Business and Human Rights Rules: What Should Companies Prepare?

Business

Business and Human Rights Rules: What Should Companies Prepare?

Indonesia is developing a more structured system for assessing business compliance with human-rights principles. The new regulation is not yet final, but companies can already identify risks across workers, suppliers, workplace conditions, privacy, communities and grievance processes.

When the phrase Business and Human Rights appears, many companies may assume the issue belongs mainly to large corporations, extractive industries or businesses facing community disputes.

Its actual reach is much broader.

Human-rights questions can arise when a company hires outsourced workers, selects suppliers, installs CCTV, determines working hours, responds to complaints, acquires land, processes employee data or handles allegations of discrimination.

These activities are not peripheral to business.

They are everyday operations.

Indonesia is now moving toward a more structured framework for assessing how businesses manage those issues.

The government has authorised the preparation of a Presidential Regulation on assessing business compliance with human-rights principles. The Ministry of Human Rights aims to complete the draft during 2026.[2] As of the latest research for this article, however, it remains a draft rather than a newly enacted obligation.

That period before final regulation creates a useful question for management:

Do we actually know where human-rights risk appears inside our business?

Indonesia already has a policy foundation

Presidential Regulation No. 60/2023 established Indonesia's National Strategy on Business and Human Rights. Its framework addresses the state's responsibility to protect human rights in business activities, businesses' responsibility to respect them, and access to remedy for alleged adverse impacts.[1]

The structure broadly reflects the UN Guiding Principles on Business and Human Rights and their Protect, Respect and Remedy framework. UN Human Rights describes the corporate responsibility as avoiding infringement on the rights of others and addressing adverse impacts with which a business is involved.

Indonesia's emerging policy question is how those principles become a more systematic compliance assessment.

The Human Rights Minister has said the government aims to complete the new regulation in 2026, focus on socialisation in 2027 and move toward mandatory enforcement in 2028.[2]

That final date requires an important qualification.

It is a stated policy target, not a binding deadline businesses can already treat as enacted law.

The final regulation will determine scope, implementation phases and specific obligations.

Do not begin with “Are we violating human rights?”

The question is too broad and often produces a defensive response.

Start with business processes instead.

Who can be affected by our decisions?

Employees.

Contract workers.

Outsourced labour.

Suppliers.

Communities near facilities.

Customers.

People whose personal information the company processes.

Then ask:

What could go wrong for them?

That turns Business and Human Rights from an abstract concept into practical risk mapping.

The workforce is the closest starting point

The Indonesian government's PRISMA self-assessment tool demonstrates how operational these issues can become.

Its indicators include employment contracts, pay, overtime, social security, leave, occupational safety, freedom of association, discrimination, disability inclusion, privacy and grievance mechanisms.[4]

For HR, therefore, readiness is not simply about whether a written policy exists.

Management needs to know whether the policy works in practice.

Do actual working hours match the official system?

Do employees understand how to raise concerns?

Can people report problems without fear of retaliation?

Do internal rules disadvantage certain groups without legitimate grounds?

Human-rights readiness often begins with the gap between policy on paper and practice on the floor.

Suppliers are not outside the risk perimeter

Many companies maintain strong standards internally while knowing very little about how critical suppliers operate.

This is where due diligence becomes relevant.

PRISMA includes supply-chain indicators covering supplier-selection criteria, human-rights monitoring and outsourced workers.[4]

OECD guidance similarly notes that significant labour, human-rights and other impacts can occur in supply and value chains rather than only within a company's own operations.

That does not mean a company automatically becomes liable for every action taken by a third party.

It means that when a supplier is operationally important, understanding material risk becomes commercially sensible.

Procurement begins to look beyond:

price, quality and delivery.

It also asks:

How is this product or service being produced?

Due diligence does not mean being perfect everywhere

One concern surrounding new compliance requirements is that companies may face an endless checklist.

Risk-based due diligence works differently.

OECD guidance focuses on identifying significant impacts, prioritising them, taking prevention or mitigation measures, monitoring the response and communicating what has been done.

Risk profiles differ by business.

A factory employing thousands of workers faces different exposures from a 30-person software company.

A plantation has different land and community risks from a creative agency.

Maturity therefore does not mean having hundreds of procedures.

It means knowing which risks are material to the company's actual operating model.

