Anastasia Roumelioti

All writing

Board Memo, Addendum 2 · ESG, Responsibility & Ethics

Measuring at the Right Moment and Governing the Transition

· Anastasia Roumelioti

BOARD MEMO | ADDENDUM 2

Where this Memo sits in the series

The original Board Memo in this series established the risk: the tolerance of male violence is a systemic governance failure with measurable consequences for institutional stability, economic participation and long-term going concern. The first Addendum named the antidote: accountability. It demonstrated that the same tolerance structure operates across every jurisdiction, legal system and cultural context, and that accountability is the only mechanism that disrupts it consistently.

This Addendum addresses the harder question that follows: how do you govern something you have not previously been measuring, in an environment where the first act of measurement will produce data that looks like deterioration? It is an operational memo. The argument has been made. This is presenting the governance solution.

The prior problem: We are measuring the wrong moment!

Every governance framework currently applied to male violence and its consequences measures outcomes: the incident reported, the complaint filed, the conviction secured, the pay gap disclosed, the representation figure published. These are lag indicators. They record what has already occurred at the visible end of a long causal chain. By the time they appear in a board report, the harm they document has long since been absorbed by the people who bore it.

The harm is not the event but the anticipation of the event, sustained across a lifetime of rational threat assessment in an environment designed to make that threat credible. The human nervous system does not distinguish between a threat that has materialised and one that is credibly expected. Research on complex PTSD establishes that repeated exposure to low-level but credible threat produces cumulative neurological harm, elevated cortisol, hypervigilance, the contraction of attention and ambition, comparable to single acute trauma. The body does not wait for the event to register the cost. Our governance frameworks do.

The structural erasure of women from the historical, scientific and institutional record compounds this. Every institution that attributes contributions inaccurately, teaches history through an exclusively male lens, or fails to audit its own record for the systematic patterns documented by the Matilda effect, is sending the same signal: the threat to your presence and your legacy is credible. That signal is not the background, but part of the harm and system’s architecture.

The consequence is that the total cost of tolerating male violence is vastly larger than any current measure captures. We are not failing to measure the harm. We are measuring it after it has already happened and calling that governance. The first obligation of a board that takes this seriously is to move the measurement earlier: from the event to the environment that made the event probable.

We are reading the autopsy and calling it a health system.

Sources: Herman: Trauma and Recovery (1992) | van der Kolk: The Body Keeps the Score (2014) | Rossiter: Women Scientists in America (1993)

The regulatory consequence

If anticipatory harm is harm, the reporting implications follow on existing frameworks without requiring new legislation.

ESG frameworks currently measure the wrong end of the causal chain. The incident report, the harassment complaint, the attrition figure: these are consequences of an environment, not the environment itself. The lead indicator is the environment: what does the institution communicate, formally and informally, about the probability of harm and the security of contribution for the women inside it? The TCFD precedent on climate-related financial disclosures is directly applicable: climate risk reporting moved from retrospective outcome disclosure to prospective, scenario-based assessment of conditions and exposures. The same architecture is available here. The question is not whether it can be done. It is whether the will exists to require it.

Workplace safety law in most developed jurisdictions already covers psychological harm. The UK Health and Safety at Work Act 1974 requires employers to protect employees from risks to mental health as well as physical health. An employer who knowingly maintains an environment producing chronic anticipatory threat is, on a consistent reading of existing law, already in potential breach. The barrier is evidentiary, not legislative: the same barrier that took decades to cross for occupational stress, and which the clinical literature on anticipatory harm is now approaching. The test cases have not yet been brought. They will be.

Duty of care in negligence requires a duty, a breach and harm. All three are arguable on current law for institutional environments that produce documented anticipatory harm. The causation barrier remains significant, but it is on the same trajectory as occupational disease liability: scientific consensus, regulatory guidance, test litigation, expanded liability, compliance. Institutions that have assessed and addressed their environments now are managing a risk that is on a well-documented path toward enforceability. Institutions that have not are accumulating exposure.

From exposure to programme: the GDPR precedent

The regulatory exposure is real. The question is what a governed institution does with it. This section sets out the programme architecture.

The General Data Protection Regulation did not succeed because it created new legal risk. Organisations had always faced consequences for mishandling personal data. It succeeded because it created a programme: a shared vocabulary, named accountability, mandatory training, documented processes and a requirement to demonstrate compliance on demand. It moved data protection from a legal function that sat in one department to an operational discipline that ran through every layer of the institution. The DPO became a board-level concern. The audit became a recurring obligation. The training became mandatory for every member of staff. The question shifted from are we compliant to can we demonstrate that we are, at any point, to any regulator.

