
Approx. 5-minute read
Sexual harassment is not simply an HR or compliance issue. When it happens at work, the commercial consequences can include loss of talent, absence, reduced performance, management time, damaged employee and customer relationships, reputational harm, legal costs and compensation.
From 30 October 2026, the legal expectations on employers strengthen.
Since October 2024, employers have had a preventative duty to take reasonable steps to prevent sexual harassment. From 30 October 2026, that becomes a requirement to take all reasonable steps. The Employment Rights Act 2025 also introduces employer liability for harassment by third parties where the employer failed to take all reasonable steps to prevent it.
For employers, the practical message is straightforward: a policy sitting in a folder is not an adequate prevention strategy.
What changes from 30 October 2026?
The change from reasonable steps to all reasonable steps matters.
The new standard requires employers to take all the steps that are reasonable for their company, rather than selecting only some of them. What is reasonable will depend on factors including size, sector and the work employees perform. The emphasis is preventative: employers should identify risk and act before an incident occurs, rather than relying primarily on a complaints procedure afterwards.
In practice, employers should consider whether their approach includes:
- assessing where sexual-harassment risks could arise;
- reviewing those risks as the company and working environment change;
- maintaining clear and accessible policies;
- providing relevant training rather than relying on policy acknowledgement;
- giving employees more than one credible route to raise concerns;
- making sure managers know what to do when something is disclosed;
- investigating concerns appropriately;
- acting where behaviour falls below the required standard; and
- recording and reviewing incidents and the actions taken.
This does not mean every company needs the same controls. A 30-person technology startup and a national hospitality company have very different risk profiles.
It does mean each employer needs to understand its own risk and be able to demonstrate what it has done about it.
“It was only banter” is not an adequate sexual-harassment defence
Intent does not automatically determine whether conduct amounts to harassment.
Behaviour does not become safe or acceptable because it has happened before, nobody previously complained or the person responsible says they intended it as a joke.
Normalised does not mean safe or acceptable.
That is why training needs to go further than definitions and an annual click-through exercise. Employees and managers need practical examples of inappropriate behaviour, clear expectations around boundaries and confidence about what to do when something happens.
Managers are particularly important. They are often the first person to see behaviour, receive a concern or hear something said informally. What they do next matters.
Risk-assess the workplace you actually have
Sexual-harassment risk will not be identical across every company, team or role.
A useful assessment should consider where people actually work and interact, including:
- work social events and alcohol;
- business travel and overnight stays;
- conferences and networking events;
- client and customer sites;
- lone or isolated working;
- late-night working;
- messaging platforms and social media;
- power imbalances between senior and junior employees;
- recruitment, promotion and career decisions; and
- roles involving significant interaction with customers, suppliers, contractors or members of the public.
The purpose is not to create a theoretical risk register. It is to identify where something could realistically happen and decide what proportionate controls can reduce that risk.
Your responsibility does not stop at your front door
This becomes particularly important from 30 October 2026.
The new third-party provisions cover people employees encounter through work who are not their employer or colleagues. This can include customers, clients, service users, consultants, contractors, tradespeople, people at conferences or events and members of the public. The protection is broader than sexual harassment alone and can cover other harassment within the Equality Act framework.
If your employees work at client sites, attend conferences, interact with customers or operate in environments outside your direct physical control, do not assume responsibility simply transfers to somebody else.
Consider:
- which third parties employees regularly encounter;
- where those interactions happen;
- whether particular environments increase risk;
- what employees should do if something happens;
- escalation and reporting routes;
- relevant customer, client or supplier terms;
- training or de-escalation support where appropriate; and
- what action the company is prepared to take where a third party behaves unacceptably.
A commercially important question follows: what are you prepared to do when the person creating the risk is also an important customer?
That is when stated values and policies are genuinely tested.
Make reporting credible
A reporting process only works if employees believe they can use it.
Consider whether:
- employees know how and where to raise a concern;
- there is an alternative if the concern involves their manager;
- information will be handled appropriately;
- managers understand how to receive a disclosure;
- investigations can be conducted fairly and competently;
- appropriate escalation routes exist; and
- employees understand what happens after they raise something.
The objective is not simply to create a mechanism for complaints. It is to make it credible enough that problems surface early rather than remaining hidden until they become considerably harder to resolve.
Prevention needs evidence
If an employer ever needs to demonstrate what it did to prevent harassment, the answer should be more substantial than “we had a policy.”
Keep evidence of the controls you actually operate, such as:
- risk assessments and reviews;
- policies and updates;
- training completion and content;
- manager guidance;
- communications;
- reporting mechanisms;
- incidents and themes;
- actions taken in response; and
- subsequent changes to controls.
Documentation should evidence a functioning prevention framework, not become the framework itself.
The commercial test
The objective is not to eliminate every conceivable risk or create a workplace where people are frightened to interact.
It is to create an environment where boundaries are understood, employees can raise concerns safely, managers know how to respond and inappropriate behaviour is addressed before it becomes embedded.
For a growing company, that does not require an enormous compliance programme. It requires a proportionate one that actually works.
Start with the practical questions:
- Where are our risks?
- What controls do we already have?
- Where are the gaps?
- Are our managers equipped to respond?
- Can employees report concerns safely?
- What happens when the alleged harasser is a client, customer or other third party?
- Can we evidence the preventative steps we have taken?
From 30 October 2026, the expectation becomes clearer and more demanding: employers must take all reasonable steps to prevent sexual harassment, while the new third-party harassment provisions materially widen the situations employers need to consider.
Assess the risk. Put practical controls around it. Train people. Create credible reporting routes. Act when something happens. Review what you learn.
Protecting people protects more than compliance. It protects talent, performance, reputation and the business relationships on which growth depends.
