What Employers Should Do Now
Employer duty of care now extends beyond colleague behaviour to include harassment, abuse, and threatening behaviour from customers, clients, patients, contractors, and members of the public.
This has significant implications for public-facing roles in sectors such as retail, hospitality, healthcare, housing, social care, enforcement, and field-based work.
Employers must now assess foreseeable third-party risks and conduct specific risk assessments that consider:
The nature of public interaction
Lone working and remote working
Out-of-hours shifts
High-risk locations or environments
Limited supervision or poor connectivity
Risk assessments should be role-specific, regularly reviewed, and updated following any incident, near-miss, or change in working conditions.
Have you conducted a specific risk assessment for harassment from non-employees?
Does your risk assessment account for lone working, late-night shifts, or high-risk locations?
Policies must clearly set out how the organisation protects workers in real-world situations - not just in theory.
Employers should explicitly state that harassment, abuse, and threatening behaviour towards staff will not be tolerated.
This expectation should be:
Written into company policy and employee handbooks
Communicated to clients, service users, and contractors
Supported by visible zero-tolerance signage in public-facing locations
Contracts and service agreements should include clauses allowing:
Staff to be withdrawn from unsafe situations
Work to be suspended if harassment occurs
Contracts to be terminated where behaviour breaches agreed standards
Employees must also be explicitly empowered to withdraw from threatening situations without fear of disciplinary action.
Are staff empowered in writing to withdraw from threatening situations?
Is the “Right to Disengage” documented?
Is zero-tolerance signage in place?
Have behavioural expectations been communicated externally?
Compliance is not only about systems - it is about behaviour, awareness, and competence.
Employers should provide tailored training that reflects the risks employees face in their specific roles, including:
De-escalation training
Helps staff recognise early warning signs, manage conflict safely, and prevent incidents from escalating.
Bystander intervention training
Equips colleagues to safely support others who may be experiencing harassment or threatening behaviour.
Manager training
Ensures managers understand how to respond appropriately to reports, follow internal procedures, support affected staff, and update risk controls.
Training should be refreshed regularly and documented as part of the organisation’s compliance record.
Have staff received de-escalation or bystander training in the last 12 months?
Are managers trained to handle third-party harassment reports?
Employers must provide employees with multiple, secure routes to report incidents, concerns, or near-misses.
These may include:
Direct reporting to managers
Confidential internal reporting channels
Anonymous digital reporting tools
24/7 support services
All reported incidents should be:
Formally recorded
Time and date stamped
Reviewed promptly
Linked to updated risk assessments or control measures
Where appropriate, responses may include:
Updating risk assessments
Adjusting working practices
Withdrawing staff from unsafe situations
Suspending or terminating contracts with third parties
Clear records are essential to demonstrate that risks were identified, addressed, and managed appropriately.
Can you provide a documented audit trail after incidents or near-misses?
Is there a formal process for updating risk assessments?