Hong Kong CPD/RME HK
Book an intro

All reasonable steps to prevent sexual harassment: Your questions answered

We had a fantastic response to our recent sexual harassment webinar on 7 October, with a huge number of questions submitted throughout the session. We weren’t able to get through all of them live, so we’ve pulled together answers to some of the most common and practical questions raised by attendees.

Here are some of the key points employers asked us about, from risk assessments and reporting routes to training, third-party harassment and handling complaints.

How much of the investigation outcome should be shared with the complainant?

The complainant should be told the outcome of the investigation in a way that is clear enough to show their complaint was taken seriously and considered properly. This will usually include whether the complaint was upheld, partially upheld or not upheld, and any steps that directly affect their safety, working arrangements or future support.

Employers should avoid disclosing unnecessary confidential information about the respondent, particularly detailed disciplinary sanctions or personal information. Where action has been taken, it is often sufficient to say that appropriate action has been taken in line with the organisation’s procedures.

The compliance aim is to balance transparency with confidentiality: give the complainant a meaningful outcome, while limiting disclosure to what they reasonably need to know.

What if a “banter” culture is deeply ingrained despite training?

If employees still do not recognise the harm after training, the issue has moved beyond awareness into culture and behaviour. Employers should review whether the training reflects the real situations occurring in that workplace, reinforce clear behavioural expectations, and ensure managers consistently challenge inappropriate conduct rather than participating in or tolerating it.

Use complaints, staff feedback and the harassment risk assessment to identify where the culture is most entrenched. More targeted measures may then be needed, such as manager-specific training, realistic scenario-based learning, bystander intervention training and clearer consequences for breaches of policy.

Crucially, “nobody minds” or “nobody has complained” is not evidence that the culture is safe. Under the all reasonable steps standard, employers need to show that their controls are actually changing behaviour, not simply that training has been delivered.

How important is it to have more than one reporting route?

Very important. Employees should not be dependent on a single manager or reporting channel, particularly where that person may be involved in the complaint.

Having alternative routes, for example HR, another manager or an independent whistleblowing channel, makes it more likely concerns will be raised early and helps demonstrate that the reporting system is genuinely accessible and effective.

What might “all reasonable steps” look like for a law firm?

For a law firm, the risk assessment should pay particular attention to client contact, entertainment, business travel, late working, power imbalances and senior or commercially important clients. From 30 October, clients can also be third parties for harassment purposes, so firms need controls that address their behaviour as well as conduct between employees.

Putting appropriate conduct expectations into a client engagement letter or terms of business could be one reasonable step, particularly where client-facing harassment is a foreseeable risk. It would not be mandatory in every case or sufficient on its own. Firms should also have clear reporting routes, manager training, escalation procedures and authority to challenge a client where necessary.

The test is whether the firm can show it identified its actual risks and took all the reasonable measures available to address them, rather than relying on a generic policy.

How should an annual sexual harassment risk assessment review be carried out?

Treat it as a structured update rather than starting from scratch. Review any complaints, informal concerns, exit feedback, staff surveys, changes in working practices, new client or customer risks, and whether existing controls actually worked.

Then consider whether the risk profile has changed, whether any controls need strengthening, and whether new reasonable steps are now available. Record the review date, what evidence was considered, what changed and who is responsible for follow-up. Annual review is a useful baseline, although any significant complaint, organisational change or new risk should trigger an earlier review.

Should sexual harassment have its own policy, or can it sit within the Code of Conduct?

A separate sexual harassment policy is strongly preferable. It gives employers much clearer evidence that they have identified the risk specifically and put dedicated preventative measures in place.

The policy should cover what sexual harassment is, third-party harassment, reporting routes, investigation procedures, protection from retaliation, manager responsibilities and the consequences of misconduct.

The Code of Conduct can still reinforce those expectations, although relying on a few paragraphs within a broader code is unlikely to demonstrate the same level of focus or accessibility under the all reasonable steps standard.

What if both parties say the other is lying?

That is where the investigation needs to move beyond competing accounts and test the evidence. The investigator should look for contemporaneous messages, emails, CCTV, witness evidence, previous complaints, patterns of behaviour and inconsistencies in each account. They should also assess credibility carefully, without assuming that confidence, emotion or the absence of witnesses proves either side right or wrong.

