How to Prevent Workplace Violence: 8 Steps (2026)

To prevent workplace violence, you need four things running at the same time: a written policy that says violence is not tolerated, reporting routes people can actually use, training that teaches staff to spot warning signs and step back, and a recurring risk assessment that finds the holes in your site. This guide walks through how to prevent workplace violence in eight steps, roughly a quarter of the work to start and a standing commitment after that.

The honest truth is that most organizations already have one or two of these pieces. A stack of laminated posters near reception, a phone number nobody has tested, an online course that people finish in nine minutes. The gap is almost never knowledge. It is ownership, follow-through and whether the thing was rehearsed.

Use this as a working plan rather than a document to file. Prevention is not a one-time training requirement, and the eight steps below are ordered by what unblocks the most risk first, not by how hard they are.

Table of Contents

What You Need

Before you assess anything, gather the material. Without it, a risk assessment turns into guesswork and your policy has nothing to attach to.

  • Workforce and visitor patterns. Shift schedules, late-night or lone-working hours, cash handling, delivery windows, and how contractors, temps and gig workers move through the site.
  • Incident history. Every report, near miss, conflict, workers’ compensation claim, security call and law-enforcement contact from at least the last two years, including the ones that never became formal complaints.
  • Employee input. Surveys or listening sessions on where people feel unsafe, what they have seen and what they would never report. Frontline staff usually know where the pressure is building.
  • Guidance. Occupational safety guidance from OSHA, your state plan, your workers’ compensation carrier, and any industry association standard that applies to your sector.
  • Reporting options. A named human being, not just a shared inbox, plus at least one route that does not require an employee to approach their own manager.
  • Emergency contacts. Local law enforcement non-emergency number, emergency services, facilities and security, and an outside counsel or violence-prevention consultant.
  • Support resources. An employee assistance program contact, a behavioral health referral pathway, and a plan for counselling after an incident.

Be clear about one limit here. This article is general information, not legal or clinical advice. Employment law, reporting duties and safety rules differ by state, by industry and by worksite, and a few states now impose specific written-plan obligations on covered employers. Before you publish a policy, have qualified legal, occupational safety, security and behavioral-health professionals review it. That is a day of work and it prevents months of rework.

Step-by-Step: How to Prevent Workplace Violence

Eight steps, in the order that actually moves risk. The first two build the structure, the middle four build the capability, and the last two keep the whole thing honest. Adapt the sequence to your industry, your workforce, your site and your risk profile. A rural clinic with one overnight provider needs a different mix than a 900-person distribution center, and a fully remote team needs a different one again.

1. Build a prevention team and define responsibility

Prevention works when someone owns it by name. A cross-functional team is the fastest way to stop gaps: HR owns policy and the reporting intake, safety owns hazard identification and the plan, security owns access and physical controls, facilities owns lighting, sightlines and signage, the employee assistance program owns support, communications owns messaging, and frontline managers own escalation.

Write down four things for each function: what you own, who the backup owner is, what you escalate, and how it gets documented. If a task has no named owner and no named backup, it does not happen. That is the whole lesson.

Set the confidentiality rules at the same meeting. The team sees more sensitive information than almost any other group in the company, and that access stays with the need to know. Also agree now on what the team is not allowed to do: it does not diagnose anyone, it does not investigate on its own outside a defined process, and it does not make assumptions about who is likely to be violent based on a diagnosis, a grievance history or a personality.

2. Conduct a workplace violence risk assessment

A risk assessment is a structured conversation with the people who work there, followed by a written list of what you are fixing first. Start by walking the site at the times that matter: the opening, the closing, the shift change, the pay-out. Most sites are fine at 10am on a Tuesday and a different place at 11pm. If you are working out how to prevent workplace violence for your own site, walk it at shift change and after dark, and take someone from reception with you.

Work through these hazard categories:

  • People. Current employees, contractors, temps, visitors, delivery personnel, former workers, and anyone with a personal or domestic conflict that could reach the workplace.
  • Places. Reception, parking areas, isolated rooms, restrooms without call points, remote or after-hours workspaces, and any location with a single point of entry.
  • Tasks. Cash handling, medication or controlled items, evictions, terminations, disciplinary conversations, high-value deliveries, and lone working.
  • Digital. Social media posts, messaging apps, email, online harassment campaigns, doxxing, and threats made from outside the building that still target staff.

Bring employees and contractors into the walkthrough. The receptionist and the closing cashier will tell you things the risk register never recorded. Then review every past report and near miss, and ask one question of each: why was this reported, and why wasn’t the last one?

