Key findings
- The reforms scheduled for 30 October 2026 strengthen the preventative duty relating to sexual harassment to one of taking “all reasonable steps” and introduce provisions on third-party harassment. The legal routes are distinct, so employers should build a coherent prevention system without assuming every form of harassment is assessed under an iden
- For public-facing employers, the central practical issue is controllability around an interaction. They cannot direct every customer, client or visitor, but they can determine staffing, lone-working safeguards, employee authority, escalation routes, access restrictions and commercial consequences.
- Policies and training remain necessary, but completion rates are not evidence that exposure has been controlled. The evidence suggests training can improve knowledge and transfer outcomes, while its effectiveness depends on design and organisational context (Roehling and Huang, 2018) [[roehling2018]]; (Roehling et al., 2022) [[roehling2022]].
- A proportionate approach for SMEs is an interface-based control cycle: identify high-exposure interactions, give staff usable authority, equip managers to respond, and use incident patterns to redesign work or intervene with repeat third parties.
- October should be treated as the start of ongoing risk management, not a one-off policy-refresh deadline. Employers should monitor the implementation timetable and any further supporting detail (GOV.UK, 2026) [[dbt2026timeline]].
The reform changes the management question
The Employment Rights Act 2025 changes scheduled for 30 October 2026 are easily reduced to an HR compliance task. That framing misses the operational issue. For employers whose people deal with customers, clients, visitors or online users, the question is whether work is organised so that foreseeable harassment can be prevented, interrupted and reported.
The Government’s implementation timetable identifies 30 October 2026 as the intended commencement date for a strengthened duty to take “all reasonable steps” to prevent sexual harassment, alongside third-party harassment provisions. The timetable and supporting material should continue to be monitored, because implementation detail can develop further (GOV.UK, 2026) ↗. The explanatory notes distinguish the strengthened sexual-harassment duty from the third-party provisions, which engage the wider Equality Act harassment framework (legislation.gov.uk, 2025) ↗. That legal distinction matters. A single practical prevention system is sensible, but it should not rest on the assumption that every form of harassment has the same legal test.
The significant point is the work interface: where an employee encounters a customer, client, visitor, supplier, contractor or online user. A retail worker serving a regular customer, a care worker visiting a client’s home, a junior consultant attending a client event and a technician working at a customer site face materially different conditions. In none of these examples does the employer control the third party directly. It may, however, control much of the environment around the encounter: whether the employee works alone, whether help is available, whether service can be paused, how standards are communicated, and whether access or commercial consequences can follow.
That makes the reform a management-capability issue as well as a legal one. Smaller businesses can be particularly exposed. A small high-street firm or local service business may depend heavily on a handful of experienced people and a limited number of valuable customer relationships. If staff conclude that a commercially important customer will be protected at their expense, the loss is not confined to an individual incident: confidence, retention and operational capability may all deteriorate.
Sanctuary’s view is that third-party harassment should be managed as an operational risk with shared ownership. HR can lead policy, reporting and case capability, but site leaders, account managers, customer operations and procurement often hold the practical levers that determine whether prevention works.
Why policy and training do not control exposure on their own
A dignity-at-work policy, accessible reporting routes and competent investigations remain essential. They set expectations and create a route after something has gone wrong. But they are not equivalent to controls that change the conditions in which foreseeable risk arises.
The Equality and Human Rights Commission’s technical guidance places risk assessment at the centre of prevention and indicates that an employer is unlikely to meet the preventative-duty requirement without one. It also treats an employer’s response after an incident as relevant evidence of whether policies are being implemented in practice rather than merely held on paper (Equality and Human Rights Commission, n.d.) ↗. The implication is not that every employer needs a large compliance infrastructure. It is that the employer needs to identify its most foreseeable exposures and match them with workable action.
The training evidence reinforces this distinction. Roehling and Huang’s interdisciplinary review identified limitations in the sexual-harassment training evidence base and called for stronger research into when, how and for whom training works (Roehling and Huang, 2018) ↗. A later meta-analysis found positive effects on proximal and transfer outcomes (Roehling et al., 2022) ↗. This is a case for better-designed training, not for treating a generic annual module as proof that work has become safer.
