When systems fail at the top: What Gibson v Maritime New Zealand (2026) means for WHS Officers
- Martyn

- Apr 15
- 4 min read

In March 2026, the New Zealand High Court decision in Gibson v Maritime New Zealand presents a significant development in modern work health and safety law. It addresses a question that has long sat largely untested in complex organisations:
What does “due diligence” actually require of a chief executive?
This case provides a clear, and confronting, answer.
The incident
In August 2020, a 31-year-old stevedore was killed at the Port of Auckland when a container fell during crane operations.
The Port accepted responsibility and pleaded guilty to breaching its primary duty of care. The regulator then prosecuted the CEO, Tony Gibson, personally for failing to exercise due diligence under the Health and Safety at Work Act 2015.
This shifted the case from an operational failure to one of executive accountability.
The legal issue
The case did not turn on whether the organisation failed. That was already established, as the Port pleaded guilty.
The question was whether the CEO failed to take reasonable steps to ensure that:
effective systems were in place to manage critical risk, and
those systems were actually working in practice.
The focus was on crane operations, particularly:
the absence of effective exclusion zones
failure to verify that controls were functioning on the ground.
The outcome
The High Court dismissed both the conviction appeal and the sentence appeal, upholding the CEO’s original conviction, along with a financial penalty of approximately $190,000.
This is one of the first successful prosecutions of a senior officer of a large organisation under modern due diligence provisions.
Why the CEO was found liable
The Court’s reasoning is instructive.
Knowledge of risk was not enough
The CEO understood the risks associated with suspended loads, however, knowledge alone does not discharge due diligence. Risk controls must be verified for effectiveness.
Systems existed, but were not effective
The organisation had established safety systems, including policies, training, and governance structures.
However, these systems did not adequately reflect actual work practices, particularly on night shift. Work as done differed from work as imagined.
Failure to verify “work as done”
A central issue was the gap between documented systems and operational reality.
The CEO:
did not ensure effective monitoring of frontline practices
was on notice of deficiencies
did not ensure systems captured actual risk exposure.
Over reliance on behavioural controls
The organisation relied heavily on:
rules and procedures
training and worker compliance.
There was insufficient emphasis on higher order controls, such as engineering or physical safeguards.
Due diligence cannot be delegated
The Court confirmed that Officers cannot rely solely on management layers or assume systems are effective.
Reliance must be accompanied by active inquiry and verification.
What the case clarifies about due diligence
This decision provides practical clarity on Officer obligations.
Officers are not required to guarantee safety outcomes, but must take reasonable steps to ensure compliance
the test is objective, that is, what a reasonable officer would do in the same circumstances
organisational complexity increases expectations, rather than reducing them
failure of the organisation does not automatically result in Officer liability, but liability arises where the officer could and should have influenced improvement.
Practical implications for executives and boards
This case has direct relevance to governance and assurance.
Paper systems are not enough
Documented systems, policies, and training provide limited protection unless they are:
implemented
monitored
aligned with operational reality, i.e Work As Imagined = Work As Done.
Verification is the critical control
The central question for officers is:
How do you know your controls are working?
Not whether systems exist, but whether they are effective.
Test “work as done”
Executives need mechanisms to understand:
how work is actually performed
where drift from procedural norms occurs and why
whether informal practices undermine controls.
Known risks require active response
Where critical risks are known, passive oversight is insufficient.
Failure to strengthen controls in response to known deficiencies creates exposure.
Leadership must be operationally informed
Effective due diligence requires:
direct understanding of operations
engagement with frontline risk
challenge of filtered or incomplete reporting (Beware of watermelons! Green on the outside but red under the surface).
SafeWork NSW v Doble - due diligence done well
Doble, a Company Director and Officer, was acquitted of charges of breaching Officer duties.
Due diligence is based on reasonableness in the circumstances, not perfection
Officers are not required to manage day-to-day operations
Officers can rely on competent managers and systems, where that reliance is reasonable
The burden of proof sits with the regulator to show what reasonable steps were not taken
What was done well
Competent people in place
Appropriate managers and WHS capability were established
Structured governance systems existed
Reporting lines, processes, and oversight mechanisms were in place
Reasonable reliance on others
The officer relied on qualified personnel and systems appropriately
No ignored warning signs (no “red flags”)
No evidence of known systemic failure or unaddressed risk
Proportionate level of oversight
The level of verification and involvement matched the context and risk.
Key lessons for Officers
You do not need to be an operational expert, but you must ensure capability exists
Reliance on others is acceptable, but must be informed and defensible
Due diligence requires structured systems and governance, not perfection
Your exposure increases significantly when:
risks are known but not acted on
warning signs are ignored
reliance becomes passive.
Bottom line
Officers meet their duty when they establish credible systems, appoint competent people, and rely on them reasonably
and there are no clear signals requiring further intervention.
Final reflection
This is not a case of an indifferent or disengaged executive. The Court accepted that:
significant effort had been invested in safety systems
the organisation had a structured safety framework.
Yet liability still arose.
The distinction is clear, due diligence is not about effort, it is about whether critical risks are effectively controlled and verified, and that cannot be done from a desk!




Comments