A sexual harassment risk assessment is a foundational part of an employer’s approach to preventing harassment. From 30 October 2026, employers will be required to take all reasonable steps to prevent sexual harassment. That makes it important to understand the particular risks within the organisation, rather than relying solely on standard policies and generic training.
A good risk assessment provides the structure for doing that. It helps an employer identify where harassment could occur, who may be particularly exposed, what controls are already in place and what further measures may reasonably be required. It can also provide important evidence of the steps the organisation has taken if those arrangements are later scrutinised by an employment tribunal.
The process does not have to be unnecessarily complicated. However, it must be systematic, evidence-based and relevant to the organisation. If you don’t have a sexual harassment risk assessment that was completed with the Employment Rights Act in mind, your organisation is risking serious liability should an incident of sexual harassment occur.
Set the scope
Start by deciding what the assessment actually covers. Sexual harassment risks do not begin and end at the office door. Employers should consider the different parts of their workforce and the situations in which people interact through work. That could include remote working, client visits, recruitment, business travel, work social events and digital communications.
The assessment should also consider third parties such as customers, clients, suppliers and service users where employees may come into contact with them through their work. Setting the scope properly matters because an assessment that looks only at the conventional workplace can easily miss some of the organisation’s most significant risks.
Gather evidence
The next stage is to understand what is actually happening within the organisation. Previous complaints and investigations are an obvious starting point, although employers should look more widely. Informal concerns, exit interviews, employee feedback and patterns in absence or turnover may all help identify areas that warrant closer examination.
Talking to employees is particularly important. People working directly with customers, working late shifts or attending client events may see risks that are much less visible from head office. The aim is to build the assessment around real working practices rather than assumptions about where harassment might occur.
Turn the evidence into specific risk scenarios
Broad statements such as “there is a risk of sexual harassment” are unlikely to be very useful. Instead, employers should identify specific situations in which problems could arise. For example, there might be a risk of junior employees receiving inappropriate messages from an important client and feeling unable to challenge the behaviour because of the commercial relationship.
A useful scenario should help identify who is exposed, what the behaviour might involve, where it could happen and what factors make the situation harder to prevent or report.
This makes it much easier to determine what preventative measures may actually be required.
Assess the level of risk
Once the scenarios have been identified, consider how significant each one is. Employers can look at factors such as how frequently employees encounter the situation, whether contact takes place privately or without supervision, whether there have previously been warning signs and how serious the consequences could be.
Some organisations may choose to use a formal likelihood and impact scoring system. Others may use something simpler. The important point is that there is a consistent method for identifying which risks require the greatest attention.
Test the controls already in place
The assessment should then examine what the organisation is already doing to manage each risk. Having a policy, training programme or reporting procedure does not automatically mean that the risk is adequately controlled. Employers should ask whether those measures actually work.
Is sexual harassment training relevant to the situations employees encounter? Do managers know what to do when someone raises a concern? Do employees know how to report harassment? Is there an alternative route where the person normally receiving a complaint is themselves involved? Testing controls helps expose the gap between having a procedure on paper and having something that operates effectively in practice.
Identify and record further reasonable steps
Where the existing controls do not sufficiently address the risk, employers should consider what further measures could reasonably be introduced. The safest approach is to work backwards from each risk. Ask what could prevent the behaviour, reduce employees’ exposure or allow somebody to intervene earlier.
Cost, resources and practicality can form part of that assessment. What is reasonable for a multinational employer may look very different from what is reasonable for a small business. Employers should still record why particular measures were adopted, rejected or replaced with alternatives. That documentation can become important evidence of the organisation’s decision-making if its approach is subsequently challenged.
Keep the assessment under review
A sexual harassment risk assessment should not be treated as a document that is completed once and filed away. Employers should establish regular review dates and reconsider the assessment when circumstances change. A complaint, investigation, organisational change, new working arrangement or emerging risk may all indicate that existing controls need to be revisited.
Complaints can also reveal weaknesses that were previously unknown. An incident might show that managers did not know how to respond, employees did not understand how to report concerns or an identified control simply did not work as intended. Those lessons should feed back into the risk assessment and preventative measures.
The risk assessment should therefore operate as a living part of the organisation’s harassment prevention programme. It provides the link between the risks employees actually face and the policies, training, reporting systems and other reasonable steps designed to address them.
With the move to the all reasonable steps standard, employers need to be able to demonstrate that they have thought seriously about their particular risks, acted on what they found and continued to test whether their controls are working.