The mechanism is straightforward. Training may help an employee recognise misconduct, understand the organisation’s standard and apply learning. It cannot, by itself, give a lone worker authority to leave a property, a receptionist permission to end an interaction, or a manager the organisational backing to restrict a commercially important client. Knowledge without decision rights can leave employees better able to identify a problem but no more able to stop it.
Compare two statements. “We do not tolerate harassment” is an important organisational norm. “If a customer makes sexualised comments, staff may pause or end service, seek support, record the incident and trigger a manager review of access or contact restrictions” is an operational control. The second statement allocates authority, specifies action and creates the conditions for a consistent response.
There is a real trade-off. Highly detailed procedures can become unusable in a small team or during a fast-moving incident. Too much discretion, however, can leave workers to negotiate difficult behaviour alone and lead to inconsistent treatment of repeat offenders. The proportionate answer is a small number of clear red lines, immediate safety options, reliable escalation and visible management backing when staff exercise reasonable judgement.
The useful unit of prevention is the interface, not the job title
A receptionist, delivery driver and field engineer may all be labelled customer-facing, but their exposure is not comparable. A daytime reception desk with colleagues nearby presents different risks from a lone evening visit, an abusive online interaction or work on a client-controlled site. Grouping all these roles together produces generic controls precisely where tailored arrangements are needed.
Sanctuary recommends an interface-based control cycle. This is a practical management framework, not a substitute for legal advice on an employer’s particular circumstances.
**1. Map exposure where it occurs.** Identify interactions with customers, clients, visitors, suppliers, contractors, residents and online users. Consider location, time of day, lone working, alcohol, power imbalances, previous concerns, language needs, digital moderation and whether another organisation controls the premises. Review complaints, grievances, exit feedback and local manager intelligence, but do not rely exclusively on formal reports. Low reporting can reflect low confidence as well as low risk.
**2. Define staff authority before an incident.** Decide what employees may do without seeking permission: pause a meeting, end a call, request a colleague, transfer service, leave an unsafe location or contact a manager. For higher-risk work, practical safeguards may include buddying, check-ins, alternative meeting formats or a requirement not to enter a location alone. The test is whether the arrangement can be used under pressure, rather than whether it looks comprehensive in a policy.
**3. Set a manager response standard.** The first managerial response affects whether employees report again. Managers need a short, rehearsed sequence: address immediate safety and welfare; receive the account without blame; preserve relevant information; decide whether service, contact or access should be restricted; explain the next steps; and consider repeat contact or retaliation. For an SME, this may be a two-page playbook and an out-of-hours escalation contact rather than specialist case-management software.
**4. Use organisational levers and learn from recurrence.** Record the channel, location, third-party relationship, broad nature of the concern, action taken and whether it recurs. The purpose is not to accumulate sensitive information for its own sake. It is to identify a repeat individual, a problematic site, an unsafe event format, a shift pattern or a client relationship requiring intervention. Where people work at client premises or through outsourced arrangements, contracts and account plans should clarify who can investigate, exclude a third party, change work arrangements and protect the employee while concerns are addressed.
This approach reflects the EHRC emphasis on risk assessment and meaningful implementation (Equality and Human Rights Commission, n.d.) ↗. It also provides a more useful record than policy acknowledgements alone: an employer can show what risks it identified, what authority it gave staff, how it responded and what it changed when patterns emerged.
Proportionate preparation means concentrating on controllable conditions
The Government’s August 2026 Employer Bulletin advised employers to prepare for the October changes, including the strengthened sexual-harassment duty and third-party harassment provisions (GOV.UK, 2026) ↗. Preparation does not require an SME to replicate the infrastructure of a large employer. It does require the business to be able to explain—and, where appropriate, evidence—how it has addressed the interactions in which exposure is most foreseeable.
A useful implementation review asks four questions.
**Where is risk concentrated?** Identify the limited number of settings where exposure is most likely. For hospitality, this may mean late-night service or particular events; for professional services, client entertainment and travel; for trades businesses, lone visits to customer premises. Starting with these interfaces is likely to be more valuable than immediately rewriting every policy.