That architecture is directly transferable. Personal data exists and is being processed whether an organisation knows it or not; GDPR made ignorance indefensible. Anticipatory harm is occurring in institutional environments whether those institutions measure it or not; the emerging regulatory framework makes ignorance equally indefensible. The parallel holds at every level of the programme design.

Mandatory literacy, not optional awareness

GDPR training is not optional and not aspirational. Every member of staff, from the board to the front desk, must complete it. It covers what data is, why it matters, what the rules are, and what happens when they are breached. It is repeated. It is documented. Completion is tracked and can be demonstrated to a regulator on demand.

The equivalent programme for anticipatory harm covers: what anticipatory harm is and how it operates physiologically; how institutional environments produce or prevent it; what erasure looks like and why it is a governance issue, not a cultural preference; what the cost of tolerance is at institutional, regulatory and economic level; and what each person’s role is in either reproducing or disrupting the tolerance structure. It is mandatory, repeated and tracked. And its completion is documented as evidence that the institution has taken reasonable steps to address a known and governable risk, which is precisely what the duty of care and ESG disclosure frameworks will require.

Named accountability at Board Level

GDPR requires a named Data Protection Officer: an individual with specific expertise, direct board access and documented responsibility for the programme. The DPO cannot be overruled on compliance matters. Their appointment is itself a signal that the institution has accepted ownership of the risk.

The programme for anticipatory harm requires the equivalent: a named board-level owner of the transformation programme, with documented responsibility for the baseline assessment, the lighthouse definition, the milestone tracking and the board reporting. Not a working group and ot a committee. A named individual who can be asked, by a regulator or a court, what the institution did, when it did it, and how it knows. The existence of that person is itself a governance act. It closes the accountability gap at the point where the gap is most consequential: at the top.

The Breach Principle: the absence of governance is the offence

The most important principle GDPR established for institutional behaviour is this: the breach is not the offence. The absence of governance is the offence. An organisation that suffers a data breach but can demonstrate that it had appropriate technical and organisational measures in place is treated fundamentally differently from one that cannot. The regulator’s question is not did this happen but did you have a programme that should have prevented it, and can you show it?

The parallel is exact. Under the emerging duty of care, ESG disclosure and workplace safety frameworks described in the preceding section, the liability trigger will not be the incident of harm. It will be the absence of a documented, demonstrable programme for assessing and addressing the environment that produced it. The institution that can demonstrate a named owner, a baseline assessment, a defined lighthouse, tracked milestones and mandatory training is in a fundamentally different regulatory and legal position from the one that cannot. The harm may be the same. The accountability is not.

Boards that understand GDPR already understand this argument. They have already built a programme, appointed an owner, trained their people and documented their processes for a risk that was once invisible and is now a compliance baseline. The institutional muscle exists. Are boards willing to apply it to a risk that is harder to name, more politically uncomfortable, and more structurally embedded than data protection? The answer to that question is itself a governance choice. And governance choices, as I argue in this series from the beginning, have owners.

The breach is not the offence. The absence of governance is the offence. Boards that built a programme for data already know how to build one for this. The question is whether they will.

Governing the transition: a transformation programme, not a compliance exercise

Governing anticipatory harm requires a transformation programme. This distinction is not semantic. It determines the entire governance architecture.

A compliance exercise asks: are we meeting the standard? It is evaluated against fixed metrics at a defined point in time. Its failure mode is gaming: institutions learn to meet the metric without changing the conditions the metric was designed to measure. A transformation programme asks a different question: are we moving in the right direction? It is evaluated against evidence of directional change, not evidence of arrival. It requires a different set of instruments: a defined end state that provides orientation when interim data is unreliable, and leading indicators that measure movement before outcomes stabilise.

The distinction matters because transformation programmes have a known and predictable vulnerability in their early stages that compliance exercises do not. That vulnerability is the misreading of early data, and it is the primary mechanism by which tolerance structures defend themselves against genuine change.

The lighthouse: defining the non-tolerant End State

The lighthouse is the defined end state: a precise description of what the institution looks like when it has redesigned its environment rather than merely managed its reporting. It is not a metric. It is a direction. It provides the fixed reference point against which all interim data, including data that appears to show deterioration, is interpreted.