The employer does not need criminal-law proof. The decision is usually made on the balance of probabilities, meaning whether it is more likely than not that the alleged conduct occurred.

If the evidence remains genuinely inconclusive, the employer may have to find the allegation not substantiated, while still considering whether any wider risk controls or workplace measures need to be strengthened.

Does third-party harassment protection cover workers and agency staff, as well as employees?

The term “employee” under the Equality Act is broader than it sounds. It includes people working under a contract of employment, an apprenticeship, or a contract personally to do work. So some workers will fall within the protection even if they are not employees in the narrower Employment Rights Act sense.

Agency staff need a little more care. If they are supplied by an agency and are not employed by you, you may be the “principal” rather than their employer. Section 41 of the Equality Act already protects contract workers from harassment by the principal.

The new third-party harassment duty itself is drafted around harassment of “an employee of A”, so it does not automatically make every host organisation liable for third-party harassment of every agency worker.

From a compliance perspective, I would still include agency staff working at your premises within your harassment risk assessment, reporting routes and preventative controls. Their exact legal route may depend on the contractual arrangements, while excluding them operationally would create an unnecessary gap in protection.

Do employees need to be given the sexual harassment risk assessment?

There is no general requirement to give every employee a copy of the full risk assessment. The priority is that employees understand the risks relevant to them, what behaviour is expected, how to report concerns and what the organisation will do in response.

However, good practice is to involve employees or their representatives in the assessment and communicate the resulting actions. Current guidance also suggests employers consider publishing their harassment action plan.

So the risk assessment can remain an internal compliance document, while its practical findings should be clearly communicated and reflected in policies, training and reporting procedures.

What should a fully remote company include in its sexual harassment risk assessment?

For home-based staff, focus less on the physical home itself and more on work-related interactions that happen through it. Relevant risks could include inappropriate messages or video calls, sexual comments in Teams or Slack, misuse of personal phone numbers, harassment through social media, one-to-one calls with managers or clients, and third-party contact connected with work.

You could also consider deliveries, contractors or visitors where the contact is genuinely work-related, for example a courier delivering company equipment or an engineer attending to install employer-provided hardware. An ordinary postman delivering personal mail would usually be too remote from the employment relationship.

The assessment should cover whether employees know how to report concerns remotely, and whether managers can identify and respond to inappropriate behaviour that takes place outside a physical workplace.

What are the risks of colleagues (same sex) sharing hotel rooms after company parties?

This is a higher-risk arrangement and should be specifically covered in the event risk assessment. The fact that colleagues are the same sex does not remove the risk of sexual harassment, which can occur between people of either sex.

Where accommodation is paid for and arranged by the employer because of a work event, there is also a strong connection with employment. I would avoid making room-sharing compulsory where possible. Employees should have a genuine option to request separate accommodation without embarrassment or disadvantage, and particular care should be taken around senior/junior colleagues, alcohol consumption and anyone who has expressed discomfort. Employees should also know that workplace conduct standards continue to apply at the hotel and have a clear way to report a problem if something happens overnight.

Should sexual harassment training and policies apply globally, or only to UK employees?

For a global company, I would generally recommend having a global baseline policy and training standard, with UK-specific content added where the law requires it.

That is particularly important because employees outside the UK may still interact with UK colleagues through Teams, email, travel, client work or global events. If an overseas employee harasses a UK employee, the fact that the alleged harasser sits in another jurisdiction does not remove the UK employer’s risk.

A sensible approach is therefore one global standard of expected conduct and reporting, supplemented by jurisdiction-specific modules covering local legal duties such as the UK’s all reasonable steps and third-party harassment requirements.

What if employees are fed up with repeated harassment training?

Training is ultimately part of how the employer demonstrates that it has taken reasonable preventative steps and manages its potential liability. The aim is not to make employees repeat exactly the same course indefinitely, so employers can vary the format with shorter refreshers, new scenarios, role-specific modules, manager training and targeted content based on the risk assessment.

Training fatigue is worth managing, although it should not become a reason to stop refreshing knowledge altogether. From a legal-risk perspective, complaints that employees are being asked to complete too much training generally carry far less exposure than a sexual harassment complaint where the employer cannot show that its training remained current, effective and appropriate to the risks.

Listen again to the webinar.

Be the first to know about releases and industry news and insights.

By filling in this form you agree to share your information with VinciWorks. We take privacy seriously, click here to read our privacy notice.