Harassment risk is moving into the boardroom

Harassment risk is moving into the boardroom

August 28, 2026

The EHRC’s latest workplace harassment research challenges the assumption that a policy, annual training and low complaint numbers amount to effective prevention.

That matters because the Employment Rights Act 2025 raises the legal bar from Friday 30th October 2026. The practical question is becoming harder. What did your organisation do to prevent harassment, and can you prove it?

What does the research show?

The EHRC’s research points away from compliance theatre. Policies alone do not reduce harassment effectively. Generic, one-off training cannot drive sustained behavioural change where problems are embedded.

The research instead points to tailored, repeated training, accessible reporting routes, organisational data, and active leadership. It also warns against treating low complaint numbers as evidence of a healthy culture. They may mean people do not trust the reporting process.

That is an important warning for boards accustomed to reassuring dashboards.

What does this mean in practice?

The Employment Rights Act 2025 changes the risk calculation.

From Friday 30th October 2026, employers must take “all reasonable steps” to prevent sexual harassment. Employers will also have an obligation not to permit harassment by third parties, such as customers and clients. In that context, an employer permits harassment where it fails to take all reasonable steps to prevent it.

The difference between “reasonable steps” and “all reasonable steps” is not cosmetic. The obvious challenge after an incident will be whether there was another preventative step the employer could reasonably have been expected to take.

That puts evidence at the heart of the issue. A policy last reviewed two years ago tells you little about current risks. Training attendance proves attendance, not effectiveness. And a board paper reporting “zero complaints” may provide false comfort if employees do not trust the reporting channels.

This is governance risk. It can become litigation, regulatory scrutiny, management distraction, unwanted publicity and the loss of people you wanted to keep.

So, what should you do?

  • Assess the risk. Identify where harassment is more likely. Look at power imbalances, customer-facing roles, work travel, alcohol, lone working, insecure roles and teams with known cultural problems.
  • Test your data. Review complaints alongside absence, turnover, exit information, engagement data and progression patterns. Ask whether apparently quiet areas are genuinely healthy or are just…quiet.
  • Stress-test reporting routes. The EHRC research recommends at least two routes, including an internal and external option. Check whether employees know about them and would use them.
  • Review third-party exposure. Map where staff deal with customers, clients, patients, suppliers, contractors or other outsiders. Decide what managers can do when those people cross the line.
  • Replace generic training where necessary. Use realistic scenarios based on actual roles and risks. Give managers specific training on intervention, escalation and handling reports.
  • Create an evidence trail. Record identified risks, decisions, preventative measures, ownership, review dates and follow-up. If challenged later, you want contemporaneous evidence of prevention, not a hurried reconstruction.
  • Put this on the board agenda. Ask who owns the risk, what assurance the board receives and what would demonstrate that the controls work.

Friday 30th October 2026 is close enough that “we are reviewing our policy” is no longer much of a plan. The stronger organisations will be able to show what they knew, what they did and why.

Source: Our research into workplace harassment | EHRC

The EHRC’s new Code is not just a customer issue
Bronze statue of justice on a white backgroundCan you dismiss an employee for expressing controversial beliefs?