Sevron COSHH compliance software - Safety platform for risk assessments and data sheets
CONTACT USSIGN IN
GET STARTED FREE
Chemical ManagementHealth & Safety SoftwareImplementation ServicesLearning

By Role

Small Business OwnerSafety OfficerManufacturerMulti-Site DirectorSafety Consultant

By Industry

ManufacturingConstruction & EngineeringFuel & EnergyTechnologyHealthcareProfessional Services
Safety365 Subscription ProposalSmall Business BundleSevron BlogsUltimate COSHH Guide (PDF)Accelerated Compliance Brochure (PDF)COSHH GuideCOSHH Mock InspectionCOSHH Risk Assessment AuditBetaAll Resources
Our StorySuccess StoriesPartnersCertificationsAccelerated Compliance
CONTACT USSIGN IN
GET STARTED FREE
Safety 365
Accelerated Compliance
BOOK A DEMO
Chemical Management Software
Health & Safety Software
Implementation Services
Learning
COSHH AssessmentsRisk Assessments optimised for COSHH complianceFree and paid plans
COSHH Assessment SummaryEssential COSHH Assessment info in one clear summaryFree and paid plans
The 5-Step Risk Assessment WizardThe world's first AI-powered Risk Assessment solutionFree and paid plans
Safety Data Sheet SolutionsAccess to millions of SDS, a centralised inventory, SVHC monitoring, etc.Free and paid plans
SDS SearchFind your SDS from the UK's largest SDS databaseFree and paid plans
SDS DistributionDistribute safety data sheets to your teams and stakeholdersFree and paid plans
SDS ManagementStore, organise, and manage your SDS inventory in one placeFree and paid plans
Contact salesSee all features
Safety 365
Accelerated Compliance
BOOK A DEMO

Solutions by Role

Small Business OwnerOwner-led operations
Safety OfficerWorkplace safety leads
ManufacturerManufacturing operators
Multi-Site DirectorEnterprise executives
Safety ConsultantSafety advisor for clients

Solutions by Industry

ManufacturingFactory & production
Construction & EngineeringBuild & infrastructure
Fuel & EnergyOil, power, utilities
TechnologyTech & assembly firms
HealthcareMedical & care facilities
Professional ServicesField-based services
Contact salesSee all use cases
Safety 365
Accelerated Compliance
BOOK A DEMO
Safety365 Subscription Proposal
Enterprise pricing plans & feature breakdownsSubmit request
Small Business Bundle
Free Safety365 account for sole traders and micro-businessesRequest free account
The Accelerated Compliance Software Demo
Watch the Safety365 demo on demand — SDS management, COSHH risk assessments, and audit readiness. Free access.Watch the demo
Sevron Blogs
Insights on compliance, COSHH, safety culture, and moreNews & articles
Ultimate Guide to COSHH Compliance
Free PDF: COSHH compliance strategy, risk assessment, and UK HSE contextFree PDF download
Sevron Development Roadmap
Our product development pipeline and upcoming featuresFile download
COSHH Management Mock Inspection
16 HSE-style questions to score your COSHH compliance in 5 minutesStart mock inspection
SPOT AI COSHH Risk Assessment AuditBeta
AI-powered audit tool for your COSHH risk assessment complianceTry SPOT AI
The Complete COSHH Guide
Everything you need to know about COSHH compliance in the UKRead the guide
Sevron Accelerated Compliance Brochure
Overview of Safety365 features, benefits and client outcomesFree PDF download
Contact salesAccess all resources
Our StoryAbout Sevron
Success StoriesCustomer outcomes
PartnersPartner ecosystem
CertificationsISO & compliance
Accelerated ComplianceCertified, Competent, Compliant
A nurse confronted by a patient, and a colleague with a hand on a woman's shoulder, in front of a newspaper on the new employer duty against third-party harassment from 30 October 2026.

From 30 October, Your Harassment Duty Covers People You Do Not Employ

The colorful circular brand icon for Sevron, a leading provider of COSHH risk assessment and health and safety compliance software.BLOG

Sevron provides industry-leading software solutions to simplify health, safety, and COSHH compliance.

Home/Resources/Blog/From 30 October, Your Harassment Duty Covers People You Do Not Employ

The controls that actually decide this risk are lone working, shift patterns, site access and who is allowed to escalate a complaint. Almost none of them sit with HR.