**Can staff act in the moment?** Test the actual position of an evening-shift worker, an agency worker, a lone field employee and a colleague at a client site. Can they obtain help quickly? Can they pause service without performance consequences? Is there a route to leave an unsafe setting? A control that only works during office hours is not a complete control for a seven-day operation.
**Can the organisation act on the third party?** Identify who can issue a warning, refuse service, restrict access, reassign an account, change meeting arrangements or end a commercial relationship. Decisions are often delayed because authority is unclear, particularly when the third party is financially significant. Pre-agreed escalation prevents a frontline employee from being left to make a commercial decision alone.
**Can leaders tell whether controls are working?** Review incident and near-miss patterns regularly. Report volume alone is a weak indicator: it may rise because confidence to report has improved. More informative measures include response times, repeat exposure, follow-through on promised action, manager escalations, and changes made to sites, services or client arrangements.
A reasonable counterargument is that no employer can control the public. That is correct. Prevention is not a guarantee that misconduct will never occur. The relevant issue is what the employer can control around the interaction: staffing, information, supervision, reporting, access and response. The explanatory notes also contemplate regulations specifying steps relevant to reasonableness, which strengthens the case for an adaptable system rather than a static compliance pack (legislation.gov.uk, 2025) ↗.
The commercial case should be stated with care. National labour-market data cannot establish the cost of turnover or poor retention in an individual business. However, the UK employment rate was 75.1% and unemployment was 4.9% for May to July 2026, subject to the ONS’s advice on current Labour Force Survey quality information (Office for National Statistics, 2026) ↗. For businesses dependent on experienced frontline staff, preventable loss of capability is therefore a practical concern alongside the legal and human case.
The leadership test is whether dignity is credible at the point of service
The October 2026 changes are a near-term legal milestone. Their broader value is that they bring a recurring management choice into view: whether harassment by outsiders is treated as an unavoidable feature of public-facing work, or as a foreseeable risk that the organisation is expected to manage.
Owners, boards and senior teams should test their position against three questions. Where are people most predictably exposed to third-party conduct? What authority do workers and managers have when behaviour crosses a line, including when commercial pressure is high? What evidence will show, six months later, that the organisation identified patterns and improved conditions of work?
The strongest response will not be the longest policy or the highest training-completion rate. It will be one in which employees understand the boundaries, managers can act quickly, account owners accept the consequences of enforcing standards, and leaders use incident information to improve operations. For SMEs, proportionate preparation means directing scarce management capacity at real points of exposure rather than building a compliance architecture that nobody can sustain.
October should therefore mark the beginning of a control cycle, not the end of a documentation exercise. Policy and training matter. They become credible when connected to staff authority, escalation, commercial consequences and organisational learning.
Research foundation
References
- Department for Business and Trade (2026). Plan to Make Work Pay and Employment Rights Act: timeline update. GOV.UK.Source ↗
- The National Archives (2025). Employment Rights Act 2025: Explanatory Notes, protection from harassment. legislation.gov.uk, Sections 20–21; explanatory notes paragraphs 593–609.Source ↗
- Equality and Human Rights Commission. Sexual harassment and harassment at work: technical guidance. Equality and Human Rights Commission.Source ↗
- Mark V. Roehling; Jennifer Huang (2018). Sexual harassment training effectiveness: An interdisciplinary review and call for research. Journal of Organizational Behavior, 39, 134–150.Source ↗DOI: 10.1002/job.2257
- Mark V. Roehling; Dan Wu; Min G. Choi; James H. Dulebohn (2022). The effects of sexual harassment training on proximal and transfer training outcomes: A meta-analytic investigation. Personnel Psychology, 75, 3–31.Source ↗DOI: 10.1111/peps.12492
- HM Revenue and Customs (2026). August 2026 issue of the Employer Bulletin. GOV.UK.Source ↗
- Office for National Statistics (2026). Labour market overview, UK: September 2026. Office for National Statistics.Source ↗
- USDAgov. Hero image: SNAP Employment and Training at Cafe Reconcile in New Orleans (20230216-FNS-CDP-0306).jpg. Wikimedia Commons · Public domain.Image source ↗
Related Sanctuary capabilities
From analysis to implementation.
Discussion

No approved comments yet.