HomeEmployee ExperienceHR StrategySexual Harassment Laws Have Changed. Has Your Organisation Done Enough to Comply?

Sexual Harassment Laws Have Changed. Has Your Organisation Done Enough to Comply?

  • 6 Min Read

New sexual harassment prevention requirements are now in force, but WorkNest research found just 4% of employers had fully embedded preventative measures. Has your organisation made the changes needed to comply?

Featured Image

Tougher workplace harassment laws are now in force, but research conducted shortly before the changes took effect suggests many employers may still have work to do.

Just 4% of employers surveyed by WorkNest said their measures to prevent sexual harassment were fully in place and being monitored. More than a quarter, 26%, said they were either taking a reactive approach, typically acting after a complaint, or did not yet have a formal prevention strategy.

Only 8% considered themselves fully prepared for the new requirements.

Those findings were published ahead of the 30 October changes, which strengthened employers’ preventative duty from taking “reasonable steps” to taking “all reasonable steps” to prevent sexual harassment. Employers also now face greater responsibility for protecting employees from harassment by third parties.

The deadline has passed. For HR leaders, the question is no longer whether they are preparing for the change, but whether the measures they have introduced are enough to demonstrate compliance.

From ‘reasonable’ to ‘all reasonable’ steps

Employers have already had to adjust once.

Since October 2024, the Worker Protection Act has placed a preventative duty on employers to take reasonable steps to prevent sexual harassment. The Employment Rights Act 2025 has now strengthened that requirement.

Acas says the new standard means employers are expected to take all steps that are reasonable for their organisation, rather than selecting some measures. What those steps look like will depend on factors including the organisation’s size, sector and type of work.

That makes prevention an ongoing exercise rather than a compliance checklist.

Organisations that updated their harassment policies or introduced training following the 2024 changes should therefore not assume the work is finished.

WorkNest’s research suggests many employers recognised this before the new requirements came into force. Three quarters, 76%, said preparations for the strengthened duty were underway, although 14% had yet to start.

“There is a big difference between having some measures in place and being able to demonstrate that prevention is fully embedded,” said Tracey Burke, Senior HR Consultant at WorkNest.

“Employers need to understand where their risks arise, put proportionate measures in place and keep checking their effectiveness.”

Now that the strengthened duty is in force, that distinction has become increasingly important. Employers may need to demonstrate not simply that policies exist, but that they have identified risks, acted on them and continue to assess whether their approach is effective.

Managers could be the weak link

One of the clearest gaps identified by the research sits with line managers.

More than half of respondents, 54%, said either a lack of confidence to intervene or fear of getting it wrong was the biggest barrier preventing managers from addressing inappropriate behaviour early.

That matters because harassment prevention ultimately depends on what happens between formal complaints.

A policy might explain what constitutes unacceptable behaviour and provide a reporting route. But if managers ignore inappropriate comments, dismiss behaviour as banter or are uncertain about when they should intervene, problems can escalate before HR becomes aware of them.

Acas recommends appropriate sexual harassment training, multiple ways for workers to report concerns and preventative measures that operate across the organisation rather than only responding after incidents.

Training managers should therefore go beyond telling them what the policy says. They need practical guidance on recognising warning signs, challenging behaviour, documenting concerns and knowing when an issue should be escalated.

For HR, manager confidence should now be one measure of whether harassment prevention has genuinely been embedded.

What are your organisation’s actual risks?

The strengthened duty also makes risk assessment increasingly important.

The Employment Rights Act gives government the power to specify reasonable preventative measures through regulations, including assessments, policies and steps relating to reporting and complaint handling.

HR teams should not wait for an incident to reveal where vulnerabilities exist.

Those risks will differ considerably between organisations. A hospitality business might need to consider alcohol, late-night working and customer interactions. Healthcare employers may need to consider contact with patients. Other organisations could identify conferences, business travel, social events, messaging platforms or isolated working as areas of greater exposure.

The question is no longer simply whether an organisation has a harassment policy. It is whether that policy reflects how and where its employees actually work.

Risk assessments should also not be treated as one-off exercises completed to meet the October deadline. Changes to working practices, locations, teams or customer interactions can create new vulnerabilities, making regular review part of an effective prevention strategy.

Third-party harassment widens HR’s responsibility

The changes also put greater emphasis on behaviour from people outside the organisation.

Employers now need to consider harassment risks involving third parties, such as customers, clients, contractors, service users or members of the public, as part of their preventative approach.

That risk is not theoretical.

WorkNest found 9% of respondents had dealt with third-party harassment during the previous 12 months, while 6% had specifically dealt with the sexual harassment of an employee by a third party.

For organisations where employees regularly interact with customers or clients, prevention strategies therefore need to extend beyond internal workplace behaviour.

Measures could include regularly assessing third-party risks, recording incidents and actions, training employees in areas such as de-escalation and reviewing customer, supplier and client arrangements where appropriate.

HR should also make clear that employees are not expected to tolerate harassment simply because the person responsible is a valuable customer, client or service user.

What should HR have in place now?

With the deadline behind them, employers should be reviewing whether the measures introduced ahead of the reforms are actually working.

HR teams should examine their risk assessments, ensure policies reflect the strengthened requirements, test reporting routes and identify areas where employees interact with third parties.

Managers should know what behaviour requires intervention and feel confident acting before it develops into a formal complaint.

Training also needs to reflect the risks employees actually face. A generic annual module may have limited value if it does not address situations that arise in a particular workplace.

Employers should also be able to demonstrate that prevention is being monitored. That could mean looking at employee feedback, reporting patterns, manager confidence, recurring problem areas and whether previous incidents have resulted in changes.

The aim should not simply be to prove that training was delivered or a policy was updated before 30 October. HR needs to be able to show that preventative measures are active, relevant and reviewed as workplace risks change.

Compliance cannot end with the deadline

The legal threshold may have changed by only one word, from “reasonable steps” to “all reasonable steps”, but the implications for HR are considerably bigger.

The focus is shifting further away from how an employer responds when harassment occurs and towards what it did to stop that harassment happening in the first place.

That means the 30 October deadline should be viewed as the beginning of an ongoing obligation rather than the end of a compliance project.

For HR leaders, the question now is straightforward but potentially uncomfortable: if an incident happened tomorrow, could your organisation demonstrate that it had taken all reasonable steps to prevent it?

Was this article helpful?

Events

HRD Roundtable: Combating 'Quiet Quitting'…

08 June 2023
  • E-Book
  • 3y

HRD Network Roundtable: The Retention…

15 June 2023
  • E-Book
  • 3y

Manage change and drive value…

01 June 2023
  • E-Book
  • 3y
Sign up to our Newsletter