UPDATED SEP 24 2026·12 MIN READ
Reviewed by
Dale Allen
Dale Allen

Key Points

  • The duty is new and it is broad: From 30 October the Employment Rights Act 2025 makes an employer liable where an employee is harassed by a third party and the employer failed to take all reasonable steps to prevent it.
  • It is not limited to sexual harassment: The third-party duty covers harassment related to protected characteristics under the Equality Act 2010, including race, disability, religion or belief, sex and sexual orientation.
  • One incident is enough: There is no requirement to show a pattern or prior warnings before the protection applies.
  • The controls are operational: Lone working, shift patterns, site layout, event planning and escalation routes decide this risk far more than a policy document does.
  • Evidence is the defence: With regulations on all reasonable steps not expected until 2027 at the earliest, tribunals will judge employers on what they identified, what they changed and when they last reviewed it.

Your harassment policy almost certainly covers colleagues. Someone behaves badly, it gets reported, it gets investigated, and there is a disciplinary process at the end of it with real consequences.

Now picture the same complaint where the person who made the remark does not work for you. A customer. A patient. A delivery driver. A client whose account pays several salaries.

Every tool in that process has just disappeared. You cannot investigate them, you cannot discipline them, and in many cases you will never identify them. From 30 October you can still be held liable for what they did.

What actually changes on 30 October

The Employment Rights Act 2025 inserts a new provision into section 40 of the Equality Act 2010. An employer must not permit a third party to harass an employee, and the statute defines permitting narrowly. An employer permits it where the harassment happens in the course of the person's employment and the employer failed to take all reasonable steps to prevent it.

A third party means anyone other than the employer or a fellow employee. Customers, clients, patients, service users, contractors, suppliers, passengers, residents and members of the public all sit inside that definition, as Acas guidance for employers sets out.

Three details in the drafting matter more than the headline. The duty is not confined to sexual harassment, and reaches harassment related to protected characteristics generally. A customer making racist remarks to a member of your team engages it. So does a client mocking someone's disability, or a resident abusing a care worker over their religion. There is no requirement for previous incidents, so a single occasion engages it. And it creates a claim an employee can bring on its own, which is the part that does not exist today.

Two changes, often confused

Two things happen on 30 October and they are frequently reported as one. The existing duty to prevent sexual harassment, in force since October 2024, rises from taking reasonable steps to taking all reasonable steps. Separately, the new third-party duty arrives and covers harassment across protected characteristics. The first is a higher bar on something you already do. The second is a new liability covering people you do not employ. An organisation that only updates its sexual harassment position will have addressed half of what lands that day.

The harasser is someone you cannot discipline

This is the part that makes third-party harassment awkward in a way colleague harassment is not.

Internal cases follow a path everyone knows. Investigation, findings, sanction. When the person responsible is a customer or a client, the path stops at the first step. There is nobody to interview, no contract to enforce and no disciplinary outcome. The organisation has to control the risk by changing its own arrangements instead, because the only behaviour it can change is its own.

Then there is the commercial pressure sitting underneath it.

A supervisor catches you between meetings. One of her team has been on the receiving end of comments from a client's project manager, the kind that get called banter afterwards. It has happened three times. The third time he put a hand on her back while he said it.

The client is a name on your website. Your supervisor is not asking you to solve it. She is telling you because she does not know whether raising it formally is going to cost the account, and she does not know whether that is hers to decide.

What happens next in your organisation? If the answer depends on which manager she happened to tell, the arrangement is the risk.

Where the risk actually sits

The Equality and Human Rights Commission (EHRC) enforces the Equality Act 2010, and its technical guidance on harassment at work points employers toward a consistent set of conditions where third-party harassment concentrates.

  • Customer-facing roles: retail floors, hospitality, reception, healthcare, call centres and anywhere staff cannot walk away from an interaction
  • Lone working and home visits: care workers, engineers, delivery drivers and anyone attending a property alone
  • Power imbalance: situations where the third party has commercial power over you, including key clients, funders and regulators
  • Alcohol: licensed premises, corporate hospitality, client entertaining and staff events
  • Unsociable hours: late shifts, night work, opening and closing, and travel involving overnight stays
  • Off-site and digital contact: client premises, conferences, networking events, and interactions over messaging platforms and video calls

Sector shapes which of those bite hardest. Retail and hospitality carry frequent customer contact, often with young or temporary staff, late hours and alcohol in the same building. Healthcare and care carry close physical contact, home visits and lone working with patients and their families. Transport carries public-facing roles in remote locations on shift patterns. Construction and multi-site operations carry constant third-party presence by design, with several employers working the same site on the same day.

