal reporting doesn’t always lead to protection. Sometimes it leads to isolation, documentation, performance scrutiny, reputational undermining, or removal.

Again, this isn’t only a question of individual morality. It’s a question of structural conflict.


Structurally, HR can’t always stand with the person harmed because HR isn’t designed to be independent from the organization’s self-protection reflex. That doesn’t mean every HR professional lacks compassion or integrity. Many care deeply and may want to do the right thing. But good intentions aren’t enough when the function itself sits inside a conflicted system.


That being said, structure doesn’t erase personal responsibility.


This is where integrity becomes decisive. Every individual placed inside such a system still has to make a personal choice. When someone is asked to comply with something that’s obviously unfair, retaliatory, misleading, or unethical, the question is no longer only “What does my role require?” or “What does the organization expect from me?” The question becomes: “Can I do this and still remain aligned with my own values?”



In the Integrity Model, a decision has to be tested across several layers: ability, legality, ethics, and values. Something may be possible. It may even be internally authorized. It may be presented as compliant. But if it violates fundamental ethics or one’s own values, then compliance becomes a personal choice, not a neutral obligation.


This matters because organizational systems are made of individual decisions. Retaliation isn’t an abstract process. Gaslighting isn’t an abstract process. Procedural unfairness isn’t an abstract process. At some point, someone writes the email, opens the investigation, withholds the information, reframes the complaint, signs the letter, or remains silent while knowing what’s happening.

A conflicted system creates pressure. It doesn’t remove accountability.

Ethical leadership requires people to recognize the moment when obedience becomes complicity. In those moments, integrity isn’t demonstrated by having good intentions privately, but by refusing to participate publicly, formally, or operationally in what one knows to be wrong.



Ethical leadership requires credible channels, not performative channels



A reporting mechanism that people don’t trust is worse than symbolic. It’s dangerous.

It invites people to disclose sensitive information into a system that may not be designed to protect them. It creates the appearance of accountability while allowing the organization to control the narrative, the evidence, the process, and the outcome.

That isn’t ethical leadership.

Ethical leadership requires mechanisms that people can actually trust when the stakes are high.


This means whistleblower and serious complaint mechanisms should be handled by external, independent third parties. Those third parties should have a clear mandate, defined authority, confidentiality protections, anti-retaliation safeguards, escalation protocols, and the ability to distinguish between legal matters, governance matters, cultural failures, and interpersonal conflicts.

The organization shouldn’t control the entire process when the organization itself may be part of the problem.


Independence isn’t a threat to leadership. It’s a protection for ethical leadership. It protects the person reporting, the person accused, the integrity of the process, the organization from self-deception, boards and administrators from relying only on filtered internal narratives, and the possibility of truth.



Governance, not containment



One of the most important shifts we need to make is to stop treating whistleblowing as an HR issue.


Whistleblowing is a governance issue.


A serious report isn’t just an employee relations matter. It may reveal a failure of leadership, culture, oversight, incentives, risk management, psychological safety, or ethical accountability.


That’s why boards and administrators have a responsibility to ensure reporting systems are not merely compliant, but credible.


The fiduciary duty of administrators isn’t only to protect the organization from liability. It’s to protect the legitimacy, integrity, and long-term sustainability of the organization. Sometimes that requires confronting uncomfortable truths rather than managing them away.


An organization that retaliates against those who report concerns isn’t protecting itself; it’s destroying trust in its own governance. An organization that silences whistleblowers isn’t reducing risk; it’s compounding risk. An organization that investigates itself without independence isn’t demonstrating accountability; it’s asking stakeholders to accept a conflict of interest as a process.


And an organization that weaponizes the process against the person who came forward is using governance language to disguise retaliation.



The role of managers cannot be delegated to HR



There’s another uncomfortable point: taking care of people isn’t the role of HR alone.

It’s the role of every manager.

Managers are the first line of ethical leadership. They create the climate in which people either speak or remain silent. They determine whether concerns are welcomed or punished. They model whether values matter only in speeches or also in decisions. They influence whether people feel protected, respected, and heard.

When organizations delegate “people care” entirely to HR, they often allow managers to avoid their own responsibilities.


But leadership can’t be outsourced.


A manager who harms people can’t be redeemed by the existence of an HR department. A leadership culture that tolerates retaliation can’t be corrected by a reporting form. A governance system that protects power over truth can’t be made ethical through policy language.


Ethical leadership lives in behavior, structure, and consequences. It lives in what leaders tolerate, investigate, ignore, reward, punish, and protect. It also lives in whether people who speak truth are protected or sacrificed.



Do growing organizations really need HR departments?



As organizations grow, the question of HR often appears naturally. At some point, payroll, benefits, contracts, onboarding, policies, and compliance require structure.

But growth shouldn’t automatically mean recreating the same HR model that has failed so many people.


There are alternatives; organizations can use external HR administration providers for payroll, benefits, and employment logistics, or rely on qualified legal counsel for legal matters. They can also establish independent ethics and reporting channels, they can create governance-level oversight for serious concerns and train managers to carry their real responsibility for the people they lead.


The question isn’t whether administrative HR functions are necessary. Many are.

The question is whether an internal HR department should be presented as the protector of employees when it’s structurally accountable to management.

That promise may be impossible to keep.

And making promises an organization can’t keep is itself an ethical problem.



Building mechanisms people can trust



A credible ethical reporting system should be built around several principles:


  • First, independence. Serious concerns should be receivable and reviewable by a party not embedded in the management chain.


  • Second, protection. The person reporting must be protected not only from formal retaliation, but also from informal retaliation: exclusion, reputation damage, reassignment, demotion, performance targeting, or slow professional erasure.


  • Third, due process. Anyone accused through the process must have access to the substance of the allegations, a fair opportunity to respond, and protection from vague, shifting, or retaliatory claims.


  • Fourth, clarity. The mechanism should distinguish between illegal conduct, policy violations, ethical breaches, governance failures, cultural issues, and interpersonal conflicts. Not every issue belongs in the same process.


  • Fifth, escalation. Matters involving potential illegality should be directed toward the appropriate formal authorities. Matters involving governance failure should reach the appropriate oversight body. Matters involving cultural harm should trigger leadership accountability, not only individual case management.


  • Sixth, transparency of process. Confidentiality doesn’t mean opacity. People need to know how reports are handled, who reviews them, what protections exist, and what happens after submission.


  • Seventh, accountability. Reporting systems must include consequences for retaliation, bad-faith investigations, suppression of evidence, misuse of counter-allegations, and leadership failure to act.


  • Finally, learning. Ethical incidents shouldn’t be buried once resolved. They should be used to strengthen governance, culture, training, and leadership expectations.



Ethical leadership begins where self-protection ends



The real test of ethical leadership isn’t how an organization behaves when it’s praised. It’s how it behaves when someone tells the truth at a cost.

Does the organization listen? Does it protect the person who speaks? Does it seek facts, or does it seek control? Does it ask what happened, or who is now a problem? Does it confront the failure, or manage the liability? Does it offer due process, or procedural fog? Does it protect integrity, or power?


The difference between ethical leadership and performative ethics is often revealed in that moment.


A whistleblower mechanism should never become a trap. It should never become a tool to identify, isolate, and remove those who challenge misconduct. It should never be controlled entirely by those whose interests may be threatened by the report.


If organizations want people to speak up, they must build systems worthy of that trust. If organizations want people to accept accountability, they must provide fair process. And if leaders want to claim ethical leadership, they must be willing to place truth beyond their own control.

 
 
 

Comments


bottom of page