Prioritize what you find by likelihood times potential harm, and write down the gaps plainly. Then set the indicators that mean the plan is failing: a second report from the same person within a year, a threat that reached a supervisor and nothing happened for 30 days, a hazard you logged twice and did not fix, or a training completion rate that keeps falling. Those triggers are what make step 8 real.

3. Write and enforce a clear prevention policy

Your policy should be short enough that people finish it and specific enough that a manager can act on it in under a minute. Ten sections is about right: purpose, definition of workplace violence and the four types your organization cares about, prohibited conduct, reporting routes, investigation process, anti-retaliation, access and visitor rules, contractor responsibilities, emergency procedures, and the annual review date.

Define the term broadly enough to cover the real scope. A threat made in a messaging app from a former employee, aimed at a current one, is workplace violence even though it never touches a building. Language that stops at “acts of physical violence on premises” is why policies miss digital and off-site threats.

Also say what the policy does not mean, because this is where employers get into trouble. Grievances, safety complaints, whistleblowing, organizing activity and ordinary workplace disputes are protected. A policy that reads as “you can be disciplined for complaining” is a policy that will be used badly, and possibly in ways your state’s law does not allow. Have counsel review that paragraph specifically.

Enforcement is the part that builds or destroys trust. Managers document credible threats, escalate them within a defined timeframe, and take the same first response every time regardless of the person’s seniority or how much they bill in sales. Write that down, and hold it.

For context, several US states now require covered employers to maintain a written workplace violence prevention plan with training, recordkeeping and review. California, for example, requires covered employers to have a plan under Senate Bill 553 and Title 8 of the California Code of Regulations, Section 3203, and OSHA enforces a general duty to address recognized serious hazards. Rules vary by state, size and sector, so confirm what applies to you rather than assuming a national standard exists.

4. Create multiple confidential reporting channels

Create multiple confidential reporting channels

People report through routes that feel safe, which means giving them more than one. Offer a named HR or safety contact with a direct line, a confidential hotline or third-party intake service, an online form, a union or worker representative where one exists, and any supervisor they trust. Add one clear path for immediate danger that bypasses the entire chain and goes straight to emergency services.

Each route needs a named owner, a response time you publish, and a way to document what came in. A generic shared address with no owner is a dead end that people learn about the hard way, and it is the single most common failure HR teams describe when they audit their own intake process.

Test the channels. Send a test report through each one and time the response. If the hotline rings out on a Tuesday afternoon, you have found your first serious gap before it matters.

A notice that works is short and concrete:

“If you experience or witness a threat, assault or intimidation at work, report it to [name] at [contact] or use the online form. Reports go to two people only, and neither is your manager. Retaliation against anyone who reports in good faith is a policy violation and may be unlawful. If someone is in immediate danger, call 911 first and report it after.”

That last line matters more than anything else on the notice. Credible immediate threats go to emergency services and trained responders first, paperwork second.

5. Train employees and managers to recognize and respond

Training works when it is short, specific to the person’s job and rehearsed. Everyone gets a core module on what counts as a threat, how to use a reporting channel, and the rule that they should not confront, investigate or diagnose anyone. Managers get more: documenting observable behavior, escalating within a timeframe, handling a termination or a difficult conversation safely, and knowing when to call police. Reception, security, HR, help desk and anyone who works alone or after hours get de-escalation practice and safe disengagement technique with a role-player, not a video alone.

Refresher every year, plus a briefing after any incident or near miss. Keep records of who attended, what was covered and what changed as a result. Knowing how to prevent workplace violence in the moment, rather than on paper, is the entire point of the rehearsal.

On the behavioral side, document observable facts, not personality judgments:

What you may seeWhy it mattersWhat to record
Escalating arguments with colleagues, customers or supervisors over multiple weeksUnresolved conflict that has nowhere to goDates, who was involved, what was said
Threatening language, direct or implied, in person or onlineA stated intent or a credible pattern of intimidationExact words, medium, witnesses, time
Sudden withdrawal, decline in performance or attendance collapsePossible personal crisis affecting stabilityObjective changes only, never a diagnosis
Fixating on a person, a grievance or a perceived injusticeTargeting is a feature of most serious incidentsSpecific statements, not impressions
Bringing weapons to the workplace or discussing plans to actHighest-acuity indicator, treated as an immediate threatDetails, location, time, then escalate now
New or changed access patterns: badge sharing, tailgating, unusual presencePossible attempt to bypass controlsObserved behavior and camera or log detail

Treat this as a screening aid, not a prediction tool. Most people who appear on such a list never cause harm, and treating the list as evidence of future violence is both unfair and, in many jurisdictions, unlawful. A team that over-reacts loses the trust it needs for the reports that matter.

