Compliance asks if it was done. Governance asks if you can prove it
- Josephine Tan
Governance is no longer a back-office function but a strategic capability, and organisations that continue to treat it as a compliance checklist risk losing both trust and talent. That was the central message of a recent LinkedIn Live session hosted by AsiaHRM, titled From Compliance to Confidence: Governance as the Foundation of Trust, Talent and Sustainable Growth.
Moderated by Rita Tsui, Founder of AsiaHRM, the session brought together Trisha Parashar, a lawyer practising at Tis Hazari Court in New Delhi, and Dr Aaiman Siddiqui, Assistant Professor at Lloyd Business School, India, to examine where compliance ends, where governance begins, and what the rise of AI in HR means for both.
Where compliance ends and governance begins
Opening the discussion, Parashar addressed a common conflation: organisations often use “governance” and “compliance” interchangeably. The distinction, she argued, lies in their nature. Compliance is retrospective and substantive – a matter of asking whether requirements have been met. Governance, by contrast, is procedural: “It is not a checklist… It is a mechanism where you can see and identify what has not been done.”
Governance, she added, also provides a means to demonstrate that compliance has occurred. Even an organisation that has followed every requirement must be able to answer the question of how it complied – and that proof is what governance supplies. She described it as a roadmap that evolves as organisations scale, anticipating the next compliance obligations as thresholds are crossed.
Tsui summarised the relationship: governance is broader than compliance, with compliance forming one part of it.
From control mechanism to trust mechanism
Dr Siddiqui approached the question from an organisational behaviour perspective, arguing that governance has shifted from a control mechanism to a trust mechanism – a change driven in part by generational expectations. Today’s workforce, she said, is more committed to organisations they can trust over the long term than those that exercise governance through punishment.
Traditional governance focused on preventing mistakes, she noted, whereas contemporary governance is oriented towards transparency, fairness and engagement. Control has its place, but only up to a point: “If that exceeds a certain limit, then of course your employees are going to be outraged… They are not going to stay in your organisation.”
Asked how organisations can make the shift in practice, Dr Siddiqui identified four components: transparency, fairness, responsibility and accountability. She also observed that trust accrues over time – an established organisation with decades of history can command a level of trust that a new entrant cannot easily replicate.
Tsui added that management support is critical to the transition, noting that boards may need to be convinced of the value of moving from control to trust.
AI in HR: Three areas of legal risk
The discussion then turned to the legal risks HR leaders should prepare for as AI becomes embedded in recruitment, performance management and employee monitoring.
On recruitment, Parashar pointed to algorithmic screening tools that filter candidates without any in-person assessment. The legal exposure here, she said, is indirect discrimination: candidates from particular institutions may be favoured, while those with employment gaps may be automatically filtered out – causing organisations to miss legitimate talent. Crucially, she stressed, accountability for those decisions “still lies on the person and not the AI.”
On performance management, she cautioned that AI-generated productivity scores and ratings are “too statistical, too mechanical” to capture human potential, and judging promotion prospects through automated systems risks eroding trust within the organisation. She also raised the difficulty of functionality, explaining an automated judgment if it is challenged as discriminatory or faulty.
READ MORE: Most leaders agree sustainability matters. Far fewer know what to do with it.
On employee monitoring, Parashar flagged practices such as keystroke tracking and sentiment analysis, particularly in an era of cross-border remote work. With data privacy laws in the picture, she said, organisations must be able to answer who owns accountability for a privacy breach arising from automated tracking. She also questioned how workplace complaints – citing India’s Prevention of Sexual Harassment (POSH) framework as an example – would be handled in fully automated monitoring environments.
Across all three areas, one question recurred: who has the accountability? Tsui echoed the point, observing that while organisations increasingly rely on AI, the ultimate responsibility must rest with humans rather than the technology – though she noted having heard of organisations where AI appears to have become the de facto decision-maker.
The accountability question ultimately looped back to where the session began: governance as a boardroom priority rather than a back-office function. As AI reshapes how organisations hire, evaluate and monitor their people, the panellists’ message was consistent – the frameworks may be automated, but the trust they are meant to build, and the responsibility they carry, cannot be.


