Key findings

  • The Employment Rights Act 2025 raises the preventative sexual-harassment standard to “all reasonable steps” and creates a direct prohibition on employers permitting third-party harassment where they have not taken those steps.
  • The most consequential risks often sit at worker–third-party interfaces: customer transactions, client sites, home visits, events, calls and online channels. Those settings require controls tailored to how work is actually done.
  • Policies and training remain necessary but are weak standalone controls. EHRC guidance calls for anticipatory risk management and learning from reports, while the evidence for bystander programmes supports active practice but remains methodologically limited.
  • A proportionate interface-control model can help SMEs and larger employers prioritise exposure, give managers authority to act, set external boundaries and show that incident data leads to operational change.

The October change is a test of operating practice, not policy ownership

The central question for employers is no longer whether they can point to a harassment policy. It is whether they can show that foreseeable risks have been identified and controlled in the places where workers encounter them.

**What the evidence establishes.** From **30 October 2026**, the Employment Rights Act 2025 strengthens the preventative duty relating to sexual harassment: employers must take **all reasonable steps** to prevent it. On the same date, the Act introduces a prohibition on employers permitting third-party harassment in the course of employment where they have failed to take all reasonable steps to prevent it. It also gives ministers power to specify steps that may be treated as reasonable, including risk assessments, policies, reporting arrangements and complaint handling (Employment Rights Act 2025, ss. 21–22) .

Third parties are not a narrow category. Acas identifies customers, clients, service users, contractors, conference attendees and members of the public, and notes that harassment can arise online as well as face to face (Acas, 2026) . The existing preventative duty already requires an anticipatory approach: EHRC technical guidance says employers should consider where harassment may occur, assess the risk and act before receiving a complaint .

**Sanctuary analysis.** “All reasonable steps” is not a demand for a guaranteed harm-free workplace, nor does it prescribe one identical control set for every employer. It does, however, make a purely reactive model increasingly difficult to defend. An organisation that investigates after an incident but has not considered predictable conditions of exposure — lone work, late shifts, client hospitality, direct messages or home visits — has a weak account of prevention.

That shifts responsibility beyond HR. HR may own the policy framework, reporting routes and capability strategy, but operations determines staffing and escalation; commercial teams set client and customer expectations; procurement can influence supplier terms; digital teams shape moderation and evidence capture; and line managers decide what happens in the moment. The legal change therefore exposes a practical governance question: do these functions collectively protect workers, or are employees expected to absorb abuse as an unavoidable feature of customer-facing work?

This matters particularly for SMEs, high-street businesses and growing firms, where the owner-manager, supervisor and customer relationship may be closely intertwined. A small employer does not need a large-company compliance programme. It does need a credible way to identify its highest-risk interactions, make boundaries clear and support staff to act when those boundaries are crossed.

The worker–third-party interface is the useful unit of risk analysis

A generic entry for “harassment” on a corporate risk register is rarely enough. It may signal that leaders recognise the issue, but it does not identify the point at which risk arises or the control most likely to reduce it.

**Sanctuary analysis.** The more useful unit of analysis is the **interface**: a defined setting in which a worker interacts with someone outside the employer. A retailer may have materially different risks at a checkout, during a delivery, on a late closing shift and through social-media messages. A professional-services business may need different protections for client hospitality, travel, site work and video calls. For organisations working in care, education or health settings, the risks may differ between service users, relatives, visitors and contractors.

This distinction matters because prevention works through the conditions of an interaction. At one interface, a clear customer conduct notice and rapid manager support may be sufficient. At another, the necessary controls may include two-person visits, an authority to leave a client site, a named escalation contact, evidence-preservation arrangements or a customer exclusion process. Acas’s guidance points to this breadth, including risk assessments, incident records, relevant policies, training, terms and conditions, clear consequences for customers, and — where appropriate — staffing, security or safety equipment (Acas, 2026) .

The mechanism is straightforward. A policy describes expected conduct; an interface control changes the environment in which conduct occurs. If a worker cannot contact a manager, end an unsafe interaction or expect a client relationship to be challenged, the policy leaves the burden of prevention with the person exposed to harm. Conversely, controls that alter access, supervision, authority and consequences give workers practical options before an incident escalates.

**A necessary trade-off.** Employers should resist turning proportionality into a defence for inaction. EHRC guidance makes clear that reasonable steps depend on context, including the employer’s size and resources, but no employer is exempt from the duty to take preventative action . For a microbusiness, the answer may be a short exposure map, a simple reporting route and clear rules on refusing service. For a multi-site employer, it may require differentiated controls by location, shift and worker group. The principle is the same: simpler should mean prioritised, not superficial.

Why training and low complaint volumes are unreliable proxies for prevention

Policies, reporting routes and training are important foundations. They are not, by themselves, evidence that prevention is working.

**What the evidence establishes.** The EHRC’s employer checklist recommends using both formal and informal complaint information, anonymous workforce feedback and lessons-learned activity. It also calls for policies, procedures and training to be reviewed with worker input (EHRC, 2024) . This is a more demanding proposition than recording course-completion rates: it asks employers to test whether workers experience the arrangements as usable and credible.

The evidence on workplace bystander interventions supports practical learning but should not be oversold. Nielsen and colleagues’ scoping review found a small and uneven evidence base. Practice-based workshops appeared more promising for prosocial bystander behaviour than passive awareness approaches, and leadership support was an important facilitator. Yet many studies had no follow-up, organisational outcomes were often poorly measured, and the review could not determine which programme designs produce durable effects (Nielsen et al., 2025) .

**Sanctuary analysis.** The implication is not that training should be abandoned. It is that training should be designed around decisions people can actually make: how to interrupt safely, obtain support, create distance, document an incident and escalate without retaliation. Managers need additional rehearsal: when they can end a customer interaction, remove a worker from a site, challenge a client or involve security.