6. Reduce physical and operational risks: how to prevent workplace violence at work

Reduce physical and operational risks: how to prevent workplace violence at work

Controls work by removing opportunities, not by making people afraid. Visitor and contractor sign-in with a named host. Badge and access management, including a process for deactivating former employees the same day they leave. Reception protocols for visitors who do not have an appointment. Good lighting at entries, parking, and any area where money or high-value goods are handled. Clear sightlines into and out of isolated rooms, and trimming plants or structures that create blind corners.

Then the operational ones. Late-opening and lone-worker check-in procedures. Two-person closing for cash locations. Secure storage for anything that could be used as a weapon or a projectile, where local law allows it. Delivery arrival coordination so nobody receives a surprise visitor alone. Duress alarms or panic buttons in high-risk spots like restrooms, cash offices and public-facing counters.

For remote and hybrid work, the risks move with the person. A threat from an ex-partner or a former employee can arrive by phone and text, and the target may be working from home. Agree on a way for staff to flag a personal safety emergency discreetly, and clarify where company responsibility ends and personal safety begins, without that conversation reading as “we don’t help.”

Balance every control against privacy, accessibility, disability accommodations and the fact that people notice and remember when a workplace gets hostile. Ask for feedback on new controls and change the ones that are making things worse. A lobby that looks like a checkpoint is a lobby people route around, including the visitors you most wanted to see.

7. Prepare and rehearse the incident response plan

The first ten minutes decide a lot. Write the sequence plainly enough that a person in shock can follow it: call emergency services, give the exact address and floor, warn reception and security, move people away from the area, and do not enter the scene. Then the calmer layers: evacuation and shelter procedures for the rest of the building, an internal and external communication tree, backup owners for every role on it, first-aid arrangements and where the kits are, and the point at which law enforcement takes the lead rather than you.

Cover the scenarios you are actually likely to face: a threat made in person, an assault, an armed incident, sabotage, and a threat that follows the person home. Have the sheriff or police non-emergency contact and your outside counsel’s number printed on the plan, not in someone’s head.

After that, protect the business and the people. Decide who speaks to media, who notifies families, how you preserve evidence and footage before it overwrites, and how operations continue. No plan prevents every incident. A rehearsed one limits harm, and saying otherwise is how organizations end up improvising at the worst possible moment.

Then rehearse. Two scenario-based drills a year, one with a surprise element, with an after-action review that produces written corrective actions with owners and dates. Swapping drafts with a peer organization of similar size tends to surface gaps your own team has stopped seeing, and costs nothing but an hour of somebody’s time.

8. Review the program and support affected people

Once the program runs, watch it. Track report volume and response times, repeat reports from the same source, near misses, training completion, the age of your open hazard corrections, and employee confidence in using the reporting channel. A rising report count is not automatically a sign that things are getting worse; it often means people trust the system enough to use it. What matters is what happened next.

Put a review date in the calendar and hold it: at minimum annually, sooner after any incident, a near miss, a site change, a new leadership team or a shift in staffing. Peer review against a plan from another organization of similar size catches the blind spots your own team has stopped seeing.

Support is where most programs quietly fail. Anyone who experienced or witnessed violence gets the same offer of counseling, the same confidentiality, and the same clear statement that they did nothing wrong. Provide the contact, the timing and the follow-up without requiring anyone to justify wanting help. Warn people in advance what records are kept and who sees them, because being asked to sign a release four days after an assault is its own trauma.

Support the witnesses and the bystanders too, and the managers who made the call. And keep the line simple for everyone: if the danger is immediate or serious, call emergency services rather than waiting for an internal process to catch up.

Common Mistakes

Almost every program that quietly fails shares one of these patterns, and each has a straightforward fix.

Treating violence as only a security problem

Badges and cameras reduce opportunity, but the threats that reach people come from conflicts, grievances and personal situations that security never sees. Fix: put HR, safety and employee support on the same team with equal weight.

Waiting for an incident before acting

Every serious case had a prior report, a prior threat, or a known stressor that somebody noticed. Fix: run the assessment and the policy before the first call, not after it.

Relying on a single reporting channel

If the only route runs through the person the employee is afraid of, you have no channel. Fix: at least three, with one that bypasses the direct manager entirely, and test each one.