In the context of governing anticipatory harm, the lighthouse describes an institution in which: the reasonable expectation of a person raising a concern is confidence in the outcome, not fear of reprisal; contributions are attributed accurately regardless of the sex of the contributor; the cost of speaking is lower than the cost of silence; and the institution’s historical record reflects the actual distribution of contribution rather than the prior assumptions of those who compiled it. None of these conditions require a perfect institution.

They require a governed one: one in which these standards are stated, assessed, reported and acted upon.

The milestones: leading indicators of movement

Milestones are leading indicators of movement toward the lighthouse. They measure whether the system is changing, not whether it has changed. Specifically designed to remain meaningful during the transition period, when outcome-based metrics are unreliable, milestones answer the question the board must be able to ask at every stage: is the programme moving in the right direction, regardless of what the lag indicators currently show?

Milestone indicators for this transformation include: whether the institution has conducted a baseline assessment of the environment in which women operate, not only its formal policies but its informal architecture; the proportion of complaints that result in documented structural review rather than individual case management only; whether an audit of internal attribution and historical record practices has been completed and acted upon; the ratio of people reporting confidence in the outcome of raising a concern, tracked over time as a trend rather than a point-in-time measure; and whether the board itself has reviewed the diagnostic questions in this series against its own environment and published its findings. Each of these measures direction, and none waits for arrival.

The misreading of early data

The most consequential governance decision a board will make in the early stages of this transformation is how it interprets rising incident data. This is where the programme is most vulnerable, and where the tolerance structure most effectively defends itself.

During transition, two effects operate simultaneously. First, previously invisible harm becomes visible: reporting increases, incidents surface, the gap between stated values and actual conditions becomes measurable for the first time. Second, some actors respond to new scrutiny by intensifying the behaviours under scrutiny, before controls are sufficiently embedded to prevent it. Both effects produce numbers that look like deterioration. Neither is deterioration.

An increase in visible incidents in the early stages of a transformation programme is evidence that the environment is becoming less tolerant of silence, not more tolerant of harm. A governance framework that responds to rising incident numbers by pausing or reversing the intervention has misread its own data. It has confused the surfacing of previously tolerated conditions with the creation of new ones. This confusion is not accidental. It is the mechanism by which most institutional change programmes fail, and the tolerance structure has always depended on it.

The lighthouse and milestones framework provides the corrective. If milestone indicators are positive, the direction is correct. Rising incident data alongside positive milestones is success. It means previously invisible harm is becoming visible: the first and necessary precondition for addressing it. The appropriate board response is to accelerate controls, deepen the structural review, and hold the direction. The tolerance structure has always depended on silence. When silence ends, the numbers rise and that is not a problem to be managed. That is the point!

In early transformation, an increase in visible harm is a leading indicator of success. It means the environment is becoming less tolerant of silence, not more tolerant of harm.

The Board’s obligations

The governance intervention begins with assessment. The board’s first obligation is to establish, honestly and with the same rigour applied to financial or operational risk, what the environment in which people operate within the institution actually communicates. Not the policy, the environment.

The assessment must address four questions. First: what is the reasonable expectation of a person who raises a concern in this institution, based on the historical record of outcomes, not on the stated policy? Second: whose names are on the record when significant contributions are made, and does that distribution reflect the actual distribution of contribution? Third: when a person’s career stalls or they exit the institution, what proportion of reviews conclude with a structural explanation rather than an individual one? Fourth: does the institution’s own historical record, its case studies, its leadership programmes, its named examples, reflect the contributions of everyone accurately or has it reproduced the erasure pattern this series has documented? I would expect the majority of people to be women…

The answers to these questions will locate the institution on the tolerance spectrum. They will also establish the baseline from which the transformation programme is measured. An institution that cannot answer these questions does not have an information gap. It has a governance gap. The information is available. The decision not to look is itself a governance choice, and it is accountable.

The regulatory horizon described in this Addendum is not a future threat to be anticipated. It is a current condition to be addressed. The clinical evidence is established. The legal architecture is in place. The measurement frameworks are in development. The question for boards is not whether accountability for anticipatory harm will arrive. It is whether the institution will be ready when it does, or whether it will still be reading the autopsy.

Governance framework and recommendations

The full governance framework for how boards, regulators and institutions can respond to male violence as systemic risk, including the 'What good governance looks like' section, the analysis of SLAPPs as a tool of institutional silence, and the 'Men as stakeholders' argument, is set out in:

Board Memo 1: A Going Concern, Why Boards Must Confront Male Violence

Also make sure you read the first addendum

Addendum 1: Tolerance of Male Violence as a global governance risk

More writing