Incident counts require similar care. A rise in reports after clearer communication or better manager practice may indicate greater trust and visibility, rather than more underlying harassment. A low number of formal complaints may reflect safety, but it may also reflect silence, fear or resignation. That is why the EHRC’s emphasis on comparing reporting data with worker feedback is valuable .

The more useful management question is not “have reports fallen?” in isolation. It is whether the employer can identify repeated patterns at particular interfaces, protect people promptly, and change the conditions that allowed those patterns to recur. A dashboard that rewards zero reports can inadvertently discourage the very reporting that makes prevention possible.

A proportionate interface-control model

**Sanctuary recommendation.** Employers should approach the period before 30 October as an implementation programme, not a document-refresh exercise. The following model is deliberately scalable: a small business can apply it to its handful of highest-exposure situations, while a larger employer can use it across sites, services and worker groups.

**1. Map exposure as well as incidents.** Identify every material third-party interface: premises, client sites, homes, travel, events, calls, messaging platforms and social channels. Then identify amplifiers of risk, such as lone work, out-of-hours activity, time pressure, weak managerial access or a pronounced power imbalance. Invite workers, including agency staff and those in less visible roles, to challenge the map through short workshops or anonymous feedback.

**2. Define controls for each priority interface.** For every high-priority interaction, specify three things: what prevents harm, what happens during an incident and what happens afterwards. A late-shift shop-floor interaction might require visible behavioural expectations, immediate supervisor support, authority to refuse service and a follow-up process. A client-site visit might require a contractual standard, a named client escalation route and permission to withdraw. Digital channels may require clear moderation ownership, evidence capture and response-time expectations. Acas specifically identifies contractual and transaction-level conditions as potential preventative controls (Acas, 2026) .

**3. Give managers decision rights, not just awareness.** Written guidance should tell managers who can end an interaction, who contacts a client, how a worker is protected while a concern is assessed, what needs recording and how retaliation or informal disadvantage will be prevented. Scenario practice is more valuable than abstract reminders because it exposes conflicting pressures: an upset customer, a valuable account, a staffing shortage or an employee who is unsure whether their experience will be taken seriously.

**4. Align commercial arrangements with worker safety.** Review customer terms, venue notices, booking conditions, supplier clauses, client onboarding and account-management processes. This is where a stated commitment is tested. If an account manager has no route to challenge a client, or a branch manager fears losing revenue by barring an abusive customer, the organisation has designed incentives against prevention. Clear external expectations make later action more credible and reduce the likelihood that staff are asked to negotiate safety alone.

**5. Create a learning record, not a surveillance system.** Record the interface, context, immediate protection, response time, outcome and resulting control change using only information needed to manage risk. Review patterns with an appropriately senior owner and worker representation. The aim is an evidence trail showing that risks were identified, options considered, measures implemented and their effectiveness revisited — alongside a system that workers can trust to handle concerns with care.

What credible readiness looks like on 30 October

Readiness should be judged by operational answers, not by the date on a revised policy. A prepared employer should be able to answer five questions quickly:

- Which worker–third-party interfaces present the most foreseeable risk?

- What preventive, in-the-moment and post-incident controls operate at each of them, and who owns those controls?

- Can a worker obtain immediate support and safely leave an interaction where necessary?

- What are the consequences for a customer, client or other third party when a concern is substantiated?

- How will leaders know whether reporting is trusted, controls are used and weaknesses are being corrected?

**Sanctuary judgement.** There is a temptation to treat launch as completion. The Government’s economic analysis anticipates that employment-rights reforms will require monitoring and evaluation because effects will emerge over time and vary between measures (Department for Business and Trade, 2026) . Employers should apply the same discipline internally. The first months after implementation should be used to test whether controls work under normal commercial pressure, rather than to declare success from training completion or complaint totals.

The October reforms make the architecture of everyday work more visible: who is present, who has authority, whether a worker can exit, whether concerns are believed, and whether commercial priorities override safety. Organisations that treat those design choices as part of harassment prevention will be better placed to meet the strengthened standard. Those that rely chiefly on policy publication and post-incident investigation will have addressed the language of prevention without yet building its operating reality.

Sanctuary interface-control model for third-party harassment preventionOriginal Sanctuary conceptual framework. It translates statutory expectations and regulator guidance into an implementation sequence; it does not present numerical evidence.
Map worker–third-party interfaces
Assess foreseeable situational risk
Design proportionate preventive and immediate-response controls
Equip managers and workers through scenario practice
Record, review and improve controls with worker input

Research foundation

References

  1. Acas (2026). Third party harassment - Harassment law changes. Advisory, Conciliation and Arbitration Service (Acas).
    Source ↗
  2. Equality and Human Rights Commission (2020). Sexual harassment and harassment at work: technical guidance. Equality and Human Rights Commission.
    Source ↗
  3. Equality and Human Rights Commission (2024). Preventing sexual harassment at work: checklist and action plan for employers. Equality and Human Rights Commission.
    Source ↗
  4. UK Parliament (2025). Employment Rights Act 2025. UK Public General Acts.
    Source ↗
  5. Kristan Stampe Nielsen; Maj Hansen; Eva Gemzøe Mikkelsen (2025). Bystander interventions against gender-based violence and harassment in the workplace: a scoping review. Frontiers in Psychology, 16, 1570812.
    Source ↗DOI: 10.3389/fpsyg.2025.1570812
  6. Department for Business and Trade (2026). Employment Rights Act 2025: economic analysis. UK Government.
    Source ↗
  7. Sanctuary Consulting & Development Group. Hero image: administrator-supplied photograph. Owner supplied / permission confirmed.
    Image source ↗

Discussion

Challenge the analysis.

No approved comments yet.