Generic one-time training

A generic module taught once is compliance theater. Fix: role-specific content, annual refreshers, and drills that involve a role-player rather than a video.

Encouraging untrained confrontation

Employees who “handle it themselves” are the ones who get hurt first. Fix: teach disengagement and reporting, and state plainly that no employee is expected to physically intervene or to investigate.

Vague or inconsistent policies

A page of values with no reporting route, no owner and no timeframe cannot be applied. Fix: ten specific sections, a named owner for each, and the same first response every time regardless of seniority.

Ignoring contractors, former workers and online conduct

A growing share of cases involve people with no current employment relationship, including in messages and social media. Fix: include contractors and temps in the plan and training, and cover digital threats explicitly.

Not documenting near misses

The report that was never written is the one you cannot learn from. Fix: log near misses, conflicts and security calls in a single place, and review them at each meeting.

Failing to support the people affected

An organization that handles the incident paperwork beautifully and then leaves a witness struggling is telling its staff what the policy really means. Fix: same-day outreach, a named support contact, and follow-up that does not require the person to ask twice.

A few implementation tips that make this stick. Start with the three highest-risk gaps rather than the cheapest. Put the review date in the calendar before you publish the policy. Write the reporting notice in plain language and read it out loud to a new hire. Assign one person who can say, out loud, what the response time is. And if you do only one thing this quarter, make it the reporting channel: named owner, real anti-retaliation wording, tested and published.

Frequently Asked Questions

What should an employer do after receiving a workplace violence threat?

Treat the threat as real. Document the exact words, the medium, the time and the witnesses. If it names specific plans, weapons or intent to reach a particular site, contact law enforcement immediately rather than waiting for an internal review. Route it to the named prevention owner, who assesses immediate risk, applies access restrictions and supports the people who heard it. Immediate danger goes to emergency services first.

Should employees confront a threatening person?

No. Employees should not confront, follow, investigate or try to change the behavior of someone who may be threatening violence, and they should never physically intervene. The safe response is to disengage, move somewhere safe, call emergency services when danger is immediate, and report it through an established channel. Only trained managers and security handle a situation, with law enforcement involved when the risk is credible.

How can employees report workplace violence anonymously?

Give people real options, not a phone number on a poster. A confidential hotline or third-party intake service, an online form, a named HR or safety contact, and a worker or union representative all count. A third-party line is strongest where anonymity matters most, because the report reaches the organization without identifying the reporter. Test every channel with a test report, publish the response time, and pair anonymity with a plain anti-retaliation statement.

Can online threats and harassment require workplace violence action?

Yes. A threat sent by email, a messaging app or a social media account, or a harassment campaign aimed at someone because of their job, can fall inside a workplace violence prevention policy. The same applies to former employees with no current ties and to personal or domestic situations that spill into work. Define violence broadly so digital and off-site conduct is covered, tell staff online threats are taken seriously, and involve law enforcement when a threat is credible and specific.

How often should a workplace violence prevention plan be reviewed?

At least once a year, and more often whenever something changes: an incident or near miss, a new site or shift pattern, a new leadership team, a significant staffing change, or a new legal requirement. Annual is the floor, not the target. Reviews work best when they look at evidence: report volume, response times, repeat reports, the age of open hazard corrections, and training completion. If a hazard survives two review cycles, that is the finding to raise.

A policy does not create a legal right to discipline, and this is where well-intentioned employers cause real harm. Grievances, safety complaints, whistleblowing, organizing activity and ordinary workplace disputes are protected in many jurisdictions, and a policy written as a general anti-complaint weapon can be unlawful. What a policy does give you is a stated standard of conduct and a consistently applied process. Have qualified counsel review the enforcement and reporting language.

Should contractors and visitors receive workplace violence training?

Contractors, temporary and gig workers who work on site should get the same core training as employees, plus site-specific instruction on access, sign-in and reporting, and you should document who completed it. Visitors need the reception and sign-in briefing rather than a full course, plus a way to report a concern while in the building. If you use a staffing agency, put the training obligation in the contract and confirm it was done.

Conclusion

Appoint a named owner today. Then, in this order: assess the site at the hours that are actually risky, publish a short policy with a real reporting route attached, train people on what to do instead of confront, and put the review date in the calendar before anything else goes live.

If you can only act on one thing, find the highest-risk gap you have not fixed yet and close it this week. That is usually the untested reporting channel or the after-dark site nobody has walked. And keep going after that. How to prevent workplace violence is not a project that ends, it is a set of habits that hold, and it only holds as long as somebody is checking.

Leave a Comment