A grievance mechanism is more than an email address

PRISMA also examines grievance mechanisms, including confidentiality, reporting processes, resolution, communication to employees and supply-chain partners, and protection against retaliation.[4]

A company may have a complaint@company.com address.

That alone does not create an effective mechanism.

Do employees know it exists?

Can suppliers use it?

Who reads complaints?

How quickly are they assessed?

How are conflicts of interest handled?

Can a complainant face retaliation from a manager?

An effective grievance process can work as an early-warning system.

Problems discovered early are often easier to manage than issues first discovered through social media, a regulator or litigation.

PRISMA can be used before the next regulation arrives

The Ministry of Human Rights already provides PRISMA as a self-assessment tool intended for businesses across sectors and company sizes. It helps organisations identify potential risks, prepare follow-up actions, monitor implementation and communicate the process.[4]

The ministry also issued a 2025 circular on business-and-human-rights compliance assessment through PRISMA.[6]

Businesses therefore do not need to wait for the new Presidential Regulation to start identifying gaps.

PRISMA should not, however, be treated as automatic proof that every legal obligation has been fulfilled.

It is a readiness and assessment tool, not a substitute for legal analysis.

Five areas businesses can review now

GATICORP suggests beginning with five practical lenses.

People: Who can be affected by the company?

Workplace: How are safety, discrimination, working conditions and privacy managed?

Suppliers: Which third parties could create significant people-related or operational risk?

Community: Can business activity affect land, health, the environment or surrounding communities?

Remedy: If harm occurs, is there a credible way to raise a complaint and pursue resolution?

This is an editorial framework, not an official legal standard.

Compliance cannot sit entirely inside HR

HR owns many workforce issues.

Procurement manages suppliers.

Operations controls working conditions.

Legal manages contractual exposure.

Security may operate CCTV.

IT handles data.

Senior management shapes incentives and culture.

Business and Human Rights is therefore a cross-functional risk issue.

If it is treated entirely as an HR programme, risks beyond the employment relationship may remain invisible.

What can companies do before the final rules?

Start with inventory rather than a new department.

List existing policies.

Map higher-risk processes.

Review critical suppliers.

Test grievance channels.

Document incidents and corrective action.

Compare current practices against PRISMA indicators.

Then identify genuinely material gaps.

When final rules arrive, a company that already understands its risk profile will be better positioned to adjust than one beginning its data collection after compliance becomes mandatory.

From reputation to operating discipline

Business and Human Rights has often been grouped with CSR or sustainability.

Indonesia's emerging regulatory direction suggests that is becoming too narrow.

The issue reaches into employment, facilities, supplier selection, complaints, personal information and community relationships.

In other words, it is increasingly an issue of operating discipline.

Indonesia's proposed compliance regulation is not yet final, and important implementation details remain unknown.

Companies do not need to invent obligations that do not yet exist.

But they also do not need to wait before doing something that already makes business sense:

know who can be affected by the business, understand the most material risks, and build credible mechanisms to prevent and address problems before they become larger ones.

Sources:

  • [1] Pemerintah Republik Indonesia / BPK JDIH. Peraturan Presiden Nomor 60 Tahun 2023 tentang Strategi Nasional Bisnis dan Hak Asasi Manusia. 26 September 2023.
  • [2] Kementerian Hak Asasi Manusia RI. Presiden RI Setuju Penyusunan Perpres Penilaian Kepatuhan Pelaku Usaha terhadap Bisnis dan HAM. 18 February 2026.
  • [3] Kementerian Hak Asasi Manusia RI. Matangkan RPerpres, Kementerian HAM Gandeng Media Dorong Edukasi Praktik Bisnis yang Hormati HAM. 3 June 2026.
  • [4] Kementerian Hak Asasi Manusia RI — PRISMA. Penilaian Risiko Bisnis dan HAM.
  • [5] OECD. OECD Responsible Business Outlook 2026 dan Due Diligence for Responsible Business Conduct. June 2026/current guidance.
  • [6] Kementerian HAM RI. Surat Edaran Menteri HAM No. M.HA-01.HA.03.02 Tahun 2025 mengenai penilaian kepatuhan melalui PRISMA.

Published: August 12, 2026

Source and editorial notes are managed through GATICORP CMS.