For many organisations, workplace bullying and harassment have traditionally been viewed as employee relations issues – serious, but largely confined to HR. This is now changing rapidly.
Regulators, legislators and stakeholders increasingly view non-financial misconduct as a governance and compliance risk. The expectation is no longer simply that organisations respond appropriately when concerns arise, but that they can demonstrate they took all reasonable steps to prevent misconduct in the first place.
For many HR leaders, C-suite members and compliance teams, this marks a significant shift in accountability.
Regulatory expectations are rising
Recent legislative and regulatory changes have strengthened expectations on employers.
The Employment Rights Act (2025) is introducing a proactive duty to take all reasonable steps to prevent sexual harassment. The Economic Crime and Corporate Transparency Act (ECCTA) has sharpened focus on organisational culture, internal controls and speak-up arrangements. And the Financial Conduct Authority (FCA) have extended their rules on bullying and harassment within financial firms.
The direction of travel is clear – organisations are increasingly expected to evidence prevention – not just simply reaction with the occasion arises. Employers may therefore face greater scrutiny where they cannot demonstrate effective reporting mechanisms, appropriate manager capability, timely investigations, active monitoring of workplace culture risks and meaningful preventative measures.
In practice, policies alone are unlikely to be enough.
Many organisations may still be underprepared
Despite the changing landscape, preparedness remains low. Recent results from our survey showed that only 3% of respondents felt fully prepared for the Employment Rights Act’s new ‘all reasonable steps’ duty coming into force in October.
Many organisations still place too much confidence in the existence of policies or formal procedures. Increasingly, however, regulators are looking beyond documentation to assess whether arrangements are trusted, embedded and effective in practice.
Silence does not mean there is no problem
One of the most common organisational misunderstandings is the assumption that low reporting levels indicate low levels of misconduct. In reality, bullying and harassment are frequently underreported. Employees may fear retaliation, reputational damage or simply believe that raising concerns will not lead to meaningful action.
Our latest Safecall Benchmark Report data reflects this growing pressure. – over the past five years, bullying reports increased by 8%, while harassment reports increased by 6%.
The data is revealing. While web reporting dominates overall, bullying, harassment and unfair treatment concerns generate above-average use of phone reporting channels. When issues feel personal, people often want to speak to someone directly.
Culture failures now carry broader risk
Another common mistake is minimising bullying as interpersonal conflict or a “personality clash”.
Increasingly, regulators and stakeholders see patterns of inappropriate behaviour as indicators of wider governance and leadership weaknesses. Poorly handled concerns can create multiple layers of exposure, including regulatory scrutiny, employment claims, reputational damage and employee attrition.
At the same time, external pressure is intensifying. Media scrutiny around workplace conduct continues to grow, while strengthened UK government incentives for reporting credible tax fraud reflect a broader trend towards encouraging external reporting where trust in internal processes is lacking.
What good looks like
Organisations that are better positioned to demonstrate preparedness typically have clear behavioural standards, trained managers, informed employees, multiple trusted reporting routes, active monitoring of trends and properly scoped investigations, all supported by board-level visibility of culture and conduct risks.
Most importantly, they recognise that policy alone is insufficient. Effective prevention requires a holistic, system-wide approach.
Going forward, the key question for leadership teams is no longer whether misconduct risks exist, but whether the organisation could credibly demonstrate it has done everything reasonably possible to prevent, identify and address them.
For many organisations, now is the time to stress-test those arrangements before they are tested externally – and at the wrong time.