Every control on that list is an operational decision

Read the risk conditions again and notice what they have in common. Which of them could your HR policy change by itself?

Lone working. Shift patterns. Who covers closing. Whether a home visit is signed off and how contact is maintained during it. Whether the bar at the client event is open all evening. Whether reception has a way to summon help. Whether a supervisor knows she is allowed to escalate a complaint about a contractor without checking the commercial implications first.

Not one of those is a policy question. They are all decisions about how work is arranged, and they sit with operations, site management and the safety function. A policy states the standard. Someone else decides who is on the floor at eleven at night.

That is why the strongest guidance on this treats third-party harassment as an organisational risk rather than an HR matter. HR still owns the policy, the reporting route and the investigation. The conditions that create the exposure are set elsewhere, by people who are used to assessing risk and recording controls.

The same conduct already engages a health and safety duty

These controls belong with the safety function for a second reason, and it predates October by decades. The Health and Safety Executive defines work-related violence as any incident where a person is abused, threatened or assaulted in circumstances relating to their work. That definition covers verbal abuse and threats, face to face, online or by telephone, and HSE names members of the public, customers, patients and service users as sources. The same population the new harassment duty covers.

HSE says plainly that it is not the primary authority for bullying and harassment, which sits with the EHRC. What it does say is that employers have a legal duty to assess the risk of violence and reduce it so far as is reasonably practicable, and that serious or persistent verbal abuse damages a worker's mental health.

So a customer shouting racial abuse at one of your team engages two duties at once. One arrives on 30 October and belongs to the EHRC. The other has been a health and safety obligation for years. The controls are the same either way.

What you have to be able to evidence

Here is the uncomfortable practical position. The government has power to make regulations defining what all reasonable steps means, and none have been made. There is no statutory definition to measure yourself against.

What that means is that tribunals will judge on evidence. How the risk was identified, what was put in place, whether anyone reviewed it, and whether it changed when the circumstances did. The EHRC has been clear in its eight-step guide for employers that an employer is unlikely to demonstrate compliance without a risk assessment, and the government has indicated it expects all reasonable steps to include risk assessments, accessible policies and robust reporting routes.

A one-size-fits-all assessment will not survive that. The expectation is a tailored one, covering roles, sites and working patterns, identifying where the risk arises, who is most exposed, what controls already operate and what else is needed.

Training belongs in that picture as one step. Our training partner The Knights of Safety Academy runs a free course on sexual harassment in the workplace built on a RESPECT framework, covering behavioural expectations, reporting routes, manager escalation, power dynamics and alcohol. A single module completed once will not discharge the duty on its own. Training that is refreshed, targeted at the people who need it and recorded against names is one of the steps a tribunal can actually see.

What makes the record hold up

Assess by role and site instead of writing one assessment for the organisation. Name the third parties involved, since a care home, a call centre and a construction site face different people. Record the controls already operating before you add new ones. Give every action an owner and a date. Log incidents even when nothing formal follows, because a pattern involving the same client or the same shift is the evidence that a risk was foreseeable. And set a review date, because an assessment written before a site opened, a contract changed or a shift pattern moved is describing a workplace that no longer exists.

Where this has to live once it is written

An assessment that sits in a folder proves very little. The duty is anticipatory. A tribunal asks what you knew and acted on before the incident. Anything written afterwards is answering a different question.

There is a fair question about why a company known for chemical compliance is writing about harassment. The answer is that the controls described above are the ones we have always worked with. Lone working, shift arrangements, site access, contractor presence, incident records and review cycles are the substance of workplace risk assessment, whatever the hazard happens to be, and violence and aggression have been assessed that way for decades. A safer workplace means safer chemical handling and better managed buildings. It means work that does not make people ill. It also means people who can do their job without being abused by somebody who walked through the door.

Our risk management module holds the register, tracks controls against named owners and schedules reviews so they happen on time rather than in hindsight. Where the same third party or the same shift keeps appearing in incident and near-miss records, that pattern is visible before it becomes evidence someone else uses. It is the practical end of the Accelerated Compliance approach, taking a team from trained and capable through to genuinely audit-ready.

What arrives on 30 October raises the standard on something employers were already expected to manage. The organisations that struggle will be the ones that kept treating harassment as a document to hold rather than a risk to manage.

Frequently Asked Questions

Does the duty apply if the third party cannot be identified?

Yes. The duty is on the employer to take all reasonable steps to prevent the harassment, and that obligation does not depend on tracing the person responsible. This is a genuine area of uncertainty for situations like an anonymous customer in a shop, and it reinforces why the assessment and the controls matter more than the investigation.

We have never had a complaint. Does that mean we are compliant?

No. The duty is anticipatory, so it asks what you did to prevent harassment rather than how you responded once someone raised it. An absence of complaints can equally mean people do not believe reporting is safe or worth the trouble, which is itself something a risk assessment should be testing for.

Does it only cover sexual harassment?

No. The third-party duty covers harassment related to protected characteristics under the Equality Act 2010. The separate change on the same date, raising the standard from reasonable steps to all reasonable steps, applies specifically to the sexual harassment preventative duty.

Do small employers have to comply?

Yes. What is reasonable is judged against the size, sector and resources of the organisation, so a small employer is not expected to do what a national operator does. Proportionality shapes which steps are expected of you. The duty itself applies either way.

What can a tribunal award?

For claims presented from 6 April 2026, the Presidential Guidance for employment tribunals sets injury to feelings awards at £1,300 to £12,600 for less serious cases, rising to £37,700 to £62,900 for the most serious, with exceptional cases capable of exceeding that. Where a tribunal finds sexual harassment and the employer also breached its preventative duty, compensation can be increased by up to 25%, and serious breaches with aggravating features can attract a further penalty of up to £20,000.


The duty arrives on 30 October whether or not anyone has assessed for it. If your register does not yet reach the people who walk through your door, speak to our team.

Sevron Team
About Sevron Team

Safety & Compliance Experts

The Sevron team brings decades of combined experience in health and safety compliance, risk assessment, and workplace safety solutions.

Dale Allen

Reviewed by

Dale Allen

CEO & Founder

Related Articles

An employee sitting apart from colleagues at work, representing unseen effort and the psychosocial hazard of feeling undervalued.
Compliance

Feeling Undervalued at Work: A Hazard That Starts With Unseen Effort

An office worker under workload pressure at a desk, representing work-related stress and the gap a workplace stress risk assessment is meant to close.
Compliance

The Stress Risk Assessment Your Risk Register is Missing

A warehouse incident report on a clipboard beside a worker receiving first aid, falling boxes as a near miss, and a supervisor calling to report the accident.
Compliance

Near Miss and Incident Reporting Under RIDDOR

In this section

View all in Compliance

685,800+ health and safety professionals in 135+ countries
rely on Sevron to simplify chemical safety compliance.

Companies that trust Sevron including Pepsico, Transocean, JCB, Bridgestone, ThermoFisher Scientific, University of Leicester, Cork Health Group, Coca-Cola, and P&G
Sevron - EHS Compliance Software

Health and safety compliance made simple. Helping UK businesses manage risk assessments, COSHH, and safety data sheets with confidence.

SAFETY365

Chemical ManagementHealth & Safety SoftwareImplementationLearning COSHH AssessmentsSDS Search

Use Cases

Small BusinessSafety OfficerManufacturerMulti-site DirectorConsultantView All Use Cases

Resources

BlogCOSHH GuideUltimate Guide (COSHH PDF)Subscription ProposalSmall Business BundleAccelerated Compliance BrochureCOSHH Software DemoDevelopment RoadmapCOSHH Mock InspectionCOSHH RA Audit

Company

Our StoryPartnersCertificationsAccelerated ComplianceContact Us
ISO 27001 Certified - Information Security Management
ISO 9001 Certified - Quality Management System
Sevron reviews on CapterraSevron reviews on Software AdviceSevron reviews on GetApp
BOOK A DEMO

© 2026 Sevron Ltd. All rights reserved.

Made with care in the United Kingdom

Privacy PolicyTermsFair UseCookies